WorksheetsCybersecurity Basics Pt.1
Total questions: 105
Worksheet time: 3hrs 15mins
In cybersecurity, what does CIA stand for?
Confidentiality, Integrity, Availability
Central Intelligence Agency
Cybersecurity Investigation Agency
Cybersecurity, Internet, Accessibility
Alice is buying books from an online retail site, and she finds that she is able to change the price of a book from $20 to $1.
Which part of the CIA triad has been broken?
C
I
A
None of the above
John is working on his college applications online, when the admissions website crashes. He is unable to turn in his college application on time.
Which part of the CIA triad has been broken?
C
I
A
None of the above
Tony gets his phone bill in the mail. The bill was supposed to be for $80, but the mail person spilled water on the bill, smearing the ink. The bill now asks for $8.
Which part of the CIA triad has been broken?
C
I
A
None of the above
Kim takes her college admissions test and is waiting to get her results by email. By accident, Kim’s results are sent to Karen.
Which part of the CIA triad has been broken?
C
I
A
None of the above
Rob opens his fitness tracking app to start logging a workout. The app crashes, and he is unable to log his workout.
Which part of the CIA triad has been broken?
C
I
A
None of the above
According to the CIA triad, which of the following is not considered in the triad?
Confidentiality
Integrity
Availability
Authenticity
Which of the following contains the primary goals and objectives of security?
Social Media
The CIA triad
The Internet
None of the above
What does confidentiality of data refer to?
Rules which allow access only to all parties
Rules which hide data
Rules which restrict access only to those who need to know
Rules which prevent data from being changed
What does integrity of data refer to?
The level of assurance which can be given as to how structured data is
The level of assurance which can be given as to how accurate and trustworthy data is
The level of assurance which can be given as to how strong data is
The level of assurance which can be given as to how relevant the data is
What does availability of data refer to?
The level of assurance that data exists
The level of assurance that data will be restricted to people who need it, when they need it
The level of assurance that data will be accurate and trustworthy
The level of assurance that data will be available to people who need it, when they need it
Cynthia is working on her university applications online, when the admissions website crashes. She is unable to turn in her application on time.
C
I
A
None of the above
Implementing data validation checks can prevent errors such as incorrect medication dosages or patient information.
Confidentiality
Integrity
Availability
Encrypted Messages:
When you send a private message to a friend, you use a special code (encryption) that only you and your friend can understand.
Confidentiality
Integrity
Availability
Using encrypted email systems or secure messaging apps ensures that patient information shared between doctors and specialists remains secret.
Confidentiality
Integrity
Availability
A doctor writes a prescription for a patient. If the prescription is altered or tampered with, the patient might get the wrong medication.
Confidentiality
Integrity
Availability
In the event of a system failure, the backup system can take over, ensuring that healthcare providers have continuous access to necessary information.
Confidentiality
Integrity
Availability
Password Protection:
Imagine you have a diary that you don't want anyone else to read. You put a lock on it and keep the key hidden.
Confidentiality
Integrity
Availability
When a system prompts for confirmation ensuring that the data is correct before it is saved.
Confidentiality
Integrity
Availability
Banks ensure that ATM machines are operational and have cash available for customers to withdraw money at any time
Confidentiality
Integrity
Availability
An audit trail logs every access and change made to a patient's record, including who made the change and when.
Confidentiality
Integrity
Availability
Only authorized healthcare professionals should have access to a patient's electronic health records.
Confidentiality
Integrity
Availability
A person completed a form on a website. They provided gender as “Female” when they logged into their account the following day, their gender information displayed as “male”.
Confidentiality
Integrity
Availability
Developing and regularly testing disaster recovery plans ensures that healthcare facilities can quickly restore services after a disruption, such as a natural disaster or cyberattack.
Confidentiality
Integrity
Availability
When you buy something, you get a receipt that shows exactly what you purchased and the amount you paid.
Confidentiality
Integrity
Availability
You visit amazon.co.uk to purchase an item but the website is offline.
Confidentiality
Integrity
Availability
How does limiting access contribute to maintaining confidentiality?
Why is it important to maintain the integrity of data like grades?
What does CIA stand for in the context of information security?
Confidentiality, Integrity, and Authentication.
Confidentiality, Integrity, and Authorization.
Confidentiality, Integrity, and Accountability.
Confidentiality, Integrity, and Availability
Which subtopic of CIA Triad focuses on keeping information private and protected from unauthorized access?
confidentiality
authentication
availability
integrity
Which subtopic of CIA Triad ensures that information is accurate, complete, and trustworthy?
Authentication
Integrity
Confidentiality
Availability
Which subtopic of CIA Triad ensures that information is accessible and usable when needed?
Non-repudiation
Confidentiality
Availability
Integrity
Explain how data integrity can be compromised in a network.
By using strong passwords
Through unauthorized data modification
By implementing firewalls
Through regular data backups
Which of the following best describes the concept of data integrity?
Ensuring data is available when needed
Ensuring data is accurate and unaltered
Ensuring data is encrypted
Ensuring data is backed up
What is the primary goal of ensuring system availability in cybersecurity?
To prevent unauthorized access
To ensure systems are operational and accessible
To encrypt sensitive data
To verify user identities
Identify a common threat to system availability.
Data encryption
Denial of Service (DoS) attack
Data redundancy
User authentication
Discuss how multi-factor authentication enhances security.
By requiring only a password
By using multiple methods to verify identity
By encrypting data
By backing up data
Which of the following is an example of an authentication method?
Data encryption
Passwords
Data compression
Data fragmentation
Evaluate the effectiveness of biometric authentication compared to traditional passwords.
Biometric authentication is less secure
Biometric authentication is more secure and convenient
Traditional passwords are more secure
Both are equally secure
What is a potential drawback of using biometric authentication?
It is less secure than passwords
It can be expensive to implement
It requires frequent password changes
It is not user-friendly
How does encryption contribute to data confidentiality?
By making data accessible to everyone
By converting data into a secure format
By deleting unnecessary data
By compressing data
Phish or No Phish?
(Click on the image to see a larger version)
Phish
No Phish
Scam or Real?
(Click on the image to see a larger version)
Scam
Real
What should you look for in the URL to make sure that a site is safe before adding personal information?
https: and a padlock
www. and a globe symbol
that it ends with .com
The weakest point in a security system, is usually:
Poorly coded software
People
Unreliable hardware
Poor network connections
What is PHISHING?
Where a device is used to intercept packets of data as they are transferred across a network. This data is then analysed to look for passwords and other personal data.
Where an executable file is secretly installed to record each key pressed and send
Writing a snippet of code to try and retrieve data from a machine
Sending emails pretending to be from reputable companies to try and get people to reveal personal information
Which of the following people should you share your school password with when they ask?
Your teacher
The head teacher
IT support
Your parents/carers
Nobody
What should you do with a phishing email?
Delete it
Forward it to your friends
Check out the links to see whether they are real
Reply and ask them to stop spamming you
What is the best defense against email scams?
Delete your email when there are links
Avoid email and use social media
Disconnect your home phone because who uses them anyway?
Be skeptical when you are asked for personal information
Which of the following should you NOT do in response to an email scam?
Tell your parents
Reply to the email
Report the email as spam
Delete the email
Which of the following is NOT a tactic commonly used by scammers?
Asking to verify your account information
Asking you to tell your friends about their offer
Making you feel like you have to reply immediately
Telling you that there is a problem with your account that needs to be fixed
Which of the following are often signs that an email is a scam (Tick all that apply)?
Bad grammar and spelling
A link to a fake website
Asking for personal information, such as usernames and passwords
Addressed to you by name
Is this a phishing scam?
Yes
No
Is this a phishing scam?
Yes
No
Is this a phishing scam?
Yes
No
Is this a phishing scam?
Yes
No
Is this a phishing scam?
Yes
No
Is this a phishing scam?
Yes
No
Phishing attacks are mainly using links (shortened URLS) to get you to give them...
money
coffee
personal information
True or False: Phishing attacks are NOT common
True
False
Targeted attacks that focus on ONE person are called __________ phishing.
ninja
spear
sword
big
What 2 places do scammers commonly use information from to create targeted spear phishing attacks? [Choose 2]
Social Media
Identification Cards
Online public records
Libraries
What made Mike McFly (and others) easy to target for a spear phishing attack?
Uses Facebook
Uses Social Media
Privacy settings allows anyone AND everyone to know where he is and what he is doing.
Doesn't like coffee
True or False: The best way to avoid a URL or Link that you don't trust from an EMAIL is to go to the website independently without using the URL.
True
False
The Phishing video author's best advice when opening an unknown link or URL is...
Open every and all shortened URLS and Links
Exercise Extreme Caution
Open some URLS, but not unknown Links
"When someone poses (acts) as an institution, like a bank or a school, and sends you a personalized message asking you to provide private information." is called...
internet scam
identity theft
private information
phishing
"A type of crime in which your private information is stolen and used for criminal activity." is called...
internet scam
identity theft
private information
phishing
"Information that can be used to identify you because it is unique to you." is called...
internet scam
identity theft
private information
phishing
One of the first steps you should take to identify a phishing website is to look at the URL.
true
false
When a malicious actor is attempting to illicit information from a victim, what types of information might they be trying to obtain?
Mother’s maiden name
Addresses
Credit card information
Birthdays
All of these
Phishing attack that is directed towards specific individuals
Spear Phishing
Whaling
SPIM
Smishing
A spear phishing attack that is specific towards a high profile target
Spear Phishing
SPIM
Whaling
Invoice Scam
91% of phishing attacks that successfully get their recipients to click on a link and disclose personal information use a technique called "spear phishing". What is it about spear phishing that’s so effective?
They use very sharp bait hooks.
They use your computer's webcam to make sure it's you.
They personalize the information in the email so you'll believe it's real.
They make use of virtual reality to fool you.
A second type of phishing that's particularly effective is called "clone phishing", so named because...
Each one features C3PO and other Star Wars actors.
They send you the same message over and over and over...
All these emails are created by robots.
The senders replace an email with an attachment you've already received with a similar one that has an infected attachment for you to download.
One kind of phishing that’s used to snare you as you surf the web is called "forgery," where a fake website looks just like a real one. How do they accomplish that forgery?
In the web address, they use “1” instead of “l”, “0” instead of “O” and so on.
They use visual trickery to get you to look away for a moment while they load the bogus website.
They are so smart, they take down the real website and replace it with a criminal one.
They alter the legitimate website so it rips you off.
Not all phishing is done with email and websites. Sometimes fraudsters use your phone to text or call you. They say there's a problem with your bank account and use the information you give them to access and withdraw money or make purchases. They do that by...
Making your phone's caller ID look like it's coming from your bank.
Sounding super convincing using lots of financial words.
Choosing only people with lots of money.
Making sure you're comfortable with them on the phone while they're ripping you off.
Which protocol is secure when browsing website?
HTTP
HTTPS
TELNET
IPV4
When using an untrusted network, what should a person do?
Use a VPN
Use a hotspot instead
Only go to certain sites
No steps are needed
Mr. Taylor normally sits and waits on a target. He sends out anonymous emails hoping that someone would answer the call.
Beware, he seems legitimate.
Hacking
Identify Theft
Phishing
Cyberstalking
Cute smiles and rosy cheeks always makes a heart melt. Be aware, that's a cover up in disguise. When you're not looking she steals the money from your possession without you knowing.
Don't fall for it!
Forgery
Embezzlement
Hacking
Cyberstalking
Just sign on the dotted line and it's yours!
Many persons sign your name as theirs to get loans, cars and many other things.
Phishing
Forgery
Electronic Eavesdropping
Denial of Service Attack
Many persons just feel as though they could ruin other people's lives for the fun of it.
People tend to feel that if they ruin someone's lives, it will also make them feel better about themselves.
Electronic Eavesdropping
Forgery
Phishing
Sabotage
"Shiver me timbers and away I blow", with all of the copying and illegal downloading I go.
Make sure you know where merchants are getting their product from.
Denial of Service Attack
Phishing
Software Piracy
Electronic Eavesdropping
Boy this new look sure looks good to me. Everything about this guy is perfect!
Be careful, people can steal your information to use for their own.
Cyberstalking
Identity Theft
Hacking
Phishing
How many of the following are reasons why someone might want hack a computer system? (Choose 1 - 4 answers)
For political reasons
For ethical reasons
For fun
To steal data
To avoid your computer being infected by malware, you should not:
Download music, movies or software from illegal sites
open emails from people you don’t know
open email attachments
post personal details on social networking sites
Hackers:
will destroy your computer hardware
are rarely able to steal personal data
sometimes steal passwords so they can access your online account
can only steal one password at a time
You can protect yourself against spam or fraudulent emails by:
using a spam filter
never clicking on links that you are suspicious of
being aware of different types of fraudulent email
all of the above
If you receive an email from a well-known company, but its name is misspelt in the sender’s address, you should:
click on the link in the email to check if it’s genuine
reply, pointing out the error
report it as a possible phishing scam
forward the email to a friend to check
A phishing email is one which:
requests a payment for goods you have not received
offers you products in which you may have no interest
encourages you to click on a link to a fraudulent website
contains abusive and threatening language
Define a cyber threat and explain how it differs from a cyberattack.
Explain the purpose and importance of strong passwords.
Describe the three key principles of the CIA triad and explain why each is important in cybersecurity.
How can regular software updates help prevent cyberattacks?
Describe what a vulnerability is in the context of cybersecurity.
