WorksheetsIT Sec quiz
Total questions: 20
Worksheet time: 10mins
What is the definition of confidentiality in the security context?
Ensuring that data is not modified without authorization.
Ensuring that only authorized users can access data.
Ensuring that actions cannot be denied by the subjects who performed them.
Ensuring that data is available when needed.
Ensuring that data is encrypted before being transmitted.
Which of the following is not a security goal?
Integrity
Availability
Authenticity
Scalability
Confidentiality
What is the purpose of a Message Authentication Code (MAC)?
To encrypt data for secure transmission.
To ensure data integrity and authenticity.
To generate a public key for encryption.
To provide anonymity for the sender.
To compress data for faster transmission.
Which of the following is true about public-key cryptography?
The same key is used for encryption and decryption.
The public key is used for decryption, and the private key is used for encryption.
The private key is used for decryption, and the public key is used for encryption.
Public-key cryptography is faster than symmetric-key cryptography.
Public-key cryptography does not require key distribution.
What is the main advantage of using a digital signature?
It ensures data confidentiality.
It provides non-repudiation and authenticity.
It compresses data for faster transmission.
It encrypts data for secure storage.
It allows for anonymous communication.
What is the primary purpose of a challenge-response protocol?
To encrypt data for secure transmission.
To verify the identity of a user or system.
To compress data for faster transmission.
To generate a public key for encryption.
To provide anonymity for the sender.
What is a replay attack?
An attack where the attacker intercepts and retransmits valid data to gain unauthorized access.
An attack where the attacker guesses passwords using a dictionary.
An attack where the attacker modifies data in transit.
An attack where the attacker floods the network with traffic.
An attack where the attacker exploits a buffer overflow vulnerability.
What is the purpose of a salt in password hashing?
To encrypt the password before storage.
To make the password longer and more complex.
To prevent rainbow table attacks by adding randomness.
To compress the password for faster storage.
To allow the password to be decrypted easily.
What is the main objective of the Bell-LaPadula model?
To ensure data integrity.
To control information flow based on security levels.
To provide non-repudiation for access logs.
To enforce separation of duties.
To ensure availability of resources.
In the Bell-LaPadula model, what does the "no read-up" property enforce?
A subject cannot read data at a higher security level.
A subject cannot write data to a lower security level.
A subject cannot read data at a lower security level.
A subject cannot write data to a higher security level.
A subject cannot execute programs at a higher security level.
What is a Distributed Denial of Service (DDoS) attack?
An attack where the attacker floods a target system with traffic from multiple sources.
An attack where the attacker intercepts and modifies data in transit.
An attack where the attacker exploits a buffer overflow vulnerability.
An attack where the attacker guesses passwords using a dictionary.
An attack where the attacker retransmits valid data to gain unauthorized access.
What is the primary goal of a SQL injection attack?
To encrypt data in the database.
To extract or manipulate data in the database.
To compress data for faster retrieval.
To delete all data in the database.
To create a backup of the database.
What is the purpose of a nonce in a blockchain block?
To encrypt the block's data.
To ensure the block's hash meets the difficulty target.
To compress the block's data for faster transmission.
To provide anonymity for the block's creator.
To allow the block to be decrypted easily.
What is the "nothing-at-stake" problem in proof-of-stake blockchains?
Validators can support multiple chains without penalty.
Validators must stake a large amount of cryptocurrency to participate.
Validators can only validate blocks on one chain.
Validators are required to perform complex computations.
Validators must trust a central authority.
What is the primary function of a firewall in network security?
To compress data for faster transmission.
To authenticate users accessing the network.
To provide a backup for data storage.
To monitor and control incoming and outgoing network traffic.
To encrypt data transmitted over the network.
What does the term "phishing" refer to in cybersecurity?
A process of backing up data to prevent loss.
A strategy for improving network performance.
A technique used to encrypt data for secure transmission.
A type of malware that damages computer systems.
A method of stealing sensitive information through deceptive emails.
What is the role of a Certificate Authority (CA) in public key infrastructure?
To monitor network traffic for security breaches.
To provide anonymity for users.
To encrypt data for secure transmission.
To issue and manage digital certificates.
To store user passwords securely.
What is the main function of encryption in data security?
To ensure data is accessible to everyone.
To protect data from unauthorized access.
To monitor data integrity during transmission.
To provide a backup of data in case of loss.
To compress data for storage efficiency.
What does the term "social engineering" refer to in cybersecurity?
A technique used to manipulate individuals into divulging confidential information.
A type of malware that spreads through social media.
A method of improving network performance.
A process for securing physical access to systems.
A strategy for encrypting data securely.
What is the purpose of a VPN (Virtual Private Network)?
To store data securely in the cloud.
To increase internet speed by bypassing restrictions.
To monitor user activity on the internet.
To compress data for faster transmission.
To provide a secure connection over a public network.
