WorksheetsAP Ck CyberSecurity Unit 1
Total questions: 10
Worksheet time: 5mins
Which of the following describes availability when referring to the CIA Triad?
Data are permanently deleted after use by authorized individuals.
Data are only accessible by authorized individuals.
Data are accurate and trustworthy when being viewed by authorized individuals.
Data are accessible when required by authorized individuals.
Which of the following is a potential effect of a breach involving data from a government system?
Members of the public could have their PII compromised.
The government will be able to access additional resources.
Private industries will be given access to more government contracts.
The government will reduce their spending on security features.
A teenager with a keen interest in making quick money stumbles across a popular hacking forum boasting tools to exploit vulnerabilities. Eager to test their luck, they download a widely-used exploit kit that claims to bypass security systems with ease. Hoping to find a way to steal funds and without fully understanding the software’s inner workings they simply follow the tool’s instructions and deploy it against a local business’s website. Within hours, the exploit kit grants them unauthorized access to the company’s financial database. They quickly transfer a small sum of money to their own bank account.
Which of the following describes the type of adversary in this scenario?
Hacktivist
Script kiddie
State adversary
Insider threat
Which of the following describes a state adversary?
They are typically funded through a criminal organization to disrupt a rival organization.
They typically act alone and are motivated by a social cause and believe their end goal justifies all their illegal methods.
They are typically employed by a government and have access to more powerful tools than the average adversary.
They typically work for the organization that they are trying to attack leveraging their access to the organization’s systems.
A developer is creating a tool that pings an IP address that a user inputs. For example, if a user inputs "17.43.125.6" then the system will ping that IP address and display the results to the user. The developer is testing for vulnerabilities and decides to see if they can run a traceroute as well as the ping when using the tool, which is not the intended use of this tool.
To test if the application would run both the traceroute and the ping, the developer enters the input "17.43.125.6 && traceroute 8.34.56.121" into the application.
Which of the following attacks was the developer ensuring their application was protected against?
Injection Attack
Buffer Overflow Attack
Social Engineering Attack
Cross-site Scripting Attack
A risk manager is running a risk assessment for their organization. They have gathered all the assets that are in the scope of assessment and determined the value for each asset. Which of the following steps should be the risk managers next step in the risk assessment?
They should analyze any risks posed by potential vulnerabilities for the assets.
They should determine the vulnerabilities that would impact the assets.
They should document the vulnerabilities that are detected against the assets.
They should analyze any threats posed by potential vulnerabilities for the assets.
Which of the following is an example of a hardware vulnerability for a device?
A device that uses insecure APIs.
A device that allows unsanitized user inputs.
A device that has imported third-party libraries.
A device with out-of-date firmware.
Which of the following proactive strategies help a cybersecurity professional determine threats that could impact a system they are trying to protect?
They can run system health checks.
They can set up user access controls.
They can implement multi-factor authentication.
They can think like an adversary would.
Which of the following would be an example of something that might show up on a quantitative security vulnerability risk analysis?
The chance of a laptop being damaged is high.
The probability of a laptop’s battery going bad is 4%.
The impact of a laptop screen cracking is “critical”.
The cost to replace a stolen laptop would be $800.
An organization realizes that they have a significant amount of risk in a certain area and decide to purchase insurance to cover this risk. The policy ensures the insurance company would pay for any losses if the risk were to be exploited. Which of the following types of risk management strategies was implemented by this organization?
Risk avoidance
Risk transference
Risk mitigation
Risk acceptance
