wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Unit 8 Security

Total questions: 131

Worksheet time: 1hrs 6mins

Name
Class
Date
1.

What does CIA stand for?

a)

Confidentiality, Integrity, and Access

b)

Confidentiality, Integrity, and Availability

c)

Confidentiality, Integration, and Access

d)

Confidentiality, Integration, and Availability

2.

What is confidentiality?

a)

Ensuring identity

b)

Integrity

c)

Protection of information

d)

Sharing of information

3.

What are the five confidentiality concerns?

a)

Snooping, Social Engineering, Dumpster Diving, Tapping, and Impersonation

b)

Snooping, Eavesdropping, Dumpster Diving, Wiretapping, and Social Engineering

c)

Snooping, Eavesdropping, Dumpster Diving, Wiretapping, and Socializing

d)

Snooping, Eavesdropping, Recycle Swimming, Wiretapping, and Socializing

4.

What should you do if you find an email to be suspicious?

a)

Validate the identity of the sender

b)

Troll the sender

c)

Sweep the leg

d)

Call the internet police

5.

What does PII stand for?

a)

Personally Identifying Information

b)

Publicly Identifying Information

c)

Personal Incognito Information

d)

Private Identity Information

6.

What is the method called where one searches trash for information?

a)

Wiretapping

b)

Dumpster Diving

c)

Recycle Swimming

d)

Dumpster Swimming

7.

What is the method called where someone manipulates a person in order to gain information?

a)

Kayaking

b)

Social Engineering

c)

Dumpster Diving

d)

Wiretapping

8.

What is Wiretapping?

a)

Searching trash for information

b)

Putting a listener on the phone line so as to listen to the conversation

c)

Listening in on someone else's conversation

d)

Searching for unauthorized information

9.

Which of the following is not an example of PII?

a)

Social Security Number

b)

Home Address

c)

A Company's Financial Records

d)

Driver's License Number

10.

What is one method of protecting information?

a)

Dumpster Diving

b)

Fishing

c)

Eavesdropping

d)

File Encryption

11.

What does the CIA triad stand for?

a)

Confidentiality, Integrity, and Access

b)

Confidentiality, Integrity, and Availability

c)

Confidentiality, Integration, and Access

d)

Confidentiality, Integration, and Availability

12.

What is availability?

a)

The presence of information and systems that are always ready to be used by authorized persons

b)

The presence of information and systems that are always ready to be used

c)

The protection of information

13.

What are the five availability concerns?

a)

Denial of Service, Power Outage, Hardware Failure, DDOS, and Service Outage

b)

Denial of Service, Power Outage, Hardware Failure, Destruction, and Service Outage

c)

DOS, Power Outage, Hardware Failure, DDOS, and Service Outage

d)

DOS, Power Outage, Hardware Failure, Destruction, and Service Disruption

14.

Which of the following is a protection of availability?

a)

Antivirus

b)

Router

c)

Switch

d)

Network Packet Creation

15.

How is DOS and DDOS different?

a)

DDOS is caused by multiple machines

b)

DOS is caused by multiple machines

c)

DOS is caused by robots

d)

DDOS is caused by robots

16.

What is the concern called where system(s) providing power are shut down?

a)

Power Down

b)

Power Outage

c)

Service Outage

d)

Service Down

17.

What can happen when there is lack of availability?

a)

Data Loss/Corruption

b)

Business Failure

c)

Physical Harm

d)

All of the above

e)

None of the above

18.

What is the difference between backup and redundancy?

a)

There is no difference

b)

Backup is the replication of data while redundancy is when data is stored across multiple storage units

c)

Listening in on someone elses conversation

d)

Redundancy is the replication of data while backup is when data is stored across multiple storage units

19.

What is one way to protect against Denial of Service attacks?

a)

Watch the network traffic

b)

Phishing

c)

Identify network irregularities

d)

Anti-firewall

20.

What is Integrity?

a)

Maintenance of data so as for it to remain constant unless authorized changes are made

b)

Maintenance of data so as for it to change constantly unless authorized changes are made

c)

Maintenance of data so as for it to remain constant unless unauthorized changes are made

21.

What are the four Integrity concerns?

a)

Replay Attack, Adversary-in-the-middle Attack, Impersonation, and Unauthorized Information Alteration

b)

Replay Attack, Impersonation, Authorized Information Alteration, and Adversary-in-the-middle Attack

c)

Replay Attack, Adversary Attack, Impersonation, and Unauthorized Information Alteration

d)

Replay Attack, Impersonation, Adversary Attack, and Authorized Information Alteration

22.

What is the difference between an Adversary-in-the-middle Attack and a Replay Attack?

a)

Replay Attack is a type of Adversary-in-the-middle Attack. It steals and sells information transmitted.

b)

Replay Attack is a type of Adversary-in-the-middle Attack. It can only delay information transmitted.

c)

Replay Attack is a type of Adversary-in-the-middle Attack. It repeats or delays information transmitted.

d)

Replay Attack is a type of Adversary-in-the-middle Attack. It can only repeat information transmitted.

23.

How can you limit unauthorized information alteration?

a)

Adversary-in-the-middle

b)

Audit Log

c)

Social Engineering

d)

SSL/TLS

24.

What is one example of impersonation?

a)

Dress as a clown for a job as a party clown

b)

Login using a friends account and hack another computer

c)

Dress up for graduation

d)

Login using your own account and hack another computer

25.

How do you prevent Adversary-in-the-middle Attacks?

a)

Use devices that have certification-based authentication

b)

Use devices that have a certificate of authenticity

c)

Use any device

d)

Use devices that have a certificate award of honor

26.

How do you prevent Replay Attacks?

a)

Use a website that has www

b)

Use a website that has TLS

c)

Use a website that has SSL

d)

Use a website that has TLS or SSL

27.

What does TLS stand for?

a)

Transport Layer Socket

b)

Transport Lock Socket

c)

Transfer Layer Security

d)

Transport Layer Security

28.

What sort of information should keep its integrity?

a)

Locker Numbers

b)

Phone Numbers

c)

Nicknames

d)

Social Security Numbers

29.

A ______ restricts data from entering a system and/or leaving a system.

a)

Anti-virus program

b)

Firewall

c)

Anti-malware program

d)

Cryptosystem

30.

Which of the following is the most secure password?

a)

123456

b)

password

c)

starwarsyoda

d)

5T+lee@aC$4

31.

When an exploit is found, what is used to secure it?

a)

Patches

b)

Anti-virus

c)

Firewalle

d)

Drivers

32.

What does OEM stand for?

a)

Organically Engineered Machine

b)

Original Equipment Manufacturer

c)

Other Equipment Manual

d)

Organic Equivalent Machine

33.

As long as a file doesn't appear malicious, you should keep it if you are not using it.

a)

True

b)

False

34.

Default passwords are considered safe and do not need to be changed.

a)

True

b)

False

35.

Which of the following helps secure a device when browsing the internet?

a)

Firewalls

b)

Never clicking on untrusted links

c)

Antivirus software

d)

All of the above

36.

When using the internet, what should be used to help keep your privacy?

a)

A. HTTP

b)

B. HTTPS

c)

C. Both a and b

d)

D. Neither a or b

37.

When sharing information, you should always ________?

a)

A. Limit what is shared

b)

B. Not share PII

c)

C. Both a and b

d)

D. Neither a or b

38.

When emailing, what should you be aware of?

a)

A. Phishing

b)

B. Fishing

c)

C. HTTPS and HTTP

d)

D. VPN

39.

What is phishing?

a)

A. The sending of emails that contain malicious links/attachments or ask for information/money

b)

B. The sending of emails that contain malicious data

c)

C. Fishing

d)

D. Vishing

40.

What is the main concern for business software?

a)

A. Profits Information

b)

B. Customer and Employee Personally Identifying Information

c)

C. Blueprints of the factory

d)

D. Security camera footage

41.

Which of the following is a way to protect your privacy while using an instant messaging application?

a)

A. Never share PII

b)

B. Communicate only with people you know and trust

c)

C. Encrypt all messages that are being sent

d)

D. All of the above

42.

What is the difference between a black and white list?

a)

The color

b)

A black list is allowed websites while a white list is blocked websites

c)

A black list is blocked websites while a white list is allowed websites

d)

There is no difference between a black list and a white list

43.

What does IDS stand for?

a)

Identifying Data Standards

b)

Intrusion Detection System

c)

Identity Data Standards

d)

Intrusion Data System

44.

What is one method that does not ensure privacy for Desktop Software?

a)

IDS

b)

Black and White Lists

c)

Social Engineering

d)

Lock computer screen when not in use

45.

Confidential information can be broken into all of the following categories EXCEPT...?

a)

Personal information

b)

Customer information

c)

Company public information

d)

Company confidential information

46.

______ information includes phone numbers, social security numbers, and photos.

a)

Personal

b)

Customer

c)

Company public

d)

Company confidential

47.

______ information is all the data about any people that have (or are) customers with an organization.

a)

Personal

b)

Customer

c)

Company public

d)

Company confidential

48.

______ information is how a company does their business and all the data that goes along with it.

a)

Personal

b)

Customer

c)

Company public

d)

Company confidential

49.

How should passwords be stored?

a)

As hashes

b)

In the shadow directory

c)

Encrypted

d)

On a remote server

50.

A social security number would be considered _________.

a)

Personal Information

b)

Company Confidential Information

c)

Company Private Information

d)

None of the above

51.

A company's operations would be considered _________.

a)

Customer Information

b)

Company Confidential Information

c)

Company Private Information

d)

Personal Information

52.

Which of the following is NOT an AAA protocol?

a)

RADIUS

b)

Diameter

c)

TACACS

d)

B-AAA

53.

Which of the following servers communicates via radio network controllers?

a)

AN-AAA

b)

TACACS

c)

B-AAA

d)

H-AAA

54.

Which of the following is NOT one of the "A"s of AAA?

a)

Authentication

b)

Authorization

c)

Assymetry

d)

Accounting

55.

What does TACACS stand for?

a)

Technical Authorization Controller and Control System

b)

Terminal Access Controller Access-Control System

c)

Triad Authority Collective and Continuous Server

d)

Trick question, it's named after Daniel Tacac

56.

What is the purpose of Authorization?

a)

Who can access the network?

b)

What all can a person access on the network?

c)

What all did the person access while on the network?

d)

None of the above

57.

What is the purpose of Authentication?

a)

Who can access the network?

b)

What all can a person access on the network?

c)

What all did the person access while on the network?

d)

None of the above

58.

What is the purpose of Accounting?

a)

Who can access the network?

b)

What all can a person access on the network?

c)

What all did the person access while on the network?

d)

None of the above

59.

What is authentication?

a)

Any method a computer uses to determine who or what can access it

b)

Any method a computer uses to determine what a verified user can do

c)

The record-keeping and tracking of user activities on a computer network

d)

None of the above

60.

Which of the following is an example of a biometric reading?

a)

Password

b)

Iris scan

c)

PIN

d)

SMS token

61.

What does PIN stand for?

a)

Password Integrated Network

b)

Private Identity Network

c)

Personal Identification Number

d)

Public Integration Network

62.

Which device will an SMS token be sent to/stored on?

a)

Smart card

b)

Cell phone

c)

USB flash drive

d)

Fingerprint

63.

Which of the following can be used to find a user's location?

a)

IP address

b)

MAC address

c)

Serial Number

d)

All of the above

64.

Which of the following is an example of using an SSO?

a)

Google account

b)

Microsoft account

c)

Adobe account

d)

All of the above

65.

What is the benefit of using a SSO?

a)

It is more secure since it is a form of two factor authentication

b)

It allows multiple users to access the same account

c)

It provides unlimited access to all network resources

d)

It eliminates the need for passwords

66.

Which of the following is not an example of a factor?

a)

Location

b)

Password

c)

PIN

d)

A web browser's background

67.

Which of the following is an example of a security question?

a)

What is the name of your first pet?

b)

What is the name of your elementary school?

c)

What is your mother's maiden name?

d)

All of the above

68.

What is authentication?

a)

Any method a computer uses to determine who or what can access it

b)

Any method a computer uses to determine what a verified user can do

c)

The record-keeping and tracking of user activities on a computer network

d)

None of the above

69.

Which of the following is an example of a biometric reading?

a)

Password

b)

Iris scan

c)

PIN

d)

SMS token

70.

What does PIN stand for?

a)

Password Integrated Network

b)

Private Identity Network

c)

Personal Identification Number

d)

Public Integration Network

71.

Which device will an SMS token be sent to/stored on?

a)

Smart card

b)

Cell phone

c)

USB flash drive

d)

Fingerprint

72.

Which of the following can be used to find a user's location?

a)

IP address

b)

MAC address

c)

Serial Number

d)

All of the above

73.

Which of the following is an example of using an SSO?

a)

Google account

b)

Microsoft account

c)

Adobe account

d)

All of the above

74.

What is the benefit of using a SSO?

a)

It is more secure since it is a form of two factor authentication

b)

It allows multiple users to access the same account

c)

It provides unlimited access to all network resources

d)

It eliminates the need for passwords

75.

Which of the following is not an example of a factor?

a)

Location

b)

Password

c)

PIN

d)

A web browser's background

76.

Which of the following is an example of a security question?

a)

What is the name of your first pet?

b)

What is the name of your elementary school?

c)

What is your mother's maiden name?

d)

All of the above

77.

What is authorization?

a)

Any method a computer uses to determine who or what can access it

b)

Any method a computer uses to determine what a verified user can do

c)

The record-keeping and tracking of user activities on a computer network

d)

None of the above

78.

What is policy enforcement?

a)

Determining what authorized rights are for users

b)

Determining what applications can run at the same time

c)

Ensuring that users only gain access to authorized rights

d)

Removing unauthorized files from a system

79.

What is policy definition?

a)

Determining what authorized rights are for users

b)

Determining what applications can run at the same time

c)

Ensuring that users only gain access to authorized rights

d)

Removing unauthorized files from a system

80.

Which type of user has the highest/most privileges?

a)

User

b)

Privileged User

c)

Executive User

d)

Master User

81.

What does MAC stand for?

a)

Massively Awesome Computer

b)

Mandatory Access Control

c)

Mechanism Accessory Console

d)

Migration Activity Console

82.

What does DAC stand for?

a)

Direct Access Control

b)

Discretionary Access Control

c)

Digital Accessory Console

d)

Decryption Activity Console

83.

As the owner of a spreadsheet, you can determine who in your environment has read only access and who has read/write access, what is this known as?

a)

Access Control

b)

User Management

c)

Permission Setting

d)

Authorization

84.

What is the correct answer for AAA Authorization?

a)

MAC

b)

RBAC

c)

DAC

d)

TAC

85.

What is non-repudiation?

a)

Log files can't repeat, unless they are the same log file

b)

The owner of a private key cannot deny having sent a digital signature

c)

Tracking cannot be used to verify the user of a system

d)

Repeated computations provide unique log files

86.

What can be used to guarantee non-deniability?

a)

Biometrics

b)

Receipt

c)

Physical signature

d)

All of the above

87.

CIA in Information Security stands for -

a)

Confidentiality, Integration and Availability

b)

Continuity, Integration and Availability

c)

Continuity, Integrity and Accessibility

d)

Confidentiality, Integrity and Availability

88.

Which of the following is a key component of ensuring data integrity?

a)

Authorization

b)

Authentication

c)

Hashing

d)

Encryption

89.

What is the primary purpose of a digital signature?

a)

To encrypt data

b)

To verify the identity of the sender

c)

To compress data

d)

To provide a backup

90.

Which of the following best describes the concept of availability in information security?

a)

Ensuring data is accurate and reliable

b)

Protecting data from unauthorized access

c)

Verifying the identity of users accessing the system

d)

Ensuring data is accessible to authorized users when needed

91.

Which of the following is NOT true regarding strong passwords?

a)

Contains a minimum of 4 characters

b)

Contains symbols

c)

Contains numbers

d)

Contains upper and lower case letters

92.

Commonly used passwords are stored in what is commonly known as a ______.

a)

Library

b)

Dictionary

c)

Encyclopedia

d)

Collection

93.

Which of the following is part of the password reset process?

a)

Ask security questions

b)

Send a token via side-channel

c)

Allow the user to change the password

d)

All of the above

94.

Which of the following is a password best practice?

a)

Longer passwords

b)

Password expirations

c)

Use Password Managers

d)

All of the above

95.

Which of the following is a password best practice?

a)

Do not use a password manager

b)

Never reuse passwords

c)

Keep the passwords simple and not complex

d)

Never have a password expiration date

96.

Which of the following would be considered the most secure password?

a)

G@nd0lf

b)

G@nd0lf&L0tR!7

c)

GandolfTheGrey

d)

GaNdOlFtHeWiZaRd

97.

Why should a user not use the same password across multiple websites?

a)

In case a website is compromised and that password is captured

b)

True

c)

False

98.

What does the word kryptos mean?

a)

A secret

b)

To study

c)

Disguise

d)

To teach

99.

What does the word graphein mean?

a)

A secret

b)

To study

c)

Disguise

d)

To teach

100.

What does encrypt mean?

a)

Hide in plain sight

b)

Convert into a code

c)

Revert a code to the original

d)

Recover file from deletion

101.

What does decrypt mean?

a)

Hide in plain sight

b)

Convert into a code

c)

Revert a code to the original

d)

Recover file from deletion

102.

What is the message to be sent which has not been encrypted?

a)

Cleartext

b)

Ciphertext

c)

Plaintext

d)

Cybertext

103.

What is data that is physically stored in a digital form such as databases, spreadsheets, archives, or external storage drives?

a)

Data in transit

b)

Data at rest

c)

Data in motion

d)

Data in use

104.

Which of the following is NOT a way to secure sensitive data?

a)

AES

b)

RSA

c)

VGA

d)

All of the above

105.

At what level is encryption for data at rest done?

a)

The whole disk

b)

The database

c)

Individual files/folders

d)

All of the above

106.

What is the term used to describe data that is in transit through networks?

a)

Data in transit

b)

Data in motion

c)

Data in flight

d)

All of the above

107.

What is private data in transit?

a)

Data sent via email

b)

Data sent within a private network

c)

Data sent via SMS

d)

Data transferred from one computer to another via USB

108.

What does TLS stand for?

a)

Technical Logistics Service

b)

Transport Layer Security

c)

Technology Level Security

d)

Transferral Level Security

109.

Which encryption extension is used for email?

a)

HTTPS

b)

HTTP

c)

STARTTLS

d)

AES

110.

What is a contingency plan?

a)

A plan devised for an outcome other than the one stipulated in the usual plan

b)

A plan to improve system performance

c)

A plan to increase company profits

d)

A plan to expand business operations

111.

What are some situations that warrant a contingency plan?

a)

Hard drive failure, Power loss, Physical facility damage, Malicious attack

b)

System upgrade, Software installation, Employee training, Marketing campaign

c)

Product launch, Customer feedback, Market research, Sales meeting

d)

Team building, Office renovation, Holiday planning, Budget review

112.

What is fault tolerance?

a)

The ability of a system to continue to operate uninterrupted when one or more of its components fail

b)

The ability of a system to increase speed under heavy load

c)

The ability of a system to reduce costs during operation

d)

The ability of a system to expand storage capacity

113.

How do fault tolerance systems work?

a)

They use backup components that automatically activate when a component fails

b)

They increase the speed of existing components

c)

They reduce the number of components needed

d)

They rely on manual intervention to fix issues

114.

What is replication?

a)

Running multiple versions of identical systems

b)

Creating a backup of data

c)

Developing new software

d)

Deleting old files

115.

Give an example of replication.

a)

Server having an identical server running in parallel

b)

Installing a new operating system

c)

Updating software to the latest version

d)

Deleting duplicate files

116.

What is redundancy?

a)

The inclusion of extra hardware in case of failure which does not run in parallel to the original hardware

b)

Running multiple versions of identical systems

c)

Creating a backup of data

d)

Developing new software

117.

What are redundancy and replication when defined within the context of nodes?

a)

Redundancy is the duplication of nodes in the case of failure while replication is synchronizing the state between redundant nodes

b)

Redundancy is creating a backup while replication is deleting old files

c)

Redundancy is updating software while replication is installing new hardware

d)

Redundancy is developing new software while replication is running multiple systems

118.

What is Carbonite?

a)

An online backup tool

b)

A chemical element

c)

A chemical compound composed of Carbon and Graphite

d)

An internal computing component

119.

A(n) ______ is the state of a system at a particular point in time.

a)

Snapshot

b)

Image

c)

Photograph

d)

Recording

120.

A ______ is computer software, firmware, or hardware that creates and runs virtual machines.

a)

Supervisor

b)

Hypervisor

c)

Firewall

d)

FireWire

121.

What is responsible for identifying when a file is ready for archiving?

a)

Archive bit

b)

File readiness

c)

Time stamp

d)

Clearby

122.

A ______ is a place that a company can temporarily relocate to following a security breach or natural disaster.

a)

Contingency area

b)

Disaster recovery site

c)

Temp storage

d)

None of the above

123.

A ______ disaster recovery site is simply an empty building.

a)

Hot

b)

Warm

c)

Cold

d)

Tepid

124.

Which of the following is NOT part of the disaster recovery process?

a)

Data restoration

b)

Prioritization

c)

Restoring process

d)

Snapshot

125.

Which of the following is NOT part of the disaster recovery process?

a)

Data restoration

b)

Prioritization

c)

Restoring process

d)

Snapshot

126.

The most critical systems need to be restored first.

a)

True

b)

False

127.

The most critical systems need to be restored first.

a)

True

b)

False

128.

______ is deciding what needs to be recovered first.

a)

Data restoration

b)

Prioritization

c)

Restoring Process

d)

None of the above

129.

______ is deciding what needs to be recovered first.

a)

Data restoration

b)

Prioritization

c)

Restoring Process

d)

None of the above

130.

______ is the steps to get everything back to running smoothly.

a)

Data restoration

b)

Prioritization

c)

Restoring Process

d)

None of the above

131.

______ is the steps to get everything back to running smoothly.

a)

Data restoration

b)

Prioritization

c)

Restoring Process

d)

None of the above