WorksheetsControl Types Quiz
Total questions: 98
Worksheet time: 49mins
Which of the following is an example of a technical control?
Firewalls
Risk assessments
Incident response
Locks
What type of control involves high-level policy and decision making?
Technical Controls
Managerial Controls
Operational Controls
Physical Controls
Which control type is designed to detect and report events?
Preventive Controls
Detective Controls
Corrective Controls
Compensating Controls
What is an example of a compensating control?
Firewalls
Security cameras
Patches
Using a camera system when no physical guards exist
Which control category focuses on day-to-day operational activities?
Technical Controls
Managerial Controls
Operational Controls
Physical Controls
What is the primary purpose of deterrent controls in security?
Enforce expected behaviors
Deter attacks
Grant permissions
Track user actions
Which of the following is an example of directive controls?
Surveillance cameras
Acceptable Use Policies (AUP)
Firewalls
Encryption
What does confidentiality in core security concepts aim to prevent?
Unauthorized access to information
Unauthorized changes to information
Unauthorized user actions
Unauthorized identity verification
In the AAA framework, what is the role of authentication?
Granting permission
Verifying identity
Tracking user actions
Enforcing policies
What is the main focus of a gap analysis in security?
Continuous verification
Identifying differences between current and desired states
Adaptive identity validation
Enforcing expected behaviors
What is the purpose of bollards in physical security?
To provide lighting in dark areas
To block vehicle entry
To detect motion using microwaves
To monitor CCTV footage
Which type of sensor is used for heat detection?
Pressure
Infrared
Microwave
Ultrasonic
What is the role of access control vestibules in security?
To provide identity credentials
To control entry using mantraps
To deter crime with bright areas
To monitor with CCTV
How do ultrasonic sensors contribute to security?
By detecting weight changes
By detecting motion using high-frequency sound
By providing identity credentials
By blocking vehicle entry
What is eliminated in the data plane of Zero Trust architecture?
Policy-driven access decisions
Implicit trust zones
Threat surface reduction
Identity credentials
What is a honeypot used for in cybersecurity?
To store sensitive data securely
To lure attackers with a fake system
To encrypt data transmissions
To monitor network traffic
Which of the following is a network of honeypots?
Honey file
Honeytoken
Honeynet
Firewall
What is the primary purpose of change management in IT?
To increase system complexity
To prevent unexpected downtime
To reduce employee workload
To enhance user interface design
Which key element of change management involves planning to reverse changes if needed?
Approval Process
Impact Analysis
Backout Plan
Maintenance Window
What is the role of allow lists/deny lists in technical implications?
To enhance user experience
To restrict what can/can't run
To improve system aesthetics
To increase data storage capacity
What is the purpose of downtime planning in system management?
To enhance software features
To account for system interruptions
To increase network speed
To reduce hardware costs
Which of the following is required after updates in system management?
Data backup
Service/Application Restarts
User training
Hardware replacement
What is a characteristic of a public key in Public Key Infrastructure (PKI)?
Kept secret
Shared with everyone
Used for encryption only
Held by a third party
In Public Key Infrastructure (PKI), what is the role of key escrow?
Encrypts data
Decrypts data
Third party holds a backup key
Generates public keys
Which of the following is not an encryption level mentioned in the document?
Full disk
Partition
File
Network
What is the primary purpose of transport encryption?
Secure data at rest
Secure data in motion
Encrypt database records
Encrypt hardware components
Which type of encryption uses two keys, one for encryption and one for decryption?
Symmetric Encryption
Asymmetric Encryption
Transport Encryption
Key Exchange Protocols
What is an example of symmetric encryption?
RSA
ECC
AES
TLS
What is the role of a Trusted Platform Module (TPM)?
Encrypt data in motion
Secure crypto processor on motherboard
Store symmetric keys
Perform key exchange
Which of the following is a key exchange protocol?
AES
Diffie-Hellman
RSA
ECC
What is the primary function of a Key Management System?
To encrypt data
To manage keys throughout their lifecycle
To store passwords
To generate random numbers
Which cryptographic technique involves hiding data inside other files?
Tokenization
Data Masking
Steganography
Hashing
What is the purpose of salting in cryptography?
To encrypt data
To add random data to input before hashing
To replace sensitive data with non-sensitive equivalents
To verify sender and data integrity
What does a Certificate Authority (CA) do?
Encrypts data
Issues and manages certificates
Validates passwords
Hides data inside other files
What is the role of a Root of Trust in cryptographic systems?
To encrypt data
To establish trust starting with a root CA
To hide parts of sensitive data
To produce a fixed-size digest of data
What is the purpose of a Certificate Signing Request (CSR)?
To secure all subdomains
To request a certificate
To revoke a certificate
To encrypt data
Which type of threat actor is typically government-sponsored and focuses on espionage or disruption?
Hacktivist
Insider Threat
Nation-State
Organized Crime
What is a characteristic of an Unskilled Attacker, also known as a Script Kiddie?
Uses sophisticated tools
Motivated by political causes
Uses existing tools without understanding
Seeks financial profit
Which attribute of threat actors involves insider versus outsider origin?
Resources/Funding
Internal vs. External
Sophistication/Capability
Motivations
What is the primary goal of data exfiltration?
Gathering intelligence
Stealing sensitive information
Denial-of-service attacks
Hacktivism
Which of the following is an example of a message-based threat?
Phishing emails
Denial-of-service attacks
Hacktivism
Cyberwarfare
What is the main purpose of espionage in cybersecurity?
To cause instability
To gather intelligence
To steal money
To expose for ransom
What type of attack involves threatening exposure for ransom?
Espionage
Blackmail
Ethical hacking
Chaos/Disruption
What is "smishing" primarily associated with?
Short Message Service (SMS)
Instant Messaging (IM)
Social media
Which type of threat involves embedding malicious code inside images?
File-Based Threats
Image-Based Threats
Voice Call Threats
Open Service Ports
What is an example of a file-based threat?
USB drives loaded with malware
Executable files (.exe)
Open Wi-Fi networks
Unsupported Linux distros
What does "vishing" refer to in the context of voice call threats?
Embedding code in images
Voice phishing to extract information
Using USB drives for attacks
Exploiting open service ports
Which of the following is a vulnerability associated with removable devices?
Steganography attacks
USB drop attacks
Bluejacking
Malicious PDFs
What is a characteristic of unsecure wireless networks?
No WPA2/WPA3 protection
Poor physical security
Unsupported Linux distros
Malicious macros
What is a common risk associated with leaving unnecessary ports open, such as telnet or FTP?
Increased network speed
Enhanced data encryption
Vulnerability to unauthorized access
Improved firewall protection
What are default credentials typically associated with?
Custom security settings
Factory default usernames/passwords
Advanced encryption methods
User-defined passwords
Which of the following is an example of a supply chain attack?
Phishing emails
Compromising Managed Service Providers (MSPs)
Using strong passwords
Installing antivirus software
What is the primary goal of phishing attacks?
To improve network speed
To ask for credentials through deceptive emails
To enhance data encryption
To provide technical support
What does the term "vishing" refer to?
Email scams
Fraudulent phone calls
SMS text scams
Fake websites
What is the purpose of a watering hole attack?
To improve website performance
To infect a site commonly visited by the target
To enhance user experience
To provide free software updates
Which of the following is an example of a physical attack surface?
Open Wi-Fi
Unlocked server rooms
Poorly coded web apps
Untrained employees
What is typo squatting?
A type of phishing scam
Registering domains similar to legitimate ones
Exposing network ports
Using outdated software versions
How can attack surfaces grow?
By using strong passwords
Through cloud services and IoT devices
By updating software regularly
By training employees
Which of the following is a network attack surface?
Vulnerable IoT devices
Exposed APIs
Untrained employees
Lack of change management
What is a Memory Injection attack?
An attack that manipulates memory during program execution.
An attack that injects SQL statements into databases.
An attack that changes the state of a system before use.
An attack that injects scripts into web pages.
Which of the following describes a Buffer Overflow?
Injecting scripts into web pages.
Excess data overflowing into adjacent memory.
Changing a state before it is used.
Injecting SQL statements into databases.
What is a Time-of-Check (TOC) vulnerability?
An attack that occurs between the check and use of a resource.
A state that is verified but changed before use.
An attack that injects SQL statements into databases.
An attack that manipulates memory during execution.
What is SQL Injection (SQLi)?
Injecting malicious scripts into web pages.
Injecting malicious SQL statements into input fields.
Manipulating memory during program execution.
Changing a state before it is used.
What is Cross-Site Scripting (XSS)?
An attack that manipulates memory during execution.
An attack that injects SQL statements into databases.
An attack that injects malicious scripts into web pages.
An attack that changes a state before it is used.
What is a potential risk associated with firmware vulnerabilities?
They can be easily updated by users.
They are immune to attacks if not patched.
They can be attacked if not patched.
They are only a concern for software developers.
What does "End-of-Life (EOL) Devices" refer to?
Devices that are newly released.
Devices that are no longer supported or patched by vendors.
Devices that are immune to modern threats.
Devices that are only used in legacy systems.
What is a VM Escape in virtualization vulnerabilities?
A VM that runs without any issues.
Malicious code running in a VM breaks out to attack the host machine.
A VM that is immune to attacks.
A VM that is properly isolated from the host machine.
What is a common issue with cloud-specific vulnerabilities?
Perfectly configured cloud storage.
Insecure APIs.
Strong identity and access management controls.
Fully secure cloud environments.
What is a service provider risk in supply chain vulnerabilities?
Cloud providers ensuring perfect security.
Hosting companies mishandling security.
Service providers offering free services.
Vendors providing regular updates.
What is a potential risk associated with hardware providers?
Malicious components inserted into motherboards, network cards
Libraries, updates infected at the source
Weak algorithms like MD5, SHA-1
Publicly exposed data due to misconfigured cloud services
Which of the following is an example of a cryptographic vulnerability?
Side loading apps from official stores
Predictable random number generation
Removing device restrictions
No patch available yet
What does "jailbreaking" a mobile device involve?
Installing apps from official stores
Removing device restrictions, exposing users to security threats
Updating the device's operating system
Encrypting the device's data
What characterizes a zero-day vulnerability?
Known to vendors and users before exploitation
No patch available yet
Strong encryption methods
Secure cloud configurations
What is a characteristic of ransomware?
Unauthorized data collection
Systems locked, ransom notes, encrypted file extensions
Legit-looking software that performs malicious actions
Rapid self-replication across networks
Which type of malware is known for rapid self-replication across networks?
Spyware
Trojan Horse
Worm
Keylogger
What does a keylogger do?
Hides the presence of malware
Monitors keystrokes and may cause unusual login behavior
Triggers malicious code on specific dates
Slows down devices with unwanted programs
Which attack indicator involves multiple login failures and account lockouts?
RFID Cloning
Brute Force Attacks
Environmental Disruptions
Distributed Denial-of-Service (DDoS)
What is the main purpose of a rootkit?
To encrypt files and demand ransom
To hide the presence of malware
To replicate rapidly across networks
To monitor keystrokes
What is an Amplified DDoS attack?
A small request triggers massive responses.
Attack appears to originate from legitimate sources.
Data interception between sender and receiver.
Reusing stolen credentials to gain unauthorized access.
Which type of attack involves DNS cache poisoning?
Wireless Attacks
DNS Attacks
Buffer Overflows
Replay Attacks
What is a characteristic of a Reflected DDoS attack?
Attack appears to originate from legitimate sources.
Evil twin access points.
SQLi attempts visible in logs.
Malware spreading across systems.
Which attack involves data interception between sender and receiver?
On-Path Attacks (Man-in-the-Middle)
Buffer Overflows
Injection Attacks
Replay Attacks
What is a common indicator of a Buffer Overflow?
Crashes, unusual application behavior.
Captured valid data resent to mimic legitimate access.
DNS tunneling.
Rogue hotspots.
What is a common indicator of privilege escalation?
Access to unintended files
Unusual user permission changes
Forcing weaker encryption
Single passwords tried across many users
Which attack involves two different inputs producing the same hash?
Downgrade Attack
Password Spraying
Collision Attack
Account Lockout
What is a characteristic of a brute force password attack?
Forcing weaker encryption
Systematic password guessing until access is gained
Exploiting hash collisions
Access to unintended files
What does a downgrade attack typically involve?
Exploiting hash collisions
Forcing weaker encryption during handshake processes
Single passwords tried across many users
Unusual user permission changes
What is an indicator of concurrent session usage?
Sudden lockout due to too many login attempts
Same account active in multiple locations
Users reporting denied access to legitimate resources
Systematic password guessing
What is an example of an "Impossible Travel Event" in cybersecurity?
Logins from geographically impossible locations
CPU usage abnormally high
Systems becoming unresponsive
Unexpected timestamps in logs
Which of the following describes "Resource Consumption Spikes"?
Systems becoming unresponsive
CPU/memory/network usage abnormally high
Deletion of log files
Unexpected system activity
What is the purpose of dividing networks into smaller segments?
To increase network speed
To limit attacker movement
To reduce hardware costs
To simplify network management
What do Access Control Lists (ACLs) specify in a network?
Network speed
Who can access what
Hardware requirements
Software updates
What is the function of Application Allow Lists?
To allow all applications to run
To block unknown or malicious programs
To increase application speed
To reduce application size
What is the purpose of using sandbox environments for suspicious apps?
To enhance app performance
To test app functionality
To isolate and analyze potential threats
To improve user interface
Why is it critical to maintain current security patches?
To increase software speed
To fix vulnerabilities and enhance security
To add new features
To reduce software size
What is the role of encryption in data security?
To compress data for storage
To enhance data readability
To protect data at rest, in transit, and in use
To increase data transfer speed
How does the principle of least privilege help in security?
By granting all users full access
By reducing the impact of compromised accounts
By increasing system complexity
By allowing unrestricted data sharing
What is the purpose of configuration management tools like Chef and Puppet?
To design user interfaces
To enforce secure settings across systems
To develop mobile applications
To manage network traffic
