WorksheetsChapter Summary
Total questions: 71
Worksheet time: 36mins
What is the process of protecting the value of data as the organization creates, stores, shares, uses, modifies, archives, and finally destroys that data called?
Data (information) security
Data mining
Data visualization
Data redundancy
During data handling, which of the following is NOT one of the steps an organization takes?
Classifies data
Categorizes data
Encrypts data
Retains data
Destroys data
A best practice for securing data is ________ the data.
encrypting
deleting
sharing
printing
Hashing is a process that takes an input set of data and returns a ________ result called the hash value.
fixed-length
variable-length
random
encrypted
System hardening is the process of applying secure configurations to reduce the ________ surface.
attack
display
storage
network
Which of the following is NOT a best practice security policy mentioned in the chapter?
Data handling
Password
Acceptable use
Social engineering
Change management
Change management practices address documentation, approval, and rollback as core activities.
True
False
Why is security awareness training important for an organization?
It reduces the internal threat to an organization by educating, training, and raising awareness among employees.
It increases the number of cyber attacks on the organization.
It decreases employee productivity by distracting them from their main tasks.
It makes the organization completely immune to all security threats.
Which topic is covered in Module 1?
Understand System Hardening
Understand Data Security
Understand Best Practice Security Policies
Understand Security Awareness Training
Module 2 covers which topic?
Understand System Hardening
Network Security Basics
Incident Response Procedures
Cloud Computing Fundamentals
Which module covers 'Understand Best Practice Security Policies'?
Module 1
Module 2
Module 3
Module 4
Module 4 is associated with which domains?
5.1, 5.1.1, 5.1.2, 5.1.3
5.2, 5.2.1
5.3, 5.3.1, 5.3.2, 5.3.3, 5.3.4, 5.3.5, 5.3.6
5.4, 5.4.1, 5.4.2, 5.3.2
State one of the learning objectives:
Explain concepts of security operations.
Describe the process of software installation.
List the types of network cables.
Identify common office equipment.
State one of the learning objectives:
Discuss data handling best practices.
Describe the process of photosynthesis.
Explain the laws of motion.
Identify the capitals of European countries.
State one of the learning objectives:
Identify key concepts of logging and monitoring.
Describe the process of photosynthesis.
Explain the laws of thermodynamics.
List the capitals of European countries.
State one of the learning objectives:
Summarize the different types of encryption and their common uses.
Describe the process of photosynthesis in plants.
Explain the causes of the French Revolution.
List the major planets in our solar system.
State one of the learning objectives:
Describe the concepts of configuration management.
Explain the process of software testing.
List the types of computer networks.
Summarize the history of programming languages.
State one of the learning objectives:
Explain the application of common security policies.
Describe the process of software installation.
List the types of computer hardware.
Identify popular social media platforms.
State one of the learning objectives:
Discuss the importance of security awareness training.
List the steps to install a software update.
Describe the process of hardware recycling.
Explain the basics of network cabling.
State one of the learning objectives:
Practice the terminology of and review the concepts of network operations.
Memorize unrelated historical dates.
Learn advanced calculus techniques.
Study the anatomy of plants.
Which of the following is NOT a step in the data handling process?
Create
Store
Encrypt
Destroy
Fill in the blank: The data handling process includes Create, Store, Share, Use, Modify, Archive, and _____
Destroy
Encrypt
Transfer
Analyze
Which data sensitivity level could put the organization’s future existence at risk if compromised?
Highly restricted
Moderately restricted
Low sensitivity
Unrestricted public data
Fill in the blank: Compromise of data with a _____ sensitivity label could lead to loss of temporary competitive advantage, loss of revenue, or disruption of planned investments or activities.
Moderately restricted
Public
Highly confidential
Unclassified
Unrestricted public data, if compromised, can cause substantial loss of life or property damage.
True
False
Which of the following is an ingress monitoring tool?
Firewalls
FTP
APIs
Fill in the blank: IDS/IPS tools are used for _____ monitoring.
Ingress
Egress
Physical
Application
Which of the following is an egress monitoring data type?
Gateways
SIEM solutions
Email (content and attachments)
Anti-malware solutions
Fill in the blank: Applications/application programming interfaces (APIs) are monitored as part of _____ data types.
Egress monitoring
Ingress monitoring
Static analysis
Data encryption
Which type of encryption uses the same key for both encryption and decryption?
Symmetric
Asymmetric
Fill in the blank: Asymmetric encryption uses _____ keys.
different
identical
public-only
shared
Which of the following is a function of a cryptographic hash?
It is easy to compute the hash value for any given message.
It is easy to reverse the hash process.
It is easy to modify a message and produce the same hash value.
It is easy to find two messages that hash to the same value.
Fill in the blank: It is computationally infeasible to reverse the hash process or otherwise derive the original plaintext of a message from its hash value. This property is called ________.
Nonreversible
Deterministic
Commutative
Associative
Content integrity assurance means it is computationally infeasible to modify a message such that re-applying the hash function will produce the original hash value.
True
False
Which property of a cryptographic hash ensures that it is computationally infeasible to find two or more different, sensible messages that hash to the same value?
Useful
Nonreversible
Unique
Deterministic
Fill in the blank: The same input will always generate the same hash, when using the same hashing algorithm. This property is called ________.
Deterministic
Randomness
Volatility
Ambiguity
Which of the following is NOT a configuration management procedure?
A) Identification
B) Baseline
C) Change control
D) Encryption
Which of the following are elements of configuration management?
Version control and change control
Testing and debugging
User interface design and documentation
Marketing and sales
Which of the following is a best practice security policy?
Data handling
Password
Acceptable use
All of the above
Fill in the blank: Appropriate use of personal devices is covered under the ________ policy.
Bring your own device
Acceptable use
Privacy
Remote work
Change management is about the appropriate transition from current state to a future state.
True
False
Which of the following is NOT a data handling policy procedure?
Classify
Categorize
Encrypt
Hash
Fill in the blank: The process of protecting data by converting it into a coded format is called ________.
Encrypt
Compress
Format
Backup
Which of the following are data handling policy procedures?
Data encryption and regular backups
Data visualization and chart making
Data entry and data deletion
Data mining and data analysis
Which of the following is encouraged for password creation?
Short passwords
Longer passphrases
Using the same password everywhere
Writing down your password
Passwords cannot be the same or similar to other passwords used on any other ________, system, application or personal account.
websites
documents
printers
folders
Passwords should not be a single word or a commonly used phrase.
True
False
Which of the following should be avoided when creating passwords?
Names and birthdays of friends and family
Favorite bands
Catchphrases
All of the above
Dictionary words and phrases should be ________ when creating passwords.
avoided
used
preferred
encouraged
Default installation passwords must be changed ________ after installation is complete.
immediately
after one week
after one month
whenever convenient
User passwords must be changed on a schedule established by the ________.
organization
user
software
network
True or False: Previously used passwords may be reused according to best practice security policies.
True
False
System-level passwords must be changed according to a schedule established by ________.
the organization
the government
the software vendor
the user
Passwords must not be shared with anyone, even ________ or supervisors.
IT staff
friends
family members
colleagues
Which of the following is NOT an acceptable use policy (AUP) procedure?
Data access
System access
Passwords
Cooking recipes
Which of the following devices can be included in a bring your own device (BYOD) policy?
Cell phone
Tablet
Laptop
All of the above
Privacy policy protects which of the following?
PII
ePHI
Bank/credit card information
All of the above
GDPR is a privacy regulation in which region?
EU
Asia
South America
Australia
Personal Information Protection and Electronic Documents Act (PIPEDA) is a privacy law in which country?
Canada
United States
Australia
United Kingdom
Change management policy consists of three major activities. Fill in the blank: The first activity is _________.
Deciding to change
Implementing the change
Evaluating the outcome
Communicating the change
Change management policy consists of three major activities. Fill in the blank: The second activity is _________.
Making the change
Identifying the stakeholders
Evaluating the risks
Documenting the process
Change management policy consists of three major activities. Fill in the blank: The third activity is _________
Confirming that the change has been correctly accomplished
Initiating the change request
Documenting the change for future reference
Assigning roles to the change team
Which of the following is a type of security awareness training?
Education
Monitoring
Auditing
Enforcement
Which of the following is a type of security awareness training?
Training
Auditing
Enforcement
Monitoring
Which of the following is a type of security awareness training?
Awareness
Auditing
Enforcement
Monitoring
Which of the following is a social engineering technique?
Baiting
Encryption
Firewalling
Logging
Which of the following is a social engineering technique?
Phone phishing or vishing
Encryption
Firewalling
Logging
Which of the following is a social engineering technique?
Pretexting
Encryption
Firewalling
Logging
Which of the following is a social engineering technique?
Quid pro quo
Encryption
Firewalling
Logging
Which of the following is a social engineering technique?
A) Tailgating
B) Encryption
C) Firewalling
D) Logging
Which of the following is a social engineering technique?
False flag or false front operations
Encryption
Firewalling
Logging
