Font size
WorksheetsCompTIA N+ N10-009 Mock Test 3 Revision
Total questions: 59
Worksheet time: 33mins
Which of the following is NOT one of the three main goals of computer security as remembered by the CIA triad?
Confidentiality
Compliance
Integrity
Availability
What term describes a weakness in a system-like an unlocked door-that could let someone cause harm, whether by accident or on purpose?
Threat
Risk
Vulnerability
Exploit
What is the chance that someone or something might take advantage of that weakness to cause damage?
Vulnerability
Threat
Risk
Attack Vector
The person or thing causing the threat is called a/an:
Attack vector
Vulnerability actor
Risk agent
Threat actor
What is the process of spotting possible problems (like weaknesses or threats), figuring out how serious they are, and deciding how to deal with them?
Security Audit
Posture Assessment
Process Assessment
Risk Management
Improving a system's security is called:
Hardening
Compliance
Assessment
Auditing
Which of the following is any data that can identify a person-like their name, ID number, phone number, or address?
Confidential Information
Personal Information
Sensitive Data
Personally Identifiable Information (PII)
The General Data Protection Regulation (GDPR) is a privacy law from which region?
United States
European Union
Asia
Australia
What is the term for protecting data by making sure only the right people or systems can read it?
Access Control
Encryption
Hashing
Logical Security
Which type of algorithm changes readable text (called plaintext) into unreadable code (called ciphertext), requiring a special key to change it back?
Hash algorithm
Encryption algorithm
Decoding algorithm
Compression algorithm
What is data that is saved and not currently moving anywhere, such as on a hard drive, SSD, USB flash drive, or cloud storage?
Data in use
Data at rest
Data in transit
Data in motion
What is the actual method or code that a hacker uses to take advantage of that weakness?
Vulnerability
Threat
Risk
Exploit
A special kind of weakness that no one (not even the software developer) knows about yet is called a:
Known vulnerability
Zero-day vulnerability
Undetected threat
Hidden exploit
What type of threat comes from someone outside the organization who doesn't have login access?
Internal threat
Accidental threat
Malicious insider
External threat
What is the term for when an attacker pretends to be someone or something else?
Phishing
Spoofing
Malware
Denial of Service
Which type of attack involves an attacker trying to break or block a service so that normal users can't use it, often by overloading the system?
Malware attack
Spoofing attack
Footprinting attack
Denial of Service (DoS) attack
What is a large group of computers that have been secretly taken over by a hacker and controlled from a central point?
Trojan network
Zombie farm
Botnet
Virus collective
Which type of malware attaches itself to files and spreads when the file is opened?
Worm
Trojan
Virus
PUP
What is an attack where a hacker secretly places themselves between two devices (like your computer and a server) during a conversation?
DoS attack
Spoofing attack
On-path attack
VLAN hopping attack
What attack involves sending out fake messages that pretend to come from a trusted device-like the router-to trick other computers into sending their traffic to the hacker's device instead?
MAC spoofing
IP spoofing
DNS spoofing
ARP spoofing (ARP poisoning)
What attack targets a switch by sending a massive amount of fake data using random, made-up MAC addresses to fill up its MAC address table?
MAC flooding
VLAN hopping
ARP poisoning
DNS poisoning
Which type of attack involves a hacker tricking the network into letting their device talk to VLANs they shouldn’t have access to, sometimes by using a double-tagged frame?
ARP spoofing attack
VLAN hopping attack
MAC flooding attack
DNS attack
What is any device or service connected to your network without the IT department’s permission?
Authorized device
Rogue device or service
Managed service
Shadow IT (only if accidental)
What happens when there’s an unauthorized or fake DHCP server on the network?
Rogue DHCP
IP spoofing
DNS poisoning
MAC flooding
What type of attack targets the system that helps devices translate website names (like google.com) into IP addresses they can actually connect to?
ARP attack
DHCP attack
DNS attack
MAC attack
What is the social engineering trick where an attacker pretends to be someone trustworthy-often using fake emails or websites-to fool someone into doing something dangerous, like downloading a virus or giving away their password?
Impersonation
Phishing
Baiting
Quid pro quo
Which of the following is an example of an external threat?
A hacker using malware.
What is the primary goal of footprinting and fingerprinting attacks?
To overload the network.
To steal login credentials directly.
To gather information about a network before launching a bigger attack.
To install malware on target systems.
What is it called when attackers register fake websites with names similar to real ones (like [suspicious link removed] instead of google.com)?
Which term refers to data that is currently being used by a device, meaning it’s temporarily held in the computer’s memory (RAM or CPU)?
Data in transit
Data in transit
Data in storage
Data in use
Confidentiality means that everyone should be able to see the information.
Integrity means the information must stay the way it was meant to be, without unauthorized changes.
False
True
Risk is how likely it is that a threat will actually happen and how bad the damage would be.
True
False
Security policies are rules that make sure risks are known and steps (called security controls) are in place to reduce those risks.
True
False
It is always a good idea to fix every possible security risk regardless of cost.
A Mission Essential Function (MEF) is something a business cannot stop doing-even for a short time.
True
Regulatory compliance is about what the law requires, whereas internal audits are about what the company thinks is important.
False
True
Data sovereignty is when a country says that certain data-like personal info-must stay within that country's borders.
True
False
Encryption is a type of physical security.
True
You can turn a hash back into the original text.
Data in transit is data that is saved and not currently moving anywhere.
An exploit is like a broken lock, and a vulnerability is the trick someone uses to open that broken lock.
False
Reputational threat intelligence is written information explaining how attacks happen.
True
False
Social engineering involves hacking a computer rather than tricking a human.
A worm requires a user to open a file to spread.
False
True
Trojans are programs that ask for permission before installing hidden malware.
In MAC spoofing, hackers fake MAC addresses to sneak past security rules.
Yes, MAC spoofing is a technique used by hackers to fake MAC addresses and bypass security rules.
ARP (Address Resolution Protocol) has strong built-in security checks.
If a MAC flooding attack is successful, a switch starts sending traffic out to all ports like a hub.
False, the switch drops all incoming traffic completely.
True, the switch behaves like a hub, broadcasting traffic to all ports.
Shadow IT devices are always set up with malicious intent.
Typosquatting is a common threat in private networks.
DNS client cache poisoning affects only one computer's stored IP addresses.
DNS server cache poisoning affects all users who use that server if successful.
The CIA triad stands for (a) , Integrity, and Availability.
The method a threat actor uses to attack is called the (a) .
A posture assessment uses the chosen framework to check how advanced or (a) a company is in applying security policies and tools.
Data locality means that where data is (a) and processed matters, especially because different countries have different rules about privacy and data protection.
(a) algorithms turn any size of text into a fixed-length code and are used to check data integrity.
Data in (a) (also called data in motion) is data that is moving across a network.
