wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Cybersecurity Fundamentals Quiz

Total questions: 95

Worksheet time: 48mins

Name
Class
Date
1.

What is the core aim of cybersecurity, according to the sources?

a)

To enhance digital marketing strategies and online presence.

b)

To address the risks and vulnerabilities associated with digital systems and networks.

c)

To develop new hardware and software for information systems.

d)

To solely prevent harm caused intentionally by system operators.

2.

Which of the following best describes the principle of "defense in depth" in cybersecurity?

a)

Implementing a single, highly secure measure to protect against all threats.

b)

Focusing only on physical security controls for digital assets.

c)

Implementing multiple layers of security controls to protect against a wide range of cyber threats.

d)

Relying solely on advanced technological safeguards without human intervention.

3.

According to the sources, what does risk management in cybersecurity primarily involve?

a)

Eliminating all potential threats and vulnerabilities entirely.

b)

Prioritizing cybersecurity efforts based on the likelihood and potential impact of threats, and business objectives.

c)

Outsourcing all security responsibilities to third-party vendors.

d)

Focusing exclusively on technical vulnerabilities within digital systems.

4.

Which of the following is NOT listed as a non-technical aspect of cybersecurity?

a)

Security awareness training.

b)

Incident response planning.

c)

Regulatory compliance.

d)

Network intrusion detection systems.

5.

Why is "Protection of Sensitive Data" paramount in information management, according to the sources?

a)

It reduces the need for data backups.

b)

It allows for easier data sharing with unauthorized entities.

c)

It safeguards vast amounts of sensitive data, including PII and intellectual property, from unauthorized access and theft.

d)

It simplifies regulatory compliance by eliminating security measures.

6.

Which cybersecurity measure helps in "Preservation of Integrity" of data?

a)

Distributed Denial of Service (DDoS) protection.

b)

Encryption and access controls.

c)

Digital signatures, cryptographic hashing, and integrity monitoring tools.

d)

Disaster recovery planning.

7.

What is one of the financial consequences of cybersecurity incidents for organizations?

a)

Increased customer loyalty and brand reputation.

b)

Significant financial losses including legal fees, regulatory fines, and loss of business.

c)

Reduced need for security investments.

d)

Improved operational efficiency due to forced system upgrades.

8.

What is one of the learning outcomes for students completing the cybersecurity fundamentals course regarding cybersecurity principles?

a)

Developing advanced hacking techniques.

b)

Gaining a comprehensive understanding of the CIA triad, risk management, and defense in depth.

c)

Becoming proficient in coding security software.

d)

Specializing in a single cybersecurity technology.

9.

Which regulatory compliance standard is mentioned in the learning outcomes as applicable to data protection and privacy?

a)

ISO 9001.

b)

Payment Card Industry Data Security Standard (PCI DSS).

c)

Sarbanes-Oxley Act (SOX).

d)

California Consumer Privacy Act (CCPA).

10.

What is a strategic objective of the course related to the ENISA strategy?

a)

To promote cybersecurity as a fundamental right.

b)

To develop proprietary cybersecurity technologies for the EU.

c)

To centralize all cybersecurity operations within ENISA.

d)

To eliminate all cyber threats globally.

11.

How does the ENISA New Strategy align with Nova's Master's program in Information Management?

a)

It replaces the need for practical cybersecurity studies.

b)

It provides a theoretical framework without practical implications.

c)

It deepens understanding of cybersecurity and aligns with the real-life and business-oriented focus of studies.

d)

It focuses solely on technical aspects, disregarding policy frameworks.

12.

The course is grounded in which cybersecurity framework and follows the guidelines of which strategy?

a)

ISO 27001 and GDPR.

b)

NIST Cybersecurity Framework and ENISA's New Strategy towards a Trusted and Cyber Secure Europe.

c)

OWASP Top 10 and HIPAA.

d)

CIS Controls and CCPA.

13.

Which NIST Cybersecurity Framework function focuses on preventing cyber threats from compromising systems and data?

a)

Identify.

b)

Protect.

c)

Detect.

d)

Respond.

14.

What is the primary reason the NIST Cybersecurity Framework is important for a Cybersecurity Fundamentals course?

a)

It is a mandatory regulation for all organizations.

b)

It provides a comprehensive, yet flexible framework for managing cybersecurity risks and is widely recognized.

c)

It focuses exclusively on advanced technical cybersecurity concepts.

d)

It simplifies cybersecurity to only essential measures.

15.

According to the Kill Chain principle, what is the stage where an attacker collects information about the target system and its vulnerabilities?

a)

Weaponization.

b)

Delivery.

c)

Reconnaissance.

d)

Exploitation.

16.

How long do hackers frequently spend inside an environment, on average, before fully executing a hack?

a)

Less than 50 days.

b)

100-140 days.

c)

Over 300 days.

d)

Only a few hours.

17.

Which malicious activity are botnets NOT commonly used for?

a)

Distributed denial-of-service (DDoS) attacks.

b)

Sending spam emails.

c)

Chatroom management for policy enforcement.

d)

Stealing data.

18.

Which skill or mindset is characteristic of many successful hackers, according to the sources?

a)

Strict adherence to established procedures.

b)

Aversion to risk-taking.

c)

Creative problem-solving.

d)

Disregard for technical expertise.

19.

What do hackers often recognize as "the weakest link in the chain"?

a)

Advanced encryption algorithms.

b)

Hardware vulnerabilities.

c)

Humans.

d)

Network infrastructure.

20.

What is the main purpose of incorporating practical demonstrations into the cybersecurity foundations course for Master's students?

a)

To replace theoretical learning entirely.

b)

To provide students with hands-on experience in cybersecurity tools and techniques and bridge theory with practical application.

c)

To exclusively focus on defensive measures without addressing offensive mindsets.

d)

To prepare students only for certifications, not real-world scenarios.

21.

According to the UK government's definition, what does cybersecurity primarily refer to?

a)

The protection of physical documents from harm or misuse.

b)

The protection of information systems, data, and services from unauthorized access, harm, or misuse.

c)

The development of new software and hardware for computing.

d)

The legal framework governing internet usage.

22.

The Cybersecurity Body of Knowledge (CyBOK) is divided into how many top-level Knowledge Areas (KAs)?

a)

5.

b)

10.

c)

21.

d)

30.

23.

What is a crucial element arguably still missing from the UK government's cybersecurity definition?

a)

A mention of specific hardware components.

b)

The impact of information loss or reduced safety on human behaviors, or how security/privacy breaches impact trust.

c)

Details about network protocols.

d)

Reference to historical cybersecurity incidents.

24.

Information Security is widely regarded as comprised of three main elements. Which of the following is NOT explicitly one of them, according to ISO 27000 definition?

a)

Confidentiality.

b)

Integrity.

c)

Authentication.

d)

Availability.

25.

Which of the following is an example of a Cyber-Physical System (CPS)?

a)

A standalone desktop computer.

b)

An industrial control system.

c)

A traditional paper filing system.

d)

A simple calculator.

26.

What is Cyberspace best understood as, according to the sources?

a)

A physical location where computers are stored.

b)

A "place" where business is conducted, human communications take place, and art is made.

c)

A specific type of network protocol.

d)

A programming language for secure systems.

27.

Who coined the term "cyberspace" for "widespread, interconnected digital technology"?

a)

Claude Shannon.

b)

William Gibson.

c)

Jerome Saltzer.

d)

Auguste Kerckhoffs.

28.

In cybersecurity, controls are often expressed in terms of affecting which three aspects?

a)

Speed, cost, and efficiency.

b)

Prevention, detection, and reaction.

c)

People, process, and technology.

d)

Hardware, software, and data.

29.

What does the "Precautionary Principle" in security design imply for designers of large-scale connected systems?

a)

They should only consider security implications after deployment.

b)

They must consider security and privacy implications from conception through decommissioning.

c)

They should prioritize innovation over security concerns.

d)

They should only address security concerns when a breach occurs.

30.

What is the high-level design of a system from a security perspective called?

a)

Security Implementation.

b)

Security Architecture.

c)

Security Policy.

d)

Security Assurance.

31.

Which of the following is NOT one of the key security requirements of the CIA triad?

a)

Confidentiality.

b)

Identification.

c)

Integrity.

d)

Availability.

32.

What does "Data confidentiality" assure?

a)

That data is accurate and reliable.

b)

That private or confidential information is not made available or disclosed to unauthorized individuals.

c)

That data is always accessible to authorized users.

d)

That data is changed only in a specified and authorized manner.

33.

One of the challenges of computer security is that successful attacks are often designed by exploiting what?

a)

Obvious and well-known weaknesses.

b)

Unexpected weaknesses by looking at the problem in a completely different way.

c)

The absence of any security mechanisms.

d)

Simple brute-force methods only.

34.

Which characteristic describes a 'Threat' in computer security terminology?

a)

A flaw or weakness in a system's design.

b)

An action, device, or procedure that reduces a vulnerability.

c)

A potential for violation of security, existing when there is a circumstance or event that could breach security and cause harm.

d)

A set of rules that specify how a system provides security services.

35.

What is a 'Vulnerability' defined as in computer security?

a)

An intelligent act to evade security services.

b)

A potential for security violation.

c)

A flaw or weakness in a system’s design, implementation, or operation that could be exploited.

d)

A measure of expected loss.

36.

What is the primary characteristic of a 'Passive Attack'?

a)

It alters system resources or affects their operation.

b)

It involves eavesdropping or monitoring transmissions to learn information without affecting system resources.

c)

It creates a false data stream.

d)

It is easily detectable by the system.

37.

Which of Saltzer and Schröder’s design principles states that 'the design of security measures embodied in both hardware and software should be as simple and small as possible'?

a)

Fail-safe defaults.

b)

Complete mediation.

c)

Open design.

d)

Economy of mechanism.

38.

The principle of 'Psychological acceptability' implies what regarding security mechanisms?

a)

They should be overly complex to deter attackers.

b)

They should significantly interfere with user work to ensure maximum security.

c)

They should not interfere unduly with the work of users and meet the needs of those who authorize access.

d)

They should only be implemented by security experts, not users.

39.

What is the purpose of 'Layering' as a contemporary security design principle?

a)

To replace all other security principles.

b)

To use multiple, overlapping protection approaches so that the failure of one does not leave the system unprotected.

c)

To centralize all security controls in a single layer.

d)

To reduce the number of security controls needed.

40.

Which of the following is NOT one of the three aspects of a comprehensive security strategy?

a)

Specification/policy.

b)

Marketing/branding.

c)

Implementation/mechanisms.

d)

Correctness/assurance.

41.

What is a network sniffer primarily used for?

a)

To block all network traffic automatically.

b)

To encrypt data packets before transmission.

c)

To capture and analyze network traffic.

d)

To establish VPN connections.

42.

Which of the following is a legitimate purpose for using packet sniffing?

a)

Injecting malicious programs or viruses into a segment.

b)

Spying on businesses to steal confidential data.

c)

Identifying problems within the network and troubleshooting them.

d)

Monitoring someone’s online behavior for unethical purposes.

43.

How do hackers commonly place sniffers at unsecured Wi-Fi hotspots?

a)

By physically installing hardware on the router.

b)

By setting up fake hotspots to intercept unencrypted passwords and usernames.

c)

By directly connecting to the hotspot's server.

d)

By sending encrypted signals to the hotspot.

44.

What is the difference between Active Sniffing and Passive Sniffing?

a)

Active sniffing targets unbridged networks, while passive sniffing targets point-to-point networks.

b)

Active sniffing actively injects additional traffic into the LAN, while passive sniffing is inserted into a hub and waits for data.

c)

Passive sniffing is illegal, while active sniffing is ethical.

d)

Active sniffing only captures encrypted data, while passive sniffing captures all data.

45.

What is 'Password sniffing' a type of cyber-attack that commonly occurs on public Wi-Fi networks?

a)

It encrypts passwords to make them more secure.

b)

It monitors a victim’s connection to a remote database to obtain their password.

c)

It creates strong passwords for users automatically.

d)

It only targets encrypted communications.

46.

Which type of sniffing attack takes over a web user session by secretly collecting the session ID and masquerading as the authorized user?

a)

DNS poisoning.

b)

JavaScript card sniffing.

c)

TCP session hijacking.

d)

Address resolution protocol (ARP) sniffing.

47.

What is the main goal of 'DNS poisoning'?

a)

To encrypt DNS queries for enhanced security.

b)

To redirect internet traffic to phishing websites or phony web servers.

c)

To optimize DNS server performance.

d)

To monitor DNS traffic for legitimate purposes.

48.

What distinguishes 'JavaScript card sniffing attacks' from 'Foam Jacking'?

a)

JavaScript card sniffing targets any online form, while Foam Jacking targets payment forms.

b)

JavaScript card sniffing targets online store payment forms specifically, while Foam Jacking attacks any type of information in any online form.

c)

Foam Jacking relies on malicious JavaScript, but JavaScript card sniffing does not.

d)

JavaScript card sniffing is a physical attack, while Foam Jacking is digital.

49.

What is the purpose of Address Resolution Protocol (ARP) sniffing, also known as ARP spoofing?

a)

To convert MAC addresses to IP addresses.

b)

To reroute traffic away from their intended destination and towards an attacker.

c)

To secure ARP communication.

d)

To discover legitimate MAC addresses on a network.

50.

Which example of a packet sniffing attack involved exploiting a computer vulnerability developed by the United States National Security Agency (NSA)?

a)

BIPASS RAT and Cobalt Strike.

b)

Hacking Wi-Fi networks using PMKID.

c)

The history-sniffing attack.

d)

Password sniffing cyberattack involving EternalBlue exploit.

51.

One key way to protect against sniffing attacks is to 'Avoid using unsecured networks.' Why?

a)

Unsecured networks are always faster.

b)

Unsecured networks lack firewall protection and antivirus software, making information unencrypted and easy to access.

c)

Unsecured networks only transmit encrypted data.

d)

Unsecured networks are not vulnerable to Man-in-the-Middle (MITM) attacks.

52.

How does using a Virtual Private Network (VPN) help prevent sniffer attempts?

a)

It creates a direct, unencrypted connection to the internet.

b)

It allows sniffers to monitor all traffic easily.

c)

It encrypts all incoming and outgoing communication, making it difficult for spies or sniffers to see traffic.

d)

It only protects against passive sniffing.

53.

Which type of protocol should users prefer to avoid packet sniffing, indicated by the 's' in its name?

a)

HTTP.

b)

FTP.

c)

HTTPS.

d)

SMTP.

54.

What is a 'sniffer detection application' primarily designed to do?

a)

Inject sniffers onto a network.

b)

Detect and preempt sniffing attacks before they cause damage.

c)

Increase network congestion for analysis.

d)

Encrypt all network traffic automatically.

55.

Which tool is a free and open-source network protocol analyzer used for troubleshooting, analysis, development, and education?

a)

Nmap.

b)

Anti-Sniff.

c)

Wireshark.

d)

Snort.

56.

Why is Wireshark considered important for applied security and ethical hacking?

a)

It simplifies network configuration.

b)

It provides insights into network traffic and helps identify security threats, vulnerabilities, and misconfigurations.

c)

It automatically blocks all malicious network traffic.

d)

It only works on encrypted networks.

57.

What is one of the key features of Wireshark's capabilities?

a)

Automated penetration testing.

b)

Deep Inspection, dissecting and displaying details for hundreds of protocols.

c)

Malware removal.

d)

Hardware diagnostics.

58.

Which component is required for packet capturing when installing Wireshark on Windows?

a)

Java Runtime Environment (JRE).

b)

Microsoft SQL Server.

c)

Npcap.

d)

VirtualBox.

59.

What is the first step when you want to start capturing packets in Wireshark?

a)

Apply filters immediately.

b)

Select the network interface you wish to monitor and click the 'Start Capturing Packets' button.

c)

Save the capture file.

d)

Install additional plugins.

60.

Is the use of network sniffers subject to privacy and security laws?

a)

No, they can be used freely on any network.

b)

Yes, it's important to only use them under applicable laws and regulations and on networks you own or have permission to access.

c)

Only if financial information is involved.

d)

Only when used by government institutions.

61.

What is the primary difference between Wireshark 'capture filters' and 'display filters'?

a)

Capture filters modify network traffic, while display filters only show it.

b)

Capture filters limit the amount of traffic Wireshark saves to a file, while display filters narrow down displayed captured traffic.

c)

Display filters are used during live capture, while capture filters are for offline analysis.

d)

Capture filters are for IP addresses, while display filters are for protocols.

62.

Which Wireshark filter expression would display traffic involving a specific IP address, for example, 192.168.0.1?

a)

ip.addr != 192.168.0.1.

b)

ip.addr == 192.168.0.1.

c)

host 192.168.0.1.

d)

src or dst 192.168.0.1.

63.

ng a specific IP address, for example, 192.168.0.1?

a)

ip.addr != 192.168.0.1.

b)

ip.addr == 192.168.0.1.

c)

host 192.168.0.1.

d)

src or dst 192.168.0.1.

64.

To display all TCP SYN/ACK packets, which filter expression should be used?

a)

tcp.flags.syn==1 && tcp.flags.ack==1.

b)

tcp.flags == 0x012.

c)

tcp.port == 80.

d)

tcp.analysis.flags.

65.

How would you apply a filter in Wireshark to display only packets to and from any address in the 10.0.0.0/24 network space?

a)

ip.src == 10.0.0.0/24.

b)

ip.dst == 10.0.0.0/24.

c)

ip.addr == 10.0.0.0/24.

d)

ip.network == 10.0.0.0/24.

66.

Which Wireshark filter is useful for searching on a specific string or user ID within packets?

a)

tcp.port.

b)

frame contains [string].

c)

ip.proto.

d)

tcp.time_delta.

67.

What does the filter !(arp or icmp or stp) achieve in Wireshark?

a)

It displays only ARP, ICMP, and STP packets.

b)

It displays all packets that contain ARP, ICMP, or STP.

c)

It masks out (removes) ARP, ICMP, or STP packets to reduce background noise.

d)

It filters for packets that are exactly ARP, ICMP, or STP.

68.

To filter traffic based on a specific IP protocol, such as TCP or UDP, which filter expression can be used?

a)

ip.addr == [IP address].

b)

ip.proto == [protocol].

c)

ip.len > [length].

d)

tcp.port == [port number].

69.

What is the purpose of the SYN-ACK packet in the TCP handshake process?

a)

To initiate the connection request from the client.

b)

To acknowledge the SYN packet and include a random sequence number from the server.

c)

To confirm the connection request from the client.

d)

To terminate the TCP connection.

70.

Which TCP port is the default communication channel used for web traffic, allowing users to send and receive web page data using the HTTP protocol?

a)

Port 21.

b)

Port 23.

c)

Port 80.

d)

Port 443.

71.

What does an HTTP "200 OK" status code indicate?

a)

That the server encountered an error.

b)

That the requested resource was not found.

c)

That the request was successful and the requested resource is being returned.

d)

That the request is pending further action.

72.

Wireshark TCP Analysis flags like "Out-Of-Order" and "Retransmission" provide useful information primarily for what purpose?

a)

To indicate successful data transmission.

b)

To analyze and troubleshoot network issues related to TCP performance.

c)

To identify new network protocols.

d)

To verify encryption strength.

73.

What does a "Duplicate Acknowledgement" TCP flag indicate in Wireshark?

a)

A successful packet transmission.

b)

A network packet has been received out of order, causing the receiver to send an acknowledgment for the missing packet.

c)

The sender is retransmitting a packet unnecessarily.

d)

The connection has been closed.

74.

To remove ICMP, DNS, and ARP protocols from a Wireshark display, which filter expression can be used?

a)

(icmp and dns and arp).

b)

icmp or dns or arp.

c)

!(icmp or dns or arp).

d)

not (icmp, dns, arp).

75.

What is the "Follow TCP Stream" feature in Wireshark used for?

a)

To filter packets based on specific keywords.

b)

To reconstruct and view the entire data exchange between two network devices in a specific TCP conversation.

c)

To generate new TCP packets for testing.

d)

To analyze only the header information of TCP packets.

76.

The "TCP contains" filter in Wireshark allows you to search for what?

a)

Only the source and destination IP addresses in a TCP packet.

b)

Packets containing specific data within the payload of a TCP packet.

c)

The TCP handshake sequence numbers.

d)

All encrypted TCP traffic.

77.

An SYN attack (SYN flood) is a type of Denial-of-Service (DoS) attack that exploits what aspect of the TCP/IP protocol?

a)

The process of data encryption.

b)

The three-way handshake, by sending many SYN requests without completing the connection.

c)

The ability to send large files quickly.

d)

The functionality of UDP packets.

78.

Which filter expression in Wireshark would you use to discover SYN attacks by looking for packets with the SYN flag set and the ACK flag unset?

a)

tcp.flags.syn==1.

b)

tcp.flags.ack==0.

c)

tcp.flags.syn==1 && tcp.flags.ack==0.

d)

tcp.flags == SYN.

79.

Which of the following is NOT listed as a common form of Denial of Service (DoS) attacks?

a)

Network flood attacks.

b)

Application-layer attacks.

c)

Distributed Denial of Service (DDoS) attacks.

d)

Data exfiltration attacks.

80.

What is the primary characteristic of a Distributed Denial-of-Service (DDoS) attack?

a)

A single attacker overwhelming a server from one location.

b)

Multiple attackers or compromised devices overwhelming a target with fraudulent traffic until it becomes unresponsive.

c)

An attack that targets unencrypted data streams only.

d)

An attack that aims to steal sensitive data.

81.

Which of these is a described symptom of a DDoS attack?

a)

A steady, consistent flow of traffic from diverse sources.

b)

An exponential, unexpected rise in traffic at a single endpoint/server.

c)

The server continuously generating new logs without issues.

d)

Your website responding faster than usual.

82.

What is recommended for a strong password, according to the sources?

a)

It should be at least 6 characters long and easy to remember.

b)

It should be at least 12 characters long and include a mix of uppercase and lowercase letters, numbers, and symbols.

c)

It should be a common word or phrase.

d)

It should be updated once a year.

83.

Which new trend in password management involves eliminating passwords entirely and using alternative authentication methods like biometrics?

a)

Multifactor authentication (MFA).

b)

Single sign-on (SSO).

c)

Passwordless authentication.

d)

Zero-knowledge password management.

84.

How can passwordless authentication be implemented using a "magic link"?

a)

By requiring a user to enter a one-time code from an SMS.

b)

By sending an email with a URL containing a unique token that verifies the user when clicked.

c)

By asking the user for their fingerprint directly.

d)

By providing a hardware token to the user.

85.

Multi-factor authentication (MFA) involves requiring users to provide additional authentication factors. Which of these is an example of "what a user knows"?

a)

An ID card.

b)

Biometric data like a fingerprint.

c)

A user's login ID and password combination.

d)

A hardware token.

86.

What is a significant advantage of SMS 2FA?

a)

It is highly resistant to SIM swapping attacks.

b)

It is the most secure MFA alternative available.

c)

It works offline, as it does not require the phone to be online.

d)

It is the most cost-effective method for authentication.

87.

Which of the following is listed as a disadvantage of SMS 2FA?

a)

Low learning curve for users.

b)

Requires expensive smartphones.

c)

Vulnerable to SIM swapping attacks.

d)

Does not require additional hardware.

88.

What is the core distinction between "Passwords" and "Identity"?

a)

Passwords are inherent attributes, while identity is used for authentication.

b)

Passwords are a means of authentication to verify identity, while identity refers to a set of personal attributes that define who you are.

c)

They are interchangeable terms in cybersecurity.

d)

Identity is always public, while passwords are always private.

89.

What is the purpose of "Authentication" in cybersecurity?

a)

To determine if a user has necessary permissions.

b)

To define policies for identity management.

c)

To verify a user's identity to ensure they are who they claim to be.

d)

To manage user access to applications.

90.

What is "Authorization" in the context of cybersecurity?

a)

The process of verifying a user's identity.

b)

The process of determining whether a user has the necessary permissions to perform a specific action or access a particular resource.

c)

The process of creating new user accounts.

d)

The process of logging all user activities.

91.

Single Sign-On (SSO) aims to simplify password management by allowing users to do what?

a)

Use different credentials for each application.

b)

Sign in to multiple applications or services with a single set of login credentials.

c)

Manually enter passwords for each service.

d)

Bypass authentication for certain services.

92.

What is a key security risk associated with the "Centralized IM" model?

a)

Increased user control over their data.

b)

High security risk and data breaches due to centralization and fragmented identities across many enterprises.

c)

Enhanced interoperability between different entities.

d)

Reduced cost of customer services due to fewer password reset requests.

93.

Which technology has enabled the emergence of "Decentralized IM" as a disruptive innovation?

a)

Centralized Ledger Technology (CLT).

b)

Distributed Ledger Technology (DLT) and Verifiable Credentials data model.

c)

Traditional relational databases.

d)

Single Sign-On (SSO) protocols only.

94.

In the Verifiable Credentials (VCs) model, who sits at the center of the triangle of trust?

a)

The issuer.

b)

The verifier.

c)

The holder (user).

d)

The certificate authority.

95.

What is "Password cracking"?

a)

The process of creating strong, unique passwords.

b)

The process of guessing or recovering a password from a stored or transmitted password hash to gain unauthorized access.

c)

A method to encrypt sensitive data.