WorksheetsIT3101-IAS-PLE
Total questions: 50
Worksheet time: 25mins
An attacker modifies financial records to insert fraudulent transactions. Which triad(s) were directly violated?
CIA – Availability only
CIA – Confidentiality and Integrity
CIA – Integrity only
DAD – Denial and Disclosure
After a flood destroyed its primary data center, a company relied on its secondary backup facility to restore operations. Which CIA principle was preserved by this action?
Confidentiality
Integrity
Availability
Nonrepudiation
An organization sets up security policies requiring all employees to attend annual cybersecurity awareness training. What type of control is this?
Technical Control
Operational Control
Managerial Control
Physical Control
A company applies data masking to display only the last four digits of customer credit card numbers. What is the main objective of this technique?
Prevent unauthorized access to entire data
Destroy unnecessary data
Replace sensitive values with random tokens
Encrypt data in transmission
An attacker intercepts sensitive data being transmitted between a client and a server. Which data state was compromised?
Data in use
Data in transit
Data at rest
Data minimized
A company experiences a ransomware attack. They restore operations by using backup files. Which type of control was applied in the recovery process?
Preventive
Detective
Corrective
Directive
A power outage corrupts some stored customer files, leading to missing information in their records. This is an example of a violation of which principle?
Confidentiality
Integrity
Availability
Compliance
Which technique involves partially hiding data, such as showing only the last four digits of a credit card?
Hashing
Masking
Tokenization
Encryption
Which of the following is an operational control?
Access control lists
Biometric locks
Log monitoring
Risk assessment exercises
An organization enforces access restrictions by limiting users to login only from certain countries. What type of restriction is this?
Permission restriction
Role-based restriction
Geographic restriction
Physical restriction
Which of the following describes tokenization?
Using hash values to obscure data
Replacing sensitive values with unique identifiers
Removing all data permanently in the storage
Hiding some fields with “X” or “*”
A DLP (Data Loss Prevention) system that monitors outgoing network traffic for sensitive data is classified as:
Agent-based DLP
Agentles DLP
Masking system
Tokenization tool
A company installs a biometric lock on the data center door. This is an example of what type of control?
Technical control
Operational control
Physical control
Managerial control
Which of the following best describes the main motivation of organized crime as cyber threat actors?
Political influence
Financial gain
Proving technical skills
Revenge
Which threat actor is most likely to carry out a zero-day attack using custom research labs?
Script kiddies attackers
Hacktivists attackers
Nation-state attackers
Insider attackers
Which of the following scenarios best illustrates a hacktivist motivation?
Launching ransomware for quick profit
Defacing a government website to protest policy
Exploiting zero-day vulnerabilities for espionage
Selling stolen credit cards on the dark web
A disgruntled employee steals sensitive data after being denied a promotion. This is an example of:
Competitor attack
Nation-state threat
Insider threat
Shadow IT
Which hacker “hat” type describes someone who identifies vulnerabilities without authorization but later reports them?
White hat
Black hat
Gray hat
Blue hat
An attacker drops infected USB drives in a company’s parking lot. Which threat vector is being exploited?
Cloud computing
Removable devices
Message-based
upply chain
A phishing email that tricks users into entering login details into a fake website is an example of:
Wired network attack
Message-based attack
Shadow IT risk
System misconfiguration
A poorly secured Wi-Fi network allows outsiders to connect from the parking lot. This is an example of:
Wireless network threat
Supply chain vulnerability
Physical network breach
Cloud-based attack
Which of the following best explains why shadow IT is risky?
It always involves malicious insiders activity
It introduces technology outside of official security controls
t is performed by competitors to steal data in an organization
It is required for faster software updates and system performace
A nation-state group that compromises power grid systems during conflict is most likely motivated by:
Service disruption and political gain
Quick financial profit
Demonstrating security network technical skills
Revenge against competitors
A company has strong antivirus protection, but users still report sudden file encryption with ransom notes displayed.
Which security control likely failed, and what alternative mitigation could have minimized the damage?
Firewall filtering – stronger intrusion prevention
Backup strategy – maintaining offline and immutable backups
Patch management – enforcing stricter update schedules
User account control – stricter privilege management
A security analyst detects unusual outbound traffic from multiple systems. The traffic is directed toward known malicious IPs, but no files on the systems match antivirus signatures. Which malware type is most likely responsible?
Worm
Virus
Bloatware
Logic bomb
An employee downloads a “free PDF editor” that later starts enrolling the device into paid subscription services without consent. What best identifies this malware?
Spyware
Keylogger
Trojan
Ransomware
Which malware type poses the greatest threat if a company relies heavily on online transactions but uses strong file backups?
Ransomware
Worms
Spyware
Viruses
A company discovers a malicious script embedded inside payroll software, designed to activate on the last Friday of every month. Which malware type does this represent?
Logic bomb
Worm
Keylogger
Rootkit
Which malware would be most effective for attackers who want long-term, stealthy access to a corporate server without triggering detection?
Ransomware
Worm
Rootkit
Virus
A system administrator observes a suspicious process imitating “explorer.exe” that sends keystroke data to a remote server. Which two malware types could explain this behavior?
Keylogger and Spyware
Virus and Worm
Logic bomb and Trojan
Ransomware and Bloatware
If a worm infection spreads via IoT devices and USB drives, which layered defense strategy would be most effective in prevention?
Stronger user awareness training
Limiting software installation permissions
Network segmentation and patch management
Restoring from backups
A newly hired IT technician claims that pre-installed “manufacturer software” isn’t dangerous because it isn’t malware. From a cybersecurity perspective, why is this reasoning flawed?
Bloatware is legally malware
Bloatware is harmless but consumes resources
Bloatware may be exploited and increase attack surface
Bloatware is always a safe spyware integrates by the manufacturer
Statement A: Ransomware often uses phishing emails as the initial infection vector.
Statement B: The only way to recover from ransomware is by paying the ransom.
Statement A is correct
Statement B is correct
Both statements are correct
Both statements are incorrect
Statement A: Bloatware is intentionally designed to damage a computer system.
Statement B: Bloatware may not be malicious but can consume system resources and increase vulnerabilities.
Statement A is correct
Statement B is correct
Both statements are correct
Both statements are incorrect
Statement A: Viruses need a host file or program to spread.
Statement B: Viruses can remain dormant until triggered by specific conditions.
Statement A is correct
Statement B is correct
Both statements are correct
Both statements are incorrect
Statement A: Threat intelligence feeds can include details such as MAC addresses, file hashes, and URLs.
Statement B: Using only one threat intelligence feed is always sufficient to stay updated on emerging threats.
Statement A is correct
Statement B is correct
Both statements are correct
Both statements are incorrect
Which type of hacker is authorized to test systems?
Black-hat hacker
White-hat hackeR
Gray-hat hacker
Script kiddie
Insiders pose a risk because they:
Have authorized access
Use phishing emails
Exploit software flaws
Hack for fun
Which type of threat actor is motivated by financial gain?
Nation-state
Hacktivist
Cybercriminal
White-hat hacker
Cyberterrorists aim to:
Spread malware for fun
Cause fear and disruption
Test security systems
Monitor browsing
Which of the following reduces the attack surface?
Applying patches
Ignoring updates
Sharing passwords
Disabling firewalls
Clicking a fake login page is an example of:
Social engineering
Hardware attack
Software update
Firewall defense
Email viruses usually spread through:
Attachments
Firewalls
Rootkits
Updates
A simple way to remove bloatware is to:
Uninstall it
Encrypt it
Hide it
Spread it
Adding fraudulent transactions to a financial record is an example of:
Disclosure
Denial
Alteration
Masking
Which term describes stored data on hard drives, tapes, or cloud?
Data in transit
Data at rest
Data in use
Data in motion
Which technique transforms data so the original cannot be retrieved?
Tokenization
Masking
Obfuscation
Hashing
Which technique completely cuts off a system from external networks?
Segmentation
Isolation
Obfuscation
Data minimization
Which triad is most useful in identifying possible threats?
CIA triad
DAD triad
IT governance
NIST framework
Which of the following BEST protects against eavesdropping attacks on transmitted data?
Tokenization
Encryption
Masking
Obfuscation
