NEW
Font size
WorksheetsCyber II - Unit 1: Quiz 1 - Foundational Practice & Frameworks
Total questions: 25
Worksheet time: 13mins
Ethics in cybersecurity primarily ensures
Responsible use of cybersecurity skills
Higher salaries for cybersecurity professionals
Legal protection for hackers
Faster internet speeds
Ethical hacking involves illegally accessing systems.
True
False
Which organization provides ethical guidelines for cybersecurity professionals?
ISC2
ISO
FCC
NICCS
Which is NOT part of the CIA Triad?
Central
Confidentiality
Availability
Integrity
The DIE triad focuses primarily on data.
True
False
The concept "Immutable Infrastructure" means:
Systems cannot be changed once deployed
Data can be altered easily
Data must always be available
Infrastructure changes daily
Which is NOT a function of the NIST Cybersecurity Framework (CSF)?
Back-up
Respond
Identify
Detect
The NIST Risk Management Framework (RMF) is only used by federal agencies.
True
False
ISO 27001 primarily:
Provides international security standards
Focuses on financial data
Is a general cybersecurity framework
Only applies to small businesses
GDPR stands for:
General Data Protection Regulation
General Department Privacy Regulation
Government Data Privacy Rule
General Data Protection Responsibility
Regulated data includes passport numbers.
True
False
PCI-DSS regulates:
Credit card transactions
Health records
Email communications
Public databases
Which term describes the commitment to protect society, uphold trust, act honorably, and always prioritize the public good while using knowledge and resources responsibly?
Integrity
Availability
Confidentiality
Cybersecurity ethics
What is a set of rules that limits access to information?
Framework
Regulated data
Confidentiality
Cybersecurity ethics
What is the assurance that the information is trustworthy and accurate?
Availability
Ephemerality
Immutability
Integrity
What is the guarantee of reliable access to the information by authorized people?
Availability
Integrity
Confidentiality
Framework
What is a three-part model designed to guide how infrastructure should be designed to limit the attack surface for an organization?
CIA Triad
DAD Triad
NIST
DIE Triad
What is a three-part model designed to assist cybersecurity experts when analyzing risk and is made to directly counter the CIA Triad?
DIE Triad
CIA Triad
DAD Triad
NIST
What is private business information that provides a competitive edge?
Intellectual property data
Legal information data
Financial data
Trade secret data
What is the process of categorizing data based on sensitivity and security needs?
Data classification
Tokenization
Obfuscation
Encryption
What is making data unreadable without special knowledge or tools?
Tokenization
Hashing
Encryption
Obfuscation
A cybersecurity professional discovers a critical vulnerability in a company's software that could be exploited by a competitor to steal trade secrets. The professional is offered a large sum of money to sell the exploit on the black market. Which principle is most critical for the professional to uphold in this scenario?
Confidentiality
Integrity
Cybersecurity ethics
Availability
How do the CIA and DIE triads work together in a complementary way?
The CIA Triad focuses on physical security, while the DIE Triad focuses on digital security.
The CIA Triad is for government systems, and the DIE Triad is for private sector systems.
The CIA Triad focuses on protecting data, while the DIE Triad focuses on building infrastructure to enhance that protection.
he CIA Triad is a modern framework, and the DIE Triad is a legacy framework.
According to the NIST Cybersecurity Framework (CSF), which of the following is a primary step to take after detecting a cybersecurity incident?
Identify
Protect
Respond
Recover
How do regulations like GDPR and HIPAA primarily impact data management in organizations?
They mandate that all data must be encrypted to a specific standard.
They require organizations to perform a full system audit once a month.
They enforce strict rules on how sensitive data is collected, stored, and used, which can be categorized as a type of "regulated data."
They allow organizations to sell user data, provided they inform the user first.
