NEW
Font size
WorksheetsModule 02: Personal Cybersecurity
Total questions: 52
Worksheet time: 26hrs 0mins
Indicate whether the statement is true or false. 1. Security questions should be answered with a fictious answer instead of the accurate answer.
True
False
Indicate whether the statement is true or false. 2. Virtually anyone could type in a person's username and pretend to be that person.
True
False
Indicate whether the statement is true or false. 3. Passwords are still considered a strong defense against attackers.
True
False
Indicate whether the statement is true or false. 4. FACTA grants consumers the right to request one free credit report from each of the three national credit-reporting firms every 12 months.
True
False
Indicate whether the statement is true or false. 5. The weakness of passwords centers on human memory.
True
False
Indicate whether the statement is true or false. 6. When creating passwords, the most important principle is that length is more important than complexity.
True
False
Indicate whether the statement is true or false. 7. Impersonation is a technique used in social engineering.
True
False
What is it called if a user misspells the URL or uses the incorrect domain and is sent to a fake look-alike site?
pharming
phishing
polling
typo squatting
Which security technique requires an authorization by what the user knows and what the user has?
special email account
two-factor authorization
biometrics
social networking
What type of attack continuously enters different passwords against the same account?
Brute force attack
Phishing attack
Man-in-the-middle attack
Denial of Service attack
What popular online activity involves allowing users to stay connected with friends, family, and peers?
affiliate marketing
affiliate networking
social networking
social marketing
With which type of social engineering attack are users asked to respond to an email or are directed to a website where they are requested to update personal information, such as passwords or credit card numbers?
pharming
typo squatting
phishing
pretexting
The built-in security function of all password managers is known as ____________________?
two-factor authentication
biometrics
vault
random password generator
Using which social engineering principle might an attacker impersonate a CEO of a company?
scarcity
authority
urgency
trust
What law contains rules regarding consumer privacy?
Credit and Transactions Act
Fair and Accurate Credit Transactions Act
Fair Credit Reporting Act
Accurate Transactions Act
In the United States, if a consumer finds a problem on their credit report, they must first send a letter to the credit-reporting agency. Under federal law, how many days does the agency have to investigate and respond to the alleged inaccuracy and issue a corrected report?
15
30
45
60
What type of attack is when a small number of common passwords are used to attempt to log in to multiple user accounts?
password cracking
typo squatting
password spraying
social networking
Which of the following is an alternate method instead of passwords for authentication?
biometrics
special email account
anonymous user id
fictitious security answer
What type of program lets a user create and store multiple strong passwords in a single user database file that is protected by one strong master password?
password manager
password generator
password fault program
password vault program
What type of attack is a false warning, often contained in an email message claiming to come from the information technology (IT) department?
impersonation
authentication
hoax
revalidation
What is the special algorithm that creates a scrambled password from a user entered password?
modification
brute force
scrambled
hash
The “Consensus” principle of social engineering is exemplified by which of the following examples?
I’m the CEO calling
You know who I am
If you don’t reset my password, I’ll call your supervisor
I called last week and your colleague reset my password
How often does FACTA grant consumers the right to request one free credit report from each of the three national credit-reporting firms?
every 2 months
every 6 months
every 12 months
every 18 months
What is the best approach to establishing strong security with passwords?
Keep passwords short so you can remember them.
Use the same password for many sites.
Keep a written log of your passwords.
Use technology for managing passwords.
What type of attacker is most likely to use information you have posted about yourself on a social networking site?
identity thief
phisher
cracker
hoaxer
Which of the following involves using someone’s personal information, such as a Social Security number, to fraudulently establish bank or credit card accounts?
identity borrowing
identity theft
information theft
property theft
The most frequently attacked sector of the market by phishing schemes and attacks is ____________________?
financial
manufacturing
retail
marketing
28. Technically speaking, the process for creating a password digital representation is based on a hash algorithm, which creates a(n) _________________?
digest
encryption key
digital certificate
public key
29. ________________ may involve the use of a PC and smartphone to login to a secure system.
Two-factor authentication
Single sign-on
Password hint
Guest login
30. A(n) ________________ is a false warning, often contained in an email message claiming to come from the IT department.
hoax
phishing
malware
spam
31. One of the best tools to put people at ease for social engineering and obtaining information is ________________.
pretexting
humor
dumpster diving
shoulder surfing
32. A(n) ________________ is a unique name used for identification.
username
password
address
The steps that ensure that the individual is who they claim to be.
h. Identity fraud
a. Authentication
b. Authorization
c. Password
A password attack in which every possible combination of letters, numbers, and characters is used to match passwords in a stolen password file.
e. brute force attack
a. Phishing
b. Shoulder surfing
c. Keylogging
A secret combination of letters, numbers, and/or symbols that serves to authenticate a user by what they know.
d. Password
a. Username
b. Email address
c. Security question
Software designed to find passwords based on digests known as 'candidates'.
e. Password cracking
a. Firewall configuration
b. Data compression
c. Network sniffing
Some of the characteristics of weak passwords are:
They are short and easy to guess.
They use a mix of uppercase, lowercase, numbers, and symbols.
They are unique for every account.
They are regularly updated.
General recommendations for creating passwords include:
Using a mix of letters, numbers, and symbols
Using only your birthdate
Using the word 'password'
Using the same password for all accounts
Password cracking is accomplished by:
using various techniques to guess or decrypt passwords
creating strong passwords for users
encrypting passwords to protect them
storing passwords in a secure database
The psychological approaches used by attackers in person-to-person contact to gain the trust of the person include:
Building rapport and using social engineering techniques
Using technical hacking tools only
Relying solely on physical intimidation
Ignoring the target's emotions and behaviors
Phishing is:
a method used to trick people into giving away personal information online.
a way to improve internet speed.
a technique for creating strong passwords.
a process for encrypting emails.
Do not use passwords that consist of dictionary words or phonetic words. Do not repeat characters (xxx) or use sequences (abc, 123, qwerty). Do not use birthdays, family member names, pet names, addresses, or any personal information. Do not use short passwords. A strong password should be a minimum of 18 characters in length.
Do not use passwords that consist of dictionary words or phonetic words. Do not repeat characters (xxx) or use sequences (abc, 123, qwerty). Do not use birthdays, family member names, pet names, addresses, or any personal information. Do not use short passwords. A strong password should be a minimum of 18 characters in length.
Use passwords that are easy to remember, such as your name or birthday, and keep them short for convenience.
Repeat characters and use simple sequences like 123 or abc to make your password easier to recall.
A strong password should be a common word or phrase that you use frequently.
Password cracking works by:
Trying different combinations to guess the correct password.
Encrypting passwords to make them secure.
Storing passwords in a database.
Sending passwords over a secure connection.
Phishing is a form of social engineering that involves:
Tricking individuals into revealing sensitive information through deceptive emails or websites.
Physically stealing someone's computer to access their data.
Using strong encryption to protect sensitive information.
Developing antivirus software to prevent malware attacks.
Pretending to be somebody else in order to gain something(like money) is called:
Identity theft
Hacking
Digital asset
Malware
Which of the following is LEAST likely to indicate a phishing attack?
An email from your bank asks you to call the number on your card to verify a transaction.
An email from a merchant asks that you click on a link to reset your password.
An email from a utility company asks you to enter your date of birth and social security number for verification purposes.
An email that indicates you have won a large sum of money and asks you to enter your bank account number so that money can be transferred to you.
From: no_reply@emailinternet.chase.com
Subject: Account Status
Attention US Bank Customer,
Due to a recent security check on your account, we require you to confirm your details. Failure to do so within 24 hours will lead to account suspension. Sorry for the inconveenince.
Click here to confirm your account
Regards,
US Bank Online Customer Service
This email has been sent by US Bank.
Which of these is the best definition of Phishing?
Calling someone to create an invented situation that increases the chance they will share sensitive information with you.
Sending an email that pretends to be from a reputable company which usually has a link to click that takes you to a website that looks real but is not.
A cyber attack that redirects a user from a real URL to a website that looks real but is not.
Looking at someone entering their personal data into a system and copying what you see.
