Font size
WorksheetsCybersecurity Vocabulary and Definitions
Total questions: 75
Worksheet time: 1hrs 15mins
Fill in the blank: ________ is a cyber-security term that refers to a flaw in a system that can leave it open to attack.
Vulnerability
Encryption
Firewall
Authentication
Fill in the blank: ________ is malware that prevents or limits users from accessing their system, either by locking the system's screen or by locking the user's files unless a ransom is paid.
Ransomware
Adware
Spyware
Rootkit
Fill in the blank: ________ is software that is hidden from the user in order to gather information about internet interaction, keystrokes, passwords, and other valuable data.
Spyware
Adware
Ransomware
Malware
Fill in the blank: ________ is designed to display advertisements on your computer and redirect your search request to advertising websites to collect marketing data about you.
Adware
Spyware
Ransomware
Rootkit
Fill in the blank: ________ is a type of surveillance technology used to monitor and record each keystroke.
Keylogger
Firewall
Antivirus
Router
Fill in the blank: ________ is a collection of tools or programs that enable administrator-level access to computer or computer network.
Rootkit
Firewall
Antivirus
Proxy
Fill in the blank: ________ is a program that claims to free your computer from viruses but instead introduces viruses onto your system.
Trojan horse
Firewall
Antivirus
Cookie
Fill in the blank: ________ is a network attack in which an unauthorized person gains access to network and stays there undetected for a long period of time.
Advanced Persistent Threat (APT)
Denial of Service (DoS)
Phishing Attack
Man-in-the-Middle Attack
Fill in the blank: ________ is the body of technologies, processes, and practices involved in protecting individuals and organizations from cyber crime.
Cyber Security
Data Mining
Cloud Computing
Web Development
Fill in the blank: ________ is any malicious act that attempts to gain access to a computer network without authorization or permission from the owners.
Cyber threat
Data backup
Software update
Network maintenance
Fill in the blank: ________ is a method of bypassing normal authentication and gaining access in OS or application.
Backdoor
Firewall
Patch
Encryption
Fill in the blank: ________ is an attack that intercepts and relays messages between two parties who are communicating directly with each other.
Man-in-the-middle attack
Phishing attack
Denial-of-service attack
Brute force attack
Fill in the blank: ________ is any attack where the attackers attempt to prevent the authorized users from accessing the service.
Denial of service attack
Phishing attack
Man-in-the-middle attack
SQL injection
Fill in the blank: ________ is a very common exploited web application vulnerability that allows malicious hacker to steal and alter data in website’s database.
SQL injection
Cross-site scripting (XSS)
Denial of Service (DoS)
Phishing
Fill in the blank: ________ is a code injection attack that allows an attacker to execute malicious javascript in another user’s browser.
Cross-Site Scripting (XSS)
SQL Injection
Denial of Service (DoS)
Man-in-the-Middle (MitM)
Fill in the blank: ________ is devised to bring real-time, adaptable, risk-aware access control to the enterprise. It represents a fundamental shift in the way access control is managed by introducing environmental conditions and risk levels into the access control decision process.
Risk-adaptive access control (RAdAC)
Role-based access control (RBAC)
Mandatory access control (MAC)
Discretionary access control (DAC)
What is Policy-based Access control (PBAC)?
Emerging model that seeks to help enterprises address the need to implement concrete access controls based on abstract policy and governance requirements. PBAC combines attributes from the resource, the environment, and the requester with information on the particular set of circumstances under which the access request is made. It uses rule sets that specify whether the access is allied under organizational policy for those attributes under those circumstances.
A legacy access control model that only uses user roles to determine access rights, without considering policies or attributes.
A method of access control that grants permissions solely based on the physical location of the user.
A security model that allows unrestricted access to all resources within an organization, regardless of user identity or context.
What is Attribute based access control (ABAC)?
Access control decisions are made based on a set of characteristics, or attributes. Associated with the requester, the environment, and/or the resource itself.
Access control decisions are made solely based on user roles within an organization.
Access control decisions are made based on predefined lists of allowed users.
Access control decisions are made only by the system administrator.
What is Role-based access control (RBAC)?
RBAC determines access based on roles. More than one person can have the same role. RBAC allows for the grouping of individuals into categories of people who fulfill a particular role. One set of access control permissions on a particular resource. The source code tree for a new piece of software can be set once for all members of the software engineering department.
RBAC assigns access based on individual user preferences and personal history.
RBAC provides access only to administrators and denies all other users.
RBAC allows unrestricted access to all resources for every user, regardless of their role.
What is Identity Management?
A broad term to include the use of different products to identify, authenticate, and authorize users through automated means.
A process of managing physical assets in an organization.
A method for encrypting sensitive data in transit.
A system for monitoring network traffic for security threats.
What is Access Control in security engineering?
It is where security engineering meets computer science. Its function is to control which (active) subject have access to a which (passive) object with some specific access operation.
It is a method for encrypting data to prevent unauthorized access.
It is a process of backing up data to ensure data recovery in case of loss.
It is a technique for monitoring network traffic for suspicious activity.
What is Physical Security?
Essential to preventing unauthorized access to sensitive data as well as protecting an organization’s personnel and resources.
A method for encrypting digital files on a computer.
A type of software used to detect viruses.
A process for backing up data to the cloud.
Who are Insider threats?
An insider that is defined as someone with legitimate access to the network.
A person who hacks into the network from outside.
A software that protects the network from viruses.
A device used to store backup data.
What is a Zero-day attack?
A threat aimed at exploiting a software application vulnerability before the application vendor becomes aware of it and before the vulnerability becomes widely known to the internet security community. These attacks are among to mitigate and leave computers and networks extremely vulnerable.
A type of attack that only occurs after a software patch has been released and installed.
An attack that targets outdated hardware components rather than software vulnerabilities.
A threat that is only effective against mobile devices and not computers.
What are Botnets?
Networks of compromised computers used by hackers for malicious purposes, usually criminal in nature.
A type of computer virus that only infects mobile devices.
A security protocol used to protect wireless networks.
A software used for legitimate network management.
What is Removable media in the context of security threats?
The use of removable media on an organization's network poses a significant security threat. Without proper protection, these types of media provide a pathway for malware to move between networks or hosts.
Removable media is a type of software used to encrypt files on a network.
Removable media refers to permanent storage devices that cannot be disconnected from a network.
Removable media is a security protocol used to monitor network traffic.
What is cloud computing in the context of security?
Large amounts of customer data are stored in shared resources, which raises a variety of data encryption and availability issues.
Cloud computing is a method of securing local hard drives from malware.
Cloud computing refers to the use of physical servers only for data storage.
Cloud computing is a way to prevent phishing attacks on email accounts.
What is the Data Protection Act?
The law that protects us against illegal and inappropriate use of our personal information without our consent, and the same applies to us using the information of others.
A law that regulates the use of public parks and recreational areas.
A set of rules for managing internet bandwidth in organizations.
A policy for protecting company property from theft.
What is data protection law?
Data protection law has become not only a vehicle for protecting citizens and consumers, it has become a gateway to trade.
Data protection law is a set of rules for managing financial investments.
Data protection law refers to guidelines for environmental conservation.
Data protection law is a system for regulating international travel.
Data security is commonly referred to as the ________, availability, and integrity of data.
confidentiality
transparency
redundancy
authenticity
Good governance involves clearly defining jobs and responsibilities and evaluating employees according to their ________.
results
attendance
appearance
seniority
Risk management refers to identifying, evaluating, and managing various risks, including legal, financial, and security-related risks. Organizations must employ resources to minimize risks by monitoring and controlling the impact of ________ events.
security
routine
celebratory
predictable
The Committee of Sponsoring Organizations of the Treadway Commission (COSO) framework is a reputable ERM framework businesses across industries use to create a more holistic view of ________.
risk
profit
marketing
technology
The National Institute of Standards and Technology (NIST) Cybersecurity Framework is a repeatable process for managing and improving ________.
cybersecurity
productivity
customer service
financial reporting
The International Organization for Standardization (ISO) offers guidance on various business needs, including information security and ________ management.
risk
inventory
marketing
customer
ISACA is a global professional association that develops frameworks for IT governance and risk management, including the Control Objectives for Information and Related Technologies (COBIT).
True
False
A GRC framework is a model for managing governance and compliance risk in a company. It involves identifying the key policies that can drive the company toward its ________.
goals
losses
competitors
expenses
GRC maturity is the level of integration of governance, risk assessment, and ________ within an organization.
compliance
finance
marketing
operations
Who assesses risks when making strategic decisions?
Senior executives
Junior employees
Interns
Customers
Who helps businesses mitigate legal exposures?
Legal teams
Marketing teams
IT support
Sales representatives
Who supports compliance with regulatory requirements?
Finance managers
Marketing managers
Sales executives
Product designers
Who deals with confidential recruitment information?
HR executives
Marketing managers
IT technicians
Finance analysts
OCEG created an open-source GRC Capability Model integrating risk, governance, audit, ethics/culture, IT, and ________.
compliance
finance
marketing
sales
Compliance refers to an organization's adherence to government regulations, industry standards, and internal ________.
policies
vehicles
colors
holidays
Cyber threat intelligence is an area of cybersecurity that focuses on the collection and analysis of information about current and potential attacks that threaten the safety of an organization or its ________.
assets
employees
software
customers
Fill in the blank: __________ is a high-level assessment of potential threats, identifying who might be interested in attacking the organization or companies in its industry and their motivations. It is presented to executives in the form of whitepapers, reports and presentations to show them how the organization needs to respond.
Strategic threat intelligence
Operational threat intelligence
Technical threat intelligence
Incident response planning
Fill in the blank: __________ relates to how and where the organization may be targeted and focuses on cybercriminals tactics, techniques, and procedures. It is technical and is presented to IT and network professionals, to have them put defenses in place to prevent these types of attacks.
Tactical threat intelligence
Strategic threat intelligence
Operational threat intelligence
Physical security intelligence
Fill in the blank: __________ is information gleaned from active attacks, cyber hotpots (traps to entice hackers to reveal their tactics) and data shared by third parties. It includes highly specific data such as URLs, file names and hashes, domain names, and IP addresses, and should be used to block attacks (if caught early enough), limiting damage and eliminating known threats in the network.
Operational Threat intelligence
Strategic Threat intelligence
Tactical Threat intelligence
Technical Threat intelligence
Fill in the blank: __________ is the process to identify intelligence needs of organization, critical assets, and their vulnerabilities.
Intel planning/strategy
Incident response
Risk acceptance
Asset disposal
Fill in the blank: __________ is the process to identify and collect relevant data for threat analytics.
Data collection and aggregation
Threat mitigation
Incident response
Vulnerability scanning
Fill in the blank: __________ is the process to analyze collected data to develop relevant, timely, and actionable intelligence.
Threat analytics
Data encryption
Network segmentation
Access control
Fill in the blank: __________ is the process to mitigate threats and disseminate intelligence.
Intel usage and dissemination
Threat escalation
Data encryption
Incident reporting
Ransomware locks system down before demanding payment for the user to gain access.
True
False
Fill in the blank: One common type of malware is __________, which can be installed on a system without your knowledge to obtain internet, usage data and other sensitive information.
spyware
adware
ransomware
rootkit
Fill in the blank: __________ is a standardized XML based programming language developed to represent structured cyber threat indicators that can be easily understood by humans and cyber technologies.
Structured threat information expression
Common Vulnerability Scoring System
Open Web Application Security Project
Advanced Persistent Threat Modeling
Fill in the blank: __________ defines set of services and message exchanges that, when implemented, enable sharing of actionable cyber threat information.
Trusted Automated eXchange of indicator information
Simple Mail Transfer Protocol
Domain Name System
File Transfer Protocol
What is the definition of Intelligence in the context of digital forensics? Intelligence - __________ about threats and threat actors that provides sufficient understanding for mitigating a harmful event.
Information
Hardware
Encryption
Authentication
Which organization describes the four phases of the digital evidence forensic process?
A) NIST
B) ISO
C) IEEE
D) STIX
What is the first phase of the digital evidence forensic process according to NIST?
A) Collection
B) Examination
C) Analysis
D) Reporting
Fill in the blank: Collection is the identification of potential sources of forensic data and acquisition, handling, and __________ of that data.
storage
deletion
encryption
transmission
Examination in digital forensics refers to __________ and extracting relevant information from the collected data.
accessing
deleting
encrypting
transmitting
Analysis in digital forensics involves drawing __________ from the data and correlation of data from multiple sources.
conclusions
pictures
guesses
stories
Reporting in digital forensics is about preparing and presenting information that resulted from the __________ phase.
analysis
collection
preservation
identification
Who developed the Cyber Kill Chain?
Lockheed Martin
NIST
Microsoft
What is the first step of the Cyber Kill Chain?
A) Reconnaissance
B) Weaponization
C) Delivery
D) Exploitation
Which CSIRT activity involves training members in how to respond to an incident?
Preparation
Detection
Recovery
Eradication
Which CSIRT activity quickly identifies, analyzes, and validates an incident?
Detection and Analysis
Recovery and Restoration
Post-Incident Review
Containment and Eradication
Which CSIRT activity implements procedures to contain the threat, eradicate the impact on organizational assets, and use backups to restore data and software?
Containment, Eradication, and Recovery
Vulnerability Assessment and Patch Management
Security Policy Development
User Awareness Training
Which CSIRT activity documents how the incident was handled, recommends changes for future response, and specifies how to avoid a reoccurrence?
Post-Incident Activities
Incident Detection
Incident Containment
Incident Identification
The final step of the Cyber Kill Chain that describes the threat actor achieving their original objective.
(a)
Is when the threat actor performs research, gathers intelligence, and selects targets.
(a)
uses the information from reconnaissance to develop a weapon against specific targeted systems or individuals in the organization.
(a)
The weapon is transmitted to the target using a delivery vector. If the weapon is not delivered, the attack will be unsuccessful.
(a)
The threat actor uses it to break the vulnerability and gain control of the target
(a)
The threat actor establishes a back door into the system to allow for continued access to the target.
(a)
