WorksheetsCybersecurity Quiz
Total questions: 69
Worksheet time: 35mins
Which of the following best describes data integrity?
Ensuring that the data is not modified
Only authorized users can access data
Changing data into something that has no meaning
Ability to ensure identity of sender or receiver
Which of the following is a function of encryption in cybersecurity?
Change the data into something that has no meaning
Ensure the data is not modified
Block any traffic of the rule
Distinguish between human and bot
Which of the following is an example of a symmetric encryption algorithm?
HES, 3DES
RSA, ECC
SHA, MD5
WEP, WPA
What is the main purpose of a firewall in network security?
Block any traffic of the rule
Encrypt data for confidentiality
Authenticate users
Prevent data modification
Which of the following best describes non-repudiation?
Ability of a system to prevent any party from denying he already did
Ensuring only authorized users can access data
Changing data into something meaningless
Blocking unauthorized network traffic
Which protocol is NOT considered a traditional network security protocol?
WEP
SSH
TLS
SSL
Which of the following is a method to distinguish between a human and a bot?
CAPTCHA
Firewall
Antivirus
Checksum
Which mindset assumes that someone wants to break your system and encourages you to study your system to avoid attacks?
Security mindset
Happy-path mindset
Positive mindset
Cyberspace mindset
Why is it not enough to only add security at the edge of the network?
Security should be added in both the border and inside the system
Edge security is always absolute
Only internal threats exist
Firewalls are not effective at the edge
Under what condition can a system be considered practically secure, according to the document?
When the resources required for an attack to succeed are greater than the value of the data being protected
When the system is disconnected from all networks
When only authorized users have access
When a firewall is installed
Which of the following is NOT a method to guarantee a system is completely secure?
Using weak passwords
Backup
Cloud service
Antivirus
What is the main motivation for an attacker to breach a system?
The value of the data being protected
The complexity of the encryption algorithm
The number of users on the system
The type of firewall used
Which of the following is a tool used in vulnerability assessment?
Penetration testing using tool
Data encryption
CAPTCHA
Cloud service
Which type of attacker is known for having a strong understanding of systems and using their skills for criminal purposes?
Black Hat
White Hat
Grey Hat
Script Kiddie
What is the primary motivation of a Grey Hat hacker?
Usually not to cause harm or steal data
To work for the government
To only test their own systems
To always follow ethical guidelines
Which of the following best describes a Script Kiddie?
Does not fully understand the technical background of hacking
Works for the national government
Has strong skills like a Black Hat
Only attacks physical assets
Which of the following is considered a tangible asset?
Physical thing
Business plan
Data record
Copyright
What is the main duty of cybersecurity?
To change and improve organizational culture
To create new software
To increase hardware speed
To reduce employee numbers
Which of the following is an example of a threat?
Someone who intends to cause harm to an asset
A new software update
A backup system
A firewall installation
What is a zero-day attack?
An exploit that is unknown to the world
An attack that happens every day
A physical theft of hardware
A routine system update
Which of the following is NOT a step in countermeasure?
Prevention
Detection
Reaction
Exploitation
What is a vulnerability in the context of cybersecurity?
A weakness that hackers can exploit to gain access to systems
A type of hardware upgrade
A new software feature
A backup procedure
Which of the following is an example of exposure in cybersecurity?
Known vulnerability that is not yet patched
A new antivirus installation
A secure password policy
A regular software update
(DoK Level 2) How can assets be categorized in cybersecurity?
Hardware, Software, Communication lines
Only physical things
Only business plans
Only employee records
(DoK Level 2) What is the difference between an event and an incident in cybersecurity?
An event can be routine and not require action, while an incident negatively affects the IT system and requires action
An event always requires action, while an incident never does
An event is always negative, while an incident is always positive
There is no difference between an event and an incident
(DoK Level 3) If an employee is not well educated about security policies, what could be a potential consequence for the organization?
It might destroy the organization's security
It will increase the organization's profits
It will improve the organization's reputation
It will reduce the need for cybersecurity
(DoK Level 3) Why is it important to implement detection as part of a countermeasure strategy?
So you can detect when, how, and which asset has been damaged
To increase the number of employees
To reduce the cost of hardware
To avoid using any security mechanisms
Which of the following best defines "risk" in the context of network security?
The potential for damage that could occur when vulnerability is exploited
The process of encrypting data during transmission
The method of authenticating users in a network
The act of backing up data to prevent loss
Which of the following is NOT a key component of risk?
Threat agent exploiting vulnerability
Impact if the attacker is successful
Data encryption algorithm
Vulnerability in the system
What is the primary purpose of network security?
Protect data during communication
Increase network speed
Reduce hardware costs
Improve user interface design
Which of the following is an example of a secure communication protocol?
HTTPS
FTP
Telnet
HTTP
Which of the following is NOT one of the five things to ensure during data transmission?
Safe communication
Message secrecy
Authentic identity of participants
Data compression
What does "confidentiality" in the C-T-A triad refer to?
Hiding data from unauthorized access
Ensuring data is always available
Making data readable to everyone
Allowing data to be modified by anyone
Which of the following best describes "integrity" in information security?
Protection from unauthorized access and ensuring data is not altered
Making sure data is always available
Encrypting all data transmissions
Allowing anonymous access to data
What is the main focus of "availability" in the C-T-A triad?
Ensuring data are accessible when needed
Hiding data from unauthorized users
Encrypting data at rest
Preventing data from being modified
Which of the following is a method to support data integrity?
Digital watermarking
Data compression
Data fragmentation
Data mining
If a machine is compromised and able to read private data, which aspect of security is most at risk?
Confidentiality
Availability
Non-repudiation
Anonymity
Why is a checksum value important in data integrity?
It helps detect if data has been changed during transmission
It encrypts the data for secure communication
It compresses the data for faster transfer
It anonymizes the sender of the data
Which of the following is an example of a measure to ensure availability?
Backup and load balancing
Data encryption
User authentication
Message hashing
Which of the following is a main threat to system availability?
Network failure
Unauthorized access
Modification
Masquerading
What is the principle of least privilege in access control?
Having only the permissions needed to do your job
Giving all users administrator rights
Allowing access to all resources
Sharing passwords with colleagues
Which of the following is an example of providing confidentiality for sensitive data?
Using a physical dedicated point-to-point link
Allowing public access to data
Storing passwords in plain text
Disabling encryption
What is the main function of end-to-end encryption (E2EE)?
Encrypting data on the sender's device and only decrypting on the receiver's device
Encrypting data only at intermediate network nodes
Allowing all network devices to read the message content
Storing data in unencrypted form
To keep data at rest confidential, which of the following is NOT required?
Disabling user authentication
Strong encryption
User authentication with name and password
Access control policies
Which of the following is a threat to confidentiality?
Snooping
Modification
Denial of service
Ransomware
Which of the following security attacks is classified as a threat to integrity?
Modification
Denial of service
Snooping
Traffic analysis
Which of the following best describes the three main security goals?
Confidentiality, integrity, and availability
Encryption, authentication, and authorization
Privacy, access, and control
Prevention, detection, and response
Which security service focuses on the person’s attitude and behavior?
Privacy
Confidentiality
Availability
Anonymity
To ensure which security service can we substitute the original names with nicknames?
Confidentiality
Privacy
Anonymity
Availability
Which security service is concerned with the ability to access or not access a specific resource?
Availability
Privacy
Confidentiality
Anonymity
If you don’t want anyone except the one you give permission to access your resource, which security service are you ensuring?
Confidentiality
Privacy
Anonymity
Availability
Which security service ensures that unauthorized persons should not have any access or disclosure of data?
Anonymity
Confidentiality
Privacy
Availability
If all entities in a system are equal and unknown to each other, which security service does this describe?
Privacy
Confidentiality
Anonymity
Availability
Announcing the name of a person who has not participated in any activity is a violation of which security service?
Privacy
Confidentiality
Anonymity
Availability
Having part of the information that identifies a participant is a violation of which security service?
Privacy
Confidentiality
Anonymity
Availability
Announcing the name of the person who has the permission to access specific data is a violation of which security service?
Privacy
Confidentiality
Anonymity
Availability
Having part of your information provided to unauthorized persons is considered a violation of which security service?
Privacy
Confidentiality
Anonymity
Availability
Which security service is addressed by the policy: "Avoid using public WiFi networks"?
Integrity
Availability
Confidentiality
Authentication
Removing duplicate records in a system is a solution mechanism for which aspect of the C-I-A Triad?
Confidentiality
Integrity
Availability
Authentication
Blacklisting incoming connections from known IP addresses primarily enhances which security service?
Confidentiality
Integrity
Availability
Non-repudiation
Issuing a digital signature is most closely related to which component of the C-I-A Triad?
Confidentiality
Integrity
Availability
Authentication
Do not repeat passwords for every site you register in. This policy is mainly concerned with which security service?
Confidentiality
Integrity
Availability
Non-repudiation
Shredding or incinerating papers is a solution mechanism for which aspect of security?
Availability
Confidentiality
Integrity
Authentication
Issuing a robot test via CAPTCHA is intended to improve which security service?
Confidentiality
Integrity
Availability
Non-repudiation
Adopting cloud computing services is primarily a solution for which part of the C-I-A Triad?
Confidentiality
Integrity
Availability
Authentication
Utilizing VPN tunneling is a mechanism to enhance which security service?
Confidentiality
Integrity
Availability
Non-repudiation
Fault-tolerant technologies such as RAID that can detect and fix faults are mainly used to ensure which security service?
Confidentiality
Integrity
Availability
Authentication
Given a scenario where a company wants to ensure that their data is not altered during transmission, which security service should they focus on?
Confidentiality
Integrity
Availability
Authentication
A business wants to make sure their services are always accessible to users, even during a cyber attack. Which part of the C-I-A Triad is most relevant?
Confidentiality
Integrity
Availability
Non-repudiation
