wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

010_016_CyberCapstone

Total questions: 113

Worksheet time: 58mins

Name
Class
Date
1.

What is Mr. Cusack Room number?

a)

502

b)

1000

2.

How do changes in a home environment differ from those in a corporate environment?

a)

Home changes impact multiple systems, corporate changes affect only one

b)

Home changes don’t require approval, corporate changes need formal processes

c)

Corporate changes are less risky than home changes

d)

Home changes follow strict approval guidelines

e)

Corporate changes do not require documentation

3.

Why is a formal change control process necessary in an organization?

a)

To allow unrestricted system changes

b)

To increase the complexity of IT operations

c)

To ensure changes are tested, reviewed, and approved before implementation

d)

To prevent employees from using IT resources

e)

To delay necessary system updates

4.

How does change control contribute to system security?

a)

It prevents users from accessing the system

b)

It ensures that only IT staff can make system changes

c)

It helps prevent vulnerabilities by managing updates properly

d)

It eliminates the need for security software

e)

It reduces the number of IT staff needed

5.

What role does change control play in maintaining system stability?

a)

Prevents unauthorized changes that could cause disruptions

b)

Eliminates the need for system updates

c)

Ensures all applications are identical

d)

Reduces the number of users on the system

e)

Blocks any software updates

6.

Why is consistency important in change control?

a)

Ensures all employees make personal changes to systems

b)

Reduces the risk of unexpected failures or incompatibilities

c)

Prevents organizations from updating their systems

d)

Avoids unnecessary documentation

e)

Eliminates the need for IT teams

7.

How does change control help with accountability?

a)

Prevents system administrators from making updates

b)

Ensures all changes are documented and tracked

c)

Stops all software installations

d)

Restricts access to system logs

e)

Removes the need for change requests

8.

In what ways does change control mitigate risks?

a)

Reduces the possibility of system failures

b)

Increases unauthorized changes

c)

Prevents necessary updates

d)

Ensures IT staff can bypass policies

e)

Eliminates documentation requirements

9.

What information should be included in a change request submission?

a)

Reason, scope, affected systems, and schedule

b)

Only the name of the requester

c)

A list of employees impacted

d)

A summary of past system changes

e)

None of the above

10.

Why is risk assessment crucial in the change control process?

a)

To determine potential negative impacts of the change

b)

To eliminate all system updates

c)

To avoid involving stakeholders

d)

To speed up the change approval process

e)

To restrict IT teams from making changes

11.

Who is responsible for approving, modifying, or rejecting a change request?

a)

The IT team

b)

The Change Control Board

c)

The application/data owner

d)

The system users

e)

The CEO

12.

What is the role of the application/data owner in the change control process?

a)

Initiates and verifies system functionality after the change

b)

Approves all changes

c)

Implements and tests system updates

d)

Denies change requests

e)

Monitors security settings

13.

How does the IT team contribute to change control?

a)

Makes unauthorized changes

b)

Implements and tests changes

c)

Rejects all change requests

d)

Restricts user access

e)

Monitors only security updates

14.

What responsibilities does the Change Control Board have?

a)

Approving or denying changes

b)

Implementing system updates

c)

Blocking unauthorized access

d)

Writing code for applications

e)

Monitoring internet usage

15.

Who are stakeholders in the change control process?

a)

Only IT staff

b)

Individuals or departments affected by the change

c)

Only upper management

d)

Only employees who requested the change

e)

None of the above

16.

Why is it important to involve stakeholders in change control decisions?

a)

To gain insights on potential impacts

b)

To slow down the process

c)

To eliminate documentation requirements

d)

To allow unrestricted changes

e)

To block IT staff from making updates

17.

What potential issues can arise from implementing a change?

a)

Downtime, data corruption, or software failures

b)

Increased efficiency

c)

Enhanced system security

d)

Faster application processing

e)

Lower IT costs

18.

How can not making a change lead to security vulnerabilities?

a)

Leaves outdated software open to attacks

b)

Prevents unauthorized changes

c)

Ensures system stability

d)

Reduces IT workload

e)

Blocks all updates

19.

Why should thorough testing be performed before deploying a change?

a)

To detect potential issues before affecting production systems

b)

To speed up implementation

c)

To eliminate the need for documentation

d)

To avoid involving stakeholders

e)

To prevent IT staff from approving changes

20.

How does scheduling changes during low-impact periods help an organization?

a)

Minimizes disruptions to business operations

b)

Increases downtime

c)

Makes testing unnecessary

d)

Blocks user access

e)

Eliminates the need for approvals

21.

What is the primary role of a technician in the change control process?

a)

To approve changes

b)

To execute changes

c)

To document changes

d)

To review changes

22.

Which of the following best describes an "allow list"?

a)

A list of applications that are blocked

b)

A list of applications that are allowed to run

c)

A list of users who can access the system

d)

A list of network protocols that are permitted

23.

Why is documentation important in change control?

a)

It helps in tracking and reverting changes

b)

It ensures that only approved changes are made

c)

It provides a backup of all system data

d)

It allows for the installation of new software

24.

Explain the difference between an allow list and a deny list in terms of application control.

a)

An allow list blocks all applications except those explicitly allowed, while a deny list allows all applications except those explicitly blocked.

b)

An allow list allows all applications except those explicitly blocked, while a deny list blocks all applications except those explicitly allowed.

c)

Both allow and deny lists block all applications.

d)

Both allow and deny lists allow all applications.

25.

What is a common challenge when dealing with legacy systems in change control?

a)

They are easy to update

b)

They often lack developer support

c)

They have no dependencies

d)

They require no documentation

26.

How can downtime be managed in a 24/7 organization during change control?

a)

By ignoring downtime requirements

b)

By implementing a primary-secondary system for seamless transitions

c)

By scheduling downtime during peak hours

d)

By shutting down the system completely

27.

Why might a system reboot or service restart be necessary during change control?

a)

To increase system speed

b)

To apply changes effectively

c)

To delete unnecessary files

d)

To install new hardware

28.

What is the role of version control in change management?

a)

It helps in tracking and reverting changes

b)

It allows for unauthorized changes

c)

It prevents any changes from being made

d)

It speeds up the change process

29.

Describe a scenario where dependencies might complicate a change control process.

a)

Updating a single application with no dependencies

b)

Updating firewall management software that requires all firewalls to be updated first

c)

Installing a new printer driver

d)

Changing user passwords

30.

What is a potential solution for managing changes that require downtime in a 24/7 organization?

a)

Implementing a primary-secondary system

b)

Ignoring downtime requirements

c)

Scheduling downtime during peak hours

d)

Shutting down the system completely

31.

How does change control ensure that IT changes are implemented properly?

a)

By allowing technicians to make any changes they see fit

b)

By documenting, reviewing, and implementing changes according to a plan

c)

By preventing any changes from being made

d)

By allowing changes only during business hours

32.

What is a key takeaway regarding the execution of change requests by technicians?

a)

Technicians can make changes outside the predefined scope

b)

Technicians execute change requests according to predefined scopes

c)

Technicians do not need to follow any documentation

d)

Technicians can approve changes

33.

Why is it important to have a predefined scope in change control?

a)

To allow for flexibility in making changes

b)

To ensure that only approved changes are made

c)

To speed up the change process

d)

To allow technicians to make changes as they see fit

34.

What might be a reason for requiring special handling of legacy applications during change control?

a)

They are always up-to-date

b)

They may have old OS dependencies

c)

They are easy to update

d)

They have no dependencies

35.

In what way does version control contribute to effective change management?

a)

It prevents any changes from being made

b)

It allows for unauthorized changes

c)

It helps track and revert changes when needed

d)

It speeds up the change process

36.

What does PKI stand for in the context of cryptography?

a)

Public Key Infrastructure

b)

Private Key Interface

c)

Public Key Integration

d)

Private Key Infrastructure

37.

Which of the following is a characteristic of symmetric encryption?

a)

Uses two different keys for encryption and decryption

b)

Uses the same key for both encryption and decryption

c)

Requires a Certificate Authority for operation

d)

Is slower than asymmetric encryption

38.

In asymmetric encryption, what is the role of the public key?

a)

It is used to decrypt data

b)

It is kept secret by the owner

c)

It is used to encrypt data

d)

It is used to generate the private key

39.

Explain why symmetric encryption might pose scalability issues in large networks.

a)

Because it requires a Certificate Authority for each user

b)

Because the same key must be shared among all users, increasing the risk of key compromise

c)

Because it is slower than asymmetric encryption

d)

Because it requires more computational power

40.

Describe a scenario where key escrow might be necessary in an organization.

a)

When an organization wants to ensure data can be decrypted even if the original user is unavailable

b)

When an organization wants to increase the speed of encryption

c)

When an organization wants to reduce the number of keys in use

d)

When an organization wants to eliminate the need for a Certificate Authority

41.

What is the primary advantage of using asymmetric encryption over symmetric encryption?

a)

It is faster than symmetric encryption

b)

It eliminates the need for key management

c)

It allows secure communication without sharing a secret key

d)

It requires less computational power

42.

How does a Certificate Authority (CA) contribute to the trust model in PKI?

a)

By encrypting data with a public key

b)

By verifying the identity of entities and issuing digital certificates

c)

By storing private keys securely

d)

By generating public/private key pairs

43.

Analyze the potential risks associated with storing a private key without a password.

a)

It increases the speed of decryption

b)

It makes the private key vulnerable to unauthorized access

c)

It reduces the complexity of key management

d)

It ensures the private key is always available

44.

Evaluate the effectiveness of using a third-party key management service in a large organization.

a)

It eliminates the need for encryption

b)

It centralizes key management, reducing the risk of key loss

c)

It increases the complexity of encryption algorithms

d)

It requires each user to manage their own keys

45.

Consider the example of Alice and Bob. Why is it important for Alice to keep her private key secure?

a)

To ensure Bob can encrypt messages to her

b)

To prevent unauthorized decryption of messages intended for her

c)

To allow others to verify her identity

d)

To enable the generation of new public keys

46.

What is the role of randomization in the key generation process for asymmetric encryption?

a)

It ensures the keys are identical

b)

It increases the speed of key generation

c)

It enhances the security by making keys unpredictable

d)

It simplifies the encryption process

47.

Why is it computationally infeasible to derive a private key from a public key in asymmetric encryption?

a)

Because the keys are stored in different locations

b)

Because the mathematical relationship between the keys is complex

c)

Because the public key is encrypted

d)

Because the private key is never shared

48.

Discuss the implications of a compromised private key in a PKI system.

a)

It allows unauthorized users to encrypt data

b)

It allows unauthorized users to decrypt data

c)

It prevents the use of the public key

d)

It requires the generation of a new public key

49.

How does the use of large prime numbers contribute to the security of asymmetric encryption?

a)

It makes the encryption process faster

b)

It simplifies the key management process

c)

It increases the difficulty of factoring the keys

d)

It reduces the size of the keys

50.

Propose a method to enhance the security of private key storage.

a)

Store the private key on a public server

b)

Use a password to protect the private key

c)

Share the private key with trusted colleagues

d)

Use the same private key for multiple users

51.

What is the primary purpose of data at rest encryption?

a)

To encrypt data while it is being transmitted over a network.

b)

To encrypt data stored on devices such as SSDs and hard drives.

c)

To encrypt data in a database.

d)

To encrypt data using public algorithms.

52.

Which of the following is a method of file-level encryption in Windows?

a)

BitLocker

b)

FileVault

c)

EFS (Encrypting File System)

d)

IPsec

53.

Explain how column-level encryption can improve database performance compared to full database encryption.

a)

It encrypts all data, reducing the need for decryption.

b)

It encrypts only sensitive columns, allowing non-sensitive data to remain in plain text for faster searches.

c)

It uses asymmetric keys for faster encryption.

d)

It compresses data before encryption to save space.

54.

What is the role of a VPN in data in transit encryption?

a)

To encrypt data stored on a hard drive.

b)

To create an encrypted tunnel for secure communication between sites or remote users.

c)

To encrypt individual files on a computer.

d)

To provide a public key for encryption.

55.

Discuss the trade-offs involved in choosing an encryption algorithm.

a)

Security level, speed, and complexity of implementation.

b)

Cost, availability, and user-friendliness.

c)

Color, size, and shape.

d)

Brand, warranty, and customer service.

56.

Why is the secrecy of the encryption key more important than the secrecy of the algorithm?

a)

Because algorithms are always secret and never shared.

b)

Because knowing the algorithm does not grant access without the correct key.

c)

Because keys are easier to remember than algorithms.

d)

Because algorithms are less secure than keys.

57.

How does key strengthening increase resistance to brute force attacks?

a)

By using shorter keys.

b)

By performing the encryption or hashing process multiple times.

c)

By using weaker algorithms.

d)

By storing keys in plain text.

58.

Evaluate the effectiveness of using longer keys in encryption.

a)

Longer keys are less secure and easier to break.

b)

Longer keys provide more resistance to brute force attacks.

c)

Longer keys are faster to process.

d)

Longer keys are only useful for symmetric encryption.

59.

What is the main advantage of using AES over DES?

a)

AES is slower but more secure.

b)

AES uses a smaller key size.

c)

AES supports multiple versions for varied security levels.

d)

AES is a symmetric key algorithm.

60.

Describe a scenario where file-level encryption would be more appropriate than full disk encryption.

a)

When encrypting an entire hard drive is necessary.

b)

When only specific files or folders need to be encrypted for security.

c)

When encrypting data in transit.

d)

When using a VPN for secure communication.

61.

What is the primary function of HTTPS in data in transit encryption?

a)

To encrypt data stored on a server.

b)

To encrypt web traffic between a browser and web servers.

c)

To encrypt emails.

d)

To encrypt database entries.

62.

How does algorithm transparency contribute to the robustness of encryption techniques?

a)

By keeping the algorithm secret from everyone.

b)

By allowing public scrutiny and trust in the algorithm's security.

c)

By making the algorithm more complex.

d)

By reducing the need for encryption keys.

63.

Analyze the impact of processing power on the required key length for encryption.

a)

As processing power increases, shorter keys become more secure.

b)

As processing power increases, longer keys may be required for continued security.

c)

Processing power has no impact on key length.

d)

Processing power only affects symmetric encryption.

64.

What is the main difference between symmetric and asymmetric keys in encryption?

a)

Symmetric keys are always longer than asymmetric keys.

b)

Symmetric keys use the same key for encryption and decryption, while asymmetric keys use a pair of keys.

c)

Asymmetric keys are faster than symmetric keys.

d)

Symmetric keys are only used for database encryption.

65.

Propose a method to enhance the security of a database containing sensitive information.

a)

Use full disk encryption for the server.

b)

Implement column-level encryption for sensitive data.

c)

Use a VPN for all database connections.

d)

Store all data in plain text for easy access.

66.

What is the primary purpose of data at rest encryption?

a)

To encrypt data while it is being transmitted over a network.

b)

To encrypt data stored on devices such as SSDs and hard drives.

c)

To encrypt data in a database.

d)

To encrypt data using public algorithms.

67.

Which of the following is an example of full disk encryption on Mac OS?

a)

BitLocker

b)

FileVault

c)

EFS

d)

TrueCrypt

68.

Explain how column-level encryption can improve database performance compared to transparent encryption.

a)

Column-level encryption encrypts all data, reducing the need for decryption.

b)

Column-level encryption only encrypts sensitive columns, allowing non-sensitive data to remain in plain text, which speeds up searches.

c)

Column-level encryption uses asymmetric keys, which are faster than symmetric keys.

d)

Column-level encryption is not related to performance improvements.

69.

Describe a scenario where data in transit encryption is crucial.

a)

When storing data on a local hard drive.

b)

When accessing a website over HTTPS to protect web traffic.

c)

When encrypting a database column.

d)

When using a symmetric key for file encryption.

70.

What is the role of algorithm transparency in encryption?

a)

It ensures that encryption keys are kept secret.

b)

It makes encryption algorithms public, increasing trust in their robustness.

c)

It hides the encryption process from users.

d)

It allows for faster encryption and decryption processes.

71.

Why is key secrecy more important than algorithm secrecy in encryption?

a)

Because knowing the algorithm does not help if the key is unknown.

b)

Because algorithms are always secret.

c)

Because keys are easier to guess than algorithms.

d)

Because algorithms are more complex than keys.

72.

How does key length affect the security of an encryption system?

a)

Longer keys make encryption faster.

b)

Longer keys are more resistant to brute force attacks.

c)

Longer keys are less secure.

d)

Key length does not affect security.

73.

What is the main advantage of using AES over DES?

a)

AES uses a shorter key length.

b)

AES is faster and more secure than DES.

c)

AES is easier to implement.

d)

AES is less complex than DES.

74.

Discuss the trade-offs involved in choosing an encryption algorithm.

a)

Only security level matters.

b)

Considerations include security level, speed, and complexity of implementation.

c)

Only speed is important.

d)

Complexity of implementation is the only factor.

75.

What is the purpose of key strengthening techniques?

a)

To make encryption keys shorter.

b)

To increase resistance to brute force attacks by adding computational overhead.

c)

To simplify the encryption process.

d)

To reduce the need for encryption keys.

76.

How does a VPN protect data in transit?

a)

By encrypting data stored on a device.

b)

By creating an encrypted tunnel for secure communication.

c)

By using file-level encryption.

d)

By encrypting database columns.

77.

Why is it important for both parties to agree on the same encryption algorithm?

a)

To ensure that data is stored securely.

b)

To ensure successful encryption and decryption.

c)

To make the encryption process faster.

d)

To reduce the complexity of the encryption process.

78.

Evaluate the impact of processing power on key length requirements.

a)

Increased processing power allows for shorter keys.

b)

Increased processing power necessitates longer keys for continued security.

c)

Processing power does not affect key length.

d)

Longer keys are only needed for asymmetric encryption.

79.

What is the difference between full disk encryption and file-level encryption?

a)

Full disk encryption encrypts individual files, while file-level encryption encrypts the entire disk.

b)

Full disk encryption encrypts the entire storage device, while file-level encryption encrypts individual files or folders.

c)

Full disk encryption is faster than file-level encryption.

d)

There is no difference between the two.

80.

How does brute force attack resistance relate to key length in encryption?

a)

Shorter keys are more resistant to brute force attacks.

b)

Longer keys are more resistant to brute force attacks.

c)

Key length does not affect brute force attack resistance.

d)

Only asymmetric keys are resistant to brute force attacks.

81.

What is the primary function of a Trusted Platform Module (TPM)?

a)

To manage encryption keys across different platforms

b)

To provide redundancy in data centers

c)

To perform cryptographic functions on individual machines

d)

To act as a dedicated security processor in devices

82.

Which of the following is a feature of a Hardware Security Module (HSM)?

a)

Boot ROM that monitors the boot process

b)

Supports cryptographic accelerators for real-time encryption

c)

Automatic key rotation for security

d)

True random number generator for cryptographic security

83.

What is a key feature of Key Management Systems (KMS)?

a)

Automatic key rotation for security

b)

AES encryption in hardware to protect stored data

c)

Secure storage of encryption keys for web servers

d)

Real-time encryption of data in memory

84.

What challenge is associated with data security?

a)

Data does not require continuous protection

b)

Data is widely distributed across multiple devices

c)

Attackers are not evolving their techniques

d)

Data is always static and easy to protect

85.

What is a feature of a Secure Enclave?

a)

Organizes various types of keys

b)

Boot ROM that monitors the boot process

c)

Associates keys with users in the software

d)

Provides redundancy in power supplies

86.

Which hardware component is designed for cryptographic functions on modern motherboards?

a)

Secure Enclave

b)

Key Management Systems (KMS)

c)

Hardware Security Module (HSM)

d)

Trusted Platform Module (TPM)

87.

Why is it important to locate hardware in secure locations?

a)

To ensure easy access for all employees

b)

To reduce the cost of the hardware

c)

To protect against physical theft and tampering

d)

To improve the hardware's performance

88.

A portable laptop is running Windows 10 Pro. A user enables BitLocker on Drive D.

Which of the following statements is true?

a)

If the user copies of filed to a network share, it remains encrypted.

b)

If the user copies a file to an unencrypted USB drive, the file remains encrypted.

c)

The files will be automatically 

decrypted when the drive is installed in another computer

d)

All of these statements are true

e)

None of these statements are true

89.

What is encrypted by BitLocker?

a)

Only email contents

b)

Only operating system files

c)

Only user files

d)

The entire contents of the operating system partition

90.

Lorrine will be traveling for two weeks. For security purposes, she wants to encrypt the entire drive of her Windows computer before she leaves. What should she use?

a)

KeePass

b)

Bitlocker

c)

Last Pass

d)

Password Manager

91.

A portable laptop running WIndows 10 Pro. A user enables BitLocker on Drive D.

Type yes or no for this statement.

If the user copies the file to a network share, it will remain encrypted.

(a)  

92.

Which of the following type of solutions would you classify an FPGA as?

a)

Hardware security module

b)

Trusted platform module

c)

Anti-tamper

d)

Root of trust

93.

Which of the following is a characteristic of symmetric encryption?

a)

It uses a pair of keys: one public and one private.

b)

It uses the same key for both encryption and decryption.

c)

It is slower than asymmetric encryption.

d)

It is primarily used for digital signatures.

94.

What is the main advantage of using public key infrastructure (PKI)?

a)

It eliminates the need for encryption.

b)

It provides a framework for managing digital certificates and keys.

c)

It speeds up the encryption process.

d)

It reduces the size of encrypted data.

95.

In asymmetric encryption, what is the role of the private key?

a)

It is used to encrypt data.

b)

It is used to decrypt data.

c)

It is used to generate a hash.

d)

It is used to compress data.

96.

Which of the following is a key management practice?

a)

Using the same key for all users

b)

Regularly rotating encryption keys

c)

Storing keys in plain text

d)

Sharing keys over unsecured channels

97.

What is encryption?

a)

A person who tricks you into giving your password

b)

converting information or data into a code to prevent unauthorized access.

c)

To upload your personal data to the cloud

d)

When there is a security breach in your data

98.

The human resources organization want to ensure that stored employee data is encrypted. Which security mechanism would they use?

a)

Hashing

b)

Encryption in transit

c)

Encryption at rest

99.

What is the primary purpose of obfuscation?

a)

To delete sensitive data

b)

To compress data

c)

To make information more difficult to understand

d)

To encrypt data

100.

What does the term 'steganography' mean?

a)

Data encryption

b)

Hidden writing

c)

Data compression

d)

Public key cryptography

101.

Which of the following is NOT a method of steganography?

a)

Audio & Video Steganography

b)

Data Masking

c)

Network Traffic Steganography

d)

Image Steganography

102.

What is tokenization primarily used for?

a)

Compressing data

b)

Deleting data

c)

Replacing sensitive data with a token

d)

Encrypting data

103.

In data masking, which of the following is a common technique?

a)

Encrypting the entire data

b)

Deleting the data

c)

Using asterisks to replace parts of the number

d)

Compressing the data

104.

What is a security advantage of tokenization?

a)

Tokens are encrypted

b)

Tokens can be reused multiple times

c)

Tokens cannot be reused if intercepted

d)

Tokens are stored in plain text

105.

Which of the following statements is true about data masking?

a)

It conceals portions of sensitive information

b)

It compresses data for storage

c)

It encrypts the entire data

d)

It deletes sensitive data

106.

What is a Steganography

a)

A Dinosaur

b)

A Software that draws Graphs

c)

A way of concealing text

d)

A type of malware

107.

A technical is assigned to harden a laptop for a medical practice. which of the following should be used to protect PII in the event of hardware theft?

a)

Hard drive encription

b)

Disable bluetooth

c)

password expiration

d)

Host based firewall

108.

Which of the following methods is used to replace all or part of a data field with a randomly generated number used to reference the original value stored in another vault or database?

a)

Tokenization

b)

Anonymization

c)

Data masking

d)

Data minimization

109.

A technician is assigned to harden a laptop for a medical practice. Which of the following should be used to protect PII in the event of hardware theft?

a)

Hard drive encription

b)

Disable bluetooth

c)

password expiration

d)

Host based firewall

110.

A technician is assigned to harden a laptop for a medical practice. which of the following should be used to protect PII in the event of hardware theft?

a)

Hard drive encription

b)

Disable bluetooth

c)

password expiration

d)

Host based firewall

111.

Companies must make clear what they are doing with the personal information is a part of

a)

Statement of Notice

b)

Statement of Choice

c)

Statement of access

d)

Statement of security

112.

When you purchase an exam voucher at diontraining.com, the system only collects your name, email, and credit card information. Which of the following privacy methods is being used by Dion Training?

a)

Anonymization

b)

Data minimization

c)

Data masking

d)

Tokenization

113.

Token-based authentication typically uses which of the following?

a)

A physical device

b)

A knowledge of personal information

c)

A biometric scan

d)

A password