Font size
Worksheets010_016_CyberCapstone
Total questions: 113
Worksheet time: 58mins
What is Mr. Cusack Room number?
502
1000
How do changes in a home environment differ from those in a corporate environment?
Home changes impact multiple systems, corporate changes affect only one
Home changes don’t require approval, corporate changes need formal processes
Corporate changes are less risky than home changes
Home changes follow strict approval guidelines
Corporate changes do not require documentation
Why is a formal change control process necessary in an organization?
To allow unrestricted system changes
To increase the complexity of IT operations
To ensure changes are tested, reviewed, and approved before implementation
To prevent employees from using IT resources
To delay necessary system updates
How does change control contribute to system security?
It prevents users from accessing the system
It ensures that only IT staff can make system changes
It helps prevent vulnerabilities by managing updates properly
It eliminates the need for security software
It reduces the number of IT staff needed
What role does change control play in maintaining system stability?
Prevents unauthorized changes that could cause disruptions
Eliminates the need for system updates
Ensures all applications are identical
Reduces the number of users on the system
Blocks any software updates
Why is consistency important in change control?
Ensures all employees make personal changes to systems
Reduces the risk of unexpected failures or incompatibilities
Prevents organizations from updating their systems
Avoids unnecessary documentation
Eliminates the need for IT teams
How does change control help with accountability?
Prevents system administrators from making updates
Ensures all changes are documented and tracked
Stops all software installations
Restricts access to system logs
Removes the need for change requests
In what ways does change control mitigate risks?
Reduces the possibility of system failures
Increases unauthorized changes
Prevents necessary updates
Ensures IT staff can bypass policies
Eliminates documentation requirements
What information should be included in a change request submission?
Reason, scope, affected systems, and schedule
Only the name of the requester
A list of employees impacted
A summary of past system changes
None of the above
Why is risk assessment crucial in the change control process?
To determine potential negative impacts of the change
To eliminate all system updates
To avoid involving stakeholders
To speed up the change approval process
To restrict IT teams from making changes
Who is responsible for approving, modifying, or rejecting a change request?
The IT team
The Change Control Board
The application/data owner
The system users
The CEO
What is the role of the application/data owner in the change control process?
Initiates and verifies system functionality after the change
Approves all changes
Implements and tests system updates
Denies change requests
Monitors security settings
How does the IT team contribute to change control?
Makes unauthorized changes
Implements and tests changes
Rejects all change requests
Restricts user access
Monitors only security updates
What responsibilities does the Change Control Board have?
Approving or denying changes
Implementing system updates
Blocking unauthorized access
Writing code for applications
Monitoring internet usage
Who are stakeholders in the change control process?
Only IT staff
Individuals or departments affected by the change
Only upper management
Only employees who requested the change
None of the above
Why is it important to involve stakeholders in change control decisions?
To gain insights on potential impacts
To slow down the process
To eliminate documentation requirements
To allow unrestricted changes
To block IT staff from making updates
What potential issues can arise from implementing a change?
Downtime, data corruption, or software failures
Increased efficiency
Enhanced system security
Faster application processing
Lower IT costs
How can not making a change lead to security vulnerabilities?
Leaves outdated software open to attacks
Prevents unauthorized changes
Ensures system stability
Reduces IT workload
Blocks all updates
Why should thorough testing be performed before deploying a change?
To detect potential issues before affecting production systems
To speed up implementation
To eliminate the need for documentation
To avoid involving stakeholders
To prevent IT staff from approving changes
How does scheduling changes during low-impact periods help an organization?
Minimizes disruptions to business operations
Increases downtime
Makes testing unnecessary
Blocks user access
Eliminates the need for approvals
What is the primary role of a technician in the change control process?
To approve changes
To execute changes
To document changes
To review changes
Which of the following best describes an "allow list"?
A list of applications that are blocked
A list of applications that are allowed to run
A list of users who can access the system
A list of network protocols that are permitted
Why is documentation important in change control?
It helps in tracking and reverting changes
It ensures that only approved changes are made
It provides a backup of all system data
It allows for the installation of new software
Explain the difference between an allow list and a deny list in terms of application control.
An allow list blocks all applications except those explicitly allowed, while a deny list allows all applications except those explicitly blocked.
An allow list allows all applications except those explicitly blocked, while a deny list blocks all applications except those explicitly allowed.
Both allow and deny lists block all applications.
Both allow and deny lists allow all applications.
What is a common challenge when dealing with legacy systems in change control?
They are easy to update
They often lack developer support
They have no dependencies
They require no documentation
How can downtime be managed in a 24/7 organization during change control?
By ignoring downtime requirements
By implementing a primary-secondary system for seamless transitions
By scheduling downtime during peak hours
By shutting down the system completely
Why might a system reboot or service restart be necessary during change control?
To increase system speed
To apply changes effectively
To delete unnecessary files
To install new hardware
What is the role of version control in change management?
It helps in tracking and reverting changes
It allows for unauthorized changes
It prevents any changes from being made
It speeds up the change process
Describe a scenario where dependencies might complicate a change control process.
Updating a single application with no dependencies
Updating firewall management software that requires all firewalls to be updated first
Installing a new printer driver
Changing user passwords
What is a potential solution for managing changes that require downtime in a 24/7 organization?
Implementing a primary-secondary system
Ignoring downtime requirements
Scheduling downtime during peak hours
Shutting down the system completely
How does change control ensure that IT changes are implemented properly?
By allowing technicians to make any changes they see fit
By documenting, reviewing, and implementing changes according to a plan
By preventing any changes from being made
By allowing changes only during business hours
What is a key takeaway regarding the execution of change requests by technicians?
Technicians can make changes outside the predefined scope
Technicians execute change requests according to predefined scopes
Technicians do not need to follow any documentation
Technicians can approve changes
Why is it important to have a predefined scope in change control?
To allow for flexibility in making changes
To ensure that only approved changes are made
To speed up the change process
To allow technicians to make changes as they see fit
What might be a reason for requiring special handling of legacy applications during change control?
They are always up-to-date
They may have old OS dependencies
They are easy to update
They have no dependencies
In what way does version control contribute to effective change management?
It prevents any changes from being made
It allows for unauthorized changes
It helps track and revert changes when needed
It speeds up the change process
What does PKI stand for in the context of cryptography?
Public Key Infrastructure
Private Key Interface
Public Key Integration
Private Key Infrastructure
Which of the following is a characteristic of symmetric encryption?
Uses two different keys for encryption and decryption
Uses the same key for both encryption and decryption
Requires a Certificate Authority for operation
Is slower than asymmetric encryption
In asymmetric encryption, what is the role of the public key?
It is used to decrypt data
It is kept secret by the owner
It is used to encrypt data
It is used to generate the private key
Explain why symmetric encryption might pose scalability issues in large networks.
Because it requires a Certificate Authority for each user
Because the same key must be shared among all users, increasing the risk of key compromise
Because it is slower than asymmetric encryption
Because it requires more computational power
Describe a scenario where key escrow might be necessary in an organization.
When an organization wants to ensure data can be decrypted even if the original user is unavailable
When an organization wants to increase the speed of encryption
When an organization wants to reduce the number of keys in use
When an organization wants to eliminate the need for a Certificate Authority
What is the primary advantage of using asymmetric encryption over symmetric encryption?
It is faster than symmetric encryption
It eliminates the need for key management
It allows secure communication without sharing a secret key
It requires less computational power
How does a Certificate Authority (CA) contribute to the trust model in PKI?
By encrypting data with a public key
By verifying the identity of entities and issuing digital certificates
By storing private keys securely
By generating public/private key pairs
Analyze the potential risks associated with storing a private key without a password.
It increases the speed of decryption
It makes the private key vulnerable to unauthorized access
It reduces the complexity of key management
It ensures the private key is always available
Evaluate the effectiveness of using a third-party key management service in a large organization.
It eliminates the need for encryption
It centralizes key management, reducing the risk of key loss
It increases the complexity of encryption algorithms
It requires each user to manage their own keys
Consider the example of Alice and Bob. Why is it important for Alice to keep her private key secure?
To ensure Bob can encrypt messages to her
To prevent unauthorized decryption of messages intended for her
To allow others to verify her identity
To enable the generation of new public keys
What is the role of randomization in the key generation process for asymmetric encryption?
It ensures the keys are identical
It increases the speed of key generation
It enhances the security by making keys unpredictable
It simplifies the encryption process
Why is it computationally infeasible to derive a private key from a public key in asymmetric encryption?
Because the keys are stored in different locations
Because the mathematical relationship between the keys is complex
Because the public key is encrypted
Because the private key is never shared
Discuss the implications of a compromised private key in a PKI system.
It allows unauthorized users to encrypt data
It allows unauthorized users to decrypt data
It prevents the use of the public key
It requires the generation of a new public key
How does the use of large prime numbers contribute to the security of asymmetric encryption?
It makes the encryption process faster
It simplifies the key management process
It increases the difficulty of factoring the keys
It reduces the size of the keys
Propose a method to enhance the security of private key storage.
Store the private key on a public server
Use a password to protect the private key
Share the private key with trusted colleagues
Use the same private key for multiple users
What is the primary purpose of data at rest encryption?
To encrypt data while it is being transmitted over a network.
To encrypt data stored on devices such as SSDs and hard drives.
To encrypt data in a database.
To encrypt data using public algorithms.
Which of the following is a method of file-level encryption in Windows?
BitLocker
FileVault
EFS (Encrypting File System)
IPsec
Explain how column-level encryption can improve database performance compared to full database encryption.
It encrypts all data, reducing the need for decryption.
It encrypts only sensitive columns, allowing non-sensitive data to remain in plain text for faster searches.
It uses asymmetric keys for faster encryption.
It compresses data before encryption to save space.
What is the role of a VPN in data in transit encryption?
To encrypt data stored on a hard drive.
To create an encrypted tunnel for secure communication between sites or remote users.
To encrypt individual files on a computer.
To provide a public key for encryption.
Discuss the trade-offs involved in choosing an encryption algorithm.
Security level, speed, and complexity of implementation.
Cost, availability, and user-friendliness.
Color, size, and shape.
Brand, warranty, and customer service.
Why is the secrecy of the encryption key more important than the secrecy of the algorithm?
Because algorithms are always secret and never shared.
Because knowing the algorithm does not grant access without the correct key.
Because keys are easier to remember than algorithms.
Because algorithms are less secure than keys.
How does key strengthening increase resistance to brute force attacks?
By using shorter keys.
By performing the encryption or hashing process multiple times.
By using weaker algorithms.
By storing keys in plain text.
Evaluate the effectiveness of using longer keys in encryption.
Longer keys are less secure and easier to break.
Longer keys provide more resistance to brute force attacks.
Longer keys are faster to process.
Longer keys are only useful for symmetric encryption.
What is the main advantage of using AES over DES?
AES is slower but more secure.
AES uses a smaller key size.
AES supports multiple versions for varied security levels.
AES is a symmetric key algorithm.
Describe a scenario where file-level encryption would be more appropriate than full disk encryption.
When encrypting an entire hard drive is necessary.
When only specific files or folders need to be encrypted for security.
When encrypting data in transit.
When using a VPN for secure communication.
What is the primary function of HTTPS in data in transit encryption?
To encrypt data stored on a server.
To encrypt web traffic between a browser and web servers.
To encrypt emails.
To encrypt database entries.
How does algorithm transparency contribute to the robustness of encryption techniques?
By keeping the algorithm secret from everyone.
By allowing public scrutiny and trust in the algorithm's security.
By making the algorithm more complex.
By reducing the need for encryption keys.
Analyze the impact of processing power on the required key length for encryption.
As processing power increases, shorter keys become more secure.
As processing power increases, longer keys may be required for continued security.
Processing power has no impact on key length.
Processing power only affects symmetric encryption.
What is the main difference between symmetric and asymmetric keys in encryption?
Symmetric keys are always longer than asymmetric keys.
Symmetric keys use the same key for encryption and decryption, while asymmetric keys use a pair of keys.
Asymmetric keys are faster than symmetric keys.
Symmetric keys are only used for database encryption.
Propose a method to enhance the security of a database containing sensitive information.
Use full disk encryption for the server.
Implement column-level encryption for sensitive data.
Use a VPN for all database connections.
Store all data in plain text for easy access.
What is the primary purpose of data at rest encryption?
To encrypt data while it is being transmitted over a network.
To encrypt data stored on devices such as SSDs and hard drives.
To encrypt data in a database.
To encrypt data using public algorithms.
Which of the following is an example of full disk encryption on Mac OS?
BitLocker
FileVault
EFS
TrueCrypt
Explain how column-level encryption can improve database performance compared to transparent encryption.
Column-level encryption encrypts all data, reducing the need for decryption.
Column-level encryption only encrypts sensitive columns, allowing non-sensitive data to remain in plain text, which speeds up searches.
Column-level encryption uses asymmetric keys, which are faster than symmetric keys.
Column-level encryption is not related to performance improvements.
Describe a scenario where data in transit encryption is crucial.
When storing data on a local hard drive.
When accessing a website over HTTPS to protect web traffic.
When encrypting a database column.
When using a symmetric key for file encryption.
What is the role of algorithm transparency in encryption?
It ensures that encryption keys are kept secret.
It makes encryption algorithms public, increasing trust in their robustness.
It hides the encryption process from users.
It allows for faster encryption and decryption processes.
Why is key secrecy more important than algorithm secrecy in encryption?
Because knowing the algorithm does not help if the key is unknown.
Because algorithms are always secret.
Because keys are easier to guess than algorithms.
Because algorithms are more complex than keys.
How does key length affect the security of an encryption system?
Longer keys make encryption faster.
Longer keys are more resistant to brute force attacks.
Longer keys are less secure.
Key length does not affect security.
What is the main advantage of using AES over DES?
AES uses a shorter key length.
AES is faster and more secure than DES.
AES is easier to implement.
AES is less complex than DES.
Discuss the trade-offs involved in choosing an encryption algorithm.
Only security level matters.
Considerations include security level, speed, and complexity of implementation.
Only speed is important.
Complexity of implementation is the only factor.
What is the purpose of key strengthening techniques?
To make encryption keys shorter.
To increase resistance to brute force attacks by adding computational overhead.
To simplify the encryption process.
To reduce the need for encryption keys.
How does a VPN protect data in transit?
By encrypting data stored on a device.
By creating an encrypted tunnel for secure communication.
By using file-level encryption.
By encrypting database columns.
Why is it important for both parties to agree on the same encryption algorithm?
To ensure that data is stored securely.
To ensure successful encryption and decryption.
To make the encryption process faster.
To reduce the complexity of the encryption process.
Evaluate the impact of processing power on key length requirements.
Increased processing power allows for shorter keys.
Increased processing power necessitates longer keys for continued security.
Processing power does not affect key length.
Longer keys are only needed for asymmetric encryption.
What is the difference between full disk encryption and file-level encryption?
Full disk encryption encrypts individual files, while file-level encryption encrypts the entire disk.
Full disk encryption encrypts the entire storage device, while file-level encryption encrypts individual files or folders.
Full disk encryption is faster than file-level encryption.
There is no difference between the two.
How does brute force attack resistance relate to key length in encryption?
Shorter keys are more resistant to brute force attacks.
Longer keys are more resistant to brute force attacks.
Key length does not affect brute force attack resistance.
Only asymmetric keys are resistant to brute force attacks.
What is the primary function of a Trusted Platform Module (TPM)?
To manage encryption keys across different platforms
To provide redundancy in data centers
To perform cryptographic functions on individual machines
To act as a dedicated security processor in devices
Which of the following is a feature of a Hardware Security Module (HSM)?
Boot ROM that monitors the boot process
Supports cryptographic accelerators for real-time encryption
Automatic key rotation for security
True random number generator for cryptographic security
What is a key feature of Key Management Systems (KMS)?
Automatic key rotation for security
AES encryption in hardware to protect stored data
Secure storage of encryption keys for web servers
Real-time encryption of data in memory
What challenge is associated with data security?
Data does not require continuous protection
Data is widely distributed across multiple devices
Attackers are not evolving their techniques
Data is always static and easy to protect
What is a feature of a Secure Enclave?
Organizes various types of keys
Boot ROM that monitors the boot process
Associates keys with users in the software
Provides redundancy in power supplies
Which hardware component is designed for cryptographic functions on modern motherboards?
Secure Enclave
Key Management Systems (KMS)
Hardware Security Module (HSM)
Trusted Platform Module (TPM)
Why is it important to locate hardware in secure locations?
To ensure easy access for all employees
To reduce the cost of the hardware
To protect against physical theft and tampering
To improve the hardware's performance
A portable laptop is running Windows 10 Pro. A user enables BitLocker on Drive D.
Which of the following statements is true?
If the user copies of filed to a network share, it remains encrypted.
If the user copies a file to an unencrypted USB drive, the file remains encrypted.
The files will be automatically
decrypted when the drive is installed in another computer
All of these statements are true
None of these statements are true
What is encrypted by BitLocker?
Only email contents
Only operating system files
Only user files
The entire contents of the operating system partition
Lorrine will be traveling for two weeks. For security purposes, she wants to encrypt the entire drive of her Windows computer before she leaves. What should she use?
KeePass
Bitlocker
Last Pass
Password Manager
A portable laptop running WIndows 10 Pro. A user enables BitLocker on Drive D.
Type yes or no for this statement.
If the user copies the file to a network share, it will remain encrypted.
(a)
Which of the following type of solutions would you classify an FPGA as?
Hardware security module
Trusted platform module
Anti-tamper
Root of trust
Which of the following is a characteristic of symmetric encryption?
It uses a pair of keys: one public and one private.
It uses the same key for both encryption and decryption.
It is slower than asymmetric encryption.
It is primarily used for digital signatures.
What is the main advantage of using public key infrastructure (PKI)?
It eliminates the need for encryption.
It provides a framework for managing digital certificates and keys.
It speeds up the encryption process.
It reduces the size of encrypted data.
In asymmetric encryption, what is the role of the private key?
It is used to encrypt data.
It is used to decrypt data.
It is used to generate a hash.
It is used to compress data.
Which of the following is a key management practice?
Using the same key for all users
Regularly rotating encryption keys
Storing keys in plain text
Sharing keys over unsecured channels
What is encryption?
A person who tricks you into giving your password
converting information or data into a code to prevent unauthorized access.
To upload your personal data to the cloud
When there is a security breach in your data
The human resources organization want to ensure that stored employee data is encrypted. Which security mechanism would they use?
Hashing
Encryption in transit
Encryption at rest
What is the primary purpose of obfuscation?
To delete sensitive data
To compress data
To make information more difficult to understand
To encrypt data
What does the term 'steganography' mean?
Data encryption
Hidden writing
Data compression
Public key cryptography
Which of the following is NOT a method of steganography?
Audio & Video Steganography
Data Masking
Network Traffic Steganography
Image Steganography
What is tokenization primarily used for?
Compressing data
Deleting data
Replacing sensitive data with a token
Encrypting data
In data masking, which of the following is a common technique?
Encrypting the entire data
Deleting the data
Using asterisks to replace parts of the number
Compressing the data
What is a security advantage of tokenization?
Tokens are encrypted
Tokens can be reused multiple times
Tokens cannot be reused if intercepted
Tokens are stored in plain text
Which of the following statements is true about data masking?
It conceals portions of sensitive information
It compresses data for storage
It encrypts the entire data
It deletes sensitive data
What is a Steganography
A Dinosaur
A Software that draws Graphs
A way of concealing text
A type of malware
A technical is assigned to harden a laptop for a medical practice. which of the following should be used to protect PII in the event of hardware theft?
Hard drive encription
Disable bluetooth
password expiration
Host based firewall
Which of the following methods is used to replace all or part of a data field with a randomly generated number used to reference the original value stored in another vault or database?
Tokenization
Anonymization
Data masking
Data minimization
A technician is assigned to harden a laptop for a medical practice. Which of the following should be used to protect PII in the event of hardware theft?
Hard drive encription
Disable bluetooth
password expiration
Host based firewall
A technician is assigned to harden a laptop for a medical practice. which of the following should be used to protect PII in the event of hardware theft?
Hard drive encription
Disable bluetooth
password expiration
Host based firewall
Companies must make clear what they are doing with the personal information is a part of
Statement of Notice
Statement of Choice
Statement of access
Statement of security
When you purchase an exam voucher at diontraining.com, the system only collects your name, email, and credit card information. Which of the following privacy methods is being used by Dion Training?
Anonymization
Data minimization
Data masking
Tokenization
Token-based authentication typically uses which of the following?
A physical device
A knowledge of personal information
A biometric scan
A password
