Font size
WorksheetsIS 404 - Final Exam
Total questions: 100
Worksheet time: 50mins
What is cryptography primarily used for?
Data compression
Data visualization
Securing information and communications using codes
Data duplication
The prefix “crypt” means ______.
Writing
Hidden
Code
Message
Individuals who practice cryptography are called ______.
Cryptologists
Cryptographers
Programmers
Hackers
What does “confidentiality” ensure?
Only authorized individuals can access information
Data is readable to all users
Messages can be modified anytime
Encryption keys are shared publicly
Which type of cryptography uses the same key for encryption and decryption?
Symmetric Key Cryptography
Asymmetric Key Cryptography
Hashing
Digital Signatures
What is used to verify the identity of a sender and receiver?
Confidentiality
Authentication
Integrity
Non-repudiation
What does “encryption” mean?
Converting readable data into coded form
Sending data to multiple users
Copying the data for backup
Deleting sensitive information
What is a cipher in cryptography?
A. A file storage method
B. A type of virus
C. A method to convert plaintext into ciphertext
D. A data compression tool
What does a substitution cipher do?
Replaces characters with other characters using a rule
Rearranges characters in a message
Deletes letters from the text
Converts characters to binary code
What does a transposition cipher do?
Replaces letters with symbols
Rearranges the order of characters to encrypt data
Converts numbers into letters
Uses mathematical equations to encrypt data
The message “HELLO” becomes “LOHEL.” What cipher was used?
Substitution Cipher
Transposition Cipher
Modern Cipher
Hash Function
Why is symmetric cryptography considered risky?
It is too complicated to use
The shared key could be stolen during exchange
It cannot encrypt large data
It requires both public and private keys
Why are modern ciphers considered more secure than classical ones?
They use complex mathematical algorithms and computer processing
They use only alphabet shifts
They require no keys
They are easier to decode
Which statement best describes asymmetric key cryptography?
Uses a single shared key
Uses two keys: one public for encryption and one private for decryption
Requires no keys at all
Uses mathematical hashing only
Which key system uses one key for both encryption and decryption?
Symmetric Key Cryptography
Asymmetric Key Cryptography
Hash Function
Public Key System
What happens if even a small change is made to input data in a hash function?
The same hash output will appear
The hash output will change completely
The system will reject the input
The function will stop working
In asymmetric encryption, if everyone has access to your public key, why is your data still safe?
Because public keys change constantly
Because only your private key can decrypt the message
Because public keys are secret
Because the sender signs the message
What is a substitution cipher?
It replaces characters with other characters using a rule
It rearranges characters in a different order
It deletes letters from the message
It converts the text into binary
You uploaded a file, and the system generated an SHA-256 value. Later, you check the file again, and the hash value changed. What does this indicate?
The file was modified or corrupted
The file was safely encrypted
The file is too large for hashing
The encryption key expired
In a Caesar Cipher, if each letter is shifted by 3, what is the encrypted version of "CAT"?
ZXR
BAT
FDW
EAT
Which cryptographic method is most suitable for verifying passwords during login without storing the actual password?
Symmetric key encryption
Asymmetric encryption
Hash functions
Transposition cipher
You rearrange "CRYPTO" into "TOCRYP." Which cipher was used?
Substitution Cipher
Transposition Cipher
Modern Cipher
Public Key Cipher
Which of the following transformations best describes a transposition cipher operation?
"DATA" → "EDTA"
"DATA" → "GDUD"
"DATA" → "ATAD"
"DATA" → "DATE"
What does IAM stand for?
Information Access Management
Identity and Access Management
Integrated Account Management
Internal Authentication Mechanism
What is the main goal of IAM?
To restrict all users from accessing data
To ensure users can access the right resources for the right reasons
To manage computer viruses
To back up organizational data
Which of the following is not one of the four pillars of IAM?
Authentication
Authorization
Administration
Application
What is a digital identity?
A user's physical ID card
A collection of attributes tied to a specific user or entity
A temporary password
An antivirus code
Which type of authentication uses fingerprints or facial recognition?
Token-based
Password-based
Biometric-based
Certificate-based
What type of access control allows users to define their own permissions?
Role-based
Mandatory
Discretionary
Attribute-based
How does authentication differ from authorization?
Authentication verifies identity; authorization defines access rights.
Authentication defines access rights; authorization verifies identity.
What is the purpose of identity administration?
To manage user identities throughout their lifecycle.
To encrypt all passwords.
To install antivirus software.
To monitor network traffic.
Why is auditing important in IAM systems?
It checks whether users are productive.
It ensures IAM components work properly and detects misuse.
It speeds up internet connectivity.
It automatically grants all users access.
What type of authentication uses digital certificates?
Token-based
Biometric-based
Certificate-based
Password-based
Which access control model is based on job roles?
MAC
RBAC
DAC
ABAC
Which access control model relies on the security clearance of the user?
Mandatory Access Control (MAC)
Role-Based Access Control (RBAC)
Discretionary Access Control (DAC)
Attribute-Based Access Control (ABAC)
Which of the following is NOT a type of authentication?
Password-based
Encryption-based
Token-based
Biometric-based
Which statement best describes attribute-based access control (ABAC)?
Access depends on the user’s role.
Access is based on attributes like time, user, and resource type.
Access is granted to everyone by default.
Access is only allowed to administrators.
Which of the following best defines “authorization”?
The process of verifying identity
The process of granting or denying access to resources
The process of changing passwords
The process of logging user actions
Why might an organization use role-based access control (RBAC)?
To assign identical access to all users
To allow employees to define their own permissions
To assign permissions according to job responsibilities
To grant full access to administrators only
What is the primary weakness of password-based authentication?
It is expensive
It is vulnerable to human error and password reuse
It automatically deletes inactive accounts
It hides users’ login attempts
Why is auditing critical in cybersecurity?
It reduces system performance
It detects unauthorized access and misuse attempts
It automatically deletes inactive accounts
It hides users’ login attempts
A user logs in using a password and a verification code sent to their phone. What type of authentication is this?
Password-only
Multi-factor authentication
Biometric authentication
Certificate-based authentication
If a system logs every user login and logout, which IAM pillar is applied?
Authorization
Auditing
Administration
Authentication
A bank wants to ensure tellers can only view account data, not edit it. Which control is appropriate?
Role-based access control
Attribute-based access control
Mandatory access control
Discretionary access control
You are asked to identify who accessed a restricted file. Which IAM pillar provides this data?
Authorization
Auditing
Authentication
Administration
If a company wants to apply IAM, which sequence best represents the flow of access control?
Auditing → Authorization → Authentication → Administration
Authentication → Authorization → Auditing → Administration
Administration → Authentication → Authorization → Auditing
Authorization → Administration → Auditing → Authentication
A university wants to verify student logins through facial recognition. What authentication method is used?
Biometric authentication
Token-based authentication
Password-based authentication
Certificate-based
Which type of cloud is hosted by a third-party provider and shared among multiple users?
Public cloud
Private cloud
Hybrid cloud
Open-source cloud
What does Software as a Service provide?
System management tools
Applications hosted by a third party and accessed through a web browser
Hardware maintenance services
Internet connection for business
What does Platform as a Service provide?
Email and communication apps
Tools and computing infrastructure mainly for developers
File storage and backup
Operating system updates
What does Infrastructure as a Service provide?
Email hosting services
Web development tools
Virtualized computing resources like networks and storage
Security monitoring
What does “jailbreaking” or “rooting” do?
Removes system restrictions and weakens security
Makes the device waterproof
Upgrades device firmware automatically
Protects device from malware
What does “phishing” aim to do?
Improve mobile network speed
Trick users into revealing sensitive information
Remove malware from phones
Secure Wi-Fi networks
What type of control limits the damage after a cyberattack occurs?
Preventive control
Detective control
Deterrent control
Corrective control
Which tool acts as a security “gatekeeper” between users and cloud services?
Cloud Workload Protection Platform
Cloud Access Security Broker
Cloud Security Posture Management
Virtual Private Network
Mobile security mainly protects:
Smartphones, tablets, and laptops
Desktop computers only
Servers and databases
Websites and browsers
What is “juice jacking”?
Installing fake applications
Intercepting Wi-Fi networks
Using a compromised charging station to steal data
Sending phishing links via SMS
Which describes a cloned app?
A fake version of a legitimate app designed to steal information
An app that creates backups
A system app for data recovery
A verified app from the Play Store
Which practice strengthens mobile security?
Ignoring software updates
Regularly updating apps and OS
Using public Wi-Fi for faster speed
Saving passwords on browsers
Why are hybrid clouds popular among organizations?
They are cheaper than private clouds
They combine benefits of both public and private clouds
They require no internet connection
They are easier to secure
Which control type identifies and reacts to security threats?
Preventive control
Detective control
Corrective control
Deterrent control
Which cloud risk results from not being able to see all cloud assets?
Lack of visibility
Access management
Misconfiguration
Compliance
What makes mobile phishing dangerous?
It only targets social media
Mobile users are distracted and see limited screen information
It cannot bypass antivirus
It only affects Android devices
What is the risk of jailbreaking or rooting?
Improved device speed
Disabling built-in security protections
Better customization
Access to official apps
Why should users avoid public Wi-Fi?
It is slow
It costs too much
Hackers can intercept and manipulate data
It drains battery faster
A company wants to develop apps without managing servers. Which cloud service model should they use?
Infrastructure as a Service
Platform as a Service
Software as a Service
Cloud Workload Protection Platform
A business detects unusual login activity from multiple locations. Which control type helps identify such threats?
Detective control
Corrective control
Deterrent control
Preventive control
An organization that hosts both private and public applications is using:
Private cloud
Hybrid cloud
Community cloud
Multi-tenant cloud
When a user installs a fake banking app that steals credentials, what threat is this?
Malware (Trojan)
Juice jacking
Phishing
Ransomware
A company needs to track cloud configurations and ensure compliance. Which tool is most appropriate?
Cloud Workload Protection Platform
Cloud Access Security Broker
Cloud Security Posture Management
Virtual Private Network
A company stores customer data on Amazon Web Services (AWS) and uses Gmail for business emails. Which setup is this?
Private cloud
Hybrid cloud
Public cloud
Community cloud
You’re downloading an app that asks for access to your camera and contacts, but it’s a calculator app. What should you do?
Cancel the installation
Accept the permissions
Restart your phone
Turn off Wi-Fi
A new app promises to clean your phone and speed it up but is not from the official app store. You should:
Avoid installing it temporarily
Install and test it
Disable antivirus
Restart the phone first
Which of the following is the first stage of an IT compliance audit?
Preparation
Fieldwork
Audit Report
Follow-Up
What does Data Management and Protection ensure?
That data is accessible to everyone
That data is stored, encrypted, and backed up securely
That data is deleted monthly
That data is transferred to external parties
What is the difference between internal and external audits?
Internal audits are more expensive
External audits are done by company employees
Internal audits are performed by company staff; external audits by independent parties
Both are conducted by the HR department
What is a possible limitation of internal audits?
They take too long to finish
They are too strict
They cost too much
Internal teams may overlook certain risks
What advantage do external audits provide?
They reduce employee workload
They replace company security systems
They offer objective and unbiased evaluations
They stop all cybersecurity attacks
Why is incident response planning reviewed in an IT audit?
To check marketing procedures
To ensure there’s a clear plan for handling data breaches and security incidents
To reduce internet costs
To monitor employee attendance
When auditors assess data encryption, which area are they reviewing?
Risk assessment
Data management and protection
Incident response
Access control
A company finds that employees are sharing passwords. During an IT compliance audit, which area will this fall under?
Data management
Access and Identity Control
Risk assessment
Physical security
During fieldwork, auditors discover that backup systems are not updated regularly. What should the company improve?
Automation tools
Data Management and Protection
Marketing strategy
Office layout
Auditors found that anyone could enter the server room without ID verification. This is a failure in:
Data protection
Automation
Physical Security
Access control
After receiving an audit report, management creates a new password policy and trains staff. This is part of which stage?
Preparation
Fieldwork
Audit Report
Follow-Up
The auditor checks whether the company uses encryption for storing sensitive client data. What is this an example of?
Fieldwork stage
Preparation stage
Audit report
Follow-up
Network security focuses on protecting the network infrastructure from unauthorized access, misuse, or theft.
True
False
A firewall can block or allow traffic based on security rules.
True
False
Packet-filtering firewalls examine the full content of data packets to detect malicious code.
True
False
Stateful inspection firewalls remember active connections and track whether network traffic is part of a valid session.
True
False
A circuit-level gateway checks the content of data packets to detect hidden malware. False
True
False
Intrusion Prevention Systems (IPS) only detect attacks but do not take any action to block them.
True
False
Intrusion Detection Systems (IDS) are designed to actively block threats before they reach the network.
True
False
Network segmentation divides a large network into smaller subnetworks to improve performance and security.
True
False
A guest Wi-Fi network that provides internet access only is an example of network segmentation.
True
False
An application-level gateway reads the entire message content before allowing communication.
True
False
A VPN hides the user’s IP address and encrypts internet traffic for privacy.
True
False
A Stateful Inspection Firewall acts like a guard who not only checks your ID but also remembers if you’ve already entered before.
True
False
. A Circuit-Level Gateway is like a telephone operator ensuring that the call connection is properly established before letting the people talk.
True
False
The Circuit-Level Gateway focuses on the data’s content rather than the connection setup.
True
False
A Packet-Filtering Firewall reads the full content of the message to make sure it’s safe before delivery.
True
False
