Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

MCyber_Chap22N23

Total questions: 22

Worksheet time: 22mins

Name
Class
Date
1.
What law protects the privacy of an employee’s personal information from being shared with third parties?
a)
SOX
b)
GLBA
c)
PCI DSS
d)
FIRPA
2.
What is the primary goal of IT security governance?
a)
To provide a set of policies and procedures to manage sensitive data
b)
To provide oversight to ensure that risks are adequately mitigated
c)
To define a set of controls that an organization should implement
d)
To make decisions to mitigate risk
3.
An organization has experienced several incidents involving employees downloading unauthorized software and using unauthorized websites and personal USB devices. What measures could the organization implement to manage these threats? (Choose three correct answers)
a)
Implement disciplinary action
b)
Monitor all employee activity
c)
Disable USB access
d)
Provide security awareness training
e)
Use content filtering
4.
What federal act law would an individual be subject to if they knowingly accessed a government computer without permission?
a)
CFAA
b)
GLBA
c)
ECPA
d)
SOX
5.
What do penetration tests and red team exercises achieve?
a)
They simulate attacks to gauge the security capabilities of an organization.
b)
They provide audit controls for all NetBIOS connections made.
c)
They provide a list of malware that has successfully penetrated the firewall.
d)
They provide audit trails for all TCP connections in place at any given time.
6.
Which of the following frameworks identifies controls based on the latest information about common cyber attacks and provides benchmarks for various platforms?
a)
CSA
b)
The National Cybersecurity Workforce
c)
CIS
d)
ISO
7.
The ability to carry out highly specialized review and evaluation of incoming cybersecurity information to determine if it is useful for intelligence is covered in what category of the National Cybersecurity Workforce Framework?
a)
Protect and defend
b)
Oversight and development
c)
Security provision
d)
Analyze
8.
What act protects the personal information of students in schools?
a)
HIPPA
b)
FERPA
c)
CIPA
d)
COPPA
9.
Which of the following principles is used by the U.S. government in its access control models?
a)
Job rotation
b)
Separation of duties
c)
Need to know
d)
Mandatory vacations
10.
What is the function of the Cloud Security Alliance (CSA)?
a)
It provides security guidance to any organization that uses cloud computing.
b)
It audits the CIA Triad objectives
c)
It produces a statement of applicability (SOA) which stipulates control objectives and audit controls to be implemented.
d)
It ensures total compliance with the ISO 27000 standards.
11.
Which cybersecurity weapon scans for use of default passwords, missing patches, open ports, misconfigurations, and active IP addresses?
a)
Packet analyzers
b)
Vulnerability scanners
c)
Packet sniffers
d)
Password crackers
12.
The laptop of an attacker is attached to a corporate network. The attacker is examining all of the network traffic that is passing through the network interface card. Which network reconnaissance method does this scenario describe?
a)
Penetration exercise
b)
Red team blue team
c)
Sniffing
d)
Bug bounty
13.
What describes a feature of credentialed scans?
a)
They are less invasive than non-credentialed scans.
b)
They try to exploit vulnerabilities and may even crash the target.
c)
They return fewer false positives and fewer false negatives
d)
They do not require usernames and passwords to provide authorized access to a system.
14.
How does network scanning help assess operations security?
a)
It can detect open TCP ports on network systems.
b)
It can detect weak or blank passwords.
c)
It can simulate attacks from malicious sources.
d)
It can log abnormal activity
15.
What network security testing tool has the ability to provide details on the source of suspicious network activity?
a)
Tripwire
b)
Zenmap
c)
SIEM
d)
Superscan
16.
A new person has joined the security operations team for a manufacturing plant. What is a common scope of responsibility for this person?
a)
Managing redundancy operations for all systems
b)
Data security on host devices
c)
Physical and logical security of all business personnel
d)
Day-to-day maintenance of network security
17.
Which penetration test phase is concerned with conducting reconnaissance to gain information about the target network or device?
a)
Attack
b)
Discovery
c)
Reporting
d)
Planning
18.
What network testing tool is used for password auditing and recovery?
a)
Metasploit
b)
SuperScan
c)
Nessus
d)
L0phtcrack
19.
An administrator is troubleshooting NetBIOS name resolution on a Windows PC. What command line utility can be used to do this?
a)
nbtstat
b)
Ipconfig
c)
Arp
d)
Netstat
20.
What network scanning tool has advanced features that allows it to use decoy hosts to mask the source of the scan?
a)
Nessus
b)
Metasploit
c)
Tripwire
d)
Nmap
21.
A new technician was overheard telling colleagues that a secure network password had been discovered through a search of social media sites. What technique was used to acquire the password?
a)
Passive reconnaissance
b)
Man-in-the-middle
c)
Active reconnaissance
d)
Buffer overflow
e)
Brute force
22.
Which approach provides automated tools allowing an organization to collect data about security threats from various sources?
a)
SuperScan
b)
Nmap
c)
SOAR
d)
Netcat