wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Test Your Skills — Multiple Choice Questions

Total questions: 139

Worksheet time: 1hrs 10mins

Name
Class
Date
1.

You are trying to explain security to a nontechnical manager. She has taken a rather extreme view of computer security. Which of the following is one of the extreme viewpoints about computer security discussed in this chapter?

a)

The federal government will handle security.

b)

Microsoft will handle security.

c)

There are no imminent dangers to your system.

d)

There is no danger if you use Linux.

2.

You have just taken over as network security administrator for a small community college. You want to take steps to secure your network. Before you can formulate a defense for a network, what do you need?

a)

Appropriate security certifications

b)

A clear picture of the dangers to be defended against

c)

To finish this textbook

d)

The help of an outside consultant

3.

Mary is teaching an introductory cybersecurity course to freshmen. She is explaining to them the major threats. Which of the following is not one of the three major classes of threats?

a)

Attempts to intrude on the system

b)

Online auction fraud

c)

Denial of service attacks

d)

A computer virus

4.

Being able to define attack terms is an important skill for a cybersecurity professional. What is a computer virus?

a)

Any program that is downloaded to your system without your permission

b)

Any program that self-replicates

c)

Any program that causes harm to your system

d)

Any program that can change your Windows Registry

5.

Being able to define attack terms is an important skill for a cybersecurity professional. What is spyware?

a)

Any software that monitors your system

b)

Only software that logs keystrokes

c)

Any software used to gather intelligence

d)

Only software that monitors what websites you visit

6.

What is a penetration tester?

a)

A person who hacks a system without being caught

b)

A person who hacks a system by faking a legitimate password

c)

A person who hacks a system to test its vulnerabilities

d)

A person who is an amateur hacker

7.

Elizabeth is explaining various hacking terms to a class. She is in the process of discussing the history of phone system hacking. What is the term for hacking a phone system?

a)

Telco-hacking

b)

Hacking

c)

Cracking

d)

Phreaking

8.

What is malware?

a)

Software that has some malicious purpose

b)

Software that is not functioning properly

c)

Software that damages your system

d)

Software that is not properly configured for your system

9.

What is war-driving?

a)

Driving and seeking a computer job

b)

Driving while using a wireless connection for hacking

c)

Driving looking for wireless networks to hack

d)

Driving and seeking rival hackers

10.

What is the name for the hacking technique that involves using persuasion and deception to get a person to provide information to help compromise security?

a)

Social engineering

b)

Conning

c)

Human intel

d)

Soft hacking

11.

There are many threats on the Internet. Which one is currently the most common may change over time, but certain threats have always been more common than others. Which of the following is the most common threat on the Internet?

a)

Auction fraud

b)

Phreaking

c)

Computer viruses

d)

Illegal software

12.

What are the three approaches to security?

a)

Perimeter, layered, hybrid

b)

High security, medium security, low security

c)

Internal, external, and hybrid

d)

Perimeter, complete, none

13.

Defining your security strategy is an important step in securing a network. You are trying to classify devices based on the approach they take to security. An intrusion detection system is an example of which of the following?

a)

Proactive security

b)

Perimeter security

c)

Hybrid security

d)

Good security practices

14.

Which of the following is the most basic security activity?

a)

Authentication

b)

Firewalls

c)

Password protection

d)

Auditing

15.

The most desirable approach to security is one that is which of the following?

a)

Perimeter and dynamic

b)

Layered and dynamic

c)

Perimeter and static

d)

Layered and static

16.

As of 2022, which of the following is the fastest-growing target for cyber attacks?

a)

IoT

b)

Servers

c)

Laptops

d)

USB devices

17.

Which of the following types of privacy law affects computer security?

a)

Any state privacy law

b)

Any privacy law applicable to your organization

c)

Any privacy law

d)

Any federal privacy law

18.

The first computer incident-response team is affiliated with what university?

a)

Massachusetts Institute of Technology

b)

Carnegie Mellon University

c)

Harvard University

d)

California Technical University

19.

Which of the following is the best definition of the term sensitive information?

a)

Any information that has an impact on national security

b)

Any information that is worth more than $1,000

c)

Any information that, if accessed by unauthorized personnel, could damage your organization in any way

d)

Any information that is protected by privacy laws

20.

Which of the following is the best description of doxing?

a)

A DoS malware attack

b)

Framing someone for a crime

c)

Putting personal information out in the public domain

d)

Stealing personal information

21.

Malek is purchasing cable to use in setting up small office networks. He wants to stock up on commonly used cable. What type of cable do most networks use?

a)

Net cable

b)

STP

c)

Phone cable

d)

UTP

22.

You are assigned to attach connectors to segments of cable. What type of connector is used with network cables?

a)

RJ-11

b)

RJ-85

c)

RJ-12

d)

RJ-45

23.

What type of cable is used in most networks?

a)

Unshielded twisted-pair

b)

Shielded twisted-pair

c)

Unshielded untwisted-pair

d)

Shielded untwisted-pair

24.

John is trying to simply connect three computers in a small network. He does not need any sort of routing capability and is not concerned about network traffic. What is the simplest device for connecting computers?

a)

NIC

b)

Interface

c)

Hub

d)

Router

25.

Sharice is trying to teach a new technician basic networking terms. What should she tell this new technician NIC stands for?

a)

Network interface card

b)

Network interaction card

c)

Network interface connector

d)

Network interaction connector

26.

Which of the following is a device used to connect two or more networks?

a)

Switch

b)

Router

c)

Hub

d)

NIC

27.

Juan has just installed a new T1 line in a medical office. The front desk receptionist has asked what speed they can expect. A T1 line sends data at what speed?

a)

100Mbps

b)

1.54Mbps

c)

155Mbps

d)

56.6Kbps

28.

Which of the following best describes polycloud?

a)

Using a private and public cloud

b)

Using cloud and local resources

c)

Using more than one cloud provider for resilience and redundancy

d)

Using more than one cloud provider for the services offered

29.

What protocol translates web addresses into IP addresses?

a)

DNS

b)

TFTP

c)

DHCP

d)

SMTP

30.

What protocol is used to send email, and on what port does it work?

a)

SMTP, port 110

b)

POP3, port 25

c)

SMTP, port 25

d)

POP3, port 110

31.

Gunther is setting up encrypted remote communications so that the server administrators can remotely access servers. What protocol is used for remotely logging on to a computer in a secure manner?

a)

SSH

b)

HTTP

c)

Telnet

d)

SMTP

32.

Mohammed needs to open a firewall port so that web traffic can be passed through the firewall. What protocol is used for web pages, and on which port does it work?

a)

HTTP, port 21

b)

HTTP, port 80

c)

DHCP, port 80

d)

DHCP, port 21

33.

What is the name for the point where the backbones of the Internet connect?

a)

Connectors

b)

Routers

c)

Network access points

d)

Switches

34.

You are examining a list of IP addresses. Some are internal, some are external, and some are not valid. Which of the following is not a valid IP address?

a)

127.0.0.1

b)

295.253.254.01

c)

131.156.5.2

d)

245.200.11.1

35.

What class of address is the IP address 193.44.34.122?

a)

A

b)

B

c)

C

d)

D

36.

The IP address 127.0.0.1 always refers to your what?

a)

Nearest router

b)

ISP

c)

Self

d)

Nearest NAP

37.

Internet addresses of the form www.chuckeasttom.com are called what?

a)

User-friendly web addresses

b)

Uniform resource locators

c)

User-accessible web addresses

d)

Uniform address identifiers

38.

Which U.S. government agency created the distributed network that formed the basis for the Internet?

a)

Advanced Research Projects Agency

b)

Central Intelligence Agency

c)

NASA

d)

Department of Energy

39.

Which of the following was one of the three universities involved in the original distributed network set up by a government agency?

a)

UC Berkeley

b)

Harvard

c)

MIT

d)

Princeton

40.

You are explaining the history of networking to a group of first-year students. What did Vint Cerf invent?

a)

The World Wide Web

b)

Email

c)

TCP

d)

The first computer virus

41.

You are explaining the history of networking to a group of first-year students. What did Tim Berners-Lee invent?

a)

The World Wide Web

b)

Email

c)

TCP

d)

The first computer virus

42.

John is working with command-line utilities to gather diagnostic information about a computer that cannot connect to the network. Which utility provides information about a machine’s network configuration?

a)

Ping

b)

IPConfig

c)

Tracert

d)

MyConfig

43.

Sheryl is explaining the OSI model to new technicians at her company. She is trying to explain what protocols operate at the various layers of the OSI model. At what layer of the OSI model does TCP operate?

a)

Transport

b)

Application

c)

Network

d)

Data link

44.

Which layer of the OSI model is divided into two sublayers?

a)

Data link

b)

Network

c)

Presentation

d)

Session

45.

Which of the following is a unique hexadecimal number that identifies your network card?

a)

NIC address

b)

MAC address

c)

NIC ID

d)

MAC ID

46.

Candice is discussing Internet fraud with a colleague. She is trying to explain the most common types of fraud. What is the term for the most common type of Internet investment fraud?

a)

The Nigerian fraud

b)

The Manhattan fraud

c)

The pump and dump

d)

The bait and switch

47.

You have become quite active in online investing. You want to get some advice but are concerned about the veracity of the advice you receive. What is the most likely problem with unsolicited investment advice?

a)

You might not earn as much as claimed.

b)

The advice might not be truly unbiased.

c)

The advice might not be from a legitimate firm.

d)

You might lose money.

48.

Juan is a security officer for an investment firm. He is explaining various scams to the brokers. What is the term for artificially inflating a stock in order to sell it at a higher value?

a)

Bait and switch

b)

The Nigerian fraud

c)

Pump and dump

d)

The Wall Street fraud

49.

What is the top rule for avoiding Internet fraud?

a)

If it seems too good to be true, it probably is.

b)

Never use your bank account numbers.

c)

Only work with people who have verifiable email addresses.

d)

Don’t invest in foreign deals.

50.

Which of the following is not one of the Security and Exchange Commission’s tips for avoiding investment fraud?

a)

Don’t invest online.

b)

Consider the source of an offer.

c)

Always be skeptical.

d)

Always research an investment.

51.

Aliya is active on online auctions but wants to avoid auction fraud. What are the four categories of auction fraud?

a)

Failure to send, failure to disclose, sending to wrong address, failure to deliver

b)

Failure to send, failure to disclose, sending something of lesser value, failure to deliver

c)

Failure to disclose, sending something to wrong address, failure to send, failure to deliver

d)

Failure to disclose, sending something of lesser value, failure to send, sending something of greater value

52.

What is the term for a seller bidding on her own item to drive up the price?

a)

Bid siphoning

b)

Bid shielding

c)

Shill bidding

d)

Ghost bidding

53.

What is the term for submitting a fake but very high bid to deter other bidders?

a)

Bid siphoning

b)

Bid shielding

c)

Shill bidding

d)

Ghost bidding

54.

What is typically the goal of identity theft?

a)

To make illicit purchases

b)

To discredit the victim

c)

To avoid criminal prosecution

d)

To invade privacy

55.

According to the U.S. Department of Justice, identity theft is generally motivated by what?

a)

Malicious intent

b)

Personal hostility toward the victim

c)

Economic gain

d)

Thrill seeking

56.

Clarence is a police detective with a small-town police department. He is trying to consider how seriously to take reports of cyber stalking. Why is cyber stalking a serious crime?

a)

It is frightening to the victim.

b)

It can be a prelude to violent crime.

c)

It is using interstate communication.

d)

It can be a prelude to identity theft.

57.

What is cyber stalking?

a)

Any use of the Internet to send or post threats

b)

Any use of electronic communications to stalk a person

c)

The use of email to send threats

d)

The use of email to stalk a person

58.

What do law enforcement officials usually require of a victim in order to pursue harassment allegations?

a)

A verifiable threat of death or serious injury

b)

A credible threat of death or serious injury

c)

A verifiable threat of harm

d)

A credible threat of harm

59.

If you are posting anonymously in a chat room and another anonymous poster threatens you with assault or even death, is this person’s post harassment?

a)

Yes; any threat of violence is harassment.

b)

Probably not because both parties are anonymous, so the threat is not credible.

c)

Yes; chat room threats are no different from threats in person.

d)

Probably not because making a chat room threat is not the same as making a threat in person.

60.

What must exist for cyber stalking to be illegal in a state or territory?

a)

Specific laws against cyber stalking in that state or territory

b)

Specific laws against cyber stalking in that nation

c)

Nothing; existing stalking laws can apply

d)

Nothing; existing international cyber stalking laws apply

61.

What is the first step in protecting yourself against identity theft?

a)

Never provide personal data about yourself unless absolutely necessary.

b)

Routinely check your records for signs of identity theft.

c)

Never use your real name on the Internet.

d)

Routinely check for spyware on your computer.

62.

What can you do on your local computer to protect your privacy?

a)

Install a virus scanner.

b)

Install a firewall.

c)

Set your browser’s security settings.

d)

Set your computer’s filter settings.

63.

What is a cookie?

a)

A piece of data that web servers gather about you

b)

A small file that contains data and is stored on your computer

c)

A piece of data that your web browser gathers about you

d)

A small file made that contains data and then is stored on the web server

64.

Which of the following is not an efficient method of protecting yourself from auction fraud?

a)

Only use auctions for inexpensive items.

b)

Only use reputable auction sites.

c)

Only work with well-rated sellers.

d)

Only bid on items that seem realistic.

65.

What is the top rule for chat room safety?

a)

Make certain you have antivirus software installed.

b)

Never use your real name or any real personally identifying characteristics.

c)

Only use chat rooms that encrypt transmissions.

d)

Use chat rooms that are sponsored by well-known websites or companies.

66.

Why is it useful to have a separate credit card dedicated to online purchases?

a)

If the credit card number is used illegally, you will limit your financial liability.

b)

You can keep better track of your auction activities.

c)

If you are defrauded, you can possibly get the credit card company to handle the problem.

d)

You can easily cancel that single card if you need to do so.

67.

What percentage of cyber stalking cases escalate to real-world violence?

a)

Fewer than 1%

b)

About 25%

c)

90% or more

d)

About 19%

68.

If you are a victim of cyber stalking, what should you do to assist the police?

a)

Nothing; it is their job, and you should stay out of it.

b)

Attempt to lure the stalker into a public place.

c)

Keep electronic and hard copies of all harassing communications.

d)

Try to provoke the stalker into revealing personal information about himself.

69.

What is the top way to protect yourself from cyber stalking?

a)

Do not use your real identity online.

b)

Always use a firewall.

c)

Always use a virus scanner.

d)

Do not give out email addresses.

70.

When considering the various attacks that can be executed on your system, it is important to understand which attacks are most common. Of the following, which is one of the most common and simplest attacks on a system?

a)

Denial of service attack

b)

Buffer overflow

c)

Session hacking

d)

Password cracking

71.

All DoS attacks are predicated on overwhelming a system’s workload capacity. Therefore, measuring the workload of a system is critical. Which of the following is not a valid way to define a computer’s workload?

a)

Number of simultaneous users

b)

Storage capacity

c)

Maximum voltage

d)

Speed of network connection

72.

What do you call a DoS attack launched from several machines simultaneously?

a)

Wide-area attack

b)

Smurf attack

c)

SYN flood

d)

DDoS attack

73.

It is important to understand the different types of DoS attacks and the symptoms of those attacks. Leaving a connection half open is a symptom of which type of attack?

a)

Smurf attack

b)

Partial attack

c)

SYN flood attack

d)

DDoS attack

74.

While there are a wide range of different ways to execute a DoS attack, they all are predicated on the same idea. What is the basic concept behind a DoS attack?

a)

Computers don’t handle TCP packets well.

b)

Computers can handle only a finite load.

c)

Computers cannot handle large volumes of TCP traffic.

d)

Computers cannot handle large loads.

75.

What is the most significant weakness in a DoS attack from the attacker’s viewpoint?

a)

The attack is often unsuccessful.

b)

The attack is difficult to execute.

c)

The attack is easy to stop.

d)

The attack must be sustained.

76.

What is the most common class of DoS attacks?

a)

Distributed denial of service

b)

Smurf attacks

c)

SYN floods

d)

Ping of death

77.

A range of countermeasures can help defend against DoS attacks. What are three methods for protecting against SYN flood attacks?

a)

SYN cookies, RST cookies, and stack tweaking

b)

SYN cookies, DoS cookies, and stack tweaking

c)

DoS cookies, RST cookies, and stack deletion

d)

DoS cookies, SYN cookies, and stack deletion

78.

Juan is explaining various DoS attacks to security operators at his company. Which attack mentioned in this chapter causes a network to perform a DoS attack on one of its own servers?

a)

SYN flood

b)

Ping of death

c)

Smurf attack

d)

DDoS

79.

What is the name for a defense that depends on a hash being sent back to the requesting client?

a)

Stack tweaking

b)

RST cookies

c)

SYN cookies

d)

Hash tweaking

80.

What type of defense depends on sending the client an incorrect SYN/ACK?

a)

Stack tweaking

b)

RST cookies

c)

SYN cookies

d)

Hash tweaking

81.

You are attempting to explain various DoS attacks to a new security technician. You want to make sure she can differentiate between these different attacks and notice the signs of a specific attack. What type of defense depends on changing the server so that unfinished handshaking times out sooner?

a)

Stack tweaking

b)

RST cookies

c)

SYN cookies

d)

Hash tweaking

82.

What type of attack is dependent on sending packets that are too large for the server to handle?

a)

Ping of death

b)

Smurf attack

c)

Slammer attack

d)

DDoS

83.

You want to make sure your team can identify the various DoS attack vectors. What type of attack uses the victim’s own network routers to perform a DoS attack on the target?

a)

Ping of death

b)

Smurf attack

c)

Slammer attack

d)

DDoS

84.

If you are a website developer and concerned about DoS attacks, what is one mitigation technique you can implement in the website itself?

a)

Bandwidth throttling

b)

Web application firewall

c)

Encryption with HTTPS

d)

CAPTCHA

85.

How can securing internal routers help protect against DoS attacks?

a)

Attacks cannot occur if the internal router is secured.

b)

Because attacks originate outside the network, securing internal routers cannot help protect against DoS attacks.

c)

Securing the router will only stop router-based DoS attacks.

d)

It will prevent an attack from propagating across network segments.

86.

What can your do to your internal network routers to help defend against DoS attacks?

a)

Disallow all traffic that is not encrypted

b)

Disallow all traffic that comes from outside the network

c)

Disallow all traffic that comes from inside the network

d)

Disallow all traffic that comes from untrusted sources

87.

Dorothy is a network administrator. Her system has been experiencing an attack that is using bots to send fake requests to the cloud resources her company uses. This is causing disruption of the availability of these resources. How is this attack best described?

a)

PDoS

b)

DDoS

c)

EDoS

d)

DoS

88.

No attack mitigation strategy is perfect, and you need to allow at least some traffic into and out of your network, or else your network is of no use. What can you do with your firewall to defend against at least some DoS attacks?

a)

Block all incoming traffic

b)

Block all incoming TCP packets

c)

Block all incoming traffic on port 80

d)

Block all incoming ICMP packets

89.

You are trying to identify all potential DoS attack vectors. In doing so, you hope to provide mitigation for each of these attack vectors. Why will protecting against Trojan horse attacks reduce DoS attacks?

a)

Many denial of service attacks are conducted by using a Trojan horse to get an unsuspecting machine to execute the DoS attack.

b)

If you can stop a Trojan horse attack, you will also stop DoS attacks.

c)

A Trojan horse will often open ports and thus allow DoS attacks.

d)

A Trojan horse has much the same effect as a DoS attack.

90.

John is a network security administrator for a midsized college. He is trying to explain to a new hire what a virus is. Which of the following is the best definition of virus?

a)

A program that causes harm on your computer

b)

A program used in a DoS attack

c)

A program that slows down networks

d)

A program that self-replicates

91.

Isabelle is responsible for cybersecurity at her company. She is concerned that a virus would cause damage to the IT systems. What is the most common damage caused by virus attacks?

a)

Slowing down networks by the virus traffic

b)

Deleting files

c)

Changing the Windows Registry

d)

Corrupting the operating system

92.

You are trying to form policies for your organization to mitigate the threat of viruses. You want to ensure that you address the most common way for a virus to spread. What is the most common way for a virus to spread?

a)

By copying to shared folders

b)

By email attachment

c)

By FTP

d)

By download from a website

93.

Which of the following is the primary reason that Microsoft Outlook is so often a target for virus attacks?

a)

Many hackers dislike Microsoft.

b)

Outlook copies virus files faster.

c)

It is easy to write programs that access Outlook’s inner mechanisms.

d)

Outlook is more commonly used than other email systems.

94.

Juan is a network administrator for a small graphic design company. In April 2021 his company was hit by a virus that specifically targeted macOS and was a first-stage downloader for other malware components. What attack was this?

a)

Schlayer

b)

Pegasus

c)

Mirai

d)

Sasser

95.

What factor about the WannaCry virus is especially interesting to security practitioners?

a)

It could have been prevented with good patch management.

b)

It deleted critical system files.

c)

It was difficult to protect against.

d)

It was very sophisticated and likely an example of nation-state weaponized malware.

96.

What is the name of the very first virus ever detected?

a)

Creeper

b)

Wabbit

c)

Mimail

d)

Unnamed

97.

Elizabeth has found malware on a system in her company. The malware blocks about 600 Windows processes, and demands ransom. What has Elizabeth found?

a)

Thanatos

b)

Clop

c)

Kedi RAT

d)

Schlayer

98.

Mohaned has found malware on his network. This malware encrypts files demanding ransom and also blocks approximately 600 Windows processes. What malware has Mohaned found?

a)

Schlayer

b)

Thanatos

c)

Cl0p

d)

Pegasus

99.

Which of the following is a method that any person can use to protect against virus attacks?

a)

Set up a firewall.

b)

Use encrypted transmissions.

c)

Use secure email software.

d)

Never open unknown email attachments.

100.

You are trying to develop methods to mitigate the threat of viruses in your company. Which of the following is the safest way to send and receive attachments?

a)

Use a code word indicating that an attachment is legitimate.

b)

Send only spreadsheet attachments.

c)

Use encryption.

d)

Use virus scanners before opening attachments.

101.

Shelly is trying to teach new employees how to handle emailed security alerts. Which of the following is true regarding emailed security alerts?

a)

You must follow them.

b)

Most companies do not send alerts via email.

c)

You can trust attachments on security alerts.

d)

Most companies send alerts via email.

102.

Which of the following is something a Trojan horse might do?

a)

Open a backdoor for malicious software.

b)

Change your memory configuration.

c)

Change ports on your computer.

d)

Alter your IP address.

103.

Jared is explaining various attacks to students in an introduction to cybersecurity class. He wants to make certain they fully understand the different attacks. What does a buffer-overflow attack do?

a)

It overflows a port with too many packets.

b)

It puts more email in an email system than it can hold.

c)

It overflows the system.

d)

It puts more data in a buffer than it can hold.

104.

What virus exploited buffer overflows?

a)

Sobig virus

b)

Mimail virus

c)

Sasser virus

d)

Schlayer virus

105.

What can you do with a firewall to help protect against virus attacks?

a)

There is nothing you can do on a firewall to stop virus attacks.

b)

Shut down all unneeded ports.

c)

Close all incoming ports.

d)

None of the above are correct.

106.

Malek is explaining various malware types to new technical support personnel. He is explaining to them the various types of malware so that they can recognized them. What type of malware is a key logger?

a)

Virus

b)

Buffer overflow

c)

Trojan horse

d)

Spyware

107.

Which of the following is a step that all computer users should take to protect against virus attacks?

a)

Purchase and configure a firewall.

b)

Shut down all incoming ports.

c)

Use nonstandard email clients.

d)

Install and use antivirus software.

108.

What is the primary way a virus scanner works?

a)

By comparing files against a list of known virus profiles

b)

By blocking files that copy themselves

c)

By blocking all unknown files

d)

By looking at files for virus-like behavior

109.

In addition to the primary way a virus scanner works, what other way can a virus scanner work?

a)

By comparing files against a list of known virus profiles

b)

By blocking files that copy themselves

c)

By blocking all unknown files

d)

By looking at files for virus-like behavior

110.

Elizabeth is describing web-based attacks to a group of students in a computer security course. What does an SQL injection attack require?

a)

Having database admin privileges

b)

Creating an SQL statement that is always true

c)

Creating an SQL statement that will force access

d)

Understanding web programming

111.

Juan is using a rainbow table to circumvent passwords on a Windows computer. What is the best description of a rainbow table?

a)

A table of precomputed hashes

b)

A brute-force password attack

c)

A dictionary attack on passwords

d)

A multi pronged attempt to crack passwords

112.

You are responsible for security on an e-commerce system. You want to mitigate as many attacks as you can. How can you prevent cross-site scripting?

a)

Filter user input.

b)

Use an IDS.

c)

Use a firewall.

d)

It cannot be prevented.

113.

What is an advantage of using Shodan.io?

a)

It is free.

b)

It can check for a wide range of vulnerabilities.

c)

It is designed for Windows systems.

d)

It includes an IDS.

114.

Perez is exploring different password cracking tools. A friend has told him about ophcrack. ophcrack depends on the attacker doing what?

a)

Getting physical access to the machine

b)

Getting domain admin privileges

c)

Using social engineering

d)

Using a scanning tool

115.

If you wish to view items that have been removed from a website, what is the best way to do so?

a)

Use Nessus.

b)

Use Nmap.

c)

Use www.netcraft.com.

d)

Use www.archive.org.

116.

Malek needs a port scanner so he can scan open ports on his own network. Which of the following is a popular port scanner?

a)

Nessus

b)

ophcrack

c)

MBSA

d)

Nmap

117.

Jane wants to mitigate as many attacks as she can. A colleague suggested that she block ICMP packets. Blocking incoming ICMP packets will prevent what type of scan?

a)

SYN

b)

Ping

c)

FIN

d)

Stealth

118.

It is important that you understand cybersecurity terminology, including terms for different actors in cybersecurity. What is the correct term for a person who uses hacking techniques for illegal activities?

a)

A hacker

b)

A gray hat hacker

c)

A phreaker

d)

A cracker

119.

What is the term for a person who hacks into phone systems?

a)

A hacker

b)

A gray hat hacker

c)

A phreaker

d)

A cracker

120.

Penelope is teaching an introductory cybersecurity course and is trying to explain the terminology to students. What is the term for a person who uses tools to hack without understanding the underlying technology?

a)

A script kiddy

b)

A gray hat hacker

c)

A novice

d)

A white hat hacker

121.

What is the name for the process of trying to list all the servers on a network?

a)

Port scanning

b)

Enumeration

c)

Vulnerability scanning

d)

Scouting

122.

Terrance is performing a scan. What response will a Windows machine give to a FIN scan?

a)

ACK

b)

None

c)

SYN

d)

RST

123.

Jaron is trying to do a port scan of his own company. He wants to test to see if the company’s security systems will be able to detect his scan. Which of the following is considered the stealthiest port scan?

a)

SYN

b)

Connect

c)

Ping

d)

Nmap

124.

What is the stealthiest way to find out what type of server a website is running?

a)

Use Nmap.

b)

Use Cain and Abel.

c)

Use www.netcraft.com.

d)

Use www.archive.org.

125.

Terrance is trying to explain industrial espionage to a group of new security techs. What is the ultimate goal of espionage?

a)

To subvert a rival government

b)

To obtain information that has value

c)

To subvert a rival business

d)

To obtain information not otherwise available

126.

In order to truly understand industrial espionage, you need to understand the mindset of the spy. What is the best outcome for a spy attempting an espionage activity?

a)

To obtain information without the target even realizing he did so

b)

To obtain information with or without the target realizing he did so

c)

To obtain information and discredit the target

d)

To obtain information and cause harm to the target

127.

What is the usual motivating factor for corporate/industrial espionage?

a)

Ideological

b)

Political

c)

Economic

d)

Revenge

128.

Which of the following types of information would be a likely target for industrial espionage?

a)

A new algorithm that the company’s IT department has generated

b)

A new marketing plan that the company has formulated

c)

A list of all the company’s customers

d)

All of these answers are correct

129.

Accurate statistics on corporate espionage are difficult to obtain. One reason is that the victims don’t always report the crime, as they often don’t want the incidents to become public. Which of the following is a likely reason that an organization might be reluctant to admit it has been a victim of corporate espionage?

a)

It would embarrass the IT department.

b)

It would embarrass the CEO.

c)

It might cause stock value to decline.

d)

It might lead to involvement in a criminal prosecution.

130.

What is the difference between corporate and industrial espionage?

a)

None; they are interchangeable terms.

b)

Industrial espionage only refers to heavy industry, such as factories.

c)

Corporate espionage only refers to executive activities.

d)

Corporate espionage only refers to publicly traded companies.

131.

Information is a valuable asset. It can be useful to calculate that value in order to determine how much effort should be put into protecting it. What formula can you use to calculate the value of information?

a)

Resources needed to produce the information plus resources gained from the information

b)

Resources needed to produce the information multiplied by resources gained from the information

c)

Time taken to derive the information plus money needed to derive the information

d)

Time taken to derive the information multiplied by money needed to derive the information

132.

If a company purchases a high-end UNIX server to use for its research and development department, what is probably the most valuable part of the system?

a)

The high-end UNIX server

b)

The information on the server

c)

The devices used to protect the server

d)

The room to store the server

133.

Information is an asset to your company if it

a)

cost any sum of money to produce.

b)

cost a significant sum of money to produce.

c)

might have economic value.

d)

might cost significant money to reproduce.

134.

What is the greatest security risk to any company?

a)

Disgruntled employees

b)

Hackers

c)

Industrial spies

d)

Faulty network security

135.

Which of the following is the best definition for spyware?

a)

Software that assists in corporate espionage

b)

Software that monitors activity on a computer

c)

Software that logs computer keystrokes

d)

Software that steals data

136.

What is the highest level of security you can expect to obtain?

a)

A level of security that makes the effort required to get information more costly than the value of the information

b)

A level of security comparable with government security agencies, such as the Central Intelligence Agency

c)

A level of security that has a 92.5% success rate in stopping intrusion

d)

A level of security that has a 98.5% success rate in stopping intrusion

137.

In the context of preventing industrial espionage, why might you wish to limit the number of company CD burners and control access to them in your organization?

a)

An employee could use such media to take sensitive data.

b)

An employee could use such media to copy software from the company.

c)

CDs could be a vehicle for spyware to get on your system.

d)

CDs could be a vehicle for a virus to get on your system.

138.

Why would you want to scan an employee’s computer when he leaves the organization?

a)

To check the workflow prior to his leaving

b)

To check for signs of corporate espionage

c)

To check for illegal software

d)

To check for pornography

139.

What is the reason for encrypting hard drives on laptop computers?

a)

To prevent a hacker from reading the data while you are online

b)

To ensure that data transmissions are secure

c)

To ensure that another user on that machine will not see sensitive data

d)

To prevent a thief from getting data off of a stolen laptop