Font size
WorksheetsEnd-of-Semester Test — Extracted Questions
Total questions: 55
Worksheet time: 3hrs 45mins
Select the correct answer. What is shadow IT an example of?
competitor
script kiddie
hacktivist
threat actor
Select the correct answer. An executive for a manufacturing company wants to diversify the sources for its raw materials. What threat vector is the executive trying to minimize?
social media
supply chain
direct access
cloud
Select all the correct answers. What are two specifications sponsored by the Department of Homeland Security (DHS) for sharing cybersecurity information?
OSINT
MITRE
IoC
STIX
TAXII
Select all the correct answers. An employee for a domain registrar service receives a phone call from someone claiming to be an executive from the company. He demands that the employee quickly change some customer information because the service company is in a hurry. Which two social engineering techniques are being implemented by the caller?
pretexting
urgency
authority
familiarity
scarcity
Select the correct answer. Which type of phishing attack uses text messages to try and steal sensitive information?
whaling
spear phishing
vishing
smishing
Match each attack with an example of it being perpetrated: "An attacker posts a link to a giveaway that embeds a file into the URL." Which attack is illustrated?
hoax
typosquatting
pharming
prepending
Match each attack with an example of it being perpetrated: "An attacker sends links to a site that mimics a popular site to gain sensitive information from a user." Which attack is illustrated?
hoax
typosquatting
pharming
prepending
Match each attack with an example of it being perpetrated: "An attacker sends an email asking for money, and in exchange, the attacker promises to send back double the money." Which attack is illustrated?
hoax
typosquatting
pharming
prepending
Match each attack with an example of it being perpetrated: "An attacker registers a domain name that is one letter off from a popular website, then designs it like the original to collect usernames and passwords." Which attack is illustrated?
hoax
typosquatting
pharming
prepending
Select the correct answer. Which type of password attack uses precomputed passwords and hashes?
rainbow table
spraying
dictionary
brute force
Select all the correct answers. Which two techniques are useful to prevent adversarial AI attacks?
employ a white-box methodology for algorithm development
find tainted data for training
make the AI algorithms public
keep algorithms secret
use a black-box technique when developing algorithms
Select the correct answer. Imani is an employee at a financial firm. She suddenly sees a pop-up window on her system saying that her data has been encrypted and she should send money to restore the system. What type of security attack has Imani suffered?
ransomware
adware
botnet
spyware
Select the correct answer. A user is sent to a site to authenticate, but the user notices that the URL contains "http" instead of "https." What type of attack behaves in this way?
cross-site scripting
replay attack
SSL stripping
clickjacking
Select the correct answer. Which type of attack injects malicious code into a database?
SQL
DLL
XML
LDAP
Match each software attack to a remedy. Which software attack is addressed by this remedy: display only minimal information as output when responding to abnormal conditions?
buffer overflow
improper input handling
privilege escalation
error handling
Match each software attack to a remedy. Which software attack is addressed by this remedy: ensure the antivirus program can detect when applications try to use more memory than allocated for a variable?
buffer overflow
improper input handling
privilege escalation
error handling
Match each software attack to a remedy. Which software attack is addressed by this remedy: sanitize any data coming externally from users?
buffer overflow
improper input handling
privilege escalation
error handling
Match each software attack to a remedy. Which software attack is addressed by this remedy: give users and applications the least amount of access that their accounts need?
buffer overflow
improper input handling
privilege escalation
error handling
Select the correct answer. Which type of attack enables hosts to update their MAC:IP address tables with spoofed information?
MAC flooding
jamming
ARP poisoning
on-path attack
Select all the correct answers. Jamal is an administrator. He discovers a script on one of his Linux systems. Which three types of commands in the script should mark the script as a possible security threat?
mkdir
wget
chmod
crontab
sudo
Select the correct answer. An attacker sets up a Wi-Fi network with a name that is similar to a legitimate one in the same area. Which type of attack is the attacker perpetrating?
bluejacking
evil twin
initialization vector
bluesnarfing
Select all the correct answers. After a security incident, it has been discovered that a threat actor copied privacy-law-compliant user data from your system to the threat actor's system. Which two types of impacts have occurred?
data loss
data breach
privacy breach
data exfiltration
availability loss
Select the correct answer. An administrator notices that a server is receiving FTP connection requests even though FTP is not needed on the server and has not been configured. What type of configuration issue is the administrator facing?
file permissions
open ports and services
weak encryption
unsecured root access
Match each third-party risk with a solution that addresses it: For the risk of system integration, which solution addresses it?
have a backup plan so workflow is not interrupted if a third-party service changes or goes offline
use another vendor for vulnerability and penetration testing
evaluate the third party based on its history, standards, and product support
use the same access management and encryption used locally
Match each third-party risk with a solution that addresses it: For the risk of outsourced code development, which solution addresses it?
have a backup plan so workflow is not interrupted if a third-party service changes or goes offline
use another vendor for vulnerability and penetration testing
evaluate the third party based on its history, standards, and product support
use the same access management and encryption used locally
Match each third-party risk with a solution that addresses it: For the risk of data storage, which solution addresses it?
have a backup plan so workflow is not interrupted if a third-party service changes or goes offline
use another vendor for vulnerability and penetration testing
evaluate the third party based on its history, standards, and product support
use the same access management and encryption used locally
Match each third-party risk with a solution that addresses it: For the risk of vendor management, which solution addresses it?
have a backup plan so workflow is not interrupted if a third-party service changes or goes offline
use another vendor for vulnerability and penetration testing
evaluate the third party based on its history, standards, and product support
use the same access management and encryption used locally
Select the correct answer. Benjamin is an administrator for a financial firm. He needs to regularly decommission hard drives and be sure that they will be unreadable. He wants to do so by using a strong electromagnetic force rather than physical destruction. Which method would best suit Benjamin?
burning
shredding and pulping
degaussing
pulverizing
Select the correct answer. Which type of physical authentication method employs a user's unique characteristics?
key fobs
one-time passwords
smart cards
biometrics
Select the correct answer. Which term describes the functions that an individual is allowed to perform?
identification
authorization
authentication
accounting
Select the correct answer. An organization needs a way to recognize individuals near their building via external security cameras. This identification should happen without the individual providing any type of badge. What type of user identification would be most useful for this situation?
fingerprints
gait recognition
iris scanner
voice recognition
Select all the correct answers. Which two options are "something you have" (possession factor) authentication types?
key fob
smart card
PIN pattern
password
iris pattern
Select all the correct answers. What three statements regarding the limitations of cryptography are true?
More complex ciphers can cause latency during a protocol's handshake.
Asymmetric ciphers are faster to process than symmetric ciphers.
Low-power devices should use more complex cipher algorithms.
Longer keys are generally more secure than shorter keys.
Ciphers with low entropy are more predictable.
Select the correct answer. Which option describes a linked list in which each new addition is cryptographically tied to the previous one?
blockchain
steganography
perfect forward secrecy
hash
Match each encryption term with the situation that uses it. A security administrator needs to make the passwords that users create more complex to store them.
hashing
perfect forward secrecy
salting
key exchange
Match each encryption term with the situation that uses it. A user wants to be sure that a message cannot be decrypted after a session has expired.
hashing
perfect forward secrecy
salting
key exchange
Match each encryption term with the situation that uses it. An administrator wants others to be able to verify the authenticity of a file they have sent.
hashing
perfect forward secrecy
salting
key exchange
Match each encryption term with the situation that uses it. An individual wants to send a message and let others know that the individual is an authentic sender and that the message has not been altered.
hashing
perfect forward secrecy
salting
key exchange
Select the correct answer. Which type of security scan gives an insight into what an attacker can do if they are able to break into an account?
intrusive
credentialed
non-intrusive
non-credentialed
Select all the correct answers. A penetration tester has been tasked with attacking a network which is a known environment to the tester. Which two terms best describe the rules of engagement for the tester?
grey box
blue team
black box
red team
white box
Select the correct answer. An administrator installs security assessment technology that allows hosts to forward events to an SIEM server using SNMP. What type of model is the administrator using?
log aggregation
agent-based
listener/collector
sensor/packet capture
Select the correct answer. An administrator wants to be able to detect when a network is being scanned and, in response, return misleading information. What method is the administrator employing in this situation?
fake telemetry
masking
cold site
honeynets
Select the correct term. Match each term to its example of data protection: An administrator needs to automatically stop sensitive data from being exfiltrated from a system or network. Which term matches this example?
data in transit
tokenization
data loss prevention
masking
Select the correct term. Match each term to its example of data protection: An administrator must be sure that the data traversing the network is encrypted. Which term matches this example?
data in transit
tokenization
data loss prevention
masking
Select the correct term. Match each term to its example of data protection: An administrator needs to block out some sensitive data in a file before sending it to a third party so that its value can never be determined. Which term matches this example?
data in transit
tokenization
data loss prevention
masking
Select the correct term. Match each term to its example of data protection: An administrator needs to replace sensitive data with something else but be able to swap it back when needed. Which term matches this example?
data in transit
tokenization
data loss prevention
masking
Select the correct answer. Which technology describes an app and the parts of an operating system that it needs to run?
edge computing
container
thin client
fog computing
Select the correct answer. A business organization would like to create a cloud environment that allows suppliers and distributors to connect to in order to work better. Which type of cloud model would best fit this situation?
community
public
hybrid
private
Select all the correct answers. Which two options describe adding more servers when an app's demand increases over time?
scalability
elasticity
provisioning
software diversity
deprovisioning
Select the correct answer. A developer is writing code that should accept a file as input. Since the developer is worried the file might not always exist for each user, he wants to try and catch the error before it happens so that it doesn't crash the app. What technique is the developer using?
normalization
code reuse
exception handling
input validation
Select the correct answer. A developer is creating an embedded device that needs fast wireless communication that is within four inches of the device it is communicating with. It should also support encryption. Which protocol would be ideal for this device?
Infrared
Bluetooth
Wi‑Fi
NFC
Select the correct answer. Which type of embedded system has integrated circuits that can be customized as needed rather than replaced?
SoC
MFD
RTOS
FPGA
Select the correct answer. An administrator wants a simple RAID system that just mirrors all the contents of one disk onto another. What type of RAID should the administrator implement?
RAID 5
RAID 1
RAID 0
RAID 10
Select the correct answer. Which type of backup will include all files changed since the last complete backup job?
differential
incremental
mirror
full
Select the correct answer. An administrator needs a server that will stay online even during a power outage. Which type of device will enable this functionality?
generator
uninterruptible power supply
dual power supply
load balancer
