wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

End-of-Semester Test — Extracted Questions

Total questions: 55

Worksheet time: 3hrs 45mins

Name
Class
Date
1.

Select the correct answer. What is shadow IT an example of?

a)

competitor

b)

script kiddie

c)

hacktivist

d)

threat actor

2.

Select the correct answer. An executive for a manufacturing company wants to diversify the sources for its raw materials. What threat vector is the executive trying to minimize?

a)

social media

b)

supply chain

c)

direct access

d)

cloud

3.

Select all the correct answers. What are two specifications sponsored by the Department of Homeland Security (DHS) for sharing cybersecurity information?

a)

OSINT

b)

MITRE

c)

IoC

d)

STIX

e)

TAXII

4.

Select all the correct answers. An employee for a domain registrar service receives a phone call from someone claiming to be an executive from the company. He demands that the employee quickly change some customer information because the service company is in a hurry. Which two social engineering techniques are being implemented by the caller?

a)

pretexting

b)

urgency

c)

authority

d)

familiarity

e)

scarcity

5.

Select the correct answer. Which type of phishing attack uses text messages to try and steal sensitive information?

a)

whaling

b)

spear phishing

c)

vishing

d)

smishing

6.

Match each attack with an example of it being perpetrated: "An attacker posts a link to a giveaway that embeds a file into the URL." Which attack is illustrated?

a)

hoax

b)

typosquatting

c)

pharming

d)

prepending

7.

Match each attack with an example of it being perpetrated: "An attacker sends links to a site that mimics a popular site to gain sensitive information from a user." Which attack is illustrated?

a)

hoax

b)

typosquatting

c)

pharming

d)

prepending

8.

Match each attack with an example of it being perpetrated: "An attacker sends an email asking for money, and in exchange, the attacker promises to send back double the money." Which attack is illustrated?

a)

hoax

b)

typosquatting

c)

pharming

d)

prepending

9.

Match each attack with an example of it being perpetrated: "An attacker registers a domain name that is one letter off from a popular website, then designs it like the original to collect usernames and passwords." Which attack is illustrated?

a)

hoax

b)

typosquatting

c)

pharming

d)

prepending

10.

Select the correct answer. Which type of password attack uses precomputed passwords and hashes?

a)

rainbow table

b)

spraying

c)

dictionary

d)

brute force

11.

Select all the correct answers. Which two techniques are useful to prevent adversarial AI attacks?

a)

employ a white-box methodology for algorithm development

b)

find tainted data for training

c)

make the AI algorithms public

d)

keep algorithms secret

e)

use a black-box technique when developing algorithms

12.

Select the correct answer. Imani is an employee at a financial firm. She suddenly sees a pop-up window on her system saying that her data has been encrypted and she should send money to restore the system. What type of security attack has Imani suffered?

a)

ransomware

b)

adware

c)

botnet

d)

spyware

13.

Select the correct answer. A user is sent to a site to authenticate, but the user notices that the URL contains "http" instead of "https." What type of attack behaves in this way?

a)

cross-site scripting

b)

replay attack

c)

SSL stripping

d)

clickjacking

14.

Select the correct answer. Which type of attack injects malicious code into a database?

a)

SQL

b)

DLL

c)

XML

d)

LDAP

15.

Match each software attack to a remedy. Which software attack is addressed by this remedy: display only minimal information as output when responding to abnormal conditions?

a)

buffer overflow

b)

improper input handling

c)

privilege escalation

d)

error handling

16.

Match each software attack to a remedy. Which software attack is addressed by this remedy: ensure the antivirus program can detect when applications try to use more memory than allocated for a variable?

a)

buffer overflow

b)

improper input handling

c)

privilege escalation

d)

error handling

17.

Match each software attack to a remedy. Which software attack is addressed by this remedy: sanitize any data coming externally from users?

a)

buffer overflow

b)

improper input handling

c)

privilege escalation

d)

error handling

18.

Match each software attack to a remedy. Which software attack is addressed by this remedy: give users and applications the least amount of access that their accounts need?

a)

buffer overflow

b)

improper input handling

c)

privilege escalation

d)

error handling

19.

Select the correct answer. Which type of attack enables hosts to update their MAC:IP address tables with spoofed information?

a)

MAC flooding

b)

jamming

c)

ARP poisoning

d)

on-path attack

20.

Select all the correct answers. Jamal is an administrator. He discovers a script on one of his Linux systems. Which three types of commands in the script should mark the script as a possible security threat?

a)

mkdir

b)

wget

c)

chmod

d)

crontab

e)

sudo

21.

Select the correct answer. An attacker sets up a Wi-Fi network with a name that is similar to a legitimate one in the same area. Which type of attack is the attacker perpetrating?

a)

bluejacking

b)

evil twin

c)

initialization vector

d)

bluesnarfing

22.

Select all the correct answers. After a security incident, it has been discovered that a threat actor copied privacy-law-compliant user data from your system to the threat actor's system. Which two types of impacts have occurred?

a)

data loss

b)

data breach

c)

privacy breach

d)

data exfiltration

e)

availability loss

23.

Select the correct answer. An administrator notices that a server is receiving FTP connection requests even though FTP is not needed on the server and has not been configured. What type of configuration issue is the administrator facing?

a)

file permissions

b)

open ports and services

c)

weak encryption

d)

unsecured root access

24.

Match each third-party risk with a solution that addresses it: For the risk of system integration, which solution addresses it?

a)

have a backup plan so workflow is not interrupted if a third-party service changes or goes offline

b)

use another vendor for vulnerability and penetration testing

c)

evaluate the third party based on its history, standards, and product support

d)

use the same access management and encryption used locally

25.

Match each third-party risk with a solution that addresses it: For the risk of outsourced code development, which solution addresses it?

a)

have a backup plan so workflow is not interrupted if a third-party service changes or goes offline

b)

use another vendor for vulnerability and penetration testing

c)

evaluate the third party based on its history, standards, and product support

d)

use the same access management and encryption used locally

26.

Match each third-party risk with a solution that addresses it: For the risk of data storage, which solution addresses it?

a)

have a backup plan so workflow is not interrupted if a third-party service changes or goes offline

b)

use another vendor for vulnerability and penetration testing

c)

evaluate the third party based on its history, standards, and product support

d)

use the same access management and encryption used locally

27.

Match each third-party risk with a solution that addresses it: For the risk of vendor management, which solution addresses it?

a)

have a backup plan so workflow is not interrupted if a third-party service changes or goes offline

b)

use another vendor for vulnerability and penetration testing

c)

evaluate the third party based on its history, standards, and product support

d)

use the same access management and encryption used locally

28.

Select the correct answer. Benjamin is an administrator for a financial firm. He needs to regularly decommission hard drives and be sure that they will be unreadable. He wants to do so by using a strong electromagnetic force rather than physical destruction. Which method would best suit Benjamin?

a)

burning

b)

shredding and pulping

c)

degaussing

d)

pulverizing

29.

Select the correct answer. Which type of physical authentication method employs a user's unique characteristics?

a)

key fobs

b)

one-time passwords

c)

smart cards

d)

biometrics

30.

Select the correct answer. Which term describes the functions that an individual is allowed to perform?

a)

identification

b)

authorization

c)

authentication

d)

accounting

31.

Select the correct answer. An organization needs a way to recognize individuals near their building via external security cameras. This identification should happen without the individual providing any type of badge. What type of user identification would be most useful for this situation?

a)

fingerprints

b)

gait recognition

c)

iris scanner

d)

voice recognition

32.

Select all the correct answers. Which two options are "something you have" (possession factor) authentication types?

a)

key fob

b)

smart card

c)

PIN pattern

d)

password

e)

iris pattern

33.

Select all the correct answers. What three statements regarding the limitations of cryptography are true?

a)

More complex ciphers can cause latency during a protocol's handshake.

b)

Asymmetric ciphers are faster to process than symmetric ciphers.

c)

Low-power devices should use more complex cipher algorithms.

d)

Longer keys are generally more secure than shorter keys.

e)

Ciphers with low entropy are more predictable.

34.

Select the correct answer. Which option describes a linked list in which each new addition is cryptographically tied to the previous one?

a)

blockchain

b)

steganography

c)

perfect forward secrecy

d)

hash

35.

Match each encryption term with the situation that uses it. A security administrator needs to make the passwords that users create more complex to store them.

a)

hashing

b)

perfect forward secrecy

c)

salting

d)

key exchange

36.

Match each encryption term with the situation that uses it. A user wants to be sure that a message cannot be decrypted after a session has expired.

a)

hashing

b)

perfect forward secrecy

c)

salting

d)

key exchange

37.

Match each encryption term with the situation that uses it. An administrator wants others to be able to verify the authenticity of a file they have sent.

a)

hashing

b)

perfect forward secrecy

c)

salting

d)

key exchange

38.

Match each encryption term with the situation that uses it. An individual wants to send a message and let others know that the individual is an authentic sender and that the message has not been altered.

a)

hashing

b)

perfect forward secrecy

c)

salting

d)

key exchange

39.

Select the correct answer. Which type of security scan gives an insight into what an attacker can do if they are able to break into an account?

a)

intrusive

b)

credentialed

c)

non-intrusive

d)

non-credentialed

40.

Select all the correct answers. A penetration tester has been tasked with attacking a network which is a known environment to the tester. Which two terms best describe the rules of engagement for the tester?

a)

grey box

b)

blue team

c)

black box

d)

red team

e)

white box

41.

Select the correct answer. An administrator installs security assessment technology that allows hosts to forward events to an SIEM server using SNMP. What type of model is the administrator using?

a)

log aggregation

b)

agent-based

c)

listener/collector

d)

sensor/packet capture

42.

Select the correct answer. An administrator wants to be able to detect when a network is being scanned and, in response, return misleading information. What method is the administrator employing in this situation?

a)

fake telemetry

b)

masking

c)

cold site

d)

honeynets

43.

Select the correct term. Match each term to its example of data protection: An administrator needs to automatically stop sensitive data from being exfiltrated from a system or network. Which term matches this example?

a)

data in transit

b)

tokenization

c)

data loss prevention

d)

masking

44.

Select the correct term. Match each term to its example of data protection: An administrator must be sure that the data traversing the network is encrypted. Which term matches this example?

a)

data in transit

b)

tokenization

c)

data loss prevention

d)

masking

45.

Select the correct term. Match each term to its example of data protection: An administrator needs to block out some sensitive data in a file before sending it to a third party so that its value can never be determined. Which term matches this example?

a)

data in transit

b)

tokenization

c)

data loss prevention

d)

masking

46.

Select the correct term. Match each term to its example of data protection: An administrator needs to replace sensitive data with something else but be able to swap it back when needed. Which term matches this example?

a)

data in transit

b)

tokenization

c)

data loss prevention

d)

masking

47.

Select the correct answer. Which technology describes an app and the parts of an operating system that it needs to run?

a)

edge computing

b)

container

c)

thin client

d)

fog computing

48.

Select the correct answer. A business organization would like to create a cloud environment that allows suppliers and distributors to connect to in order to work better. Which type of cloud model would best fit this situation?

a)

community

b)

public

c)

hybrid

d)

private

49.

Select all the correct answers. Which two options describe adding more servers when an app's demand increases over time?

a)

scalability

b)

elasticity

c)

provisioning

d)

software diversity

e)

deprovisioning

50.

Select the correct answer. A developer is writing code that should accept a file as input. Since the developer is worried the file might not always exist for each user, he wants to try and catch the error before it happens so that it doesn't crash the app. What technique is the developer using?

a)

normalization

b)

code reuse

c)

exception handling

d)

input validation

51.

Select the correct answer. A developer is creating an embedded device that needs fast wireless communication that is within four inches of the device it is communicating with. It should also support encryption. Which protocol would be ideal for this device?

a)

Infrared

b)

Bluetooth

c)

Wi‑Fi

d)

NFC

52.

Select the correct answer. Which type of embedded system has integrated circuits that can be customized as needed rather than replaced?

a)

SoC

b)

MFD

c)

RTOS

d)

FPGA

53.

Select the correct answer. An administrator wants a simple RAID system that just mirrors all the contents of one disk onto another. What type of RAID should the administrator implement?

a)

RAID 5

b)

RAID 1

c)

RAID 0

d)

RAID 10

54.

Select the correct answer. Which type of backup will include all files changed since the last complete backup job?

a)

differential

b)

incremental

c)

mirror

d)

full

55.

Select the correct answer. An administrator needs a server that will stay online even during a power outage. Which type of device will enable this functionality?

a)

generator

b)

uninterruptible power supply

c)

dual power supply

d)

load balancer