Font size
WorksheetsCybersecurity Quiz
Total questions: 41
Worksheet time: 21mins
Fill in the blank: Cybersecurity aims to protect networks, devices, people, and data from _____ or unauthorized access.
criminal exploitation
changing business priorities
poor financial management
market shifts
A security professional collaborates with information technology teams to deploy an application that helps identify risks and vulnerabilities. What does this scenario describe?
Upgrading network capacity
Installing detection software
Conducting a security audit
Ethical hacking
Which of the following entities may be an internal threat to an organization? Select three answers.
Trusted partners
Vendors
Customers
Employees
Fill in the blank: Identity theft is the act of stealing _____ to commit fraud while impersonating a victim.
hardware
business records
personal information
trade secrets
What is regulatory compliance?
Sites and services that require complex passwords to access
Threats and risks from employees and external vendors
Laws and guidelines that require implementation of security standards
Expenses and fines associated with vulnerabilities
Which of the following proficiencies are examples of technical skills? Select two answers.
Communicating with employees
Prioritizing collaboration
Automating tasks with programming
Applying computer forensics
Fill in the blank: Security _____ and event management (SIEM) tools enable security professionals to identify and analyze threats, risks, and vulnerabilities.
information
improvement
identity
intelligence
What do security professionals typically do with SIEM tools?
Identify and analyze security threats, risks, and vulnerabilities
Locate and preserve criminal evidence
Identify threat actors and their locations
Educate others about potential security threats, risks, and vulnerabilities
Which of the following threats are examples of malware? Select two answers.
Error messages
Worms
Bugs
Viruses
What historical event used a malware attachment to steal user information and passwords?
Morris worm
LoveLetter attack
Equifax breach
Brain virus
Fill in the blank: Exploiting human error to gain access to private information is an example of _____ engineering.
digital
network
social
communication
A security professional is asked to teach employees how to avoid inadvertently revealing sensitive data. What type of training should they conduct?
Training about security architecture
Training about social engineering
Training about business continuity
Training about network optimization
Which domain involves defining security goals and objectives, risk mitigation, compliance, business continuity, and the law?
Security architecture and engineering
Security and risk management
Security assessment and testing
Identity and access management
A security professional is optimizing data security by ensuring that effective tools, systems, and processes are in place. Which domain does this scenario describe?
Identity and access management
Security architecture and engineering
Security and risk management
Communication and network security
A cybersecurity analyst needs to collect data from multiple places to analyze filtered events and patterns. What type of tool should they use?
network protocol analyzer (packet sniffer)
Playbook
Linux operating system
Security information and event management (SIEM)
Fill in the blank: Security professionals use _____ to help them manage a security incident before, during, and after it has occurred.
charts
playbooks
spreadsheets
programming
A security professional must deactivate user accounts when employees leave the company to remove access to sensitive information and resources. Which domain does this scenario describe?
Security and risk management
Security assessment and testing
Communication and network security
Identity and access management
As a security analyst, you are tasked with auditing your organization's network to identify security related issues. How might a network protocol analyzer (packet sniffer) help you perform this task?
By automating tasks that reduce human error
By removing malware and viruses from the network
By simulating attacks on connected devices
By capturing and analyzing data traffic on the network
Fill in the blank: A security professional has been tasked with implementing strict password policies on workstations to reduce the risk of password theft. This is an example of _____.
hardware changes
security teams
networking regulations
security controls
You are helping your security team consider risk when setting up a new software system. Using the CIA triad, you focus on confidentiality, availability, and what else?
Integrity
Intelligence
Inconsistencies
Information
Fill in the blank: _____ are items perceived as having value to an organization.
Assets
Incidents
Lifecycles
Alerts
Fill in the blank: Some of the most dangerous threat actors are _____ because they often know where to find sensitive information, can access it, and may have malicious intent.
disgruntled employees
past vendors
dissatisfied customers
senior partners
A security professional is updating software on a coworker’s computer and unexpectedly encounters an email containing private information about another employee. The security professional chooses to follow company guidelines regarding privacy protections and does not share the information with coworkers. Which concept does this scenario describe?
Preserving evidence
Business email compromise
Security ethics
Security controls
Fill in the blank: The ethical principle of _____ involves safeguarding an organization’s human resources records that contain personal details about employees.
non-bias
privacy protection
unlimited access
honesty
Which of the following describes a set of rules for data protection that are established and enforced by a governing authority?
Laws
Guidelines
Protections
Restrictions
Fill in the blank: Linux relies on a(n) _____ as the primary user interface.
dashboard
command line
ciphertext
error log
Fill in the blank: A database is a _____ of organized data stored in a computer system.
collection
frame
visualization
model
Fill in the blank: Security _____ refers to an organization’s ability to manage its defense of critical assets and data, as well as its ability to react to change.
governance
posture
architecture
hardening
How does business continuity enable an organization to maintain everyday productivity?
By outlining faults to business policies
By exploiting vulnerabilities
By establishing risk disaster recovery plans
By ensuring return on investment
A security analyst ensures that employees are able to review only the data they need to do their jobs. Which security domain does this scenario relate to?
Security assessment and testing
Identity and access management
Software development security
Communication and network security
Fill in the blank: The software development security domain involves the use of the software development ___, which is an efficient process used by teams to quickly build software products and services.
staging
operations
lifecycle
functionality
A business experiences an attack. As a result, its critical business operations are interrupted and it faces regulatory fines. What type of consequence does this scenario describe?
Reputation
Financial
Practical
Identity
Fill in the blank: In the Risk Management Framework (RMF), the _____ step involves knowing how systems are operating and assessing whether or not those systems support the organization's security goals.
authorize
implement
monitor
categorize
How do organizations use security frameworks to develop an effective security posture?
As a guide to reduce risk and protect data and privacy
As a policy to support employee training initiatives
As a guide to identify threat actor strategies
As a policy to protect against phishing campaigns
Fill in the blank: A security professional uses _____ to verify that an employee has permission to access a resource.
admission
authorization
encryption
integrity
Which of the following is an example of biometrics?
Encryption
Password
Security framework
Fingerprint
You work as a security analyst for a supply chain organization and need to confirm all inventory data is correct, authentic, and reliable. Which core principle of the CIA triad are you using?
Integrity
Availability
Credibility
Confidentiality
A security team has just finished addressing a recent security incident. They now conduct tests to ensure that all of their repairs were successful. Which OWASP principle does this scenario describe?
Fix security issues correctly
Separation of duties
Principle of least privilege
Minimize attack surface area
Fill in the blank: The planning elements of an internal security audit include establishing scope and _____, then conducting a risk assessment.
compliance
goals
controls
limitations
A security analyst performs an internal security audit. They review their company’s existing assets, then evaluate potential risks to those assets. Which aspect of a security audit does this scenario describe?
Communicating results
Completing a controls assessment
Establishing the scope and goals
Assessing compliance
Fill in the blank: To assess the performance of a software application, security professionals use _____, including response time, availability, and failure rate.
metrics
dashboards
logs
SIEM tools
