WorksheetsSecurity 1 -30 / 49
Total questions: 100
Worksheet time: 50mins
What are the three components of the CIA triad?
Confidentiality, Integrity, Availability.
Confidentiality, Information, Access.
Control, Integrity, Authentication.
Confidentiality, Investigation, Authorization.
Name two responsibilities of a CISO.
Security strategy and governance; incident response oversight; risk management; policy creation (any two).
Managing company finances; overseeing marketing campaigns
Designing product features; handling customer support
Organizing company events; managing office supplies
Give one example of a technical control and one operational control.
A firewall and security awareness training
A firewall and a router
Security awareness training and a password
A router and a password
The difference between preventive and detective controls is:
Preventive controls aim to stop unwanted events before they occur, while detective controls identify events after they have happened.
Preventive controls are only used in physical security, while detective controls are used in cybersecurity.
Detective controls are more effective than preventive controls in all situations.
Preventive controls are implemented after an incident, while detective controls are implemented before an incident.
OWASP focuses on which kind of risks?
Financial risks
Physical security risks
Web application security risks
Environmental risks
What is the purpose of CIS Benchmarks?
To provide security best practices for IT systems and software
To create new programming languages
To design hardware components for computers
To develop entertainment software
SOC 2 Type II is used to demonstrate:
Ongoing effectiveness of security controls over a period of time
Compliance with HIPAA regulations
Financial statement accuracy
Initial implementation of security controls
Select three competencies a security professional should have.
Technical expertise, risk assessment, communication skills
Cooking skills, artistic ability, musical talent
Salesmanship, fashion sense, gardening skills
Driving skills, painting, singing
Which control functional type operates after an attack to restore systems?
Detective
Preventive
Corrective
Deterrent
Combining frameworks, controls, and regulations is important for an organization's security posture because:
it ensures a comprehensive and layered approach to security.
it eliminates the need for employee training.
it guarantees zero security breaches.
it allows organizations to ignore compliance requirements.
Integrity in information security is defined as:
Ensuring data is accurate and unaltered.
Protecting data from unauthorized access.
Making data available when needed.
Encrypting data for confidentiality.
A SOC is primarily established for which of the following purposes?
To monitor and respond to security threats in an organization
To manage financial transactions
To oversee human resources activities
To develop marketing strategies
A compensating control is:
A security measure that substitutes for a primary control when it cannot be implemented.
A type of firewall used to block all network traffic.
A method for increasing employee productivity.
A way to reduce the cost of security systems.
NIST CSF stands for ______ and is useful because ______.
National Institute of Standards and Technology Cybersecurity Framework; it provides guidelines for managing and reducing cybersecurity risk.
National Information Security Taskforce Cybersecurity Formula; it helps in creating passwords.
Network Infrastructure Security Technology Control System; it is used for network monitoring.
National Internet Security Training Certification; it is required for IT professionals.
Which regulation focuses on protecting personal data of EU residents?
GDPR
HIPAA
CCPA
FERPA
The main goal of security testing is:
To identify vulnerabilities in a system
To improve the user interface
To increase system speed
To reduce development costs
Select three types of activities that belong to security testing.
Vulnerability scanning, penetration testing, risk assessment
Unit testing, integration testing, system testing
Usability testing, performance testing, load testing
Code review, debugging, documentation
The objective of a Vulnerability Assessment is:
To identify and evaluate security weaknesses in a system
To install new security software
To monitor network traffic continuously
To recover lost data
How does a pentest differ from a VA?
A pentest simulates real-world attacks to find vulnerabilities, while a VA only identifies and lists vulnerabilities without exploiting them.
A pentest is only for web applications, while a VA is for networks.
A pentest is less thorough than a VA.
A pentest does not require any technical skills, while a VA does.
The goal of a penetration test is:
To identify and exploit vulnerabilities in a system to assess its security.
To install new software on a system.
To improve system performance.
To backup data regularly.
The analogy of a house and a safe is used to describe VA vs Pentest. What does this analogy illustrate?
VA is like checking if the house is locked, while Pentest is like trying to break into the safe.
VA is like building a house, while Pentest is like decorating the safe.
VA is like buying furniture for the house, while Pentest is like painting the safe.
VA is like cleaning the house, while Pentest is like organizing the safe.
A Red Team’s main objective is:
To identify and exploit security vulnerabilities in an organization’s systems.
To provide technical support to users.
To develop new software applications for the organization.
To monitor network traffic for suspicious activity.
TTD and TTM are used for which purpose in Red Team engagements?
Measuring detection and mitigation times
Identifying vulnerabilities in code
Testing network bandwidth
Evaluating employee satisfaction
The Blue Team are responsible for which of the following tasks?
Defending systems against cyber attacks
Launching cyber attacks on other organizations
Developing new software applications
Managing company finances
What is the purpose of a Purple Team?
Enable real-time collaboration and feedback between Red and Blue Teams.
Conduct penetration testing independently.
Focus solely on defensive security measures.
Develop security policies without testing.
Why is a Rules of Engagement document important before a pentest?
Defines scope, schedule, and allowed actions; protects both client and tester legally.
It provides a list of vulnerabilities to be tested.
It guarantees the success of the pentest.
It replaces the need for any legal agreements.
List four common pentesting methodologies.
OWASP, NIST SP 800-115, OSSTMM, PTES.
ISO 27001, GDPR, HIPAA, PCI DSS.
Agile, Scrum, Waterfall, DevOps.
ITIL, COBIT, Six Sigma, PRINCE2.
According to PTES, what comes after 'Exploitation'?
Post-Exploitation then Reporting.
Reconnaissance then Scanning.
Vulnerability Analysis then Exploitation.
Reporting then Reconnaissance.
What does the OWASP Testing Guide focus on?
Testing web applications and services for security issues using global best practices.
Developing mobile applications for performance optimization.
Designing user interfaces for accessibility compliance.
Managing cloud infrastructure for cost efficiency.
Why must ethical hackers respect the testing scope?
Because testing outside the agreed scope is illegal and unauthorized.
Because it helps hackers learn new skills.
Because it makes the test easier to perform.
Because it increases the chances of finding vulnerabilities.
What is the difference between a threat and a vulnerability?
A threat is a potential attack; a vulnerability is the weakness that the threat can exploit.
A threat is a weakness; a vulnerability is an attack.
A threat and a vulnerability are the same thing.
A vulnerability is a potential attack; a threat is the weakness that can be exploited.
What creates a risk in cybersecurity?
When a threat successfully exploits a vulnerability.
When all vulnerabilities are patched.
When there are no threats present.
When security measures are perfect.
Name two academic sources for cybersecurity research.
IEEE Xplore and ACM Digital Library (also arXiv).
Wikipedia and Reddit.
YouTube and Facebook.
Quora and Instagram.
What is the purpose of RFCs in cybersecurity?
Define standards and best practices for Internet and security protocols.
Monitor network traffic for malicious activity.
Encrypt data to prevent unauthorized access.
Develop antivirus software for endpoint protection.
Give two well-known cybersecurity conferences.
DEF CON and Black Hat (others: RSA, Usenix).
Comic-Con and E3 (others: PAX, Gamescom).
CES and MWC (others: IFA, Computex).
Sundance and Cannes (others: TIFF, Berlinale).
Give two well-known cybersecurity conferences.
DEF CON and Black Hat (others: RSA, USENIX).
Comic-Con and E3 (others: PAX, Gamescom).
CES and MWC (others: IFA, Computex).
Sundance and Cannes (others: TIFF, Berlinale).
What does STIX stand for and what does it do?
Structured Threat Information Expression – standard format for sharing threat data.
Secure Threat Intelligence Exchange – protocol for encrypting threat reports.
Systematic Threat Investigation Xchange – tool for analyzing cyber threats.
Standardized Threat Identification XML – markup language for threat signatures.
What is TAXII used for?
The protocol for transporting structured threat information (STIX data).
A tool for encrypting email messages.
A framework for network device management.
A protocol for secure web browsing.
Which U.S. government service enables automated cyber threat data sharing?
AIS (Automated Indicator Sharing) by DHS.
USPS (United States Postal Service)
IRS (Internal Revenue Service)
SSA (Social Security Administration)
What does CVE stand for?
Common Vulnerabilities and Exposures.
Certified Vulnerability Expert.
Computer Virus Encyclopedia.
Cybersecurity Vulnerability Event.
Who maintains the NVD?
NIST (National Institute of Standards and Technology).
Microsoft Corporation.
Google LLC.
International Organization for Standardization (ISO).
What is Exploit-DB used for?
It provides public exploits and proof-of-concept code for known vulnerabilities.
It is a database for storing encrypted passwords.
It is a tool for scanning networks for vulnerabilities.
It is a platform for secure file sharing.
What kind of data do Threat Maps visualize?
Real-time cyberattacks – their sources, targets, and types.
Weather patterns and climate changes.
Stock market trends and financial data.
Global shipping routes and logistics information.
Give one example of a well-known cybersecurity blog.
Krebs on Security or Schneier on Security.
TechCrunch
Mashable
Gizmodo
Why are default passwords a vulnerability?
They allow attackers easy access if not changed after installation.
They improve system performance.
They make the system more secure.
They prevent unauthorized updates.
Which database lists default credentials for common devices?
cirt.net/passwords.
exploit-db.com/credentials.
shodan.io/defaults.
securityfocus.com/passwords.
What is the difference between a threat and a vulnerability? (Fill in the blank)
A threat is a potential attack; a vulnerability is the weakness that the threat can exploit.
A threat is a weakness; a vulnerability is a potential attack.
A threat and a vulnerability are the same thing.
A vulnerability is a potential attack; a threat is the weakness that the vulnerability can exploit.
What creates a risk in cybersecurity? (Fill in the blank)
When a threat successfully exploits a vulnerability.
When a vulnerability is patched.
When security policies are strictly followed.
When there are no threats present.
Name two academic sources for cybersecurity research.
IEEE Xplore and ACM Digital Library (also arXiv).
Wikipedia and Reddit.
YouTube and Facebook.
Quora and Instagram.
What is the purpose of RFCs in cybersecurity?
Define standards and best practices for Internet and security protocols.
Provide encryption keys for secure communication.
Monitor network traffic for malicious activity.
Develop malware for penetration testing.
Give two well-known cybersecurity conferences.
DEF CON and Black Hat (others: RSA, USENIX).
Comic-Con and E3 (others: PAX, Gamescom).
CES and MWC (others: IFA, Computex).
Sundance and Cannes (others: TIFF, Berlinale).
What does STIX stand for and what does it do?
Structured Threat Information Expression — standard format for sharing threat data.
Secure Transmission Internet Exchange — protocol for secure email.
Systematic Threat Intelligence Xchange — a malware removal tool.
Security Threat Investigation XML — a vulnerability scanner.
What is TAXII used for?
The protocol for transporting structured threat information (STIX data).
A tool for encrypting email messages.
A method for scanning network vulnerabilities.
A protocol for secure file transfer.
Which U.S. government service enables automated cyber threat data sharing?
AIS (Automated Indicator Sharing) by DHS.
USPS (United States Postal Service)
IRS (Internal Revenue Service)
SSA (Social Security Administration)
What does CVE stand for?
Common Vulnerabilities and Exposures.
Certified Vulnerability Expert.
Computer Virus Encyclopedia.
Cybersecurity Vulnerability Evaluation.
Who maintains the NVD?
NIST (National Institute of Standards and Technology).
Microsoft Corporation.
International Organization for Standardization (ISO).
Google Inc.
What is Exploit-DB used for?
It provides public exploits and proof-of-concept code for known vulnerabilities.
It is a database for storing encrypted passwords.
It is a tool for scanning network ports.
It is a platform for sharing open-source software projects.
What kind of data do Threat Maps visualize?
Real-time cyberattacks — their sources, targets, and types.
Historical weather patterns and forecasts.
Global financial transactions and market trends.
Social media activity and user engagement statistics.
Give one example of a well-known cybersecurity blog.
Krebs on Security or Schneier on Security.
TechCrunch
Mashable
Gizmodo
Why are default passwords a vulnerability?
They allow attackers easy access if not changed after installation.
They improve system performance.
They make the system more secure.
They prevent unauthorized access.
Which database lists default credentials for common devices?
cirt.net/passwords.
exploit-db.com/credentials.
shodan.io/defaults.
securityfocus.com/passwords.
What is the main purpose of encryption?
To protect confidentiality by converting plaintext into unreadable ciphertext.
To increase the speed of data transmission.
To compress data for storage efficiency.
To ensure data is always available.
Is hashing reversible?
No – it’s a one-way process for data integrity.
Yes – you can always retrieve the original data.
Sometimes – depending on the algorithm used.
Only if you have the secret key.
Difference between symmetric and asymmetric encryption?
Symmetric uses one shared key; asymmetric uses a public/private pair.
Symmetric uses two keys; asymmetric uses one shared key.
Symmetric uses only public keys; asymmetric uses only private keys.
Symmetric and asymmetric encryption are identical.
Give one example of a symmetric and one asymmetric cipher.
AES (symmetric), RSA (asymmetric).
DES (asymmetric), ECC (symmetric).
RSA (symmetric), AES (asymmetric).
Blowfish (asymmetric), ElGamal (symmetric).
What is the main problem with symmetric encryption?
Secure distribution of the shared key.
High computational cost compared to asymmetric encryption.
Lack of encryption algorithms.
Inability to encrypt large files.
What does ECC offer compared to RSA?
Same security with smaller key sizes and less computational load.
Lower security and higher computational load.
No advantage in key size or computational efficiency.
Requires larger key sizes for equivalent security.
What does a digital signature prove?
Integrity, authenticity, and non-repudiation of a message.
Confidentiality and encryption of a message.
The physical location of the sender.
The speed of message transmission.
What is Perfect Forward Secrecy (PFS)?
Ensures old session data remains confidential even if a long-term key is later compromised.
Allows encrypted data to be decrypted if the session key is lost.
Requires all users to share the same encryption key for every session.
Prevents the use of encryption in future sessions.
Which mode of operation uses XOR and an IV to link blocks?
Cipher Block Chaining (CBC).
Electronic Codebook (ECB).
Output Feedback (OFB).
Counter (CTR).
What is salting used for? (Fill in the blank)
Adds randomness to password hashes to prevent rainbow table attacks.
Encrypts passwords for secure storage.
Removes special characters from passwords.
Stores passwords in plain text for easy retrieval.
What is a Certificate Authority (CA)?
A trusted organization that issues and signs digital certificates.
A type of encryption algorithm used for securing data.
A protocol for transferring files over the internet.
A device used to store cryptographic keys.
What is stored in a digital certificate?
The subject's public key plus identity info and validity period.
Only the subject's private key.
A list of trusted websites.
Encrypted passwords.
How does OCSP differ from CRL? (Fill in the blank)
OCSP checks certificate status online in real time; CRL is a periodic revocation list.
OCSP is used for encrypting data; CRL is used for signing certificates.
OCSP is a type of certificate; CRL is a type of encryption algorithm.
OCSP is a hardware device; CRL is a software protocol.
Name two cryptographic technologies shaping the future. (Fill in the blank)
Post-Quantum Cryptography and Homomorphic Encryption.
Symmetric Encryption and Hash Functions.
Classical Cryptography and Steganography.
Digital Signatures and Password Hashing.
What is Steganography used for?
Hiding information inside other files (e.g., images or audio) without visible changes.
Encrypting data using complex algorithms.
Compressing files to reduce their size.
Transmitting data over secure networks.
What is the main purpose of the WHOIS tool?
To retrieve domain registration and ownership information.
To encrypt website data for security.
To monitor website traffic statistics.
To block malicious IP addresses.
Which command can be used to find WHOIS data for a university domain?
whois sdu.edu.kz
ping sdu.edu.kz
nslookup sdu.edu.kz
traceroute sdu.edu.kz
What kind of devices does Shodan index?
Internet-connected devices (IoT, servers, webcams, routers, etc.)
Offline devices (not connected to the internet)
Mobile applications only
Local computer files
What is required before using the Shodan CLI?
An API key obtained after signing up.
A VPN connection.
A premium subscription.
A verified email address.
Which Shodan command lists IP port, and organization info?
shodan search -fields ip,str,port,org 'hostname:"example.com"'
shodan info -fields ip,port,org 'hostname:"example.com"'
shodan scan -fields ip,port,org 'hostname:"example.com"'
shodan list -fields ip,port,org 'hostname:"example.com"'
What does the DIG command do?
Retrieves DNS records for a given domain.
Deletes files from a directory.
Displays disk usage statistics.
Installs software packages.
What is the function of netstat?
Displays open ports and network connections.
Monitors CPU usage.
Manages disk partitions.
Edits system registry.
What does nslookup check?
DNS information (domain-to-IP mappings).
CPU usage statistics.
File system permissions.
Network cable integrity.
Which command in nmap performs a TCP SYN scan?
nmap -sS
nmap -sT
nmap -sU
nmap -sP
What is the purpose of the O flag in nmap?
To detect the operating system.
To scan for open ports only.
To enable verbose output.
To perform a stealth scan.
Which flag in nmap scans all ports?
-p-
-A
-sV
-O
Why is UDP scanning considered "noisy"?
It sends many packets and can easily be detected or slowed down.
It always uses encrypted packets.
It only scans open ports.
It never triggers any alerts.
What does masscan do?
Performs very fast network scans.
Encrypts files on a system.
Monitors CPU usage.
Creates backup copies of data.
What is the function of amass?
Enumerates subdomains.
Scans for open ports.
Performs brute force attacks.
Encrypts network traffic.
What is gobuster used for?
Directory and file brute-forcing on web servers.
Password cracking for SSH servers.
Scanning for open ports on a network.
Intercepting and modifying HTTP requests.
What is the main use of Nikto?
Scans web servers for vulnerabilities and outdated software.
Monitors network traffic for suspicious activity.
Encrypts files for secure storage.
Manages user authentication on web applications.
How many potential issues can Nikto test for?
Over 7,000 potentially dangerous files and configurations.
About 500 files and configurations.
Less than 1,000 files and configurations.
Exactly 2,000 files and configurations.
What programming language is recon-ng built in?
Python.
Java.
C++.
Ruby.
What is hping3 commonly used for?
Packet crafting, spoofing, and DoS simulation.
Web application development.
Database management and optimization.
Image editing and graphic design.
Video streaming and playback.
Why is authorization important before scanning?
Because unauthorized scanning is illegal and unethical.
Because it makes scanning faster.
Because it improves network speed.
Because it guarantees data accuracy.
Which tool is used to find domain registration details like registrar and expiry date?
WHOIS
Ping
Traceroute
Nslookup
Which web tool is used to find information about domain name and SSL?
CA information, Censys
Google Analytics
Pingdom
Mailchimp
Which command displays your system's IP configuration details?
ipconfig
ping
dir
cls
Which command is used to track the path packets take to a destination host?
traceroute
ping
netstat
ifconfig
