WorksheetsL 1 2 3 4
Total questions: 100
Worksheet time: 50mins
Which type of security control includes alarms, gateways, locks, and guards to detect access to premises and hardware?
Physical control
Technical control
Administrative control
Logical control
What type of security control discourages attackers psychologically, e.g. warning signs or legal penalty?
Deterrent control
Preventive control
Detective control
Corrective control
What term describes the property of a secure network where a sender cannot deny having sent a message?
Non-repudiation
Confidentiality
Integrity
Availability
Which property ensures that systems operate continuously and authorized users can access data?
Availability
Confidentiality
Integrity
Authentication
What does NIST stand for in the context of information security?
National Institute of Standards and Technology
National Information Security Taskforce
Network Institute for Security Technologies
National Internet Security Team
National Institute of Secure Transactions
Which of the ISO standards are about personal data and privacy?
ISO 27701
ISO 9001
ISO 14001
ISO 50001
Which security business function helps resolve tensions between IT and programming divisions in a growing business?
DevSecOps
Penetration Testing
Incident Response
Network Monitoring
Which security business function helps resolve tensions between IT and programming divisions in a growing business (Variant 2)?
DevSecOps
Penetration Testing
Network Monitoring
Incident Response
Who ensures fairness and referees between red and blue team activities?
White cell
Red cell
Blue cell
Green cell
What describes a “script kiddie”?
A user of pre-made tools without deep technical understanding
A professional hacker with advanced skills
A developer who writes original security software
A cybersecurity expert specializing in penetration testing
Which type of malware is self-replicating and spreads across networks without requiring user interaction?
Worm
Trojan Horse
Spyware
Adware
Which risk arises when competitors use cyber espionage?
Theft of intellectual property or disruption or damage to reputation
Increase in employee satisfaction
Improvement in public relations
Reduction in operational costs
Which type of threat intelligence platform is usually subscription-based and closed?
Closed or proprietary threat intelligence platforms
Open-source threat intelligence platforms
Community-driven threat intelligence platforms
Government-sponsored threat intelligence platforms
Which of the following is an example of an attack vector (multiple correct answers)?
Removable media
Direct physical access
What resource level usually enables the most sophisticated threat actors?
Substantial budget and funding (nation states or criminal syndicates)
Limited access to open-source tools
Basic technical skills with minimal funding
Volunteer-based resources
Which statement best describes a vulnerability in the context of security assessments?
A weakness that could be exploited to cause a breach
A tool used to prevent unauthorized access
A method for encrypting sensitive data
A process for monitoring network traffic
Which term describes an unencrypted message?
Plaintext
Ciphertext
Hash
Token
Which hashing algorithm generates a 256-bit digest?
SHA-256
MD5
SHA-1
RIPEMD-160
ROT13 is an example of which type of cipher?
Substitution
Transposition
Stream
Block
Which encryption method uses the same secret key for both encryption and decryption?
Symmetric
Asymmetric
Public Key
Hashing
Which encryption uses a public and private key pair?
Asymmetric
Symmetric
Hashing
Steganography
What cryptographic function is created by combining hashing with private key encryption?
Digital Signature
Symmetric Encryption
Hash Function
Public Key Infrastructure
Which algorithm allows Alice and Bob to derive a shared secret over an insecure channel?
Diffie-Hellman
RSA
SHA-256
AES
Which technique hides information inside images or audio?
Steganography
Cryptography
Watermarking
Compression
Which authority validates digital certificates?
Certificate Authority
Domain Registrar
Internet Service Provider
Web Browser
What are the three components of the CIA triad?
Confidentiality, Integrity, Availability.
Control, Investigation, Authentication.
Confidentiality, Investigation, Authorization.
Control, Integrity, Authentication.
Name two responsibilities of a CISO.
Security strategy and governance; incident response oversight; risk management; policy creation (any two).
Managing company finances; overseeing marketing campaigns; product development; customer service (any two).
Organizing company events; handling payroll; designing office layouts; planning vacations (any two).
Supervising cafeteria staff; maintaining office plants; scheduling janitorial services; ordering office supplies (any two).
Give one example of a technical control and one operational control.
Technical: firewall or encryption. Operational: security awareness training or change-management procedures.
Technical: password reuse. Operational: ignoring security policies.
Technical: using outdated software. Operational: disabling antivirus.
Technical: sharing passwords. Operational: skipping security audits.
What is the difference between preventive and detective controls?
Preventive controls stop attacks before they happen (e.g., access control); detective controls identify or record attacks in progress or after (e.g., IDS, logs).
Preventive controls only monitor attacks, while detective controls block them before they happen.
Preventive controls are used after an attack, while detective controls are used before an attack.
Preventive controls and detective controls serve the same purpose and are interchangeable.
What kind of risks does OWASP focus on?
Web application and API security risks (OWASP Top 10).
Physical security risks in data centers.
Risks related to hardware manufacturing defects.
Financial risks in banking operations.
What is the purpose of CIS Benchmarks?
Provide secure configuration guidance and checklists to harden systems.
Monitor network traffic for suspicious activity.
Develop new operating systems for commercial use.
Create malware detection algorithms.
What is SOC 2 Type II used to demonstrate?
That a service provider not only has controls designed but also operating effectively over time.
That a service provider is compliant with GDPR regulations.
That a service provider has achieved ISO 27001 certification.
That a service provider only has controls designed, not necessarily operating effectively over time.
Name three competencies a security professional should have (from the slides).
Risk assessments/testing; log auditing; business continuity planning (any three).
Graphic design; social media management; event planning.
Sales forecasting; customer service; product development.
Interior decorating; fashion consulting; travel planning.
Which control functional type operates after an attack to restore systems?
Corrective control.
Preventive control.
Detective control.
Compensating control.
Combining frameworks, controls, and regulations is important for an organization because:
it helps ensure comprehensive risk management and compliance.
it increases operational costs without benefits.
it complicates decision-making unnecessarily.
it reduces the need for employee training.
A framework helps an organization's security posture by:
Providing structured guidelines and best practices for security.
Allowing unrestricted access to all systems.
Eliminating the need for security policies.
Guaranteeing complete immunity from cyber threats.
Integrity in information security is defined as:
Ensuring that information is accurate and unaltered.
Preventing unauthorized access to information.
Guaranteeing the availability of information when needed.
Encrypting data to protect its confidentiality.
A SOC is primarily established for which of the following purposes?
To monitor and respond to security threats
To develop software applications
To manage company finances
To oversee employee recruitment
A compensating control is:
A security measure that substitutes for a primary control when it cannot be implemented, such as using CCTV cameras when physical guards are not available.
A control that is always more expensive than the primary control.
A control that eliminates all risks without any exceptions.
A control that is only used in financial audits.
NIST CSF stands for ______ and is useful because ______.
National Institute of Standards and Technology Cybersecurity Framework; it provides guidelines for managing and reducing cybersecurity risk.
National Information Security Taskforce Cybersecurity Formula; it helps in creating passwords.
Network Infrastructure Security Technology Control System; it is used for monitoring network traffic.
National Internet Security Team Cybersecurity Foundation; it is useful for training employees.
Which regulation focuses on protecting personal data of EU residents?
GDPR
HIPAA
FERPA
CCPA
The main goal of security testing is:
to identify vulnerabilities in a system
to improve the user interface
to increase system speed
to reduce development costs
Which of the following lists three types of activities that belong to security testing?
Vulnerability scanning, penetration testing, security auditing
Unit testing, integration testing, system testing
Performance testing, usability testing, reliability testing
Code review, documentation, deployment
The objective of a Vulnerability Assessment is:
To identify and evaluate security weaknesses in a system
To install new software updates
To monitor network traffic continuously
To create user accounts
A pentest differs from a VA in that:
A pentest simulates real-world attacks, while a VA identifies vulnerabilities without exploiting them.
A pentest only scans for vulnerabilities, while a VA exploits them.
A pentest is less thorough than a VA.
A pentest is performed without any tools, while a VA uses automated tools.
The goal of a penetration test is:
to identify and exploit vulnerabilities in a system to assess its security.
to install new software on a system.
to improve system performance.
to backup data regularly.
Describe the analogy of a house and a safe for VA vs Pentest.
VA is like checking if the house is locked; Pentest is like trying to break into the safe.
VA is like building a house; Pentest is like buying a safe.
VA is like painting the house; Pentest is like cleaning the safe.
VA is like owning a house; Pentest is like renting a safe.
A Red Team’s main objective is:
to identify and exploit vulnerabilities in systems to improve security
to monitor network traffic for suspicious activity
to develop security policies and procedures
to provide technical support to end users
TTD and TTM are used for what purpose in Red Team engagements?
Measuring detection and mitigation times
Identifying vulnerabilities in code
Testing network bandwidth
Evaluating employee satisfaction
The Blue Team are responsible for which of the following activities?
Defending systems against cyber attacks
Launching cyber attacks on other organizations
Developing new software applications
Managing company finances
The purpose of a Purple Team is:
To facilitate collaboration between Red and Blue Teams for improved cybersecurity.
To conduct penetration testing independently.
To manage network infrastructure.
To develop security policies without testing.
A Rules of Engagement document is important before a pentest because:
it defines the scope, boundaries, and expectations for the test
it provides a list of vulnerabilities to exploit
it guarantees the success of the pentest
it eliminates the need for any legal agreements
List four common pentesting methodologies.
OWASP, NIST SP 800-115, OSSTMM, PTES.
ISO 27001, COBIT, ITIL, PCI DSS.
Agile, Scrum, Waterfall, DevOps.
GDPR, HIPAA, FERPA, SOX.
According to PTES, what comes after “Exploitation”?
Post-Exploitation, then Reporting.
Reconnaissance, then Scanning.
Vulnerability Assessment, then Exploitation.
Reporting, then Reconnaissance.
What does the OWASP Testing Guide focus on?
Testing web applications and services for security issues using global best practices.
Designing user interfaces for web applications.
Optimizing web applications for performance and speed.
Developing mobile applications using secure coding techniques.
Why must ethical hackers respect the testing scope?
Because testing outside the agreed scope is illegal and unauthorized.
Because it helps hackers gain more access to sensitive data.
Because it allows hackers to bypass security protocols.
Because it makes the hacking process faster.
What is the difference between a threat and a vulnerability?
A threat is a potential attack; a vulnerability is the weakness that the threat can exploit.
A vulnerability is a potential attack; a threat is the weakness that the vulnerability can exploit.
A threat and a vulnerability are the same thing in cybersecurity.
A threat is a security patch; a vulnerability is a type of malware.
What creates a risk in cybersecurity?
When a threat successfully exploits a vulnerability.
When all vulnerabilities are patched.
When there are no threats present.
When security policies are strictly followed.
Name two academic sources for cybersecurity research.
IEEE Xplore and ACM Digital Library (also arXiv).
Reddit and Facebook.
Wikipedia and Quora.
YouTube and Instagram.
What is the purpose of RFCs in cybersecurity?
Define standards and best practices for Internet and security protocols.
Monitor network traffic for malicious activity.
Encrypt data to prevent unauthorized access.
Detect and respond to cyber threats in real time.
Give two well-known cybersecurity conferences.
DEF CON and Black Hat (others: RSA, USENIX).
Comic-Con and E3 (others: PAX, Gamescom).
CES and MWC (others: IFA, Computex).
Sundance and Cannes (others: TIFF, Berlinale).
What does STIX stand for and what does it do?
Structured Threat Information Expression – standard format for sharing threat data.
Secure Threat Intelligence Exchange – protocol for encrypting threat reports.
Systematic Threat Investigation Xchange – tool for analyzing cyber attacks.
Standardized Threat Indicator XML – markup language for malware signatures.
What is TAXII used for?
The protocol for transporting structured threat information (STIX data).
A tool for encrypting email messages.
A method for scanning network vulnerabilities.
A protocol for wireless communication.
Which U.S. government service enables automated cyber threat data sharing?
AIS (Automated Indicator Sharing) by DHS.
USPS (United States Postal Service)
IRS (Internal Revenue Service)
SSA (Social Security Administration)
What does CVE stand for?
Common Vulnerabilities and Exposures.
Certified Vulnerability Expert.
Computer Virus Encyclopedia.
Cybersecurity Vulnerability Evaluation.
Who maintains the NVD?
NIST (National Institute of Standards and Technology).
Microsoft Corporation.
Open Web Application Security Project (OWASP).
Internet Engineering Task Force (IETF).
What is Exploit-DB used for?
It provides public exploits and proof-of-concept code for known vulnerabilities.
It is a database for storing encrypted passwords.
It is a tool for scanning network ports.
It is a platform for sharing open-source software projects.
What kind of data do Threat Maps visualize?
Real-time cyberattacks – their sources, targets, and types.
Historical weather patterns across continents.
Global financial transactions between banks.
Social media trends and user engagement statistics.
Give one example of a well-known cybersecurity blog.
Krebs on Security or Schneier on Security.
TechCrunch
Mashable
Gizmodo
Why are default passwords a vulnerability?
They allow attackers easy access if not changed after installation.
They improve system performance.
They make the system more secure.
They prevent unauthorized updates.
Which database lists default credentials for common devices?
cirt.net/passwords.
exploit-db.com/vulnerabilities.
shodan.io/devices.
nvd.nist.gov/credentials.
What is the difference between a threat and a vulnerability?
A threat is a potential attack; a vulnerability is the weakness that the threat can exploit.
A vulnerability is a potential attack; a threat is the weakness that the vulnerability can exploit.
A threat and a vulnerability are the same thing in cybersecurity.
A threat is always internal; a vulnerability is always external.
What creates a risk in cybersecurity?
When a threat successfully exploits a vulnerability.
When all vulnerabilities are patched.
When security policies are strictly followed.
When there are no threats present.
Name two academic sources for cybersecurity research.
IEEE Xplore and ACM Digital Library (also arXiv).
Wikipedia and Reddit.
YouTube and Facebook.
Quora and Instagram.
What is the purpose of RFCs in cybersecurity?
Define standards and best practices for Internet and security protocols.
Monitor network traffic for malicious activity.
Encrypt data transmissions over the Internet.
Detect and remove malware from computer systems.
Give two well-known cybersecurity conferences.
DEF CON and Black Hat (others: RSA, USENIX).
Comic-Con and E3 (others: PAX, Gamescom).
CES and MWC (others: IFA, Computex).
Sundance and Cannes (others: TIFF, Berlinale).
What does STIX stand for and what does it do?
Structured Threat Information Expression – standard format for sharing threat data.
Secure Transmission Internet Exchange – protocol for secure email.
Systematic Threat Investigation Xchange – tool for malware analysis.
Standardized Technical Information XML – format for software documentation.
What is TAXII used for?
The protocol for transporting structured threat information (STIX data).
A tool for encrypting email messages.
A method for scanning network vulnerabilities.
A protocol for managing user authentication.
Which U.S. government service enables automated cyber threat data sharing?
AIS (Automated Indicator Sharing) by DHS.
USPS (United States Postal Service)
IRS (Internal Revenue Service)
SSA (Social Security Administration)
What does CVE stand for?
Common Vulnerabilities and Exposures.
Certified Vulnerability Expert.
Computer Virus Encyclopedia.
Cybersecurity Vulnerability Evaluation.
Who maintains the NVD?
NIST (National Institute of Standards and Technology).
Microsoft Corporation.
Open Web Application Security Project (OWASP).
Internet Engineering Task Force (IETF).
What is Exploit-DB used for?
It provides public exploits and proof-of-concept code for known vulnerabilities.
It is a database for storing encrypted passwords.
It is a tool for scanning network ports.
It is a platform for sharing open-source software projects.
What kind of data do Threat Maps visualize?
Real-time cyberattacks – their sources, targets, and types.
Weather patterns across the globe.
Stock market trends and financial forecasts.
Global population growth statistics.
Give one example of a well-known cybersecurity blog.
Krebs on Security or Schneier on Security.
TechCrunch
Mashable
Gizmodo
Why are default passwords a vulnerability?
They allow attackers easy access if not changed after installation.
They improve system performance.
They make the system more secure.
They are always unique for each device.
Which database lists default credentials for common devices?
cirt.net/passwords.
exploit-db.com/credentials.
shodan.io/defaults.
securityfocus.com/passwords.
What is the main purpose of encryption?
To protect confidentiality by converting plaintext into unreadable ciphertext.
To increase the speed of data transmission.
To compress data for storage efficiency.
To verify the identity of a sender.
Is hashing reversible?
No – it’s a one-way process for data integrity.
Yes – you can always get the original data back.
Only reversible with a special key.
It depends on the algorithm used.
Difference between symmetric and asymmetric encryption?
Symmetric uses one shared key; asymmetric uses a public/private pair.
Symmetric uses two keys; asymmetric uses one shared key.
Symmetric uses only public keys; asymmetric uses only private keys.
Symmetric and asymmetric encryption are identical.
Give one example of a symmetric and one asymmetric cipher.
AES (symmetric), RSA (asymmetric).
DES (asymmetric), ECC (symmetric).
RSA (symmetric), AES (asymmetric).
Blowfish (asymmetric), Diffie-Hellman (symmetric).
The main problem with symmetric encryption is:
It requires both parties to share and securely manage the same secret key.
It uses very weak algorithms for encryption.
It is only used for encrypting images.
It does not provide any confidentiality.
ECC offers which of the following advantages compared to RSA?
Stronger security with shorter key lengths
Requires longer key lengths for equivalent security
Is less efficient than RSA
Provides no advantage over RSA
A digital signature proves:
the authenticity and integrity of a message
the speed of data transmission
the size of the file
the type of encryption used
Perfect Forward Secrecy (PFS) refers to:
A security feature that ensures session keys cannot be compromised even if the server's private key is exposed.
A method for encrypting data using only symmetric keys.
A protocol for authenticating users without passwords.
A technique for storing passwords securely on a server.
The mode of operation that uses XOR and an IV to link blocks is:
ECB (Electronic Codebook)
CBC (Cipher Block Chaining)
OFB (Output Feedback)
CFB (Cipher Feedback)
Salting is used for:
Enhancing password security by adding random data
Encrypting data with a public key
Compressing files to save space
Improving network speed
A Certificate Authority (CA) is:
an organization that issues digital certificates to verify identities online
a type of encryption algorithm used for secure communication
a protocol for transferring files over the internet
a device used to store cryptographic keys
What is stored in a digital certificate?
The public key and identity information of the certificate holder
Only the private key of the certificate holder
A list of all trusted websites
The password for secure access
OCSP differs from CRL in which of the following ways?
OCSP provides real-time certificate status, while CRL provides periodic lists of revoked certificates.
OCSP and CRL both provide real-time certificate status.
CRL is faster than OCSP in checking certificate status.
OCSP provides a list of revoked certificates, while CRL checks certificate status individually.
Name two cryptographic technologies shaping the future.
Quantum cryptography and blockchain technology
Symmetric encryption and steganography
Classical ciphers and hashing
Password protection and data compression
