wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CIA Triad and Security Concepts Worksheet

Total questions: 100

Worksheet time: 53mins

Name
Class
Date
1.

The three concepts that form the CIA triad are:

a)

confidentiality, integrity and availability

b)

communication, integrity and authentication

c)

confidentiality, integrity, access control

d)

communication, information and authenticity

2.

A loss of ________ is the unauthorized disclosure of information.

a)

authenticity

b)

confidentiality

c)

reliability

d)

integrity

3.

Verifying that users are who they say they are is ________.

a)

authenticity

b)

credibility

c)

accountability

d)

integrity

4.

Any action that compromises security is a:

a)

security attack

b)

security service

c)

security alert

d)

security mechanism

5.

One entity pretends to be another:

a)

replay

b)

masquerade

c)

service denial

d)

passive attack

6.

Protection of transmitted data from passive attacks is:

a)

encryption

b)

compression

c)

fragmentation

d)

multiplexing

7.

A service protecting availability:

a)

replay

b)

availability

c)

masquerade

d)

integrity

8.

Threats inhibiting legitimate users:

a)

Information access

b)

Reliability

c)

Passive

d)

Service

9.

A potential for violation of security:

a)

threat

b)

attack

c)

risk

d)

attack vector

10.

Protection against traffic analysis:

a)

connectionless confidentiality

b)

connection confidentiality

c)

traffic-flow confidentiality

d)

selective-field confidentiality

11.

Data proving source and integrity:

a)

A. Authentication

b)

B. Authorization

c)

C. Nonrepudiation

d)

D. Encryption

12.

Mapping plaintext to ciphertext:

a)

Transposition

b)

Substitution

c)

Traditional

d)

Symmetric

13.

Original message & coded message:

a)

decryption, encryption

b)

plaintext, ciphertext

c)

deciphering, enciphering

d)

cipher, plaintext

14.

Restoring plaintext:

a)

deciphering

b)

transposition

c)

steganography

d)

encryption

15.

Trying every possible key:

a)

brute-force

b)

Caesar attack

c)

ciphertext only

d)

chosen plaintext

16.

Deciphering without algorithm knowledge:

a)

brute-force

b)

Caesar attack

c)

ciphertext only

d)

chosen plaintext

17.

Select the correct answer.

a)

blind deciphering

b)

steganography

c)

cryptanalysis

d)

transposition

18.

Ciphertext + key → plaintext:

a)

Voronoi algorithm

b)

decryption algorithm

c)

cryptanalysis

d)

diagram algorithm

19.

Same key used by both sides:

a)

public-key encryption

b)

two-key

c)

asymmetric

d)

conventional encryption

20.

Algorithm-exploiting attacks:

a)

Brute-force

b)

Cryptanalytic

c)

Block cipher

d)

Transposition

21.

Easiest attack to defend:

a)

ciphertext-only

b)

chosen ciphertext

c)

known plaintext

d)

chosen plaintext

22.

22. A way to improve on the simple monoalphabetic technique is to use different monoalphabetic substitutions as one proceeds through the plaintext message. The general name for this approach is:

a)

Polyalphabetic cipher

b)

Transposition cipher

c)

Caesar cipher

d)

Stream cipher

23.

A technique referred to as a __________ is a mapping achieved by performing some sort of permutation on the plaintext letters.

a)

transposition cipher

b)

polyalphabetic cipher

c)

Caesar cipher

d)

monoalphabetic cipher

24.

The methods of __________ conceal the existence of the message in a graphic image.

a)

steganography

b)

decryptology

c)

cryptology

d)

cryptograph

25.

DES exhibits the classic __________ block cipher structure, which consists of a number of identical rounds of processing.

a)

Feistel

b)

SAC

c)

Shannon

d)

Rendell

26.

A sequence of plaintext elements is replaced by a __________ of that sequence.

a)

permutation

b)

diffusion

27.

A _________ cipher encrypts data one bit or one byte at a time.

a)

product

b)

block

c)

key

d)

stream

28.

The vast majority of network-based symmetric cryptographic applications use _________ ciphers.

a)

linear

b)

block

c)

permutation

d)

stream

29.

A _________ cipher treats a block of plaintext as a whole and produces an equal-length ciphertext block.

a)

bit

b)

product

c)

stream

d)

block

30.

_________ is when each plaintext element is uniquely replaced by a corresponding ciphertext element.

a)

Substitution

b)

Diffusion

31.

Key sizes of _________ or less are now considered to be inadequate.

a)

128 bits

b)

32 bits

c)

16 bits

d)

64 bits

32.

Feistel proposed the concept of a _________ cipher, which is the execution of multiple ciphers in sequence.

a)

linear

b)

permutation

c)

differential

d)

product

33.

The criteria used in the design of the _________ focused on the design of the S-boxes and the P function.

a)

Avalanche Attack

b)

Data Encryption Standard

c)

Product Cipher

d)

Substitution Key

34.

The greater the number of rounds, the _________ it is to perform cryptanalysis.

a)

easier

b)

less difficult

c)

equally difficult

d)

harder

35.

The function F provides the element of __________ in a Feistel cipher.

a)

clarification

b)

alignment

c)

confusion

d)

stability

36.

One of the most intense research areas in symmetric block ciphers is __________ design.

a)

S-box

b)

F-box

c)

E-box

d)

D-box

37.

Mister and Adams proposed S-box columns should be __________ functions.

a)

horizontal

b)

angular

c)

bent

d)

vertical

38.

The Nyberg approach with simple mathematics is __________.

a)

human-made

b)

random

c)

math-made

d)

random with testing

39.

Allowing maximum encryption mappings is the __________.

4 lines
40.

Authentication applied to the entire original IP packet is ___________.

a)

security mode

b)

cipher mode

c)

tunnel mode

d)

transport mode

41.

Asymmetric encryption is also known as:

a)

public-key encryption

b)

private-key encryption

c)

optimal encryption

d)

digital-key encryption

42.

Public-key encryption is also known as:

a)

digital-key encryption

b)

asymmetric encryption

c)

one-way time exchange encryption

d)

optimal-key encryption

43.

Asymmetric encryption can be used for:

a)

both confidentiality and authentication

b)

neither confidentiality nor authentication

c)

confidentiality

d)

authentication

44.

The plaintext is recovered from the ciphertext using the paired key and a:

a)

digital signature

b)

recovery encryption

c)

decryption algorithm

d)

encryption algorithm

45.

The most widely used public-key cryptosystem is:

a)

optimal asymmetric encryption

b)

asymmetric encryption

c)

RSA

d)

DES

46.

Public-key algorithms are based on:

a)

permutation

b)

mathematical functions

c)

substitution

d)

symmetry

47.

__________ are two related keys, a public key and a private key:

a)

Asymmetric keys

b)

Key exchanges

c)

Symmetric keys

d)

Cipher keys

48.

The _________ indicates that the subscriber has sole control of the private key.

a)

OAEP

b)

Public Key Certificate

49.

A cryptographic algorithm that uses a public key and private key is:

a)

Private Key Cryptographic Algorithm

b)

Key Exchange Cryptographic Algorithm

c)

Public Key Cryptographic Algorithm

d)

RSA Digital Cryptographic Algorithm

50.

A public-key encryption scheme has _________ ingredients.

a)

six

b)

four

c)

eight

d)

two

51.

The key used in symmetric encryption is called a:

a)

public

b)

secret

c)

private

d)

decryption

52.

The readable message fed into the algorithm is:

a)

ciphertext

b)

exchange

c)

plaintext

d)

encryption

53.

Two RSA computation issues: encryption/decryption and:

a)

time complexity

b)

trap-door functions

c)

key generation

d)

padding

54.

__________ depend on the running time of decryption.

a)

Mathematical attacks

b)

Timing attacks

c)

Chosen ciphertext attacks

d)

Brute-force attacks

55.

The __________ of an algorithm measures efficiency.

a)

time complexity

b)

one-way function

c)

timing attack

d)

OAEP

56.

Authentication applied to all except IP header is:

a)

tunnel mode

b)

transport mode

c)

association mode

d)

security mode

57.

Encapsulating header and trailer (RFC 4303) is:

a)

SPI

b)

ESP

58.

Payload that identifies packet flows:

a)

Configuration

b)

Vendor ID

c)

Traffic Selector

d)

Extensible Authentication Protocol

59.

Primary IPsec integrity method:

a)

MD5

b)

AES

c)

RSA

d)

DH

60.

Source & destination of encrypted IPsec packet:

a)

Original sender & receiver

b)

Sender & outbound VPN gateway

c)

Sending and receiving VPN gateways

d)

VPN gateway & original destination

61.

Private management traffic uses:

a)

IPsec

b)

IKE Phase 1

c)

IKE Phase 2

d)

IKE Phase 3

62.

Negotiated during IKE Phase 1:

a)

Hashing

b)

DH group

c)

Encryption

d)

Authentication method

63.

Establish shared secret over untrusted network:

a)

AES

b)

SHA

c)

RSA

d)

DH

64.

Two peer authentication methods in IKE Phase 1:

a)

RSA signatures

b)

PSK

c)

DH Group 2

d)

TCP handshake

65.

Encrypted management protocols (Choose three):

a)

SNMPv2c

b)

Telnet

c)

SNMPv3

d)

HTTPS

e)

SSH

66.

Valid Layer 2 security for 802.11ac:

(a)  

67.

Guest WLAN splash page authentication:

a)

LDAP

b)

RADIUS

c)

local

d)

WebAuth

e)

PSK

68.

Single sign-on wireless authentication (Choose two):

a)

LDAP

b)

RADIUS

c)

Local

d)

WEP

e)

PSK

69.

128-bit encryption with 802.11n speeds:

a)

Static WEP

b)

WPA-TKIP

c)

WPA2-AES

d)

CKIP

70.

Trusted DHCP ports feature:

a)

DHCP snooping

b)

port security

71.

True about named ACLs:

a)

Support standard and extended ACLs

b)

Filter usernames/passwords

c)

Filter Layer 7

d)

Standard only

e)

Rate limit traffic

72.

Valid extended ACL number:

a)

99

b)

1

c)

64

d)

299

e)

100

73.

ACL problem cause:

a)

Permit entry inactive

b)

Misconfigured ACL

c)

Deny all active

d)

Implicit deny

74.

Verify which interfaces are affected by ACL:

a)

show ip access-lists

b)

show access-lists

c)

show interface

75.

Which command displays the IP interface information?

a)

D. show ip interface

b)

E. list ip interface

76.

Permit only four networks (Choose two):

a)

access-list 10 permit ip 192.168.146.0 0.0.1.255

b)

access-list 10 permit ip 192.168.148.0 0.0.1.255

c)

access-list 10 permit ip 192.168.146.0 0.0.0.255

d)

access-list 10 permit ip 192.168.147.0 0.0.255.255

e)

access-list 10 permit ip 192.168.149.0 0.0.255.255

77.

Router ACL is used for:

a)

filtering packets through a router

b)

change admin distance

c)

protect server

d)

control route metric

78.

IPsec protocol when confidentiality is required:

a)

MD5

b)

PSK

c)

AH

d)

ESP

79.

Port security true statements:

a)

Can apply to dynamic access ports

b)

Apply to EtherChannels

c)

Switch learns up to defined maximum MACs

80.

Standard ACLs are based on:

a)

destination + wildcard

b)

destination + subnet

c)

source + subnet

d)

source + wildcard

81.

VPN component ensuring data unaltered:

a)

encryption

b)

authentication

c)

key exchange

d)

data integrity

82.

service password-encryption provides security by:

a)

encrypting traffic

b)

encrypting passwords in config file

c)

requiring encrypted input

d)

MD5 routing validation

e)

auto-generate passwords

83.

Packets processed by inbound ACL:

a)

before they are routed

b)

after routing

c)

before and after

d)

after routing but before queue

84.

Wildcard mask for /29:

a)

0.0.0.224

b)

0.0.0.7

c)

255.255.255.224

d)

255.255.255.248

e)

0.0.0.8

85.

Valid reasons for VLANs (Choose three):

a)

F. increase security

b)

B. isolate broadcast traffic

c)

C. increase collision

d)

E. logically group hosts

e)

A. VTP easier

86.

Secure terminal protocol:

a)

WEP

b)

SSH

c)

ARP

d)

SNMPv1

e)

Telnet

87.

Extended ACL filters:

a)

protocol

b)

VLAN number

c)

TCP/UDP ports

d)

switch port

88.

Permit SSH/Telnet on vty:

a)

transport output all

b)

transport preferred all

c)

transport type all

d)

transport input all

89.

Protect the data plane (Choose three):

a)

QoS

b)

IPS

c)

antispoofing

d)

ACLs

e)

policing

90.

True about stateless firewall:

a)

Operates at Layer 4

b)

More secure than stateful

c)

Tracks streams

d)

Not vulnerable to spoofing

91.

True of all firewalls:

a)

Maintain state table

b)

Hide source

c)

Operate at Layer 7

d)

Are multihomed devices

92.

Validate address requests:

a)

IP Source Guard

b)

port security

c)

DHCP snooping

d)

dynamic ARP inspection

93.

Result of port-security mac-address sticky:

a)

Saved in startup-config

b)

Saved in running-config

c)

Saved in VLAN DB

d)

Static saved in startup

e)

Static saved in running

94.

Port security true (Choose two):

a)

Apply to dynamic access ports

b)

Apply to EtherChannels

c)

Learn MACs up to maximum

d)

Sticky saved to startup-config

e)

Configure in voice VLAN

95.

Reasons for VPN instead of WAN:

a)

broadband incompatibility

b)

better throughput

c)

scalability

d)

increased security

e)

reduced cost

96.

Traffic replication feature:

a)

copy run start

b)

traceroute

c)

ICMP SLA

d)

SPAN

97.

ACL wildcard substitutes:

a)

all

b)

any

c)

host

d)

range

e)

subnet

98.

IEEE authentication mechanism:

a)

802.1x

b)

802.11

c)

802.2x

d)

802.3x

99.

DHCP snooping info stored in:

a)

MAC table

b)

CAM table

c)

DHCP binding database

d)

VLAN database

100.

Command to save learned MACs:

a)

switch port-security

b)

switch port-security mac-address sticky

c)

switch port-security maximum 10

d)

switch mode access