NEW
Font size
WorksheetsPKI + CF Quiz
Total questions: 40
Worksheet time: 20mins
Information Security primarily ensures protection of information in terms of:
Cost and performance
Confidentiality, Integrity, Availability
Storage efficiency
Network throughput
A security threat is best described as:
A weakness in a system
A potential cause of unwanted incident
A countermeasure
A security control
File encryption mainly protects data against:
Hardware failure
Unauthorized access
Data redundancy
Network latency
Which cryptographic algorithm is symmetric in nature?
RSA
ECC
AES
Diffie-Hellman
Diffie-Hellman is primarily used for:
Digital signatures
Secure key exchange
Hash generation
Certificate revocation
(Scenario) An organization wants fast encryption for large volumes of data stored on disk. Which approach is most appropriate?
RSA encryption
ECC encryption
Symmetric key encryption
Digital signatures
Which attack targets weaknesses in encryption implementation rather than the algorithm itself?
Brute force attack
Cryptographic issue
Replay attack
Phishing attack
(Scenario) Two parties want to communicate securely without previously sharing a secret key. Which mechanism should they use first?
AES encryption
Hashing
Diffie-Hellman key exchange
HMAC
SHA is classified as a:
Symmetric cipher
Asymmetric cipher
Hashing algorithm
Key exchange protocol
(Scenario) A system requires message integrity and authentication but no confidentiality. Which mechanism best fits?
AES
RSA
HMAC
File encryption
A digital signature primarily provides:
Confidentiality only
Integrity and non-repudiation
Availability
Anonymity
(Scenario) A user verifies a website’s certificate chain during SSL handshake. What entity ultimately establishes trust?
Web server
Registration Authority
Trusted Certificate Authority
DNS server
Certificate Revocation Lists (CRL) are used to:
Issue certificates
Validate hashing algorithms
List revoked certificates
Generate public keys
(Scenario) A real-time certificate validity check is required with minimal latency. Which mechanism should be used?
CRL
OCSP
PKCS
FIPS
PKCS standards mainly define:
Network protocols
Cryptographic algorithm strengths
Cryptographic message and key formats
Legal compliance rules
FIPS 140-2 specifies requirements for:
Network firewalls
Cryptographic modules
Digital evidence handling
Web authentication
Multi-factor authentication improves security by:
Using longer passwords
Combining multiple authentication factors
Encrypting credentials
Reducing login attempts
Zero Trust Architecture assumes that:
Internal networks are trusted
Perimeter security is sufficient
No implicit trust is granted
VPN access is mandatory
SSL/TLS is primarily used to secure:
File systems
Network routing
Web communications
Disk encryption
Time stamping services mainly provide proof of:
Identity
Data ownership
Existence of data at a specific time
Confidentiality
Computer forensics primarily deals with:
Network optimization
Legal collection and analysis of digital evidence
Malware development
Data encryption
The process of computer forensics consists of how many major steps?
Four
Five
Six
Eight
Preservation in forensics ensures that evidence is:
Quickly analyzed
Modified carefully
Protected from alteration
Compressed
Chain of custody refers to:
Encryption of evidence
Documentation of evidence handling
Network trace logs
Backup procedures
Forensic duplication is required to:
Speed up investigation
Work on original evidence
Maintain evidence integrity
Encrypt disk images
(Scenario) A responder starts analyzing a suspect hard drive without imaging it first. What principle is violated?
Documentation
Preservation
Detection
Interpretation
Hexadecimal notation is commonly used because it:
Is faster to compute
Maps easily to binary values
Encrypts data
Reduces file size
(Scenario) An investigator uses a hex editor to modify evidence data accidentally. What is the immediate impact?
Faster analysis
Evidence integrity compromised
Improved readability
Legal admissibility increased
Hashing in forensics is mainly used to:
Encrypt files
Verify data integrity
Compress evidence
Recover deleted files
(Scenario) Two disk images produce the same MD5 hash. What does this indicate?
Guaranteed identical files
Hash collision possibility
Disk corruption
Encryption failure
Bit rot refers to:
Intentional data deletion
Gradual data degradation
Malware infection
Hashing error
(Scenario) Evidence is collected from a live running system. What type of artefacts are primarily targeted?
Archived logs only
Volatile memory artefacts
Backup images
Offline disk sectors
Standard Operating Procedures in forensics ensure:
Faster investigation
Consistency and repeatability
Advanced encryption
Tool automation
(Scenario) An investigator fails to maintain an evidence checkout log. What is the major risk?
Increased storage usage
Broken chain of custody
Data encryption loss
Longer investigation time
Accreditation standards in forensics mainly address:
Network protocols
Investigator credibility and process quality
Hash algorithms
Storage capacity
Mobile forensics primarily deals with analysis of:
Network routers
Mobile devices and their data
Cloud servers
Email headers
Sysinternals Suite is mainly used for:
Disk imaging
Windows system analysis
Network sniffing
Password cracking
FTK Imager is primarily used to:
Analyze logs
Capture forensic images
Decrypt files
Monitor network traffic
OSF in forensics stands for:
Open Security Framework
Open Source Forensics
Online Storage Facility
Operational Security Function
Hex editors are mainly used to:
Encrypt evidence
View and analyze raw data
Generate hash values
Recover passwords
