Cybersecurity Quiz 1 & 2

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/146

flashcard set

Earn XP

Description and Tags

Quiz 1: 1.0 Security concepts: Sec 1.1 – 1.3, Quiz 2: 2.0 Threats, Vulnerabilities, and Mitigations: Sec 2.1 – 2.3 - 3.0 Cryptographic Solutions: Sec 3.1 – 3.5

Last updated 10:13 PM on 8/27/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

147 Terms

1
New cards

Security operations center (SOC)

The location where security professionals monitor and protect critical information assets in an organization.

2
New cards

Development and operations (DevOps)

A combination of software development and systems operations and refers to the practice of integrating one discipline with the other.

3
New cards

DevSecOps

A combination of software development, security operations, and systems operations and refers to the practice of integrating each discipline with the others.

4
New cards

Computer incident response team (CIRT)/computer security incident response team (CSIRT)/computer emergency response team (CERT)

Team with responsibility for incident response. The CSIRT must have expertise across a number of business domains (IT, HR, legal, and marketing, for instance).

5
New cards

computer incident response team (CIRT)

team with responsibility for incident response. The CIRT must have expertise across a number of business domains (IT, HR, legal, and marketing, for instance).

6
New cards

You are the Chief Information Security Officer (CISO) at a large corporation. You have been tasked with implementing a new security control to protect sensitive customer data.

The control must be able to automatically detect and prevent unauthorized access to the data.

Which type of control should you implement?

Technical control

7
New cards

You are the head of the cybersecurity team at a large corporation. You notice an increase in network traffic that appears to be legitimate but is causing a slowdown in your systems.

Upon further inspection, you find that the traffic patterns vary each time, making it difficult to distinguish from normal traffic.

What type of security challenge are you MOST likely facing?

Sophisticated attack

8
New cards

You are the Chief Information Security Officer (CISO) at a large corporation. Your company is expanding rapidly and the complexity of managing security across different business functions is increasing.

You need a dedicated team to monitor and protect critical information assets across the organization.

Which of the following would be the MOST effective solution?

Establishing a Security Operations Center (SOC)

9
New cards

Which of the following security challenges refers to the rapid and broad spread of an attack, often affecting a large number of computers in a relatively short amount of time?

Attack scale and velocity

10
New cards

Which of the following is a method of implementing security controls?

Managerial controls

11
New cards

Your computer system is a participant in an asymmetric cryptography system. You've created a message to send to another user. Before transmission, you hash the message and encrypt the hash using your private key. You then attach this encrypted hash to your message as a digital signature before sending it to the other user.

In this example, which protection does the hashing activity provide?

Integrity

12
New cards

You are the Chief Information Security Officer (CISO) at a tech company. Your company is facing issues with silos between the development and operations teams, leading to inefficiencies and security vulnerabilities.

Which approach should you adopt to encourage collaboration and integrate security considerations at every stage of software development and deployment?

Adopting a Development and Operations (DevOps) approach

13
New cards

A user copies files from her desktop computer to a USB flash device and puts the device into her pocket.

Which of the following security risks is MOST pressing?

Confidentiality

14
New cards

A large multinational corporation has recently experienced a significant data breach. The breach was detected by an external cybersecurity firm, and the corporation's IT department was unable to prevent or detect the breach in its early stages.

The CEO wants to ensure that such a breach does not happen again and is considering several options to enhance the company's security posture.

Which of the following options would be the MOST effective in preventing and detecting future data breaches?

Implementing a dedicated Computer Incident Response Team (CIRT).

15
New cards

Which of the following are often identified as the three main goals of security? (Select three.)

Integrity, Confidentiality, Availability

16
New cards

Security Control

A technology or procedure put in place to mitigate vulnerabilities and risk and to ensure the confidentiality, integrity, and availability (CIA) of information.

17
New cards

Managerial

A category of security control that provides oversight of information systems.

18
New cards

Operational

A category of security control that is implemented by people.

19
New cards

Technical

A category of security control that is implemented as a system.

20
New cards

Physical

A category of security control that is implemented by hardware used to deter or detect, such as alarms, gateways, locks, lighting, and security cameras.

21
New cards

Preventive

A type of security control that acts before an incident to eliminate or reduce the likelihood that an attack can succeed.

22
New cards

Access control lists (ACLs)

The collection of access control entries (ACEs) that determines which subjects (user accounts, host IP addresses, and so on) are allowed or denied access to the object and the privileges given (read-only, read/write, and so on).

23
New cards

Detective

A type of security control that acts during an incident to identify or record that it is happening.

24
New cards

Corrective

A type of security control that acts after an incident to eliminate or minimize its impact.

25
New cards

Directive

A type of control that enforces a rule of behavior through a policy or contract.

26
New cards

Deterrent

A type of security control that discourages intrusion attempts.

27
New cards

Compensating

A security measure that takes on risk mitigation when a primary control fails or cannot completely meet expectations.

28
New cards

Chief Information Officer (CIO)

A company officer with the primary responsibility of managing information technology assets and procedures.

29
New cards

Chief Technology Officer (CTO)

A company officer with the primary role of making effective use of new and emerging computing platforms and innovations.

30
New cards

Chief Security Officer

Typically, the job title of the person with overall responsibility for information assurance and systems security.

31
New cards

Informations Systems Security Officer (ISSO)`

Organizational role with technical responsibilities for implementation of security policies, frameworks, and controls.

32
New cards

A company finds that employees are accessing streaming websites that are not being monitored for malware or viruses.

Which type of control can the network administrator implement to protect the system and keep the employees from viewing unapproved sites?

Technical

33
New cards

Which of the following is an example of a preventative control type?

An advanced network appliance

34
New cards

After a recent server outage, the company discovered that an employee accidentally unplugged the power cable from the server while grabbing some office supplies from the nearby shelf.

What security control did the company lack that led to the server outage?

Physical

35
New cards

An acceptable use policy requires the system to encrypt confidential information while in transit. All employees must use secure email when exchanging proprietary information with external vendors.

Which of the following describes this type of acceptable use policy?

Operational

36
New cards

Which type of control makes use of policies, DRPs, and BCPs?

Managerial

37
New cards

The security operations manager of a multinational corporation focuses on enhancing directive operational controls.

Which of the following should the manager implement?

User awareness and training programs.

38
New cards

Which type of control is used to discourage malicious actors from attempting to breach a network?

Deterrent

39
New cards

The chief security officer (CSO) at a financial organization wants to implement additional detective security controls.

Which of the following would BEST represent this type of control?

Installation of surveillance camera.

40
New cards

A company moved its office supplies to another room and instituted a new security system for entry. The company implemented this after a recent server outage.

What category of security control BEST describes the function of this recent implementation?

Corrective

41
New cards

Which of the following BEST describes compensating controls?

Partial control solution that is implemented when a control cannot fully meet a requirement.

42
New cards
Threat actor
A person or entity responsible for an event that has been identified as a security incident or as a risk.
43
New cards
Internal/external
The degree of access that a threat actor possesses before initiating an attack. An external threat actor has no standing privileges, while an internal actor has been granted some access permissions.
44
New cards
Level of sophistication/capability
A formal classification of the resources and expertise available to a threat actor.
45
New cards
Resources/funding
The ability of threat actors to draw upon funding to acquire personnel, tools, and development of novel attack types.
46
New cards
Service disruption
A type of attack that compromises the availability of an asset or business process.
47
New cards
Data exfiltration
The process by which an attacker copies data from a private network to an external network.
48
New cards
Disinformation
A type of attack that falsifies an information resource that is normally trusted by others.
49
New cards
Blackmail
Demanding payment to prevent the release of information.
50
New cards
Extortion
Demanding payment to prevent or halt some type of attack.
51
New cards
Fraud
Falsifying records, such as an internal fraud that involves tampering with accounts.
52
New cards
Hacker
Often used to refer to someone who breaks into computer systems or spreads viruses. Ethical hackers prefer to think of themselves as experts on and explorers of computer security systems.
53
New cards
Unauthorized hacker
A hacker operating with malicious intent.
54
New cards
Authorized hacker
A hacker engaged in authorized penetration testing or other security consultancy.
55
New cards
Unskilled attacker
An inexperienced attacker that typically uses tools or scripts created by others.
56
New cards
Hacktivist
A threat actor that is motivated by a social issue or political cause.
57
New cards
Advanced persistent threat (APT)
An attacker's ability to obtain, maintain, and diversify access to network systems using exploits and malware.
58
New cards
Nation-state actors
A type of threat actor that is supported by the resources of its host country's military and security services.
59
New cards
Organized crime
A type of threat actor that uses hacking and computer fraud for commercial gain.
60
New cards
Internal threat
A type of threat actor who is assigned privileges on the system that cause an intentional or unintentional incident.
61
New cards
Unintentional or inadvertent insider threat
A threat actor that causes a vulnerability or exposes an attack vector without malicious intent.
62
New cards
Shadow IT
Computer hardware, software, or services used on a private network without authorization from the system owner.
63
New cards
Vulnerable software
Weakness that could be triggered accidentally or exploited intentionally to cause a security breach.
64
New cards
Unsupported systems
Product life cycle phase where mainstream vendor support is no longer available.
65
New cards
Unsecure network
Configuration that exposes a large attack surface, such as through unnecessary open service ports, weak or no authentication, use of default credentials, or lack of secure communications/encryption.
66
New cards
Lure
An attack type that will entice a victim into using or opening a removable device, document, image, or program that conceals malware.
67
New cards
Supply chain
The end-to-end process of supplying, manufacturing, distributing, and finally releasing goods and services to a customer.
68
New cards

The IT department at a large corporation noticed an unfamiliar software application running on its network. Upon investigation, they discovered that a team in the marketing department started using a new cloud-based project management tool to improve their workflow efficiency.

The team did not consult with the IT department before implementing this tool.

In the context of cybersecurity threats, what does this situation BEST exemplify?

Shadow IT

69
New cards

A multinational corporation recently fell victim to a series of cyberattacks, disrupting services and leading to significant financial losses. After an investigation, the corporation found that these attacks were part of a systematic campaign to undermine the corporation's market position.

The highly sophisticated attacks suggest the involvement of a well-resourced entity with specific strategic objectives.

Which of the following motivations BEST describes this scenario?

Political

70
New cards

Which type of threat actor is MOST likely to engage in cyber espionage with strategic or political motivations?

Nation-state

71
New cards

The IT manager in your organization proposes taking steps to deflect a potential threat actor. The proposal includes the following:

  • Create and follow onboarding and off-boarding procedures.

  • Employ the principal of least privilege.

  • Have appropriate physical security controls in place.

Which type of threat actor do these steps guard against?

Insider

72
New cards

A prominent multinational corporation has experienced an unexpected spike in unauthorized network traffic aimed at its web servers. Upon investigation, the corporation discovered that the goal of this traffic was to disrupt its online services rather than gain unauthorized access or steal data.

The attack started shortly after the corporation made a controversial policy decision that sparked a public backlash.

Which type of threat actor is MOST likely responsible?

Hacktivist

73
New cards

In which phase of an attack does the attacker gather information about the target?

Reconnaissance

74
New cards

Reconnaissance

process of gathering information about an organization, including system hardware information, network configuration, and individual user information.

75
New cards

Breach

penetration of system defenses. Breaches are achieved using the information gathered during reconnaissance.

76
New cards

Escalating privileges

one of the primary objectives of an attacker, which can be achieved by configuring additional (escalated) rights to do more than breach the system.

77
New cards

Staging

preparing a computer to perform additional tasks in the attack, such as installing software designed to attack other systems.

78
New cards

Exploit

take advantage of known vulnerabilities in software and systems. Types of exploitation include stealing information, denying services, crashing systems, and modifying information.

79
New cards

As a cybersecurity analyst, you are tasked with reducing the supply chain attack surface in your organization.

Which of the following areas should you focus on to MOST effectively mitigate this risk?

Vendor management

80
New cards

A group of hackers has been monitoring recent orders from a company involving new laptops and Universal Serial Bus (USB) thumb drives. The group infiltrated the shipping company and added malicious USB thumb drives to the order. The target company received the order without any concerns.

What vectors made this attack successful?

Supply chain, Removable media

81
New cards

CloudSecure is facing a cybersecurity challenge where some of its critical software applications are no longer supported by vendors, making them vulnerable to potential exploits. The IT team is exploring various strategies to mitigate the risk posed by these unsupported apps.

What is the MOST effective approach to enhance the security posture?

Isolating the unsupported apps from other systems to reduce the attack surface.

82
New cards
Social engineering
An activity where the goal is to use deception and trickery to convince unsuspecting users to provide sensitive data or to violate security guidelines.
83
New cards
Impersonation
A social engineering attack where an attacker pretends to be someone they are not.
84
New cards
Pretexting
A social engineering tactic where a team communicates, whether directly or indirectly, a lie or half-truth in order to get someone to believe a falsehood.
85
New cards
Phishing
An email-based social engineering attack in which the attacker sends email from a supposedly reputable source, such as a bank, to try to elicit private information from the victim.
86
New cards
Vishing
A human-based attack where the attacker extracts information while speaking over the phone or leveraging IP-based voice messaging services (VoIP).
87
New cards
Smishing
A form of phishing that uses SMS text messages to trick a victim into revealing information.
88
New cards
Pharming
A type of attack that redirects users from a legitimate website to a malicious one.
89
New cards
Typosquatting
An attack in which an attacker registers a domain name with a common misspelling of an existing domain, so that a user who misspells a URL in a browser is taken to the attacker's website.
90
New cards
Business email compromise
An impersonation attack in which the attacker gains control of an employee's account and uses it to convince other employees to perform fraudulent actions.
91
New cards
Watering hole attack
An attack in which an attacker targets specific groups or organizations, discovers which websites they frequent, and injects malicious code into those sites.
92
New cards

An attack that targets senior executives and high-profile victims is referred to as what?

Whaling

93
New cards

Which of the following is a passive computer attack technique in which an attacker anticipates or observes the websites an organization uses often and infects them with malware?

Watering hole

94
New cards

A representative at a company reports receiving numerous unsolicited phone calls seeking banking information for a credit report.

Which social engineering variant is the finance director experiencing?

Vishing

95
New cards

What is the term for a phishing attack conducted through a voice channel, such as a phone call?

Vishing

96
New cards

Employees at CloudCom receive a suspicious email claiming to be from "CloudCom Support," informing employees that their passwords need to be reset urgently due to a security breach. The email includes a link to a login page that looks identical to CloudCom's official site.

What type of social engineering attack does this scenario exemplify?

Typosquatting

97
New cards

The cybersecurity manager of a large organization is investigating a recent security breach that occurred during office hours. Investigatory research shows that the suspect convinced the janitor to let them inside the building because they had forgotten their badge at home.

Once inside, the suspect pulled the fire alarm and accessed the building's network room amongst the chaos. The intruder then attached a monitoring device to a network port before escaping unnoticed.

Which of the following is the social engineering technique the threat actor employed in this scenario?

Pretexting

98
New cards

An employee receives an email from an unknown sender claiming to be from the IT department.

The email states that there is a login issue on the network and that the user needs to run the file to resolve the problem. The executable file prompts the user to input a network password, which the threat actor records.

What social engineering technique is the threat actor using in this scenario?

Phishing

99
New cards

Which of the following is an example of a Vishing social engineering attack?

A call from a threat actor posing as a remote sales representative to obtain the login credentials to a remote access server from the help desk.

100
New cards

You are a cybersecurity analyst at a large corporation. You notice that a particular employee has been receiving emails from an unknown sender who claims to be a new colleague from a different department.

The sender has been engaging in friendly conversation, asking about the employee's role, and subtly inquiring about certain company processes. Recently, the sender asked the employee to open an attachment that supposedly contains a funny meme.

What phase of the social engineering process does this scenario represent and what should be your immediate action?

Exploitation phase - Isolate the employee's system and conduct a thorough security scan.