1/9
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
As a security professional Anvi works for an organization authoring documents that define policies and procedures outlining security controls. What type of resource does the organization provide?
a. Regulation
b. Benchmark
c. Standard
d. Framework
Framework
An information security framework is a series of documented processes used to define policies and procedures for implementation and management of security controls in an enterprise environment.
Evin thinks one of the computer systems where he works may have been compromised. He does not currently have a good way of determining if an unauthorized user logged in successfully. Which of the following can Evin implement that will, going forward, help him identify who logs in?
a. Authentication
b. Authorization
c. Availability
d. Accounting
Accounting
Accounting is a component of the security principle that involves controlling access to information. Accounting creates a record that is preserved of who accessed the enterprise network, what resources they accessed, and when they disconnected from the network.
An attacker hacks into a cell phone with the intent of stealing credit card information. The attacker also tries to extend the nefarious activity to contacts in the victim's phone, and their contacts as well. What entity was the attacker targeting?
a. A government agency
b. A competitor
c. An individual
d. An enterprise
An individual
A category of targets focuses on individuals as the victims. Threat actors steal and use stolen data, credit card numbers, online financial account information, or Social Security numbers to profit from their victims.
Which of the following best describes what Della could do to prevent unauthorized parties from viewing sensitive customer information at her retail store?
a. Limit access to certain areas once access is granted.
b. Ensure the data cannot be manipulated or changed.
c. Use software to encrypt data in a secure database.
d. Verify the ID of the party requesting access to the data.
Use software to encrypt data in a secure database.
Confidentiality ensures that only authorized parties can view the information. Providing confidentiality can involve several different security tools such as using software to encrypt credit card numbers stored on the web server or in a database, for example.
Company A wants to be first to market with a product forecasted to be very profitable. A few bad actors in Company A launch an attack against Company B to steal intellectual property that will help them. What type of threat actor would do something like this?
a. Competitors
b. Revengeful
c. Script kiddie
d. Hacker in a hoodie
Competitors
Competitors launch attacks against an opponent's system to steal classified information as well as new product research.
To bypass institutional overhead, a well-intentioned networking instructor purchases a wireless router and connects it to the network. The goal is to allow students to establish connectivity with each other by connecting through the wireless router. In what activity did the instructor participate?
a. Insider threat
b. Ethical hacking
c. Shadow IT
d. APT
Shadow IT
The process of bypassing corporate approval for technology purchases, such as buying a wireless router, is known as shadow IT. In the question, the instructor's motivation was ethical (of sound moral principle) but, nevertheless, it weakened security.
A criminal organization has decided to leave their traditional ways and pursue cyberattacks as their new mode of operation. Why would they do this?
a. Less competition
b. Generate disruption
c. Easier to hide their tracks
d. Political beliefs
Easier to hide their tracks
Evidence indicates that organized crime has moved into cyberattacks, which they consider to be less risky. This makes it easier for them hide their tracks.
A work-study student works at the registrar's office and is given limited access to a student database. The student is very technologically savvy and figures out a way of gaining additional privileges. The student is not pleased with one of their grades and changes it. Which of the following best describes the type of scenario this activity characterizes?
a. Cyberterrorism
b. Shadow IT
c. Revenge
d. Insider threat
Insider threat
A serious threat to an enterprise comes from its own employees, contractors, and business partners, called insiders. They pose an insider threat because the threat is coming from an entity who is in a position of trust, so they will not be suspected.
A malicious actor lacking technical knowledge uses an attack tool to perform a sophisticated attack. If the attacker is successful penetrating the defenses of the targeted organization, what type of activity are they most likely to perform? Select two.
a. Copy data
b. Blackmail
c. Disrupt service
d. Corrupt data
e. Manipulate data
Copy data
Disrupt service
Unskilled attackers employ easy-to-use attack tools to carry out their attacks. They can often be successful in penetrating defenses, particularly if the defenses are weak. Their motivation is usually data exfiltration (unauthorized copying of data) or service disruption (obstructing normal business electronic processes).
A broker launches a variety of attacks to find a weakness that will lead to financial gain. What activity is the broker most likely to engage in?
a. Sell information about a discovered vulnerability
b. Steal classified information against a competitor
c. Obtain, repackage, and sell pirated software
d. Create and sell malicious software to the highest bidder
Sell information about a discovered vulnerability
Brokers sell their knowledge of a weakness to other attackers or governments. They do not report the weaknesses to the software vendor. Instead, they sell them to the highest bidder, who are willing to pay a high price for the unknown weakness.