csc438 finale

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/239

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 3:17 PM on 6/16/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

240 Terms

1
New cards

Which of the following is FALSE about rootkits?

a. A rootkit is malware that can hide the presence of other malware.

b. Rootkits continue to be used extensively and their usage has not diminished.

c. Rootkits can be used to hide its own presence.

d. Rootkits cannot be detected by either an OS or common antimalware scanning software.

Rootkits continue to be used extensively and their usage has not diminished.

2
New cards

What is the goal of a buffer overflow attack?

a. To change the address in the buffer to the attacker's malware code

b. To cause the computer to function erratically

c. To steal data stored in RAM

d. To link to an existing rootkit

To change the address in the buffer to the attacker's malware code

3
New cards

Which area of computer memory is dynamic memory for the programmer to allocate as necessary?

a. Text

b. Stack

c. Heap

d. Data

Heap

4
New cards

Jan is explaining to his colleague the reasons why a web application infrastructure is a tempting target for attackers. Which of the following is NOT a reason Jan would give?

a. A successful compromise could impact all web users who access the web server.

b. An attack could provide a pathway into the enterprise's network infrastructure.

c. An attack on a web application infrastructure is considered the easiest attack to create.

d. The multiple elements in a web application infrastructure provide for a range of vulnerabilities that can be used as different attack vectors.

An attack on a web application infrastructure is considered the easiest attack to create.

5
New cards

Which of the following is FALSE about a cross-site scripting (XSS) attack?

a. The underlying web application that accepts the malicious code becomes the vehicle to deliver the malicious script to every user's browser when he or she accesses that site.

b. An attacker attempts to execute malicious scripts in the victim's web browser by directly injecting it into the user's web browser.

c. XSS is essentially a client-side code injection attack using a web application.

d. The term cross-site scripting refers to an attack using scripting that originates on one site (the web server) to impact another site (the user's computer).

An attacker attempts to execute malicious scripts in the victim's web browser by directly injecting it into the user's web browser.

6
New cards

Ricardo is reviewing the different types of XSS attacks. Which attack only impacts the user who entered the text on the website?

a. Reflected XSS

b. Persistent XSS

c. Document Object Model XSS

d. Universal XSS

Reflected XSS

7
New cards

What is the goal of a SQL injection attack?

a. To corrupt data in the database

b. To manipulate a NoSQL database

c. To extract data from a database

d. To inject malware that will infect the web browsers of subsequent users

To extract data from a database

8
New cards

Bette is researching how a session hijacking attack could occur. Which of the following would she NOT find as a means for the attack to occur?

a. MITM

b. XSS

c. Guessing the session ID

d. MVFL

MVFL

9
New cards

Which of the following is FALSE about a password spraying attack?

a. It takes one or a small number of commonly used passwords in attempts to break into an account.

b. Because it is spread across many different accounts, it is much less likely to raise any alarms.

c. It is considered as the optimal means for breaking into accounts.

d. It is a type of targeted guessing.

It is considered as the optimal means for breaking into accounts.

10
New cards

Why is credential stuffing effective?

a. Because users repeat their passwords on multiple accounts

b. Because it can circumvent all known password security protections

c. Because it is the fastest known password cracking attack

d. Because it is the oldest and most reliable attack on passwords

Because users repeat their passwords on multiple accounts

11
New cards

What is the goal of a directory traversal attack?

a. It has no goal other than to silently look through files stored on a file server.

b. Its goal is to move from the root directory to other restricted directories.

c. Its goal is to identify a vulnerability in a server or endpoint so that access can be gained into a network.

d. Its goal is to pivot to another server.

Its goal is to move from the root directory to other restricted directories.

12
New cards

What is pretexting?

a. Sending text messages to selected victims

b. Obtaining private information

c. Preparing to enter a network through a RCE vulnerability

d. Moving laterally before entering a vulnerable endpoint

Obtaining private information

13
New cards

Which type of OS is found on an embedded system?

a. RSTS

b. SoC

c. RTOS

d. XRXS

RTOS

14
New cards

Aiko has been asked by her friend if she should download and install an app that allows her to circumvent the built-in limitations on her Android smartphone. What is this called?

a. Jailbreaking

b. Side-caring

c. Rooting

d. Pivoting

Rooting

15
New cards

Aiya wants a new notebook computer. She has asked a technician about a model that has USB OTG. Which of the following would the technician NOT tell Aiya about USB OTG?

a. A device connected via USB OTG can function as a peripheral for external media access.

b. A device connected via USB OTG can function as a host.

c. Connecting a mobile device to an infected computer using USB OTG could allow malware to be sent to that device.

d. USB OTG is only available for connecting Android devices to a subnotebook.

USB OTG is only available for connecting Android devices to a subnotebook.

16
New cards

The organization for which Cho works has just purchased a manufacturing plant that has many machines using Modbus. Cho has been asked to research Modbus. Which of the following will Cho NOT find regarding Modbus?

a. Many SCADA systems use Modbus.

b. The original version of Modbus used serial ports.

c. A later variation to Modbus incorporated the TCP/IP protocol.

d. Modbus is robust security.

Modbus is robust security.

17
New cards

What is the network used in vehicles for communications?

a. CAN

b. ECU

c. EDU

d. M-BUS

CAN

18
New cards

Which of the following is NOT a security constraint for embedded systems and specialized devices?

a. Power

b. Compute

c. Cost

d. Patches

Patches

19
New cards

Which of the following is the greatest asset but also a security vulnerability of a mobile device?

a. Low cost

b. Portability

c. Cameras

d. Small screen

Portability

20
New cards

What is geo-tagging?

a. Restricting where an app functions based on its location.

b. Adding geographical identification data to media.

c. Tracking a victim who is wearing a GPS-enabled wearable device.

d. Using the GPS feature of a smartphone.

Adding geographical identification data to media.

21
New cards

Abby has received a request for a data set of actual data for testing a new app that is being developed. She does not want the sensitive elements of the data to be exposed. What technology should she use?

a. Masking

b. Tokening

c. Data Object Obfuscation (DOO)

d. PII Hiding

Masking

22
New cards

Braden has been asked to serve as the individual to whom day-to-day actions have been assigned by the owner. What role is Braden taking?

a. Data custodian/steward

b. Data privacy officer

c. Data controller

d. Data processor

Data custodian/steward

23
New cards

Cora is researching access control schemes. Which scheme will Cora find is the least restrictive?

a. Role-Based Access Control

b. MAC

c. Rule-Based Access Control

d. DAC

DAC

24
New cards

Mia is teaching a new intern about permissions. The intern asks about is a set of permissions attached to an object. Which of these will Mia tell her are permissions attached to an object?

a. ACL

b. SRE

c. Object modifier

d. Entity attribute (EnATT)

ACL

25
New cards

Gabe needs a mechanism that will provide both filesystem security and network security. Which of these will he choose?

a. DBAs

b. DAPs

c. HAPs

d. ACLs

ACLs

26
New cards

Will is searching for information on geographic access requirements. What is another name for this technology that Will can search for?

a. Geolocating

b. Geofencing

c. Geotagging

d. Geoidentifying

Geofencing

27
New cards

Rowan is explaining to a colleague that encryption can provide a range of security protections. Which of these would Rowan NOT include in the list of protections?

a. Nonrepudiation

b. Accounting

c. Integrity

d. Confidentiality

Accounting

28
New cards

hich of the following is used to protect IP?

a. BLB

b. ARC

c. XLS

d. DRM

DRM

29
New cards

Which of the following is NOT correct about watermarking?

a. It can be erased if the content is altered.

b. It is invisible.

c. It allows for unauthorized duplications to be traced back to the source.

d. It is used with DRM.

It can be erased if the content is altered

30
New cards

Which of the following allows deidentified material to be retrieved as needed?

a. Data masking

b. Element obfuscation

c. Tokenization

d. Reordering

Tokenization

31
New cards

Which of the following is NOT true about data sovereignty?

a. Data sovereignty is a concept that until recently was less of an issue.

b. Generally, data is subject to the laws of the country in which it is collected or processed.

c. Governments cannot force companies to store data within specific countries.

d. Data sovereignty is the country-specific requirements that apply to data.

Governments cannot force companies to store data within specific countries

32
New cards

Which of the following is NOT covered by DRM?

a. Ebooks

b. PHI

c. Music

d. Computer games

PHI

33
New cards

Which of the following techniques turns paper into dust so that any data contained on the paper is destroyed?

a. Hammering

b. Stoning

c. Pulverizing

d. Pulping

Pulverizing

34
New cards

Which of the following permanently destroys an entire hard drive by eliminating the magnetic field?

a. Wiping

b. Magnetic stripping

c. Degaussing

d. HDD purging

Degaussing

35
New cards

Which of the following is NOT a nontechnical control?

a. Identifying data

b. Data masking

c. Data sovereignty

d. Nondisclosure agreements

Data masking

36
New cards

Which of the following data types results in the highest risk of fines if the data is exposed?

a. Sensitive

b. High risk

c. Medium value

d. Private

High risk

37
New cards

Which of the following involves determining how long data must be kept?

a. Data retention

b. Data storage

c. Data collection

d. Data analysis

Data retention

38
New cards

Which of the following is NOT a basic principle when considering the retention of data?

a. Always retain data for six months after it is no longer used.

b. Organizations must be able to justify their decisions.

c. Periodic reviews of the data being held are necessary.

d. A policy must be in place.

Always retain data for six months after it is no longer used

39
New cards

Which of the following is a principle that data collected for one specified purpose should not be used for a new purpose?

a. Data amalgamation

b. Reuse restriction

c. Data specificity

d. Purpose limitation

Purpose limitation

40
New cards

Which of the following is NOT a user concern regarding the risks associated with the usage of their private data?

a. The inability to retrieve stolen data

b. Individual inconveniences

c. Associations with groups

d. Statistical inferences

The inability to retrieve stolen data

41
New cards

Which of the following threats would be classified as the actions of a hactivist?

a. Compliance threat

b. Internal threat

c. Environmental threat

d. External threat

External threat

42
New cards

Which of these is NOT a formal and documented response to risk?

a. Mitigation

b. Transference

c. Resistance

d. Avoidance

Resistance

43
New cards

Which of the following is NOT a threat classification category?

a. Compliance

b. Financial

c. Tactical

d. Strategic

Tactical

44
New cards

In which of the following threat classifications would a power blackout be classified?

a. Operational

b. Managerial

c. Technical

d. Strategic

Operational

45
New cards

Which of the following is a systematic evaluation of the effectiveness of the controls as compared to a state of established criteria?

a. Comparison

b. Evaluation

c. Assessment

d. Audit

Audit

46
New cards

Which of the following frameworks focuses on the management and measurement of risk?

a. Prescriptive frameworks

b. Descriptive frameworks

c. Risk-based frameworks

d. Assessment frameworks

Risk-based frameworks

47
New cards

What does a work product retention policy address?

a. How long a document of work must be retained before it can be destroyed

b. What the approved methods are for storing a document

c. Who owns material produced by an employee

d. Where a document can be stored

Who owns material produced by an employee

48
New cards

Which of the following is NOT covered by an AUP?

a. Vendors

b. Competitors

c. Visitors

d. Contractors

Competitors

49
New cards

Which of the following is a step-by-step implementation of a policy?

a. Standard

b. Procedure

c. Guideline

d. Rule

Procedure

50
New cards

Which of the following approaches to risk calculation typically assigns a numeric value (1-10) or label (High, Medium, or Low) to represent a risk?

a. Quantitative risk calculation

b. Qualitative risk calculation

c. Rule-based risk calculation

d. Policy-based risk calculation

Qualitative risk calculation

51
New cards

Which of the following is a list of potential threats and associated risks?

a. Risk assessment

b. Risk matrix

c. Risk register

d. Risk portfolio

Risk register

52
New cards

Giovanni is completing a report on risks. Which risk option would he use to classify the action that the organization has decided not to construct a new a data center because it would be located in an earthquake zone?

a. Transference

b. Avoidance

c. Rejection

d. Prevention

Avoidance

53
New cards

Which of the following control categories includes conducting workshops to help users resist phishing attacks?

a. Managerial

b. Operational

c. Technical

d. Administrative

Operational

54
New cards

Emiliano needs to determine the expected monetary loss every time a risk occurs. Which formula will he use?

a. AV

b. SLE

c. ARO

d. ALE

SLE

55
New cards

Simona needs to research a control that attempts to discourage security violations before they occur. Which control will she research?

a. Deterrent control

b. Preventative control

c. Detective control

d. Corrective control

Deterrent control

56
New cards

Which of the following is NOT correct about supply chain infections?

a. They can be mitigated by VDD.

b. Supply chain assessment can reduce the risk.

c. They only involve software.

d. A supply chain is often global and more difficult to monitor.

They only involve software

57
New cards

What identifies business processes and functions and then quantifies the impact a loss of these functions may have on business operations?

a. BIA

b. VDR

c. RBP

d. AUP

BIA

58
New cards

Which of the following is NOT a category of risk?

a. Internal and external

b. Legacy systems

c. Public

d. Multiparty

Public

59
New cards

Which threat classification affects the long-term goals of the organization?

a. Managerial

b. Financial

c. Compliance

d. Strategic

Strategic

60
New cards

Which of the following is NOT used in a cyber systems assessment?

a. SOAR analysis

b. Analytical testing

c. Vulnerability assessment

d. Penetration testing

SOAR analysis

61
New cards

Which of the following is NOT a reason why computer forensics is important?

a. Amount of digital evidence

b. Increased scrutiny by the legal profession

c. Higher level of computer skill by criminals

d. Federal laws that mandate all attacks be examined using forensics

Federal laws that mandate all attacks be examined using forensics.

62
New cards

What is the name of a device that prevents writing to a hard drive?

a. Drive blocker

b. Write blocker

c. Sector restrictor

d. Device blocker

Write blocker

63
New cards

What type of cameras should NOT be used in a forensics investigation?

a. Digital still camera

b. Video camera

c. Still camera

d. HD camera

Digital still camera

64
New cards

Alvaro has been asked to acquire tape to secure evidence bags that cannot be removed and reapplied without leaving visual evidence. What type of tape should he use?

a. Tamper-evident

b. Tamper-resistant

c. Tamper-impervious

d. Tamper-controlled

Tamper-evident

65
New cards

Which of the following is NOT a name for a unique digital fingerprint of a set of data?

a. Hash

b. Digest

c. Message digest

d. Certificate

Certificate

66
New cards

Which imaging utility can generate a physical image copy?

a. dd

b. dr

c. dt

d. de

dd

67
New cards

Which of the following is NOT a reason for bandwidth monitoring?

a. To identify cyber incident

b. To troubleshoot network performance

c. To monitor bandwidth agreements

d. To find application buffer overflows

To find application buffer overflows

68
New cards

Which of the following is NOT a reason for a traffic spike?

a. Mail server problems

b. Software updates

c. Remote external backups

d. Processor consumption

Processor consumption

69
New cards

Which of the following is NOT a helpful question in determining the cause of a traffic spike?

a. Do the spikes appear at the same time on the same day?

b. Do other monitoring points on the network match these patterns?

c. Do the spikes occur during business hours or at other times?

d. Is the traffic using all common protocols?

Is the traffic using all common protocols?

70
New cards

Which of the following is false about traffic spikes?

a. Using traffic spikes as a symptom of a cyber incident is considered to be easy and straightforward.

b. A malware's spike can become camouflaged among normal spikes.

c. Malware can be programmed to perform an event that causes a traffic spike on a regular interval.

d. Normal traffic spikes are not uncommon.

Using traffic spikes as a symptom of a cyber incident is considered to be easy and straightforward.

71
New cards

Aika wants to monitor bandwidth consumption to determine if there has been a cyber incident. What will be her first step?

a. Identify an open port on the router.

b. Install a packet tracker on the network.

c. Receive permission from her Internet Service Provider (ISP).

d. Establish a baseline of normal bandwidth utilization.

Establish a baseline of normal bandwidth utilization.

72
New cards

Which of the following is false about beaconing?

a. Beaconing occurs when infected devices attempt to contact the threat actor's external C&C server.

b. Beaconing is a three-way communication process.

c. Beaconing is used to receive updated or new instructions from a C&C server.

d. Data exfiltration is accomplished through beaconing.

Beaconing is a three-way communication process.

73
New cards

Which of the following is NOT a type of attack that can be generated through a botnet?

a. Spamming

b. Spreading malware

c. Buffer overflows

d. Manipulating online polls

Buffer overflows

74
New cards

Etsu is reviewing log files and discovers that data has been stolen and sent out from the network. In her report, what does she call this?

a. Exfiltration

b. Infiltration

c. Gathering

d. Sweeping

Exfiltration

75
New cards

Why would a threat actor NOT use BitTorrent for data exfiltration?

a. BitTorrent has never been used for data exfiltration and thus is untested.

b. BitTorrent is not popular and would be difficult for the threat actors to find clients.

c. BitTorrent is considered too slow for file transfers.

d. The BitTorrent protocol can be easily identified.

The BitTorrent protocol can be easily identified.

76
New cards

Which of the following is NOT true about a P2P C&C?

a. It can mask irregular peer-to-peer communications but not data exfiltration through beaconing.

b. A single compromised computer acts as an internal C&C device.

c. It uses an internal mesh network.

d. A P2P C&C uses common protocols.

It can mask irregular peer-to-peer communications but not data exfiltration through beaconing.

77
New cards

If an attacker wants to learn which services are running on a server, which of the following would he use?

a. Port scan

b. Sweep scan

c. Ping sweep

d. IP sweep

Port scan

78
New cards

Which of the following about new account creation is false?

a. Malware can often attempt to compromise a user application database by creating a new account.

b. New account creation can only be used for a threat actor to log in to the application.

c. New account creation should be immediately investigated.

d. Some applications allow logging in to an application to only be performed by the same Windows user who created the database.

New account creation can only be used for a threat actor to log in to the application.

79
New cards

Which of the following is NOT correct about tcpdump?

a. Various forks are available for Windows computers.

b. It operates on UNIX and Linux OS.

c. It only displays TCP/IP packets being transmitted.

d. It is a command-line packet analyzer.

It only displays TCP/IP packets being transmitted.

80
New cards

Which of the following is the best way to perform forensics on a VM?

a. Suspend the VM and resume it later under forensic analysis so that the forensics investigator can use normal procedures to analyze the VM.

b. Take a snapshot of the state of the hard disk so that it is preserved and any changes to the disk are stored in a separate file.

c. Load the VM into a virtual container box (VCB) and use regular forensic tools.

d. It is not recommended that forensics be performed on a VM due to its volatile nature.

Take a snapshot of the state of the hard disk so that it is preserved and any changes to the disk are stored in a seperate file.

81
New cards

What is the act of violating an explicit or implied security policy that may or may not be successful?

a. Cyber breach

b. Cyber incident

c. Security event

d. Adverse security event

Cyber incident

82
New cards

Adamo has been asked to create a new cyber incident response plan. What will be the final phase in the plan?

a. Reporting

b. Eradication

c. Recovery

d. Post-Incident

Post-Incident

83
New cards

Rico is developing a list of personnel who may be asked to serve on a cyber incident response team. Who will have the responsibility of helping the team to focus on minimizing damage and recovering quickly from a cyber incident?

a. Associate director

b. Coordinator

c. Lead investigator

d. Team leader

Team leader

84
New cards

Viola is examining data that was compromised during a recent attack. Into which category would a password number be classified?

a. PII

b. PHI

c. SPI

d. PUI

PII

85
New cards

Which of the following is NOT an example of intellectual property?

a. Trademark

b. Brand image

c. Copyright

d. Patent

Brand image

86
New cards

Why is financial information data considered to have a high value?

a. The loss of accounting data prevents an organization from providing stakeholders an accurate picture of its financial health.

b. Federal laws prohibit backing up corporate accounting data, so the loss cannot be replaced.

c. Corporate accounting data has a high value only if it is part of a merger and acquisition.

d. Accounting data is very detailed and would require a significant effort to restore it.

The loss of accounting data prevents an organization from providing stakeholders an accurate picture of its financial health.

87
New cards

What is the first step in determining the detection and analysis phase of incident response?

a. Deciding how many systems were impacted

b. Determining who launched the attack

c. Deciding if what occurred was a cybersecurity incident

d. Examining the type of data that was compromised

Deciding if what occurred was a cybersecurity incident.

88
New cards

Which of the following scopes of impact describes the length of time needed for IT systems to return to their normal functions?

a. Downtime

b. Recovery time

c. Response time

d. Recapture time

Recovery time

89
New cards

Kristin is reviewing the impact of a recent attack and found that it only caused a seldom-used test server to be taken offline for short period of time. She has decided that this incident does not deserve a high priority ranking. What scope of impact has she used in making this determination?

a. Network importance measure (NIM)

b. System evaluation

c. System process criticality

d. Structural impact

System process criticality

90
New cards

What is the best way for an organization to limit adverse public reactions to a cyber incident?

a. By keeping the news of a cyber incident secret

b. By controlling the conversation

c. By communicating only with stakeholders

d. By responding defensively

By controlling the conversation

91
New cards

Which of the following is NOT a reason for communications in a cyber incident?

a. To limit adverse reactions

b. To allow for unplanned release of information

c. To satisfy state legislative mandates

d. To meet federal regulatory requirements

To allow for unplanned release of information

92
New cards

Which of the following is false regarding state legislative mandates about communication in a cyber incident?

a. Only California has a state security breach notification law.

b. No two state laws are identical.

c. Some states have a broader definition of personal information.

d. Providing notice to the State Attorney General is required in some states.

Only California has a state security breach notification law.

93
New cards

Pat is researching requirements for communicating with affected parties in a cyber incident. What requirement would Pat find that is in place in the European Union (EU)?

a. PIPEDA

b. GDPR

c. PI

d. ICO

GDPR

94
New cards

Isabella has been asked to research HIPAA requirements for her employer. Which of the following is false regarding HIPAA?

a. Healthcare enterprises must guard protected healthcare information.

b. HIPAA only applies to information in electronic format.

c. HIPAA includes any third-party business associate that handles protected healthcare information.

d. Healthcare enterprises must implement policies and procedures to safeguard information.

HIPAA only applies to information in electronic format.

95
New cards

For internal communications, which two categories are often used?

a. Senior-level and junior-level

b. Technical and management

c. Security and networking

d. Communication and cyber

Technical and management

96
New cards

Kaitlyn is creating an incident response plan. Who should first be notified in the event of a cyber incident?

a. Cyber incident response team

b. CEO

c. Law enforcement

d. Local media

Cyber incident response team

97
New cards

Which of the following is not a reason for contacting law enforcement agencies in the event of a cyber incident?

a. They can work with foreign counterparts to stop organized cybercrime.

b. They have many resources and experience.

c. Identifying threat actors often leads to no arrests or convictions.

d. Companies providing information can assist in intelligence sharing efforts.

Identifying threat actors often leads to no arrests or convictions.

98
New cards

Eva is researching which law enforcement agency to contact in the event of different types of cyber incidents. Which law enforcement agency should be contacted no matter the type of incident?

a. CIA

b. NSA

c. FBI

d. Secret Service

FBI

99
New cards

Which of the following is NOT a communications best practice strategy?

a. Contact local news media before the word leaks out.

b. Use a secure method of communication.

c. Be transparent but be careful.

d. Provide a context.

Contact local news media before the word leaks out.

100
New cards

Anabelle needs to eradicate malware from a hard drive. Which should she NOT do?

a. Delete the files from the hard drive by using the Quick Format option.

b. Overwrite the data using sanitization.

c. Use secure disposal as a last resort.

d. Use the Schneier sanitation method.

Delete the files from the hard drive by using the Quick Format option.