1/21
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Vittoria is working on her computer information systems degree at a local college and has started researching information security positions. Because she has no prior experience, which of the following positions would Vittoria most likely be offered?
Security Technician
Which of the following is false about the CompTIA Security+ certification?
a. Security+ is one of the most widely acclaimed security certifications.
b. Security+ is internationally recognized as validating a foundation level of security skills and knowledge.
c. The Security+ certification is a vendor-neutral credential.
d. Professionals who hold the Security+ certification earn about the same or slightly less than security professionals who have not achieved this certification.
d. Professionals who hold the Security+ certification earn about the same or slightly less than security professionals who have not achieved this certification.
Ginevra is explaining to her roommate the relationship between security and convenience. Which statement most accurately indicates this relationship?
a. Security and convenience are directly proportional.
b. Security and convenience have no relationship.
c. Any proportions between security and convenience depend on the type of attack.
d. Security and convenience are inversely proportional.
d. Security and convenience are inversely proportional.
Serafina is studying to take the Security+ certification exam. Which of the following of the CIA elements ensures that only authorized parties can view protected information?
a. confidentiality
b. integrity
c. availability
d. credentiality
a. Confidentiality
Which of the following AAA elements is applied immediately after a user has logged into a computer with their username and password?
a. authentication
b. authorization
c. identification
d. recording
b. authorization
Gia has been asked to enhance the security awareness training workshop for new hires. Which category of security control would Gia be using?
a. managerial
b. technical
c. operational
d. physical
c. operational
Which specific type of control is intended to mitigate (lessen) damage caused by an attack?
a. corrective control
b. compensating control
c. preventive control
d. restrictive control
a. Corrective control (A control that is intended to mitigate or lessen the damage caused by the incident is called a corrective control.)
Which control is designed to ensure that a particular outcome is achieved by providing incentives?
a. deterrent control
b. incentive control
c. detective control
d. directive control
d. Directive control (A directive control is designed to ensure that a particular outcome is achieved. One type of directive control is an incentive, which is the "carrot" instead of the "stick." Incentives are often overlooked as a control, but they can be very powerful.)
Which of the following controls is NOT implemented before an attack occurs?
a. detective control
b. deterrent control
c. preventive control
d. directive control
a. detective control (A detective control is used to identify an attack and occurs during an attack.)
Complete this definition of information security: That which protects the integrity, confidentiality, and availability of information _____.
a. on electronic digital devices and limited analog devices that can connect via the Internet or through a local area network
b. through a long-term process that results in ultimate security
c. using both open-sourced as well as supplier-sourced hardware and software that interacts appropriately with limited resources
d. through products, people, and procedures on the devices that store, manipulate, and transmit the information
d. through products, people, and procedures on the devices that store, manipulate, and transmit the information. (Information security may be defined as that which protects the integrity, confidentiality, and availability of information through products, people, and procedures on the devices that store, manipulate, and transmit the information.)
Which of the following groups have the lowest level of technical knowledge for carrying out cyberattacks?
a. unskilled attackers
b. hacktivists
c. nation-state actors
d. organized crime
a. unskilled attackers
Ilaria is explaining to her parents why information security is the preferred term when talking about security in the enterprise. Which of the following would Ilaria NOT say?
a. Cybersecurity usually involves a range of practices, processes, and technologies intended to protect devices, networks, and programs that process and store data in an electronic form.
b. In a business information may be in any format, from electronic files to paper documents.
c. Cybersecurity is a subset of information security.
d. Information security protects "processed data" or information.
c. Cybersecurity is a subset of information security. (Cybersecurity is considered an overall umbrella term under which information security is found.)
Which of the following is not considered an attribute of threat actors?
a. level of sophistication/capability
b. educated/uneducated
c. resources/funding
d. internal/external
d. educated/uneducated (The attributes, or characteristic features, of the different groups of threat actors vary widely. Some groups have a high level of power and complexity (called level of sophistication/capability) and have a massive network of resources, while others are "lone wolves" with minimal skills and no resources. In addition, some groups have deep resources/funding while others have none. And whereas some groups of threat actors may originate from within the enterprise, others are strictly outside (internal/external).)
What is considered the motivation of an employee who practices shadow IT?
a. deception
b. ignorance
c. ethical
d. malicious
c. ethical. (The process of bypassing corporate approval for technology purchases is known as shadow IT. The employee's motivation is often ethical (it has sound moral principles) but nevertheless weakens security.)
Which tool is most commonly associated with nation-state actors?
a. Closed-Source Resistant and Recurrent Malware (CSRRM)
b. Advanced Persistent Threat (APT)
c. Unlimited Harvest and Secure Attack (UHSA)
d. Network Spider and Worm Threat (NSAWT)
b. Advanced Persistent Threat (APT) (Nation-state actors are often involved in multiyear intrusion campaigns targeting highly sensitive economic, proprietary, or national security information. This has created a new class of attacks called Advanced Persistent Threats. These attacks use innovative attack tools (advanced) and once a system is infected it silently extracts data over an extended period of time (persistent). APTs are most commonly associated with nation-state actors.)
Flavia is reading about insider threats. Which of the following is NOT true about insider threats?
a. Attacks from an insider threat are hard to recognize.
b. Insider threats are usually dismissed as not being a serious risk.
c. Insider threats often occur because the enterprise is watching for outsiders.
d. Government insiders have stolen large volumes of sensitive information.
b. Insider threats are usually dismissed as not being a serious risk.
What is the primary motivation of hacktivists?
a. disruption/chaos
b. financial gain
c. data exfiltration
d. war
a. disruption/chaos (Today many hacktivists work through disinformation campaigns by spreading fake news and supporting conspiracy theories, making their motivation disruption/chaos (to produce extreme confusion))
What is another name for "attack surface"?
a. vulnerability exposure
b. threat vector
c. legacy platform
d. attack floor
b. threat vector (An attack surface, also called a threat vector, is a digital platform that threat actors target for their exploits.)
Which of the following is NOT a message-based attack surface?
a. voice calls
b. instant messages
c. texts
d. network protocols
d. Network Protocols (Due to their popularity and widespread usage, coupled with the fact that the other person's true identity can be easily masked, communication tools are popular threat vectors by attackers. The most common communication tools are message-based and include email, texts, instant messages, and voice calls.)
Which of the following is NOT true about supply chains?
a. A supply chain is a network that moves a product from its creation to the end-user.
b. Vendors are the first step in a supply chain.
c. Each link in a supply chain can be a potential attack surface.
d. Hardware providers and software providers are types of supply chains.
b. Vendors are the first step in a supply chain. (A supply chain is typically made up of suppliers (the first step in the chain) that provide the raw materials, manufacturers who convert the material into products, vendors who purchase the products to resell them, warehouses that store products, distribution centers that deliver products to the retailers, and retailers who sell the product ultimately to the consumer.)
There are three types of information protection (often called the CIA Triad) :
CIA --> Confidentiality: Only approved individuals may access information. Integrity: Ensures information is correct and unaltered. Availability: Ensures information is accessible to authorized users
A ___ is an individual or entity responsible for cyber incidents against the technology equipment of enterprises and users
A threat actor is an individual or entity responsible for cyber incidents against the technology equipment of enterprises and users