Time limit: 0
Quiz-summary
0 of 103 questions completed
Questions:
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- 11
- 12
- 13
- 14
- 15
- 16
- 17
- 18
- 19
- 20
- 21
- 22
- 23
- 24
- 25
- 26
- 27
- 28
- 29
- 30
- 31
- 32
- 33
- 34
- 35
- 36
- 37
- 38
- 39
- 40
- 41
- 42
- 43
- 44
- 45
- 46
- 47
- 48
- 49
- 50
- 51
- 52
- 53
- 54
- 55
- 56
- 57
- 58
- 59
- 60
- 61
- 62
- 63
- 64
- 65
- 66
- 67
- 68
- 69
- 70
- 71
- 72
- 73
- 74
- 75
- 76
- 77
- 78
- 79
- 80
- 81
- 82
- 83
- 84
- 85
- 86
- 87
- 88
- 89
- 90
- 91
- 92
- 93
- 94
- 95
- 96
- 97
- 98
- 99
- 100
- 101
- 102
- 103
Information
Cybersecurity Essentials FINAL Quiz Test Online
You have already completed the quiz before. Hence you can not start it again.
Quiz is loading...
You must sign in or sign up to start the quiz.
You have to finish following quiz, to start this quiz:
Results
0 of 103 questions answered correctly
Your time:
Time has elapsed
You have reached 0 of 0 points, (0)
| Average score |
|
| Your score |
|
Categories
- Not categorized 0%
- 1
- 2
- 3
- 4
- 5
- 6
- 7
- 8
- 9
- 10
- 11
- 12
- 13
- 14
- 15
- 16
- 17
- 18
- 19
- 20
- 21
- 22
- 23
- 24
- 25
- 26
- 27
- 28
- 29
- 30
- 31
- 32
- 33
- 34
- 35
- 36
- 37
- 38
- 39
- 40
- 41
- 42
- 43
- 44
- 45
- 46
- 47
- 48
- 49
- 50
- 51
- 52
- 53
- 54
- 55
- 56
- 57
- 58
- 59
- 60
- 61
- 62
- 63
- 64
- 65
- 66
- 67
- 68
- 69
- 70
- 71
- 72
- 73
- 74
- 75
- 76
- 77
- 78
- 79
- 80
- 81
- 82
- 83
- 84
- 85
- 86
- 87
- 88
- 89
- 90
- 91
- 92
- 93
- 94
- 95
- 96
- 97
- 98
- 99
- 100
- 101
- 102
- 103
- Answered
- Review
-
Question 1 of 103
1. Question
1 pointsWhich statement best describes a motivation of hacktivists?Correct
Incorrect
-
Question 2 of 103
2. Question
1 pointsWhich type of cybercriminal is the most likely to create malware to compromise an organization by stealing credit card information?Correct
Incorrect
-
Question 3 of 103
3. Question
1 pointsA specialist in the HR department is invited to promote the cybersecurity program in community schools. Which three topics would the specialist emphasize in the presentation to draw students to this field? (Choose three.)Correct
Incorrect
-
Question 4 of 103
4. Question
1 pointsAn organization allows employees to work from home two days a week. Which technology should be implemented to ensure data confidentiality as data is transmitted?Correct
Incorrect
-
Question 5 of 103
5. Question
1 pointsWhich type of networks poses increasing challenges to cybersecurity specialists due to the growth of BYOD on campus?Correct
Incorrect
-
Question 6 of 103
6. Question
1 pointsA cybersecurity specialist is working with the IT staff to establish an effective information security plan. Which combination of security principles forms the foundation of a security plan?Correct
Incorrect
-
Question 7 of 103
7. Question
1 pointsWhich framework should be recommended for establishing a comprehensive information security management system in an organization?Correct
Incorrect
-
Question 8 of 103
8. Question
1 pointsWhat are three states of data during which data is vulnerable? (Choose three.)Correct
Incorrect
-
Question 9 of 103
9. Question
1 pointsUsers report that the database on the main server cannot be accessed. A database administrator verifies the issue and notices that the database file is now encrypted. The organization receives a threatening email demanding payment for the decryption of the database file. What type of attack has the organization experienced?Correct
Incorrect
-
Question 10 of 103
10. Question
1 pointsWhat three best practices can help defend against social engineering attacks? (Choose three.)Correct
Incorrect
-
Question 11 of 103
11. Question
1 pointsWhich statement describes a distributed denial of service attack?Correct
Incorrect
-
Question 12 of 103
12. Question
1 pointsA cyber criminal sends a series of maliciously formatted packets to the database server. The server cannot parse the packets and the event causes the server crash. What is the type of attack the cyber criminal launches?Correct
Incorrect
-
Question 13 of 103
13. Question
1 pointsAn executive manager went to an important meeting. The secretary in the office receives a call from a person claiming that the executive manager is about to give an important presentation but the presentation files are corrupted. The caller sternly recommends that the secretary email the presentation right away to a personal email address. The caller also states that the executive is holding the secretary responsible for the success of this presentation. Which type of social engineering tactic would describe this scenario?Correct
Incorrect
-
Question 14 of 103
14. Question
1 pointsWhat are the two most effective ways to defend against malware? (Choose two.)Correct
Incorrect
-
Question 15 of 103
15. Question
1 pointsThe employees in a company receive an email stating that the account password will expire immediately and requires a password reset within 5 minutes. Which statement would classify this email?Correct
Incorrect
-
Question 16 of 103
16. Question
1 pointsIn which situation would a detective control be warranted?Correct
Incorrect
-
Question 17 of 103
17. Question
1 pointsAn organization has implemented antivirus software. What type of security control did the company implement?Correct
Incorrect
-
Question 18 of 103
18. Question
1 pointsAlice and Bob are using public key encryption to exchange a message. Which key should Alice use to encrypt a message to Bob?Correct
Incorrect
-
Question 19 of 103
19. Question
1 pointsWhich statement describes a characteristics of block ciphers?Correct
Incorrect
-
Question 20 of 103
20. Question
1 pointsThe IT department is tasked to implement a system that controls what a user can and cannot do on the corporate network. Which process should be implemented to meet the requirement?Correct
Incorrect
-
Question 21 of 103
21. Question
1 pointsAlice and Bob use a pre-shared key to exchange a confidential message. If Bob wants to send a confidential message to Carol, what key should he use?Correct
Incorrect
-
Question 22 of 103
22. Question
1 pointsWhich access control strategy allows an object owner to determine whether to allow access to the object?Correct
Incorrect
-
Question 23 of 103
23. Question
1 pointsWhich method is used by steganography to hide text in an image file?Correct
Incorrect
-
Question 24 of 103
24. Question
1 pointsThe X.509 standards defines which security technology?Correct
Incorrect
-
Question 25 of 103
25. Question
1 pointsWhich hashing algorithm is recommended for the protection of sensitive, unclassified information?Correct
Incorrect
-
Question 26 of 103
26. Question
1 pointsTechnicians are testing the security of an authentication system that uses passwords. When a technician examines the password tables, the technician discovers the passwords are stored as hash values. However, after comparing a simple password hash, the technician then discovers that the values are different from those on other systems. What are two causes of this situation? (Choose two.)Correct
Incorrect
-
Question 27 of 103
27. Question
1 pointsYou have been asked to work with the data collection and entry staff in your organization in order to improve data integrity during initial data entry and data modification operations. Several staff members ask you to explain why the new data entry screens limit the types and size of data able to be entered in specific fields. What is an example of a new data integrity control?Correct
Incorrect
-
Question 28 of 103
28. Question
1 pointsWhat technology should be implemented to verify the identity of an organization, to authenticate its website, and to provide an encrypted connection between a client and the website?Correct
Incorrect
-
Question 29 of 103
29. Question
1 pointsYour organization will be handling market trades. You will be required to verify the identify of each customer who is executing a transaction. Which technology should be implemented to authenticate and verify customer electronic transactions?Correct
Incorrect
-
Question 30 of 103
30. Question
1 pointsAlice and Bob are using a digital signature to sign a document. What key should Alice use to sign the document so that Bob can make sure that the document came from Alice?Correct
Incorrect
-
Question 31 of 103
31. Question
1 pointsAn organization has determined that an employee has been cracking passwords on administrative accounts in order to access very sensitive payroll information. Which tools would you look for on the system of the employee? (Choose three)Correct
Incorrect
-
Question 32 of 103
32. Question
1 pointsAn organization wants to adopt a labeling system based on the value, sensitivity, and criticality of the information. What element of risk management is recommended?Correct
Incorrect
-
Question 33 of 103
33. Question
1 pointsAn organization has recently adopted a five nines program for two critical database servers. What type of controls will this involve?Correct
Incorrect
-
Question 34 of 103
34. Question
1 pointsBeing able to maintain availability during disruptive events describes which of the principles of high availability?Correct
Incorrect
-
Question 35 of 103
35. Question
1 pointsWhich risk mitigation strategies include outsourcing services and purchasing insurance?Correct
Incorrect
-
Question 36 of 103
36. Question
1 pointsThe awareness and identification of vulnerabilities is a critical function of a cybersecurity specialist. Which of the following resources can be used to identify specific details about vulnerabilities?Correct
Incorrect
-
Question 37 of 103
37. Question
1 pointsWhich technology would you implement to provide high availability for data storage?Correct
Incorrect
-
Question 38 of 103
38. Question
1 pointsWhich two values are required to calculate annual loss expectancy? (Choose two.)Correct
Incorrect
-
Question 39 of 103
39. Question
1 pointsWhat is it called when an organization only installs applications that meet its guidelines, and administrators increase security by eliminating all other applications?Correct
Incorrect
-
Question 40 of 103
40. Question
1 pointsThere are many environments that require five nines, but a five nines environment may be cost prohibitive. What is one example of where the five nines environment might be cost prohibitive?Correct
Incorrect
-
Question 41 of 103
41. Question
1 pointsWhich technology can be used to protect VoIP against eavesdropping?Correct
Incorrect
-
Question 42 of 103
42. Question
1 pointsMutual authentication can prevent which type of attack?Correct
Incorrect
-
Question 43 of 103
43. Question
1 pointsWhich of the following products or technologies would you use to establish a baseline for an operating system?Correct
Incorrect
-
Question 44 of 103
44. Question
1 pointsWhat Windows utility should be used to configure password rules and account lockout policies on a system that is not part of a domain?Correct
Incorrect
-
Question 45 of 103
45. Question
1 pointsWhat describes the protection provided by a fence that is 1 meter in height?Correct
Incorrect
-
Question 46 of 103
46. Question
1 pointsWhich wireless standard made AES and CCM mandatory?Correct
Incorrect
-
Question 47 of 103
47. Question
1 pointsWhich three protocols can use Advanced Encryption Standard (AES)? (Choose three.)Correct
Incorrect
-
Question 48 of 103
48. Question
1 pointsWhich website offers guidance on putting together a checklist to provide guidance on configuring and hardening operating systems?Correct
Incorrect
-
Question 49 of 103
49. Question
1 pointsWhich law was enacted to prevent corporate accounting-related crimes?Correct
Incorrect
-
Question 50 of 103
50. Question
1 pointsWhich cybersecurity weapon scans for use of default passwords, missing patches, open ports, misconfigurations, and active IP addresses?Correct
Incorrect
-
Question 51 of 103
51. Question
1 pointsA cybersecurity specialist is asked to identify the potential criminals known to attack the organization. Which type of hackers would the cybersecurity specialist be least concerned with?Correct
Incorrect
-
Question 52 of 103
52. Question
1 pointsWhat is an example of early warning systems that can be used to thwart cybercriminals?Correct
Incorrect
-
Question 53 of 103
53. Question
1 pointsWhich technology should be used to enforce the security policy that a computing device must be checked against the latest antivirus update before the device is allowed to connect to the campus network?Correct
Incorrect
-
Question 54 of 103
54. Question
1 pointsWhich data state is maintained in NAS and SAN services?Correct
Incorrect
-
Question 55 of 103
55. Question
1 pointsWhich technology can be used to ensure data confidentiality?Correct
Incorrect
-
Question 56 of 103
56. Question
1 pointsWhat is an impersonation attack that takes advantage of a trusted relationship between two systems?Correct
Incorrect
-
Question 57 of 103
57. Question
1 pointsUsers report that the network access is slow. After questioning the employees, the network administrator learned that one employee downloaded a third-party scanning program for the printer. What type of malware might be introduced that causes slow performance of the network?Correct
Incorrect
-
Question 58 of 103
58. Question
1 pointsWhat type of application attack occurs when data goes beyond the memory areas allocated to the application?Correct
Incorrect
-
Question 59 of 103
59. Question
1 pointsWhat type of attack has an organization experienced when an employee installs an unauthorized device on the network to view network traffic?Correct
Incorrect
-
Question 60 of 103
60. Question
1 pointsA penetration testing service hired by the company has reported that a backdoor was identified on the network. What action should the organization take to find out if systems have been compromised?Correct
Incorrect
-
Question 61 of 103
61. Question
1 pointsSmart cards and biometrics are considered to be what type of access control?Correct
Incorrect
-
Question 62 of 103
62. Question
1 pointsWhich access control should the IT department use to restore a system back to its normal state?Correct
Incorrect
-
Question 63 of 103
63. Question
1 pointsA user has a large amount of data that needs to be kept confidential. Which algorithm would best meet this requirement?Correct
Incorrect
-
Question 64 of 103
64. Question
1 pointsWhat happens as the key length increases in an encryption application?Correct
Incorrect
-
Question 65 of 103
65. Question
1 pointsYou have been asked to describe data validation to the data entry clerks in accounts receivable. Which of the following are good examples of strings, integers, and decimals?Correct
Incorrect
-
Question 66 of 103
66. Question
1 pointsWhich hashing technology requires keys to be exchanged?Correct
Incorrect
-
Question 67 of 103
67. Question
1 pointsWhat is a feature of a cryptographic hash function?Correct
Incorrect
-
Question 68 of 103
68. Question
1 pointsA VPN will be used within the organization to give remote users secure access to the corporate network. What does IPsec use to authenticate the origin of every packet to provide data integrity checking?Correct
Incorrect
-
Question 69 of 103
69. Question
1 pointsYour risk manager just distributed a chart that uses three colors to identify the level of threat to key assets in the information security systems. Red represents high level of risk, yellow represents average level of threat and green represents low level of threat. What type of risk analysis does this chart represent?Correct
Incorrect
-
Question 70 of 103
70. Question
1 pointsKeeping data backups offsite is an example of which type of disaster recovery control?Correct
Incorrect
-
Question 71 of 103
71. Question
1 pointsWhat are two incident response phases? (Choose two.)Correct
Incorrect
-
Question 72 of 103
72. Question
1 pointsThe team is in the process of performing a risk analysis on the database services. The information collected includes the initial value of these assets, the threats to the assets and the impact of the threats. What type of risk analysis is the team performing by calculating the annual loss expectancy?Correct
Incorrect
-
Question 73 of 103
73. Question
1 pointsWhat approach to availability provides the most comprehensive protection because multiple defenses coordinate together to prevent attacks?Correct
Incorrect
-
Question 74 of 103
74. Question
1 pointsWhich utility uses the Internet Control Messaging Protocol (ICMP)?Correct
Incorrect
-
Question 75 of 103
75. Question
1 pointsIn a comparison of biometric systems, what is the crossover error rate?Correct
Incorrect
-
Question 76 of 103
76. Question
1 pointsWhich protocol would be used to provide security for employees that access systems remotely from home?Correct
Incorrect
-
Question 77 of 103
77. Question
1 pointsWhich threat is mitigated through user awareness training and tying security awareness to performance reviews?Correct
Incorrect
-
Question 78 of 103
78. Question
1 pointsHVAC, water system, and fire systems fall under which of the cybersecurity domains?Correct
Incorrect
-
Question 79 of 103
79. Question
1 pointsTechnologies like GIS and IoE contribute to the growth of large data stores. What are two reasons that these technologies increase the need for cybersecurity specialists? (Choose two.)Correct
Incorrect
-
Question 80 of 103
80. Question
1 pointsWhich two groups of people are considered internal attackers? (Choose two.)Correct
Incorrect
-
Question 81 of 103
81. Question
1 pointsWhich methods can be used to implement multifactor authentication?Correct
Incorrect
-
Question 82 of 103
82. Question
1 pointsA security specialist is asked for advice on a security measure to prevent unauthorized hosts from accessing the home network of employees. Which measure would be most effective?Correct
Incorrect
-
Question 83 of 103
83. Question
1 pointsWhat type of attack will make illegitimate websites higher in a web search result list?Correct
Incorrect
-
Question 84 of 103
84. Question
1 pointsWhat is a nontechnical method that a cybercriminal would use to gather sensitive information from an organization?Correct
Incorrect
-
Question 85 of 103
85. Question
1 pointsWhich algorithm will Windows use by default when a user intends to encrypt files and folders in an NTFS volume?Correct
Incorrect
-
Question 86 of 103
86. Question
1 pointsBefore data is sent out for analysis, which technique can be used to replace sensitive data in nonproduction environments to protect the underlying information?Correct
Incorrect
-
Question 87 of 103
87. Question
1 pointsAn organization plans to implement security training to educate employees about security policies. What type of access control is the organization trying to implement?Correct
Incorrect
-
Question 88 of 103
88. Question
1 pointsPasswords, passphrases, and PINs are examples of which security term?Correct
Incorrect
-
Question 89 of 103
89. Question
1 pointsWhat technique creates different hashes for the same password?Correct
Incorrect
-
Question 90 of 103
90. Question
1 pointsYou have been asked to implement a data integrity program to protect data files that need to be electronically downloaded by the sales staff. You have decided to use the strongest hashing algorithm available on your systems. Which hash algorithm would you select?Correct
Incorrect
-
Question 91 of 103
91. Question
1 pointsWhat kind of integrity does a database have when all its rows have a unique identifier called a primary key?Correct
Incorrect
-
Question 92 of 103
92. Question
1 pointsWhat approach to availability involves using file permissions?Correct
Incorrect
-
Question 93 of 103
93. Question
1 pointsWhich national resource was developed as a result of a U.S. Executive Order after a ten-month collaborative study involving over 3,000 security professionals?Correct
Incorrect
-
Question 94 of 103
94. Question
1 pointsWhich two protocols pose switching threats? (Choose two.)Correct
Incorrect
-
Question 95 of 103
95. Question
1 pointsWhat is the most difficult part of designing a cryptosystem?Correct
Incorrect
-
Question 96 of 103
96. Question
1 pointsWhat technology should you implement to ensure that an individual cannot later claim that he or she did not sign a given document?Correct
Incorrect
-
Question 97 of 103
97. Question
1 pointsWhich type of cybercriminal attack would interfere with established network communication through the use of constructed packets so that the packets look like they are part of the normal communication?Correct
Incorrect
-
Question 98 of 103
98. Question
1 pointsAn organization just completed a security audit. Your division was cited for not conforming to X.509 requirements. What is the first security control you need to examine?Correct
Incorrect
-
Question 99 of 103
99. Question
1 pointsWhat technology can be implemented as part of an authentication system to verify the identification of employees?Correct
Incorrect
-
Question 100 of 103
100. Question
1 pointsWhich technology can be used to prevent a cracker from launching a dictionary or brute-force attack of a hash?Correct
Incorrect
-
Question 101 of 103
101. Question
1 pointsWhich technology can be implemented as part of an authentication system to verify the identification of employees?Correct
Incorrect
-
Question 102 of 103
102. Question
1 pointsNetbus belongs to which malware type?Correct
Incorrect
-
Question 103 of 103
103. Question
1 pointsA user complains about frequently receiving messages on the smartphone that urges the user to visit different insurance websites. If the user clicks the link to visit, a user login message will pop up and ask the user to register first. Which wireless and mobile device attack has the user experienced?Correct
Incorrect
