A company stores customer records on a laptop’s hard drive. Which action best protects this data if the laptop is stolen?
A student sends a file containing sensitive information over the internet. Which measure best protects the data while it is being transmitted?
A hospital employee is viewing patient records to update treatment notes. What state is the data in during this process?
An organization classifies some files as “highly sensitive” and others as “public.” What is the most likely reason for this classification?
A company collects names, email addresses, and phone numbers from customers. What type of data is this?
A clinic stores patient test results and billing information. Which regulation is most relevant to protecting this data?
A hacker gains physical access to a computer with unencrypted files. What can the hacker most likely do?
A company gives all employees administrative privileges on their computers. What risk does this create?
A shared folder allows all employees to edit important documents. What vulnerability does this create?
A web application asks users to enter a number but does not check the input. A user enters text instead. What security issue does this demonstrate?
An attacker enters SQL commands into a website’s login form. What type of attack is this?
A website allows users to post comments. An attacker inserts malicious JavaScript into a comment that runs when others view it. What type of attack is this?
A program crashes when a user inputs more data than expected, overwriting memory. What type of attack is this?
A company stores highly sensitive military designs on an unencrypted drive. How would this risk most likely be classified?
A company encrypts customer data but uses a very short encryption key. How would this risk most likely be classified?
An employee stores personal notes on an unprotected shared drive. How would this risk most likely be classified?
A company requires employees to attend training on handling sensitive data. What type of control is this?
A policy defines which encryption algorithms and key lengths are allowed. What type of policy is this?
A company assigns access to files based on job roles like “manager” or “accountant.” What model is this?
A system denies access to a database outside of business hours, even for authorized users. What model is this?
A file owner decides who can view or edit their file. What model is this?
A government system assigns security levels and prevents users from accessing higher-level data. What model is this?
A user has permissions listed as rwxr-x---. What does this indicate?
A system uses full disk encryption. What must typically happen before the system boots?
Which statement best describes asymmetric encryption?
A sender wants to securely send a message to a receiver using asymmetric encryption. Which key should the sender use?
Why are longer encryption keys generally more secure?
A web application firewall (WAF) is installed. What is its primary function?
A system detects that a file’s hash has changed since last week. What does this indicate?
A security analyst notices login attempts with input like ' OR 1=1 -- in logs. What does this suggest?
Identify the type of sensitive data stored by the company and explain why it requires protection. (2 points for correctly identifying all types of data stored and explaining each)
Explain one risk to confidentiality, integrity, or availability in this scenario.
Identify the type of attack shown in the logs and briefly explain how it works.
Describe one specific way the company could prevent this type of attack.
Recommend one access control improvement and explain how it would reduce risk.