Twa kɔ nsɛm atitiriw so
Log in
Sign up for FREE
arrow_back
Laabri

CyberSecurity Fundamentals Final Exam

star
star
star
star
star
Last updated 2 months ago
55 Nsɛmmisa
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
Asemmisa {{asɛmmisaAhyɛnsode}}
39.

A website uses "HTTPS" instead of "HTTP." What additional security feature does HTTPS provide?

Asemmisa {{asɛmmisaAhyɛnsode}}
40.

A user installs a Free Game on their computer. Shortly after, they notice their computer is running slowly and sending data without their knowledge. What type of malware has most likely been installed? 

Asemmisa {{asɛmmisaAhyɛnsode}}
41.

Why is it important to regularly update Software and Operating Systems from a Cybersecurity perspective?

Asemmisa {{asɛmmisaAhyɛnsode}}
42.

Which of the following best explains why using public Wi-Fi without a VPN can be risky? 

Asemmisa {{asɛmmisaAhyɛnsode}}
43.

A ransomware attack encrypts all files on a company's server and demands payment for the decryption key. Which cybersecurity principle has been most directly violated? 

Asemmisa {{asɛmmisaAhyɛnsode}}
44.

A Social Engineering Attack involves an attacker calling an employee and pretending to be from the IT Department, asking for their password. What is the best term for this specific type of Social Engineering?

Asemmisa {{asɛmmisaAhyɛnsode}}
45.

How does a Denial of Service (DoS) attack affect a target system?

Asemmisa {{asɛmmisaAhyɛnsode}}
46.

A School Network Administrator notices unusual spikes in network traffic late at night when no students are present. The traffic appears to be originating from several computers in the Computer Lab and is being sent to an unknown External Server. Using your knowledge of Cybersecurity, what is the most likely explanation, and what should the Administrator do first? 

Asemmisa {{asɛmmisaAhyɛnsode}}
47.

A company is designing a new cybersecurity policy. They must choose between two approaches: (1) Allow all network traffic by default and block only known threats, or (2) Block all network traffic by default and allow only verified, necessary traffic. Which approach is more secure and why? 

Asemmisa {{asɛmmisaAhyɛnsode}}
48.

An attacker wants to gain access to a system protected by a password. The attacker uses an automated tool that systematically tries every possible combination of characters until the correct password is found. If a password is 4 characters long and uses only lowercase letters (26 possibilities per character), how many possible combinations must the attacker try in the worst case? Use the formula 26^n where n is the number of characters. 

Asemmisa {{asɛmmisaAhyɛnsode}}
49.

A Cybersecurity Analyst is reviewing logs and finds that an attacker gained access to a system by exploiting a vulnerability in an outdated web application, then used that access to move to other systems on the network, and finally exfiltrated sensitive data. Which Cybersecurity Strategy, if properly implemented, would have been  MOST effective at limiting the attacker's ability to move between systems?

Asemmisa {{asɛmmisaAhyɛnsode}}
50.

A student is creating a Security plan for their School's Computer Lab. They want to ensure that even if one Security measures fail, other measures will still protect the systems. Which Cybersecurity Principle does this strategy reflect, and which combination of measures best implements it? 

Asemmisa {{asɛmmisaAhyɛnsode}}
51.

An organization discovers that an employee has been sending confidential company data to a personal email account over several months. Which combination of cybersecurity controls, if implemented beforehand, would have been MOST effective at detecting and preventing this insider threat?

Asemmisa {{asɛmmisaAhyɛnsode}}
52.

A Hacker intercepts encrypted communication between two users. Even though the hacker cannot read the messages now, they store the encrypted data hoping that future advances in computing will allow them to decrypt it. What type of threat does this represent, and what is the best long-term defense against it? 

Asemmisa {{asɛmmisaAhyɛnsode}}
53.

A Cybersecurity Team is evaluating the risk of a potential attack on their system. They know that the probability of a successful attack occurring is 1/5 and the potential financial loss if the attack succeeds is $50,000. Using the formula for expected loss: Expected Loss = Probability × Impact, what is the expected financial loss from this threat?

Asemmisa {{asɛmmisaAhyɛnsode}}
54.

A School is deciding whether to store student records on a Local Server or in a Cloud-based System. From a Cybersecurity perspective, which of the following represents the most Well-reasoned Analysis of the trade-offs? 

Asemmisa {{asɛmmisaAhyɛnsode}}
55.

A Cybersecurity Analyst notices that a series of failed login attempts are being made on a company's server, each attempt using a slightly different password derived from a list of commonly used passwords. After analyzing the pattern, the analyst determines the attack is automated. Which type of attack is being carried out, 

and what is the MOST effective combination of countermeasures to stop it? 

Asemmisa {{asɛmmisaAhyɛnsode}}
1.

_____ are like laws within the boundaries of an Organization.

Asemmisa {{asɛmmisaAhyɛnsode}}
2.

Which of the following is NOT part of the choice of an Organizational Security Architecture?

Asemmisa {{asɛmmisaAhyɛnsode}}
3.

Another word or phrase that means "incident candidate" is ______.

Asemmisa {{asɛmmisaAhyɛnsode}}
4.

Which of the following is NOT a method for testing Contingency plan?

Asemmisa {{asɛmmisaAhyɛnsode}}
5.

Which of following is NOT one of the three general information Security policy categories?

Asemmisa {{asɛmmisaAhyɛnsode}}
6.

Privacy of Customer Information may be violated by which of the following?

Asemmisa {{asɛmmisaAhyɛnsode}}
7.

InfoSec _______ management is the process of designing, implementing, and managing the use of the collective Data elements (called measurements or metrics) to determine the effectiveness of the overall Security program.

Asemmisa {{asɛmmisaAhyɛnsode}}
8.

Overtime, policies and procedures may become inadequate because of _______.

Asemmisa {{asɛmmisaAhyɛnsode}}
9.

A Virtual Private Network (VPN) uses Encryption Technology and Security protocols to encrypt traffic transmitted across unsecured Public Networks.

Asemmisa {{asɛmmisaAhyɛnsode}}
10.

Which of there is NOT one of the major categories of Firewall processing modes?

Asemmisa {{asɛmmisaAhyɛnsode}}
11.

The principle of limiting User Access Privileges to a specific information required to perform their assigned tasks are known as _________.

Asemmisa {{asɛmmisaAhyɛnsode}}
12.

Security Industry certifications are often used to help filter Applicants for jobs, but suffer which of the following challenges?

Asemmisa {{asɛmmisaAhyɛnsode}}
13.

Scanning and Analysis Tools can be used by Organizations and Attackers for which of the following purposes?

Asemmisa {{asɛmmisaAhyɛnsode}}
14.

______ are a type of Intrusion Detection and Prevention System (IDPS) focused on protecting Information assets by examining communication traffic.

Asemmisa {{asɛmmisaAhyɛnsode}}
15.

A Project Manager is an important part of any Information Security Project, as that person is responsible for coordinating activities such as ___________.

Asemmisa {{asɛmmisaAhyɛnsode}}
16.

Which of these is NOT a part of the Organizational Change Model used to support Change Management for Information Security requirements.

Asemmisa {{asɛmmisaAhyɛnsode}}
17.

The secure Hash function is used in Cryptography to confirm a message's _________.

Asemmisa {{asɛmmisaAhyɛnsode}}
18.

HyperText Transfer Protocol Secure (HTTPS) is used to provide which of these functions for Web-based communications.

Asemmisa {{asɛmmisaAhyɛnsode}}
19.

A potential weakness in an Asset or its Defensive Control System is called a ___________.

Asemmisa {{asɛmmisaAhyɛnsode}}
20.

The Information Security Project Team should consist of people with what rules and experience?

Asemmisa {{asɛmmisaAhyɛnsode}}
21.

Which group(s) of people are responsible for facilitating the Information Security Program that protects the Organization's ability to function?

Asemmisa {{asɛmmisaAhyɛnsode}}
22.

The process of using Interpersonal Skills to convince people to reveal or access credentials or valuable information to an attacker is known as ___________.

Asemmisa {{asɛmmisaAhyɛnsode}}
23.

Shifting risks to other areas or to outside entities is a Risk Treatment known as ____________.

Asemmisa {{asɛmmisaAhyɛnsode}}
24.

The result of this calculation of likelihood of Threat Event (attack) occurrence multiplied by Impact (or consequence), plus or minus an Element (uncertainity) is known as _________.

Asemmisa {{asɛmmisaAhyɛnsode}}
25.

Which of these is often the most valuable asset that the Information Security Organization tries to protect?

Asemmisa {{asɛmmisaAhyɛnsode}}
26.

What does the term "malware" stand for?

Asemmisa {{asɛmmisaAhyɛnsode}}
27.

What is the primary purpose of a Firewall?

Asemmisa {{asɛmmisaAhyɛnsode}}
28.

What does "HTTP" stand for?

Asemmisa {{asɛmmisaAhyɛnsode}}
29.

Which of the following is an example of a strong password?

Asemmisa {{asɛmmisaAhyɛnsode}}
30.

What is phishing?

Asemmisa {{asɛmmisaAhyɛnsode}}
31.

What does "VPN" stand for?

Asemmisa {{asɛmmisaAhyɛnsode}}
32.

Which of the following best describes encryption?

Asemmisa {{asɛmmisaAhyɛnsode}}
33.

What is two-factor authentication (2FA)?

Asemmisa {{asɛmmisaAhyɛnsode}}
34.

Which of the following is NOT a type of malware?

Asemmisa {{asɛmmisaAhyɛnsode}}
35.

What does "CIA" stand for in the context of CyberSecurity?

Asemmisa {{asɛmmisaAhyɛnsode}}
36.

A student receives an email claiming to be from their school asking for their login credentials. The email contains a link to a website that looks identical to the school's official site. Which type of Cyberattack does this scenario best represents?

Asemmisa {{asɛmmisaAhyɛnsode}}
37.

A company stores its user passwords as plain text in a database. Why is this considered a poor Cybersecurity practice?

Asemmisa {{asɛmmisaAhyɛnsode}}
38.

Which of the following actions best demonstrates the concept of "least privilege" in Cybersecurity?