

Computer Security Principles
Test Bank
Course Introduction
This course provides an in-depth exploration of the fundamental principles and practices of computer security. Topics include the basics of confidentiality, integrity, and availability, security policies, cryptographic techniques, user authentication methods, access control models, and risk management. Students will examine common threats and vulnerabilities, as well as defensive strategies to mitigate attacks. The course also covers ethical and legal aspects of security, and provides practical skills to analyze and secure computer systems, networks, and applications in today's digital environment.
Recommended Textbook
CompTIA Security+ Guide to Network Security Fundamentals 5th Edition by Mark Ciampa
Available Study Resources on Quizplus
15 Chapters
750 Verified Questions
750 Flashcards
Source URL: https://quizplus.com/study-set/3831

Page 2

Chapter 1: Introduction to Security
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/76425
Sample Questions
Q1) A premeditated, politically motivated attack against information, computer systems, computer programs, and data, which often results in violence.
A)asset
B)cyberterrorism
C)hactivist
D)exploit kit
E)computer spy
F)risk
G)threat
H)threat agent
I)vulnerability
J)threat vector
Answer: B
Q2) Script kiddies acquire which item below from other attackers to easily craft an attack:
A)Exploit kit
B)Botnet
C)Zero day
D)Backdoor
Answer: A
To view all questions and flashcards with answers, click on the resource link above.
Page 3

Chapter 2: Malware and Social Engineering Attacks
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/76418
Sample Questions
Q1) What is malware?
Answer: Malware is software that enters a computer system without the user's knowledge or consent and then performs an unwanted-and usually harmful-action. Malware is a general term that refers to a wide variety of damaging or annoying software programs. One way to classify malware is by its primary objective. Some malware has the primary goal of rapidly spreading its infection, while other malware has the goal of concealing its purpose. Another category of malware has the goal of making a profit for its creators.
Q2) Which of the following is malicious computer code that reproduces itself on the same computer?
A)virus
B)worm
C)adware
D)spyware
Answer: A
Q3) What is a worm?
Answer: A worm is a malicious program that uses a computer network to replicate, and is designed to enter a computer through the network then take advantage of vulnerability in an application or an operating system on the host computer.
To view all questions and flashcards with answers, click on the resource link above.
Page 4

Chapter 3: Application and Networking-Based Attacks
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/76417
Sample Questions
Q1) Ethernet LAN networks utilize the physical _________________ address to send packets.
Answer: Media Access Control (MAC)
Q2) Attacks that take place against web based services are considered to be what type of attack?
A)client-side
B)hybrid
C)server-side
D)relationship
Answer: C
Q3) How does a SYN flood attack work?
Answer: A SYN flood attack involves an attacker sending SYN segments in IP packets to a server, with modified source IP addresses in the packets. This causes additional traffic to pass between the server and the spoofed IP address.
Q4) How does ARP poisoning take advantage of the use of ARP?
Answer: An attacker modifies the MAC address in the ARP cache so that corresponding IP addresses point to different computers.
Q5) A web browser makes a request for a web page using the ________________. Answer: Hypertext Transport Protocol (HTTP)
To view all questions and flashcards with answers, click on the resource link above. Page 5

Chapter 4: Host, Application, and Data Security
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/76416
Sample Questions
Q1) What type of video surveillance is typically used by banks, casinos, airports, and military installations, and commonly employs guards who actively monitor the surveillance?
A)CCTV
B)ICTV
C)IPTV
D)ITV
Q2) Spam filtering software that analyzes every word in an email and determines how frequently a word occurs in order to determine if it is spam.
A)Access list
B)Activity phase controls
C)Android
D)Barricade
E)Bayesian filtering
F)Cross-site request forgery (XSRF)
G)Fuzz testing
H)iOS
I)NoSQL
J)Supervisory control and data acquisition (SCADA)
Q3) How does an RFID tag embedded into an ID badge function without a power supply?
To view all questions and flashcards with answers, click on the resource link above. Page 6

Chapter 5: Basic Cryptography
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/76415
Sample Questions
Q1) What type of cryptographic algorithm is considered to be a one-way algorithm, in that its contents can't be used to reveal the original set of data?
A)hash
B)key
C)digest
D)block
Q2) Describe the RIPEMD hash.
Q3) A cipher that manipulates an entire block of plaintext at one time.
A)Advanced Encryption Standard (AES)
B)Block cipher
C)Ciphertext
D)Data Encryption Standard (DES)
E)Diffie-Hellman (DH)
F)Elliptic curve cryptography (ECC)
G)Ephemeral key
H)Private key
I)Public key
J)Stream cipher
Q4) Describe hard disk drive encryption.
Q5) The Data Encryption Standard is a(n) ______________ cipher.
To view all questions and flashcards with answers, click on the resource link above. Page 7

Chapter 6: Advanced Cryptography
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/76414
Sample Questions
Q1) A framework for managing all of the entities involved in creating, storing, distributing, and revoking digital certificates
A)Bridge trust model
B)Certificate Authority (CA)
C)Certificate Repository
D)Digital certificate
E)Distributed trust model
F)key escrow
G)Public key Infrastructure (PKI)
H)Session keys
I)Third-party trust
J)Trust model
Q2) ____________________ may be defined as confidence in or reliance on another person or entity.
Q3) Digital signatures actually only show that the public key labeled as belonging to the person was used to encrypt the digital signature.
A)True
B)False
Q4) List the four stages of a certificate life cycle.
To view all questions and flashcards with answers, click on the resource link above. Page 8

Chapter 7: Network Security
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/76413
Sample Questions
Q1) Which network address below is not a private IP address network?
A)10.4.5.0
B)172.63.255.0
C)192.168.255.0
D)172.17.16.0
Q2) What technology enables authorized users to use an unsecured public network, such as the Internet, as if were a secure private network?
A)IKE tunnel
B)VPN
C)endpoint
D)router
Q3) List and describe three advantages to subnetting.
Q4) How does a Unified Threat Management (UTM) security product help reduce administrative overhead?
Q5) Describe how VLAN communication takes place.
Q6) What is the difference between anomaly based monitoring and signature based monitoring?
Q7) Workgroup switches must work faster than core switches.
A)True
B)False
To view all questions and flashcards with answers, click on the resource link above. Page 9

Chapter 8: Administering a Secure Network
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/76412
Sample Questions
Q1) The deployment of this technology below can be used as a defense against DoS and DDoS SYN flood attacks:
A)flood guard
B)protocol guard
C)link guard
D)frame guard
Q2) The ____________ is a high-speed storage network protocol that can transmit up to 16 gigabits per second.
Q3) List the steps of a DNS lookup.
Q4) Despite its promise to dramatically impact IT, cloud computing raises significant security concerns.
A)True
B)False
Q5) What transport protocol is used by Windows operating systems to allow applications on separate computers to communicate over a LAN?
A)SSH
B)Telnet
C)NetBIOS
D)DHCP
To view all questions and flashcards with answers, click on the resource link above. Page 10

Chapter 9: Wireless Network Security
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/76411
Sample Questions
Q1) Identify and describe two types of wireless probes.
Q2) What proprietary EAP method developed by Cisco requires mutual authentication for WLAN encryption using Cisco client software?
A)LEAP
B)TKIP
C)EAP
D)PEAP
Q3) The second generation of WPA security from the Wi-Fi Alliance that addresses authentication and encryption on WLANs and is currently the most secure model for Wi-Fi security.
A)Bluejacking
B)Bluesnarfing
C)Initialization vector (IV)
D)Near field communication (NFC)
E)Preshared key (PSK)
F)RF Jamming
G)War driving
H)Wi-Fi Protected Setup (WPS)
I)Wi-Fi Protected Access 2 (WPA 2)
J)Wired Equivalent Privacy (WEP)
To view all questions and flashcards with answers, click on the resource link above. Page 11

Chapter 10: Mobile Device Security
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/76424
Sample Questions
Q1) A small form factor storage media of a variety of different types and sizes.
A)Asset tracking
B)Geo-fencing
C)Geo-tagging
D)Location services
E)Lock screen
F)Mobile application management (MAM)
G)Off-boarding
H)On-boarding
I)Remote wiping
J) Secure digital (SD)
Q2) List at least three things that can be done in order to reduce the risk of theft or loss of a mobile device.
Q3) What term is used to describe the operation of stockrooms where mobile devices are stored prior to their dispersal to employees?
A)Asset tracking
B)Inventory control
C)Device monitoring
D)Access filtering
Q4) Describe some of the risks associated with BYOD.
Page 12
To view all questions and flashcards with answers, click on the resource link above.

Chapter 11: Access Control Fundamentals
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/76423
Sample Questions
Q1) Discuss the differences between DAP and LDAP.
Q2) Describe how Kerberos works.
Q3) What access control model below is considered to be the most restrictive access control model, and involves assigning access controls to users strictly according to the custodian?
A)Mandatory Access Control
B)Role Based Access Control
C)Discretionary Access Control
D)Rule Based Access Control
Q4) To assist with controlling orphaned and dormant accounts, what can be used to indicate when an account is no longer active?
A)Password expiration
B)Account expiration
C)Last login
D)Account last used
Q5) The strength of RADIUS is that messages are always directly sent between the wireless device and the RADIUS server.
A)True
B)False
To view all questions and flashcards with answers, click on the resource link above. Page 13

Chapter 12: Authentication and Account Management
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/76422
Sample Questions
Q1) The use of one authentication credential to access multiple accounts or applications is referred to as?
A)Individual Sign On
B)Single Sign On
C)Unilateral Sign On
D)Federated Sign On
Q2) A password attack in which every possible combination of letters, numbers, and characters is used to create encrypted passwords that are matched against those in a stolen password file.
A)Authentication factors
B)Bcrypt
C)Brute force attack
D)Dictionary attack
E)Hybrid attack
F)Key stretching
G)NTLM (New Technology LAN Manager) hash
H)Salt
I)Single sign-on
J)Token
Q3) The most common type of authentication today is a(n)
14
To view all questions and flashcards with answers, click on the resource link above.

Chapter 13: Business Continuity
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/76421
Sample Questions
Q1) What are the steps in damage control?
Q2) The maximum length of time that an organization can tolerate between backups.
A)Business continuity
B)Chain of custody
C)Clustering
D)Computer forensics
E)Continuity of operations
F)Faraday cage
G)Hot site
H)Mean time between failures (MTBF)
I)Recovery point objective
J)Risk assessment
Q3) RAID level 0 is known as disk mirroring, because it involves connecting multiple drives in the server to the same disk controller card.
A)True
B)False
Q4) What is required upon completion of an evidence examination?
Q5) Identify two scenarios that could be used in a BIA.
Q6) What are the objectives of disaster exercises?
Q7) Explain how to best capture volatile data.
To view all questions and flashcards with answers, click on the resource link above. Page 15

Chapter 14: Risk Mitigation
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/76420
Sample Questions
Q1) A(n) ____________________ is a methodical examination and review that produces a detailed report of its findings.
Q2) A security policy that outlines how the organization uses personal information it collects.
A)Acceptable use policy (AUP)
B)Change management
C)False negative
D)False positive
E)Operational risk control type
F)Privacy policy
G)Technical risk control type
H)Peer-to peer network
I)Single Loss Expectancy (SLE)
J)Incident management
Q3) What type of learner learns best through hands-on approaches?
A)Visual
B)Auditory
C)Kinesthetic
D)Spatial
Q4) List two characteristics of a policy.
To view all questions and flashcards with answers, click on the resource link above. Page 16

Chapter 15: Vulnerability Assessment and Third Party Integration
Available Study Resources on Quizplus for this Chatper
50 Verified Questions
50 Flashcards
Source URL: https://quizplus.com/quiz/76419
Sample Questions
Q1) Which is the term for a computer typically located in an area with limited security and loaded with software and data files that appear to be authentic, yet they are actually imitations of real data files.
A)port scanner
B)write blocker
C)honeypot
D)honeycomb
Q2) The start-up relationship agreement between parties.
A)asset
B)cyberterrorism
C)hactivist
D)exploit kit
E)computer spy
F)risk
G)threat
H)threat agent
I)vulnerability
J)threat vector
Q3) When a security hardware device fails or a program aborts, which state should it go into?
To view all questions and flashcards with answers, click on the resource link above. Page 17