Skip to main content

Cybersecurity Fundamentals Exam Questions - 1076 Verified Questions

Page 1


Cybersecurity Fundamentals

Exam Questions

Course Introduction

Cybersecurity Fundamentals introduces the essential concepts and practices of securing computer systems, networks, and data against digital threats. This course covers the core principles of confidentiality, integrity, and availability, as well as common types of cyber attacks such as malware, phishing, and social engineering. Students will learn about network security protocols, basic cryptography, authentication mechanisms, and risk management strategies. The curriculum also addresses legal and ethical considerations, best practices for securing personal and organizational information, and current trends in cyber defense. The goal is to provide a solid foundation for further study in cybersecurity and prepare students to recognize and mitigate basic security risks.

Recommended Textbook

Computer Security Principles and Practice 3rd Edition by William Stallings

Available Study Resources on Quizplus

24 Chapters

1076 Verified Questions

1076 Flashcards

Source URL: https://quizplus.com/study-set/3981 Page 2

Chapter 1: Computer Systems Overview

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/79973

Sample Questions

Q1) The more critical a component or service,the higher the level of availability required.

A)True

B)False

Answer: True

Q2) Replay,masquerade,modification of messages,and denial of service are example of _________ attacks.

Answer: active

Q3) A __________ is any action that compromises the security of information owned by an organization.

A)security mechanism

B)security policy

C)security attack

D)security service

Answer: C

Q4) Contingency planning is a functional area that primarily requires computer security technical measures.

A)True

B)False

Answer: False

To view all questions and flashcards with answers, click on the resource link above. Page 3

Chapter 2: Cryptographic Tools

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/79962

Sample Questions

Q1) A __________ processes the plaintext input in fixed-size blocks and produces a block of ciphertext of equal size for each plaintext block.

Answer: block cipher

Q2) An important element in many computer security services and applications is the use of cryptographic algorithms.

A)True

B)False

Answer: True

Q3) Transmitted data stored locally are referred to as __________ .

A)ciphertext

B)DES

C)data at rest

D)ECC

Answer: C

Q4) A __________ processes the input elements continuously,producing output one element at a time.

Answer: stream cipher

Q5) There are two general approaches to attacking a symmetric encryption scheme: cryptanalytic attacks and __________ attacks.

Answer: brute-force

To view all questions and flashcards with answers, click on the resource link above. Page 4

Chapter 3: User Authentication

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/79956

Sample Questions

Q1) User authentication is the fundamental building block and the primary line of defense.

A)True

B)False

Answer: True

Q2) In a biometric scheme some physical characteristic of the individual is mapped into a digital representation.

A)True

B)False

Answer: True

Q3) A good technique for choosing a password is to use the first letter of each word of a phrase.

A)True

B)False

Answer: True

Q4) A __________ authentication system attempts to authenticate an individual based on his or her unique physical characteristics.

Answer: biometric

Q5) A __________ is an individual to whom a debit card is issued.

Answer: cardholder

To view all questions and flashcards with answers, click on the resource link above. Page 5

Chapter 4: Access Control

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/79955

Sample Questions

Q1) Security labels indicate which system entities are eligible to access certain resources.

A)True

B)False

Q2) A __________ is an entity capable of accessing objects.

A)group

B)object

C)subject

D)owner

Q3) __________ access control controls access based on the roles that users have within the system and on rules stating what accesses are allowed to users in given roles.

Q4) A(n)__________ is a resource to which access is controlled.

A)object

B)owner

C)world

D)subject

Q5) An access right describes the way in which a subject may access an object. A)True

B)False

To view all questions and flashcards with answers, click on the resource link above. Page 6

Chapter 5: Database and Cloud Security

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/79954

Sample Questions

Q1) An IDS is a set of automated tools designed to detect unauthorized access to a host system.

A)True

B)False

Q2) A _________ is defined to be a portion of a row used to uniquely identify a row in a table.

A)foreign key

B)query

C)primary key

D)data perturbation

Q3) _________ is a model for enabling ubiquitous,convenient,on-demand network access to a shared pool of configurable computing resources that can be rapidly provisioned and released with minimal management effort or service provider interaction.

Q4) __________ encompasses intrusion detection,prevention and response.

A)Intrusion management

B)Security assessments

C)Database access control

D)Data loss prevention

Q5) The __________ cloud infrastructure is operated solely for an organization.

Page 7

To view all questions and flashcards with answers, click on the resource link above.

Chapter 6: Malicious Software

Available Study Resources on Quizplus for this Chatper

44 Verified Questions

44 Flashcards

Source URL: https://quizplus.com/quiz/79953

Sample Questions

Q1) In addition to propagating,a worm usually carries some form of payload.

A)True

B)False

Q2) __________ technology is an anti-virus approach that enables the anti-virus program to easily detect even the most complex polymorphic viruses and other malware,while maintaining fast scanning speeds.

Q3) The __________ is what the virus "does".

A)infection mechanism

B)trigger

C)logic bomb

D)payload

Q4) __________ code refers to programs that can be shipped unchanged to a heterogeneous collection of platforms and execute with identical semantics.

Q5) Malicious software aims to trick users into revealing sensitive personal data.

A)True

B)False

Q6) The four phases of a typical virus are: dormant phase,triggering phase,execution phase and __________ phase.

Q7) A __________ is a collection of bots capable of acting in a coordinated manner.

Page 8

To view all questions and flashcards with answers, click on the resource link above.

Chapter 7: Denial-Of-Service Attacks

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/79952

Sample Questions

Q1) Since filtering needs to be done as close to the source as possible by routers or gateways knowing the valid address ranges of incoming packets,an _______ is best placed to ensure that valid source addresses are used in all packets from its customers.

Q2) It is possible to specifically defend against the ______ by using a modified version of the TCP connection handling code.

A)three-way handshake

B)UDP flood

C)SYN spoofing attack

D)flash crowd

Q3) Slowloris is a form of ICMP flooding.

A)True

B)False

Q4) If an organization is dependent on network services it should consider mirroring and ________ these servers over multiple sites with multiple network connections.

Q5) The SYN spoofing attack targets the table of TCP connections on the server.

A)True

B)False

To view all questions and flashcards with answers, click on the resource link above. Page 9

Chapter 8: Intrusion Detection

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/79951

Sample Questions

Q1) The broad classes of intruders are: cyber criminals,state-sponsored organizations,_________ ,and others.

Q2) The primary purpose of an IDS is to detect intrusions,log suspicious events,and send alerts.

A)True

B)False

Q3) __________ is a security service that monitors and analyzes system events for the purpose of finding,and providing real-time warning of attempts to access system resources in an unauthorized manner.

Q4) Intrusion detection is based on the assumption that the behavior of the intruder differs from that of a legitimate user in ways that can be quantified.

A)True

B)False

Q5) A _________ monitors the characteristics of a single host and the events occurring within that host for suspicious activity.

A)host-based IDS

B)security intrusion

C)network-based IDS

D)intrusion detection

To view all questions and flashcards with answers, click on the resource link above. Page 10

Chapter 9: Firewalls and Intrusion Prevention Systems

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/79950

Sample Questions

Q1) _________ matching scans incoming packets for specific byte sequences (the signature)stored in a database of known attacks.

Q2) Snort Inline enables Snort to function as an intrusion prevention capability.

A)True

B)False

Q3) Unlike a firewall,an IPS does not block traffic.

A)True

B)False

Q4) The firewall can protect against attacks that bypass the firewall.

A)True

B)False

Q5) Distributed firewalls protect against internal attacks and provide protection tailored to specific machines and applications.

A)True

B)False

Q6) A DMZ is one of the internal firewalls protecting the bulk of the enterprise network.

A)True

B)False

To view all questions and flashcards with answers, click on the resource link above. Page 11

Chapter 10: Buffer Overflow

Available Study Resources on Quizplus for this Chatper

44 Verified Questions

44 Flashcards

Source URL: https://quizplus.com/quiz/79972

Sample Questions

Q1) The buffer overflow type of attack has been known since it was first widely used by the __________ Worm in 1988.

A)Code Red

B)Slammer

C)Morris Internet

D)Alpha One

Q2) _________ is a tool used to automatically identify potentially vulnerable programs.

A)Slamming

B)Sledding

C)Fuzzing

D)All of the above

Q3) A ___________ overflow occurs when the targeted buffer is located on the stack,usually as a local variable in a function's stack frame.

Q4) An essential component of many buffer overflow attacks is the transfer of execution to code supplied by the attacker and often saved in the buffer being overflowed.This code is known as _________ .

Q5) Shellcode has to be __________,which means it cannot contain any absolute address referring to itself.

To view all questions and flashcards with answers, click on the resource link above. Page 12

Chapter 11: Software Security

Available Study Resources on Quizplus for this Chatper

43 Verified Questions

43 Flashcards

Source URL: https://quizplus.com/quiz/79971

Sample Questions

Q1) To counter XSS attacks a defensive programmer needs to explicitly identify any assumptions as to the form of input and to verify that any input data conform to those assumptions before any use of the data.

A)True

B)False

Q2) Software security is closely related to software quality and reliability.

A)True

B)False

Q3) "Incorrect Calculation of Buffer Size" is in the __________ software error category.

A)Porous Defenses

B)Allocation of Resources

C)Risky Resource Management

D)Insecure Interaction Between Components

Q4) The correct implementation in the case of an atomic operation is to test separately for the presence of the lockfile and to not always attempt to create it.

A)True

B)False

Q5) Program input data may be broadly classified as textual or ______.

To view all questions and flashcards with answers, click on the resource link above. Page 13

Chapter 12: Operating System Security

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/79970

Sample Questions

Q1) Manual analysis of logs is a reliable means of detecting adverse events.

A)True

B)False

Q2) The most important changes needed to improve system security are to ______.

A)disable remotely accessible services that are not required

B)ensure that applications and services that are needed are appropriately configured

C)disable services and applications that are not required

D)all of the above

Q3) You should run automatic updates on change-controlled systems.

A)True

B)False

Q4) Unix and Linux systems grant access permissions for each resource using the ______ command.

Q5) ______ virtualization systems are typically seen in servers,with the goal of improving the execution efficiency of the hardware.

Q6) Backup and archive processes are often linked and managed together.

A)True

B)False

Page 14

To view all questions and flashcards with answers, click on the resource link above.

Chapter 13: Trusted Computing and Multilevel Security

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/79969

Sample Questions

Q1) "No read up" is also referred to as the _________ property.

Q2) A subject can exercise only accesses for which it has the necessary authorization and which satisfy the MAC rules.

A)True

B)False

Q3) When multiple categories or levels of data are defined,the requirement is referred to as __________ security.

Q4) _________ secure is a class of system that has system resources at more than one security level and that permits concurrent access by users who differ in security clearance and need-to-know,but is able to prevent each user from accessing resources for which the user lacks authorization.

Q5) _________ is assurance that a system deserves to be trusted such that the trust can be guaranteed in some convincing way such as through formal analysis or code review.

A)TCB

B)Trustworthiness

C)Trusted computing

D)TPM

Q6) An object is said to have a security ________ of a given level.

Page 15

To view all questions and flashcards with answers, click on the resource link above.

Chapter 14: It Security Management and Risk Assessment

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/79968

Sample Questions

Q1) The intent of the ________ is to provide a clear overview of how an organization's IT infrastructure supports its overall business objectives.

A)risk register

B)corporate security policy

C)vulnerability source

D)threat assessment

Q2) The _________ provides the most accurate evaluation of an organization's IT system's security risks.

Q3) IT security needs to be a key part of an organization's overall management plan.

A)True

B)False

Q4) The purpose of ________ is to determine the basic parameters within which the risk assessment will be conducted and then to identify the assets to be examined.

A)establishing the context

B)control

C)risk avoidance

D)combining

To view all questions and flashcards with answers, click on the resource link above.

Page 16

Chapter 15: It Security Controls,plans,and Procedures

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/79967

Sample Questions

Q1) Physical access or environmental controls are only relevant to areas housing the relevant equipment.

A)True

B)False

Q2) Controls may vary in size and complexity in relation to the organization employing them.

A)True

B)False

Q3) The implementation process is typically monitored by the organizational ______.

A)security officer

B)general counsel

C)technology officer

D)human resources

Q4) The _______ plan documents what needs to be done for each selected control,along with the personnel responsible,and the resources and time frame to be used.

Q5) The recommended controls need to be compatible with the organization's systems and policies.

A)True

B)False

Q6) Incident response is part of the ________ class of security controls.

To view all questions and flashcards with answers, click on the resource link above. Page 17

Chapter 16: Physical and Infrastructure Security

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/79966

Sample Questions

Q1) Misuse of the physical infrastructure includes vandalism,theft of equipment,theft by copying,theft of services,and unauthorized entry.

A)True

B)False

Q2) Tornados,tropical cyclones,earthquakes,blizzards,lightning,and floods are all types of ________ disasters.

Q3) A(n)________ is a battery backup unit that can maintain power to processors,monitors,and other equipment and can also function as a surge protector,power noise filter,and an automatic shutdown device.

Q4) The CHUID is a PIV card data object.

A)True

B)False

Q5) Physical access control should address not just computers and other IS equipment but also locations of wiring used to connect systems,equipment and distribution systems,telephone and communications lines,backup media,and documents.

A)True

B)False

Q6) _______ threats encompass threats related to electrical power and electromagnetic emission.

Page 18

To view all questions and flashcards with answers, click on the resource link above.

Chapter 17: Human Resources Security

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/79965

Sample Questions

Q1) Many companies incorporate specific e-mail and Internet use policies into the organization's security policy document.

A)True

B)False

Q2) The group of users,sites,networks,or organizations served by the CSIRT is a(n)_______.

Q3) CERT stands for ___________.

A)Computer Error Response Team

B)Compliance Error Repair Technology

C)Computer Emergency Response Team

D)Compliance Emergency Response Technology

Q4) Security basics and literacy is required for those employees,including contractor employees,who are involved in any way with IT systems.

A)True

B)False

Q5) ________ is explicitly required for all employees.

A)Security awareness

B)Education and experience

C)Security basics and literacy

D)Roles and responsibilities relative to IT systems

Page 19

To view all questions and flashcards with answers, click on the resource link above.

Chapter 18: Security Auditing

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/79964

Sample Questions

Q1) Monitoring areas suggested in ISO 27002 include: authorized access,all privileged operations,unauthorized access attempts,changes to (or attempts to change)system security settings and controls,and __________.

Q2) System conditions requiring immediate attention is a(n)_______ severity.

A)alert

B)err

C)notice

D)emert

Q3) With _________ the linking to shared library routines is deferred until load time so that if changes are made any program that references the library is unaffected.

A)statically linked shared libraries

B)dynamically linked shared libraries

C)system linked shared libraries

D)all of the above

Q4) The foundation of a security auditing facility is the initial capture of the audit data.

A)True

B)False

Q5) The audit _______ are a permanent store of security-related events on a system.

To view all questions and flashcards with answers, click on the resource link above. Page 20

Chapter 19: Legal and Ethical Aspects

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/79963

Sample Questions

Q1) Computer technology has involved the creation of new types of entities for which no agreed ethical rules have previously been formed.

A)True

B)False

Q2) Computer attacks are considered crimes but do not carry criminal sanctions.

A)True

B)False

Q3) ________ rights may be used to prevent others from using a confusingly similar mark,but not to prevent others from making the same goods or from selling the same goods or services under a clearly different mark.

Q4) The U.S.legal system distinguishes three primary types of property: real property,personal property,and _________ property.

Q5) The 2001 _________ is the first international treaty seeking to address Internet crimes by harmonizing national laws,improving investigative techniques,and increasing cooperation among nations.

Q6) Privacy is broken down into four major areas: anonymity,unlinkability,unobservability,and _________.

Q7) The three types of patents are: utility patents,design patents,and ________.

To view all questions and flashcards with answers, click on the resource link above. Page 21

Chapter 20: Symmetric Encryption and Message

Confidentiality

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/79961

Sample Questions

Q1) For general-purpose stream-oriented transmission you would typically use _______ mode.

A)CTR

B)CFB

C)ECB

D)CBC

Q2) A ________ is a key used between entities for the purpose of distributing session keys.

A)permanent key

B)session key

C)distribution key

D)all of the above

Q3) Public-key encryption was developed in the late ________.

A)1950s

B)1970s

C)1960s

D)1980s

Q4) An encryption scheme is _________ if the cost of breaking the cipher exceeds the value of the encrypted information and/or the time required to break the cipher exceeds the useful lifetime of the information.

To view all questions and flashcards with answers, click on the resource link above. Page 22

Chapter 21: Public-Key Cryptography and Message

Authentication

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/79960

Sample Questions

Q1) NIST has published FIPS PUB 186,which is known as the ___________.

Q2) __________ are alarming for two reasons: they come from a completely unexpected direction and they are a ciphertext-only attack.

Q3) The appeal of HMAC is that its designers have been able to prove an exact relationship between the strength of the embedded hash function and the strength of HMAC.

A)True

B)False

Q4) SHA-1 is considered to be very secure.

A)True

B)False

Q5) The evaluation criteria for the new hash function are: security,_______,and algorithm and implementation characteristics.

Q6) ______ has been issued as RFC 2014,has been chosen as the mandatory-to-implement MAC for IP Security,and is used in other Internet protocols,such as Transport Layer Security.

Q7) The purpose of the __________ algorithm is to enable two users to exchange a secret key securely that can then be used for subsequent encryption of messages.

To view all questions and flashcards with answers, click on the resource link above. Page 23

Chapter 22: Internet Security Protocols and Standards

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/79959

Sample Questions

Q1) The _________ is used to convey SSL-related alerts to the peer entity.

Q2) The ________ is housed in the user's computer and is referred to as a client e-mail program or a local network e-mail server.

Q3) A security association is uniquely identified by three parameters: security parameter index,protocol identifier,and ________________.

Q4) IPsec provides two main functions: a combined authentication/encryption function called ___________ and a key exchange function.

Q5) The default algorithms used for signing S/MIME messages are SHA-1 and the _________.

Q6) The ________ function consists of encrypted content of any type and encrypted-content encryption keys for one or more recipients.

A)clear-signed data

B)signed data

C)enveloped data

D)signed and enveloped data

Q7) The SSL record protocol provides two services for SSL connection: message integrity and _________.

To view all questions and flashcards with answers, click on the resource link above. Page 24

Chapter 23: Internet Authentication Applications

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/79958

Sample Questions

Q1) ________ is a process where authentication and permission will be passed on from one system to another,usually across multiple enterprises,reducing the number of authentications needed by the user.

A)Integration

B)Registration

C)Synchronization

D)Federation

Q2) _______ certificates are used in most network security applications,including IP security,secure sockets layer,secure electronic transactions,and S/MIME.

A)X.509

B)PKI

C)FIM

D)SCA

Q3) Kerberos is designed to counter only one specific threat to the security of a client/server dialogue.

A)True

B)False

Q4) ________ is a set of SOAP extensions for implementing message integrity and confidentiality in Web services.

To view all questions and flashcards with answers, click on the resource link above. Page 25

Chapter 24: Wireless Network Security

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/79957

Sample Questions

Q1) The transmission medium carries the radio waves for data transfer.

A)True

B)False

Q2) The purpose of the authentication phase is to maintain backward compatibility with the IEEE 802.11 state machine.

A)True

B)False

Q3) The 802.11i RSN security specification defines the following services: authentication,privacy with message integrity,and ________.

Q4) The wireless environment lends itself to a ______ attack because it is so easy for the attacker to direct multiple wireless messages at the target.

A)DoS

B)man-in-the-middle

C)network injection

D)identity theft

Q5) The security requirements are: confidentiality,integrity,availability,authenticity,and

Q6) At the top level of the group key hierarchy is the ___________.

Q7) The field following the MSDU field is referred to as the ___________.

To view all questions and flashcards with answers, click on the resource link above.

Turn static files into dynamic content formats.

Create a flipbook
Cybersecurity Fundamentals Exam Questions - 1076 Verified Questions by Quizplus - Issuu