Skip to main content

Cybersecurity Fundamentals Final Exam - 1136 Verified Questions

Page 1


Cybersecurity Fundamentals

Final Exam

Course Introduction

Cybersecurity Fundamentals introduces students to the essential concepts and principles of protecting computer systems, networks, and data from digital threats. This course covers the basics of information security, including risk management, threat landscapes, cryptography, network security, security protocols, and ethical considerations. Students will explore common types of cyber attacks, security controls, and best practices for safeguarding personal and organizational information. Through real-world case studies and hands-on activities, learners gain a foundational understanding of how to identify vulnerabilities, respond to incidents, and develop strategies for effective cybersecurity in today's interconnected world.

Recommended Textbook Principles of Computer Security CompTIA Security+ and Beyond 3rd Edition by Wm. Arthur Conklin

Available Study Resources on Quizplus

25 Chapters

1136 Verified Questions

1136 Flashcards

Source URL: https://quizplus.com/study-set/2933 Page 2

Chapter 1: Introduction and Security Trends

Available Study Resources on Quizplus for this Chatper

49 Verified Questions

49 Flashcards

Source URL: https://quizplus.com/quiz/58443

Sample Questions

Q1) Why is the Morris worm significant?

A)It placed embarrassing text on people's screens.

B)This was the first large-scale attack on the Internet.

C)It was the very first virus on the Internet.

D)It attacked the Windows operating system.

Answer: B

Q2) In 2009 _______________ was cut and resulted in widespread phone and Internet outages in the San Jose area of California.

Answer: fiber cable

Q3) Explain the steps in minimizing possible avenues of attack.

Answer: Answer might include the following information: First,the administrator will ensure that all patches for the operating system and applications are installed.Next,they will harden the system by shutting down as many of the services as possible.Lastly,try to minimize the amount of information made available to the public as much as possible.

Q4) Hackers who are able to discover new vulnerabilities and write code to exploit them are known as _______________.

Answer: elite hackers

To view all questions and flashcards with answers, click on the resource link above.

Page 3

Chapter 2: General Security Concepts

Available Study Resources on Quizplus for this Chatper

65 Verified Questions

65 Flashcards

Source URL: https://quizplus.com/quiz/58442

Sample Questions

Q1) Requiring one employee to place an order and another employee to authorize the sale is an example of which principle?

A)Least privilege

B)Separation of duties

C)Implicit deny

D)Keep it simple

Answer: B

Q2) A person who tries to gradually obtain information necessary to compromise a network-by first appealing for help,and then,if necessary,by a more aggressive approach-is a(n)__________.

A)phreaker

B)social engineer

C)hacktivist

D)terrorist

Answer: B

Q3) Gathering seemingly unimportant information and then combining it to discover potentially sensitive information is known as _______________.

Answer: data aggregation

To view all questions and flashcards with answers, click on the resource link above.

4

Chapter 3: Operational-Organizational Security

Available Study Resources on Quizplus for this Chatper

43 Verified Questions

43 Flashcards

Source URL: https://quizplus.com/quiz/58441

Sample Questions

Q1) The outermost layer of physical security should

A)Be where the most specific controls are

B)Have the strongest authentication controls

C)Contain the most private activities

D)Contain the most publicly visible activities

Answer: D

Q2) A fire suppression system that is safe for equipment,but dangerous for humans is A)Halon

B)Sprinkler-based systems

C)Class A fire extinguisher

D)Water-based systems.

Answer: A

Q3) Open spaces can serve as a barrier to protect a facility. It is difficult to cross open spaces without being detected.

A)True

B)False

Answer: True

Q4) _______________ are devices that have batteries that are used to keep equipment running in the event of a power outage.

Answer: UPS

Page 5

To view all questions and flashcards with answers, click on the resource link above.

Chapter 4: The Role of People in Security

Available Study Resources on Quizplus for this Chatper

40 Verified Questions

40 Flashcards

Source URL: https://quizplus.com/quiz/58440

Sample Questions

Q1) A person parks his car by an ATM,sets up a small camera discreetly pointed at ATM keypad,and then pretends to be going through bank papers in his car.This would be an example of

A)Piggybacking

B)Shoulder surfing

C)Phishing

D)Social engineering

Q2) Phishing is the most common form of social engineering attack related to computer security.

A)True

B)False

Q3) Spear phishing is when an attacker attempts to redirect a user to a bogus web site that appears similar to the web site the user had intended to access.

A)True

B)False

Q4) _______________ is when an e-mail trying to get sensitive information is sent to a group that has something in common,making the attack seem more personal.

Q5) Give an example of a hoax and how it might actually be destructive.

To view all questions and flashcards with answers, click on the resource link above. Page 6

Chapter 5: Cryptography

Available Study Resources on Quizplus for this Chatper

49 Verified Questions

49 Flashcards

Source URL: https://quizplus.com/quiz/58439

Sample Questions

Q1) The process for protecting intellectual property from unauthorized use is called

Q2) Hashing functions are special mathematical functions that performs a two-way encryption.

A)True

B)False

Q3) An attacker is able to decrypt a message by finding a key that was not securely stored and should have been revoked.The is the result of

A)Poor key management

B)A weak key

C)A weak algorithm

D)A small keyspace

Q4) Alice sends Bob a message along with an MD5 hash of the message.Upon receipt,Bob runs the MD5 hashing algorithm and finds that the hash matches the one sent by Alice.This application of encryption is an example of

A)Authentication

B)Nonrepudiation

C)Integrity

D)Confidentiality

To view all questions and flashcards with answers, click on the resource link above. Page 7

Chapter 6: Public Key Infrastructure

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/58438

Sample Questions

Q1) _______________ is the process of giving the keys to a third party so that they can decrypt and read sensitive information if the need arises.

Q2) When a person loses a laptop that had a private key stored on it,that person should request a revocation of the related certificate.

A)True

B)False

Q3) What is a public key infrastructure?

A)A structure that enables parties to use communications such as e-mail

B)A structure that provides all of the components needed for entities to communicate securely and in a predictable manner

C)A structure that enables secure communications in chat rooms,and when instant messaging and text messaging

D)Is another name for digital signatures

Q4) A digital certificate binds an individual's identity to a public key.

A)True B)False

Q5) _______________ binds a public key to a known user through a trusted intermediary,typically a certificate authority.

To view all questions and flashcards with answers, click on the resource link above. Page 8

Chapter 7: Standards and Protocols

Available Study Resources on Quizplus for this Chatper

44 Verified Questions

44 Flashcards

Source URL: https://quizplus.com/quiz/58437

Sample Questions

Q1) SSL provides secure connections for web transfers using encryption.

A)True

B)False

Q2) Briefly describe a public key infrastructure (PKI).

Q3) PKI stands for private key infrastructure.

A)True

B)False

Q4) The X.905 standard specifies formats for public key certificates.

A)True

B)False

Q5) IPsec is short for the "second" version of IP.

A)True

B)False

Q6) WEP has all of the following weaknesses of EXCEPT:

A)The secret key is only 40 bits long.

B)It is susceptible to collision attacks.

C)Even the 128 bit version is vulnerable.

D)Many wireless implementations do not come with WEP enabled.

Q7) WEP is sometimes used to secure a wireless connection.What are the security issues related to WEP?

To view all questions and flashcards with answers, click on the resource link above. Page 9

Chapter 8: Physical Security

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/58436

Sample Questions

Q1) Which of these,according to this chapter,is not a step that can be taken to help mitigate physical security risk?

A)All users need security training.

B)Electronic physical security systems need to be protected from network-based attacks.

C)Authentication systems should use multiple factors when feasible.

D)Constant monitoring of all employees by camera.

Q2) A newer portable media that provides new obstacles is a(n)

A)Access token

B)USB drive

C)CD-ROM

D)CCTV

Q3) The _______________ is the weakest link in the security chain.

Q4) The following are examples of clean-agent fire suppression systems EXCEPT:

A)Carbon dioxide

B)Argon

C)Halon

D)Inergen

Q5) What are the types of fire,and their suppression methods?

Q6) What is multiple-factor authentication?

To view all questions and flashcards with answers, click on the resource link above. Page 10

Chapter 9: Network Fundamentals

Available Study Resources on Quizplus for this Chatper

55 Verified Questions

55 Flashcards

Source URL: https://quizplus.com/quiz/58435

Sample Questions

Q1) Packet delivery to distant systems is usually accomplished by the use of

A)MAC addresses

B)Domain names

C)IP Addresses

D)ARP protocol

Q2) Remote Packet Delivery (where packets are delivered to a remote location)uses _________ addresses to send packets.

Q3) Network Address Translation (NAT)

A)Translates private (non-routable)IP addresses into public (routable)IP addresses

B)Translates the IP addresses of one protocol to the IP address of another protocol

C)Is one of the items in an IP packet header

D)Translates MAC addresses to IP addresses

Q4) What is a DMZ and what is it used for?

Q5) What is NAT and what is it used for?

Q6) NAT translates private (nonroutable)IP addresses into public (routable)IP addresses.

A)True

B)False

To view all questions and flashcards with answers, click on the resource link above.

Page 11

Chapter 10: Infrastructure Security

Available Study Resources on Quizplus for this Chatper

42 Verified Questions

42 Flashcards

Source URL: https://quizplus.com/quiz/58434

Sample Questions

Q1) ________ are applications designed to detect,log,and respond to unauthorized

A.network or host use,both in real time and after the fact

A)Windows Operating System

B)Intrusion detection systems (IDS)

C)Firewalls

D)Twisted wire pairs

Q2) A bridge works on layer 3 of the OSI model.

A)True

B)False

Q3) The most common implementation of VPN is via IPsec

A)True

B)False

Q4) What are the four common methods for connecting equipment at the physical layer?

Q5) _______ are characterized by the use of a laser to read data stored on a physical device.

A)Authentication rules

B)FTP sites

C)Modems

D)Optical media

Q6) What are the different types of removable media?

To view all questions and flashcards with answers, click on the resource link above. Page 12

Chapter 11: Authentication and Remote Access

Available Study Resources on Quizplus for this Chatper

46 Verified Questions

46 Flashcards

Source URL: https://quizplus.com/quiz/58433

Sample Questions

Q1) TACACS+ uses

A)UDP port 49 and TCP port 50 for login

B)UDP port 49 and TCP port 49 for login

C)UDP port 49 and UDP port 50 for login

D)TCP port 49 and UDP port 50 for login

Q2) Which type of access control would be used to grant permissions based on the duties that must be performed?

A)Mandatory access control

B)Discretionary access control

C)Role-based access control

D)Rule-based access control

Q3) Which protocol enables the secure transfer of data from a remote PC to a server by creating a VPN across a TCP/IP network?

A)PPPP

B)PPTP

C)PTPN

D)PPTN

Q4) The two protocols used in IPSec to provide traffic security are _________ and

Q5) What are the three steps of establishing proper privileges?

To view all questions and flashcards with answers, click on the resource link above. Page 13

Chapter 12: Wireless

Available Study Resources on Quizplus for this Chatper

43 Verified Questions

43 Flashcards

Source URL: https://quizplus.com/quiz/58432

Sample Questions

Q1) _______________ is a modulation type that spreads the traffic sent over the entire bandwidth.

Q2) Why is wireless problematic from a security standpoint?

A)There is no control over physical limitations.

B)Insufficient signal strength

C)There is no control over the physical layer of traffic.

D)There is no control over the network.

Q3) The cryptographic standard for proposed for 3G networks is A)EVDO

B)MISTY1

C)HSPA

D)KASUMI

Q4) WEP provides strong protection for confidentiality.

A)True

B)False

Q5) Alert messages in Wireless Transport Layer Security (WTLS)are sometimes sent in plaintext and are not authenticated.

A)True

B)False

Q6) Describe the different wireless systems in use today.

Page 14

To view all questions and flashcards with answers, click on the resource link above.

Chapter 13: Intrusion Detection Systems and Network Security

Available Study Resources on Quizplus for this Chatper

49 Verified Questions

49 Flashcards

Source URL: https://quizplus.com/quiz/58431

Sample Questions

Q1) Antivirus products do all of the following EXCEPT:

A)Automated updates

B)Media scanning

C)Block network traffic based on policies

D)Scan e-mail for malicious code and attachments

Q2) Your boss is concerned about employees viewing in appropriate or illegal web sites in the workplace.Which device would be the best at addressing this concern?

A)Antivirus

B)Firewall

C)Protocol analyzer

D)Internet content filter

Q3) _______________ detection looks for things that are out of the ordinary,such as a user logging in when he's not supposed to,or unusually high network traffic into and out of a workstation.

Q4) Content-based signatures detect character patterns and TCP flag settings.

A)True

B)False

Q5) A(n)_______________ is also known as a packet sniffer and network sniffer.

Q6) List three approaches that antispam software uses to filter out junk e-mail.

To view all questions and flashcards with answers, click on the resource link above. Page 15

Chapter 14: Baselines

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/58430

Sample Questions

Q1) _______________ is a term usually applied to a formal,large software update,which may address several software problems.

Q2) Which of the following is the command to stop a service in UNIX?

A)Stop

B)Kill

C)End

D)Finish

Q3) Mac OS X FileVault encrypts files with 3DES encryption.

A)True

B)False

Q4) Securing an application against local-and internet-based attacks is called

Q5) On a UNIX system,if a file has the permission r-x rw- ---,what permission does the world have?

A)Read and execute

B)Read and write

C)Read,write,execute

D)No permissions

Q6) List four of the new modifications and capabilities of Windows 2003 Server.

Q7) List three of the new capabilities of Windows Server 2008.

To view all questions and flashcards with answers, click on the resource link above. Page 16

Chapter 15: Types of Attacks and Malicious Software

Available Study Resources on Quizplus for this Chatper

50 Verified Questions

50 Flashcards

Source URL: https://quizplus.com/quiz/58429

Sample Questions

Q1) A(n)_______________ attack is an attack designed to prevent a system or service from functioning normally.

Q2) Malicious code that sits dormant until a particular event occurs to release its payload is called what?

A)Trojan

B)Logic bomb

C)Trigger virus

D)Logic worm

Q3) _______________ is the use of fraudulent e-mails or instant messages that appear to be genuine but are designed to trick users.

Q4) Johnny received a "new version" of the game Solitaire in an e-mail.After running the program,a backdoor was installed on his computer without his knowledge.What kind of an attack is this?

A)Logic bomb

B)Hoax

C)Trojan

D)Worm

Q5) List and describe various types of malware.

Q6) Describe some of the types of attacks that can be launched against a network.

17

To view all questions and flashcards with answers, click on the resource link above.

Chapter 16: E-Mail and Instant Messaging

Available Study Resources on Quizplus for this Chatper

47 Verified Questions

47 Flashcards

Source URL: https://quizplus.com/quiz/58428

Sample Questions

Q1) The trends show that e-mail hoaxes are being thwarted due to new technology.

A)True

B)False

Q2) _______________ refers to an unsolicited commercial e-mail whose purpose is the same as the junk mails in a physical mailbox;it tries to persuade the recipient buy something.

Q3) Malicious code that is scripted to send itself to other users is known as a ________.

A)virus

B)worm

C)Trojan

D)logic bomb

Q4) Briefly give two examples of how hoax e-mails work.

Q5) Securing e-mail is something that must be done by

A)Networking administrators

B)Security administrators

C)Outlook express

D)Users

Q6) Explain some of the problems with PGP.

Q7) What is a basic description of a Trojan horse?

To view all questions and flashcards with answers, click on the resource link above. Page 18

Chapter 17: Web Components

Available Study Resources on Quizplus for this Chatper

45 Verified Questions

45 Flashcards

Source URL: https://quizplus.com/quiz/58427

Sample Questions

Q1) The SFTP protocol incorporates what into FTP?

A)SSL

B)Secure java scripting

C)28 bit encryption key

D)the TCP protocol

Q2) _______________ is using an embedded control from another site with or without the other site's permission.

Q3) What are some of the security issues associated with web applications and plug-ins?

Q4) Which of the following do not enhance the security of the browser?

A)Browser plug-ins

B)Patches

C)Disabling javascript

D)Rejecting cookies

Q5) HTTPS uses TCP port

A)433

B)443

C)344

D)434

Q6) What are some security issues related to web-based applications?

To view all questions and flashcards with answers, click on the resource link above. Page 19

Chapter 18: Secure Software Development

Available Study Resources on Quizplus for this Chatper

40 Verified Questions

40 Flashcards

Source URL: https://quizplus.com/quiz/58426

Sample Questions

Q1) Errors found after development is complete are expensive.

A)True

B)False

Q2) What is the waterfall model characterized by?

A)A generic,repeatable process for debugging software

B)A protocol limiting liquids in the workplace

C)A linear,multistep process

D)A process for ensuring that all inputs are tested

Q3) Which is related to a code injection error?

A)VB.NET

B)SQL

C)JavaScript

D)C#

Q4) Canonicalization vulnerabilities are restricted to Windows systems.

A)True

B)False

Q5) When the function of code is changed in an unintended way,it is an example of code injection.

A)True

B)False

Page 20

To view all questions and flashcards with answers, click on the resource link above.

Chapter 19: Disaster Recovery, Business Continuity, and Organizational Policies

Available Study Resources on Quizplus for this Chatper

53 Verified Questions

53 Flashcards

Source URL: https://quizplus.com/quiz/58425

Sample Questions

Q1) What are the various ways a backup can be conducted and stored?

Q2) List the four ways backups are conducted and stored

Q3) Which document's main focus is the continued operation of the organization?

A)BIA

B)DRP

C)AUP

D)BCP

Q4) Which document defines the required data,resources,and steps to restore critical organizational processes?

A)BIA

B)BCP

C)DRP

D)AUP

Q5) Incremental backups back up all information since the last full backup.

A)True

B)False

Q6) _______________ increases reliability through the use of redundant hard drives.

21

Q7) _______________ is a term that refers to a type of business function that is nice to have,but does not affect the operation of the organization.

To view all questions and flashcards with answers, click on the resource link above.

Chapter 20: Risk Management

Available Study Resources on Quizplus for this Chatper

42 Verified Questions

42 Flashcards

Source URL: https://quizplus.com/quiz/58424

Sample Questions

Q1) Residual risk is covered by insurance companies.

A)True

B)False

Q2) The term _______________ refers to taking action to reduce the likelihood of a threat occurring.

Q3) Which of the following is the value for the expected loss of a single asset?

A)SLE

B)ALE

C)SRO

D)ARO

Q4) A(n)_______________ is any resource or information an organization needs to conduct its business.

Q5) Cause and effect analysis is the process of identifying relationships between a risk and the organization's needs.

A)True

B)False

Q6) _______________ is the overall decision-making process of identifying threats and vulnerabilities and their potential impacts,determining the costs to mitigate such events,and deciding what actions are cost effective for controlling these risks.

Page 22

To view all questions and flashcards with answers, click on the resource link above.

Chapter 21: Change Management

Available Study Resources on Quizplus for this Chatper

35 Verified Questions

35 Flashcards

Source URL: https://quizplus.com/quiz/58423

Sample Questions

Q1) What is the key concept in change management?

A)Least privilege

B)Separation of duties

C)Defense in depth

D)Redundancy

Q2) What is configuration auditing?

A)Ensures that configuration items are built and maintained according to the requirements,standards,or contractual agreements

B)Ensures that only approved changes to a baseline can be implemented

C)Ensures all changes made separate from the baseline are well documented and controlled

D)Identifies which assets need to be controlled

Q3) _____________ is the process of identifying which assets need to be managed and controlled.

Q4) All access to systems,software,and data should be assigned using what principle?

A)Least privilege

B)Role-based access

C)Minimum use

D)Activity-based access

Q5) What is the importance of a baseline to change management?

To view all questions and flashcards with answers, click on the resource link above. Page 23

Chapter 22: Privilege Management

Available Study Resources on Quizplus for this Chatper

39 Verified Questions

39 Flashcards

Source URL: https://quizplus.com/quiz/58422

Sample Questions

Q1) Management password policy should address all of the following except?

A)Password reuse

B)Password complexity rules

C)Protection of passwords

D)Password salting to ensure unique hash values

Q2) Groups are used to

A)Create a collection of users to simplify privilege management

B)Circumvent an overly restrictive ACL ruleset

C)Create a collection of programs simplifying ACL implementation

D)Separate computers into logical groups that perform similar functions

Q3) Which of the following is NOT an advantage of decentralized privilege management?

A)It is highly flexible;changes can be made whenever they are needed.

B)It does not require a dedicated set of personnel and resources.

C)It reduces bureaucracy.

D)Fewer people must be trained on tasks associated with privilege management.

Q4) Minimum password age policy specifies the number of days a password may be used before it must be changed.

A)True

B)False

24

To view all questions and flashcards with answers, click on the resource link above.

Chapter 23: Computer Forensics

Available Study Resources on Quizplus for this Chatper

40 Verified Questions

40 Flashcards

Source URL: https://quizplus.com/quiz/58421

Sample Questions

Q1) The cluster that holds the fragment of the original file is referred to as _______________,because the operating system has marked it as usable when needed.

Q2) Evidence that is convincing or measures up without question is what standard of evidence?

A)Sufficient evidence

B)Competent evidence

C)Relevant evidence

D)Real evidence

Q3) To be credible in court proceedings,what are the three standards that evidence must meet?

Q4) The _______________ refers to second-hand evidence.

Q5) The space that is left over in a cluster is called slack space.

A)True

B)False

Q6) What is the space in a cluster that is not occupied by a file called?

A)Free space

B)Slack space

C)Open space

D)Unused space

Page 25

To view all questions and flashcards with answers, click on the resource link above.

Chapter 24: Legal Issues and Ethics

Available Study Resources on Quizplus for this Chatper

40 Verified Questions

40 Flashcards

Source URL: https://quizplus.com/quiz/58420

Sample Questions

Q1) Which of the following is a characteristic of the Patriot Act?

A)Extends the tap-and-trace provisions of existing wiretap statutes to the Internet,and mandates certain technological modifications at ISPs to facilitate electronic wiretaps on the Internet

B)A major piece of legislation affecting the financial industry,and also one with significant privacy provisions for individuals

C)Makes it a violation of federal law to knowingly use another's identity

D)Implements the principle that a signature,contract,or other record may not be deleted

E)Denies legal effect,validity,or enforceability solely because it is electronic form

Q2) The CAN-SPAM Act allows unsolicited e-mail as long as there is an unsubscribe link;the content must not be deceptive and not harvest emails.

A)True

B)False

Q3) What are the laws and regulations regarding the import and export of encryption software?

Q4) What are some ethical issues associated with information security?

Q5) What are the laws that govern computer access and trespass?

To view all questions and flashcards with answers, click on the resource link above.

Page 26

Chapter 25: Privacy

Available Study Resources on Quizplus for this Chatper

40 Verified Questions

40 Flashcards

Source URL: https://quizplus.com/quiz/58419

Sample Questions

Q1) Define privacy.

Q2) What are the privacy laws as they relate to computer security in various industries?

Q3) _______________ refers to the positive affirmation by a customer that she read the notice,understands her choices,and agrees to release her personal information for the purposes explained to her.

Q4) The three things that should govern how good citizenry collects PII are notice,choice,and consent.

A)True

B)False

Q5) In the United States the primary path to privacy is _______.In Europe the primary path to privacy is _________.

A)opt-in;opt-in

B)opt-in;opt-out

C)opt-out;opt-out

D)opt-out;opt-in

Q6) Privacy laws as they relate to education are very recent phenomena.

A)True

B)False

To view all questions and flashcards with answers, click on the resource link above. Page 27

Turn static files into dynamic content formats.

Create a flipbook