Unit 12: Understanding The Need of Security Measures - Practice Quiz

DECAP145 60 Questions
0 Correct 0 Wrong 60 Left
0/60

1 What does the 'C' in the CIA triad of information security stand for?

Basic Security Concepts Easy
A. Compression
B. Connectivity
C. Compatibility
D. Confidentiality

2 Which term describes any potential danger that could exploit a weakness in a computer system?

Basic Security Concepts Easy
A. A threat
B. A cookie
C. A backup
D. A driver

3 What is a scam that tricks users into revealing personal information through fake emails or websites called?

Threats to Users Easy
A. Caching
B. Backing up
C. Formatting
D. Phishing

4 Stealing someone's personal details to pretend to be them online is known as:

Threats to Users Easy
A. Data backup
B. Identity theft
C. Defragmentation
D. Encryption

5 Which of the following is a common physical threat to computer hardware?

Threats to Hardware Easy
A. Spam email
B. Weak passwords
C. Power surges
D. Software bugs

6 Which device helps protect hardware from sudden power failures and voltage fluctuations?

Threats to Hardware Easy
A. Router
B. UPS (Uninterruptible Power Supply)
C. Scanner
D. Webcam

7 A malicious program that can replicate itself and spread to other files is called a:

Threat to Data Easy
A. Virus
B. Firewall
C. Cache
D. Cookie

8 Which type of malware locks or encrypts a user's data and demands payment to release it?

Threat to Data Easy
A. Middleware
B. Freeware
C. Ransomware
D. Firmware

9 Cyber terrorism mainly refers to the use of computers and the internet to:

Cyber Terrorism Easy
A. Cause disruption and spread fear for political goals
B. Speed up internet browsing
C. Design faster hardware
D. Improve data backups

10 Which of these is a likely target of a cyber terrorist attack?

Cyber Terrorism Easy
A. A cooking recipe blog
B. A personal photo album
C. A single game save file
D. Critical national infrastructure

11 Which software is designed to detect and remove malicious programs from a computer?

Taking Protective Measures: Keeping your System Safe Easy
A. Presentation software
B. Painting software
C. Spreadsheet software
D. Antivirus software

12 What is the main purpose of a firewall?

Taking Protective Measures: Keeping your System Safe Easy
A. To increase screen brightness
B. To compress large files
C. To clean the keyboard
D. To monitor and control network traffic

13 Which of the following is the strongest password?

Protecting Yourself Easy
A. abcdef
B. 123456
C. password
D. P@ssw0rd!2024

14 Adding a second step, like a code sent to your phone, when logging in is called:

Protecting Yourself Easy
A. Two-factor authentication
B. Disk formatting
C. File compression
D. Screen mirroring

15 Which practice best helps protect your privacy on social media?

Protecting your Privacy Easy
A. Accepting all friend requests
B. Sharing your home address publicly
C. Adjusting privacy settings to limit who sees your posts
D. Using the same password everywhere

16 What is a cookie in the context of web browsing?

Managing Cookies Easy
A. A small file storing information about your website visits
B. A backup device
C. A type of computer virus
D. A hardware component

17 How can a user manage or remove cookies stored on their computer?

Managing Cookies Easy
A. By updating the printer driver
B. By restarting the monitor
C. Through the browser settings
D. By changing the mouse

18 What does spyware primarily do?

Spyware and other BUGS Easy
A. Backs up important files
B. Speeds up the computer
C. Secretly collects information about a user's activity
D. Cools down the processor

19 Converting data into a coded form so only authorized people can read it is called:

Keeping your data secure Easy
A. Encryption
B. Formatting
C. Deletion
D. Printing

20 Why is it important to regularly back up your data?

Backing Up data Easy
A. To make the screen brighter
B. To reduce the keyboard size
C. To recover files if the original data is lost or damaged
D. To increase internet speed

21 A bank wants to ensure that only account holders can view their statements and that the data is not altered in transit. Which two components of the CIA triad are being addressed?

Basic Security Concepts Medium
A. Availability and Integrity
B. Authentication and Availability
C. Confidentiality and Availability
D. Confidentiality and Integrity

22 An employee receives an email that appears to be from the company's IT department asking them to confirm their login credentials via a link. This is an example of which threat to users?

Threats to Users Medium
A. Phishing
B. Spoofing hardware
C. Spamming
D. Snooping

23 A user notices their files have been renamed with a strange extension and a message demands payment to unlock them. Which type of malware is most likely responsible?

Threat to Data Medium
A. Ransomware
B. Keylogger
C. Rootkit
D. Adware

24 A company installs its servers in a room without temperature control. Over time the servers fail frequently. Which category of hardware threat does this represent?

Threats to Hardware Medium
A. Social engineering
B. Data interception
C. Environmental threat
D. Malware infection

25 A program secretly monitors which websites a user visits and sends this information to advertisers without consent. What is this program best classified as?

Spyware and other BUGS Medium
A. Cookie
B. Antivirus
C. Firewall
D. Spyware

26 A user wants websites to remember their login sessions but does not want tracking data to persist after closing the browser. Which approach best fits this need?

Managing Cookies Medium
A. Allow session cookies but block third-party cookies
B. Disable JavaScript in the browser
C. Block all cookies completely
D. Allow all cookies including third-party

27 An attacker disables a nation's power grid control systems to cause widespread panic and disruption. This act is best described as:

Cyber Terrorism Medium
A. Spamming
B. Software piracy
C. Identity theft
D. Cyber terrorism

28 A company performs a full backup on Sunday and only backs up files changed since that full backup each following day. Which backup type are the daily backups?

Backing Up data Medium
A. Full backup
B. Differential backup
C. Mirror backup
D. Incremental backup

29 A user encrypts a file with a strong algorithm before uploading it to cloud storage. What is the main security benefit of doing this?

Keeping your data secure Medium
A. The file uploads faster to the cloud
B. The file cannot be deleted by anyone
C. The file automatically backs itself up
D. Even if intercepted, the file cannot be read without the key

30 Which practice most effectively reduces the damage caused if one of your online passwords is leaked in a data breach?

Protecting Yourself Medium
A. Using a unique password for each account
B. Using the same strong password everywhere
C. Writing all passwords on a sticky note
D. Changing your username frequently

31 A firewall is configured on a home network. What is its primary function?

Taking Protective Measures: Keeping your System Safe Medium
A. Backing up data automatically to the cloud
B. Encrypting the hard drive contents
C. Filtering incoming and outgoing network traffic based on rules
D. Scanning files for known virus signatures

32 Before installing a free mobile flashlight app, a user notices it requests access to contacts, location, and microphone. What is the most privacy-conscious response?

Protecting your Privacy Medium
A. Share the app with friends to test it first
B. Grant all permissions to make the app work
C. Deny unnecessary permissions or avoid installing the app
D. Install it and disable the phone's antivirus

33 An attacker calls an employee pretending to be a senior manager and pressures them to reveal a system password urgently. This technique is known as:

Threats to Users Medium
A. Packet sniffing
B. Social engineering
C. SQL injection
D. Brute forcing

34 A frequent power outage in an area keeps shutting down office computers abruptly, risking data loss and hardware damage. Which device best addresses this problem?

Safeguarding your hardware Medium
A. Network switch
B. Uninterruptible Power Supply (UPS)
C. Antivirus software
D. External hard drive

35 A malicious program disguises itself as a useful game but secretly opens a backdoor for an attacker once installed. What is this type of malware called?

Threat to Data Medium
A. Cookie
B. Worm
C. Boot sector virus
D. Trojan horse

36 A photographer keeps the only copy of all client photos on a single laptop. Applying the 3-2-1 backup rule, what is the minimum change they should make?

Backing Up data Medium
A. Keep 3 copies on 2 media types with 1 offsite
B. Keep 1 copy on the laptop only
C. Keep 2 copies both on the same laptop
D. Keep 3 copies all in the same folder

37 A system requires a password and a one-time code sent to a phone before granting access. This security method is best described as:

Basic Security Concepts Medium
A. Single sign-on
B. Access logging
C. Two-factor authentication
D. Data encryption

38 Software vendors regularly release updates labelled as security patches. Why is applying them promptly important?

Taking Protective Measures: Keeping your System Safe Medium
A. They increase the storage capacity of the device
B. They always add new visual themes to the software
C. They permanently stop all future malware
D. They fix known vulnerabilities attackers could exploit

39 A user's browser suddenly shows constant pop-up advertisements and a changed homepage they did not set. Which type of unwanted software is the most likely cause?

Spyware and other BUGS Medium
A. Backup agent
B. Digital certificate
C. Firewall
D. Adware

40 A user connects to free public Wi-Fi at a café and wants to keep their browsing private from others on the same network. Which tool is most appropriate?

Protecting your Privacy Medium
A. A disk defragmenter
B. A file compression tool
C. A cookie cleaner
D. A Virtual Private Network (VPN)

41 An organization implements a control that ensures a message received is identical to the message sent and has not been altered in transit. When an auditor asks which pillar of the CIA triad this specifically enforces, which answer is correct?

Basic Security Concepts Hard
A. Authentication
B. Integrity
C. Confidentiality
D. Availability

42 A security team wants a user to be unable to later deny having performed a digital transaction. Which security property must the implemented control provide?

Basic Security Concepts Hard
A. Confidentiality
B. Non-repudiation
C. Redundancy
D. Availability

43 A user receives an email that appears to be from their bank, urging them to click a link and 'verify' their credentials on a page that looks legitimate. The attack combines deception with a fake site. Which classification is most precise?

Threats to Users Hard
A. Spoofing only
B. Keylogging
C. Phishing
D. Denial-of-service

44 An attacker researches a specific executive's habits and sends a personalized message referencing a real meeting to steal login data. This targeted variant is best described as:

Threats to Users Hard
A. Pharming
B. Bulk phishing
C. Smishing
D. Spear phishing

45 A data center in a region prone to voltage fluctuations experiences repeated silent corruption of running servers without total shutdown. Which protective device most directly addresses the root cause while power remains present?

Threats to Hardware Hard
A. Anti-static wrist strap
B. Voltage regulator (line conditioner)
C. Biometric door lock
D. Fireproof safe

46 A technician handling internal components without an anti-static wrist strap risks damaging chips even when no visible spark occurs. The underlying threat is:

Threats to Hardware Hard
A. Electrostatic discharge (ESD)
B. Electromagnetic pulse from software
C. Overclocking
D. Voltage brownout

47 A company keeps its only backup on an external drive stored next to the server in the same room. Analysts flag this as a weakness. Which threat scenario does this arrangement fail to protect against?

Threat to Data Hard
A. An outdated antivirus signature
B. A weak password on user accounts
C. A phishing email to staff
D. A localized fire or flood destroying both copies

48 Ransomware encrypts a firm's files and demands payment. The firm has recent, tested, offline backups. What is the most defensible recovery decision?

Threat to Data Hard
A. Disable antivirus to speed recovery
B. Restore from the offline backups and do not pay
C. Reinstall the OS but keep encrypted files
D. Pay the ransom immediately to save time

49 An attack disables a nation's power-grid control systems to cause widespread civilian disruption for a political motive. Which term most accurately classifies this act?

Cyber Terrorism Hard
A. Spamming
B. Cyber terrorism
C. Ordinary hacking for profit
D. Social engineering

50 Which factor most distinguishes cyber terrorism from a typical financially-motivated cybercrime?

Cyber Terrorism Hard
A. The size of the ransom demanded
B. The use of a computer to commit the act
C. The intent to intimidate or coerce for political/ideological goals
D. The presence of a firewall on the target

51 A firewall is configured to inspect and control incoming and outgoing traffic. A user assumes it will also detect and remove viruses already on the disk. Why is this assumption flawed?

Taking Protective Measures: Keeping your System Safe Hard
A. A firewall filters network traffic, not files already stored on the disk
B. A firewall replaces the need for passwords
C. A firewall only works on wireless connections
D. A firewall encrypts the hard drive automatically

52 Security patches are released for a known vulnerability, yet an administrator delays applying them for months. What is the primary risk of this delay?

Taking Protective Measures: Keeping your System Safe Hard
A. The firewall will disable itself
B. Backups will automatically fail
C. The system will run faster without patches
D. Attackers can exploit the publicly known, unpatched vulnerability

53 Comparing password strength, which of the following is hardest to crack by brute force, assuming an attacker knows the length?

Protecting Yourself Hard
A. A 6-digit numeric PIN
B. The user's name followed by birth year
C. A 16-character passphrase mixing unrelated words, digits, and symbols
D. An 8-character dictionary word

54 A service offers 'two-factor authentication (2FA).' Which combination genuinely satisfies the definition of two factors?

Protecting Yourself Hard
A. A password entered twice
B. Two different passwords
C. A password plus a one-time code from a phone app
D. A username and a password

55 A user wants to reduce their trackable online footprint. Which action provides the least actual privacy benefit despite seeming protective?

Protecting your Privacy Hard
A. Reviewing app permissions regularly
B. Relying solely on 'private/incognite browsing' to hide activity from ISPs and sites
C. Limiting personal data shared on social profiles
D. Using a reputable VPN on untrusted networks

56 A shopping site keeps a user logged in across sessions and remembers their cart days later. Which cookie type is responsible, and why does deleting only session cookies fail to remove it?

Managing Cookies Hard
A. A session cookie, because it is deleted on browser close
B. A zombie cookie, because it cannot be deleted
C. A secure cookie, because it is encrypted
D. A persistent cookie, because it stores data with an expiry date beyond the session

57 A privacy analyst distinguishes first-party from third-party cookies. Why are third-party cookies of greater tracking concern?

Managing Cookies Hard
A. They are set by domains other than the visited site, enabling cross-site tracking
B. They always contain the user's password
C. They cannot be blocked by any browser setting
D. They are stored only in RAM and never on disk

58 A machine shows unexplained network traffic, sends contact lists externally, and installs a hidden program that records keystrokes. Which classification best fits software that secretly gathers and transmits user information?

Spyware and other BUGS Hard
A. A defragmenter
B. Spyware
C. A disk cleanup utility
D. A firewall log

59 A laptop is stolen but the entire disk was protected with full-disk encryption using a strong passphrase. What is the primary reason the confidential data remains protected?

Keeping your data secure Hard
A. Encryption automatically alerts the police
B. Without the key/passphrase, the encrypted data is unreadable ciphertext
C. The thief cannot physically remove the drive
D. The operating system password alone blocks all access

60 An admin applies the 3-2-1 backup rule. Which arrangement correctly satisfies it?

Backing Up data Hard
A. 3 backups on the same drive, made 2 times daily, kept for 1 year
B. 3 users, 2 servers, 1 network
C. 3 passwords, 2 firewalls, 1 antivirus
D. 3 copies of data, on 2 different media types, with 1 copy stored off-site