1What does the 'C' in the CIA triad of information security stand for?
Basic Security Concepts
Easy
A.Compression
B.Connectivity
C.Compatibility
D.Confidentiality
Correct Answer: Confidentiality
Explanation:
The CIA triad stands for Confidentiality, Integrity, and Availability, the three core goals of information security.
Incorrect! Try again.
2Which term describes any potential danger that could exploit a weakness in a computer system?
Basic Security Concepts
Easy
A.A threat
B.A cookie
C.A backup
D.A driver
Correct Answer: A threat
Explanation:
A threat is any possible danger that might exploit a vulnerability to breach security and cause harm.
Incorrect! Try again.
3What is a scam that tricks users into revealing personal information through fake emails or websites called?
Threats to Users
Easy
A.Caching
B.Backing up
C.Formatting
D.Phishing
Correct Answer: Phishing
Explanation:
Phishing uses fake emails or websites that look genuine to trick users into giving away passwords or bank details.
Incorrect! Try again.
4Stealing someone's personal details to pretend to be them online is known as:
Threats to Users
Easy
A.Data backup
B.Identity theft
C.Defragmentation
D.Encryption
Correct Answer: Identity theft
Explanation:
Identity theft is when a criminal uses another person's personal information to impersonate them, often for fraud.
Incorrect! Try again.
5Which of the following is a common physical threat to computer hardware?
Threats to Hardware
Easy
A.Spam email
B.Weak passwords
C.Power surges
D.Software bugs
Correct Answer: Power surges
Explanation:
Power surges are sudden spikes in electrical voltage that can physically damage hardware components.
Incorrect! Try again.
6Which device helps protect hardware from sudden power failures and voltage fluctuations?
Threats to Hardware
Easy
A.Router
B.UPS (Uninterruptible Power Supply)
C.Scanner
D.Webcam
Correct Answer: UPS (Uninterruptible Power Supply)
Explanation:
A UPS provides backup power and protects equipment from surges and outages, preventing sudden shutdowns and damage.
Incorrect! Try again.
7A malicious program that can replicate itself and spread to other files is called a:
Threat to Data
Easy
A.Virus
B.Firewall
C.Cache
D.Cookie
Correct Answer: Virus
Explanation:
A computer virus is malware that attaches to files and replicates, spreading to other files and systems.
Incorrect! Try again.
8Which type of malware locks or encrypts a user's data and demands payment to release it?
Threat to Data
Easy
A.Middleware
B.Freeware
C.Ransomware
D.Firmware
Correct Answer: Ransomware
Explanation:
Ransomware blocks access to data, usually by encryption, and demands a ransom payment for its release.
Incorrect! Try again.
9Cyber terrorism mainly refers to the use of computers and the internet to:
Cyber Terrorism
Easy
A.Cause disruption and spread fear for political goals
B.Speed up internet browsing
C.Design faster hardware
D.Improve data backups
Correct Answer: Cause disruption and spread fear for political goals
Explanation:
Cyber terrorism uses digital attacks to disrupt systems and create fear, often for political or ideological aims.
Incorrect! Try again.
10Which of these is a likely target of a cyber terrorist attack?
Cyber Terrorism
Easy
A.A cooking recipe blog
B.A personal photo album
C.A single game save file
D.Critical national infrastructure
Correct Answer: Critical national infrastructure
Explanation:
Cyber terrorists often target critical systems like power grids and banking to cause maximum disruption.
Incorrect! Try again.
11Which software is designed to detect and remove malicious programs from a computer?
Taking Protective Measures: Keeping your System Safe
Easy
A.Presentation software
B.Painting software
C.Spreadsheet software
D.Antivirus software
Correct Answer: Antivirus software
Explanation:
Antivirus software scans for, detects, and removes viruses and other malware to keep a system safe.
Incorrect! Try again.
12What is the main purpose of a firewall?
Taking Protective Measures: Keeping your System Safe
Easy
A.To increase screen brightness
B.To compress large files
C.To clean the keyboard
D.To monitor and control network traffic
Correct Answer: To monitor and control network traffic
Explanation:
A firewall filters incoming and outgoing network traffic, blocking unauthorized access to a system.
Incorrect! Try again.
13Which of the following is the strongest password?
Protecting Yourself
Easy
A.abcdef
B.123456
C.password
D.P@ssw0rd!2024
Correct Answer: P@ssw0rd!2024
Explanation:
A strong password mixes uppercase, lowercase, numbers, and symbols, making it harder to guess or crack.
Incorrect! Try again.
14Adding a second step, like a code sent to your phone, when logging in is called:
Protecting Yourself
Easy
A.Two-factor authentication
B.Disk formatting
C.File compression
D.Screen mirroring
Correct Answer: Two-factor authentication
Explanation:
Two-factor authentication requires a second verification step beyond the password, adding extra account security.
Incorrect! Try again.
15Which practice best helps protect your privacy on social media?
Protecting your Privacy
Easy
A.Accepting all friend requests
B.Sharing your home address publicly
C.Adjusting privacy settings to limit who sees your posts
D.Using the same password everywhere
Correct Answer: Adjusting privacy settings to limit who sees your posts
Explanation:
Configuring privacy settings controls who can view your information, reducing exposure of personal data.
Incorrect! Try again.
16What is a cookie in the context of web browsing?
Managing Cookies
Easy
A.A small file storing information about your website visits
B.A backup device
C.A type of computer virus
D.A hardware component
Correct Answer: A small file storing information about your website visits
Explanation:
A cookie is a small text file that websites store on your device to remember information such as preferences and login state.
Incorrect! Try again.
17How can a user manage or remove cookies stored on their computer?
Managing Cookies
Easy
A.By updating the printer driver
B.By restarting the monitor
C.Through the browser settings
D.By changing the mouse
Correct Answer: Through the browser settings
Explanation:
Browsers include settings that let users view, block, or delete stored cookies to manage their privacy.
Incorrect! Try again.
18What does spyware primarily do?
Spyware and other BUGS
Easy
A.Backs up important files
B.Speeds up the computer
C.Secretly collects information about a user's activity
D.Cools down the processor
Correct Answer: Secretly collects information about a user's activity
Explanation:
Spyware secretly monitors and gathers information about a user, often without their knowledge or consent.
Incorrect! Try again.
19Converting data into a coded form so only authorized people can read it is called:
Keeping your data secure
Easy
A.Encryption
B.Formatting
C.Deletion
D.Printing
Correct Answer: Encryption
Explanation:
Encryption scrambles data into an unreadable form that can only be decoded by someone with the correct key.
Incorrect! Try again.
20Why is it important to regularly back up your data?
Backing Up data
Easy
A.To make the screen brighter
B.To reduce the keyboard size
C.To recover files if the original data is lost or damaged
D.To increase internet speed
Correct Answer: To recover files if the original data is lost or damaged
Explanation:
Backups keep extra copies of data so it can be restored after loss from failure, theft, or accidental deletion.
Incorrect! Try again.
21A bank wants to ensure that only account holders can view their statements and that the data is not altered in transit. Which two components of the CIA triad are being addressed?
Basic Security Concepts
Medium
A.Availability and Integrity
B.Authentication and Availability
C.Confidentiality and Availability
D.Confidentiality and Integrity
Correct Answer: Confidentiality and Integrity
Explanation:
Restricting viewing to authorized users addresses Confidentiality, and preventing alteration of data addresses Integrity. Availability relates to ensuring access when needed, which is not the focus here.
Incorrect! Try again.
22An employee receives an email that appears to be from the company's IT department asking them to confirm their login credentials via a link. This is an example of which threat to users?
Threats to Users
Medium
A.Phishing
B.Spoofing hardware
C.Spamming
D.Snooping
Correct Answer: Phishing
Explanation:
Phishing tricks users into revealing sensitive information such as credentials by pretending to be a trusted source. Spam is unsolicited bulk mail, and snooping is unauthorized observation of data.
Incorrect! Try again.
23A user notices their files have been renamed with a strange extension and a message demands payment to unlock them. Which type of malware is most likely responsible?
Threat to Data
Medium
A.Ransomware
B.Keylogger
C.Rootkit
D.Adware
Correct Answer: Ransomware
Explanation:
Ransomware encrypts or locks a user's data and demands payment to restore access. Adware displays ads, and a keylogger records keystrokes without locking files.
Incorrect! Try again.
24A company installs its servers in a room without temperature control. Over time the servers fail frequently. Which category of hardware threat does this represent?
Threats to Hardware
Medium
A.Social engineering
B.Data interception
C.Environmental threat
D.Malware infection
Correct Answer: Environmental threat
Explanation:
Excessive heat is an environmental threat to hardware, alongside dust, humidity, and power fluctuations. Malware and social engineering target software and people, not physical conditions.
Incorrect! Try again.
25A program secretly monitors which websites a user visits and sends this information to advertisers without consent. What is this program best classified as?
Spyware and other BUGS
Medium
A.Cookie
B.Antivirus
C.Firewall
D.Spyware
Correct Answer: Spyware
Explanation:
Spyware covertly gathers information about a user's activity and transmits it to a third party. A cookie stores data locally but is not itself a hidden monitoring program.
Incorrect! Try again.
26A user wants websites to remember their login sessions but does not want tracking data to persist after closing the browser. Which approach best fits this need?
Managing Cookies
Medium
A.Allow session cookies but block third-party cookies
B.Disable JavaScript in the browser
C.Block all cookies completely
D.Allow all cookies including third-party
Correct Answer: Allow session cookies but block third-party cookies
Explanation:
Session cookies enable logins and expire when the browser closes, while third-party cookies are commonly used for cross-site tracking. Blocking all cookies would break the login feature the user wants.
Incorrect! Try again.
27An attacker disables a nation's power grid control systems to cause widespread panic and disruption. This act is best described as:
Cyber Terrorism
Medium
A.Spamming
B.Software piracy
C.Identity theft
D.Cyber terrorism
Correct Answer: Cyber terrorism
Explanation:
Cyber terrorism uses computer-based attacks against critical infrastructure to intimidate or coerce for political or ideological aims. Identity theft targets individuals' personal data, not infrastructure.
Incorrect! Try again.
28A company performs a full backup on Sunday and only backs up files changed since that full backup each following day. Which backup type are the daily backups?
Backing Up data
Medium
A.Full backup
B.Differential backup
C.Mirror backup
D.Incremental backup
Correct Answer: Differential backup
Explanation:
A differential backup copies all data changed since the last full backup, so each day's backup grows. An incremental backup only copies data changed since the last backup of any kind.
Incorrect! Try again.
29A user encrypts a file with a strong algorithm before uploading it to cloud storage. What is the main security benefit of doing this?
Keeping your data secure
Medium
A.The file uploads faster to the cloud
B.The file cannot be deleted by anyone
C.The file automatically backs itself up
D.Even if intercepted, the file cannot be read without the key
Correct Answer: Even if intercepted, the file cannot be read without the key
Explanation:
Encryption converts data into an unreadable form so that unauthorized parties who intercept it cannot understand it without the decryption key. It does not affect upload speed or prevent deletion.
Incorrect! Try again.
30Which practice most effectively reduces the damage caused if one of your online passwords is leaked in a data breach?
Protecting Yourself
Medium
A.Using a unique password for each account
B.Using the same strong password everywhere
C.Writing all passwords on a sticky note
D.Changing your username frequently
Correct Answer: Using a unique password for each account
Explanation:
Unique passwords ensure a breach of one account does not compromise the others. Reusing one password, even a strong one, lets attackers access every account once it leaks.
Incorrect! Try again.
31A firewall is configured on a home network. What is its primary function?
Taking Protective Measures: Keeping your System Safe
Medium
A.Backing up data automatically to the cloud
B.Encrypting the hard drive contents
C.Filtering incoming and outgoing network traffic based on rules
D.Scanning files for known virus signatures
Correct Answer: Filtering incoming and outgoing network traffic based on rules
Explanation:
A firewall monitors and controls network traffic according to defined rules to block unauthorized access. Scanning files for viruses is the job of antivirus software, not a firewall.
Incorrect! Try again.
32Before installing a free mobile flashlight app, a user notices it requests access to contacts, location, and microphone. What is the most privacy-conscious response?
Protecting your Privacy
Medium
A.Share the app with friends to test it first
B.Grant all permissions to make the app work
C.Deny unnecessary permissions or avoid installing the app
D.Install it and disable the phone's antivirus
Correct Answer: Deny unnecessary permissions or avoid installing the app
Explanation:
A flashlight app has no legitimate need for contacts, location, or microphone access. Excessive permission requests are a privacy red flag, so denying them or avoiding the app protects your data.
Incorrect! Try again.
33An attacker calls an employee pretending to be a senior manager and pressures them to reveal a system password urgently. This technique is known as:
Threats to Users
Medium
A.Packet sniffing
B.Social engineering
C.SQL injection
D.Brute forcing
Correct Answer: Social engineering
Explanation:
Social engineering manipulates people psychologically into revealing confidential information. Brute forcing and packet sniffing are technical attacks that do not rely on human deception.
Incorrect! Try again.
34A frequent power outage in an area keeps shutting down office computers abruptly, risking data loss and hardware damage. Which device best addresses this problem?
Safeguarding your hardware
Medium
A.Network switch
B.Uninterruptible Power Supply (UPS)
C.Antivirus software
D.External hard drive
Correct Answer: Uninterruptible Power Supply (UPS)
Explanation:
A UPS provides backup battery power during outages, allowing a safe shutdown and protecting hardware from sudden power loss. An external drive stores data but does not supply power.
Incorrect! Try again.
35A malicious program disguises itself as a useful game but secretly opens a backdoor for an attacker once installed. What is this type of malware called?
Threat to Data
Medium
A.Cookie
B.Worm
C.Boot sector virus
D.Trojan horse
Correct Answer: Trojan horse
Explanation:
A Trojan horse appears legitimate but performs malicious actions once run, such as opening a backdoor. Unlike a worm, it does not self-replicate across systems.
Incorrect! Try again.
36A photographer keeps the only copy of all client photos on a single laptop. Applying the 3-2-1 backup rule, what is the minimum change they should make?
Backing Up data
Medium
A.Keep 3 copies on 2 media types with 1 offsite
B.Keep 1 copy on the laptop only
C.Keep 2 copies both on the same laptop
D.Keep 3 copies all in the same folder
Correct Answer: Keep 3 copies on 2 media types with 1 offsite
Explanation:
The 3-2-1 rule recommends three copies of data, stored on two different media types, with one copy kept offsite. A single copy offers no protection against device failure or theft.
Incorrect! Try again.
37A system requires a password and a one-time code sent to a phone before granting access. This security method is best described as:
Basic Security Concepts
Medium
A.Single sign-on
B.Access logging
C.Two-factor authentication
D.Data encryption
Correct Answer: Two-factor authentication
Explanation:
Two-factor authentication combines two different types of evidence, such as something you know (password) and something you have (phone code). This adds a layer beyond a single password.
Incorrect! Try again.
38Software vendors regularly release updates labelled as security patches. Why is applying them promptly important?
Taking Protective Measures: Keeping your System Safe
Medium
A.They increase the storage capacity of the device
B.They always add new visual themes to the software
C.They permanently stop all future malware
D.They fix known vulnerabilities attackers could exploit
Correct Answer: They fix known vulnerabilities attackers could exploit
Explanation:
Security patches close discovered vulnerabilities before attackers can exploit them. Delaying updates leaves the system exposed to attacks targeting those known flaws.
Incorrect! Try again.
39A user's browser suddenly shows constant pop-up advertisements and a changed homepage they did not set. Which type of unwanted software is the most likely cause?
Spyware and other BUGS
Medium
A.Backup agent
B.Digital certificate
C.Firewall
D.Adware
Correct Answer: Adware
Explanation:
Adware displays unwanted advertisements and may hijack browser settings such as the homepage. A firewall and digital certificate are legitimate security tools, not causes of pop-ups.
Incorrect! Try again.
40A user connects to free public Wi-Fi at a café and wants to keep their browsing private from others on the same network. Which tool is most appropriate?
Protecting your Privacy
Medium
A.A disk defragmenter
B.A file compression tool
C.A cookie cleaner
D.A Virtual Private Network (VPN)
Correct Answer: A Virtual Private Network (VPN)
Explanation:
A VPN encrypts internet traffic, protecting it from others snooping on unsecured public Wi-Fi. Cookie cleaners and defragmenters do not secure network communication.
Incorrect! Try again.
41An organization implements a control that ensures a message received is identical to the message sent and has not been altered in transit. When an auditor asks which pillar of the CIA triad this specifically enforces, which answer is correct?
Basic Security Concepts
Hard
A.Authentication
B.Integrity
C.Confidentiality
D.Availability
Correct Answer: Integrity
Explanation:
Integrity guarantees that data is not modified or tampered with between sender and receiver. Confidentiality concerns secrecy, availability concerns access, and authentication concerns identity verification (not part of the classic CIA triad).
Incorrect! Try again.
42A security team wants a user to be unable to later deny having performed a digital transaction. Which security property must the implemented control provide?
Basic Security Concepts
Hard
A.Confidentiality
B.Non-repudiation
C.Redundancy
D.Availability
Correct Answer: Non-repudiation
Explanation:
Non-repudiation ensures a party cannot deny the authenticity of their action, typically achieved with digital signatures. The other properties address secrecy, backup, and access rather than proof of action.
Incorrect! Try again.
43A user receives an email that appears to be from their bank, urging them to click a link and 'verify' their credentials on a page that looks legitimate. The attack combines deception with a fake site. Which classification is most precise?
Threats to Users
Hard
A.Spoofing only
B.Keylogging
C.Phishing
D.Denial-of-service
Correct Answer: Phishing
Explanation:
Phishing uses fraudulent messages and fake sites to trick users into revealing credentials. Spoofing is only one component (the forged sender), while DoS and keylogging describe different attack mechanisms.
Incorrect! Try again.
44An attacker researches a specific executive's habits and sends a personalized message referencing a real meeting to steal login data. This targeted variant is best described as:
Threats to Users
Hard
A.Pharming
B.Bulk phishing
C.Smishing
D.Spear phishing
Correct Answer: Spear phishing
Explanation:
Spear phishing targets a specific individual using personalized, researched details. Bulk phishing is untargeted, pharming redirects DNS traffic, and smishing uses SMS as the delivery channel.
Incorrect! Try again.
45A data center in a region prone to voltage fluctuations experiences repeated silent corruption of running servers without total shutdown. Which protective device most directly addresses the root cause while power remains present?
Threats to Hardware
Hard
A.Anti-static wrist strap
B.Voltage regulator (line conditioner)
C.Biometric door lock
D.Fireproof safe
Correct Answer: Voltage regulator (line conditioner)
Explanation:
Voltage fluctuations (sags/surges) while power is present cause the corruption; a line conditioner stabilizes voltage. Anti-static straps prevent ESD, safes and locks address physical theft/fire, not power quality.
Incorrect! Try again.
46A technician handling internal components without an anti-static wrist strap risks damaging chips even when no visible spark occurs. The underlying threat is:
Threats to Hardware
Hard
A.Electrostatic discharge (ESD)
B.Electromagnetic pulse from software
C.Overclocking
D.Voltage brownout
Correct Answer: Electrostatic discharge (ESD)
Explanation:
Static charge built up on the body can discharge through sensitive components, damaging them even below the threshold of a visible spark. Brownouts and overclocking relate to power and clock speed, not touch-based static.
Incorrect! Try again.
47A company keeps its only backup on an external drive stored next to the server in the same room. Analysts flag this as a weakness. Which threat scenario does this arrangement fail to protect against?
Threat to Data
Hard
A.An outdated antivirus signature
B.A weak password on user accounts
C.A phishing email to staff
D.A localized fire or flood destroying both copies
Correct Answer: A localized fire or flood destroying both copies
Explanation:
Co-locating the backup with the primary data means a single physical disaster destroys both. Off-site or geographically separate backups address this. The other options are unrelated to backup location.
Incorrect! Try again.
48Ransomware encrypts a firm's files and demands payment. The firm has recent, tested, offline backups. What is the most defensible recovery decision?
Threat to Data
Hard
A.Disable antivirus to speed recovery
B.Restore from the offline backups and do not pay
C.Reinstall the OS but keep encrypted files
D.Pay the ransom immediately to save time
Correct Answer: Restore from the offline backups and do not pay
Explanation:
Tested offline backups allow full recovery without funding criminals or risking non-delivery of a key. Paying is discouraged, keeping encrypted files is pointless, and disabling antivirus increases risk.
Incorrect! Try again.
49An attack disables a nation's power-grid control systems to cause widespread civilian disruption for a political motive. Which term most accurately classifies this act?
Cyber Terrorism
Hard
A.Spamming
B.Cyber terrorism
C.Ordinary hacking for profit
D.Social engineering
Correct Answer: Cyber terrorism
Explanation:
Cyber terrorism uses computer-based attacks against critical infrastructure to cause harm or fear for political/ideological ends. Profit hacking, spamming, and social engineering lack this large-scale ideological, infrastructure-targeting intent.
Incorrect! Try again.
50Which factor most distinguishes cyber terrorism from a typical financially-motivated cybercrime?
Cyber Terrorism
Hard
A.The size of the ransom demanded
B.The use of a computer to commit the act
C.The intent to intimidate or coerce for political/ideological goals
D.The presence of a firewall on the target
Correct Answer: The intent to intimidate or coerce for political/ideological goals
Explanation:
The defining trait of cyber terrorism is ideological/political intent to cause fear or coercion. Using a computer is common to all cybercrime, and firewalls or ransom amounts do not define the category.
Incorrect! Try again.
51A firewall is configured to inspect and control incoming and outgoing traffic. A user assumes it will also detect and remove viruses already on the disk. Why is this assumption flawed?
Taking Protective Measures: Keeping your System Safe
Hard
A.A firewall filters network traffic, not files already stored on the disk
B.A firewall replaces the need for passwords
C.A firewall only works on wireless connections
D.A firewall encrypts the hard drive automatically
Correct Answer: A firewall filters network traffic, not files already stored on the disk
Explanation:
Firewalls regulate network traffic at the boundary; they do not scan or clean malware residing on local storage, which is the job of antivirus/anti-malware software.
Incorrect! Try again.
52Security patches are released for a known vulnerability, yet an administrator delays applying them for months. What is the primary risk of this delay?
Taking Protective Measures: Keeping your System Safe
Hard
A.The firewall will disable itself
B.Backups will automatically fail
C.The system will run faster without patches
D.Attackers can exploit the publicly known, unpatched vulnerability
Correct Answer: Attackers can exploit the publicly known, unpatched vulnerability
Explanation:
Once a vulnerability and its patch are public, attackers reverse-engineer the flaw and target unpatched systems. Delaying patches leaves a known, exploitable hole. Patching does not degrade speed, backups, or firewalls.
Incorrect! Try again.
53Comparing password strength, which of the following is hardest to crack by brute force, assuming an attacker knows the length?
Protecting Yourself
Hard
A.A 6-digit numeric PIN
B.The user's name followed by birth year
C.A 16-character passphrase mixing unrelated words, digits, and symbols
D.An 8-character dictionary word
Correct Answer: A 16-character passphrase mixing unrelated words, digits, and symbols
Explanation:
Longer length combined with a larger character set exponentially increases the search space. Dictionary words, short numeric PINs, and personal-data-based passwords are all quickly guessed or brute-forced.
Incorrect! Try again.
54A service offers 'two-factor authentication (2FA).' Which combination genuinely satisfies the definition of two factors?
Protecting Yourself
Hard
A.A password entered twice
B.Two different passwords
C.A password plus a one-time code from a phone app
D.A username and a password
Correct Answer: A password plus a one-time code from a phone app
Explanation:
True 2FA combines two distinct factor types: something you know (password) and something you have (the device generating the code). Two passwords or a username/password pair are both the same knowledge factor.
Incorrect! Try again.
55A user wants to reduce their trackable online footprint. Which action provides the least actual privacy benefit despite seeming protective?
Protecting your Privacy
Hard
A.Reviewing app permissions regularly
B.Relying solely on 'private/incognite browsing' to hide activity from ISPs and sites
C.Limiting personal data shared on social profiles
D.Using a reputable VPN on untrusted networks
Correct Answer: Relying solely on 'private/incognite browsing' to hide activity from ISPs and sites
Explanation:
Private browsing only stops local history and cookies from being saved; ISPs, employers, and visited sites can still observe activity. VPNs, minimizing shared data, and auditing permissions offer real protection.
Incorrect! Try again.
56A shopping site keeps a user logged in across sessions and remembers their cart days later. Which cookie type is responsible, and why does deleting only session cookies fail to remove it?
Managing Cookies
Hard
A.A session cookie, because it is deleted on browser close
B.A zombie cookie, because it cannot be deleted
C.A secure cookie, because it is encrypted
D.A persistent cookie, because it stores data with an expiry date beyond the session
Correct Answer: A persistent cookie, because it stores data with an expiry date beyond the session
Explanation:
Persistent cookies remain on disk until their expiry date, surviving browser restarts, so clearing session cookies (which vanish on close) does not remove them. Secure/zombie cookies describe other properties.
Incorrect! Try again.
57A privacy analyst distinguishes first-party from third-party cookies. Why are third-party cookies of greater tracking concern?
Managing Cookies
Hard
A.They are set by domains other than the visited site, enabling cross-site tracking
B.They always contain the user's password
C.They cannot be blocked by any browser setting
D.They are stored only in RAM and never on disk
Correct Answer: They are set by domains other than the visited site, enabling cross-site tracking
Explanation:
Third-party cookies come from external domains (often ad networks) and follow users across many sites to build behavioral profiles. They do not store passwords, are storable on disk, and can be blocked in browsers.
Incorrect! Try again.
58A machine shows unexplained network traffic, sends contact lists externally, and installs a hidden program that records keystrokes. Which classification best fits software that secretly gathers and transmits user information?
Spyware and other BUGS
Hard
A.A defragmenter
B.Spyware
C.A disk cleanup utility
D.A firewall log
Correct Answer: Spyware
Explanation:
Spyware covertly collects information about a user and transmits it, often including keyloggers. Defragmenters, cleanup tools, and firewall logs are legitimate maintenance or monitoring functions, not covert data-stealing programs.
Incorrect! Try again.
59A laptop is stolen but the entire disk was protected with full-disk encryption using a strong passphrase. What is the primary reason the confidential data remains protected?
Keeping your data secure
Hard
A.Encryption automatically alerts the police
B.Without the key/passphrase, the encrypted data is unreadable ciphertext
C.The thief cannot physically remove the drive
D.The operating system password alone blocks all access
Correct Answer: Without the key/passphrase, the encrypted data is unreadable ciphertext
Explanation:
Full-disk encryption renders data as ciphertext that cannot be decrypted without the key, so removing the drive does not help. An OS login password alone can be bypassed by mounting the drive elsewhere.
Incorrect! Try again.
60An admin applies the 3-2-1 backup rule. Which arrangement correctly satisfies it?
Backing Up data
Hard
A.3 backups on the same drive, made 2 times daily, kept for 1 year
B.3 users, 2 servers, 1 network
C.3 passwords, 2 firewalls, 1 antivirus
D.3 copies of data, on 2 different media types, with 1 copy stored off-site
Correct Answer: 3 copies of data, on 2 different media types, with 1 copy stored off-site
Explanation:
The 3-2-1 rule means keeping three total copies, on two distinct media types, with at least one copy off-site to survive local disasters. The other options misapply the numbers to unrelated resources.
Incorrect! Try again.
Did this save you a night before the exam?
LPU Notes is free, and it stays free. Ads cover part of the server bill.
The rest comes out of a student's own pocket: the domain, the storage,
and keeping the site up through the weeks everyone needs it at once.
The payment button didn't load. An ad blocker or a filtered network is the usual reason.
to try again.
Nothing here is ever locked, and nothing unlocks. Chip in only if it was worth it.
What it pays for →