What type of malware is specifically designed to spread from one computer to another?
Worm
What protocol is commonly used to securely transfer files over a network?
SFTP
What is the first step in the risk management process?
Risk Identification
Which cryptographic method is used to verify the integrity and authenticity of a message?
Hashing
Which authentication method involves something you know?
Password
Which attack involves tricking someone into giving up confidential information through emails or messages?
Phishing
Which port does HTTPS use by default?
443
What is the purpose of a Business Impact Analysis (BIA)?
To assess the impact of potential disruptions
What is the key difference between symmetric and asymmetric encryption?
Symmetric uses the same key for encryption and decryption; asymmetric uses different keys.
What is the purpose of two-factor authentication (2FA)?
To verify user identity with two different methods
What type of attack involves overwhelming a system with traffic to make it unavailable?
Denial-of-Service (DoS)
What type of firewall monitors the state of active connections and determines which network packets to allow?
Stateful
Which of the following is an example of a qualitative risk assessment method?
Probability and Impact Matrix
Which algorithm is considered a secure hashing algorithm?
SHA-256
Which access control model is based on the roles assigned to users within an organization?
Role-Based Access Control (RBAC)
Which of the following is an advanced, persistent threat often attributed to nation-state actors?
APT (Advanced Persistent Threat)
Which wireless security protocol is considered the most secure?
WPA3
Which document is critical for ensuring continuity of operations during a disaster?
Business Continuity Plan (BCP)
What is the primary purpose of a digital certificate?
Verify the identity of the certificate holder
What is the main purpose of the principle of least privilege?
To grant users the minimum level of access necessary
What is the primary purpose of a rootkit?
allows someone to maintain command and control over a computer without the computer user/owner knowing about it
What type of attack exploits vulnerabilities in the DNS to divert traffic to malicious websites?
DNS Spoofing
What risk response strategy involves transferring the risk to another party, typically through insurance?
Risk Transference
What is the process of converting ciphertext back into plaintext called?
Decryption
What is the primary function of a Kerberos authentication system?
To provide single sign-on (SSO) authentication