Threats & Vulnerabilities
Network Security
Risk Management
Cryptography
Access Control & Authentication
100

What type of malware is specifically designed to spread from one computer to another?

Worm

100

What protocol is commonly used to securely transfer files over a network?

SFTP

100

What is the first step in the risk management process?

Risk Identification

100

Which cryptographic method is used to verify the integrity and authenticity of a message?

Hashing

100

Which authentication method involves something you know?

Password

200

Which attack involves tricking someone into giving up confidential information through emails or messages?

Phishing

200

Which port does HTTPS use by default?

443

200

What is the purpose of a Business Impact Analysis (BIA)?

To assess the impact of potential disruptions

200

What is the key difference between symmetric and asymmetric encryption?

Symmetric uses the same key for encryption and decryption; asymmetric uses different keys.

200

What is the purpose of two-factor authentication (2FA)?

To verify user identity with two different methods

300

What type of attack involves overwhelming a system with traffic to make it unavailable?

Denial-of-Service (DoS)

300

What type of firewall monitors the state of active connections and determines which network packets to allow?

Stateful

300

Which of the following is an example of a qualitative risk assessment method?

Probability and Impact Matrix

300

Which algorithm is considered a secure hashing algorithm?

SHA-256

300

Which access control model is based on the roles assigned to users within an organization?

Role-Based Access Control (RBAC)

400

Which of the following is an advanced, persistent threat often attributed to nation-state actors?

APT (Advanced Persistent Threat)

400

Which wireless security protocol is considered the most secure?

WPA3

400

Which document is critical for ensuring continuity of operations during a disaster?

Business Continuity Plan (BCP)

400

What is the primary purpose of a digital certificate?

Verify the identity of the certificate holder

400

What is the main purpose of the principle of least privilege?

To grant users the minimum level of access necessary

500

What is the primary purpose of a rootkit?

allows someone to maintain command and control over a computer without the computer user/owner knowing about it

500

What type of attack exploits vulnerabilities in the DNS to divert traffic to malicious websites?

DNS Spoofing

500

What risk response strategy involves transferring the risk to another party, typically through insurance?

Risk Transference

500

What is the process of converting ciphertext back into plaintext called?

Decryption

500

What is the primary function of a Kerberos authentication system?

To provide single sign-on (SSO) authentication