CIA Triad
Network Security
Threats & Attacks
Authentication & Access
Defense & Security
100

What are the three components of the CIA triad?

The CIA triad consists of Confidentiality, Integrity, and Availability.

100

What device forwards packets between different networks?

A router forwards packets between different networks.

100

What is malware?

Malware is malicious software designed to disrupt, damage, gain unauthorized access to, or otherwise compromise systems or data.

100

What does MFA stand for?

Multi-Factor Authentication.

100

What is a firewall?

A firewall monitors and controls network traffic according to defined security rules.

200

What does confidentiality mean in cybersecurity?

Confidentiality means ensuring that information is accessible only to authorized people or systems.

200

What protocol is commonly used to securely browse websites?

HTTPS (HTTP over TLS) is commonly used to securely browse websites.

200

What type of attack attempts to trick users into revealing sensitive information through fraudulent messages?

Phishing.

200

What is the principle of least privilege?

The principle of least privilege means giving users and systems only the permissions they need to perform their authorized tasks.

200

What is antivirus software designed to detect?

Antivirus/endpoint security software is designed to detect, block, and/or remove malicious software and other suspicious activity.

300

A hospital's patient database becomes unavailable because of an attack. Which part of the CIA triad has been compromised?

Availability. The patient database is no longer accessible when it is needed.

300

What is the primary purpose of a VPN?

A VPN (Virtual Private Network) creates an encrypted connection between a device and a VPN endpoint, helping protect network traffic from interception on untrusted networks.

300

What type of malware encrypts files and demands payment for their recovery?

Ransomware encrypts or otherwise locks access to data and typically demands payment in exchange for restoring access.

300

What is the difference between authentication and authorization?

Authentication verifies who you are. Authorization determines what you are allowed to do after your identity has been established.

300

Why is patching software an important security practice?

Patching fixes known software vulnerabilities, reducing opportunities for attackers to exploit weaknesses in systems.

400

A company uses hashing to verify that a downloaded file hasn't been altered. Which CIA property is primarily being protected?

Integrity. Hashing can be used to detect whether data has been modified or corrupted.

400

What is the difference between TCP and UDP?

TCP is connection-oriented and provides mechanisms for reliable, ordered delivery. UDP is connectionless and generally provides lower overhead but does not guarantee delivery or ordering.

400

What is a DDoS attack, and what is its primary goal?

A Distributed Denial-of-Service (DDoS) attack uses many systems or sources to overwhelm a target with traffic or requests, disrupting its availability.

400

What is a brute-force attack against a password?

A brute-force attack systematically attempts many possible passwords or credentials until the correct one is found.

400

What is defense in depth?

Defense in depth is a security strategy that uses multiple layers of security controls so that if one control fails, others can still provide protection.

500

A hacker gains unauthorized access to a database and changes salary records without permission. Which CIA property is primarily violated, and why?

Integrity, because the attacker has improperly modified the salary records. Integrity concerns the accuracy and trustworthiness of data.

500

Explain why DNS can be a security concern and name one attack involving DNS.

DNS translates domain names such as example.com into IP addresses. Because DNS is critical to network communication, attacks can manipulate or disrupt it. One example is DNS spoofing/cache poisoning, where false DNS information causes users to be directed to an incorrect destination.

500

How does a SQL injection attack work at a high level?

SQL injection occurs when an application improperly incorporates untrusted user input into SQL queries, potentially allowing an attacker to alter the intended database query. Proper input validation, parameterized queries, and other secure coding practices help prevent it.

500

Why is password reuse dangerous, and how can a password manager help?

Password reuse is dangerous because if one service is breached, attackers can try the stolen password on other accounts. A password manager can generate and store unique passwords for different accounts, reducing the impact of a single compromised credential.

500

An employee clicks a malicious link, but the organization's endpoint protection blocks the resulting malware. What security concept does this demonstrate?

This demonstrates defense in depth. The phishing link represents one point of compromise, while endpoint protection provides another security layer that can prevent the attack from succeeding.