ISACA Cybersecurity Fundamentals practice quiz Flashcards

1
Q

Who has the greatest influence over access security in a password authentication environment?
A. System administrators
B. Business executives
C. Users
D. Security managers

A

C. Users

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Which of the following interpret requirements and apply them to specific situations?
A. Policies
B. Standards
C. Guidelines
D. Procedures

A

B. Standards

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Business continuity plans (BCPs) associated with organizational information systems should be developed primarily on the basis of:
A. Available resources
B. Levels of effort
C. Projected costs
D. Business needs

A

D. Business needs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

A segmented network:
A. Offers defense in depth superior to a concentric-layers model
B. Consists of two or more security zones
C. Maximizes the delay experienced by an attacker
D. Delivers superior performance for internal applications

A

B. Consists of two or more security zones

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Which cybersecurity principle is most important when attempting to trace the source of malicious activity?
A. Availability
B. Integrity
C. Nonrepudiation
D. Confidentiality

A

C. Nonrepudiation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Which of the following offers the strongest protection for wireless network traffic?
A. Wireless Protected Access 2 (WPA2)
B. Wireless Protected Access-Advanced Encryption Standard (WPA-AES)
C. Wired Equivalent Protection 128-bit (WEP-128)
D. Wireless Protected Access-Temporary Key Integrity Protocol (WPA-TKIP)

A

A. Wireless Protected Access 2 (WPA2)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Outsourcing poses the greatest risk to an organization when it involves:
A. Business support services
B. Technology infrastructure
C. Cybersecurity capabilities
D. Core business functions

A

D. Core business functions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Risk assessments should be performed:
A. At the start of a program
B. On a regular basis
C. When an asset changes
D. When a vulnerability is discovered

A

B. On a regular basis

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Maintaining a high degree of confidence regarding the integrity of evidence requires a(n):
A. Power of attorney
B. Sworn statement
C. Chain of custody
D. Affidavit

A

C. Chain of custody

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

A firewall that tracks open connection-oriented protocol sessions is said to be:
A. State-sponsored
B. Stateless
C. Stateful
D. Stated

A

C. Stateful

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

During which phase of the system development lifecycle (SDLC) should security first be considered?
A. Planning
B. Analysis
C. Design
D. Implementation

A

A. Planning

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

A cybersecurity architecture designed around the concept of a perimeter is said to be:
A. Data-centric
B. User-centric
C. Integrated
D. System-centric

A

D. System-centric

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

A passive network hub operates at which layer of the OSI model?
A. Data Link
B. Physical
C. Network
D. Transport

A

B. Physical

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Updates in cloud-computing environments can be rolled out quickly because the environment is:
A. Homogeneous
B. Distributed
C. Diversified
D. Secure

A

A. Homogeneous

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

During which phase of the six-phase incident response model is the root cause determined?
A. Recovery
B. Identification
C. Containment
D. Eradication

A

D. Eradication

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

The attack mechanism directed against a system is commonly called a(n):
A. Exploit
B. Vulnerability
C. Payload
D. Attack Vector

A

C. Payload

17
Q

Where should an organization’s network terminate virtual private network (VPN) tunnels?
A. At an interior router, to reduce network traffic congestion
B. At a dedicated “honey pot” system in the demilitarized zone (DMZ)
C. At the destination system, to prevent loss of confidentiality
D. At the perimeter, to allow for effective internal monitoring

A

D. At the perimeter, to allow for effective internal monitoring

18
Q

In practical applications:
A. Symmetric key encryption is used to securely distribute asymmetric keys
B. Asymmetric key encryption is used to securely obtain symmetric keys
C. Symmetric key encryption is used only for short messages, such as digital signatures
D. Asymmetric key encryption is used in cases where speed is important

A

B. Asymmetric key encryption is used to securely obtain symmetric keys

19
Q

Which two factors are used to calculate the likelihood of an event?
A. Threat and vulnerability
B. Vulnerability and asset value
C. Asset count and asset value
D. Threat and asset count

A

A. Threat and vulnerability

20
Q

What kind of anti-malware program evaluates system processes based on their observed behaviors?
A. Heuristic
B. Signature-based
C. Stateful
D. Polymorphic

A

A. Heuristic

21
Q

A business continuity plan (BCP) is not complete unless it includes:
A. Dedicated resources
B. Detailed procedures
C. Network diagrams
D. Critical processes

A

B. Detailed procedures

22
Q

Under the US-CERT model for incident categorization, a CAT-3 incident refers to which of the following?
A. Improper usage
B. Investigation
C. Denial of service (DoS)
D. Malicious code

A

D. Malicious code

23
Q

An interoperability error is what type of vulnerability?
A. Technical
B. Process
C. Emergent
D. Organizational

A

C. Emergent

24
Q

Securing Supervisory Control and Data Acquisition (SCADA) systems can be challenging because they:
A. Operate in specialized environments and often have non-standard design elements
B. Are subject to specialized requirements established for national security systems
C. Support critical infrastructure processes for which any risk of compromise is unacceptable
D. Cannot be replaced due to aging infrastructure and the complexity of included components

A

A. Operate in specialized environments and often have non-standard design elements

25
Q

Virtual systems should be managed using a dedicated virtual local area network (VLAN) because:
A. Network topologies do not always properly identify the locations of virtual servers
B. VLAN encryption provides a double layer of protection for virtual system data
C. Insecure protocols could result in a compromise of privileged user credentials
D. Segregation of management traffic and use traffic dramatically improves performance

A

C. Insecure protocols could result in a compromise of privileged user credentials