Accurate Answers
The University wants to make sure that students and faculty are able to log in to ICON
24 hours a dat in order to share course materials and submit work. What principle of the
CIA triad does this goal relate to? - ANSWERSAvailability
An error in ICON results in one student having the ability to see another student's
grades. What principle of the CIA triad does this situation violate? -
ANSWERSConfidentiality
Whenever a page or file is changed on ICON, the site records who made the change
and when it occurred. Thus, actions can always be attributed to a specific user. This is
an example of the principle of:? - ANSWERSNon-repudiation
Iowa State is taking the Cy-Hawk rivalry to the next level! They have launched an attack
on UI's servers in order to prevent any faculty, staff, or students from accessing to
ICON. This is an example of a __________ threat actor. - ANSWERSCompetitor
a CS student discovers a website that contains pre-written code for intercepting data
from public Wi-Fi networks. Just out of curiosity, she decides to start testing the code
against loco Wi-Fi hotspots. This is an examples of __________ threat actor. -
ANSWERSScript kiddy
The Department of Business Analytics stores future course assignments in a shared
spreadsheet. Only the DEO and department administrator have the power to edit this
document. All of the other faculty in the department have read-only permissions. If a
bug in Office365 allows the read-only users to edit the document, what type of threat
does this represent? - ANSWERSElevation of privilage
The course assignment spreadsheet should only be shared with faculty and staff in the
Department of Business Analytics. If a bug in Office365 makes the spreadsheet public
to anyone online, what type of threat does this represent? - ANSWERSInformation
disclosure
The MITRE Corporation maintains a database of known cybersecurity flaws called
__________. - ANSWERSCVEs
Target earns approximately $12,000,000 per day in digital sales via their website and
app. If a distributed denial of service attacks from hacktivists shut down the Target
website and app for 1 hour, what is the single loss expectancy (in terms of lost sales)? -
ANSWERS$500,000
, If order to manage the risk of denial of service attacks, Target has decided to update
their application infrastructure to a content distribution network (geographically
distributed groups of servers). This approach can increase the speed of content deliver
to users, but also create redundancy that allows traffic on the website and app to
redirected to a different set of servers if another is attacked. This is an example of a risk
__________ strategy. - ANSWERSMitigation
Cryptography is an example of a(n) __________ control. - ANSWERSTechnical
Assume that your encryption method uses an 8-bit key, how many possible keys are
there? (Hint: a bit stores 0 or 1) - ANSWERS2^8 = 256
Alice sends Bob a suggestive text message, but unbeknownst to either of them, Bob's
wife Eve has installed a spyware app on his phone and can read Alice's message. This
is an example of a __________ attack. - ANSWERSMan in the middle
Alice and Bob are getting better at covering their tracks. Now Alice sense Bob
encrypted messages where each letter in the message in replaced with the letter 5
spaces after it in the alphabet. This encryption method is an example of a __________.
- ANSWERSCaesar cipher
Eve has realized that Alice and Bob are using coded messages to communicate, but
she doesn't know the method they are using. In an attempt to crack the cipher, she gets
access to Bob's phone and sends Alice a text asking her "What is the code for 'I love
you'?". This is an example of a __________ attack. - ANSWERSChosen plaintext
Cole is sending his boss, Dina, a quarterly TPS report. To assure the authenticity of the
report and make sure that Dina knows that it came from Cole, he should encrypt the
message with his __________ key. - ANSWERSPrivate
HTTPS uses the TLS protocol to maintain confidentiality, authenticity, and integrity in
Internet communications. Which of the following information is NOT protected by
HTTPS/TLS?
- Query parameters
- Amount of data transmitted
- Headers
- Cookies
- Passwords - ANSWERSAmount of data transmitted
Which of the following is NOT an identification method used on HawkID cards?
- Barcode
- Smart card
- Retinol scan