Cybersecurity
Management Final with
correct questions and
answers
usr
[COMPANY NAME] [Company address]
,1. provide
the detailed steps needed to carry out . Answer:
Procedures, policies
2. A
grants the authority to perform an action on a system. A
grants access to a resource. Answer: right, permission
3. A business continuity plan (BCP) is an example of a(n) Answer: Answer:
security plan
4. A hacker wants to launch an attack on an organization. The
hacker uses a tool to capture data sent over the network in
cleartext, hoping to gather
information that will help make the attack successful. What tool is the
hacker using? Answer: a packet analyzer
5. A threat is any activity that represents a possible danger, which
includes any circumstances or events with the potential to cause
an adverse impact on all of the following, except Answer: Answer:
assessments
6. A(n) assessment attempts to identify
vulnerabilities that can be exploited.
A. risk
B. threat
C. vulnerability
D. exploit Answer: D. exploit
7. An access control such as a firewall or intrusion prevention
system cannot protect against which of the following? Answer: Social
engineering
8. Another term for data range and reasonableness checks is Answer:
Answer: input validation
9. Background checks, software testing, and awareness training are
all cate- gories of Answer: Answer: procedural controls.
10. Bill is a security professional. He is in a meeting with co-
workers and de- scribes a system that will make web sessions
more secure. He says when a user connects to the web server and
,starts a secure session, the server sends a certificate to the user. The
certificate includes a public key. The user can encrypt data with the
public key and send it to the server. Because the server holds the
private key, it can decrypt the data. Because no other entity has the
private key, no one else can decrypt the data. What is Bill
describing?
, A. Public key infrastructure (PKI)
B. Certificate authority (CA)
C. A hashing algorithm
D. A digital signature Answer: A. Public key infrastructure (PKI)
11. Bonding is a type of that covers
against losses by theft, fraud, or dishonesty. Answer: Insurance
12. Complete the equation for the relationship between risk,
vulnerabilities, and threats Answer: Risk equals Answer: Answer: Vulnerability ×
Threat .
13. Functionality testing is primarily used with Answer: Answer:
Software Development
14. Ideally, when should you perform threat modeling?
A. After writing an application or deploying a system
B. Before writing an application, but after deploying a system
C. After writing an application, but before deploying a system
D. Before writing an application or deploying a system Answer: D. Before writing
an application or deploying a system
15. In a SQL injection attack, an attacker can Answer: Answer: read sections of
a database or a whole database without authorization.
16. Piggybacking is also known as Answer:
A. tailgating.
B. a mantrap.
C. social engineering.
D. shoulder surfing. Answer: A. tailgating.
17. Primary considerations for assessing threats
based on historical data in your local area are and .
A. property value, insurance
B. weather conditions, natural disasters
C. historical data, threat modeling
D. crime statistics, flood frequency Answer: B. weather conditions, natural disasters
Management Final with
correct questions and
answers
usr
[COMPANY NAME] [Company address]
,1. provide
the detailed steps needed to carry out . Answer:
Procedures, policies
2. A
grants the authority to perform an action on a system. A
grants access to a resource. Answer: right, permission
3. A business continuity plan (BCP) is an example of a(n) Answer: Answer:
security plan
4. A hacker wants to launch an attack on an organization. The
hacker uses a tool to capture data sent over the network in
cleartext, hoping to gather
information that will help make the attack successful. What tool is the
hacker using? Answer: a packet analyzer
5. A threat is any activity that represents a possible danger, which
includes any circumstances or events with the potential to cause
an adverse impact on all of the following, except Answer: Answer:
assessments
6. A(n) assessment attempts to identify
vulnerabilities that can be exploited.
A. risk
B. threat
C. vulnerability
D. exploit Answer: D. exploit
7. An access control such as a firewall or intrusion prevention
system cannot protect against which of the following? Answer: Social
engineering
8. Another term for data range and reasonableness checks is Answer:
Answer: input validation
9. Background checks, software testing, and awareness training are
all cate- gories of Answer: Answer: procedural controls.
10. Bill is a security professional. He is in a meeting with co-
workers and de- scribes a system that will make web sessions
more secure. He says when a user connects to the web server and
,starts a secure session, the server sends a certificate to the user. The
certificate includes a public key. The user can encrypt data with the
public key and send it to the server. Because the server holds the
private key, it can decrypt the data. Because no other entity has the
private key, no one else can decrypt the data. What is Bill
describing?
, A. Public key infrastructure (PKI)
B. Certificate authority (CA)
C. A hashing algorithm
D. A digital signature Answer: A. Public key infrastructure (PKI)
11. Bonding is a type of that covers
against losses by theft, fraud, or dishonesty. Answer: Insurance
12. Complete the equation for the relationship between risk,
vulnerabilities, and threats Answer: Risk equals Answer: Answer: Vulnerability ×
Threat .
13. Functionality testing is primarily used with Answer: Answer:
Software Development
14. Ideally, when should you perform threat modeling?
A. After writing an application or deploying a system
B. Before writing an application, but after deploying a system
C. After writing an application, but before deploying a system
D. Before writing an application or deploying a system Answer: D. Before writing
an application or deploying a system
15. In a SQL injection attack, an attacker can Answer: Answer: read sections of
a database or a whole database without authorization.
16. Piggybacking is also known as Answer:
A. tailgating.
B. a mantrap.
C. social engineering.
D. shoulder surfing. Answer: A. tailgating.
17. Primary considerations for assessing threats
based on historical data in your local area are and .
A. property value, insurance
B. weather conditions, natural disasters
C. historical data, threat modeling
D. crime statistics, flood frequency Answer: B. weather conditions, natural disasters