Comprehensive Information Security Fundamentals EXAM STUDY GUIDE 2026/2027 COMPLETE QUESTIONS WITH 100%VERIFIED CORRECT ANSWERS // A++ Graded
A badge or token is considered what type of authentication? - ANSWER Something you have
A password or PIN is considered what type of authentication? - ANSWER Something you know
The set of methods we use to establish a claim of identity as being true is called ______. - ANSWER Authentication
A fingerprint is considered what type of authentication? - ANSWER Something you are
What type of authentication can prevent a man-in-the-middle attack? - ANSWER Mutual
The biometric characteristic that measures how well a factor resists change over time and with advancing age is called __________ - ANSWER Permanence
What dictates that we should only allow the bare minimum of access, as needed? - ANSWER Principle of least privilege
Access controls are policies or procedures used to control access to certain items. - ANSWER True
What does FISMA require from federal agencies? - ANSWER To develop, document, and implement an agency-wide information security program.
What are the key components of the FISMA framework? - ANSWER Standards for categorizing information, minimum security requirements, guidance for selecting and assessing security controls, and security authorization.
What is the General Data Protection Regulation (GDPR)? - ANSWER A stringent privacy and security law enacted by the European Union that applies to organizations targeting or collecting data related to EU individuals.
What are the seven data protection principles outlined in the GDPR? - ANSWER Lawfulness, fairness, and transparency; purpose limitation; data minimization; accuracy; storage limitation; integrity and confidentiality; accountability.
What does the Data Protection Act 2018 (DPA) regulate? - ANSWER The processing of personal data in the UK, updating the Data Protection Act 1998.
What rights does the DPA confer to data subjects? - ANSWER Rights to obtain information about data processing and to require rectification of inaccurate personal data.
What is cyberlaw? - ANSWER Laws that deal with protecting the Internet and online communication technologies, covering topics like privacy and jurisdiction.
Why have cyber laws become prominent? - ANSWER Due to the increase in Internet usage worldwide.
What are the potential consequences of violating cyber laws? - ANSWER Punishments ranging from fines to imprisonment.
What does the term 'technological protection measures' refer to in the context of the DMCA? - ANSWER Measures employed by copyright owners to protect their works from unauthorized access or use.
What is the significance of the accountability principle in GDPR? - ANSWER The data controller is responsible for demonstrating compliance with all GDPR principles.
What is meant by 'data minimization' under GDPR? - ANSWER Collecting and processing only as much data as necessary for specified purposes.
What does 'integrity and confidentiality' mean in the context of GDPR? - ANSWER Ensuring appropriate security measures are in place to protect personal data.
What is the role of the Information Commissioner in the DPA? - ANSWER To monitor and enforce compliance with data protection provisions.
What does the term 'ephemeral recordings' refer to in Title IV of the DMCA? - ANSWER Temporary recordings made for specific purposes that are exempt from certain copyright restrictions.
What is the purpose of the Vessel Hull Design Protection Act (VHDPA)? - ANSWER To protect the original designs of hulls of vessels up to 200 feet in length.
What is the impact of GDPR on organizations outside the EU? - ANSWER It imposes obligations on organizations anywhere that target or collect data related to individuals in the EU.
What is implemented through the use of access controls? - ANSWER Authorization
Which answer best describes the authorization component of access control? - ANSWER Authorization is the process of determining who is approved for access and what resources they are approved for.
A client-side attack that involves the attacker placing an invisible layer over something on a website that the user would normally click on, in order to execute a command differing from what the user thinks they are performing, is known as ___________. - ANSWER Clickjacking
What type of access control can prevent the confused deputy problem? - ANSWER Capability-based security
A user who creates a network share and sets permissions on that share is employing which model of access control? - ANSWER Discretionary access control
A VPN connection that is set to time out after 24 hours is demonstrating which model of access control? - ANSWER Attribute-based access control
Confidential Services Inc. is a military-support branch consisting of 1,400 computers with Internet access and 250 servers. All employees are required to have security clearances. From the options listed below, what access control model would be most appropriate for this organization? - ANSWER Mandatory access control
What is information security? - ANSWER Protecting information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction.
Using the concept of defense in depth we can protect ourselves against someone using a USB flash drive to remove confidential data from an office space within our building. - ANSWER True
Select the example(s) of identity verification. (Choose all that apply.) - ANSWER SSN
Passport
Birth certificate
Multifactor authentication is the use of more than one authentication method to access an information system. - ANSWER True
Which password below would meet complexity standards? - ANSWER !Q@S#z6ge7Uks1lw3
What is accountability comprised of? - ANSWER Authorization
Authentication
Identification
Access
What document do courts require for admissibility of records? - ANSWER Chain of custody
An employee is charged with fraud, and the company can prove in court that there are email transactions showing that the employee completed these using a digital signature. What term is being described? - ANSWER Nonrepudiation
What is auditing? - ANSWER The primary means to ensure accountability through technical means
What are the two common forms of assessments performed on networks? (Choose all that apply.) - ANSWER Penetration test
Vulnerability assessment
_______ provides us with the means to trace activities in our environment back to their source. - ANSWER Accountability
Nessus is an example of a(n) _______________ tool. - ANSWER Vulnerability scanning
A surveillance video log contains a record, including the exact date and time, of an individual gaining access to his company's office building after hours. He denies that he was there during that time, but the existence of the video log proves otherwise. What benefit of accountability does this example demonstrate? - ANSWER Non repudiation
What process ensures compliance with applicable laws, policies, and other bodies of administrative control, and detects misuse? - ANSWER Auditing
Your organization's network was recently the target of an attack. Fortunately, the new system you installed took action and refused traffic from the source before you even had a chance to respond. What system did you install? - ANSWER An intrusion prevention system
The act of scrambling plain text into cyphertext is known as ________. - ANSWER encryption
A strong hash function is designed so that a message cannot be forged that will result in the same hash as a legitimate message. - ANSWER True
An encryption cipher that uses the same key to encrypt and decrypt is called a/an ______. - ANSWER asymmetric key
Hashes provide confidentiality and integrity. - ANSWER False
An algorithm used for cryptographic purposes is known as a _______. - ANSWER cipher
__________ corroborates the identity of an entity, whether it is the sender, the sender's computer, some device, or some information. - ANSWER Authentication
The science of breaking through encryption is known as _____. - ANSWER Cryptanalysis
Hashes provide _______, but not _______. - ANSWER Integrity, confidentiality
Shovels and Shingles is a small construction company consisting of 12 computers that have Internet access. The company is concerned that a wily, computer-savvy competitor will send e-mail messages pretending to be from Shovels and Shingles to its customers, in an attempt to gather customer information. What encryption solution best prevents a competitor from successfully impersonating the company? - ANSWER: Digital signatures
Backordered Parts is a defense contractor that builds communications parts for the military. The employees use mostly Web-based applications for parts design and information sharing. Due to the sensitive nature of the business, Backordered Parts would like to implement a solution that secures all browser connections to the Web servers. What encryption solution best meets this company's needs? - ANSWER Elliptic Curve Cryptography (ECC)
We are somewhat limited in our ability to protect which type of data? - ANSWER Data in use
A cybersecurity professional must be proficient with all current laws, both state and federal, that may apply to the organization he or she works with. - ANSWER False
FISMA refers to ____. - ANSWER Federal Information Security Management Act of 2002 and Federal Information Security Modernization Act of 2014
Which statement below is true about a company operating in the United States today? - ANSWER International computing laws must be considered if any customer resides outside the U.S.
PII is personally identifiable information. This data must always _____. - ANSWER be monitored for compliance
______ ensures the protection of information, operations, and assets in federal government. - ANSWER FISMA
______ protects the privacy of students and their parents. - ANSWER FERPA
______ sets limits on the use and disclosure of patient information and grants individuals rights over their own health records. - ANSWER HIPAA
______ regulates the financial practice and governance of corporations. - ANSWER SOX
Content preview
Comprehensive Information Security Fundamentals EXAM
STUDY GUIDE 2026/2027 COMPLETE QUESTIONS
WITH 100%VERIFIED CORRECT ANSWERS // A++
Graded
A badge or token is considered what type of authentication? - ANSWER
Something you have
A password or PIN is considered what type of authentication? - ANSWER
Something you know
The set of methods we use to establish a claim of identity as being true is
called ______. - ANSWER Authentication
A fingerprint is considered what type of authentication? - ANSWER
Something you are
What type of authentication can prevent a man-in-the-middle attack? -
ANSWER Mutual
The biometric characteristic that measures how well a factor resists change
over time and with advancing age is called __________ - ANSWER
,Permanence
What dictates that we should only allow the bare minimum of access, as
needed? - ANSWER Principle of least privilege
Access controls are policies or procedures used to control access to certain
items. - ANSWER True
What does FISMA require from federal agencies? - ANSWER To develop,
document, and implement an agency-wide information security program.
What are the key components of the FISMA framework? - ANSWER
Standards for categorizing information, minimum security requirements,
guidance for selecting and assessing security controls, and security
authorization.
What is the General Data Protection Regulation (GDPR)? - ANSWER A
stringent privacy and security law enacted by the European Union that
applies to organizations targeting or collecting data related to EU individuals.
What are the seven data protection principles outlined in the GDPR? -
ANSWER Lawfulness, fairness, and transparency; purpose limitation; data
minimization; accuracy; storage limitation; integrity and confidentiality;
accountability.
What does the Data Protection Act 2018 (DPA) regulate? - ANSWER The
processing of personal data in the UK, updating the Data Protection Act
,1998.
What rights does the DPA confer to data subjects? - ANSWER Rights to
obtain information about data processing and to require rectification of
inaccurate personal data.
What is cyberlaw? - ANSWER Laws that deal with protecting the Internet
and online communication technologies, covering topics like privacy and
jurisdiction.
Why have cyber laws become prominent? - ANSWER Due to the increase
in Internet usage worldwide.
What are the potential consequences of violating cyber laws? - ANSWER
Punishments ranging from fines to imprisonment.
What does the term 'technological protection measures' refer to in the
context of the DMCA? - ANSWER Measures employed by copyright
owners to protect their works from unauthorized access or use.
What is the significance of the accountability principle in GDPR? -
ANSWER The data controller is responsible for demonstrating compliance
with all GDPR principles.
What is meant by 'data minimization' under GDPR? - ANSWER Collecting
, and processing only as much data as necessary for specified purposes.
What does 'integrity and confidentiality' mean in the context of GDPR? -
ANSWER Ensuring appropriate security measures are in place to protect
personal data.
What is the role of the Information Commissioner in the DPA? - ANSWER
To monitor and enforce compliance with data protection provisions.
What does the term 'ephemeral recordings' refer to in Title IV of the
DMCA? - ANSWER Temporary recordings made for specific purposes that
are exempt from certain copyright restrictions.
What is the purpose of the Vessel Hull Design Protection Act (VHDPA)? -
ANSWER To protect the original designs of hulls of vessels up to 200 feet in
length.
What is the impact of GDPR on organizations outside the EU? - ANSWER
It imposes obligations on organizations anywhere that target or collect data
related to individuals in the EU.
What is implemented through the use of access controls? - ANSWER
Authorization
Which answer best describes the authorization component of access control?