• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 48 pages
Exam (elaborations)

CYBER SECURITY – ACADEMIC YEAR 2026/2027 – COMPREHENSIVE EXAMINATION | VERIFIED QUESTIONS

Document preview thumbnail
Preview 4 out of 48 pages

CYBER SECURITY – ACADEMIC YEAR 2026/2027 – COMPREHENSIVE EXAMINATION | VERIFIED QUESTIONS

Content preview

CYBER SECURITY – ACADEMIC YEAR
2026/2027 – COMPREHENSIVE
EXAMINATION | VERIFIED QUESTIONS

DOMAIN 1: SECURITY FUNDAMENTALS AND THREAT LANDSCAPE
Question 1. Which of the following best describes the CIA triad in information
security?
A. Confidentiality, Integrity, and Availability
B. Control, Inspection, and Authorization
C. Cryptography, Identification, and Authentication
D. Compliance, Investigation, and Auditing
Rationale: The CIA triad is the foundational model of information security,
representing Confidentiality (protecting data from unauthorized access), Integrity
(ensuring data accuracy and trustworthiness), and Availability (ensuring
authorized users can access resources when needed).


Question 2. A phishing attack is best classified as which type of threat?
A. A physical security breach
B. A social engineering technique that attempts to trick users into revealing
sensitive information
C. A hardware failure
D. A cryptographic weakness
Rationale: Phishing uses deceptive messages, typically via email or messaging, to
manipulate individuals into disclosing credentials, clicking malicious links, or
downloading malware. It exploits human behavior rather than technical
vulnerabilities alone.


Question 3. Which of the following is an example of a vulnerability?

,A. A properly configured firewall
B. An unpatched software application that can be exploited by an attacker
C. A strong password policy
D. Regular security awareness training
Rationale: A vulnerability is a weakness in a system, application, or process that
can be exploited. Unpatched software is a common vulnerability that attackers
target to gain unauthorized access or execute malicious code.


Question 4. The primary difference between a threat and a risk is that:
A. A threat is a potential cause of an unwanted incident, while risk is the
potential for loss when a threat exploits a vulnerability
B. Threats and risks are identical concepts
C. Risks exist only in physical environments
D. Threats can be measured only in monetary terms
Rationale: A threat is anything that can cause harm. Risk combines the likelihood
that a threat will exploit a vulnerability with the potential impact of that
exploitation.


Question 5. Which of the following is an example of a passive attack?
A. Denial-of-service attack
B. Eavesdropping on network traffic
C. SQL injection
D. Ransomware deployment
Rationale: Passive attacks involve monitoring or eavesdropping without modifying
system resources. Active attacks, such as DoS, SQL injection, and ransomware,
involve modifying or disrupting system operations.


Question 6. What is the primary goal of a denial-of-service (DoS) attack?
A. To steal sensitive data
B. To make a system or network resource unavailable to legitimate users

,C. To encrypt files for ransom
D. To gain unauthorized access to a system
Rationale: A DoS attack aims to overwhelm a system or network with traffic or
requests, making it unavailable to legitimate users. It does not typically involve
data theft or encryption.


Question 7. Which of the following best describes malware?
A. Malicious software designed to damage, disrupt, or gain unauthorized
access to a computer system
B. A type of firewall
C. A network protocol
D. A cryptographic algorithm
Rationale: Malware is any software intentionally designed to cause damage,
disrupt operations, or gain unauthorized access to systems. Types include viruses,
worms, trojans, ransomware, and spyware.


Question 8. What is the primary characteristic of a worm?
A. It requires user interaction to spread
B. It self-replicates and spreads across networks without user intervention
C. It only affects standalone computers
D. It is a type of hardware failure
Rationale: A worm is a type of malware that self-replicates and spreads across
networks automatically, without requiring user interaction. This distinguishes it
from a virus, which typically requires a host file or user action.


Question 9. What is the primary characteristic of a trojan horse?
A. It self-replicates automatically
B. It disguises itself as legitimate software to trick users into installing it
C. It only affects mobile devices
D. It is a type of firewall

, Rationale: A trojan horse disguises itself as legitimate or useful software to trick
users into installing it. Once installed, it can perform malicious actions such as
stealing data or providing backdoor access.


Question 10. Which type of malware encrypts a victim's files and demands
payment for the decryption key?
A. Spyware
B. Adware
C. Ransomware
D. Rootkit
Rationale: Ransomware encrypts a victim's files and demands payment (ransom)
in exchange for the decryption key. It is a significant and growing threat to
organizations and individuals.


Question 11. What is the primary purpose of spyware?
A. To display advertisements
B. To secretly collect information about a user's activities
C. To encrypt files for ransom
D. To self-replicate across networks
Rationale: Spyware is designed to secretly collect information about a user's
activities, such as browsing habits, keystrokes, and login credentials, without the
user's knowledge or consent.


Question 12. What is a zero-day vulnerability?
A. A vulnerability that is unknown to the software vendor and has no
available patch
B. A vulnerability that has been patched
C. A vulnerability that only affects zero-day-old software
D. A vulnerability that is not exploitable

Document information

Uploaded on
September 25, 2026
Number of pages
48
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$25.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Sold
25
Followers
0
Items
3411
Last sold
1 hour ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions