Pre-Assessment Test questions and
answers
Fundamentals of Information Security
Pre-Assessment Test - correct answer
A. Threat - correct answer Which cybersecurity term is defined as the potential for an attack on a
resource?
A.Threat
B. Vulnerability
C. Risk
D. Impact
A. Port scanner - correct answer Which tool can be used to map devices on a network, along with their
operating system types and versions?
A. Port scanner
B. Stateful firewall
C. Packet filter
D. Packet sniffer
A. SQL injection - correct answer Which web attack is a server-side attack?
A. SQL injection
B. Cross-site scripting
C. Cross-site request forgery
D. Clickjacking
,A. Data in motion - correct answer An organization employs a VPN to safeguard its information. Which
security principle is protected by a VPN?
A. Data in motion
B. Data in storage
C. Data at rest
D. Data in use
A. Interruption - correct answer A malicious hacker was successful in a denial of service (DoS) attack
against an institution's mail server. Fortunately, no data was lost or altered while the server was offline.
Which type of attack is this?
A. Interruption
B. Interception
C. Modification
D. Fabrication
A. Availability - correct answer A company has had several successful denial of service (DoS) attacks on
its email server. Which security principle is being attacked?
A. Availability
B. Confidentiality
C. Integrity
D. Possession
A. File encryption - correct answer A new start-up company has started working on a social networking
website. The company has moved all its source code to a cloud provider and wants to protect this
source code from unauthorized access. Which cyber defense concept should the start-up company use
to maintain the confidentiality of its source code?
A. File encryption
, B. Alarm systems
C. Antivirus software
D. Account permissions
A. Utility - correct answer A company has an annual audit of installed software and data storage
systems. During the audit, the auditor asks how the company's most critical data is used. This
determination helps the auditor ensure that the proper defense mechanisms are in place to protect
critical data. Which principle of the Parkerian hexad is the auditor addressing?
A. Utility
B. Possession
C. Authenticity
D. Integrity
A. SQL injection - correct answer Which web attack is possible due to a lack of input validation?
A. SQL injection
B. Cross-site request forgery
C. Clickjacking
D. Extraneous files
D. Encryption - correct answer Which file action implements the principle of confidentiality from the CIA
triad?
A. Compression
B. Hash
C. Backup
D. Encryption
answers
Fundamentals of Information Security
Pre-Assessment Test - correct answer
A. Threat - correct answer Which cybersecurity term is defined as the potential for an attack on a
resource?
A.Threat
B. Vulnerability
C. Risk
D. Impact
A. Port scanner - correct answer Which tool can be used to map devices on a network, along with their
operating system types and versions?
A. Port scanner
B. Stateful firewall
C. Packet filter
D. Packet sniffer
A. SQL injection - correct answer Which web attack is a server-side attack?
A. SQL injection
B. Cross-site scripting
C. Cross-site request forgery
D. Clickjacking
,A. Data in motion - correct answer An organization employs a VPN to safeguard its information. Which
security principle is protected by a VPN?
A. Data in motion
B. Data in storage
C. Data at rest
D. Data in use
A. Interruption - correct answer A malicious hacker was successful in a denial of service (DoS) attack
against an institution's mail server. Fortunately, no data was lost or altered while the server was offline.
Which type of attack is this?
A. Interruption
B. Interception
C. Modification
D. Fabrication
A. Availability - correct answer A company has had several successful denial of service (DoS) attacks on
its email server. Which security principle is being attacked?
A. Availability
B. Confidentiality
C. Integrity
D. Possession
A. File encryption - correct answer A new start-up company has started working on a social networking
website. The company has moved all its source code to a cloud provider and wants to protect this
source code from unauthorized access. Which cyber defense concept should the start-up company use
to maintain the confidentiality of its source code?
A. File encryption
, B. Alarm systems
C. Antivirus software
D. Account permissions
A. Utility - correct answer A company has an annual audit of installed software and data storage
systems. During the audit, the auditor asks how the company's most critical data is used. This
determination helps the auditor ensure that the proper defense mechanisms are in place to protect
critical data. Which principle of the Parkerian hexad is the auditor addressing?
A. Utility
B. Possession
C. Authenticity
D. Integrity
A. SQL injection - correct answer Which web attack is possible due to a lack of input validation?
A. SQL injection
B. Cross-site request forgery
C. Clickjacking
D. Extraneous files
D. Encryption - correct answer Which file action implements the principle of confidentiality from the CIA
triad?
A. Compression
B. Hash
C. Backup
D. Encryption