.CSIA FINAL EXAM VERSION 2 QUESTIONS AND
ANSWERS PRACTICE QUESTIONS WITH SOLUTIONS
NEWEST | ALREADY GRADED A+
1. What is the primary purpose of cybersecurity risk management?
A. To eliminate all cyber threats
B. To identify, assess, and reduce risks
C. To increase internet speed
D. To replace security teams
Answer: B. To identify, assess, and reduce risks
Rationale: Cybersecurity risk management focuses on identifying threats,
assessing vulnerabilities, and implementing controls to reduce organizational risk.
2. Which security principle ensures that data is accessible only to authorized
users?
A. Integrity
B. Confidentiality
C. Availability
D. Accountability
Answer: B. Confidentiality
Rationale: Confidentiality protects sensitive information from unauthorized
disclosure.
3. What does the principle of integrity ensure?
A. Systems stay online
B. Data remains accurate and unchanged
,C. Users can access files remotely
D. Data is encrypted
Answer: B. Data remains accurate and unchanged
Rationale: Integrity guarantees that information is not altered improperly.
4. Which attack attempts to overwhelm a system with traffic?
A. Phishing
B. SQL Injection
C. Denial-of-Service
D. Spoofing
Answer: C. Denial-of-Service
Rationale: A DoS attack floods a target with excessive requests, making services
unavailable.
5. Which type of malware demands payment to restore access to files?
A. Worm
B. Trojan
C. Spyware
D. Ransomware
Answer: D. Ransomware
Rationale: Ransomware encrypts data and demands payment for decryption.
6. What is phishing?
A. Encrypting data
B. A social engineering attack to steal information
,C. Updating software
D. Securing wireless networks
Answer: B. A social engineering attack to steal information
Rationale: Phishing tricks victims into revealing sensitive information through
deceptive communication.
7. Which protocol is commonly used for secure web communication?
A. HTTP
B. FTP
C. HTTPS
D. Telnet
Answer: C. HTTPS
Rationale: HTTPS uses encryption through SSL/TLS to secure web traffic.
8. What is multi-factor authentication?
A. Using multiple passwords
B. Combining two or more authentication methods
C. Logging in from different devices
D. Changing passwords monthly
Answer: B. Combining two or more authentication methods
Rationale: MFA strengthens security by requiring multiple forms of verification.
9. Which device filters traffic between networks?
A. Switch
B. Router
, C. Firewall
D. Access Point
Answer: C. Firewall
Rationale: Firewalls monitor and filter incoming and outgoing network traffic.
10.What is the purpose of encryption?
A. To compress files
B. To speed up networks
C. To protect data confidentiality
D. To delete malware
Answer: C. To protect data confidentiality
Rationale: Encryption converts readable data into unreadable ciphertext to
prevent unauthorized access.
11.Which malware can self-replicate without user interaction?
A. Trojan
B. Worm
C. Spyware
D. Adware
Answer: B. Worm
Rationale: Worms spread independently across systems and networks.
12.Which term refers to a weakness in a system?
A. Threat
B. Patch
ANSWERS PRACTICE QUESTIONS WITH SOLUTIONS
NEWEST | ALREADY GRADED A+
1. What is the primary purpose of cybersecurity risk management?
A. To eliminate all cyber threats
B. To identify, assess, and reduce risks
C. To increase internet speed
D. To replace security teams
Answer: B. To identify, assess, and reduce risks
Rationale: Cybersecurity risk management focuses on identifying threats,
assessing vulnerabilities, and implementing controls to reduce organizational risk.
2. Which security principle ensures that data is accessible only to authorized
users?
A. Integrity
B. Confidentiality
C. Availability
D. Accountability
Answer: B. Confidentiality
Rationale: Confidentiality protects sensitive information from unauthorized
disclosure.
3. What does the principle of integrity ensure?
A. Systems stay online
B. Data remains accurate and unchanged
,C. Users can access files remotely
D. Data is encrypted
Answer: B. Data remains accurate and unchanged
Rationale: Integrity guarantees that information is not altered improperly.
4. Which attack attempts to overwhelm a system with traffic?
A. Phishing
B. SQL Injection
C. Denial-of-Service
D. Spoofing
Answer: C. Denial-of-Service
Rationale: A DoS attack floods a target with excessive requests, making services
unavailable.
5. Which type of malware demands payment to restore access to files?
A. Worm
B. Trojan
C. Spyware
D. Ransomware
Answer: D. Ransomware
Rationale: Ransomware encrypts data and demands payment for decryption.
6. What is phishing?
A. Encrypting data
B. A social engineering attack to steal information
,C. Updating software
D. Securing wireless networks
Answer: B. A social engineering attack to steal information
Rationale: Phishing tricks victims into revealing sensitive information through
deceptive communication.
7. Which protocol is commonly used for secure web communication?
A. HTTP
B. FTP
C. HTTPS
D. Telnet
Answer: C. HTTPS
Rationale: HTTPS uses encryption through SSL/TLS to secure web traffic.
8. What is multi-factor authentication?
A. Using multiple passwords
B. Combining two or more authentication methods
C. Logging in from different devices
D. Changing passwords monthly
Answer: B. Combining two or more authentication methods
Rationale: MFA strengthens security by requiring multiple forms of verification.
9. Which device filters traffic between networks?
A. Switch
B. Router
, C. Firewall
D. Access Point
Answer: C. Firewall
Rationale: Firewalls monitor and filter incoming and outgoing network traffic.
10.What is the purpose of encryption?
A. To compress files
B. To speed up networks
C. To protect data confidentiality
D. To delete malware
Answer: C. To protect data confidentiality
Rationale: Encryption converts readable data into unreadable ciphertext to
prevent unauthorized access.
11.Which malware can self-replicate without user interaction?
A. Trojan
B. Worm
C. Spyware
D. Adware
Answer: B. Worm
Rationale: Worms spread independently across systems and networks.
12.Which term refers to a weakness in a system?
A. Threat
B. Patch