CYBR 7300 Midterm Exam Questions with
Correct Answers
Accountability
The access control mechanism that ensures all actions on a system - authorized or
unauthorized - can be attributed to an authenticated identity. Also known as auditability.
(Chapter 1)
Advance-Fee Fraud (AFF)
A form of social engineering, typically conducted via email, in which an organization or
some third party indicates that the recipient is due a large amount of money and needs only a
small advance fee or personal banking info to facilitate the transfer. AKA Nigerian Prince
scam. (Chapter 1)
Advanced Persistent Threat (APT)
A collection of processes, usually directed by a human agent, that targets a specific
organization or individual. (Chapter 1)
assets
an organizational resource that is being protected. Can be logical (e.g. website, software
information, or data); or can be physical (e.g. person, computer system, hardware, or other
tangible objects). Assets, particularly information assets, are the focus of what security efforts
are attempting to protect. (Chapter 1)
Attack
an intentional or unintentional act that can damage or otherwise compromise information and
the systems that support it. AKA threat event. (Chapter 1)
,Authentication
The access control mechanism that requires the validation and verification of an
unauthenticated entity's purported identity. (Chapter 1)
Authorization
The access control mechanism that represents the matching of an authenticated entity to a list
of information assets and corresponding access levels. (Chapter 1)
Availability
An attribute of information that describes how data is accessible and correctly formatted for
use w/o interference or obstruction. (Chapter 1)
Back Door
A malware payload that provides access to a system by bypassing normal access controls. A
back door is also an intentional access control bypass left by a system designer to facilitate
development. AKA trap door or maintenance hook (Chapter 1)
Blackout
A long-term interruption (outage) in electrical power availability (Chapter 1)
Boot Virus
AKA boot-sector virus, a type of virus that targets the boot sector or master boot record
(MBR) of a computer's system hard drive or removable storage media. (Chapter 1)
Brownout
A long-term decrease in the quality of electrical power availability (Chapter 1)
brute-force password attack
,An attempt to guess a password by attempting every possible combination of characters and
numbers in it (Chapter 1)
Clickbait
Content such as e-mail attachments or embedded links crafted to convince unsuspecting users
into clicking them, which results in more Web traffic for the content provider or the
installation of unwanted software or malware. (Chapter 1)
Communications security
The protection of all communications media, technology, and content. (Chapter 1)
Cyber (or computer) security
The protection of computerized information processing systems and the data they contain and
process. The term cybersecurity is relatively new, so its use might be slightly ambiguous in
coming years as the definition gets sorted out. (Chapter 1)
Confidentiality
An attribute of information that describes how data is protected from disclosure or exposure
to unauthorized individuals or systems. (Chapter 1)
Controlling
The process of monitoring progress and making necessary adjustments to achieve desired
goals or objectives. (Chapter 1)
Cracker
A hacker who intentionally removes or bypasses software copyright protection designed to
prevent unauthorized duplication or use. (Chapter 1)
Cracking
, Attempting to reverse-engineer, remove, or bypass a password or other access control
protection, such as the copyright protection on software. See also cracker. (Chapter 1)
Cyberterrorism
The conduct of terrorist activities by online attackers. (Chapter 1)
Cyberwarfare
Formally sanctioned offensive operations conducted by a government or state against
information or systems of another government or state. Sometimes called information
warfare. (Chapter 1)
Denial-of-Service (DoS) Attack
An attack that attempts to overwhelm a computer target's ability to handle incoming
communications, prohibiting legitimate users from accessing those systems. (Chapter 1)
Dictionary Password Attack
A variation of the brute-force password attack that attempts to narrow the range of possible
passwords guessed by using a list of common passwords and possibly including attempts
based on the target's personal information. (Chapter 1)
Disclosure
In infosec, the intentional or unintentional exposure of an information asset to unauthorized
parties. (Chapter 1)
Distributed Denial-of-Service (DDoS)
A DoS attack in which a coordinated stream of requests is launched against a target from
many locations at the same time using bots or zombies. (Chapter 1)
Domain Name Service Cache Poisoning
Correct Answers
Accountability
The access control mechanism that ensures all actions on a system - authorized or
unauthorized - can be attributed to an authenticated identity. Also known as auditability.
(Chapter 1)
Advance-Fee Fraud (AFF)
A form of social engineering, typically conducted via email, in which an organization or
some third party indicates that the recipient is due a large amount of money and needs only a
small advance fee or personal banking info to facilitate the transfer. AKA Nigerian Prince
scam. (Chapter 1)
Advanced Persistent Threat (APT)
A collection of processes, usually directed by a human agent, that targets a specific
organization or individual. (Chapter 1)
assets
an organizational resource that is being protected. Can be logical (e.g. website, software
information, or data); or can be physical (e.g. person, computer system, hardware, or other
tangible objects). Assets, particularly information assets, are the focus of what security efforts
are attempting to protect. (Chapter 1)
Attack
an intentional or unintentional act that can damage or otherwise compromise information and
the systems that support it. AKA threat event. (Chapter 1)
,Authentication
The access control mechanism that requires the validation and verification of an
unauthenticated entity's purported identity. (Chapter 1)
Authorization
The access control mechanism that represents the matching of an authenticated entity to a list
of information assets and corresponding access levels. (Chapter 1)
Availability
An attribute of information that describes how data is accessible and correctly formatted for
use w/o interference or obstruction. (Chapter 1)
Back Door
A malware payload that provides access to a system by bypassing normal access controls. A
back door is also an intentional access control bypass left by a system designer to facilitate
development. AKA trap door or maintenance hook (Chapter 1)
Blackout
A long-term interruption (outage) in electrical power availability (Chapter 1)
Boot Virus
AKA boot-sector virus, a type of virus that targets the boot sector or master boot record
(MBR) of a computer's system hard drive or removable storage media. (Chapter 1)
Brownout
A long-term decrease in the quality of electrical power availability (Chapter 1)
brute-force password attack
,An attempt to guess a password by attempting every possible combination of characters and
numbers in it (Chapter 1)
Clickbait
Content such as e-mail attachments or embedded links crafted to convince unsuspecting users
into clicking them, which results in more Web traffic for the content provider or the
installation of unwanted software or malware. (Chapter 1)
Communications security
The protection of all communications media, technology, and content. (Chapter 1)
Cyber (or computer) security
The protection of computerized information processing systems and the data they contain and
process. The term cybersecurity is relatively new, so its use might be slightly ambiguous in
coming years as the definition gets sorted out. (Chapter 1)
Confidentiality
An attribute of information that describes how data is protected from disclosure or exposure
to unauthorized individuals or systems. (Chapter 1)
Controlling
The process of monitoring progress and making necessary adjustments to achieve desired
goals or objectives. (Chapter 1)
Cracker
A hacker who intentionally removes or bypasses software copyright protection designed to
prevent unauthorized duplication or use. (Chapter 1)
Cracking
, Attempting to reverse-engineer, remove, or bypass a password or other access control
protection, such as the copyright protection on software. See also cracker. (Chapter 1)
Cyberterrorism
The conduct of terrorist activities by online attackers. (Chapter 1)
Cyberwarfare
Formally sanctioned offensive operations conducted by a government or state against
information or systems of another government or state. Sometimes called information
warfare. (Chapter 1)
Denial-of-Service (DoS) Attack
An attack that attempts to overwhelm a computer target's ability to handle incoming
communications, prohibiting legitimate users from accessing those systems. (Chapter 1)
Dictionary Password Attack
A variation of the brute-force password attack that attempts to narrow the range of possible
passwords guessed by using a list of common passwords and possibly including attempts
based on the target's personal information. (Chapter 1)
Disclosure
In infosec, the intentional or unintentional exposure of an information asset to unauthorized
parties. (Chapter 1)
Distributed Denial-of-Service (DDoS)
A DoS attack in which a coordinated stream of requests is launched against a target from
many locations at the same time using bots or zombies. (Chapter 1)
Domain Name Service Cache Poisoning