STUDY GUIDE 2026/2027 COMPLETE
QUESTIONS WITH VERIFIED CORRECT
ANSWERS ||Already Graded <100%
Scored>
Your organization's network was recently the target of an attack. Fortunately, the
new system you installed took action and refused traffic from the source before
you even had a chance to respond. What system did you install? - ANSWER✓An
intrusion prevention system
The act of scrambling plain text into cyphertext is known as ________. -
ANSWER✓encryption
A strong hash function is designed so that a message cannot be forged that will
result in the same hash as a legitimate message. - ANSWER✓True
An encryption cipher that uses the same key to encrypt and decrypt is called a/an
______. - ANSWER✓asymmetric key
Hashes provide confidentiality and integrity. - ANSWER✓False
An algorithm used for cryptographic purposes is known as a _______. -
ANSWER✓cipher
, __________ corroborates the identity of an entity, whether it is the sender, the
sender's computer, some device, or some information. - ANSWER✓Authentication
The science of breaking through encryption is known as _____. -
ANSWER✓Cryptanalysis
Hashes provide _______, but not _______. - ANSWER✓Integrity, confidentiality
Shovels and Shingles is a small construction company consisting of 12 computers
that have Internet access. The company is concerned that a wily, computer-savvy
competitor will send e-mail messages pretending to be from Shovels and Shingles
to its customers, in an attempt to gather customer information. What encryption
solution best prevents a competitor from successfully impersonating the company?
- ANSWER✓Digital signatures
Backordered Parts is a defense contractor that builds communications parts for the
military. The employees use mostly Web-based applications for parts design and
information sharing. Due to the sensitive nature of the business, Backordered Parts
would like to implement a solution that secures all browser connections to the Web
servers. What encryption solution best meets this company's needs? -
ANSWER✓Elliptic Curve Cryptography (ECC)
We are somewhat limited in our ability to protect which type of data? -
ANSWER✓Data in use
A cybersecurity professional must be proficient with all current laws, both state
and federal, that may apply to the organization he or she works with. -
ANSWER✓False
,FISMA refers to ____. - ANSWER✓Federal Information Security Management
Act of 2002 and Federal Information Security Modernization Act of 2014
What is information security? - ANSWER✓Protecting information and
information systems from unauthorized access, use, disclosure, disruption,
modification, or destruction.
Using the concept of defense in depth we can protect ourselves against someone
using a USB flash drive to remove confidential data from an office space within
our building. - ANSWER✓True
Select the example(s) of identity verification. (Choose all that apply.) -
ANSWER✓SSN
Passport
Birth certificate
Multifactor authentication is the use of more than one authentication method to
access an information system. - ANSWER✓True
Which password below would meet complexity standards? -
ANSWER✓!Q@S#z6ge7Uks1lw3
What is accountability comprised of? - ANSWER✓Authorization
Authentication
, Identification
Access
What document do courts require for admissibility of records? - ANSWER✓Chain
of custody
An employee is charged with fraud, and the company can prove in court that there
are email transactions showing that the employee completed these using a digital
signature. What term is being described? - ANSWER✓Nonrepudiation
What is auditing? - ANSWER✓The primary means to ensure accountability
through technical means
Modification - ANSWER✓Altering a web server config file
Fabrication - ANSWER✓Spoofing emails
Threat - ANSWER✓Something that has potential to cause harm
Vulnerability - ANSWER✓Weaknesses that can be used to harm us
Risk - ANSWER✓Likeliness that something bad will happen
Impact - ANSWER✓The value of the asset is used to assess if a risk is present