CSIA 350 Quiz 5 Submission | Questions
and Answers | 2026/2027 Update |
100% Correct – UMGC.
1. What is the primary goal of Information Security?
A. To maximize system uptime
B. To protect the Confidentiality, Integrity, and Availability (CIA) of information
C. To ensure compliance with all government regulations
D. To prevent all hacker attacks
B. To protect the Confidentiality, Integrity, and Availability (CIA) of
information
The CIA Triad is the foundational model for information security.
Confidentiality ensures data is only accessible to authorized users, Integrity
ensures data is accurate and unaltered, and Availability ensures data and systems
are accessible when needed. While uptime, compliance, and attack prevention are
important, they are sub-goals of the main objective of protecting the CIA of
information.
2. Which of the following is a core principle of the CIA Triad?
A. Non-repudiation
B. Authentication
C. Confidentiality
D. Authorization
C. Confidentiality
Confidentiality is one of the three core pillars of the CIA Triad, along with
Integrity and Availability. Non-repudiation, authentication, and authorization are
important security concepts, but they are not the three foundational principles of
the triad itself.
,3. The principle of "least privilege" states that:
A. Users should have the minimum level of access necessary to perform their job
functions.
B. All users should have the same level of access to simplify administration.
C. Only administrators should have access to sensitive data.
D. Access should be granted based on seniority within the company.
A. Users should have the minimum level of access necessary to perform
their job functions.
The principle of least privilege is a fundamental security concept that limits
user access rights to only what is required to complete their assigned tasks. This
reduces the attack surface and minimizes the potential damage from an accident
or a compromised account. Giving everyone the same access or basing it on
seniority violates this principle.
4. What is the primary purpose of a firewall?
A. To encrypt data at rest
B. To filter network traffic based on a set of rules
C. To scan for viruses on a host system
D. To provide secure remote access
B. To filter network traffic based on a set of rules
A firewall acts as a barrier between a trusted internal network and untrusted
external networks (like the internet). Its main function is to monitor and control
incoming and outgoing network traffic based on predetermined security rules.
Encryption, antivirus scanning, and remote access are functions of other security
tools.
5. Which type of malware is designed to spread from system to system without
any user interaction?
A. Trojan Horse
B. Worm
C. Virus
D. Ransomware
, B. Worm
A worm is a standalone malware program that replicates itself to spread to
other computers, typically over a network, without needing a host program or
user action. A virus needs a host file and often user action to spread. A Trojan
Horse disguises itself as legitimate software, and ransomware is a type of malware
that encrypts files and demands payment.
6. An attack that involves overwhelming a server with a flood of traffic to make
it unavailable is known as a:
A. Man-in-the-Middle (MitM) attack
B. SQL Injection
C. Denial-of-Service (DoS) attack
D. Phishing attack
C. Denial-of-Service (DoS) attack
A Denial-of-Service (DoS) attack aims to make a machine or network resource
unavailable to its intended users by overwhelming it with illegitimate requests or
traffic. A MitM attack intercepts communication, SQL injection targets databases,
and phishing targets users via deceptive messages.
7. What is the primary function of the Advanced Encryption Standard (AES)?
A. Hashing passwords
B. Creating digital signatures
C. Symmetric-key encryption
D. Asymmetric-key encryption
C. Symmetric-key encryption
AES is a widely used symmetric-key encryption algorithm, meaning it uses the
same key for both encryption and decryption. It is not a hashing algorithm (like
SHA-256), nor is it an asymmetric algorithm (like RSA). Digital signatures are
typically created using asymmetric cryptography.
8. Which protocol provides secure, encrypted communication over the internet,
primarily for web traffic?
A. HTTP
, B. FTP
C. HTTPS
D. Telnet
C. HTTPS
HTTPS (Hypertext Transfer Protocol Secure) is the secure version of HTTP. It
uses TLS/SSL to encrypt the communication between a web browser and a web
server, ensuring confidentiality and integrity. HTTP, FTP, and Telnet are all insecure
protocols that transmit data in plaintext.
9. The process of verifying a user's claimed identity is called:
A. Authorization
B. Auditing
C. Authentication
D. Accounting
C. Authentication
Authentication is the process of verifying that a user is who they claim to be
(e.g., via password, biometrics). Authorization determines what an authenticated
user is allowed to do. Auditing and accounting are related to logging and tracking
user activity for review.
10. What is a "zero-day" vulnerability?
A. A vulnerability that has been known for zero days and is immediately patched.
B. A flaw in software that is unknown to the vendor and has no available patch.
C. A vulnerability that is only exploitable on the day it is announced.
D. An attack that takes zero days to execute.
B. A flaw in software that is unknown to the vendor and has no available
patch.
A zero-day vulnerability is a security flaw in software that is unknown to the
party responsible for patching it. Because the vendor is unaware of the flaw, there
is no patch or mitigation available, making it a significant threat. The term "zero-
day" refers to the fact that the vendor has had "zero days" to fix it since they were
made aware.
and Answers | 2026/2027 Update |
100% Correct – UMGC.
1. What is the primary goal of Information Security?
A. To maximize system uptime
B. To protect the Confidentiality, Integrity, and Availability (CIA) of information
C. To ensure compliance with all government regulations
D. To prevent all hacker attacks
B. To protect the Confidentiality, Integrity, and Availability (CIA) of
information
The CIA Triad is the foundational model for information security.
Confidentiality ensures data is only accessible to authorized users, Integrity
ensures data is accurate and unaltered, and Availability ensures data and systems
are accessible when needed. While uptime, compliance, and attack prevention are
important, they are sub-goals of the main objective of protecting the CIA of
information.
2. Which of the following is a core principle of the CIA Triad?
A. Non-repudiation
B. Authentication
C. Confidentiality
D. Authorization
C. Confidentiality
Confidentiality is one of the three core pillars of the CIA Triad, along with
Integrity and Availability. Non-repudiation, authentication, and authorization are
important security concepts, but they are not the three foundational principles of
the triad itself.
,3. The principle of "least privilege" states that:
A. Users should have the minimum level of access necessary to perform their job
functions.
B. All users should have the same level of access to simplify administration.
C. Only administrators should have access to sensitive data.
D. Access should be granted based on seniority within the company.
A. Users should have the minimum level of access necessary to perform
their job functions.
The principle of least privilege is a fundamental security concept that limits
user access rights to only what is required to complete their assigned tasks. This
reduces the attack surface and minimizes the potential damage from an accident
or a compromised account. Giving everyone the same access or basing it on
seniority violates this principle.
4. What is the primary purpose of a firewall?
A. To encrypt data at rest
B. To filter network traffic based on a set of rules
C. To scan for viruses on a host system
D. To provide secure remote access
B. To filter network traffic based on a set of rules
A firewall acts as a barrier between a trusted internal network and untrusted
external networks (like the internet). Its main function is to monitor and control
incoming and outgoing network traffic based on predetermined security rules.
Encryption, antivirus scanning, and remote access are functions of other security
tools.
5. Which type of malware is designed to spread from system to system without
any user interaction?
A. Trojan Horse
B. Worm
C. Virus
D. Ransomware
, B. Worm
A worm is a standalone malware program that replicates itself to spread to
other computers, typically over a network, without needing a host program or
user action. A virus needs a host file and often user action to spread. A Trojan
Horse disguises itself as legitimate software, and ransomware is a type of malware
that encrypts files and demands payment.
6. An attack that involves overwhelming a server with a flood of traffic to make
it unavailable is known as a:
A. Man-in-the-Middle (MitM) attack
B. SQL Injection
C. Denial-of-Service (DoS) attack
D. Phishing attack
C. Denial-of-Service (DoS) attack
A Denial-of-Service (DoS) attack aims to make a machine or network resource
unavailable to its intended users by overwhelming it with illegitimate requests or
traffic. A MitM attack intercepts communication, SQL injection targets databases,
and phishing targets users via deceptive messages.
7. What is the primary function of the Advanced Encryption Standard (AES)?
A. Hashing passwords
B. Creating digital signatures
C. Symmetric-key encryption
D. Asymmetric-key encryption
C. Symmetric-key encryption
AES is a widely used symmetric-key encryption algorithm, meaning it uses the
same key for both encryption and decryption. It is not a hashing algorithm (like
SHA-256), nor is it an asymmetric algorithm (like RSA). Digital signatures are
typically created using asymmetric cryptography.
8. Which protocol provides secure, encrypted communication over the internet,
primarily for web traffic?
A. HTTP
, B. FTP
C. HTTPS
D. Telnet
C. HTTPS
HTTPS (Hypertext Transfer Protocol Secure) is the secure version of HTTP. It
uses TLS/SSL to encrypt the communication between a web browser and a web
server, ensuring confidentiality and integrity. HTTP, FTP, and Telnet are all insecure
protocols that transmit data in plaintext.
9. The process of verifying a user's claimed identity is called:
A. Authorization
B. Auditing
C. Authentication
D. Accounting
C. Authentication
Authentication is the process of verifying that a user is who they claim to be
(e.g., via password, biometrics). Authorization determines what an authenticated
user is allowed to do. Auditing and accounting are related to logging and tracking
user activity for review.
10. What is a "zero-day" vulnerability?
A. A vulnerability that has been known for zero days and is immediately patched.
B. A flaw in software that is unknown to the vendor and has no available patch.
C. A vulnerability that is only exploitable on the day it is announced.
D. An attack that takes zero days to execute.
B. A flaw in software that is unknown to the vendor and has no available
patch.
A zero-day vulnerability is a security flaw in software that is unknown to the
party responsible for patching it. Because the vendor is unaware of the flaw, there
is no patch or mitigation available, making it a significant threat. The term "zero-
day" refers to the fact that the vendor has had "zero days" to fix it since they were
made aware.