What would be the primary objective of a whaling attack?

  • Extract personal information from random individuals
  • Gain access to sensitive company data
  • Impersonate a specific individual
  • Target a large number of individuals
The primary objective of a whaling attack is to impersonate a specific individual, usually a high-ranking executive or influential person within an organization. Attackers aim to deceive others into believing they are this individual to gain access to sensitive information or resources.

When an attacker introduces malicious code into a software system, causing it to behave in unintended ways, this is known as what?

  • Code Injection
  • Exploiting a Vulnerability
  • Malware Injection
  • Software Compromise
Code Injection occurs when an attacker inserts malicious code into a software system, leading to unintended and potentially harmful behavior.

When setting up a home wireless network, which feature allows devices to connect to the network without entering a password, but has potential security risks?

  • MAC Address Filtering
  • WEP (Wired Equivalent Privacy)
  • WPA3
  • WPS (Wi-Fi Protected Setup)
WPS allows easy device connection but poses security risks. Attackers can exploit it. Other methods like WPA3 are more secure for home networks.

What is the primary purpose of an incident reporting procedure in an organization?

  • To assign blame
  • To improve system performance
  • To prevent all incidents
  • To identify and address security incidents
The primary purpose of an incident reporting procedure in an organization is to identify and address security incidents. This process is essential for recognizing and responding to events that could potentially harm the organization's information security. Incident reporting helps in containment and recovery, minimizing the impact of security breaches.

Which method is commonly used by organizations to test the effectiveness of their security awareness training?

  • Firewall configurations
  • Phishing simulations
  • Social engineering
  • Virtual private networks (VPNs)
Phishing simulations are commonly used by organizations to test the effectiveness of their security awareness training. They simulate phishing attacks to see how well employees can recognize and respond to phishing attempts.

In a PKI (Public Key Infrastructure) system, the private key is used to _______ a message, while the public key is used to _______ it.

  • Encode, Decode
  • Encrypt, Decrypt
  • Hash, Validate
  • Sign, Verify
In a PKI system, the private key is used to sign a message, providing proof of the sender's identity and ensuring data integrity. The public key is used to verify the signature, allowing recipients to confirm the sender's identity and data authenticity.

What mechanism does IPsec use to ensure data integrity and confidentiality at the same time?

  • AH (Authentication Header)
  • ESP (Encapsulating Security Payload)
  • PPTP (Point-to-Point Tunneling Protocol)
  • SSL (Secure Sockets Layer)
IPsec uses ESP, the Encapsulating Security Payload, to provide both data integrity and confidentiality. ESP encapsulates the original packet and adds encryption and integrity checks.

A process in which an operating system ensures that an application only accesses the resources necessary for its legitimate purpose is called what?

  • Clustering
  • Multithreading
  • Sandboxing
  • Virtualization
The process in which an operating system ensures that an application only accesses the resources necessary for its legitimate purpose is called "Sandboxing." Sandboxing is a security mechanism that isolates applications, preventing them from making unauthorized changes to a system or accessing resources they shouldn't. It enhances security by containing potentially harmful processes.

Which of the following best describes a "zero-day" vulnerability?

  • A vulnerability known for zero days
  • A vulnerability that's been exploited zero times
  • A vulnerability that's undisclosed to the vendor
  • A vulnerability with no known exploits
A "zero-day" vulnerability is one that's undisclosed to the software or hardware vendor, meaning there are no patches or fixes available. It's called "zero-day" because it's effectively day zero of the vendor's awareness.

Which of the following is a primary goal of operating system hardening?

  • Enhancing security by reducing vulnerabilities
  • Expanding network connectivity
  • Increasing system performance
  • Simplifying user interfaces
The primary goal of operating system hardening is to enhance security by reducing vulnerabilities. This involves configuring the OS to minimize potential attack vectors and make it more resistant to security threats and exploits.