A _______ is a program or piece of code that appears harmless but carries a malicious intent.

  • Denial of Service (DoS)
  • Firewall Bypass
  • Trojan Horse
  • Worm
A "Trojan Horse" is a type of malware that disguises itself as a benign program but contains malicious code, named after the Greek myth.

Which of the following best describes an "insider threat"?

  • A malicious actor outside the organization trying to breach security
  • A security breach caused by unintentional employee actions
  • A security measure that guards against external threats
  • A virus or malware designed to infiltrate a network
An "insider threat" refers to a security breach caused by unintentional or malicious actions by employees or individuals with privileged access to the organization's systems. This threat can result from actions like sharing sensitive data, falling victim to phishing attacks, or intentionally causing harm.

An organization's IT department notices that a large volume of files containing sensitive financial data is being uploaded to a cloud storage service. This is against the company's policy. Which system would be best suited to detect and prevent such actions?

  • DLP (Data Loss Prevention) System
  • IDS (Intrusion Detection System)
  • NAT (Network Address Translation)
  • VPN (Virtual Private Network)
A DLP (Data Loss Prevention) system is designed to monitor and protect data while it is in use, in motion, and at rest. It can detect and prevent the unauthorized transfer or sharing of sensitive data, such as financial information, to cloud storage services.

_______ attacks specifically target high-ranking officials within an organization.

  • Botnet
  • DDoS
  • Malware
  • Spear Phishing
Spear Phishing attacks specifically target high-ranking officials within an organization. These attacks are highly targeted, personalized, and often aim to trick executives into revealing sensitive information or taking malicious actions.

What is the primary purpose of a digital signature in electronic documents?

  • Data Compression
  • Data Duplication
  • Data Encryption
  • Ensuring Authenticity
The primary purpose of a digital signature in electronic documents is to ensure authenticity. It provides a way to verify that the document has not been tampered with and that it was indeed signed by the claimed sender. Digital signatures use cryptographic techniques to achieve this.

What is the most common motivation behind insider threats in an organization?

  • Accidental actions
  • Defending against external threats
  • Lack of security measures
  • Personal gain
The most common motivation behind insider threats is personal gain. This can include financial gain, revenge against the organization, or selling sensitive information to third parties. Understanding these motivations is essential for preventing and mitigating insider threats.

A company's incident reporting procedure mandates the use of a specific platform for logging incidents to ensure traceability and accountability. This is an example of what kind of control?

  • Administrative Control
  • Physical Control
  • Preventive Control
  • Technical Control
This is an example of an Administrative Control. Administrative controls are measures and policies put in place to manage and regulate security practices. In this case, mandating the use of a specific platform is an administrative measure to ensure traceability and accountability when logging incidents.

What is the primary purpose of using a Virtual Private Network (VPN)?

  • Browse the web anonymously
  • Improve computer performance
  • Securely connect to a private network
  • Stream high-quality videos
The primary purpose of a VPN is to securely connect to a private network over the internet, ensuring data privacy and security, often used for remote work or accessing sensitive information.

In the context of data protection, what is the primary purpose of data encryption?

  • Data Availability
  • Data Compression
  • Data Confidentiality
  • Data Integrity
The primary purpose of data encryption is Data Confidentiality. It ensures that unauthorized users cannot access or read sensitive data. It transforms the data into an unreadable format, which can only be deciphered with the appropriate decryption key.

Which encryption technique transforms plaintext into ciphertext by applying an algorithm and a key, where the size of the key determines the number of possible transformations?

  • Asymmetric Encryption
  • Hashing
  • Steganography
  • Symmetric Encryption
Symmetric Encryption is a technique where the same key is used for both encryption and decryption. It transforms plaintext into ciphertext using a mathematical algorithm and a secret key. The key size determines the number of possible transformations, which affects the security of the encryption.