Information Security Fundamentals

Covers key information security topics including threat types, cryptography, encryption algorithms, network security, DoS attacks, digital signatures, security controls, penetration testing, and online banking security awareness.

16 Questions Published

Questions

Question 1 Multiple Choice (Single Answer)

Every online banking users should be aware of

  1. Phishing
  2. Key Loggers
  3. HTTPS
  4. All of the above
Question 2 Multiple Choice (Single Answer)

Securing a database application with username/password access controls should be considered:

  1. Sufficient to secure the application
  2. Sufficient only when combined with other controls
  3. Sufficient if the passwords are longer than six characters
  4. Sufficient if none of the users have administrative access
Question 3 Multiple Choice (Single Answer)

What is the first and most important thing an administrator should do prior to beginning a penetration test?

  1. Enable all necessary monitoring systems to track the test.
  2. Obtain all necessary permission to perform the test
  3. Identify system weaknesses
  4. Create a test plan
Question 4 Multiple Choice (Single Answer)

Digital certificate contains which below mention feature?

  1. The certificate expiry date
  2. The principle's private key
  3. The principle's private and public key
  4. None of above
Question 5 Multiple Choice (Single Answer)

Which of the following are considered potential security threats?

  1. Computer Viruses
  2. Loss of data
  3. Unauthorized access
  4. All the above
Question 6 Multiple Choice (Single Answer)

Identify the common digital signature algorithm?

  1. DES
  2. DSA
  3. HMAC
  4. RSA
Question 7 Multiple Choice (Single Answer)

Which statement best describes a denial of service(DoS) attack?

  1. An attack that attempts to overwhelm a network resource to deny legitimate users access to that resource
  2. An attack that generally is not intented to cause permanent damage or loss but often cause inconvenience
  3. An attack that initially appears to come from a legitimate source but will do damage once installed or run on your computer.
  4. None of the Above
Question 8 Multiple Choice (Single Answer)

What are the key security functions of cryptography?

  1. Authenticity, confidentiality, integrity, and non repudiation
  2. Detection, analysis, containment and recovery
  3. Encryption and decryption
  4. Review, identification, substantiation and elimination
Question 9 Multiple Choice (Single Answer)

Which cryptography security function ensures that encrypted data can't be altered without the alteration being detected?

  1. Authenticity
  2. Confidentiality
  3. Integrity
  4. Nonrepudiation
Question 10 Multiple Choice (Single Answer)

Symmetric encryption also known as ......

  1. Private or Secret key encryption
  2. Public key encryption
  3. Both 1 & 2
  4. None of the above
Question 11 Multiple Choice (Single Answer)

Which encryption algorithm is strongest and is being used by US Govt?

  1. DES
  2. Triple DES
  3. AES
  4. None of the above
Question 12 Multiple Choice (Single Answer)

Which of the following should be provided on a server to support encryption?

  1. Firewall
  2. Private key server
  3. Public key server
  4. None of the above
Question 13 Multiple Choice (Single Answer)

The best tactical approach for securing database applications is:

  1. Top down
  2. Bottom up
  3. End-to-end
  4. Across the lifecycle of the application
  5. Using a combination of all of the above
Question 14 Multiple Choice (Single Answer)

Which management protocols send data in clear text?

  1. SNMP
  2. Telnet
  3. FTP
  4. All of the above
Question 15 Multiple Choice (Single Answer)

How do unsecured LANS pose a threat to data confidentiality?

  1. The data is accessible at each network node
  2. They are the easiest target for spoofing attacks
  3. They can only support weak user authentication
  4. Transmitting data over an unsecured LAN allows all uses to access it.
Question 16 Multiple Choice (Single Answer)

The which type of threat is most likely to come from hackers who are highly motivated and technically competent?

  1. External
  2. Internal
  3. Structured
  4. Unstructured