Test your basic knowledge |

Information Security

Subject : it-skills
Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. The protection of information from accidental or intentional misuse by persons inside or outside an organization






2. Indicates when an account is no longer active.






3. If a password is communicated across a network to log on to a remote system - it is vulnerable to ______.






4. Can also capture transmissions that contain passwords.






5. A secret combination of letters - numbers - and/or characters that only the user should know.






6. A password-protected and encrypted file that holds an individual's identification information - including a public key and a private key. The individual's public key is used to verify the sender's digital signature - and the private key allows the in






7. A ____ is a set of software tools used by an attacker to hide the actions or presence of other types of malicious software - such as Trojans - viruses - or worms.






8. To create a rainbow table - each ____ begins with an initial password that is encrypted.






9. A hacker who exposes security flaws in applications and operating systems so manufacturers can fix them before they become widespread problems.






10. The time it takes for a key to be pressed and then released.






11. An independently rotating large cups affixed to the top of a fence prevent the hands of intruders from gripping the top of a fence to climb over it.






12. ____ IP addresses are IP addresses that are not assigned to any specific user or organization.






13. An authentication service commonly used on UNIX devices that communicates by forwarding user authentication information to a centralized server.






14. How many past backups you keep - what you did on your machine etc.






15. Users who access a Web server are usually restricted to the ____ directory.






16. Hides inside other software - usually as an attachment or a downloadable file






17. How often you perform your backups (cost-benefit analysis of backing up)






18. A standard that provides a predefined framework for hardware and software developers who need to implement access control in their devices or applications.






19. The signal from an ID badge is detected as the owner moves near a ____ - which receives the signal.






20. A person who uses his knowledge of operating systems and utilities to intentionally damage or destroy data or systems.






21. The action that is taken by the subject over the object is called a ____.






22. These attacks may allow an attacker to construct LDAP statements based on user input statements.






23. Forging of the return address on an e-mail so that the e-mail message appears to come from someone other than the actual sender. This is not a virus but rather a way by which virus authors conceal their identities as they send out viruses.






24. Magnetic tape drives - hard drives - optical media (CD or DVD) - solid-state media (flash drives or SD)






25. A method for confirming users' identities






26. A user under Role Based Access Control can be assigned only one ____.






27. An authentication protocol that operates over PPP and that requires the authenticator to take the first step by offering the other computer a challenge. The requestor responds by combining the challenge with its password - encrypting the new string o






28. Set of rules that allow or deny traffic






29. Attack computer systems by transmitting a virus hoax - with a real virus attached. By masking the attack in a seemingly legitimate message - unsuspecting users more readily distribute the message and send the attack on to their co-workers and friends






30. Using one's social skills to trick people into revealing access credentials or other information valuable to the attacker. <dumpster diving - or looking through people's trash - etc>






31. A ____ encrypts all data that is transmitted between the remote device and the network.






32. In the context of SSL encryption - a message issued from the client to the server that contains information about what level of security the client's browser is capable of accepting and what type of encryption the client's browser can decipher (for e






33. A form of filtering that blocks only sites specified as harmful.






34. A ____ can block malicious content in "real time" as it appears without first knowing the URL of a dangerous site.






35. A ____ is a series of instructions that can be grouped together as a single command and are often used to automate a complex set of tasks or a repeated series of tasks.






36. A variety of threats such as viruses - worms - and Trojan horses






37. Sending high volumes of UDP requests to a target.






38. ____ is an image spam that is divided into multiple images.






39. The ____ attack will slightly alter dictionary words by adding numbers to the end of the password - spelling words backward - slightly misspelling words - or including special characters such as @ - $ - ! - or %.






40. The set of letters - symbols - and characters that make up the password are known as a ____ set.






41. Countless requests for a TCP connection sent to an FTP server - web server - or system attached to the internet.






42. ____ involves horizontally separating words - although it is still readable by the human eye.






43. ____ uses "speckling" and different colors so that no two spam e-mails appear to be the same.






44. Can be used to determine whether new IP addresses are attempting to probe the network.






45. Legitimate users who purposely or accidentally misuse their access to the environment and cause some kind of business-affecting incident <tell people passwords - etc>






46. A ____ is a computer program or a part of a program that lies dormant until it is triggered by a specific logical event.






47. A system of security tools that is used to recognize and identify data that is critical to the organization and ensure that it is protected.






48. Considered a more "real world" access control than the other models because the access is based on a user's job function within an organization.






49. ____ is an attack in which an attacker attempts to impersonate the user by using his session token.






50. ____ can be prewired for electrical power as well as wired network connections.