Test your basic knowledge |

Information Security

Subject : it-skills
Instructions:
  • Answer 50 questions in 15 minutes.
  • If you are not ready to take this test, you can study here.
  • Match each statement with the correct term.
  • Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.

This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. A ____ is designed to separate a nonsecured area from a secured area.






2. The ____ attack will slightly alter dictionary words by adding numbers to the end of the password - spelling words backward - slightly misspelling words - or including special characters such as @ - $ - ! - or %.






3. A user or a process functioning on behalf of the user that attempts to access an object is known as the ____.






4. The protection of information from accidental or intentional misuse by persons inside or outside an organization






5. Attacker sets up a rogue DNS server that responds to legitimate requests with IP addresses for malicious or non-existent websites.






6. Keeps a record of the state of a connection between an internal computer and an external device and then makes decisions based on the connection as well as the conditions.






7. A list of statements used by a router to permit or deny the forwarding of traffic on a network based on one or more criteria.






8. A ____ encrypts all data that is transmitted between the remote device and the network.






9. A ____ is a computer program or a part of a program that lies dormant until it is triggered by a specific logical event.






10. Scrambles information into an alternative form that requires a key or password to decrypt the information






11. A key encryption technique for wireless networks that uses keys both to authenticate network clients and to encrypt data in transit.






12. A ____ is a series of instructions that can be grouped together as a single command and are often used to automate a complex set of tasks or a repeated series of tasks.






13. A framework for transporting authentication protocols instead of the authentication protocol itself.






14. ____ involves horizontally separating words - although it is still readable by the human eye.






15. Malicious or accidental threats by employees. (ex. door to secure building left propped open.)






16. A threat that originates from outside the company. (ex. power failure.)






17. A firewall capable of monitoring a data stream from end to end.






18. Forging of the return address on an e-mail so that the e-mail message appears to come from someone other than the actual sender. This is not a virus but rather a way by which virus authors conceal their identities as they send out viruses.






19. A security attack in which an internet user sends commands to another internet user's machine that cause the screen to fill with garbage characters. A flashing attack causes the user to terminate her session.






20. If a password is communicated across a network to log on to a remote system - it is vulnerable to ______.






21. Mass mailings sent as Instant Messages to users. Often these can feature links to explicit porn sites.






22. The ____ model is the least restrictive.






23. A person who uses his knowledge of operating systems and utilities to intentionally damage or destroy data or systems.






24. Countless requests for a TCP connection sent to an FTP server - web server - or system attached to the internet.






25. If a user typically accesses his bank's Web site from his home computer on nights and weekends - then this information can be used to establish a ____ of typical access.






26. An authentication system developed by the Massachusetts Institute of Technology (MIT) and used to verify the identity of networked users.






27. A database - organized as a hierarchy or tree - of the name of each site on the Internet and its corresponding IP number.






28. Although brute force and dictionary attacks were once the primary tools used by attackers to crack an encrypted password - today attackers usually prefer ____.






29. How many past backups you keep - what you did on your machine etc.






30. An attack that intercepts legitimate communication between two victims and captures - analyzes and possibly alters the data packets before sending a fake reply.






31. In the context of SSL encryption - a message issued from the client to the server that contains information about what level of security the client's browser is capable of accepting and what type of encryption the client's browser can decipher (for e






32. An attack that sends unsolicited messages to Bluetooth-enabled devices.






33. Requires mutual authentication used for WLAN encryption using Cisco client software.






34. An operating system that has been reengineered so that it is designed to be secure from the ground up is known as a ____.






35. An AP that is set up by an attacker.






36. When a device receives a beacon frame from an AP - the device then sends a frame known as a ____ frame to the AP.






37. Sending high volumes of UDP requests to a target.






38. A standard that provides a predefined framework for hardware and software developers who need to implement access control in their devices or applications.






39. Form of phishing that targets wealthy individuals.






40. An authentication protocol that operates over PPP and that requires the authenticator to take the first step by offering the other computer a challenge. The requestor responds by combining the challenge with its password - encrypting the new string o






41. In a ____ infection - a virus injects itself into the program's executable code instead of at the end of the file.






42. A random string of text issued from one computer to another in some forms of authentication. It is used - along with the password (or other credential) - in a response to verify the computer's credentials.






43. Requires that if the fraudulent application of a process could potentially result in a breach of security - then the process should be divided between two or more individuals.






44. A program or device that can monitor data traveling over a network. Sniffers can show - all the data being transmitted over a network - including passwords and sensitive information - tends to be a favorite weapon in the hacker's arsenal






45. It accepts spoken words for input as if they had been typed on the keyboard.






46. An independently rotating large cups affixed to the top of a fence prevent the hands of intruders from gripping the top of a fence to climb over it.






47. Use multiple infrared beams that are aimed across a doorway and positioned so that as a person walks through the doorway some beams are activated.






48. A technique for crashing by sending too much data to the buffer in a comuter's memory






49. Magnetic tape drives - hard drives - optical media (CD or DVD) - solid-state media (flash drives or SD)






50. Hurricanes - tornadoes - flooding and earthquakes are all examples of this.