This quiz works best with JavaScript enabled.
Home
>
Unit Viii Information And Communication Technology (Ict)
>
Cyber Security โ Quiz 25
Cyber Security Quiz 25 (10 MCQs)
This set of multiple-choice questions evaluates understanding of Bluetooth security, unsolicited message attacks, and Blue Jacking. It tests knowledge of unauthorized access, data security, and information theft. The material covers cyber threats, types of cyber attacks, personal data protection, and access control mechanisms. It also assesses comprehension of security policies, unauthorized access prevention, and cybersecurity laws.
Quiz Instructions
Select an option to see the correct answer instantly.
1.
When is it okay to share your password with a friend?
A) If your friend promises not to tell anyone.
B) If you change your password right afterward.
C) If it's your best friend.
D) It's never safe to share your password.
Show Answer
Correct Answer:
Correct answer is: (D) It's never safe to share your password.
Exam Relevance:
CISSP, CompTIA Security+, CISA
Difficulty:
Easy
Concept notes:
In cyber security, sharing passwords is considered a significant security risk. Passwords are designed to be unique and confidential to protect personal and sensitive information.
Common Mistakes:
A common misunderstanding is that sharing passwords with trusted individuals is safe. However, even trusted individuals can unintentionally compromise security.
Explanations:
Sharing passwords, even with close friends, can lead to unauthorized access and potential security breaches. Passwords should remain confidential to ensure the integrity and security of personal and sensitive information.
Option Analysis:
Option A:
Sharing a password with a friend, even if they promise not to tell anyone, still poses a security risk.
Option B:
Changing a password after sharing it does not mitigate the risk of unauthorized access that occurred during the period it was shared.
Option C:
Sharing a password with a best friend is still a security risk, as it can lead to unauthorized access and potential breaches.
Option D:
It is never safe to share your password, as it can lead to unauthorized access and potential security breaches.
2.
..... is an attack that sends unsolicited messages to Bluetooth-enabled devices.
A) Intrusion Detection.
B) Blue Jacking.
C) Hardware Vandalism.
D) None of these.
Show Answer
Correct Answer:
Correct answer is: (B) Blue Jacking.
Exam Relevance:
CISSP, CEH, CompTIA Security+
Difficulty:
Easy
Concept notes:
Blue Jacking is a type of attack that involves sending unsolicited messages to Bluetooth-enabled devices.
Common Mistakes:
A common misunderstanding is that Blue Jacking involves hacking or stealing data, but it is primarily about sending unsolicited messages.
Explanations:
Blue Jacking is an attack that sends unsolicited messages to Bluetooth-enabled devices. This type of attack does not involve stealing data or hacking into the device, but rather it is a form of spamming or้ชๆฐ่กไธบใ่ฟ็งๆปๅปไธๆถๅ็ชๅๆฐๆฎๆๅ
ฅไพต่ฎพๅค๏ผ่ๆฏๅ่็่ฎพๅคๅ้ๆช็ป่ฏทๆฑ็ๆถๆฏใ
Option Analysis:
Option A:
Intrusion Detection is a method to identify unauthorized access or malicious activities, not an attack that sends unsolicited messages.
Option B:
Blue Jacking is the correct term for sending unsolicited messages to Bluetooth-enabled devices.
Option C:
Hardware Vandalism involves physically damaging hardware, not sending unsolicited messages.
Option D:
None of these is incorrect because Blue Jacking is a valid term in cybersecurity.
3.
Why is it important to have a screen name or username instead of using your real name online?
A) Because it's more fun.
B) To confuse your friends.
C) To protect your identity.
D) Because everyone does it.
Show Answer
Correct Answer:
Correct answer is: (C) To protect your identity.
Exam Relevance:
CEH, CISSP, CompTIA Security+
Difficulty:
Easy
Concept notes:
Using a screen name or username instead of your real name online helps protect your personal information and privacy.
Common Mistakes:
A common misunderstanding is that using a screen name is just for fun or to confuse friends, but the primary reason is to protect your identity.
Explanations:
Using a screen name or username instead of your real name online is a fundamental practice in cyber security. It helps prevent unauthorized individuals from linking your online activities to your real-world identity, thereby reducing the risk of identity theft, stalking, or other forms of cyber harassment. This practice is essential for maintaining privacy and security in the digital world.
Option Analysis:
Option A:
Using a screen name is not primarily about fun; it is about security and privacy.
Option B:
Confusing friends is not a valid reason for using a screen name. The primary purpose is to protect your identity.
Option C:
This is the correct answer because using a screen name helps protect your identity and personal information online.
Option D:
Following a trend does not justify the use of a screen name. The primary reason is to protect your identity.
4.
Which of the following is considered data theft?
A) Hacking into a system to steal personal information.
B) Sharing files online.
C) Watching films on a computer.
D) Storing data on a USB drive.
Show Answer
Correct Answer:
Correct answer is: (A) Hacking into a system to steal personal information.
Exam Relevance:
CISSP, CompTIA Security+, CEH
Difficulty:
Easy
Concept notes:
Data theft involves unauthorized access to and extraction of sensitive information from a system or network.
Common Mistakes:
A common misunderstanding is that data theft only involves stealing financial information, but it can include any personal or sensitive data.
Explanations:
Hacking into a system to steal personal information is a clear example of data theft. This involves unauthorized access to a system with the intent to extract sensitive data, which is a direct violation of cybersecurity principles.
Option Analysis:
Option A:
This is the correct answer as it involves unauthorized access and theft of personal information.
Option B:
Sharing files online is not inherently data theft unless it involves unauthorized access or sharing of sensitive information.
Option C:
Watching films on a computer is a normal activity and does not involve data theft.
Option D:
Storing data on a USB drive is a common practice and does not constitute data theft unless the data was obtained through unauthorized means.
5.
What do we call the practice of securing a computer system by preventing unauthorized access?
A) Access Control.
B) Security.
C) Encryption.
D) Hacking.
Show Answer
Correct Answer:
Correct answer is: (A) Access Control.
Exam Relevance:
CISSP, CompTIA Security+, CEH
Difficulty:
Easy
Concept notes:
Access control is the practice of securing a computer system by preventing unauthorized access.
Common Mistakes:
A common misunderstanding is that encryption or security in general encompasses all aspects of preventing unauthorized access, but access control specifically refers to the mechanisms and policies that control who can access what resources.
Explanations:
Access control is the practice of securing a computer system by preventing unauthorized access. It involves defining and enforcing policies that determine who can access specific resources and what actions they can perform. This is distinct from encryption, which is the process of converting information into a secure format, and hacking, which is the unauthorized access to or manipulation of computer systems.
Option Analysis:
Option A:
Correct. Access control is the practice of securing a computer system by preventing unauthorized access.
Option B:
Incorrect. Security is a broader term that includes access control, but it is not specific to preventing unauthorized access.
Option C:
Incorrect. Encryption is the process of converting information into a secure format, not specifically preventing unauthorized access.
Option D:
Incorrect. Hacking is the unauthorized access to or manipulation of computer systems, which is the opposite of securing a system.
6.
An international breach of computer security often involves a deliberate act that is against the law
Show Answer
Correct Answer:
Correct answer is: (A) True.
Exam Relevance:
CISSP, CISM, CompTIA Security+
Difficulty:
Easy
Concept notes:
An international breach of computer security often involves a deliberate act that is against the law.
Common Mistakes:
A common misunderstanding is that breaches of computer security are always accidental or unintentional.
Explanations:
An international breach of computer security typically involves unauthorized access, theft, or damage to computer systems and networks across national borders. Such actions are deliberate and often illegal, as they violate laws related to cybersecurity and data protection. Therefore, the statement is true.
Option Analysis:
Option A:
This option correctly identifies that an international breach of computer security is often a deliberate and illegal act.
Option B:
This option incorrectly suggests that an international breach of computer security is not always a deliberate and illegal act.
7.
Someone uses your profile inorder to impersonate you
A) Spam.
B) Rootkit.
C) Spyware.
D) Identity theft.
Show Answer
Correct Answer:
Correct answer is: (D) Identity theft.
Exam Relevance:
CISSP, CompTIA Security+, CEH
Difficulty:
Moderate
Concept notes:
Identity theft involves the unauthorized use of someone's personal information to impersonate them.
Common Mistakes:
A common mistake is confusing identity theft with other forms of cyber attacks like spam, rootkits, or spyware.
Explanations:
Identity theft occurs when someone uses your personal information, such as your profile, to impersonate you. This can include using your social media accounts, financial information, or other personal data to commit fraud or other malicious activities. The other options do not specifically involve impersonation using your profile.
Spam involves unsolicited messages, rootkits are stealthy malware that hide their presence, and spyware is software that secretly monitors a user's activities. None of these directly involve impersonating the user.
Option Analysis:
Option A:
Spam involves sending unsolicited messages, not impersonation.
Option B:
Rootkits are stealthy malware that hide their presence, not impersonation.
Option C:
Spyware is software that secretly monitors activities, not impersonation.
Option D:
Identity theft involves using someone's personal information to impersonate them.
8.
Which of the following is a large scale monetary theft conducted through computer hacking, the online equivalent of the real-world bank heist?
A) Cyber heist.
B) Phishing.
C) Plagiarism.
D) None of these.
Show Answer
Correct Answer:
Correct answer is: (A) Cyber heist.
Exam Relevance:
CISSP, CISM, CEH
Difficulty:
Moderate
Concept notes:
A cyber heist is a large-scale monetary theft conducted through computer hacking, which is the online equivalent of a real-world bank heist.
Common Mistakes:
A common misunderstanding is that phishing is the same as a cyber heist. While phishing is a form of cyber attack, it typically involves tricking individuals into revealing sensitive information, rather than large-scale monetary theft.
Explanations:
A cyber heist involves sophisticated hacking techniques to steal large sums of money from financial institutions or other high-value targets. This is distinct from phishing, which is a method of stealing personal information through deceptive means, and plagiarism, which involves the unauthorized use of someone else's work.
Option Analysis:
Option A:
Correct. A cyber heist is a large-scale monetary theft conducted through computer hacking.
Option B:
Incorrect. Phishing is a method of stealing personal information through deceptive means, not large-scale monetary theft.
Option C:
Incorrect. Plagiarism involves the unauthorized use of someone else's work, not monetary theft.
Option D:
Incorrect. This option is not applicable as one of the other options is correct.
9.
Which of the following is a good practice for Internet safety?
A) Using easy-to-guess passwords.
B) Downloading files from unknown sources.
C) Keeping software and apps updated.
D) Using public Wi-Fi for online banking.
Show Answer
Correct Answer:
Correct answer is: (C) Keeping software and apps updated.
Exam Relevance:
CISSP, CompTIA Security+, CEH
Difficulty:
Easy
Concept notes:
Keeping software and apps updated is a fundamental practice in Internet safety. Updates often include security patches that protect against newly discovered vulnerabilities.
Common Mistakes:
A common misunderstanding is that software updates are only for adding new features, not for security purposes.
Explanations:
Keeping software and apps updated is crucial for Internet safety because updates frequently include security patches that address known vulnerabilities. These patches help protect against potential cyber threats and ensure that the software is secure against the latest attacks.
Option Analysis:
Option A:
Using easy-to-guess passwords is a poor practice as it makes it easier for attackers to gain unauthorized access to accounts.
Option B:
Downloading files from unknown sources can expose devices to malware and other security risks.
Option C:
Keeping software and apps updated is a good practice as it ensures that security vulnerabilities are patched and the software remains secure.
Option D:
Using public Wi-Fi for online banking is risky because public networks can be insecure and may allow attackers to intercept sensitive information.
10.
How can you protect your online accounts?
A) Keep them open.
B) Use simple passwords.
C) Use strong, unique passwords.
D) Share passwords with friends.
Show Answer
Correct Answer:
Correct answer is: (C) Use strong, unique passwords.
Exam Relevance:
CISSP, CompTIA Security+, CISA
Difficulty:
Easy
Concept notes:
Using strong, unique passwords is a fundamental practice in protecting online accounts from unauthorized access.
Common Mistakes:
A common mistake is using simple or reused passwords, which can be easily guessed or cracked by attackers.
Explanations:
Strong, unique passwords are essential because they make it significantly harder for attackers to gain unauthorized access to your accounts. Simple or reused passwords are more vulnerable to attacks such as brute force or dictionary attacks. By using strong, unique passwords, you enhance the security of your online accounts.
Option Analysis:
Option A:
Keeping accounts open increases the risk of unauthorized access.
Option B:
Simple passwords are easily guessable and can be cracked quickly.
Option C:
Strong, unique passwords provide robust protection against unauthorized access.
Option D:
Sharing passwords with others compromises the security of your accounts.
Frequently Asked Questions
What is cyber security?
Cyber security involves protecting systems, networks, and programs from digital attacks, theft, and damage. It encompasses various measures to ensure confidentiality, integrity, and availability of information.
How can I protect my personal information online?
To protect your personal information online, use strong, unique passwords, enable two-factor authentication, and regularly update your software and security patches. Be cautious of unsolicited messages and avoid sharing sensitive data over unsecured networks.
What are some common types of cyber attacks?
Common types of cyber attacks include phishing, malware, ransomware, and denial-of-service attacks. Each type aims to exploit vulnerabilities in systems or deceive users to gain unauthorized access or steal data.
What is the role of access control in cyber security?
Access control is a fundamental aspect of cyber security that restricts access to resources based on user identity and permissions. It helps prevent unauthorized access and ensures that only authorized individuals can access sensitive information.
How do cybersecurity laws impact individuals and organizations?
Cybersecurity laws establish guidelines and requirements for protecting data and preventing cyber attacks. They impact individuals and organizations by mandating security measures, data protection practices, and legal consequences for data breaches and cyber crimes.