Each question below shows the correct answer with a full explanation. Use these to build conceptual understanding before attempting a timed quiz.
Security FundamentalsEasy
Q1. What does confidentiality mean in information security?
- A.Data is regularly backed up to remote locations
- B.Data is continuously available to all authorized users
- C.Data is only accessible to authorized individuals✓ Correct
- D.Data remains unmodified and accurately preserved
Explanation
Confidentiality ensures that information is accessible only to those authorized to have access.
Report an error in this question
Security FundamentalsEasy
Q2. What does integrity mean in information security?
- A.Data remains accurate and unaltered during storage and transmission✓ Correct
- B.Data is available 24/7 within enterprise security environments
- C.Data is deleted after use within enterprise security environments
- D.Data is always encrypted regardless of the specific situation or context
Explanation
Integrity ensures that data remains accurate, complete, and unmodified except by authorized users.
Report an error in this question
Security FundamentalsEasy
Q3. What does availability mean in the CIA triad?
- A.Data can be accessed by anyone in security contexts
- B.Data is encrypted within enterprise security environments
- C.Data is stored in the cloud within enterprise security environments
- D.Authorized users can access data and resources when needed✓ Correct
Explanation
Availability ensures that information and resources are accessible to authorized users when needed.
Report an error in this question
Security FundamentalsEasy
Q4. Which of the following is a strong password practice?
- A.Using password123 within enterprise security environments
- B.Using your name as password within enterprise security environments
- C.Using a mix of uppercase, lowercase, numbers, and special characters✓ Correct
- D.Using the same password for all accounts
Explanation
A strong password uses a combination of uppercase and lowercase letters, numbers, and special characters.
Report an error in this question
Security FundamentalsEasy
Q5. What is encryption?
- A.Deleting files permanently within enterprise security environments
- B.Converting data into a coded format to prevent unauthorized access✓ Correct
- C.Compressing files to save space within enterprise security environments
- D.Backing up data to cloud within enterprise security environments
Explanation
Encryption is the process of converting plaintext data into ciphertext using an algorithm and key to prevent unauthorized access.
Report an error in this question
Security FundamentalsEasy
Q6. What is the purpose of a backup?
- A.To encrypt files using established cryptographic standards
- B.To speed up computer processing performance speed
- C.To delete unnecessary files within the data management framework
- D.To create a copy of data for recovery in case of data loss✓ Correct
Explanation
A backup is a copy of data stored separately so it can be restored in case of data loss, corruption, or disaster.
Report an error in this question
Security FundamentalsEasy
Q7. Which of the following is a type of security control?
- A.Gaming control
- B.Preventive control✓ Correct
- C.Marketing control
- D.Advertising control
Explanation
Preventive controls are security measures designed to prevent security incidents from occurring, such as firewalls and access controls.
Report an error in this question
Security FundamentalsEasy
Q8. What is authentication?
- A.Verifying the identity of a user or system✓ Correct
- B.Applying cryptographic ciphers to protect data
- C.Compressing files to reduce disk storage consumption
- D.Architecting and building responsive web applications
Explanation
Authentication is the process of verifying the identity of a user, device, or system before granting access.
Report an error in this question
Security FundamentalsEasy
Q9. What does a password manager do?
- A.Attempts to crack and compromise stored passwords
- B.Broadcasts and shares passwords on public platforms
- C.Permanently removes and erases stored passwords
- D.Securely stores and manages passwords for various accounts✓ Correct
Explanation
A password manager securely stores, generates, and manages passwords for multiple accounts.
Report an error in this question
Security FundamentalsEasy
Q10. Which is an example of 'something you know' in authentication?
- A.Smart card
- B.Retina scan
- C.Password✓ Correct
- D.Fingerprint
Explanation
A password is an example of a knowledge factor (something you know) in authentication.
Report an error in this question
Security FundamentalsMedium
Q11. What is the difference between symmetric and asymmetric encryption?
- A.Symmetric uses two keys, asymmetric uses one across computing environments
- B.There is no difference in any deployment scenario or context
- C.Symmetric is always stronger regardless of the specific situation or context
- D.Symmetric uses one key for both encryption and decryption, asymmetric uses a key pair✓ Correct
Explanation
Symmetric encryption uses a single shared key, while asymmetric encryption uses a public-private key pair.
Report an error in this question
Security FundamentalsMedium
Q12. What is a hash function used for in security?
- A.Applying symmetric ciphers for secure data transfer
- B.Generating a fixed-size output from input data for integrity verification✓ Correct
- C.Generating redundant backup copies of system data
- D.Compressing files to reduce disk storage consumption
Explanation
A hash function produces a fixed-size digest from input data, used to verify data integrity.
Report an error in this question
Security FundamentalsMedium
Q13. Which is an example of a detective security control?
- A.Intrusion Detection System (IDS)✓ Correct
- B.Firewall within enterprise security environments
- C.Data-at-rest symmetric encryption
- D.Access control list in security contexts
Explanation
An IDS is a detective control that monitors network traffic for suspicious activity and alerts administrators.
Report an error in this question
Security FundamentalsMedium
Q14. What is the purpose of an access control list (ACL)?
- A.To define which users or systems are granted access to specific resources✓ Correct
- B.To encrypt data using symmetric cipher algorithms
- C.To compress files for reducing disk storage consumption
- D.To generate comprehensive network topology diagrams
Explanation
An ACL specifies which users or system processes are granted access to objects and what operations are allowed.
Report an error in this question
Security FundamentalsMedium
Q15. What is the difference between identification and authentication?
- A.Neither is used in security within enterprise security environments
- B.They are fundamentally the same thing in security
- C.Identification claims an identity, authentication proves it✓ Correct
- D.Authentication comes before identification
Explanation
Identification is claiming an identity (e.g., entering a username), while authentication is proving that identity (e.g., entering the correct password).
Report an error in this question
Security FundamentalsMedium
Q16. What is a security token in authentication?
- A.A backup device for managing enterprise data resources
- B.A physical or digital device that generates one-time passwords for authentication✓ Correct
- C.A network firewall rule for filtering inbound traffic
- D.A software application used for enterprise computing operations
Explanation
A security token generates time-based or event-based one-time passwords as a second factor of authentication.
Report an error in this question
Security FundamentalsMedium
Q17. What is the purpose of security auditing?
- A.To deploy and install application software across enterprise computing systems
- B.To architect and design new information systems and management
- C.To increase available bandwidth for improved download speeds
- D.To systematically evaluate the security of a system by testing against established criteria✓ Correct
Explanation
Security auditing involves systematically evaluating an organization's security posture against policies, standards, and best practices.
Report an error in this question
Security FundamentalsMedium
Q18. Which security principle involves dividing critical tasks among multiple people?
- A.Need to know
- B.Least privilege
- C.Defense in depth
- D.Separation of duties✓ Correct
Explanation
Separation of duties divides critical tasks among multiple people to prevent fraud and errors.
Report an error in this question
Security FundamentalsMedium
Q19. What is a security baseline?
- A.A next-generation firewall security appliance
- B.A backup schedule for creating regular recovery snapshots
- C.The fastest network speed within enterprise security environments
- D.A minimum set of security controls required for a system✓ Correct
Explanation
A security baseline is a set of minimum security standards that must be applied to systems to ensure consistent protection.
Report an error in this question
Security FundamentalsMedium
Q20. What type of attack targets the availability component of the CIA triad?
- A.Network eavesdropping attack
- B.Denial of Service (DoS)✓ Correct
- C.Spear phishing email attack
- D.Credential data theft attack
Explanation
A DoS attack targets availability by overwhelming a system with traffic, making it unavailable to legitimate users.
Report an error in this question
Security FundamentalsHard
Q21. What is the Bell-LaPadula security model primarily designed to protect?
- A.Confidentiality✓ Correct
- B.Non-repudiation
- C.Integrity
- D.Availability
Explanation
The Bell-LaPadula model enforces confidentiality through 'no read up, no write down' rules for access control.
Report an error in this question
Security FundamentalsHard
Q22. Which security model uses 'no read down, no write up' to protect integrity?
- A.Brewer-Nash
- B.Clark-Wilson
- C.Biba Model✓ Correct
- D.Bell-LaPadula
Explanation
The Biba model protects data integrity using the rules: no read down (simple integrity) and no write up (star integrity property).
Report an error in this question
Security FundamentalsHard
Q23. What is the Clark-Wilson integrity model based on?
- A.Discretionary access control in security contexts
- B.Mandatory access control within enterprise security environments
- C.Well-formed transactions and separation of duties✓ Correct
- D.Role-based access control in security contexts
Explanation
The Clark-Wilson model enforces integrity through well-formed transactions and separation of duties.
Report an error in this question
Security FundamentalsHard
Q24. In security, what is a 'rainbow table'?
- A.A precomputed table for reversing cryptographic hash functions✓ Correct
- B.A type of firewall configuration for security management
- C.A network topology map used in enterprise network infrastructure
- D.A colorful network diagram used in enterprise network infrastructure
Explanation
A rainbow table is a precomputed table of hash values used to reverse cryptographic hash functions, typically for cracking password hashes.
Report an error in this question
Security FundamentalsHard
Q25. What is the purpose of 'salting' in password hashing?
- A.Making passwords taste better within enterprise security environments
- B.Compressing the password within enterprise security environments
- C.Adding random data to the password before hashing to prevent rainbow table attacks✓ Correct
- D.Encrypting the password twice within enterprise security environments
Explanation
Salting adds random data to a password before hashing, ensuring identical passwords produce different hashes.
Report an error in this question
Security FundamentalsHard
Q26. What is the Kerckhoffs principle in cryptography?
- A.Encryption is unnecessary within enterprise security environments
- B.A system should be secure even if everything except the key is public knowledge✓ Correct
- C.Keys should be shared publicly within enterprise security environments
- D.All algorithms should be secret regardless of the specific situation or context
Explanation
Kerckhoffs' principle states that a cryptographic system should be secure even if everything about the system is public knowledge, except the key.
Report an error in this question
Security FundamentalsHard
Q27. What is the difference between DAC and MAC access control models?
- A.MAC allows users to share freely within enterprise security environments
- B.DAC allows owners to set permissions, MAC enforces system-wide policies based on classification labels✓ Correct
- C.They are fundamentally identical concepts with no meaningful differences
- D.DAC is more restrictive than MAC within enterprise security environments
Explanation
DAC lets resource owners determine access, while MAC uses system-enforced policies based on security labels, making MAC more restrictive.
Report an error in this question
Security FundamentalsHard
Q28. Which describes 'security through obscurity'?
- A.Relying on secrecy of implementation rather than sound design for security✓ Correct
- B.Implementing zero trust within enterprise security environments
- C.Using strong encryption within enterprise security environments
- D.Using multiple firewalls within enterprise security environments
Explanation
Security through obscurity relies on keeping implementation secret rather than using fundamentally sound security practices. It is generally considered weak.
Report an error in this question
Security FundamentalsHard
Q29. What is a Common Vulnerability Scoring System (CVSS)?
- A.A cryptographic algorithm used for protecting sensitive data
- B.A standard network communication protocol for data transfer
- C.A type of malware scanner designed for compromising system integrity
- D.A standardized framework for rating the severity of security vulnerabilities✓ Correct
Explanation
CVSS is an open framework for communicating the severity of software vulnerabilities using a numerical score from 0.0 to 10.0.
Report an error in this question
Security FundamentalsHard
Q30. What does TCB (Trusted Computing Base) refer to?
- A.An automated backup solution designed for enterprise-level data recovery and restoration
- B.A physical network cable used for connecting devices within the network infrastructure
- C.The totality of protection mechanisms within a computer system responsible for enforcing security policy✓ Correct
- D.A cloud computing platform used for hosting and managing distributed enterprise workloads
Explanation
The TCB encompasses all hardware, firmware, and software components critical to security, responsible for enforcing the system's security policy.
Report an error in this question