0% found this document useful (0 votes)
6 views14 pages

Multiple Choice

The document consists of multiple-choice questions covering various topics related to information security, including threats, security systems, cryptography, and intrusion detection systems. It addresses concepts such as types of attacks, security policies, and the roles of different security components. The questions are designed to assess knowledge on the principles and practices of securing information and systems.

Uploaded by

nhats987650
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
6 views14 pages

Multiple Choice

The document consists of multiple-choice questions covering various topics related to information security, including threats, security systems, cryptography, and intrusion detection systems. It addresses concepts such as types of attacks, security policies, and the roles of different security components. The questions are designed to assess knowledge on the principles and practices of securing information and systems.

Uploaded by

nhats987650
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

UNIT 1

Reading 2
1. ……………. is a category of objects, persons, or other entities that presents a
danger to an asset.
A. Threat C. Risk
B. Security posture D. Vulnerability
2. ……………………….. , 1s a multilayered system that protects the sovereignty
of a
state, its assets, its resources, and its people.
A. Personnel security C. Network security
B. National security D. Physical security
3. Someone casually reading sensitive information not intended for his or her use is
……….
A. intentional attack C. direct attack
B. a passive attack D. active attack
5. Authorized users have ........... to a system, whereas hackers have
……………. to a system.
A. illegal access/ legal access C. lawful/illicit
B. legal access/ illegal access D. B&C are correct
6. ……………… attacks originate from the threat itself. ............. attacks originate
from a compromised system or resource that is malfunctioning or working
under the control of a threat.
A. Direct/Indirect C. B&C are correct
B. Passive/Active D. Indirect/Passive
Reading 3
1. Which critical characteristics of information is the quality or state of being
genuine or original, rather than a reproduction or fabrication?
A. Authenticity C. Accuracy
B. Confidentiality D. Utility
3. The ………………. is the quality or state of having value for some purpose or
end.
A. integrity C. availability
B. utility of information D. A&B are correct
4. ………………….. is the quality or state of ownership or control.
A. The utility of information
B. The availability of information
C. The confidentiality of information
D. The possession of information
6. If a bank teller mistakenly adds or subtracts too much from your account,
…………
A. The value of hash is unchanged.
B. The availability of information is useless.
C. the value of the information is changed.
D. The confidentiality of information is stolen.
Reading 4
1. Many system development projects do not make full use of the ..............
management system’s security capabilities, and in some cases the database is
………….. in ways that are less secure than traditional file systems.
A. database/executed C. A&B are correct
B. database/implemented D. data/implemented
2. Frequently overlooked component of an IS is ............... They are written
instructions for accomplishing a specific task.
A. networks C. software
B. procedures D, database
3. The IS component that created much of the need for increased computer and
information security is .............
A. software C. hardware
B. networking D. data
4. …………. of the IS comprises applications, operating systems, and assorted
command
utilities.
A. The software component C. The network component
B. The hardware component D. A&C are correct
5. Physical security policies deal with .............. as a physical asset and with the
protection of physical assets from harm or theft.
A. software C. spyware
B. adware D. hardware
6. ……….. are often created under the constraints of project management, which
limit time, cost, and manpower.
A. software program C. hardware program
B. spyware program D. adware program
UNIT 2
Reading 1
2. …………. is a well-known and broad category of electronic and human
activities that can breach the confidentiality of information.
A. Trojan Horse C. Espionage or trespass
B. A polymorphic threat D. Worm
4. ………….. is one that over time changes the way it appears to antivirus software
programs, making it undetectable by techniques that look for preconfigured
signatures
A. Trojan Horse C. Virus
B. A polymorphic threat D. Worm
6. Which of the followings is a malicious program that replicates itself constantly,
without requiring another program environment?
A. Black door C. Virus
B. Worm D. Worm Hoax

Reading 2
2. …………… occur when a manufacturer distributes equipment containing a
known or unknown flaw.
A. Technical hardware failures C. Theft
B. inadequate control D. Technological error
5. Large quantities of .............. are written, debugged, published, and sold before
all their bugs are detected and resolved.
A. software C. computer code
B. hardware D. computer language
6………. can present some of the most dangerous threats, because they usually
occur with very little warning and are beyond the control of people.
A. Force majeure C. Forces of nature
B. Acts of God D. All are correct
Reading 3
1. Which of the following attacks is a variation of the brute force attack?
A. Dictionary B. Password crack
C. Back door D. Hoax
2. Devers is any technology that aids in gathering information about a person or
organization without their knowledge and it is placed on a computer to secretly
gather information about the user and report it.
A. Adware B. Denial-of-Service
C. Dictionary D. Spyware
3. …………….. attacks are the most difficult to defend against, and there are
presently no controls that any single organization can apply.
A. Password crack C. DDoS
B .Dictionary D. Back door
4. ………….. belong to the state-of-the-art malicious code attack.
[Link] C. multivector
B. Worm D. All are correct
5. What attack is considered a weapon of mass destruction on the Internet to
use a popular metaphor?
A. DdoS C. Back Door
B. Brute force D. Password Crack
Reading 4
2. ………. explores the contents of a Web browsers ‘s cache and …… a malicious
cookie on the client’s system.
C. Pharming/uses C. A timing attack/ stores
D. Spam/contains D. None is correct
3. ………. can be used both for legitimate network management functions and for
stealing information.
A. Spyware C. Brute force
B. Sniffers D. Dictionary
4. Many organizations attempt to cope with the flood of spam by using email
filtering technologies.
A. to deal with C. keep up with
B. get on well D. put on with
5. Which attacks can be accomplished by exploiting various technical flaws in the
Simple Mail Transport Protocol.
A. Man-the-middle C. Mail Boming
B. Phishing D. Pharming
6 . ………… is an attempt to gain personal or financial information from an
individual, usually by posing as a legitimate entity.
A. Dictionary C. Sniffer
B. Phishing D. Hoax
UNIT 3
Reading 2
1. ………… are stand-alone, self-contained combinations of computing
hardware and software.
A. Firewall appliances B. Firewall architectures
C. Firewall systems D. Firewall software
2. Organizations can install .............. on an existing general purpose computer
system.
A. firewall hardware B. firewall architecture
C. firewall software D. firewall devices
4. Which of the following helps your computer still be safe no matter how hard the
attackers manage?
A. An anti - virus software program B. A strong password
C. A hardware firewall D. SOHO
5. The SOHO firewall serves first as a stateful firewall to enable ........ access.
A. inside-to-outside B. outside-to-inside
C. A&B are correct D. None is correct

Reading 3
1. ……………… combine the packet-filtering router with a separate, dedicated
firewall, such as an application proxy server.
A. Screened host firewalls B. Firewall systems
C. Dual-home host firewalls D. Screen subnet firewalls
5. The benefit of a ............. is its ability to translate between many different
protocols at their respective data link layers.
A. dual-homed host B. screen host
C. SOCKS Server D. screen subnet firewall
Reading 4
1. ………… requires that the filtering rules be developed and installed with the
firewall.
A. dynamic packet-filtering B. Static filtering
C. stateful filtering D. A&B are correct
2. While static filtering firewalls allow entire sets of one type of packet to enter in
response to authorized requests, the ................. allows only a particular packet with
a particular source, destination, and port address to enter.
A. dynamic packet-filtering B. static filtering
C. Stateful filtering D. A&C are correct

UNIT 4
Reading 1
1. Which system combines outputs from multiple sources and uses alarm
filtering techniques to distinguish malicious activity from false alarms?
A. An IDPS system B. A SIEM system
C. An IDP D. A&C are correct
2. To collect attack information in support of an IDPS implementation, you
can begin with .................such as Snort.
A. hardware IDPS B. firmware IDPS
C. a freeware IDPS tool D. software package
3. What is the term IDPS and IPS generally used for?
A. to describe anti-virus programs
B. to describe current anti-intrusion technologies (trùng)
C. to describe IDPS modes
D. to describe current anti-intrusion technologies
Reading 2
1. How many types does NIDS have according to the system interactivity
property? What are they?
A. It has two types: on-line and off-line NIDS
B. It has one: off-line NIDS
C. It has only one: on-line NIDS
D. B&C are correct
2. Why are Network intrusion detection systems placed at a strategic point or
points within the network?
[Link] control traffic to and from all devices on the network.
B. To monitor traffic to and from all devices on the network.
C. To supervise traffic from and to all devices on the network.
D. B&C are correct
4. ................can be also combined with other technologies to increase
detection and prediction rates.
A. HIDS [Link]
C. INN IDS [Link]
5. Why will a HIDS usually go to great lengths?
A. To prevent the object-database, checksum-database
B. To reports from any form of tampering.
C. A&B are correct
D. To detect the object-database, checksum-database

Reading 3
1. By ..................relevant data detected in a session and then using that data to
identify intrusions that involve multiple requests and responses, the IDPS can
better detect specialized, multisession attacks.
A. storing B. switching
C. transmitting D. processing
2. Which of the following IDPS may not suitable if the actions of the users or
systems on a network vary widely, with periods of low activity interspersed with
periods of heavy packet traffic?
A. Stateful Protocol Analysis IDPS B. Signature – Based IDPS
C. Statistical Anomaly-Based IDPS D. None is correct
3. Which of the followings is the approach used IDPSs?
A. The signature-based B. the statistical-anomaly
C. the stateful packet inspection D. All are correct (D)
4. Sometimes a knowledge-based IDPS has got another name. It is ..................
A. signature-based IDPS B. misuse-detection IDPS
C. A&B D. None is correct
5. Behavior-based IDPS collects statistical summaries by ...............traffic
that is known to be normal.
A. Keeping track B. controling
C. observing D. B & C are correct

Reading 4
4. ................... are instrumented with sensitive monitors and event loggers that
detect attempts to access the system and collect information about the potential
attacker’s activities.
[Link] cells B. Honeypots
C. Decoys D. B&C are correct
5. A ................is a honeypot that has been protected so that that it
cannot be easily compromised.
A. decoy B. honeypot
C. lure D. padded cell
UNIT 5
Reading 1
1. Which process needs the key?
A. encryption B. decryption
C. A&B are correct D. recovering the original information
2. What types of attacks are mentioned in the text?
A. Brute force attack B. Ciphertext-only attack
C. Known - plaintext attack D. All above are correct
3. ………….. is to adequately address confidentiality, data integrity,
authentication, and non-repudiation in both theory and practice.
A. fundamental goal of cryptography
B. general object of cryptography
C. basic goal of cryptology
D. general object of cryptanalysis
4. …………. is a service which prevents an entity from denying previous
commitments or actions.
A. Non-repudiation B. Authentication
C. Data integrity D. Confidentiality
6. A service related to verification. This function is for both parties and
information itself is ……………..
A. data integrity B. non-repudiation
C. authentication D. confidentiality
8. Which of the followings is the study of analyzing information systems in order
to study the hidden aspects of the systems?
A. Cryptography B. Cryptology
C. Cryptanalysis D. A&B are correct
Reading 4
1. Which channel is not physically accessible to the adversary?
A. A physically secure channel or secured channel
B. An unsecured channel
C. A sec`ured channel
D. A. secure channel
2. Which role does an adversary attempt to play in a two-way communication?
A. the illegitimate sender or the illegitimate receiver
B. The role of the sender only
C. the legitimate sender or the legitimate receiver
D. The role of the receiver only
3. What is a fundamental premise in cryptography?
A. the set A, C, K {Ee : e K}, {Dd : d K}
B. the sets M, C, K {Ee : e K}, {Dd : d K}
C. Either A or B
D. Both A and B
4. A/An ………….is an entity in a two-party communication which is the
legitimate transmitter of information.
A. sender B. receiver
C. adversary D. channel
5. A/An …………… is an entity in a two-party communication which is the
intended recipient of information.
A. channel B. adversary
C. sender D. receiver
6.………………….. an information security service implies defeating the
objective of the intended service.
A. Transmitting B. Defeating
C. Breaking D. Conveying
7. A/An ………………is an adversary who is capable only of reading
information from an unsecured channel.
A. passive adversary B. active adversary
C. entity D. party
8. A/An ….. is a means of conveying information from one entity to another.
A. adversary B. information security service
C. exhaustive search D. channel
9. An ………….is an adversary who may also transmit, alter, or delete
information on an unsecured channel.
A. passive adversary B. entity
C. active adversary D. party
10.…………………is a method to provide some specific aspects of security.
A. Channel B. Information security service
C. exhaustive search D. Secure channel

UNIT 6
Reading 1
1. Why are hash functions used in password verification systems to confirm the
identity of the user?
A. Because hash functions are mathematical algorithms.
B. Because hash functions are one-way.
C. Because hash functions are publish functions.
D. Because hash functions don’t require the use of key.
4. Which passwords are considered easily to be cracked?
A. Passwords that are dictionary words
B. Passwords that are poorly constructed
C. Passwords that are dictionary words and poorly constructed.
D. Password that are not long enough.
Reading 4 (trang 155)
1. What can the CA do when the user loses the privilege of using keys in the
area of authority?
A. The CA can withdraw the user’s keys.
B. The CA can revoke the user’s keys.
C. A&B are correct
D. A The CA can destroy the user’s keys.
4. The .............by the CA enables secure, encrypted, nonrepudiable e-business
transactions. nen soan lai cau nay
A. policy of certificate B. issuance of certificates
C. mechanisms of certificate D. procedure of certificate

Reading 5 (trang 161)


1. What attacks were used to gain unauthorized access to secure
communications?
A. Brute force attacks B. known-plaintext attacks
C. selected –plaintex attacks D. All are correct
2. Attackers may conduct a ....................by sending potential victims a specific
text that they are sure the victims will forward on to others.
A. known-plaintext attack B. selected-plaintext attack
C. Brute force attack D. A &C are correct
3. ....................have been used to mount successful attacks on block cipher
encryptions such as DES.
A. Differential and linear cryptanalysis C. Frequency analysis
B. Differential cryptanalysis D. Linear cryptanalysis
4. In which attack does the attacker eavesdrop on the victim’s session?
A. In a dictionary attack B. In a correlation attack
C. In a man-in-the middle attack D. In a timing attack

You might also like