Ebrahim Abdulla
Skip to content
E
Ebrahim Abdulla
Home
Resume
Learning
Blog
Contact Me
Let's talk
Home
Resume
Learning
Blog
Contact Me
Dammam, Saudi Arabia
e.sinan@me.com
Home
/
07 Cybersecurity Foundations Knowledge Check
07 Cybersecurity Foundations Knowledge Check
Cybersecurity Foundations Knowledge Check
36 scored multiple-choice questions. Select one answer per question.
1. Which statement best describes confidentiality?
(Required)
A. Ensuring information remains accurate
B. Preventing unauthorised access or disclosure
C. Keeping systems responsive
D. Restoring data after an outage
2. A user changes a supplier bank account number without approval. Which objective is affected first?
(Required)
A. Integrity
B. Availability
C. Confidentiality
D. Resilience
3. A website remains online but takes ten minutes to load each page. Which objective is affected?
(Required)
A. Confidentiality
B. Availability
C. Integrity
D. Authentication
4. Which control most directly supports availability?
(Required)
A. Load balancing and failover
B. Data masking
C. Digital signing
D. Least privilege
5. Why might a plain hash be insufficient against an active attacker?
(Required)
A. Hashes always reveal the file
B. The attacker might replace both the file and the hash
C. Hashes reduce availability
D. Hashes require public keys
6. A user enters a username. What has occurred?
(Required)
A. Authentication
B. Authorisation
C. Identification
D. Accountability
7. Which activity is authorisation?
(Required)
A. Entering a username
B. Verifying a fingerprint
C. Deciding whether a user may edit a payroll file
D. Reviewing an audit log
8. Which example combines two different authentication factors?
(Required)
A. Password and PIN
B. Password and security key
C. Fingerprint and face scan
D. Two passwords
9. What is privilege creep?
(Required)
A. A slow login process
B. Accumulation of access that is no longer required
C. Encryption-key rotation
D. Increasing password length
10. Which statement about OAuth 2.0 is correct?
(Required)
A. It is primarily an authorisation framework
B. It is a password hashing method
C. It replaces all SSO protocols
D. It is a biometric standard
11. Which document gives high-level management direction?
(Required)
A. Procedure
B. Policy
C. Work log
D. Guideline
12. Which document should define an approved minimum TLS version?
(Required)
A. Standard
B. Guideline
C. Awareness poster
D. Incident ticket
13. Which document should list the steps for disabling a leaver account?
(Required)
A. Policy
B. Procedure
C. Guideline
D. Risk appetite
14. A guideline is normally:
(Required)
A. A legal penalty
B. An optional recommendation
C. A mandatory configuration value
D. A replacement for policy
15. Which feature strengthens exception governance?
(Required)
A. No owner
B. No end date
C. Risk approval, compensating controls and expiry
D. Verbal agreement only
16. Which statement about PCI DSS is correct?
(Required)
A. It is a universal privacy law
B. It is an industry security standard for payment account data
C. It protects patents
D. It applies only to banks
17. Under GDPR, notification to a supervisory authority is generally required within what period where the conditions apply?
(Required)
A. 24 hours
B. 48 hours
C. 72 hours
D. 30 days
18. Which IP right most directly protects a distinctive brand logo?
(Required)
A. Patent
B. Trademark
C. Copyright only
D. Data retention
19. Patent rights are generally:
(Required)
A. Worldwide automatically
B. Territorial and limited in duration
C. Permanent without maintenance
D. Available only for logos
20. What is the main purpose of data minimisation?
(Required)
A. Collect every available field
B. Reduce data to what is needed for the declared purpose
C. Keep data forever
D. Replace all access controls
21. Symmetric encryption normally uses:
(Required)
A. The same secret key for encryption and decryption
B. No keys
C. A public certificate only
D. A hash instead of a cipher
22. Which algorithm is a symmetric block cipher?
(Required)
A. AES
B. RSA
C. ECDSA
D. SHA-256
23. Which key must the owner protect in asymmetric cryptography?
(Required)
A. Public key
B. Private key
C. Certificate serial number
D. Algorithm name
24. Diffie-Hellman is mainly used for:
(Required)
A. Image compression
B. Key agreement
C. Password storage
D. File deletion
25. Why is hybrid encryption common?
(Required)
A. Symmetric encryption is efficient, while asymmetric methods establish trust and keys
B. Hashes are reversible
C. Public keys must remain secret
D. It removes the need for key management
26. A cryptographic hash produces:
(Required)
A. A fixed-length digest
B. A private key
C. Reversible ciphertext
D. A user account
27. A collision occurs when:
(Required)
A. Two different inputs produce the same digest
B. A password expires
C. A public key is shared
D. A file is encrypted twice
28. Which hash should not be selected for modern collision-resistant security uses?
(Required)
A. MD5
B. SHA-256
C. SHA-384
D. SHA-3
29. A digital signature is created using the signer’s:
(Required)
A. Public key
B. Private key
C. Username
D. Password hash
30. What does a digital signature not provide by itself?
(Required)
A. Integrity support
B. Authenticity support
C. Confidentiality
D. Evidence linked to a key holder
31. Which NIST CSF 2.0 function establishes cybersecurity risk strategy, policy, roles and oversight?
(Required)
A. Identify
B. Protect
C. Govern
D. Recover
32. Which standard specifically defines requirements for a Business Continuity Management System?
(Required)
A. ISO/IEC 27001
B. ISO 22301
C. SOC 2
D. NIST FIPS 197
33. Which SOC 2 Trust Services category focuses on whether system processing is complete, valid, accurate, timely and authorised?
(Required)
A. Availability
B. Confidentiality
C. Processing Integrity
D. Privacy
34. Which statement best describes ISO/IEC 27001?
(Required)
A. It is a product-encryption algorithm
B. It defines requirements for a risk-based information security management system
C. It is a privacy law for EU residents
D. It is a penetration-testing method
35. Which statement about SOC 2 is accurate?
(Required)
A. It is an ISO certification
B. It is a government regulation
C. It is an attestation report based on AICPA Trust Services Criteria
D. It replaces an organisation’s risk assessment
36. Which combination best supports recovery from a ransomware outage?
(Required)
A. A longer password and a trademark registration
B. Tested continuity and recovery plans, protected backups and defined recovery priorities
C. A public hash posted beside the encrypted files
D. A single administrator account with unrestricted access
Name
First
Last
Email
CAPTCHA
Δ