Cybersecurity Foundations Knowledge Check

36 scored multiple-choice questions. Select one answer per question.

1. Which statement best describes confidentiality?(Required)
2. A user changes a supplier bank account number without approval. Which objective is affected first?(Required)
3. A website remains online but takes ten minutes to load each page. Which objective is affected?(Required)
4. Which control most directly supports availability?(Required)
5. Why might a plain hash be insufficient against an active attacker?(Required)
6. A user enters a username. What has occurred?(Required)
7. Which activity is authorisation?(Required)
8. Which example combines two different authentication factors?(Required)
9. What is privilege creep?(Required)
10. Which statement about OAuth 2.0 is correct?(Required)
11. Which document gives high-level management direction?(Required)
12. Which document should define an approved minimum TLS version?(Required)
13. Which document should list the steps for disabling a leaver account?(Required)
14. A guideline is normally:(Required)
15. Which feature strengthens exception governance?(Required)
16. Which statement about PCI DSS is correct?(Required)
17. Under GDPR, notification to a supervisory authority is generally required within what period where the conditions apply?(Required)
18. Which IP right most directly protects a distinctive brand logo?(Required)
19. Patent rights are generally:(Required)
20. What is the main purpose of data minimisation?(Required)
21. Symmetric encryption normally uses:(Required)
22. Which algorithm is a symmetric block cipher?(Required)
23. Which key must the owner protect in asymmetric cryptography?(Required)
24. Diffie-Hellman is mainly used for:(Required)
25. Why is hybrid encryption common?(Required)
26. A cryptographic hash produces:(Required)
27. A collision occurs when:(Required)
28. Which hash should not be selected for modern collision-resistant security uses?(Required)
29. A digital signature is created using the signer’s:(Required)
30. What does a digital signature not provide by itself?(Required)
31. Which NIST CSF 2.0 function establishes cybersecurity risk strategy, policy, roles and oversight?(Required)
32. Which standard specifically defines requirements for a Business Continuity Management System?(Required)
33. Which SOC 2 Trust Services category focuses on whether system processing is complete, valid, accurate, timely and authorised?(Required)
34. Which statement best describes ISO/IEC 27001?(Required)
35. Which statement about SOC 2 is accurate?(Required)
36. Which combination best supports recovery from a ransomware outage?(Required)
Name