Introduction to Security unit test
A test on this unit alone, marked as a percentage and a letter grade — for the test your class is actually sitting, rather than for May. Answer everything, then submit once: seeing the answer to question 3 before attempting question 4 makes the final percentage meaningless.
Accounting (auditing)
Password best practice
Principle of least privilege
Authentication factors
Separation of duties
Spear phishing
Risk = likelihood × impact
Confidentiality
Principles social engineering exploits
AI in cybersecurity, both directions
Availability
Tailgating and piggybacking
Short answer 1. Define or explain: Risk responses
3 ptsShort answer 2. Define or explain: Non-repudiation
3 ptsShort answer 3. Define or explain: Whaling
3 ptsShort answer 4. Define or explain: Social engineering
3 ptsFree response
6 ptsA school district stores student records on a single server. The server runs an operating system version for which the vendor released a patch nine months ago closing a flaw that is known to be exploited in the wild, and the district has not applied it. There are no offline backups.
Define confidentiality, integrity, and availability, and identify which of the three a ransomware attack on this server would most directly damage.
Using this scenario, distinguish among a threat, a vulnerability, and a risk.
Explain how likelihood and impact combine to produce a risk rating, and give a qualitative rating for this situation with justification.
Identify the four standard responses to an identified risk and recommend one for this situation.
Explain the principle of defense in depth and give one example of how it would apply here.
Explain why the statement "we have never had a breach" is not evidence that current controls are adequate.