Unit 1: Introduction to Security
Cybersecurity · Unit 1 · Paper 1

Introduction to Security unit test

A test on this unit alone, marked as a percentage and a letter grade — for the test your class is actually sitting, rather than for May. Answer everything, then submit once: seeing the answer to question 3 before attempting question 4 makes the final percentage meaningless.

Each paper is built from this unit’s 40 terms and is the same for everyone, so a teacher can assign “Unit 1, Paper 1” and every student sits the identical test. Multiple choice is marked objectively; the written sections you mark yourself against the model answer and rubric.
Suggested time 33 min 30 points0/17 attempted
1

Accounting (auditing)

2

Password best practice

3

Principle of least privilege

4

Authentication factors

5

Separation of duties

6

Spear phishing

7

Risk = likelihood × impact

8

Confidentiality

9

Principles social engineering exploits

10

AI in cybersecurity, both directions

11

Availability

12

Tailgating and piggybacking

Short answer 1. Define or explain: Risk responses

3 pts

Short answer 2. Define or explain: Non-repudiation

3 pts

Short answer 3. Define or explain: Whaling

3 pts

Short answer 4. Define or explain: Social engineering

3 pts

Free response

6 pts

This course has no free-response prompt tagged to this unit, so one from elsewhere in the course is used. It is still worth writing — the skill transfers.

A small company stores customer passwords so that its help desk can read them back to callers who forget them. The database is encrypted at rest, and the decryption key is stored in a file on the same server. (a) Explain why storing passwords in a recoverable form is a design error, regardless of the encryption used. (b) Describe what the company should store instead, and explain the role of a salt. (c) Explain why encrypting the database provides little protection given where the key is stored. (d) The help desk still needs a way to assist users who forget passwords. Describe a secure alternative and explain why it does not require recovering the original password.