Unit 1: Introduction to Security
Cybersecurity · Unit 1 · Paper 1

Introduction to Security unit test

A test on this unit alone, marked as a percentage and a letter grade — for the test your class is actually sitting, rather than for May. Answer everything, then submit once: seeing the answer to question 3 before attempting question 4 makes the final percentage meaningless.

Each paper is built from this unit’s 40 terms and is the same for everyone, so a teacher can assign “Unit 1, Paper 1” and every student sits the identical test. Multiple choice is marked objectively; the written sections you mark yourself against the model answer and rubric.
Suggested time 33 min 30 points0/17 attempted
1

Accounting (auditing)

2

Password best practice

3

Principle of least privilege

4

Authentication factors

5

Separation of duties

6

Spear phishing

7

Risk = likelihood × impact

8

Confidentiality

9

Principles social engineering exploits

10

AI in cybersecurity, both directions

11

Availability

12

Tailgating and piggybacking

Short answer 1. Define or explain: Risk responses

3 pts

Short answer 2. Define or explain: Non-repudiation

3 pts

Short answer 3. Define or explain: Whaling

3 pts

Short answer 4. Define or explain: Social engineering

3 pts

Free response

6 pts

A school district stores student records on a single server. The server runs an operating system version for which the vendor released a patch nine months ago closing a flaw that is known to be exploited in the wild, and the district has not applied it. There are no offline backups.

Define confidentiality, integrity, and availability, and identify which of the three a ransomware attack on this server would most directly damage.

Using this scenario, distinguish among a threat, a vulnerability, and a risk.

Explain how likelihood and impact combine to produce a risk rating, and give a qualitative rating for this situation with justification.

Identify the four standard responses to an identified risk and recommend one for this situation.

Explain the principle of defense in depth and give one example of how it would apply here.

Explain why the statement "we have never had a breach" is not evidence that current controls are adequate.