Unit 1: Introduction to Security
Cybersecurity · Unit 1 · Paper 2

Introduction to Security unit test

A test on this unit alone, marked as a percentage and a letter grade — for the test your class is actually sitting, rather than for May. Answer everything, then submit once: seeing the answer to question 3 before attempting question 4 makes the final percentage meaningless.

Each paper is built from this unit’s 40 terms and is the same for everyone, so a teacher can assign “Unit 1, Paper 2” and every student sits the identical test. Multiple choice is marked objectively; the written sections you mark yourself against the model answer and rubric.
Suggested time 33 min 30 points0/17 attempted
1

Shoulder surfing

2

Advanced persistent threat (APT)

3

Zero-day vulnerability

4

CIA triad

5

Separation of duties

6

Acceptable use policy

7

Pretexting

8

False acceptance vs false rejection

9

Principles social engineering exploits

10

Accounting (auditing)

11

Security policy

12

AI in cybersecurity, both directions

Short answer 1. Define or explain: Non-repudiation

3 pts

Short answer 2. Define or explain: Vishing and smishing

3 pts

Short answer 3. Define or explain: Availability

3 pts

Short answer 4. Define or explain: Authentication vs authorization

3 pts

Free response

6 pts

A hospital is deciding how to protect a system that stores patient records. (a) Define the confidentiality, integrity, and availability triad, and for each element give a concrete failure that would matter in this specific setting. (b) Ransomware encrypts the records and demands payment. Identify which element of the triad is most directly attacked and justify your choice. (c) Explain why a backup strategy must include restoration testing and at least one offline or immutable copy. (d) The hospital proposes requiring a second staff member to approve any bulk export of records. Name the principle this implements and explain what class of threat it addresses that technical access controls do not.