Unit 1: Introduction to Security
Cybersecurity · Unit 1 · Paper 3

Introduction to Security unit test

A test on this unit alone, marked as a percentage and a letter grade — for the test your class is actually sitting, rather than for May. Answer everything, then submit once: seeing the answer to question 3 before attempting question 4 makes the final percentage meaningless.

Each paper is built from this unit’s 40 terms and is the same for everyone, so a teacher can assign “Unit 1, Paper 3” and every student sits the identical test. Multiple choice is marked objectively; the written sections you mark yourself against the model answer and rubric.
Suggested time 33 min 30 points0/17 attempted
1

CIA triad

2

AI in cybersecurity, both directions

3

Defense in depth

4

Principles social engineering exploits

5

Pretexting

6

Vishing and smishing

7

Authentication factors

8

Risk responses

9

Baiting

10

Tailgating and piggybacking

11

Multifactor authentication

12

Non-repudiation

Short answer 1. Define or explain: Single sign-on

3 pts

Short answer 2. Define or explain: Biometric authentication

3 pts

Short answer 3. Define or explain: Confidentiality

3 pts

Short answer 4. Define or explain: Whaling

3 pts

Free response

6 pts

A school district stores student records on a single server. The server runs an operating system version for which the vendor released a patch nine months ago closing a flaw that is known to be exploited in the wild, and the district has not applied it. There are no offline backups.

Define confidentiality, integrity, and availability, and identify which of the three a ransomware attack on this server would most directly damage.

Using this scenario, distinguish among a threat, a vulnerability, and a risk.

Explain how likelihood and impact combine to produce a risk rating, and give a qualitative rating for this situation with justification.

Identify the four standard responses to an identified risk and recommend one for this situation.

Explain the principle of defense in depth and give one example of how it would apply here.

Explain why the statement "we have never had a breach" is not evidence that current controls are adequate.