Unit 4: Securing Devices
Cybersecurity · Unit 4 · Paper 2

Securing Devices unit test

A test on this unit alone, marked as a percentage and a letter grade — for the test your class is actually sitting, rather than for May. Answer everything, then submit once: seeing the answer to question 3 before attempting question 4 makes the final percentage meaningless.

Each paper is built from this unit’s 41 terms and is the same for everyone, so a teacher can assign “Unit 4, Paper 2” and every student sits the identical test. Multiple choice is marked objectively; the written sections you mark yourself against the model answer and rubric.
Suggested time 33 min 30 points0/17 attempted
1

Internet of Things security

2

Application allowlisting

3

Remote wipe

4

Keylogger

5

End-of-life software

6

Attack surface

7

Removable media risk

8

Rootkit

9

Endpoint detection and response (EDR)

10

Mobile device management (MDM)

11

Host-based IDS

12

Endpoint logs

Short answer 1. Define or explain: Logic bomb

3 pts

Short answer 2. Define or explain: Virus

3 pts

Short answer 3. Define or explain: Secure boot

3 pts

Short answer 4. Define or explain: Patch management

3 pts

Free response

6 pts

A school district discovers that a staff workstation is beaconing to an unfamiliar external address, and that the account signed in on it has just accessed an unusual number of student records. (a) Identify the first containment action the response team should take, and explain why it comes before eradication. (b) Explain why the team should preserve volatile evidence before rebuilding the machine, and give one example of evidence that would be lost by an immediate reboot. (c) The account belonged to a librarian who did not need access to student records at all. Name the security principle that was violated and explain how applying it would have limited the damage. (d) Describe one detective control and one preventive control the district should add, and state clearly which is which.