All questions

GIAC Information Security Fundamentals (GISF) Practice Test

Browse all practice questions for the GIAC Information Security Fundamentals (GISF) Practice Test. Search by topic, open any question and review its full explanation, then test yourself in the practice quiz.

GISF Practice Test 2026 – Complete Guide for Exam Prep course image
All questions

These questions are part of the practice quiz. Start practicing

  • Which attack can involve sending unsolicited ARP requests or replies?
  • Why is MD5 considered antiquated?
  • Which tool is commonly used to identify vulnerabilities in systems?
  • Which bit is referred to as 'low-order' or 'least-significant'?
  • What principle ensures that users have the minimum necessary access to perform their tasks?
  • What does biometrics authentication rely on?
  • Which standard is commonly referred to as Wi-Fi 5?
  • What does the term 'network' refer to in a computing context?
  • Which type of attack would suggest that a hash function is compromised?
  • Which categories are used for antivirus detection?
  • How many gigabytes are in a terabyte?
  • What does the term "impact" refer to in the context of risk assessment?
  • What is a logic bomb?
  • Which of the following is classified as a technical countermeasure?
  • What is the primary purpose of an access control list (ACL)?
  • What is the main function of non-repudiation in communications?
  • What happens if the full backup is lost and only the differential backups are available?
  • In role-based access control (RBAC), what determines a user’s access permissions?
  • What authentication system does Enterprise Level Authentication (ELA) rely on?
  • What is the primary purpose of content filtering in a network?
  • What is the primary function of Bluetooth technology?
  • Which of the following describes fuzzing most accurately?
  • In a binary system, how is the value of a byte determined?
  • How are incremental backups characterized?
  • Who in an organization has primary responsibility and knowledge of data management?
  • Frequency analysis is primarily used against which type of cryptographic method?
  • What is the primary vulnerability of monoalphabetic ciphers?
  • What is a key benefit of using multifactor authentication?
  • Which of the following is the correct abbreviation for a byte?
  • What does HTML5 primarily incorporate to enhance interactivity?
  • Which protocol is considered interim before more secure protocols were adopted?
  • What does spoofing mean in the context of cybersecurity?
  • What type of account provides high-level permissions for configurations and data access?
  • During which process is a user granted specific access rights to resources?
  • Which access control model allows the owner of an object to delegate permissions to other users?
  • Which of the following best describes token authentication?
  • What technique involves gaining compromising information by observing someone from a close distance?
  • Which statement best describes elliptic curve cryptography (ECC)?
  • What is NOT a purpose of the gaining access phase?
  • How does a Graphical User Interface (GUI) function?
  • What port number is used by the Post Office Protocol version 3 (POP3) for retrieving email?
  • What typically defines the length of ciphertext in a running key encryption method?
  • What does the Ping command do in network troubleshooting?
  • In risk management, what does risk acceptance imply?
  • What is the role of a security procedure?
  • What does SYN stand for in networking?
  • What is the characteristic of a stateful inspection firewall regarding deep and shallow inspection?
  • What is a machine-in-the-middle attack?
  • What kind of content does the surface web consist of?
  • What is a web cookie?
  • What is an all-in-one security appliance also known as?
  • What is the purpose of private browsing in modern browsers?
  • What does an Access Control Entry (ACE) contain in a Windows environment?
  • What is the purpose of authentication in information security?
  • What is a key characteristic of ciphertext-only attacks?
  • Which of the following phases precedes Gaining access in an attack?
  • How does a differential backup compare to an incremental backup?
  • What technique involves injecting randomized data into software for testing purposes?
  • In what way does indirect social engineering differ from other forms?
  • What approach do professional pen-testers take?
  • Which Wi-Fi standard offers the highest throughput currently available?
  • What does a 200 Series server return code indicate?
  • Which feature best describes asymmetric encryption?
  • What does "likelihood" refer to in the context of risk assessment?
  • What does a Request for Comment (RFC) document provide regarding a protocol?
  • What port number is associated with HTTPS?
  • What is the primary concern of a threat to information security?
  • Which type of cryptography requires the same key for both encryption and decryption?
  • What is a drive-by download?
  • Which cryptographic method is faster?
  • What is the purpose of a Pre-shared Key (PSK) in wireless networking?
  • What is the primary function of a sniffer?
  • Does the Internet Protocol (IP) guarantee delivery of packets?
  • In terms of network management, what is a primary benefit of segmentation?
  • What is the value of a kilobyte in bytes?
  • What does keyspace refer to?
  • What does the term 'ciphertext' imply about the integrity of communication?
  • Which term describes the legal standard assessing how protective an organization is toward its assets?
  • What type of encryption does Bluetooth's secure simple pairing use?
  • DES stands for what in the context of cryptography?
  • What is a primary function of a web application firewall (WAF)?
  • What is a backup?
  • Which type of phishing is conducted through telephone calls or VoIP systems?
  • What principle aims to prevent users from accessing more information than necessary?
  • Which of the following describes authentication?
  • What type of information does the File Transfer Protocol (FTP) transmit?
  • What is primarily involved in asset identification?
  • What does it mean for a web page to be "defaced" in a drive-by download attack?
  • What is the term "WarXing" used to describe?
  • What does 'high-order' or 'most-significant' refer to in binary numbers?
  • What is the value of a terabyte in megabytes?
  • What does virtualization create on a single computing device?
  • What type of network security device is a web application firewall designed to protect against?
  • What is the purpose of patching an operating system?
  • What does the notation 0x signify in numeric representation?
  • Which of the following approaches may be taken when some risks cannot be completely avoided or mitigated?
  • Which of the following is an example of something-we-know authentication?
  • Why might an organization want to reduce the power level on a Wi-Fi transmitter?
  • Which aspect of cloud computing distinguishes it from traditional computing?
  • What defines a Local Area Network (LAN)?
  • Which device commonly uses DHCP to obtain an IP address?
  • What does the key exchange process involve?
  • What is a Pseudo-random number generator (PRNG) used for in computers?
  • What is commonly referred to as an "evil twin" access point?
  • What is the significance of using a random "salt" in a key derivation function?
  • What role does the chief information security officer (CISO) typically play in an organization?
  • What is a session key?
  • What does active defense refer to?
  • What does the prudent person rule require of an organization?
  • Which of the following best describes the goal of a botnet?
  • In symmetric encryption, what type of key is used?
  • What is the equivalent of a gigabyte in megabytes?
  • Which aspect is critical to the function of hardware that is part of the security control hierarchy?
  • What distinguishes a stream cipher from a block cipher?
  • What is the final phase in the attack lifecycle where attackers hide their tracks?
  • What is a true negative in relation to an IDS/IPS?
  • What is the goal of implementing safeguards in security measures?
  • In hybrid cryptography, what role does the asymmetric key play?
  • Which step in the risk management process determines how important the assets are?
  • What is the primary goal of secure coding?
  • Which of the following is a characteristic of JavaScript?
  • What is the main function of a data custodian?
  • What does the hexadecimal symbol 'A' represent in decimal?
  • What type of account usually has administrative privileges on a device or network?
  • Which algorithm is used for encryption, digital signatures, and secure key exchange?
  • Which of the following methods is NOT typically a part of wireless device setup?
  • What is the goal of threat hunting?
  • What is a domain attack?
  • What does cryptography primarily focus on?
  • What is meant by implicit denial in access control?
  • What is cryptojacking?
  • What is a Command Line Interface (CLI)?
  • What is the purpose of cognitive password authentication?
  • Which of the following statements best captures the essence of risk ignorance?
  • How many bits are there in a byte?
  • What does a weak key attack exploit?
  • Which one of the following best describes asymmetric cryptography?
  • In network security, what does false negative entail?
  • What feature does signature detection in antivirus software rely on?
  • What does a packet filter firewall analyze to determine access permissions?
  • What is meant by authorization in information security?
  • What is the first step in the risk management process?
  • What does the acronym "DaaS" stand for in cloud computing?
  • What are the three types of token authentication?
  • What command is used in Linux to change file or directory permissions?
  • In the context of access controls, what does ACE stand for?
  • What defines the hexadecimal number system?
  • What is an example of a potential risk when using public charging stations?
  • What does non-repudiation refer to in the context of information security?
  • What is an Intrusion Detection System (IDS) primarily used for?
  • What does ciphertext refer to?
  • What is the term for unauthorized entry by following someone through a secure door?
  • Which phase of an attack involves installing tools to ensure undetected access?
  • Which step follows the asset valuation in the risk management process?
  • What is the role of a default gateway in a network?
  • Which Wi-Fi security protocols are currently considered secure?
  • Which type of cipher is characterized by encrypting letters with another letter in a one-to-one relationship?
  • What is the purpose of Network Address Translation (NAT)?
  • What is the function of the CPU in a computer system?
  • Can Bluetooth signals be intercepted beyond their typical operational range?
  • What type of programming environment uses Java Virtual Machines?
  • Which of the following best describes the function of a DMZ in network architecture?
  • What occurs during an exclusive lookup?
  • What does the term "detect" refer to in a security context?
  • Which type of security solution monitors the environment and takes automatic action against unauthorized access attempts?
  • What is the main benefit of Wi-Fi Protected Setup (WPS)?
  • What is a risk associated with using password lockout on internet-facing accounts?
  • What file system does Windows use for managing access control?
  • What is the primary characteristic of the AES (Advanced Encryption Standard)?
  • What capability does an intrusion prevention system (IPS) provide?
  • What is the process of modifying an Apple mobile device to remove software restrictions known as?
  • Which feature of WPA2 helps ensure that each packet is unique?
  • What is the goal of risk mitigation in the context of asset protection?
  • Which wireless setup method is considered rare?
  • What is the second phase of an attack where vulnerable assets are identified?
  • What is a birthday attack?
  • What defines spear phishing?
  • Which attack strategy is most effective when the attacker has both plaintext and ciphertext for analysis?
  • What can be a consequence of using a rogue access point?
  • In Windows, what is the purpose of NTFS?
  • What does the second hexadecimal digit represent when calculating hexadecimal values?
  • What does role-based access control (RBAC) primarily focus on?
  • When might cognitive password systems be used?
  • What does accountability in an information system offer?
  • Which statement best describes the cumulative effect of a differential backup?
  • In what way do persistent cookies differ from non-persistent cookies?
  • What is the concept of island hopping in the context of cybersecurity?
  • What is the primary purpose of implementing detection and reaction capabilities in risk management?
  • What does OS hardening aim to achieve?
  • Which activity involves informing individuals of the rules they must follow in an organization?
  • What does the concept of risk avoidance entail?
  • What is the main characteristic of a cryptographic key?
  • What is a one-time passphrase used for?
  • What does wardriving involve?
  • What does OS hardening typically involve?
  • What is SSH (Secure Shell) primarily used for?
  • What type of attack uses social engineering to manipulate a DNS registrar?
  • What does a packet represent in a network?
  • Which class of Bluetooth is most commonly used?
  • Who is responsible for using the data and ensuring its proper management?
  • When a port scanner sends a SYN to a server, what are two possible responses that can be received?
  • What defines an enclave in network security?
  • What does SHA stand for in cryptography?
  • What does Dynamic Host Configuration Protocol (DHCP) primarily do?
  • What is the primary objective of gap analysis?
  • What does permission refer to in an IT security context?
  • What is the primary purpose of a digital signature?
  • Which term best describes actions taken to lessen the impact of a vulnerability?
  • Which of the following best defines a block cipher?
  • In a Linux system, what is the account referred to as User #0?
  • What is an example of an administrative countermeasure?
  • What is defined as anything that can potentially cause harm to assets or people?
  • What does a 'bit' represent in computing?
  • Which of the following is a detailed explanation of how to implement a security policy?
  • Why is it important to implement both signature and heuristics detection in antivirus software?
  • What is a brute force attack?
  • What is the primary function of encryption?
  • What is the result when adding the high-order and low-order nibbles together?
  • What does a physical countermeasure primarily involve?
  • What is the root directory in a computer's directory hierarchy?
  • What is the purpose of likelihood and impact estimates in the risk management process?
  • What is the purpose of a Cloud Controls Matrix (CCM)?
  • In a substitution cipher, what method is used to replace units of a message?
  • What is the maximum throughput for Wi-Fi 6/6E (802.11ax)?
  • Which of the following protocols would likely be used for email transmission?
  • What does Port Address Translation (PAT) allow multiple devices to do?
  • What encryption method is used by WPA2?
  • What is the main function of a sinkhole in network security?
  • Which operation is fundamental to modern encryption schemes and compares two binary bits?
  • What method of phishing attack uses text messages (SMS) to deceive victims?
  • What type of attack involves an attacker associating their MAC address with someone else's IP address to intercept traffic?
  • What is the aim of preventive measures in security?
  • What phase of an attack involves identifying assets that could be targeted for exploitation?
  • How does a buffer overflow attack typically operate?
  • What type of cryptographic technique transposes the order of letters or words to obscure meaning?
  • What is the role of an operating system (OS) on a computer?
  • What type of firewall filters traffic based on the state of existing connections?
  • What is one characteristic of a well-configured personal firewall?
  • When discussing data representation, what does 'octet' refer to?
  • What is a potential drawback of using only differential backups?
  • In information security, what does the term 'access control' generally relate to?
  • What does the presence of a malicious add-on usually indicate?
  • What is a VPN primarily used for?
  • What is the role of a personal firewall?
  • What is the function of a non-persistent cookie?
  • What is the definition of a 'nibble' in data representation?
  • What essential tactic is at the core of social engineering attacks?
  • What does compartmentalization in network security refer to?
  • Which of the following services is considered a delivery model for the cloud focused primarily on software deployment?
  • What does hybrid cryptography combine?
  • What does a 500 Series server return code indicate?
  • What function does IPSec serve in a security protocol?
  • How many digits does the base 10 number system consist of?
  • What is the function of a key encryption key (KEK)?
  • Which hash algorithm is commonly used in government applications but is being phased out?
  • What is direct social engineering?
  • What is involved in the response phase of incident management?
  • What does penetration testing involve?
  • What type of protocol is Transmission Control Protocol (TCP)?
  • What is the meaning of RST in networking?
  • What is normally considered when identifying countermeasures?
  • What is the main objective of confirmed backup recovery?
  • What process does blockchain use to maintain security?
  • What is the main advantage of using hybrid cryptography?
  • What type of backup would allow quicker restoration of everyday files while maintaining full system recovery options?
  • What is the purpose of a security protocol?
  • What is the primary characteristic of the dark web?
  • What are two common methods for setting up Wi-Fi devices?
  • Which attack targets a specific group of individuals who visit the same website?
  • What does a one-way hash function provide in terms of data integrity?
  • In the binary system, which of the following represents the highest digit?
  • What action is commonly taken during maintaining access?
  • What is a running key in the context of encryption?
  • What does Shadow IT refer to?
  • Which term describes a network of compromised devices that can be controlled by an attacker?
  • What is the method for calculating the value of bytes?
  • What does escrow in the context of information security refer to?
  • Which of the following roles primarily utilizes the data within an organization?
  • What does the acronym PDR stand for in the context of security management?
  • What is a digital envelope in the context of hybrid cryptography?
  • Which term describes the transformation of plaintext to ciphertext?
  • When securing a wireless network, why is it advisable to assume effectively infinite distance?
  • What is the primary purpose of patch management in an organization?
  • What does deep inspection in a firewall involve?
  • Why is it important to respond effectively to security incidents?
  • What is cryptocurrency?
  • What is a common term for a wireless access point?
  • Which component is essential for interpreting and executing program instructions on a computer?
  • What is a preimage attack?
  • What is a characteristic of Infrastructure as a Service (IaaS)?
  • What is privilege escalation?
  • What does a routing table contain?
  • Which term describes the number used by a computer to recognize a user account?
  • What is the purpose of the 'chmod' command in Linux?
  • What type of devices would typically be connected in a Local Area Network (LAN)?
  • Which protocol is primarily responsible for routing packets across interconnected networks?
  • What is the initial input for a key derivation function (KDF)?
  • What is the term for following someone through a secure door without authorization?
  • What is the primary purpose of a directory in an operating system?
  • Which role has the legal responsibility to protect an organization's assets?
  • What is the primary purpose of RAM in a computer system?
  • What is the definition of a user account in a computing context?
  • What function does the robots.txt file serve on a web server?
  • Which service model allows a user to fully manage their applications on a cloud infrastructure?
  • What does the term "symmetric" refer to in symmetric cryptography?
  • Which type of device typically uses dynamic IP addresses?
  • According to Moore's Law, how often does processing speed double?
  • What does Software as a Service (SaaS) provide to its users?
  • What are the three predefined Linux file permissions?
  • What is an essential characteristic of effective gap analysis?
  • What does a biometric system compare during authentication?
  • What is the term for an infection vector that uses attractive USB drives left in public areas?
  • In cybersecurity, which action describes pivoting?
  • Which of the following best defines an application protocol?
  • What should a properly functioning IDS alert you about?
  • What does a denial-of-service (DoS) attack aim to achieve?
  • What defines multifactor authentication?
  • Which of the following is true about Linux file systems?
  • What does the term "malware" refer to overall?
  • Which of the following is the purpose of an encryption key?
  • Which type of hacking method is exemplified by spear phishing?
  • What does a 300 Series server return code signify?
  • What is a network port?
  • How should vulnerabilities be addressed to improve security?
  • Which of the following statements is true regarding a false positive?
  • Which of the following describes a device that requests services from a server?
  • What is a primary risk associated with the dark web?
  • What does SSID stand for in the context of wireless networking?
  • What is the essence of cloud computing?
  • What is the primary function of a firewall?
  • Which of the following is an example of a wide area network?
  • What is the primary meaning of privilege in information security?
  • What does lateral movement refer to in cybersecurity?
  • What is the encryption used by WPA3?
  • What is exploit software primarily used for?
  • What does TKIP stand for?
  • What is the goal of domain hijacking?
  • In networking, what is the consequence of a packet arriving out of order at its destination?
  • What is a primary characteristic of discretionary access controls (DAC)?
  • What is the ideal frequency to perform full backups?
  • What is identified during the threat identification step?
  • What is the primary function of a network protocol?
  • What is the primary role of Public Key Infrastructure (PKI)?
  • What is the main advantage of a differential backup over a full backup?
  • In a scenario with multiple permission sets in place, which type of permission takes effect?
  • What is the purpose of Elliptic Curve Cryptography (ECC)?
  • What does WEP stand for in the context of Wi-Fi security?
  • What is the definition of a user in the context of a computer system?
  • What is a differential backup?
  • What are the place values used in a nibble?
  • What is the underlying technology that ensures the security of cryptocurrencies?
  • Which of the following statements is true regarding stateful inspection firewalls?
  • Why is it important to regularly schedule backups?
  • Which protocol is used to communicate error messages related to IP?
  • Who is considered the subject in an access control context?
  • Which of the following is indicated by a 400 Series server return code?
  • What does the prefix "0d" represent in numbering systems?
  • What does the term "proprietary algorithm" commonly imply in cryptography?
  • What is plaintext in the context of cryptography?
  • What does reducing risks associated with high Wi-Fi signal range imply for a network?
  • What is active content primarily used for on a computer?
  • What is one of the primary concerns regarding the use of attractive USB drives left in public areas?
  • What is a false positive in the context of an IDS?
  • What do firewall rules typically determine?
  • Which type of phone can bypass perimeter controls such as firewalls or content filters?
  • What is Triple DES primarily known for?
  • What does the Consensus Assessment Initiative Questionnaire (CAIQ) allow cloud customers to do?
  • Which of the following best describes the concept of confidentiality in security?
  • Which of the following is NOT a method of handling risk?
  • When should you ideally perform a differential backup?
  • What is a full system image backup?
  • Which operating system is not case-sensitive and uses \ as a path separator?
  • What is "work factor" in the context of cryptography?
  • ASCII is a system used for encoding what type of values?
  • Which of the following is a key feature of heuristics detection methods in antivirus software?
  • What does ECDH stand for in cryptography?
  • What is the purpose of the Address Resolution Protocol (ARP)?
  • Which of the following is NOT a property of signcryption?
  • What main purpose do access controls serve in information security?
  • What is the main feature of User Datagram Protocol (UDP) compared to TCP?
  • What security measures are utilized in Bluetooth's secure simple pairing?
  • What protocol uses port 443 for secure communications?
  • What is the purpose of ransomware?
  • What is the primary goal of the gaining access phase in an attack?
  • Which service model allows customers to manage their own production applications while the provider manages hardware and core system applications?
  • What is the role of awareness training in administrative countermeasures?
  • What does decryption accomplish?
  • What term describes the assurance that data is correct and maintained by authorized personnel?
  • What is the value range for a nibble in computing?
  • In networking terms, what does ACK represent?
  • What does WPA2 use for encryption?
  • What is the primary function of a port scanner?
  • Why is authentication essential in information security?
  • What type of protocol is IP categorized as?
  • What is a characteristic of social engineering attacks?
  • What does the process of verification in authentication involve?
  • What is a malware development kit/factory?
  • Which account type typically has restricted access to only its own files?
  • Which of the following actions would most likely enable an attacker to gain higher privileges?
  • What is a primary risk management tool for cloud consumers?
  • What does ECDH combine with to facilitate encryption?
  • What characterizes a Trojan horse in cybersecurity?
  • What is a key component of asset valuation?
  • What does a Group ID represent in a computing environment?
  • What does the concept of accountability help prevent in information security?
  • Can MAC addresses be encrypted to enhance security?
  • Which response from a server indicates an open port?
  • During an attack, what does lateral movement accomplish?
  • What can potentially be a drawback of proxy firewalls?
  • Which phishing attack method is characterized by the use of SMS text messages?
  • How many bytes are contained within an IP address?
  • How many bytes are there in a megabyte?
  • What does the operating system manage on behalf of the user?
  • Which three items are required for configuring IPv4?
  • What is typically the role of a default gateway in a network?
  • What kind of data would be lost if only differential backups are used without regular full backups?
  • What is the main feature of the ICMP in the context of IP?
  • Which of the following components is part of a digital certificate?
  • What is often a sign of a broken hashing algorithm?
  • What type of storage does RAM provide in a computer system?
  • What does using symmetric key encryption primarily ensure?
  • What is the function of the Domain Name System (DNS)?
  • In what manner does spyware typically operate?
  • In asymmetric encryption, what type of key is typically used?
  • Which backup type is most recommended for situations where reliability is essential and time for recovery is critical?
  • Which of the following describes a BlueSniper rifle?
  • Which tool is commonly used as a network utility for scanning?
  • What does application allowlisting do?
  • What is the zero trust security model based on?
  • In the context of information security, what is the significance of the reconnaissance phase?
  • Which of the following defines a countermeasure?
  • What is the primary purpose of WEP?
  • What is a distributed denial-of-service (DDoS) attack?
  • Why is the order of rules important in a packet filter firewall?
  • Which of the following is NOT a characteristic of the zero trust security model?
  • Which of the following accurately describes cache poisoning?
  • What distinguishes a persistent cookie?
  • What is the significance of classifying alerts as true positive, false positive, true negative, and false negative?
  • In a business email compromise (BEC) attack, the threat actor impersonates which entity to gain financial advantage?
  • Which user account type can access shared resources but with limited permissions?
  • What function does gateway antivirus serve in a network?
  • What does the prefix "0b" indicate in number systems?
  • What is a virus in the context of computer security?
  • Which operating system is case-sensitive and uses / as a path separator?
  • What type of phishing uses a deep fake voice impersonation?
  • Which protocol is primarily responsible for sending emails?
  • What is the primary function of the Internet Control Message Protocol (ICMP)?
  • What does the term 'cross-platform' refer to in programming?
  • What does DMZ stand for in a network context?
  • In which phase of the risk management process is the financial impact of a threat assessed?
  • Why is security training essential for employees?
  • What does a true positive indicate in the context of an IDS?
  • Which of the following accurately describes a hard drive?
  • What is a unique characteristic of MAC addresses?
  • What characterizes a disgruntled insider threat?
  • What kind of addresses does NAT translate?
  • What role does accountability play in securing information systems?
  • What is the range of possible byte values in computing?
  • How are offensive countermeasures related to active defense?
  • What does a vulnerability scanner typically do?
  • What type of inspection allows a firewall to check only headers, making it faster but potentially less thorough?
  • What is a common characteristic of exploit software?
  • What is the definition of a group in the context of user accounts?
  • What does a digital certificate primarily certify?
  • Which of the following are typical file permissions in a computing system?
  • What does a key derivation function (KDF) produce?
  • In which scenario would a full system image backup be most beneficial?
  • What does a MAC address do?
  • How does a web cookie contribute to HTTP traffic?
  • What is the network port number commonly used for FTP?
  • What does vulnerability analysis primarily assess?
  • What is a potential target for attackers when using application allowlisting?
  • What is typically the action denied to a non-privileged user account?
  • What is the function of a cryptographic algorithm in relation to keys?
  • What is meant by sideloading in mobile applications?
  • What defines an accidental insider?
  • What is the digit range in the binary number system?
  • What type of backup includes all data?
  • Which type of firewall is the most common in use today?
  • Which cryptographic process would involve reorganizing the input data into a format suitable for security?
  • What is a key in the context of cryptography?
  • What type of key exchange methods can HTTPS utilize?
  • What does 'Availability' imply in information security?
  • Which of the following represents a bit?
  • Which encryption protocol replaced WEP?
  • What percentage of the Internet is considered the deep web?
  • What constitutes a rogue access point?
  • Which aspect of the CIA Triad ensures that information is only accessible to those authorized?
  • What type of phishing attack specifically targets wealthy or powerful individuals?
  • What is the main purpose of using a one-way hash in communications?
  • In Linux, what term is used for what Windows calls a folder?
  • What port number does HTTP typically use?
  • What is the total number of bits in a kilobyte?
  • What is juice jacking?
  • Maintaining access is which number phase in the attack lifecycle?
  • Which programming language is commonly used to create interactive effects within web browsers?
  • Which elements are critical for a good information system?
  • Which of the following best describes a symmetric key?
  • What distinguishes indirect social engineering from direct social engineering?
  • What type of user interface allows interaction through text and visual images like icons?
  • What are the place values of bits in a byte?
  • Which protocol is known for achieving higher transmission speeds at the cost of reliability?
  • What does cryptanalysis involve?
  • Which process step is concerned with finding gaps in current security measures?
  • What does the term "pivot to admin" relate to?
  • What does a TCP/IP protocol primarily facilitate?
  • How is a byte calculated when working with multiple bytes?
  • What is a worm in the context of information security?
  • What is pretexting in the context of social engineering?
  • What does accountability in a security context refer to?
  • What is the main purpose of a hashing function?
  • What is the function of a server in a network environment?
  • A megabyte is equivalent to how many kilobytes?
  • Which of the following describes a feature of a worm?
  • How much does the keyspace increase with the addition of a bit?
  • What does the security control hierarchy illustrate?
  • What is the main purpose of a rootkit in an attack scenario?
  • Which of the following is NOT one of the five phases of an attack?
  • What is the primary role of firewall rules?
  • What does maximum password aging require?
  • What does risk avoidance involve?
  • How does an external insider gain access to a system?
  • Which permission allows a user to modify file content?
  • What protocol does Diffie-Hellman use for key exchange?
  • What is a kernel in the context of an operating system?
  • What role does a data custodian play in implementing security measures?
  • What is steganography primarily used for?
  • What does Desktop as a Service (DaaS) enable users to do?
  • What is signcryption?
  • Which attack type involves DNS server manipulation to provide false information?
  • Which attack method uses known plaintext to determine the key of ciphertext?
  • What is the primary purpose of antivirus software?
  • What action is typically taken by browsers when private browsing is enabled?
  • What role does a client play in a network?
  • What does risk transference refer to in a security context?
  • Which type of cryptographic key is generally easier to manage?
  • Which measure is most directly related to reducing vulnerability?
  • Is Bluetooth susceptible to warXing attacks?
  • What is the key length of the AES-128 encryption standard?
  • To compute the value of nibbles, what is added after calculating the high-order nibble?
  • What is an important function of a user ID in an operating system?
  • What is the hexadecimal equivalent of the binary value 1010?
  • What does spyware do?
  • What is an IP address?
  • Which of the following accurately describes a characteristic of AES-128?
  • What is the historical significance of Triple DES?
  • What occurs when a hashing algorithm generates the same hash for different inputs?
  • What is the ultimate goal of creating backups in information security?
  • What could be a main characteristic of an external insider?
  • How does heuristics detection identify potential threats?
  • What do offensive countermeasures aim to accomplish?
  • What is the main purpose of minimum password aging?
  • What does the 'C' in the CIA Triad stand for?
  • What is the purpose of security policies in an organization?
  • How does a vulnerability scanner enhance port scanning?
  • What does an algorithm represent in cryptography?
  • What is the combined value of all place values in a full byte?
  • What is the key factor that a senior manager decides regarding organizational risk?
  • What are access controls used for?
  • A type of substitution cipher that employs multiple alphabets to enhance security is known as what?
  • Which type of backup only copies data items that have changed since the last backup?
  • In the context of cryptography, what is an important consideration aside from confidentiality?
  • Which of the following is an example of something you have in terms of authentication?
  • What is the purpose of the covering tracks phase in an attack?
  • Which type of firewall is known for blocking network access from external networks while potentially causing latency issues?
  • What characterizes a Wide Area Network (WAN)?
  • What is a malicious add-on?
  • What key advantage does using both differential and full backups provide?
  • What is the main goal of segmentation within a network?
  • What defines a data spill in information security?
  • What is the primary function of a rootkit?
  • What is the standard port number for Simple Mail Transfer Protocol (SMTP) used to send email?
  • Which of the following is an example of spoofing?
  • What is a benefit of using an all-in-one security appliance?
  • What is Command and Control (C2) in cybersecurity?
  • Which term describes a condition that allows a threat to potentially exploit a system?
Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy