1
CSIS 343 – CYBERSECURITY
STUDY GUIDE - MIDTERM EXAM
LIBERTY UNIVERSITY
Topic: Fundamentals Of Cybersecurity And Common Threats And Vulnerabilities
The exam consists of 45 multiple-choice and 25 true/false questions. You will have 1
hour and 30 minutes to take it and will be penalized 3 points for every 5 minutes you
go over the time limit on the exam. Using Internet Explorer as a web browser for the
exam is not advised as the timer does not appear. Using the Mozilla Firefox browser or
the Google Chrome browser is recommended and will ensure that the timer displays
properly. This time limit will not allow you to look up every question but will be
sufficient if you come to the exam fully prepared.
KEY TOPICS TO STUDY
1. INTRODUCTION TO CYBERSECURITY
o What is the primary goal of cybersecurity?
▪ A) To protect information systems from unauthorized access
▪ B) To increase internet speed
▪ C) To enhance user experience
▪ D) To develop new software applications
o Which of the following best defines "cybersecurity"?
▪ A) Measures to protect information systems from theft or damage
▪ B) Processes to create new applications
▪ C) Techniques to speed up data transfer
▪ D) Methods for user authentication
o True/False: Cybersecurity involves protecting systems from both
internal and external threats.
o True/False: The primary focus of cybersecurity is to improve user
convenience.
o What is the primary purpose of cybersecurity policies?
▪ A) To establish guidelines for secure operations
▪ B) To increase network bandwidth
▪ C) To create marketing strategies
▪ D) To monitor employee productivity
o Which of the following is considered a basic principle of
cybersecurity?
▪ A) Confidentiality
▪ B) Convenience
▪ C) Speed
▪ D) Cost
o True/False: Cybersecurity policies should be reviewed and updated
regularly.
o True/False: Cybersecurity solely focuses on protecting hardware
components.
2. COMMON THREATS AND VULNERABILITIES
o What is a common characteristic of malware?
▪ A) It improves system performance
▪ B) It is designed to harm or exploit systems
▪ C) It is always detected by antivirus software
▪ D) It facilitates data encryption
o Which vulnerability is often exploited by brute force attacks?
▪ A) SQL Injection
▪ B) Weak passwords
▪ C) Cross-Site Scripting (XSS)
▪ D) Phishing
o True/False: Phishing attacks are designed to trick individuals into
revealing sensitive information.
o True/False: Ransomware encrypts data and demands a ransom for
decryption.
o What type of attack involves tricking individuals into providing
personal information?
▪ A) Man-in-the-Middle
▪ B) Phishing
2
▪ C) SQL Injection
▪ D) Denial of Service
o Which vulnerability involves unauthorized access due to weak
passwords?
▪ A) SQL Injection
▪ B) Brute Force Attack
▪ C) Cross-Site Scripting (XSS)
▪ D) Phishing
o True/False: A zero-day exploit targets known vulnerabilities for which
no patch exists.
o True/False: Social engineering attacks rely solely on technical methods
to deceive individuals.
o Which type of attack aims to overwhelm a system with traffic to
disrupt service?
▪ A) SQL Injection
▪ B) Denial of Service
▪ C) Phishing
▪ D) Man-in-the-Middle
o What is the primary goal of a man-in-the-middle attack?
▪ A) To intercept and alter communications between two parties
▪ B) To disable network services
▪ C) To steal user credentials
▪ D) To encrypt data
3. SECURITY MEASURES AND PROTOCOLS
o Which security measure is used to monitor and prevent
unauthorized network access?
▪ A) Firewall
▪ B) Encryption
▪ C) Backup
▪ D) Antivirus Software
o What is the main purpose of encryption in cybersecurity?
▪ A) To enhance system performance
▪ B) To make data unreadable to unauthorized users
▪ C) To speed up data transfer
▪ D) To create backups of data
o True/False: Firewalls are designed to prevent unauthorized access to or
from a private network.
o True/False: Encryption ensures data integrity but not confidentiality.
o Which protocol is used to secure data transmitted over a network?
▪ A) HTTP
▪ B) FTP
▪ C) SSL/TLS
▪ D) SMTP
o What is the purpose of a VPN?
▪ A) To monitor network traffic
▪ B) To encrypt data transmitted over a network
▪ C) To prevent malware infections
▪ D) To improve system performance
o True/False: SSL and TLS are protocols used for encrypting
communications over a network.
o True/False: A strong password policy includes requirements for
complexity and regular changes.
o Which of the following is an effective method for securing sensitive
data?
▪ A) Data encryption
▪ B) Data compression
▪ C) Data backup
▪ D) Data archiving
o What does multifactor authentication involve?
▪ A) Using multiple passwords
▪ B) Combining multiple authentication methods
▪ C) Using a single authentication method
3
▪ D) Encrypting data
4. INCIDENT RESPONSE AND MANAGEMENT
o What is the first step in the incident response process?
▪ A) Recovery
▪ B) Identification
▪ C) Containment
▪ D) Eradication
o Which step involves eliminating the root cause of a security
incident?
▪ A) Identification
▪ B) Containment
▪ C) Eradication
▪ D) Recovery
o True/False: The recovery phase involves restoring systems to normal
operations after an incident.
o True/False: Incident response should only begin after the damage has
been fully assessed.
o Which document outlines procedures for responding to security
incidents?
▪ A) Incident Response Plan
▪ B) Business Continuity Plan
▪ C) Disaster Recovery Plan
▪ D) Security Policy
o What is the main goal of the containment phase in incident
response?
▪ A) To prevent further damage
▪ B) To analyze the incident
▪ C) To restore services
▪ D) To eradicate the threat
o True/False: Effective incident response includes clear communication
with all stakeholders involved.
o True/False: Incident response plans should be tested regularly to
ensure effectiveness.
o What role does forensics play in incident response?
▪ A) Data recovery
▪ B) Evidence collection and analysis
▪ C) System restoration
▪ D) Incident detection
o What should be included in an incident response plan?
▪ A) Response procedures, communication plans, and recovery
steps
▪ B) Network performance metrics
▪ C) Marketing strategies
▪ D) Financial forecasts
5. REGULATIONS AND COMPLIANCE
o What does GDPR primarily focus on?
▪ A) Data protection and privacy
▪ B) Network performance
▪ C) Software development
▪ D) User authentication
o Which regulation is specifically designed to protect health
information in the U.S.?
▪ A) GDPR
▪ B) HIPAA
▪ C) CCPA
▪ D) SOX
o True/False: Compliance with regulations like GDPR is optional for
organizations outside the European Union.
o True/False: Non-compliance with HIPAA can result in significant legal
penalties.
o What is the primary purpose of the CCPA?
▪ A) To protect consumer privacy rights
▪ B) To regulate financial transactions
4
▪ C) To ensure network security
▪ D) To promote cybersecurity education
o Which regulation requires organizations to notify individuals of
data breaches?
▪ A) GDPR
▪ B) SOX
▪ C) HIPAA
▪ D) PCI DSS
o True/False: Regulations like PCI DSS focus on securing payment card
information.
o True/False: Compliance with cybersecurity regulations is solely the
responsibility of the IT department.
o What does SOX (Sarbanes-Oxley Act) primarily address?
▪ A) Financial reporting and internal controls
▪ B) Data protection and privacy
▪ C) Network security
▪ D) Employee rights
o What does HIPAA require organizations to do?
▪ A) Protect patient health information
▪ B) Enhance software development
▪ C) Increase network performance
▪ D) Develop marketing strategies
6. RECENT TRENDS AND EMERGING THREATS
o What is a recent trend in cybersecurity regarding threat detection?
▪ A) Increased use of artificial intelligence
▪ B) Decrease in encryption usage
▪ C) Reduced focus on network security
▪ D) Increased reliance on manual monitoring
o Which of the following is an emerging threat in cybersecurity?
▪ A) Legacy system vulnerabilities
▪ B) Improved encryption algorithms
▪ C) Advanced persistent threats (APTs)
▪ D) Enhanced firewall protection
o True/False: Artificial intelligence is increasingly being used to detect
and respond to cybersecurity threats.
o True/False: Emerging threats are often targeted by traditional security
measures.
o What is the primary focus of threat hunting in cybersecurity?
▪ A) To passively monitor network traffic
▪ B) To actively search for indicators of compromise
▪ C) To manage user access
▪ D) To implement security policies
o Which emerging technology is used to enhance threat detection and
response?
▪ A) Blockchain
▪ B) Cloud computing
▪ C) Artificial Intelligence
▪ D) IoT devices
o True/False: Zero Trust architecture assumes that threats could be both
external and internal, requiring strict verification.
o True/False: Threat intelligence involves gathering and analyzing
information about potential cyber threats.
o What does the term "Zero Trust" refer to in cybersecurity?
▪ A) A model that assumes no user or system is inherently trusted
▪ B) A system that trusts all users within a network
▪ C) A technology for data encryption
▪ D) A method for improving network speed
o What is a key feature of artificial intelligence in cybersecurity?
▪ A) Automating threat detection and response
▪ B) Replacing traditional firewalls
▪ C) Enhancing network speed
▪ D) Simplifying software development
5