Question 1 · Multiple Choice — 5 points
Q1
What does Infrastructure as a Service (IaaS) provide and manage for the customer?
Correct Answer: b)
IaaS delivers the raw hardware layer — compute, storage and bandwidth. Development platforms are PaaS (c), and finished applications are SaaS.
Q2
From a social perspective, how are small companies disadvantaged when competing with the biggest players regarding cloud resources?
Correct Answer: c)
The disadvantage is access and attention: a small account does not command the same tooling or the same provider support when something breaks. Nothing legally bars small firms from SaaS (a) or banking apps (d).
Q3
What is identified as the single biggest threat to privacy regarding the government's utilization of biometrics?
Correct Answer: c)
The central worry is mass surveillance — face recognition and tracking at population scale, applied to people who are not suspected of anything. Cost (a) is a budget issue, not a privacy threat.
Q4
Which social engineering attack vector is primarily conducted over the phone?
Correct Answer: c)
Vishing is voice phishing — the attack is carried out in a phone call. Phishing is email, smishing is SMS, and dumpster diving is physical trash retrieval.
Q5
What component of a cyberattack represents the reason or goal driving the attacker?
Correct Answer: b)
An attack needs motive (the goal), method (how it is carried out) and a vulnerability (the weakness exploited). The reason driving the attacker is specifically the motive.
Q6
Which element of the CIA triad ensures that information is accessible and usable in a timely and reliable manner?
Correct Answer: d)
Availability is the timely, reliable access to information and systems. Confidentiality restricts who may see it, integrity protects it from unauthorized change, and non-repudiation is not one of the three CIA elements.
Q7
Why are IT help desk employees classified as a major security hole for Vishing scams?
Correct Answer: b)
The help desk's job is to be helpful and hand out information quickly, and its staff often get little security training — exactly the combination a vishing caller exploits.
Q8
What type of threat involves a long-term targeted attack where an attacker remains undetected for an extended period?
Correct Answer: a)
An Advanced Persistent Threat is defined by persistence and stealth — a targeted intruder who stays inside the network undetected for a long time to keep extracting information.
Q9
A user receives an urgent text message stating their primary bank account will face immediate suspension unless they follow an embedded web link. What combination of tactics is the threat actor utilizing?
Correct Answer: b)
The message arrives by SMS — SMiShing — and its lever is fear: an urgent threat of account suspension to push the victim into clicking before thinking. A phone call would be vishing.
Q10
What is a common source of data leakage and network spoofing attacks today?
Correct Answer: a)
Smartphone and mobile technology is the current source — mobile devices carry corporate data, join untrusted networks and run apps with broad permissions. Dumpster diving is an older physical vector, not the source of network spoofing.
Question 2 · Written Answers — 10 points
Q2 · Part A
4 points
List four different types of high-tech tools, equipment, or sensors that can be carried or utilized by surveillance drones.
Any four from the list — one per line.
Answer Key
- Live-feed video cameras
- Infrared cameras
- Heat sensors
- Radar
- Wi-Fi crackers
- Fake cell phone towers
- Less-lethal weapons (e.g. tasers or rubber bullets)
Any four of the above earn full credit.
Q2 · Part B
3 points
State three negative drawbacks or business risks of promoting a brand on social media platforms.
Any three — one per line.
Answer Key
- Exposure to competitors
- Needs qualified personnel
- Can tarnish the brand name
- Time consuming
Any three of the above earn full credit.
Q2 · Part C
3 points
List three specific vulnerabilities or threat types that are explicitly categorized as application-level threats.
Any three — one per line.
Answer Key
- Improper input validation
- Broken authentication and authorization
- Security misconfiguration
- SQL injection
- Broken session management
- Buffer overflow issues
- Cryptography failures
- Improper error handling and exception management
Any three of the above earn full credit.
Answer all 10 multiple-choice questions before submitting, or wait for the 60 minute timer — the paper auto-submits when time runs out.