IAS 401 — Reviewer for Finals

Midterm Exam

What is authentication design concept?
Correct answer: The strategies used to verify a user's identity
Which authentication method involves using two forms of authentication to verify a user's identity?
Correct answer: Two-factor authentication
What is the advantage of using single sign-on (SSO)?
Correct answer: It allows users to access multiple applications with a single set of login credentials
Which authentication method uses machine learning and risk-based analysis to determine the level of authentication required?
Correct answer: Adaptive authentication
A person you don't know well approaches you and asks for your login credentials to access a website. What should you do?
Correct answer: Refuse and walk away
What is social engineering?
Correct answer: The art of manipulating, influencing, or deceiving someone to gain control over their computer system.
You receive a phone call from someone claiming to be from Microsoft and telling you that your computer is infected with a virus. What should you do?
Correct answer: Hang up the phone
What is the goal of diversion theft?
Correct answer: To trick a company into making a delivery to the wrong location
What is water-holing?
Correct answer: A technique that takes advantage of websites people regularly visit and trust to gain access to the secure system.
Which authentication method allows users to access applications using their credentials from a trusted third-party provider?
Correct answer: Federated authentication
What is an example of a honeytrap?
Correct answer: A hacker tricks men into interacting with a fake attractive female
Is authorization always coupled with authentication?
Correct answer: Yes, they are always used together.
What is pretexting?
Correct answer: A false scenario used to engage a potential victim and increase the chance that the victim will bite.
What is diversion theft?
Correct answer: A con exercised by professional thieves to trick a company into making a delivery somewhere other than the intended location.
What is a password strength meter used for?
Correct answer: To help users create a more complex password
What is the first step in implementing authentication controls?
Correct answer: Identifying the critical data and systems that require protection.
What is spear phishing?
Correct answer: A small, focused, targeted attack via email on a particular person or organization with a specific personalized component.
What is quid pro quo?
Correct answer: Latin for 'something for something', in this case it's a benefit to the victim in exchange for information.
You receive an email from a friend with a link to a funny video. What should you do?
Correct answer: Ignore the email and delete it
What is certificate-based authentication?
Correct answer: A method that uses digital certificates to verify the identity of a user
What is a key concern when using passwords for authentication?
Correct answer: Password strength
What is baiting?
Correct answer: The act of dangling something in front of a victim to make them take action.
What should be done if a password leak or compromise is identified?
Correct answer: Change the password immediately
Which authentication method requires the user to provide multiple forms of identification to confirm their identity?
Correct answer: Multi-factor authentication
You receive a phone call from someone claiming to be from the IT department and asking for your login credentials. What should you do?
Correct answer: Hang up the phone
What are some common methods of implementing authentication controls?
Correct answer: Biometric identification, security tokens, and usernames and passwords.
You receive a USB drive in the mail with no return address. What should you do?
Correct answer: Report it to your IT department
You receive a phone call from a person claiming to be a technical support representative from a well-known software company. They say they need access to your computer to fix a problem. What should you do?
Correct answer: Tell them you will call the company back to verify their identity
What is the disadvantage of password-based authentication?
Correct answer: It is less secure than other authentication methods
What is the goal of implementing authentication controls?
Correct answer: To ensure that only authorized users can access sensitive information or systems.
Which authentication method involves using physical characteristics to verify a user's identity?
Correct answer: Biometric authentication
Why is encryption important?
Correct answer: It protects data during transit so that it cannot be intercepted by unauthorized parties.
What is a possible alternative to user-defined public data for usernames in high-security applications?
Correct answer: Assigned and secret usernames
What is a session identifier?
Response: A unique identifier assigned to each user in a web application.
Correct answer: A code passed back and forward between the client and server when transmitting and receiving requests.
What should policies and procedures for managing user accounts, passwords, and access privileges be based on?
Correct answer: Both A and B.
You receive a text message from a friend asking you to send them your social security number. What should you do?
Correct answer: Verify the authenticity of the message with your friend before sending any information
Why should organizations regularly review and test their security measures?
Correct answer: To ensure that they are effective and up-to-date.
What are some examples of ways to authenticate?
Correct answer: User name and password, cards, retina scans, voice recognition, and fingerprints.
What is the goal of a social engineer?
Correct answer: To deceive someone into providing valuable information or access to that information.
You receive an email from a colleague with an urgent request for your password. What should you do?
Correct answer: Report the email to your IT department
Which authentication method involves using physical characteristics to verify a user's identity?
Correct answer: Biometric authentication
Which of the following is an example of impersonation?
Correct answer: Pretending to be a bank employee
What is the goal of implementing authentication controls?
Correct answer: To confirm the identity of the user before granting access to the system or data
You receive a call from someone claiming to be a representative from your credit card company asking for your account information. What should you do?
Correct answer: Call the number on the back of your credit card to verify the authenticity of the call
You receive an email from your bank asking you to update your account information by clicking on a link. What should you do?
Correct answer: Ignore the email and delete it
What is authentication in the context of web applications?
Correct answer: The process of verifying that an individual, entity or website is whom it claims to be.
You receive a phone call from someone claiming to be from the IRS and threatening legal action if you don't pay back taxes immediately. What should you do?
Correct answer: Hang up the phone
Which of the following is an example of social engineering?
Correct answer: All of the above.
Why is it important to set a maximum password length?
Correct answer: To prevent long password Denial of Service attacks
You receive an email from someone claiming to be your CEO asking you to transfer funds to a new account. What should you do?
Correct answer: Contact the CEO directly to confirm the request
You receive a message from a social media friend with a link to a funny video. What should you do?
Correct answer: Ask for more information before clicking the link
How is authentication commonly performed in web applications?
Correct answer: By submitting a username or ID and one or more items of private information that only a given user should know.
What is an example of baiting?
Correct answer: A hacker leaves a USB drive labeled "Confidential" in a public place
Which is the most common form of authentication?
Correct answer: Password-based authentication
You receive an email from your bank asking you to confirm a recent transaction by clicking on a link. What should you do?
Correct answer: Ignore the email and delete it
What is the minimum length of passwords that should be enforced by the application?
Correct answer: 8 characters
What is session management?
Correct answer: The process of maintaining the state of an entity interacting with a server.
What are some examples of encryption protocols?
Correct answer: SSL and SSH protocols.
What is phishing?
Correct answer: The process of attempting to acquire sensitive information by masquerading as a trustworthy entity using bulk email.
What is an example of tailgating?
Correct answer: A hacker follows an authorized user through a secure entry