Basic Flashcards
11 cards from real DSSAT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 11 Basic flashcards as text
What is the most important security awareness training topic?
Answer: Social engineering
Security awareness programs should include a variety of topics, including physical security, social engineering training, security best practices, remote and on-premises security and awareness of types of malware.
Which of the following is not reason why security awareness training is essential for executives?
Answer: Executives are worse at retaining security basics than other employees.
Security awareness training is essential for executives due to their privileged access, knowledge of trade secrets and increased exposure to risk during travel, making hem high-value targets for attackers.
Why are humans still the weakest link despite security training and resources?
Answer: All of the above
Humans are still weakest link because, if cybersecurity or human cybercrime is not their job description , security can become a minor concern relative to other work responsibilities.
True or False: Deepfake technology is an enterprise security concern.
Answer: A. True
Deepfakes introduce a number of security risks. Security awareness training programs should include information on how to detect and report digital impersonations and encourage employees to think critically about potentially altered content.
Do phishing simulations work?
Answer: All of the above
Phishing simulations are debated in the security industry. Many promote their effectiveness, while others call them controversial. Either way, phishing simulations on their own are not an effective phishing prevention strategy.
Which is not an indication of ransomware infection?
Answer: Out-of-date software
Alerts about password changes, pop-ups demanding ransoms and device performance degradation are all signs of a potential ransomware attack. While unpatched, out-of-date software is not a sign of an infection, it is important to patch or update the software to prevent it from becoming a ransomware attack vector.
True or False: Although positive reinforcement in security awareness training can change risky behavior, it can also produce costly side effects, such as damaging employee morale.
Answer: B. False
Negative reinforcement, such as shaming and punishment, may change risky behavior but at the cost of employee morale. New approaches to security awareness training incorporate positive reinforcement, gamification and social proof to reduce human risks without hurting morale.
What are the most important metrics to consider in security awareness training?
Answer: Human risk scores
Traditional security awareness training metrics, such as completion rates, quiz performance and engagement metrics, are fundamentally flawed, according to Forrester. Human risk scores are the most important metric and should be used to adjust and improve training programs.
What is the best way to identify a phishing email?
Answer: All of the above
Typos, grammatical errors and suspicious links are all indications of a phishing email.
True or False: Passphrases are stronger than passwords.
Answer: A. True
Passphrases are considered stronger than passwords. Passphrases are generally easier to remember than long, complex passwords, which are often written down or saved to a user's desktop.
What is the best definition of the word "prejudice"?
Answer: A preconceived belief, or judgement made without ascertaining the facts of a case
Prejudice literally means 'pre-judging' — forming a belief or opinion before examining the actual facts of a situation. This distinguishes it from other unfair behaviors like name-calling (which is an action, not a belief) or lying about someone. The other options describe behaviors that may stem from prejudice but are not the definition of the term itself.