CompTIA ITF+ ITF+ Information Security Principles 3 — Questions and Answers
Question 1: Which of the following BEST describes ransomware?
- Software that monitors user activity and reports to advertisers
- Malware that encrypts a victim's files and demands payment for the decryption key (Correct answer)
- A program that replicates itself across a network without user interaction
- Software that displays unwanted advertisements
Correct answer: Malware that encrypts a victim's files and demands payment for the decryption key
Ransomware encrypts victim files and demands a ransom payment, typically in cryptocurrency, to restore access.
Question 2: What is the primary purpose of a firewall?
- To speed up network traffic
- To monitor and control incoming and outgoing network traffic based on rules (Correct answer)
- To assign IP addresses to devices
- To encrypt data stored on disk
Correct answer: To monitor and control incoming and outgoing network traffic based on rules
A firewall filters network traffic using predefined rules to block unauthorized access while allowing legitimate traffic.
Question 3: A user writes their password on a sticky note and places it on their monitor. Which security concept does this violate?
- Data integrity
- Physical security / confidentiality (Correct answer)
- Availability
- Non-repudiation
Correct answer: Physical security / confidentiality
Writing passwords in visible locations violates confidentiality and physical security by exposing credentials to anyone nearby.
Question 4: Which type of malware disguises itself as legitimate software to trick users into installing it?
- Worm
- Trojan horse (Correct answer)
- Adware
- Rootkit
Correct answer: Trojan horse
A Trojan horse appears to be legitimate software but contains hidden malicious code that executes when installed.
Question 5: What is the goal of a social engineering attack?
- To exploit software vulnerabilities in operating systems
- To manipulate people into revealing confidential information or performing actions (Correct answer)
- To overwhelm a server with traffic until it crashes
- To intercept encrypted network traffic
Correct answer: To manipulate people into revealing confidential information or performing actions
Social engineering targets human psychology rather than technical vulnerabilities to extract information or gain unauthorized access.
Question 6: Which of the following BEST describes data integrity?
- Ensuring data is accessible to authorized users at all times
- Ensuring data has not been altered or tampered with in an unauthorized manner (Correct answer)
- Ensuring data is kept private from unauthorized users
- Ensuring data is backed up to multiple locations
Correct answer: Ensuring data has not been altered or tampered with in an unauthorized manner
Data integrity means the data remains accurate and unmodified except through authorized processes.
Question 7: An employee receives a phone call from someone claiming to be IT support and asking for their password. What should the employee do?
- Provide the password since IT staff are trusted
- Refuse to provide the password and report the call to security (Correct answer)
- Ask the caller to email them first, then provide the password
- Change the password and then tell the caller the new one
Correct answer: Refuse to provide the password and report the call to security
Legitimate IT staff never ask for user passwords; this is likely a vishing (voice phishing) social engineering attempt.
Which of the following BEST describes ransomware?