01. A departing engineer copies the undisclosed chemical formula that gives her employer its advantage over competitors, and carries it to a rival firm.
Which category of intellectual property has been stolen?
a) Trade secret
b) Copyright
c) Trademark
d) Patent
02. An incident handler is triaging a workstation suspected of running an e-mail-borne virus.
Which observation most directly indicates that the host is now spreading the infection to other systems?
a) Antivirus on the host has quarantined an infected e-mail attachment
b) The host's antivirus signature database has not been updated
c) Several operating system files on the host can no longer be opened
d) A surge of outbound e-mail from the host that the user did not send
03. An organization keeps no retention schedule for its security logs, has no documented evidence-handling procedure and has trained no first responder. Months after a breach it is asked to substantiate what happened.
Which consequence follows directly from this lack of forensic readiness?
a) The intrusion went undetected, because detection is a forensic-readiness capability
b) Eradication was impossible without a forensic image of the affected host
c) Containment failed, since a documented chain of custody is what stops an incident spreading
d) Evidence that would substantiate the breach was never preserved, so it cannot now be produced
04. Any information of probative value that is either stored or transmitted in a digital form during a computer crime is called:
a) Computer Emails
b) Digital investigation
c) Digital evidence
d) Digital Forensic Examiner
05. Business continuity planning is an umbrella under which several subordinate plans sit.
Which of these is the plan concerned specifically with restoring IT systems and infrastructure after a disruption?
a) Incident response plan
b) Disaster recovery plan
c) Crisis communication plan
d) Business resumption plan
06. Insider threats are classified by the insider's intent and situation.
Which of the following describes a negligent insider?
a) A staff member who deliberately copies proprietary data to a personal drive before resigning
b) A legitimate user whose credentials are under an external attacker's control
c) An employee who bypasses a security procedure for convenience, without intending harm
d) An employee recruited and paid by a competitor to extract confidential information
07. Insiders understand corporate business functions.
What is the correct sequence of activities performed by an insider to damage company assets?
a) Gain privileged access, install malware then activate
b) Gain privileged access, activate and install malware
c) Install malware, gain privileged access, then activate
d) Activate malware, gain privileged access then install malware
08. James is a professional hacker employed by an organization to exploit their cloud services. In order to achieve this, James created anonymous access to the cloud services to carry out various attacks such as password and key cracking, hosting malicious data, and DDoS attacks.
Which of the following threats is he posing to the cloud platform?
a) Data breach/loss
b) Abuse and nefarious use of cloud services
c) Insecure interface and APIs
d) Insufficient due diligence
09. Malicious code that is installed on a computer without the user's knowledge, in order to acquire information from that user's machine and send it to an attacker who can access it remotely, is called:
a) Trojan
b) Spyware
c) Logic Bomb
d) Worm
10. Zaimasoft, a prominent IT organization, was attacked by perpetrators who targeted the hardware directly and caused irreversible damage to it, leaving replacement or reinstallation as the only remaining option.
Identify the type of denial-of-service attack performed on Zaimasoft.
a) DRDoS
b) DoS
c) PDoS
d) DDoS