wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

LSI 230 & SFI 1024- INFO SEC & PRIN OF INFO SEC

Total questions: 20

Worksheet time: 20mins

Name
Class
Date
1.

'X' is an integrated set of components for collecting, storing, and processing data and for providing information, knowledge and digital product.


What is 'X'?

a)

Information Security

b)

Information System

c)

Data

d)

Computer Software

2.

Which of the following is the components of information system?

a)

Peony

b)

Software

c)

Dance

d)

Netflix

3.

´Designed to protect the _____________, ________________ and _____________ of computer system data from those with malicious intentions'.


Which of the following is the INCORRECT answer?

a)

Confidentiality

b)

Integrity

c)

Confidently

d)

Availability

4.

Which of the following is NOT threat to information security?

a)

IP scan and attack

b)

Compromises to intellectual property

c)

Forces of nature

d)

Sabotage or vandalism

5.

All the followings are the methods of attack to the information system EXCEPT:

a)

Web browsing

b)

Acts of human error or failure

c)

Virus

d)

Unprotected shares

6.

Which of the following is INCORRECT about Password Cracking?

a)

Process of recovering passwords from data that have been stored in or transmitted by a computer system

b)

Help a user to commit a crime

c)

Preventive measurement of password strength

d)

Gain unauthorized access to a system

7.

-Rules that mandate or prohibit certain behavior

-Drawn from ethics


Statements above refers to:

a)

Policy

b)

Ethics

c)

Laws

d)

Procedures

8.

All of the following are the keys for a policy to be enforceable, EXCEPT

a)

Dissemination

b)

Review

c)

Compression

d)

Compliance

9.

The following is correct about ethics, law and policy in information security, EXCEPT

a)

Laws are rules that mandate or prohibit certain behavior

b)

Ignorance of law (policy) is acceptable

c)

Policies are guidelines that describe acceptable and unacceptable employee behaviors

d)

Ignorance is ethics is acceptable

10.

What is Risk Management?

a)

an uncertain event, activity or situation that can have a positive or a negative effect on any objective

b)

is the process of coordinating people and other resources to achieve the goals of the organization

c)

is the process of identifying and migrating risk

d)

reflecting the influences on risk culture, beginning with the

predisposition to risk of the individual

11.

All of the following are examples of Hardware devices, EXCEPT:

a)

Computer

b)

Smartphone

c)

Tablets

d)

Data files

12.

Example of Application Software is:

a)

Operating System

b)

Microsoft Office Power Point

c)

Printer Driver

d)

Hard Disc Analyzer

13.

Which of the following is INCORRECT for Information security functions:

a)

Protect the organization's ability to function

b)

Safeguard technology assets

c)

Enable the safe operation of applications

d)

Protect the boss

14.

Which of the following is the CORRECT sequence for Software Development Life Cycle (SDLC)?

a)

Analysis--> Design--> Implementation--> Testing--> Evaluation

b)

Analysis--> Design--> Evaluation--> Testing--> Implementation

c)

Design--> Implementation--> Testing--> Evaluation--> Analysis

d)

Design--> Evaluation--> Testing--> Implementation--> Analysis

15.

-Private Law

-Public Law

-International Law


All of the following are:

a)

Level of Law

b)

Types of Law

c)

Cyber Law Acts in Malaysia

d)

Major IT Professional Organizations and Ethics

16.

All of the following are the categories of unethical and illegal behavior, EXCEPT:

a)

Ignorance

b)

Intent

c)

Ego

d)

Accident

17.

'An uncertain event that may have a positive or negative impact on the project'.


Statement above is the definition of:

a)

Manager

b)

Disk

c)

Hazard

d)

Risk

18.

Choose the CORRECT steps in Risk Management Plan.

a)

Identify Risk--> Control Risk--> Assess Risk

b)

Identify Risk--> Assess Risk--> Control Risk

c)

Assess Risk--> Identify Risk--> Control Risk

d)

Assess Risk--> Control Risk--> Identify Risk

19.

All of the following are strategies in Risk Control, EXCEPT:

a)

Acceptance

b)

Termination

c)

Litigation

d)

Defense

20.

'Shift risks to other areas or outside entities to handle'.


Statement above is the description for:

a)

Transverse

b)

Transformers

c)

Translate

d)

Transferal