wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

BP - Organisational Procedure & Information Security

Total questions: 34

Worksheet time: 18mins

Name
Class
Date
1.

What does 'integrity of data' mean?

a)

"Accuracy and completeness of the data"

b)

"Data should be viewable at all times"

c)

"Data should be access by only the right people"

d)

"None of the above"

2.

What kind of cyber security risks can be minimised by using a Virtual Private Network (VPN)?

a)

Use of insecure Wi-Fi networks

b)

Key-Logging

c)

De-anonymization by network operators

d)

Phishing attacks

3.

An email that attempts to trick a reader into installing software that may contain a virus is:

a)

Phishing Scam

b)

Lobster trap

c)

Fishing Scam

d)

Phone Scam

4.

Which is an example of PII? (Personally Identifiable Information)

a)

Credit Card Number

b)

Name

c)

Home Address

d)

All of the above

5.

What is the best definition of Spear Phishing?

a)

"A Phishing email aimed directly at you"

b)

"A malicious virus that can encrypt or lock your computer"

c)

"A method hackers can use to guess your password"

d)

"A random Phishing email sent to a massive group"

6.

What is a step that you can take to minimise the chance and impact of a ransomware attack?

a)

"All of these answers"

b)

"Keep your computer software up to date"

c)

"Ensure that anti-virus tools are running and up to date"

d)

"Ensure that you are backing up your critical files"

7.

Who you are allowed to give your password to?

a)

"Anybody you trust"

b)

"Only supervisors and authorised IT staff if requested"

c)

"Only IT staff"

d)

"Nobody"

8.

Which security principles are covered by the CIA triad?

a)

certified, integrated, accessible

b)

continuity, integrity, accessibility

c)

confidentiality, integrity, availability

d)

confidentiality, installation, assembly

9.

What does compliance mean?

a)

providing secure access to user data

b)

using honest means to bypass security measures

c)

conducting tests to identify vulnerabilities in a system

d)

following the rules or standards that have been established

10.

Which of the following is not considered social engineering?

a)

dumpster diving

b)

convincing people to reveal information

c)

encrypting data to prevent user access until a fee is paid

d)

looking through social media sites for information

11.
What law makes organisations look after your personal data properly?
a)
Data Privacy Act
b)
Data Protection Act
c)
Data Protection Law
d)
Data Privacy Law
12.
Organisations storing your data must...
a)
Keep it up to date
b)
Keep it for no longer than 5 years after your death
c)
Ask for more data than required
d)
Wait for you to contact them to ensure its accurate
13.
How many principles does the Data Protection Act have?
a)
4
b)
8
c)
9
d)
10
14.
What is gaining unauthorised access to a computer system also known as?
a)
Hacking
b)
Spamming
c)
Phishing
d)
Logging on
15.
Why was the Computer Misuse Act of 1990 introduced?
a)
To help protect computer software
b)
To help protect computer hardware
c)
To stop the spread of computer viruses
d)
To stop people from accessing unauthorised information. 
16.
What is the name of the law that makes hacking illegal?
a)
Data Protection Act
b)
Computer Misuse Act
c)
Copyright, Designs and Patents Act
d)
Hacking Act
17.
Which of the following is NOT an offence under the Computer Misuse Act?
a)
unauthorised access to someone else's files
b)
unauthorised access to someone else's files with intent to commit further criminal offences
c)
copying software and trying to sell it to someone for a profit
d)
writing and distributing a virus
18.
Which of the following could protect against unauthorised access to an ICT system?
a)
anti-virus software
b)
a firewall
c)
anti-malware software
d)
disk defragger
19.
What are the principles of the Computer Misuse Act?
a)
Authorised access,Authorised access with intent, Authorised 
b)
Unauthorised access with intent and Unauthorised modification
c)
Unauthorised access and Unauthorised modification
d)
Unauthorised access, Unauthorised access with intent, Unauthorised modification
20.

Employee Onboarding is the process of ....

a)

Directing new employees to their work place

b)

Directing new employees about the daily tasks

c)

Introducing new employees to the organization’s environment and culture

d)

Introducing new employees to explore work environment on their own

21.

Why efficient employee onboarding matters

a)

All organisations have it

b)

Is the first interaction an employee has with the organization

c)

To help your new hires settle down in their jobs

d)

It will help in managers to direct on tasks to do

22.

Why efficient employee onboarding matters -2

a)

A memorable onboarding experience makes employees feel welcome

b)

To complete the joining formalities

c)

To Managers to start dictating the job

d)

To know about the rules and regulations

23.

Multilevel support model is also called...

a)

Frontline/backline model

b)

Help desk structure

c)

Support hierarchy

d)

None of the above

24.

____ is a well-defined, formal process help desk staff follow to:

–Handle problem incidents

–Get information to users

–Solve user problems

–Maintain records about the incident

a)

Call management

b)

Incident management

c)

ITIL

d)

None of the above

25.

_____ determines whether help desk staff are authorised to handle an incident.

a)

Prescreening

b)

Authentication procedure

c)

Logging

d)

None of the above

26.

_____ is a normal process in which an incident is transferred to a higher level support agent.

a)

Tracking

b)

Resolution

c)

Escalation

d)

None of the above

27.

_____ is a contract that defines expected performance of user support services or external vendor-provided services.

a)

SLA

b)

Last will and testament

c)

Terms and conditions

d)

None of the above

28.

How do we tighten our security?

a)

Use strong password

b)

Only connect to trusted network

c)

Log-off network account when not in use

d)

All of the above

29.

What's included in a strong password?

a)

A minimum of eight characters

b)

At least one lowercase alphabetical letter (a-z)

c)

At least one uppercase alphabetical letter (A-Z)

d)

At least one digit (0-9) and/or one special character (i.e., @ ! % & $ ^ * ( ) + = )

e)

All of the above

30.

What is one step you can take to protect yourself from social engineers on social media?

a)

Give out all your information

b)

Limit personal information in your social media profiles.

c)

Don't answer the phone

d)

Move to Harris County with no internet access.

31.

What is the document that details what a person who takes a certain job will be required to do?

a)

Job description

b)

Person specification

c)

Personality test

d)

Offer letter

32.

Which of the following does NOT describe the purpose or function of internal control?

a)

The means by which Management directs the company towards achievement of its objectives and corrects or redirects activities as circumstances change.

b)

It is a continuous activity and represents all the methods and processes which ensure adherence to policies, promote operational efficiency and enable risk to be managed by confining exposures to acceptable levels.

c)

It is designed to ensure activities and operations are carried out efficiently, effectively and economically.

d)

It is created to inspire people to work together to achieve business objectives by giving them a sense of purpose and destiny.

33.
An individual responsible for diagnosing and resolving users' technical hardware and software problems.
a)
1.  Help desk technician
b)
1.  Web site designer
c)
1.  Web application developer
d)
1.  Web site analyst
34.

Which of the following statement is FALSE?

a)

Helpdesk role does not include resolving an incident ticket

b)

All incident tickets will be assigned with the Urgency and Impacts defined in the Group Impact Classification Matrix

c)

If any CIMB IT Staff Member detected an incident, they need to ensure that an incident ticket is logged by either contacting the Helpdesk or raise the incident ticket by themselves

d)

If an incident ticket has been resolved and but the same issue is being reported again within a relatively-short period of time, this should be handled via the existing incident ticket