Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Mentoring Sesi 1 - Security+

Total questions: 10

Worksheet time: 6mins

Name
Class
Date
1.

Which security-related phrase relates to the integrity of data?

a)

Accessibility is authorized

b)

Modification is authorized

c)

Knowledge is authorized

d)

Non-repudiation is authorized

2.

An engineer looks to implement security measures by following the five functions in the National Institute of Standards and Technology (NIST) framework. When documenting the "detect" function, what does the engineer focus on?

a)

Evaluate risks and threats

b)

Install, operate, and decommission assets

c)

Ongoing proactive monitoring

d)

Restoration of systems and data

3.

How might the goals of a basic network management not be well-aligned with the goals of security?

a)

Management focuses on confidentiality and availability.

b)

Management focuses on confidentiality over availability.

c)

Management focuses on integrity and confidentiality.

d)

Management focuses on availability over confidentiality.

4.

Any external responsibility for an organization's security lies mainly with which individuals?

a)

The owner

b)

Tech staff

c)

Management

d)

Public relations

5.

What distinguishes DevSecOps from a traditional SOC?

a)

Software code is the responsibility of a programming or development team.

b)

Identification as a single point-of-contact for the notification of security incidents.

c)

A cultural shift within an organization to encourage much more collaboration.

d)

Security is a primary consideration at every stage of software development.

6.

A company has one technician that is solely responsible for applying and testing software and firmware patches. The technician goes on a two-week vacation, and no one is tasked to perform the patching duties during this time. A critical patch is released and not installed due to the absence. According to the National Institute of Standards and Technology (NIST), what has the delay in applying the patch caused?

a)

Control

b)

Risk

c)

Threat

d)

Vulnerability

7.

Any part of the World Wide Web that is accessed through non-standard methods and is intentionally not indexed and hidden from a search engine is called a _____.

a)

Dark net

b)

Cyber threat actor

c)

Deep web

d)

Dark web

8.

Which of the following could represent an insider threat? (Select all the apply.)

a)

Former employee

b)

Contractor

c)

Customer

d)

White box hacker

9.

One aspect of threat modeling is to identify potential threat actors and the risks associated with each one. When assessing the risk that any one type of threat actor poses to an organization, what are the critical factors to profile? (Select all that apply.)

a)

Education

b)

Socioeconomic status

c)

Intent

d)

Motivation

10.

A user with authorized access to systems in a software development firm installs a seemingly harmless, yet unauthorized program on a workstation without the IT department's sanction. Identify the type of threat that is a result of this user's action.

a)

Unintentional insider threat

b)

Malicious insider threat

c)

Intentional attack vector

d)

Shadow IT