NEW
Font size
WorksheetsIntroduction to Cybersecurity
Total questions: 20
Worksheet time: 20mins
Anny recently implemented an intrusion prevention system designed to block common network attacks from affecting his organization. What type of risk management strategy is Anny pursuing?
Risk Acceptance
Risk Avoidance
Risk Mitigation
Risk Transference
Which of the following principles expects an individual to behave reasonably under any given circumstance?
Due Diligence
Separation of Duties
Due Care
Least Privilege
What type of malware is characterized by spreading from system to system under its own power by exploiting vulnerabilities that do not require user intervention?
Trojan Horse
Virus
Logic Bomb
Worm
Which one of the following security programs is designed to establish a minimum standard common denominator of security understanding?
Training
Education
Indoctrination
Awareness
Which one of the following is an example of physical infrastructure hardening?
Antivirus Software
Hardware-based Network Firewall
Two Factor-Authentication
Fire Suppression System
Which information security goal is impacted when an organization experiences a DoS or DDoS attack?
Confidentiality
Integrity
Availability
Denial
What is the best way to provide accountability for the use of identities?
Logging
Authorization
Digital Signatures
Type 1 Authentication
Management support is critical to the success of a business continuity plan. Which of the following should be provided to the management to obtain their support?
Business Case
Business Impact Analysis
Risk Analysis
Threat Report
Which of the following is a critical first step in disaster recovery and contingency planning?
Plan Testing and Drills
Complete a Business Impact Analysis
Determine Offsite Backup Facility Alternatives
Organize and Create Relevant Documentation
What type of encryption is typically used for data at rest?
Asymmetric Encryption
Symmetric Encryption
DES
OTP
If Harry's organization requires him to log in with his username, a PIN, a password, and a fingerprint scan, how many distinct types of factors has he used?
One
Two
Three
Four
Mr. A has worked in human relations, payroll, and customer service roles in his company over the past few years. What type of process should his company perform to ensure that he has appropriate rights?
Reprovisioning
Account Review
Privilege Creep
Account Revocation
Which one of the following cryptographic goals protects against the risks posed when a device is lost or stolen?
Non-repudiation
Authentication
Integrity
Confidentiality
All of the following are ways of addressing risk, except:
Acceptance
Reversal
Mitigation
Transfer
Which of the following should include the process of hardening a device?
Encryption the OS
Updating and Patching the System
Using Video Cameras
Performing through Personal Background Checks
The cloud deployment model that features ownership by a cloud provider, with services offered to anyone who wants to subscribe, is known as:
Private
Public
Hybrid
Latent
It is important to classify and determine the relative sensitivity of assets to ensure that:
The cost of protection is in proportion to the sensitivity
Highly sensitive assets are protected
The cost of controls is minimized
Countermeasures are proportional to the risk
What is the most important factor in the successful implementation of an enterprisewide information security program?
Realistic Budgets Estimates
Security Awareness
Support of Senior Management
Recalculation of the work factor
Which of the following is the best approach to obtain senior management commitment to the information security program?
Describe the reduction of the risk
Present the emerging threat environment
Benchmark against other enterprises
Demonstrate the alignment of the program to business objectives
The primary focus of the change control process is to ensure that the changes are:
Authorized
Applied
Documented
Tested
