WorksheetsSecurity mega quiz!
Total questions: 130
Worksheet time: 1hrs 6mins
Which of the following are physical security methods?
Passwords
Locks
Biometrics
Permissions
Anti virus
What is the most important room in an IT building to keep secure?
Canteen
Office
Meeting room
Server room
What are the negatives to using padlocks?
Can be lockpicked
Can be forced open (bolt cutters)
Easy to use
Could lose the key
Easy to permit access
Which of the following are examples of biometrics?
Fingerprint
Pincode
Facial recognition
Padlocks
Which of the following are advantages of biometrics?
Increases security as staff can’t share each other’s password as they still need the biometric to gain access
If password is compromised someone else still can’t access the system without also having the biometric
As technology develops some biometrics become easier to forge
Disabled people may be excluded may not have the relevant biometric characteristic
What does RFID stand for?
Radio for identification
Real forced identification
Radio frequency identification
Really fast identification
What is the disadvantage to RFID?
Easy to use
Quick to use
Vulnerable to cloning
Allows entry to buildings
What is used during 2 factor authentication?
Padlocks
Tokens
CCTV
Privacy screens
What are common ways to receive an authentication token?
Fob
Smartcard
Text
What is a scenario where a privacy screen should be used?
Working on public transport
Working in your home
Working in a coffee shop
Working in the bathroom
Definition of shredding?
Physical screens that are installed to limit how much other people can view your screen.
Authentication tokens.
Physically destroying confidential documents.
Security using physical human characteristics.
Some companies might need to physically protect their data which might be stored on servers, computers, discs etc. Physical security relates to what?
Making sure computers, servers and other storage cannot be accessed electronically.
Making sure that people cannot physically get to, use or touch computers, servers and storage devices.
Select all of the examples of physical security measures.
Using a Firewall
RFID tags / badges so that staff can scan doors to open them
Use of antivirus software
Locking doors to protect equipment
Putting bars on windows or using strengthened glass
One method to protect data is to put the servers above the flood level
True
False
Backup does not protect from loss or theft
True
False
One method to protect data is to put the servers above the flood level
True
False
Backup does not protect from loss or theft
True
False
Backup data is always up to date
True
False
Security staff would be a good idea a large company to act as a deterrent to any potential Intruders
True
False
Paper-based sensitive/personal/confidential data should always be shredded to prevent others from accessing the information
True
False
What is not an example of logical protection?
Anti Malware
Password Protection
Firewall
Key-card
What monitors the traffic in and out of a network
Modem
Firewall
Router
Switch
What type of protection is: Tiered levels of access to data
Physical
Logical
What is obfuscation?
the action of making something obscure, unclear, or unintelligible, in this case, data.
making something confusing to read
making it easy to send data securely
What are the 3 principles of information security?
Confidence, Integrity, Accountability
Confidentiality, Integrity, Availability
Configuration, Information, Acceptance
Countermeasure, Intrusion, Access
Information can only be accessed by individuals, groups or processes authorized to do so
Confidentiality
Integrity
Availability
Information is maintained, so that it is up to date, accurate, complete and fit for purpose.
Confidentiality
Integrity
Availability
Information is always available to and usable by the individuals, groups or processes that need to use it.
Confidentiality
Integrity
Availability
Organisations should ensure that their information systems and associated hardware and software, work as intended.
Confidentiality
Integrity
Availability
If data is not easily accessible users may decide to make their own copies. This is a security risk, as the more copies of data there are, the harder the data is to protect.
Confidentiality
Integrity
Availability
Organisations should have a culture of checking and reporting when data is an accurate. EG. A teacher contacting a parent to find that the telephone number is out of use, should inform the schools data manager.
Confidentiality
Integrity
Availability
Organisations should have a planned pattern of data maintenance where they check the data. Possibly by sending a contact their information and asking them to confirm if it is correct.
Confidentiality
Integrity
Availability
Inaccurate data can lead to conclusions based on false information or time being wasted and phone calls to numbers that no longer exist.
Confidentiality
Integrity
Availability
Restricting access to a computer network that holds data
Confidentiality
Integrity
Availability
Data kept in a locked cupboard
Confidentiality
Integrity
Availability
This is anything that has been created by an individual. From a piece of written work such as a report to music or a game.
The impact of the loss depends on the nature of the item taken.
Loss of intellectual property
Loss of service and access
Failure in security of confidential information
Loss of information belonging to a third party
Loss of reputation
A hacker who accesses your logon information could use services that you have paid for.
Loss of intellectual property
Loss of service and access
Failure in security of confidential information
Loss of information belonging to a third party
Loss of reputation
This could result in a worsening or total loss of your own service a g a hacker accessing your Wi-Fi would reduce bandwidth.
Loss of intellectual property
Loss of service and access
Failure in security of confidential information
Loss of information belonging to a third party
Loss of reputation
If a hacker changes the password on your router to something else, your Wi-Fi would be in accessible.
Loss of intellectual property
Loss of service and access
Failure in security of confidential information
Loss of information belonging to a third party
Loss of reputation
Loss of third party services, such as social media accounts, require contact with the company before services can be resumed.
Loss of intellectual property
Loss of service and access
Failure in security of confidential information
Loss of information belonging to a third party
Loss of reputation
If it is not secure it is accessible to others the impact of this depends on where the data was confidential in the first place.
Loss of intellectual property
Loss of service and access
Failure in security of confidential information
Loss of information belonging to a third party
Loss of reputation
The leaking of confidential developments, such as client files, would damage reputation.
Loss of intellectual property
Loss of service and access
Failure in security of confidential information
Loss of information belonging to a third party
Loss of reputation
An attack on a businesses service not only impacts on the business but also on any business or individual it holds data for.
Threat to national Security
Loss of service and access
Failure in security of confidential information
Loss of information belonging to a third party
Loss of reputation
If they fail to keep data safe they have failed to meet their legal and moral obligations and will be viewed negatively by customers and potential customers leading to if sales and a drop-in income.
Threat to national Security
Loss of service and access
Failure in security of confidential information
Loss of information belonging to a third party
Loss of reputation
May be defined as a direct physical threat to a country however it also could be a threat to the financial security of the state.
Threat to national Security
Loss of service and access
Failure in security of confidential information
Loss of information belonging to a third party
Loss of reputation
An example of this would be the theft of a set of designs from a large UK company which could impact their income badly, therefore threatening the income of the country.
Threat to national Security
Loss of service and access
Failure in security of confidential information
Loss of information belonging to a third party
Loss of reputation
This means access to data at any time by people who should not be able to see it
Unauthorized or unintended access to data
Accidental loss of data
Intentional destruction of data
Intentional tampering with data
This means the data has been lost, not just a copy but the original source
Unauthorized or unintended access to data
Accidental loss of data
Intentional destruction of data
Intentional tampering with data
Editing the data means that the data is changed in somewhere but it still available.
Unauthorized or unintended access to data
Accidental loss of data
Intentional destruction of data
Intentional tampering with data
Match the example;
Government espionage, A government breach may include the security of the country and potentially give an enemy country the advantage.
Unauthorized or unintended access to data
Accidental loss of data
Intentional destruction of data
Intentional tampering with data
Match the example;
Corporate espionage could give the competitor an advantage or damage their reputation
Unauthorized or unintended access to data
Accidental loss of data
Intentional destruction of data
Intentional tampering with data
Match the example;
Not training your staff to check the recipients of the emails before sending private and sensitive data or a member of staff leaving a print out of sensitive data in a public space.
Unauthorized or unintended access to data
Accidental loss of data
Intentional destruction of data
Intentional tampering with data
Match the example;
Not setting permission levels, allowing some people who do not need to see the data, access to it.
Unauthorized or unintended access to data
Accidental loss of data
Intentional destruction of data
Intentional tampering with data
Match the example;
Human error, someone could delete the file or throw away the paperwork.
Unauthorized or unintended access to data
Accidental loss of data
Intentional destruction of data
Intentional tampering with data
Match the example;
Equipment failure the computer could fail with the database on it. This is why it is imperative that your data is backed up remotely.
Unauthorized or unintended access to data
Accidental loss of data
Intentional destruction of data
Intentional tampering with data
Match the example;
Computer viruses that delete or encrypt data
Unauthorized or unintended access to data
Accidental loss of data
Intentional destruction of data
Intentional tampering with data
Match the example;
a targeted malicious attack involves a third party accessing the data and deleting it
Unauthorized or unintended access to data
Accidental loss of data
Intentional destruction of data
Intentional tampering with data
Match the example;
A student changing their exam scores.
Unauthorized or unintended access to data
Accidental loss of data
Intentional destruction of data
Intentional tampering with data
Match the example;
An organisation changing the figures in a rival company's research.
Unauthorized or unintended access to data
Accidental loss of data
Intentional destruction of data
Intentional tampering with data
Fraudulent activity means to gain something by changing the data or to claim something that you have not achieved.
true
false
Hacking can be a variety of things, in this context it is the action of unlawfully accessing a system.
true
false
Match the impact;
The organisation may make decisions using flawed data
Unauthorized or unintended access to data
Accidental loss of data
Intentional destruction of data
Intentional tampering with data
Match the impact;
If the data has been seen by unauthorized people it is a possible infringement of the data protection act and the data holder could be liable for prosecution
Unauthorized or unintended access to data
Accidental loss of data
Intentional destruction of data
Intentional tampering with data
Match the impact;
If the data is sensitive a competitor may gain an advantage from seeing it
Unauthorized or unintended access to data
Accidental loss of data
Intentional destruction of data
Intentional tampering with data
Match the impact;
It is a breach of the data protection act if the data included personal information and so would be liable to prosecution even if a honest mistake.
Unauthorized or unintended access to data
Accidental loss of data
Intentional destruction of data
Intentional tampering with data
This is anything that has been created by an individual. From a piece of written work such as a report to music or a game.
The impact of the loss depends on the nature of the item taken.
Loss of intellectual property
Loss of service and access
Failure in security of confidential information
Loss of information belonging to a third party
Loss of reputation
A hacker who accesses your logon information could use services that you have paid for.
Loss of intellectual property
Loss of service and access
Failure in security of confidential information
Loss of information belonging to a third party
Loss of reputation
This could result in a worsening or total loss of your own service a g a hacker accessing your Wi-Fi would reduce bandwidth.
Loss of intellectual property
Loss of service and access
Failure in security of confidential information
Loss of information belonging to a third party
Loss of reputation
If a hacker changes the password on your router to something else, your Wi-Fi would be in accessible.
Loss of intellectual property
Loss of service and access
Failure in security of confidential information
Loss of information belonging to a third party
Loss of reputation
Loss of third party services, such as social media accounts, require contact with the company before services can be resumed.
Loss of intellectual property
Loss of service and access
Failure in security of confidential information
Loss of information belonging to a third party
Loss of reputation
If it is not secure it is accessible to others the impact of this depends on where the data was confidential in the first place.
Loss of intellectual property
Loss of service and access
Failure in security of confidential information
Loss of information belonging to a third party
Loss of reputation
The leaking of confidential developments, such as client files, would damage reputation.
Loss of intellectual property
Loss of service and access
Failure in security of confidential information
Loss of information belonging to a third party
Loss of reputation
An attack on a businesses service not only impacts on the business but also on any business or individual it holds data for.
Threat to national Security
Loss of service and access
Failure in security of confidential information
Loss of information belonging to a third party
Loss of reputation
If they fail to keep data safe they have failed to meet their legal and moral obligations and will be viewed negatively by customers and potential customers leading to if sales and a drop-in income.
Threat to national Security
Loss of service and access
Failure in security of confidential information
Loss of information belonging to a third party
Loss of reputation
May be defined as a direct physical threat to a country however it also could be a threat to the financial security of the state.
Threat to national Security
Loss of service and access
Failure in security of confidential information
Loss of information belonging to a third party
Loss of reputation
An example of this would be the theft of a set of designs from a large UK company which could impact their income badly, therefore threatening the income of the country.
Threat to national Security
Loss of service and access
Failure in security of confidential information
Loss of information belonging to a third party
Loss of reputation
