WorksheetsWeek 14 - Module 5 Unit 5 Behavioral Security Concepts
Total questions: 18
Worksheet time: 18mins
What is a Standard Operating Procedure (SOP)?
Policies that include privilege management, data/information handling, incident response, and use of company devices
A measure by which to evaluate compliance with the policy
General instructions for when situations have not been fully assessed or because the decision-making process is too complex
An inflexible, step-by-step listing of the actions that must be completed for any given task
What type of information would NOT be considered confidential and governed by classification and handling procedures?
Company confidential information
Website information
Customer information
Personally identifiable information
Why might a company ban use of the corporate network and desktop software for personal communications?
The company wants employees to focus 100% of their energy on job duties.
The company might be held responsible for inappropriate content posted by its employees.
The company has purchased, and therefore owns, the network and software.
The company's resources are too limited to allow personal use.
Which of the following is NOT a privacy issue that is related to using a social networking site?
You need to control how far the information that you post to the site is distributed.
You need to ensure that private information is physically shredded prior to disposal.
You need to know how the company processes, stores, and transfers or sells any data it collects about you.
You can never take back information that is publicly posted, as others may have downloaded or duplicated it.
Peter is using a P2P file-sharing service to download a Linux distribution. He notice that in addition to the Linux installation files on the remote server, he can also see files such as Salesforecast2019.xlsx and SuperCrispv2.pptx. If he download these files, he might be downloading what type of information?
Customer information
Company confidential information
Metadata
Personal information
What impact is presented when users reveal their passwords to technical support staff?
A. It exposes the passwords to brute-force attacks from malicious hackers.
It provides technical support staff with access to the user's personal files stored on the network.
It exposes users to social engineering attacks that try to gather login credentials for malicious use.
It prevents the user from needing to change a password following the password history component of the policy.
You are preparing to submit a digital photo to a photo contest and you don’t want to reveal the camera and lens you used. Which of the following do you need to remove from the file?
Personal information
Metadata
Permissions
Company confidential information
Before you install a mobile app, you notice that the app wants to access your contact list and GPS navigation. These are examples of which of the following?
Personal information
Permissions
File Sharing
Privacy
Jia Xuan want to use IM to communicate breaking news to your company’s sales force. However, you want to make sure the messages are removed after 72 hours. Which of the following features does your IM service need to support?
Self-destructing messages
Encryption
Screenshot Blocking
Voice Chat
HR has received an email claiming to be from the company’s CEO asking for the names, contact information, and social security numbers of its food scientists. The email is a phishing email that is attempting to compromise personal information. What else might the email be attempting to compromise?
Metadata
Customer information
Permissions
Company confidential information
You are part of a task force developing a privacy policy for your company. Which of the following do you need to add to the policy to cover personal smartphone usage?
BYOD policy
BYOB policy
Permissions policy
IM policy
You have just been hired as a Certified Information Privacy Technologist. Before you start your new job, you have been asked to sign a document stipulating constraints and practices that you must agree to before accessing the corporate network. What is this document called?
AUP - Acceptable use policy
NDA – Non-Disclose Agreement
EULA- End-user license agreement
PIIA - Proprietary Information and Invention Assignment
A user steps away from their computer frequently and is concerned about unauthorized users changing information while they’re away. Which of the following would help prevent this?
BIOS/UEFI password
Screensaver or lock screen password
Password expiration policy
Password complexity policy
Which of the following is the strongest password?
mypassword
mY#p@$$~W0rD
mYp@$$w0rD
MiPassWord123
Which of these is a Confidentiality concern, as defined in the "CIA Triad"?
Snooping
Destruction
Replay
Impersonation
Which part of the Confidentiality, Integrity, and Availability (CIA) triad deals with information storage?
Accessibility
Confidentiality
Integrity
Availability
Which of these is NOT a social engineering attack?
Dumpster diving
Impersonation
Denial-of-service
Shoulder surfing
Which of these is an access control?
Destruction
Accounting
Integrity
Snooping
