Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

week 6 workshop quiz for sec+

Total questions: 25

Worksheet time: 13mins

Name
Class
Date
1.

Which of these options simulates a disaster and allows you to check the thoroughness of your disaster recovery plan?

a)

Business continuity plans

b)

After-action reports

c)

Critical business functions

d)

Tabletop exercises

2.

You identify a security risk that you do not have in-house skills to address. You decide to procure contract resources. This contractor will be responsible for handling and managing this security risk. Which type of risk response strategy are you demonstrating?

a)

mitigation

b)

transference

c)

acceptance

d)

avoidance

3.

Your company develops an incident response plan. When the Web server undergoes a DoS attack, the incident response team follows the incident response plan and returns the Web server to normal operation. What should be the final outcome of this incident?

a)

incident type/category

b)

documented incident

c)

escalation guidelines

d)

roles and responsibilities

4.

When calculating risks by using the quantitative method, what is the result of multiplying the asset values by the exposure factor (EF)?

a)

SLE

b)

risk elimination

c)

ACV

d)

ALE

5.

As your organization's security administrator, you are reviewing the audit results to assess if your organization's security baselines are maintained. In which phase of the security management life cycle are you engaged?

a)

Monitor and Evaluate

b)

Implement

c)

Operate and Maintain

d)

Plan and Organize

6.

Which policy defines the sensitivity of a company's data?

a)

a security policy

b)

a backup policy

c)

a use policy

d)

an information policy

7.

Your company contracts with a third-party janitorial service to clean the offices every night. Which one of these policies presents the greatest risk to the organization if it is NOT implemented?

a)

Personal email

b)

Job rotation

c)

Clean desk policy

d)

NDA

8.

Which concept involves contracting with a third party who will provide a location and equipment to be used in the event of an emergency?

a)

Alternate processing sites

b)

Alternate business practices

c)

Offsite storage

d)

Disaster recovery plan

9.

What is defined in an acceptable use policy?

a)

which users require access to certain company data

b)

how users are allowed to employ company hardware

c)

the sensitivity of company data

d)

which method administrators should use to back up network data

10.

Which technique attempts to predict the likelihood a threat will occur and assigns monetary values in the event a loss occurs?

a)

Qualitative risk analysis

b)

Delphi technique

c)

Quantitative risk analysis

d)

Vulnerability assessment

11.

You are the security administrator for your company. You identify a security risk. You decide to continue with the current security plan. However, you develop a contingency plan for if the security risk occurs. Which type of risk response strategy are you demonstrating?

a)

mitigation

b)

transference

c)

avoidance

d)

acceptance

12.

Your client is a small retailer that accepts orders via e-mail. The e-mail form submitted by a client's customer includes credit card information, and you demonstrate to the client how risky that is. As a result, the client adds secure credit card processing to their website, and no longer accepts e-mail orders. Which risk management concept does this represent?

a)

Risk transference

b)

Risk avoidance

c)

Risk acceptance

d)

Risk mitigation

13.

What is meant by MTBF?

a)

the average amount of time from one failure to the next

b)

the estimated amount of time that it will take to replace a piece of equipment

c)

the estimated amount of time that a piece of equipment will be used before it should be replaced

d)

the estimated amount of time that it will take to repair a piece of equipment when failure occurs

14.

Which events should be considered as part of the business continuity plan? (Choose all that apply.)

a)

non-emergency server relocation

b)

natural disaster

c)

hardware failure

d)

employee resignation

15.

Which process allows you to deploy, configure, and manage data centers through scripts?

a)

Baselining

b)

Immutable systems

c)

Waterfall

d)

IaC

16.

Which principle stipulates that multiple modifications to a computer system should NOT be made at the same time?

a)

due care

b)

acceptable use

c)

change management

d)

due diligence

17.

Your client's HR practices include promotion from within, and transferring people between offices on a regular basis. It seems like the most common question you hear when employees talk on the phone is "What office are you working at now and what are you doing?" What practice will ensure that a user's permissions are relevant and current?

a)

Transitive trusts

b)

Standard naming conventions

c)

Federation

d)

Recertification

18.

The business continuity team is interviewing users to gather information about business units and their functions. Which part of the business continuity plan includes this analysis?

a)

business impact analysis (BIA)

b)

disaster recovery plan

c)

contingency plan

d)

occupant emergency plan (OEP)

19.

Which type of analysis involves comparing the cost of implementing a safeguard to the impact of a possible threat?

a)

exposure analysis

b)

risk analysis

c)

threat analysis

d)

vulnerability analysis

20.

Your company is establishing new employment candidate screening processes. Which of the following should be included? (Choose all that apply.)

a)

Check all references.

b)

Perform a background check.

c)

Verify all education.

d)

Review military records and experience.

21.

In role-based awareness training, which of the following user groups would need to learn about implementing, managing, and monitoring controls?

a)

Data owners

b)

System administrators

c)

System owners

d)

Executive users

22.

The company who just hired you provides a fixed amount to new employees so that the employee can purchase the laptop of their choice. After the purchase, the employee only needs to submit the receipt. What should you implement so that the company is able to better track the laptops?

a)

Baseline deviations

b)

Unauthorized software

c)

Asset management

d)

License compliance

23.

You are about to begin a forensic investigation. Which of the following is NOT part of the investigation?

a)

Capture a system image.

b)

Perform network traffic and log analysis.

c)

Follow the incident response plan.

d)

Capture video.

24.

What concept is being illustrated when user accounts are created by one employee and user permissions are configured by another employee?

a)

rotation of duties

b)

two-man control

c)

collusion

d)

separation of duties

25.

As your organization's security officer, you are currently completing audits to ensure that your security settings meet the established baselines. In which phase of the security management life cycle are you engaged?

a)

Implement

b)

Monitor and Evaluate

c)

Plan and Organize

d)

Operate and Maintain