wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

week 7 sec+ quiz

Total questions: 27

Worksheet time: 20mins

Name
Class
Date
1.

Which type of analysis involves comparing the cost of implementing a safeguard to the impact of a possible threat?

a)

risk analysis

b)

threat analysis

c)

exposure analysis

d)

vulnerability analysis

2.

You administer a small corporate network. On Friday evening, after close of business, you performed a full backup of the hard disk of one of the company's servers. On Monday evening, you performed a differential backup of the same server's hard disk, and on Tuesday, Wednesday, and Thursday evenings you performed incremental backups of the server's hard disk.

Which files are recorded in the backup that you performed on Thursday?

a)

all of the files on the hard disk

b)

all of the files on the hard disk that were changed or created since the differential backup on Monday

c)

all of the files on the hard disk that were changed or created since the incremental backup on Tuesday

d)

all of the files on the hard disk that were changed or created since the incremental backup on Wednesday

3.

Which concept involves contracting with a third party who will provide a location and equipment to be used in the event of an emergency?

a)

Offsite storage

b)

Alternate processing sites

c)

Disaster recovery plan

d)

Alternate business practices

4.

Management at your company has requested that you implement DLP. What is the purpose of this technology?

a)

It allows organizations to use the Internet to host services and data remotely instead of locally.

b)

It monitors data on computers to ensure the data is not deleted or removed.

c)

It implements hardware-based encryption.

d)

It protects against malware.

5.

Which automation or scripting concept can reduce the risk that new equipment might not have all the same settings, applications, and drivers as your existing equipment without changing vital user settings?

a)

Templates

b)

Configuration validation

c)

Continuous monitoring

d)

Automated courses of action

6.

Management has notified you that the mean time to repair (MTTR) a critical hard drive is too high. You need to address this issue with the least amount of expense. What should you do?

a)

Add another hard drive, and implement disk mirroring.

b)

Add two more hard drives, and implement disk striping with parity.

c)

Add another hard drive, and implement disk striping.

d)

Replace the hard drive with a faster hard drive.

7.

What is typically part of an information policy?

a)

acceptable use

b)

authentication

c)

classification of information

d)

employee termination procedure

8.

Your client is a small retailer that accepts orders via e-mail. The e-mail form submitted by a client's customer includes credit card information, and you demonstrate to the client how risky that is. As a result, the client adds secure credit card processing to their website, and no longer accepts e-mail orders. Which risk management concept does this represent?

a)

Risk acceptance

b)

Risk mitigation

c)

Risk transference

d)

Risk avoidance

9.

The business continuity team is interviewing users to gather information about business units and their functions. Which part of the business continuity plan includes this analysis?

a)

business impact analysis (BIA)

b)

occupant emergency plan (OEP)

c)

disaster recovery plan

d)

contingency plan

10.

You need to display the current protocol statistics and port connections for Windows and UNIX/Linux computers. Which command should you use?

a)

ping

b)

tracert

c)

nbtstat

d)

netstat

11.

As part of a new security initiative, your organization has decided that all employees must undergo security awareness training. What is the aim of this training?

a)

All employees excluding top management should understand the legal implications of loss of information.

b)

All employees in the IT department should be able to handle social engineering attacks.

c)

All employees in the IT department should be able to handle security incidents.

d)

All employees must understand their security responsibilities.

12.

When calculating risks by using the quantitative method, what is the result of multiplying the asset values by the exposure factor (EF)?

a)

SLE

b)

risk elimination

c)

risk elimination

d)

ACV

13.

Which policy defines the sensitivity of a company's data?

a)

a backup policy

b)

a security policy

c)

an information policy

d)

a use policy

14.

Which principle stipulates that multiple modifications to a computer system should NOT be made at the same time?

a)

acceptable use

b)

due diligence

c)

due care

d)

change management

15.

Your company is establishing new employment candidate screening processes. Which of the following should be included? (Choose all that apply.)

a)

Review military records and experience.

b)

Perform a background check.

c)

Check all references.

d)

Verify all education.

16.

Your company has recently started adopting formal security policies to comply with several state regulations. One of the security policies states that certain hardware is vital to the organization. As part of this security policy, you must ensure that you have the required number of components plus one extra to plug into any system in case of failure. Which strategy is this policy demonstrating?

a)

fault tolerance

b)

cold site

c)

clustering

d)

server redundancy

17.

You are the security administrator for your company. You identify a security risk. You decide to continue with the current security plan. However, you develop a contingency plan for if the security risk occurs. Which type of risk response strategy are you demonstrating?

a)

acceptance

b)

avoidance

c)

mitigation

d)

transference

18.

To justify the expenses of the forensic investigation, what is one thing that you should closely document?

a)

Chain of custody

b)

Man-hours

c)

Screenshots

d)

Network traffic and logs

19.

In role-based awareness training, which of the following user groups would need to learn about implementing, managing, and monitoring controls?

a)

System owners

b)

Executive users

c)

Data owners

d)

System administrators

20.

Your client allows the users to choose their own logon names for their account. You have seen opsboss, vpgal, and domainadm used as logons. You care very concerned about these obvious administrative accounts. What security control should you implement?

a)

Standard naming conventions

b)

File system security

c)

Account maintenance

d)

Recertification

21.

What preserves the existence and integrity of relevant electronic records (and paper records) when litigation is imminent?

a)

Data sovereignty

b)

Legal hold

c)

Chain of custody

d)

Incident response plan

22.

The company who just hired you provides a fixed amount to new employees so that the employee can purchase the laptop of their choice. After the purchase, the employee only needs to submit the receipt. What should you implement so that the company is able to better track the laptops?

a)

License compliance

b)

Unauthorized software

c)

Asset management

d)

Baseline deviations

23.

Which factor does NOT minimize the security breach incidents committed by internal employees?

a)

separation of duties

b)

mandatory vacations

c)

nondisclosure agreements signed by employees

d)

rotation of duties

24.

You identify a security risk that you do not have in-house skills to address. You decide to procure contract resources. This contractor will be responsible for handling and managing this security risk. Which type of risk response strategy are you demonstrating?

a)

mitigation

b)

avoidance

c)

transference

d)

acceptance

25.

Your company decides to implement a RAID-5 array on several file servers. Which feature is provided by this deployment?

a)

Scalability

b)

Elasticity

c)

High availability

d)

Distributed allocation

26.

Your organization has recently implemented a new security policy that includes the implementation of the principle of least privilege. You need to ensure that users understand this principle and implement the appropriate procedures to adhere to this principle. What is the best implementation of this principle?

a)

Ensuring that all services use the main administrative account to execute their processes

b)

Completing administrative tasks at a computer that functions only as a server

c)

Issuing the Run as command to execute administrative tasks during a regular user session

d)

Issuing a single account to each user, regardless of his job function

27.

Your client's HR practices include promotion from within, and transferring people between offices on a regular basis. It seems like the most common question you hear when employees talk on the phone is "What office are you working at now and what are you doing?" What practice will ensure that a user's permissions are relevant and current?

a)

Federation

b)

Transitive trusts

c)

Recertification

d)

Standard naming conventions