wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Security+ Lesson1

Total questions: 12

Worksheet time: 8mins

Name
Class
Date
1.

Your company is developing an application in which a private US-based hospital will allow patients to access their medical records online. Regardless of what other data the application handles, what kind of compliance do you already know you need to research?

a)

FISMA

b)

FERPA

c)

PCI DSS

d)

HIPAA

2.

The US government agency plans to migrate some of its internally hosted data to a cloud-based service. You need to make sure the proposed vendor can meet the same security requirements as the current solution. What are you currently practicing?

Each correct answer represents a complete solution. Choose all that apply.

a)

GDPR compliance

b)

FISMA compliance

c)

Due diligence

d)

Due care

e)

EGLBA compliance

3.

Joe is tuning her organization's firewall rules to prevent IP spoofing. What type of control is Joe implementing?

a)

Technical

b)

Operational

c)

Managerial

d)

Physical

4.

Which of the following controls primarily protect data availability?

a)

Hashing

b)

Patch management

c)

Digital signatures

d)

Version control

5.

Which one of the following statements is not true about compensating controls under PCI DSS?

a)

Use and regularly update antivirus software or programs.

b)

Do not use vendor-supplied defaults for system passwords and other security parameters.

c)

Allow physical access to cardholder data.

d)

Encrypt transmission of cardholder data across open public networks.

6.

A new privacy law demands more robust protection for your customer database. First, you researched database security products to find which would reliably meet your needs. Now that you’ve selected and installed one, you’re currently training administrators to perform integrity checks, update the software, and review logs for suspicious activities. What are you practicing?

a)

Availability

b)

Negligence

c)

Regulatory compliance

d)

Due care

7.

A third-party team is going to formally examine your organization’s overall security practices to make sure they meet regulatory compliance goals. Your organization may be fined if it fails. What would this verification process be called?

a)

Evaluation

b)

Certification

c)

Audit

d)

Assessment

8.

Someone stole thousands of customer records from your organization's database. What aspect of security was primarily attacked?

a)

Availability

b)

Integrity

c)

Confidentiality

d)

Portability

9.

Your internal network is protected from Internet attacks by a Cisco firewall. To improve security, your supervisor suggests installing a Fortinet firewall between the Cisco firewall and the trusted LAN, then using the space between as a perimeter network. Which security principles does this promote?

Each correct answer represents a complete solution. Choose all that apply.

a)

Defense-in-depth

b)

Availability

c)

Vendor diversity

d)

Security by obscurity

e)

Security by design

10.

Which of the following is a US government agency charged with developing and supporting standards used by other government organizations?

a)

W3C

b)

NIST

c)

ISOC

d)

OWASP

11.

Which of the following statements is correct regarding threat vector?

a)

A threat vector refers to the pathway that organization takes to find the attackers.

b)

Malware is a common example of a threat vector.

c)

The mechanism of minimizing vulnerabilities is called a threat vector.

d)

A threat vector is an unintentional threat.

12.

Assuming that all four roles exist separately at your company, who oversees strategic security needs, with a focus on organizational risk management?

a)

CPO

b)

CIO

c)

CCO

d)

CSO