Font size
WorksheetsCyber Policy Quiz 1
Total questions: 23
Worksheet time: 13mins
Where would you find the UNSW's "Acceptable Use of UNSW Information Resources Policy"?
https://www.myit.unsw.edu.au/
On UNSW
Intranet
(myUNSW)
Confluence
On the Internet upon google search
Where would you find the Data Security Standard?
On the Internet upon google search
https://my.unsw.edu.au
(myUNSW)
https://www.myit.unsw.edu.au/
Confluence
Users must not use UNSW Information Resources to:
use a project management SaaS tool
represent or create the impression of representing UNSW unless explicitly authorised to do so.
store highly sensitive research data
make an online payment using personal credit card
Acceptable Use of Information Resources Policy applies to? (Select Multiple Correct Answers)
Staff (FTE & Contractors)
Students
Third Parties & Affiliates
Alumni
Acceptable Use of Information Resources Policy includes? (Select Multiple Correct Answers)
Principles for ensuring UNSW Information Resources are used legally, ethically and responsibly.
Conditions for personal use of UNSW Information Resources.
User's responsibilities and the penalties for misuse.
Compliance requirements & Prohibitions
Requirements for reporting cyber security events
What is an "Information Resource" as per the policy definition? (Select Multiple Correct Answers)
Any Information Service
Any Information Asset
Any Digital Information
None of the options
Which of the following are examples of an "Information Service" as per the policy definitions? (Select Multiple Correct Answers)
SaaS (Software as a service)
Data telecommunications services
Print services
Medibank student insurance (no tech component)
A UNSW student is working on research project to build a POC of AI robots. The robots will feed in data from UNSW research systems prior to creating smart reports/publications. Since the POC robot is in the non production environment, the POC system need not comply with the Cyber Security Standard – Risk Management
True
False
A Solution Architect from UNSW IT is designing an encryption mechanism for a solution which is going to store employee data. She has come to you for sign off of the design which has the master encryption key is stored on the same database as the keys being protected. She mentioned the design cannot be changed due to operational issues. What is your advice to her?
Sign off on the solution as is
Raise a risk as the design may not meet Security Standard
Ignore her request
An employee from HR team wants to test a software module which will require deactivating encryption in transit. In which of the following environment, can they do that without breaching UNSW standard or policy
without a written approval the Head of School or equivalent
in an isolated testing environment or isolated network.
in a production environment
finance process purposes
Users are accountable for all activities originating from their personal UNSW accounts, or other UNSW accounts that they use, as well as any UNSW Digital Information they store, process, or (a) using, or while connected to, a UNSW Information Resource
A UNSW IT project manager is working on a project involving UNSW sensitive data using their own personal laptop. As per the Data Security Standard , user must ensure that the laptop is
secure via a lock on the office desk
is encrypted
stored only in the office locker
For the purpose of investigation of a potential breach of a code of conduct, policy, procedure by the Conduct and Integrity Office or Human Resources, users must not access prohibited material on UNSW Information Resources
True
False
Network Engineer from UNSW IT has reached out to you to ensure they are configuring the Wi-fi setting with appropriate protocols. Which of the following protocol would you advise them to use?
SNMP v1/v2
WEP
Telnet
WPA3
UNSW does not have the right to monitor, access, examine, take custody of, and retain any UNSW Information Resource
False
True
Pick the incorrect answer:
All UNSW Digital Information stored, processed, or transmitted using any UNSW Information Resource
NSW legislation Housing Act 2001
may be subject to the Government Information (Public Access) Act 2009 (NSW)
may be subject to the Health Records and Information Privacy Act 2002 (NSW).
may be subject to the State Records Act 1998 (NSW)
An employee from Finance division has been suspected to be non compliant with with UNSW policies. Who needs to their approve access to UNSW storage services and file shares that may also contain personal information?
Chief Information Security Office or delegate
VP Operations or Delegate
Chief Information Officer or Delegate
Head of School
A developer within UNSW IT is building an application that will store research data from Faculty of Law. The developer is unsure of minimum permitted key size for AES encryption and asks you for advice. Please select the option for the minimum key size permitted as per the Data Security Standard.
No minim length requirement
512
256
128
Access to UNSW Digital Information must only be granted on a “least privilege” and “need to know” basis, but need not be in accordance with the Cyber Security Standard – Identity and Access Management
True
False
UNSW Digital Information that contains personal information or health information about an individual must not be transferred outside New South Wales (NSW), or to a Commonwealth agency, unless a (a) is conducted to ensure that the transfer is compliant with all applicable privacy laws
HR team is onboarding a new vendor who use TLS 1.3 to encrypt data in transit. The UNSW system interacting with the vendor is using TLS 1.1. As per the UNSW policy, the vendor must alter it's encryption protocol to match the UNSW system.
True
False
Select correct answer(S)
Any user that handles (creates, controls, stores, processes, or transmits) UNSW Digital Information must:
classify the UNSW Digital Information in accordance with the UNSW Data Classification Standard
classify the UNSW Digital Information in consultation with the Data Controller
Determine the Confidentiality Risk Rating
Determine the Inherent Cyber Risk Rating
Choose incorrect answer:
When a new application is onboarded and a new vendor is involved in handling sensitive or highly sensitive data, which process should be kicked off: (Select Multiple)
Data sharing agreement
Data classification
System Classification
CSRA (Cyber Security Risk Assessment)
Source Code Review
