wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Cyber Policy Quiz 1

Total questions: 23

Worksheet time: 13mins

Name
Class
Date
1.

Where would you find the UNSW's "Acceptable Use of UNSW Information Resources Policy"?

a)

https://www.myit.unsw.edu.au/

b)

On UNSW

Intranet

(myUNSW)

c)

Confluence

d)

On the Internet upon google search

2.

Where would you find the Data Security Standard?

a)

On the Internet upon google search

b)

https://my.unsw.edu.au

(myUNSW)

c)

https://www.myit.unsw.edu.au/

d)

Confluence

3.

Users must not use UNSW Information Resources to:

a)

use a project management SaaS tool

b)

represent or create the impression of representing UNSW unless explicitly authorised to do so.

c)

store highly sensitive research data

d)

make an online payment using personal credit card

4.

Acceptable Use of Information Resources Policy applies to? (Select Multiple Correct Answers)

a)

Staff (FTE & Contractors)

b)

Students

c)

Third Parties & Affiliates

d)

Alumni

5.

Acceptable Use of Information Resources Policy includes? (Select Multiple Correct Answers)

a)

Principles for ensuring UNSW Information Resources are used legally, ethically and responsibly.

b)

Conditions for personal use of UNSW Information Resources.

c)

User's responsibilities and the penalties for misuse.

d)

Compliance requirements & Prohibitions

e)

Requirements for reporting cyber security events

6.

What is an "Information Resource" as per the policy definition? (Select Multiple Correct Answers)

a)

Any Information Service

b)

Any Information Asset

c)

Any Digital Information

d)

None of the options

7.

Which of the following are examples of an "Information Service" as per the policy definitions? (Select Multiple Correct Answers)

a)

SaaS (Software as a service)

b)

Data telecommunications services

c)

Print services

d)

Medibank student insurance (no tech component)

8.

A UNSW student is working on research project to build a POC of AI robots. The robots will feed in data from UNSW research systems prior to creating smart reports/publications. Since the POC robot is in the non production environment, the POC system need not comply with the Cyber Security Standard – Risk Management

a)

True

b)

False

9.

A Solution Architect from UNSW IT is designing an encryption mechanism for a solution which is going to store employee data. She has come to you for sign off of the design which has the master encryption key is stored on the same database as the keys being protected. She mentioned the design cannot be changed due to operational issues. What is your advice to her?

a)

Sign off on the solution as is

b)

Raise a risk as the design may not meet Security Standard

c)

Ignore her request

10.

An employee from HR team wants to test a software module which will require deactivating encryption in transit. In which of the following environment, can they do that without breaching UNSW standard or policy

a)

without a written approval the Head of School or equivalent

b)

in an isolated testing environment or isolated network.

c)

in a production environment

d)

finance process purposes

11.

Users are accountable for all activities originating from their personal UNSW accounts, or other UNSW accounts that they use, as well as any UNSW Digital Information they store, process, or (a)   using, or while connected to, a UNSW Information Resource

12.

A UNSW IT project manager is working on a project involving UNSW sensitive data using their own personal laptop. As per the Data Security Standard , user must ensure that the laptop is

a)

secure via a lock on the office desk

b)

is encrypted

c)

stored only in the office locker

13.

For the purpose of investigation of a potential breach of a code of conduct, policy, procedure by the Conduct and Integrity Office or Human Resources, users must not access prohibited material on UNSW Information Resources

a)

True

b)

False

14.

Network Engineer from UNSW IT has reached out to you to ensure they are configuring the Wi-fi setting with appropriate protocols. Which of the following protocol would you advise them to use?

a)

SNMP v1/v2

b)

WEP

c)

Telnet

d)

WPA3

15.

UNSW does not have the right to monitor, access, examine, take custody of, and retain any UNSW Information Resource

a)

False

b)

True

16.

Pick the incorrect answer:

All UNSW Digital Information stored, processed, or transmitted using any UNSW Information Resource

a)

NSW legislation Housing Act 2001

b)

may be subject to the Government Information (Public Access) Act 2009 (NSW)

c)

may be subject to the Health Records and Information Privacy Act 2002 (NSW).

d)

may be subject to the State Records Act 1998 (NSW)

17.

An employee from Finance division has been suspected to be non compliant with with UNSW policies. Who needs to their approve access to UNSW storage services and file shares that may also contain personal information?

a)

Chief Information Security Office or delegate

b)

VP Operations or Delegate

c)

Chief Information Officer or Delegate

d)

Head of School

18.

A developer within UNSW IT is building an application that will store research data from Faculty of Law. The developer is unsure of minimum permitted key size for AES encryption and asks you for advice. Please select the option for the minimum key size permitted as per the Data Security Standard.

a)

No minim length requirement

b)

512

c)

256

d)

128

19.

Access to UNSW Digital Information must only be granted on a “least privilege” and “need to know” basis, but need not be in accordance with the Cyber Security Standard – Identity and Access Management

a)

True

b)

False

20.

UNSW Digital Information that contains personal information or health information about an individual must not be transferred outside New South Wales (NSW), or to a Commonwealth agency, unless a (a)   is conducted to ensure that the transfer is compliant with all applicable privacy laws

21.

HR team is onboarding a new vendor who use TLS 1.3 to encrypt data in transit. The UNSW system interacting with the vendor is using TLS 1.1. As per the UNSW policy, the vendor must alter it's encryption protocol to match the UNSW system.

a)

True

b)

False

22.

Select correct answer(S)

Any user that handles (creates, controls, stores, processes, or transmits) UNSW Digital Information must:

a)

classify the UNSW Digital Information in accordance with the UNSW Data Classification Standard

b)

classify the UNSW Digital Information in consultation with the Data Controller

c)

Determine the Confidentiality Risk Rating

d)

Determine the Inherent Cyber Risk Rating

23.

Choose incorrect answer:

When a new application is onboarded and a new vendor is involved in handling sensitive or highly sensitive data, which process should be kicked off: (Select Multiple)

a)

Data sharing agreement

b)

Data classification

c)

System Classification

d)

CSRA (Cyber Security Risk Assessment)

e)

Source Code Review