wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Practice Test for Information Assurance and Security 1 - Prelims

Total questions: 70

Worksheet time: 35mins

Name
Class
Date
1.

It is an asset that, like other important business assets, has value to an organization and consequently needs to be suitably protected.

a)

Security

b)

Information Security

c)

Information

d)

Information System

2.

The architecture where an integrated combination of appliances, systems and solutions, software, alarms, and vulnerability scans working together

a)

Information

b)

Information System

c)

Security

d)

Information Security

3.

Which of the following is NOT an Information Security statement?

a)

Networks that computers and devices use should also be secured

b)

Computers and digital devices are becoming integral to conducting business

c)

Which also makes them a target of attack

d)

Devices needs to be secured

4.

It restricts access to authorized individuals.

a)

Availability

b)

Integrity

c)

Confidentiality

d)

Authentication

5.

The information can be accessed and modified by authorized individuals in an appropriate timeframe.

a)

Authentication

b)

Integrity

c)

Availability

d)

Confidentiality

6.

It is a factor of identification that has a user ID and password.

a)

Something you know

b)

Something you are

c)

Something you have

d)

Something you keep

7.

It is a factor of identification that uses physical characteristics.

a)

Something you are

b)

Something you keep

c)

Something you have

d)

Something you know

8.

It only provides access to information necessary to perform their job duties to read, modify, add, and/or delete information.

a)

Password

b)

Access Control

c)

Virtual Private Networks

d)

Authentication

9.

It is created for each resource that can read, write, delete or add information.

a)

Access Control

b)

Access control list

c)

Authentication

d)

Role-based access control

10.

It is an algorithm that encodes or scrambles information during transmission or storage.

a)

symmetric key

b)

asymmetric key

c)

decryption

d)

encryption

11.

It is a possibility that a threat exploits a vulnerability in an asset and causes damage or loss to the asset.

a)

Risk

b)

Vulnerability

c)

Threat

d)

Agent

12.

It is something that can potentially cause damage to the organization, IT Systems or network.

a)

Risk

b)

Agent

c)

Threat

d)

Vulnerability

13.

It is a weakness in the organization, IT Systems, or network that can be exploited by a threat.

a)

Risk

b)

Agent

c)

Vulnerability

d)

Threat

14.

Which is NOT an Element of Threats?

a)

Agent

b)

Motive

c)

Risk

d)

Result

15.

Which of the following is NOT an Agent of threat element?

a)

Human

b)

Machine

c)

Software

d)

Nature

16.

It is an element of threat that outcomes the applied threat.

a)

Agent

b)

Motive

c)

Result

d)

Risk

17.

Which of the following is NOT a possible threat?

a)

External Parties

b)

Employees

c)

Growth in networking and distributed computing

d)

High awareness of security issues

18.

Which of the following is NOT a Threat Source?

a)

Terroist

b)

Internal Hackers

c)

Owner of the company

d)

Poorly trained employees

19.

To provide management direction and support for Information security.

a)

Human Resources Security

b)

Asset Management

c)

Information Security Policy

d)

Organization of Information Security

20.

To prevent unauthorized access, theft, compromise, damage information and information processing facilities.

a)

Physical & Environmental Security

b)

Information Systems Acquisition

c)

Access Control

d)

Communications & Operations Management

21.

It is manipulating a person into knowingly or unknowingly giving up information.

a)

Risk Mangement

b)

Threats

c)

Social Engineering

d)

Information Security

22.

Which of the following is NOT part of the Social Engineering attack cycle?

a)

execution

b)

exploitation/expedition

c)

information gathering

d)

developing relationship

23.

It is an aggressor that will first try to build up a good bonding with the target and he makes sure that he gains the trust of the target which he’ll later exploit.

a)

Developing Relationship

b)

Information Gathering

c)

Execution

d)

Exploitation

24.

Once the target has finished the task requested by the attacker,

the cycle is complete.

a)

Exploitation

b)

Developing Relationship

c)

Execution

d)

Information Gathering

25.

These attacks deceive the user into

believing that the application in use is truly providing them with

security which is not the fact always.

a)

Tactical attacks

b)

Phishing

c)

Technical attacks

d)

Non-technical attacks

26.

Which of the following is NOT part of the Pre-atack Phase?

a)

Enumeration

b)

Identification

c)

Scanning

d)

Footprinting

27.

Which of the following is NOT Information Gathering Methodology?

a)

Ignore operating systems

b)

Locate the network range

c)

Unearth initial information

d)

Ascertain active machines

28.

It is used to find personal information like residential addresses, contact numbers, date of birth, and change of location.

a)

Web Data Extractor

b)

People Search

c)

DNS Enumerator

d)

SpiderFoot

29.

It is a free, open-source, domain footprinting tool that will scarpe the websites on the domain, as well as search Google, Netcraft, DNS to build up information.

a)

People Search

b)

Web Data Extractor

c)

DNS Enumerator

d)

SpiderFoot

30.

It is a tool to extract targeted company's contact data from the internet.

a)

People Search

b)

SpiderFoot

c)

Web Data Extractor

d)

DNS Enumerator

31.

It integrates the world's most advanced route tracing software with performance measurements.

a)

Path Analyzer Pro

b)

Google Earth

c)

Reamweaver

d)

eMailTrackerPro

32.

It uses planet imagery and geographic information right on your desktop.

a)

Reamweaver

b)

eMailTrackerPro

c)

Path Analyzer Pro

d)

Google Earth

33.

It is an email analysis tool that enables analysis of an email and its headers automatically and provides graphical results.

a)

Path Analyzer Pro

b)

Google Earth

c)

Reamweaver

d)

eMailTrackerPro

34.

It is a web site stealing tool that has everything you need instantly.

a)

eMailTrackerPro

b)

Reamweaver

c)

Google Earth

d)

Path Analyzer Pro

35.

It is an automated sub-domain retrieval tool.

a)

DNS Enumerator

b)

SpiderFoot

c)

People Search

d)

Web Data Extractor

36.

It provides rich information to perform passive reconnaissance.

a)

Web Data Extractor

b)

DNS Enumerator

c)

People Search

d)

Google

37.

It is the process of gathering resources regarding a target computer or network  system.

a)

Footprinting

b)

Scanning

c)

Identification

d)

Enumeration

38.

Which of the following is not a Footprinting resource?

a)

temperature today

b)

phone number

c)

IP addresses

d)

e-mail addresses

39.

It is used to query information regarding certain domain names.

a)

who.is

b)

nslookup

c)

SmartWhois

d)

tracert

40.

It is a tool that connects to an available database to provide information  regarding a domain or host.

a)

SmartWhois

b)

tracert

c)

who.is

d)

nslookup

41.

It is a program that provides the hostname of a particular IP address  and vice-versa.

a)

NsLookup

b)

Whois

c)

SmartWhois

d)

tracert

42.

It is a program that traces packet routes.

a)

tracert

b)

SmartWhois

c)

nslookup

d)

who.is

43.

It is is a graphical version of tracert.

a)

SmartWhois

b)

Neo trace and visual route

c)

tracert

d)

Sam Spade

44.

It is a general purpose  Internet utility  package which  includes ping,  nslookup, whois, IP  block, and  traceroute function.

a)

tracert

b)

Sam Spade

c)

Neo trace and visual route

d)

SmartWhois

45.

It detects the live system on target network and services running on target computer.

a)

Pinger

b)

War Dialers

c)

Scanning

d)

Port scanner

46.

These are tools that is used to scan a range of  phone nos. for vulnerable modems.

a)

War Dialers

b)

Pinger

c)

Scanning

d)

Port scanner

47.

It is a tool that sends an ICMP echo request  to a range of IP addresses and lists all  hosts that reply.

a)

War Dialers

b)

Pinger

c)

Scanning

d)

Port Scanner

48.

It is a tool that is used to detect services  running in a computer.

a)

Port scanner

b)

Scanning

c)

War Dialers

d)

Pinger

49.

It is used to determine the operating system  running in a computer.

a)

Foot printing

b)

Hand printing

c)

Port scanner

d)

Finger printing

50.

It is a type of Fingerprinting that takes advantage of the fact that OS  vendors implement the TCP stack  differently and sends a packet to target computer and  based on the response it guesses the OS  running in the computer.

a)

Foot printing active

b)

Finger printing passive

c)

Finger printing active

d)

Foot printing passive

51.

It is recognized as essential to protect vital processes and the systems that provide those processes.

a)

Security

b)

Information

c)

Information Security

d)

Policy

52.

It is a management framework for implementation.

a)

Organization of Information Security

b)

Information Security Policy

c)

Asset Mangement

d)

Human Resources Security

53.

To ensure the security of valuable organizational IT and its related assets.

a)

Organization of Information Security

b)

Asset Management

c)

Human Resources Security

d)

Information Security Policy

54.

To reduce the risks of human error, theft, fraud or misuse of facilities.

a)

Asset Mangement

b)

Information Security Policy

c)

Organization of Information Security

d)

Human Resources Security

55.

The target could then be manipulated by the ‘trusted’ attacker to reveal their sensitive information like password to carry out an action.

a)

Exploitation

b)

Information Gathering

c)

Developing Relationship

d)

Execution

56.

There could be variety of techniques which is used by the aggressor to gather sensitive information about the target(s).

a)

Exploitation

b)

Developing Relationship

c)

Information Gathering

d)

Execution

57.

It can be made private using an internal network to limit access to them.

a)

Virtual Private Network (VPN)

b)

Firewalls

c)

Access Control

d)

Authentication

58.

Single-factor authentication (user ID/password) is the easiest to break.

a)

Backup

b)

Encryption

c)

Password

d)

Firewalls

59.

Persons accessing the information is who they say they are.

a)

Authentication

b)

Access Control

c)

Firewalls

d)

Backup

60.

Data has not been altered in an unauthorized manner.

a)

Integrity

b)

Availability

c)

Confidentiality

d)

Result

61.

These attacks are those attacks that are purely perpetrated through

the art of deception.

a)

Non-technical attacks

b)

Technical attacks

c)

Attack

d)

Social Engineering attacks

62.

It is a new term of the century which is used to take over a private.

a)

Support Staff

b)

Spam e-mails

c)

Phishing

d)

Hoaxing

63.

Hundreds and thousands of e-mails are

sent to the victim. This is tightly related with phishing attempt.

a)

Hoaxing

b)

Spam e-mails

c)

Phishing

d)

Support Staff

64.

The attacker acts as a clean support crew to help users to fix any problem

a)

Support Staff

b)

Hoaxing

c)

Spam e-mails

d)

Phishing

65.

It is a trick to make the user believe that something false is real.

a)

Spam e-mails

b)

Hoaxing

c)

Support Staff

d)

Phishing

66.

The attacker can call up to the organization’s computer help desk and pretend to have trouble accessing the system.

a)

Authoritative Voice

b)

Hoaxing

c)

Support Staff

d)

Spam e-mails

67.

It is an element of threat performs as a catalyst of threat.

a)

Information

b)

Motive

c)

Result

d)

Agent

68.

It is an element of threat that causes the agent to act.

a)

Result

b)

Motive

c)

Agent

d)

Security

69.

To ensure the correct and secure operation of information processing facilities.

a)

Communications & Operations Management

b)

Access Control

c)

Information Security Incident Management

d)

Information Systems Acquisition, Development & Maintenance

70.

To ensure security built into information systems.

a)

Communications & Operations Management

b)

Information Systems Acquisition, Development & Maintenance

c)

Access Control

d)

Information Security Incident Management