wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

IAS_REVIEWER

Total questions: 85

Worksheet time: 50mins

Name
Class
Date
1.

Information security

a)

a “well-informed sense of assurance that the information risks and controls are in balance.”

b)

“the quality or state of being secure – to be free from danger”

c)

relates to the actual input and output processes of the system. It focuses on how data is entered into a system, verified, processed and displayed as output

d)

The branch of philosophy that considers nature, criteria, sources, logic, and the validity of moral judgment.

2.

Security

a)

Feasibility analysis to determine whether project should be continued or outsourced

b)

Components evaluated on make-or-buy decision

c)

“the quality or state of being secure – to be free from danger”

d)

A hacker who intentionally removes or bypasses software copyright protection designed

3.

Laws

a)

oversees the people, processes and technologies within a company’s IT organization to ensure they deliver outcomes that support the goals of the business

b)

The process of identifying risk, assessing its relative magnitude, and taking steps to reduce it to an acceptable level

c)

Main factor is business need

d)

Rules that mandate or prohibit certain behavior and are enforced by the state.

4.

Ethics

a)

The application of controls that reduce the risks to an organization’s information assets to an acceptable leveL

b)

The branch of philosophy that considers nature, criteria, sources, logic, and the validity of moral judgment.

c)

Necessary data support and structures identified

d)

“the quality or state of being secure – to be free from danger”

5.

Cracker

a)

The high-level information security policy that sets the strategic direction, scope, and tone for all of an organization’s security efforts.

b)

A hacker who intentionally removes or bypasses software copyright protection designed to prevent unauthorized duplication or use

c)

is software used by a company to manage key parts of operations, including accounting and resource management.

d)

Also known as a security program policy, general security policy, IT security policy, high-level InfoSec policy, or simply an InfoSec policy

6.

Phreaker

a)

a conceptual abstract design. You do not deal with the physical implementation details yet; you deal only with defining the types of information that you need.

b)

Also known as a security program policy, general security policy, IT security policy, high-level InfoSec policy, or simply an InfoSec policy

c)

Feasibility analysis to determine whether project should be continued or outsourced

d)

a hacker who manipulates the public telephone system to make free calls or disrupt services.

7.

Which is not a definition of Logical design

a)

a conceptual abstract design. You do not deal with the physical implementation details yet; you deal only with defining the types of information that you need.

b)

Creates and develops blueprints for information security

c)

The high-level information security policy that sets the strategic direction, scope, and tone for all of an organization’s security efforts.

d)

Feasibility analysis to determine whether project should be continued or outsourced

8.

Logical design

a)

Main factor is business need

b)

Necessary data support and structures identified

c)

is software used by a company to manage key parts of operations, including accounting and resource management.

d)

Feasibility analysis performed at the end

e)

Technologies to implements physical solution determined

9.

which of the following are the definition of physical design

a)

relates to the actual input and output processes of the system. It focuses on how data is entered into a system, verified, processed and displayed as output.

b)

Needed security technology is evaluated

Alternatives are generated

c)

An intentional or unintentional act that damage or otherwise compromise information and the systems that support it

d)

Final design is selected

10.

In Physical design, At end of phase, feasibility study determines readiness of organization for project such as:

a)

Technologies to support the alternatives identified and evaluated in the logical design are selected

b)

Components evaluated on make-or-buy decision

c)

Feasibility analysis performed

d)

a conceptual abstract design. You do not deal with the physical implementation details yet; you deal only with defining the types of information that you need.

11.

is software used by a company to manage key parts of operations, including accounting and resource management.

(a)  

12.

Enterprise Information Security Policy (EISP)

a)

The high-level information security policy that sets the strategic decision, scope, and tone for all of an organization’s security efforts

b)

Determination of the extent to which the organization’s information assets are exposed or at risk

c)

oversees the people, processes and technologies within a company’s IT organization to ensure they deliver outcomes that support the goals of the business

d)

Consists of details about user access and use permissions and privileges for an organizational asset or resource, such as a file storage system, software component, or network communications device

13.

Enterprise Information Security Policy (EISP)

a)

The process of examining and documenting the security posture of an organization’s information technology and the risks its faces

b)

In its simplest definition, (or economic feasibility) determines whether a particular control is worth its cost

c)

Also known as a security program policy, general security policy, IT security policy, high-level InfoSec policy, or simply an InfoSec policy

d)

Application of controls to reduce the risks to an organization’s data and information systems

14.

CIO (Chief Information Office)

a)

Oversees the people, processes and technologies within a company’s IT organization to ensure they deliver outcomes that support the goals of the business

b)

–An intentional or unintentional act that damage or otherwise compromise information and the systems that support it.CIO (Chief Information Office)

c)

Is the most prominent dedicated toward the promotion of ethical computer use in the United States

15.

Senior technology office

a)

Primarily responsible for advising senior executives on strategic planning

b)

the definition is not here

c)

The application of controls that reduce the risks to an organization’s information assets to an acceptable leveL

16.

Chief Information Security Officer

a)

Primarily responsible for advising senior executives on strategic planning

b)

All of the it

c)

A senior-level executive within an organization, responsible for establishing and maintaining the enterprise vision, strategy and program to ensure information assets and technologies are adequately protected

d)

oversees the people, processes and technologies within a company’s IT organization to ensure they deliver outcomes that support the goals of the business,

17.

Attack

a)

An intentional or unintentional act that can damage or otherwise compromise information and the systems that support it.

b)

A person who accesses systems and information without authorization and often illegally.

c)

The unauthorized duplication, installation, or distribution of copyrighted computer software, which is a violation of intellectual property

18.

Exploit

a)

A person who accesses systems and information without authorization and often illegally.

b)

A technique used to compromise a system

c)

A potential weakness in an asset or its defensive control system

19.

Vulnerability

a)

A potential weakness in an asset or its defensive control system.

b)

The probability of an unwanted occurrence, such as an adverse event or loss.

c)

A technique used to compromise a system

20.

Risk identification

a)

this category includes acts performed without intent or malicious purpose or in ignorance by an authorized user

b)

None

c)

Unauthorized access and/or data collection

d)

The recognition, enumeration, and documentation of risks to an organization’s information assets.

21.

Risk assessment

a)

A form of social engineering in which the attacker provides what appears to be legitimate communication, but it contains hidden or embedded code that redirects the reply to a third-party site in an effort to extract personal or confidential information.

b)

A determination of the extent to which an organization’s information assets are exposed to risk

c)

all

d)

The application of computing and resources to try every possible password combination

22.

Risk management

a)

The unauthorized duplication, installation, or distribution of copyrighted computer software, which is a violation of intellectual property

b)

The process of identifying risk, assessing its relative magnitude, and taking steps to reduce it to an acceptable level

c)

Sometimes called acts of God, can present some of the most dangerous threats because they usually occur with little warning and are beyond the control of people

23.

Risk control

a)

A determination of the extent to which an organization’s information assets are exposed to risk

b)

The probability of an unwanted occurrence, such as an adverse event or loss.

c)

both

d)

none

24.

Software piracy

a)

The unauthorized duplication, installation, or distribution of copyrighted computer software, which is a violation of intellectual property

b)

A potential weakness in an asset or its defensive control system.

c)

standard that has been widely adopted or accepted by a public group rather than a formal standards organization.

25.

Hacker

a)

A person who accesses systems and information without authorization and often illegally.

b)

both

c)

An intentional or unintentional act that can damage or otherwise compromise information and the systems that support it.

26.

Brute force

a)

The application of computing and resources to try every possible password combination

b)

Specification of authorization that governs the rights and privileges of users to a particular information asset

c)

all

d)

The probability of an unwanted occurrence, such as an adverse event or loss.

27.

Espionage (categories of threat)

a)

Unauthorized access and/or data collection

b)

Accidents, employee mistakes

c)

this category includes acts performed without intent or malicious purpose or in ignorance by an authorized user

d)

Fire, flood, earthquake, lightning

28.

Force of nature (categories of threat)

Floods / fire / earthquake (categories of threat)

a)

Fire, flood, earthquake, lightning

Forces of nature

b)

Accidents, employee mistakes

Forces of nature

c)

Unauthorized access and/or data collection

Forces of nature

29.

Human error or failure (categories of threat)

a)

A. this category includes acts performed without intent or malicious purpose or in ignorance by an authorized userA.

b)

B. Accidents, employee mistakes

c)

both a n b

d)

C. Non Mandatory recommendations the employee may use as reference in complying with a policy.

30.

Phishing

a)

Specification of authorization that governs the rights and privileges of users to a particular information asset

b)

A type of phishing campaign that target a specific person or group and often will include information known to be of interest of target market

c)

A form of social engineering in which the attacker provides what appears to be legitimate communication, but it contains hidden or embedded code that redirects the reply to a third-party site in an effort to extract personal or confidential information.

31.

Spear Phishing: choose the definitions

a)

A type of phishing campaign that target a specific person or group and often will include information known to be of interest of target market

b)

Any highly targeted phishing attack

c)

The process of defining and specifying the long-term direction (strategy) to be taken by an organization, and the allocation and acquisition of resources needed to pursue this effort

32.

Strategic planning

a)

The process of defining and specifying the long-term direction (strategy) to be taken by an organization, and the allocation and acquisition of resources needed to pursue this effort

b)

target a specific person or group and often will include information known to be of interest of target market

33.

Operational planning

a)

none

b)

The actions taken by management to specify the short-term goals and objectives of the organization in order to obtain specified tactical goals, followed by estimates and schedules for the allocation policy of resources necessary to achieve those goals and objectives.

c)

Also known as an economic feasibility study, the formal assessment and presentation of the economic expenditures needed for a particular security control, contrasted with its projected value to the organization.

34.

Tactical Planning

a)

the actions taken by management to specify the intermediate goals and objectives of the organization in order to obtain specified strategic goals, followed by estimates and schedules for allocation of resources necessary to achieve those goals and objectives.

b)

property owned by a person or company, regarded as having value and available to meet debts, commitments, or legacies. - The organizational resource that is being protected

c)

form of social engineering in which the attacker pretends to be an authority figure who needs information to confirm the target’s identity, but the real object is to trick the target into revealing confidential information. Pretexting is commonly performed by telephone

d)

The actions taken by management to specify the short-term goals and objectives of the organization in order to obtain specified tactical goals, followed by estimates and schedules for the allocation policy of resources necessary to achieve those goals and objectives

35.

which is not the definition of Guidelines?

a)

standard that has been widely adopted or accepted by a public group rather than a formal standards organization.

b)

Non Mandatory recommendations the employee may use as reference in complying with a policy

c)

consist of details about user access and use permissions and privileges for an organizational asset resource, such as a file storage system, software component or network communications device

36.

Access control list

a)

consist of details about user access and use permissions and privileges for an organizational asset resource, such as a file storage system, software component or network communications device.

b)

Specification of authorization that governs the rights and privileges of users to a particular information asset

c)

Include user access lists, matrices, and capabilities tables,

d)

all

37.

CBA formula

a)

Also known as an economic feasibility study, the formal assessment and presentation of the economic expenditures needed for a particular security control, contrasted with its projected value to the organization.

b)

The actions taken by management to specify the short-term goals and objectives of the organization in order to obtain specified tactical goals, followed by estimates and schedules for the allocation policy of resources necessary to achieve those goals and objectives

c)

property owned by a person or company, regarded as having value and available to meet debts, commitments, or legacies

38.

choose the definitions of Asset

a)

property owned by a person or company, regarded as having value and available to meet debts, commitments, or legacies

b)

The organizational resource that is being protected

c)

none

d)

Can be logical, such as a website, software information, or data; or can be physical, such as a person, computer system, hardware, or other tangible object. company information or personal data, and generating profit.

39.

De facto Standard

a)

Standard that has been widely adopted or accepted by a public group rather than a formal standards organization.

b)

A technique for gaining unauthorized access to computers using a forged or modified source IP address to give the perception that messages are coming from a trusted host.

c)

the best way to detect a rootkit infection, which your antivirus solution can initiate

d)

form of social engineering in which the attacker pretends to be an authority figure who needs information to confirm the target’s identity, but the real object is to trick the target into revealing confidential information. Pretexting is commonly performed by telephone.

40.

Wireless Hacking Tools

a)

A group of attacks whereby a person intercepts a communications stream and inserts himself in the conversation to convince each of the legitimate parties that he is the other communications partner. Some man-in-the-middle attacks involve encryption functions.

b)

Are used to intentionally hack into wireless networks to detect security vulnerabilities

c)

A table of hash values and their corresponding plaintext values that can be used to look up password values if an attacker is able to steal a system’s encrypted password file.

41.

Rootkit detector

a)

the best way to detect a rootkit infection, which your antivirus solution can initiate

b)

are hardware and software tools that can be used to aid in the recovery and preservation of digital evidence

c)

A table of hash values and their corresponding plaintext values that can be used to look up password values if an attacker is able to steal a system’s encrypted password file.

42.

Forensic tools

a)

are hardware and software tools that can be used to aid in the recovery and preservation of digital evidence

b)

The average amount of time between hardware failures, calculated as the total amount of operation time for a specified number of units divided by the total number of failures.

c)

the best way to detect a rootkit infection, which your antivirus solution can initiate

43.

Rainbow table

a)

A table of hash values and their corresponding plaintext values that can be used to look up password values if an attacker is able to steal a system’s encrypted password file.

b)

a software program or hardware appliance that can intercept, copy, and interpret network traffic

c)

Used by black hats to reverse engineer binary files when writing exploits. They are also used by white hats when analyzing malware.

44.

Packet sniffer

a)

all

b)

Escalating privileges to gain administrator-level or root access control over a smartphone operating system (typically associated with Apple iOS smartphones).

c)

Used by black hats to reverse engineer binary files when writing exploits. They are also used by white hats when analyzing malware.

d)

a software program or hardware appliance that can intercept, copy, and interpret network traffic.

45.

Debuggers

a)

Escalating privileges to gain administrator-level or root access control over a smartphone operating system (typically associated with Apple iOS smartphones)

b)

none

c)

Used by black hats to reverse engineer binary files when writing exploits. They are also used by white hats when analyzing malware.

d)

The average amount of time a computer repair technician needs to determine the cause of a failure

46.

Jailbreaking

a)

Escalating privileges to gain administrator-level or root access control over a smartphone operating system (typically associated with Apple iOS smartphones). See also root.

b)

The average amount of time between hardware failures, calculated as the total amount of operation time for a specified number of units divided by the total number of failures.

c)

A group of attacks whereby a person intercepts a communications stream and inserts himself in the conversation to convince each of the legitimate parties that he is the other communications partner. Some man-in-the-middle attacks involve encryption functions.

47.

Spoofing

a)

A technique for gaining unauthorized access to computers using a forged or modified source IP address to give the perception that messages are coming from a trusted host.

b)

none

c)

The process of using social skills to convince people to reveal access credentials or other valuable information to an attacker

d)

A table of hash values and their corresponding plaintext values that can be used to look up password values if an attacker is able to steal a system’s encrypted password file.

48.

Social engineering

a)

The process of using social skills to convince people to reveal access credentials or other valuable information to an attacker

b)

form of social engineering in which the attacker pretends to be an authority figure who needs information to confirm the target’s identity, but the real object is to trick the target into revealing confidential information. Pretexting is commonly performed by telephone.

c)

The average amount of time between hardware failures, calculated as the total amount of operation time for a specified number of units divided by the total number of failures

49.

Pretexting

a)

form of social engineering in which the attacker pretends to be an authority figure who needs information to confirm the target’s identity, but the real object is to trick the target into revealing confidential information. Pretexting is commonly performed by telephone.

b)

The process of using social skills to convince people to reveal access credentials or other valuable information to an attacker

c)

Used by black hats to reverse engineer binary files when writing exploits. They are also used by white hats when analyzing malware.

50.

Man-in-the-middle

a)

The average amount of time between hardware failures, calculated as the total amount of operation time for a specified number of units divided by the total number of failures.

b)

A group of attacks whereby a person intercepts a communications stream and inserts himself in the conversation to convince each of the legitimate parties that he is the other communications partner. Some man-in-the-middle attacks involve encryption functions.

c)

Escalating privileges to gain administrator-level or root access control over a smartphone operating system (typically associated with Apple iOS smartphones)

51.

Mean time between failure (MTBF)

a)

The average amount of time between hardware failures, calculated as the total amount of operation time for a specified number of units divided by the total number of failures.

b)

The average amount of time a computer repair technician needs to determine the cause of a failure.

c)

The average amount of time until the next hardware failure

d)

The average amount of time a computer repair technician needs to resolve the cause of a failure through replacement or repair of a faulty unit.

52.

Mean time to diagnose (MTTD

a)

The average amount of time between hardware failures, calculated as the total amount of operation time for a specified number of units divided by the total number of failures.

b)

- The average amount of time a computer repair technician needs to resolve the cause of a failure through replacement or repair of a faulty unit.

c)

The average amount of time a computer repair technician needs to determine the cause of a failure.

d)

The average amount of time until the next hardware failure.

53.

Mean time to failure (MTTF)

a)

The average amount of time until the next hardware failure.

b)

The average amount of time a computer repair technician needs to resolve the cause of a failure through replacement or repair of a faulty unit

c)

The average amount of time a computer repair technician needs to determine the cause of a failure.

d)

The average amount of time between hardware failures, calculated as the total amount of operation time for a specified number of units divided by the total number of failures.

54.

Mean time to repair (MTTR)

a)

The average amount of time between hardware failures, calculated as the total amount of operation time for a specified number of units divided by the total number of failures.

b)

The average amount of time a computer repair technician needs to determine the cause of a failure.

c)

The average amount of time until the next hardware failure

d)

The average amount of time a computer repair technician needs to resolve the cause of a failure through replacement or repair of a faulty unit.

55.

Cyber security

a)

A type of malware that is attached to other executable programs. When activated, it replicates and propagates itself to multiple systems, spreading by multiple communications vectors. For example, a virus might send copies of itself to all users in the infected system’s e-mail program

b)

the application of technologies, processes, and controls to protect systems, networks, programs, devices and data from cyber attacks.

c)

are individuals or teams of people who use technology to commit malicious activities on digital systems or networks with the intention of stealing sensitive

56.

Cyber criminals

a)

none

b)

are individuals or teams of people who use technology to commit malicious activities on digital systems or networks with the intention of stealing sensitive

c)

A type of malware that is capable of activation and replication without being attached to an existing program.

d)

A malware program that hides its true nature and reveals its designed behavior only when activated.

57.

Cyberactivist also known as

a)

hacktivist

b)

cyberhacker

c)

hacker

d)

security activist

58.

Cyber terrorist

a)

A hacker who attacks systems to conduct terrorist activities via networks or internet pathways.

b)

is often used as a synonym of malware, but in reality, there are some subtle differences between the two terms.

c)

none

59.

Copyright

a)

Computer software specifically designed to perform malicious or unwanted actions.

b)

Copyright Act (update to U.S. Copyright Law (17 USC)) 1976 - Protects intellectual property, including publications and software

c)

Unauthorized entry into the real or virtual property of another party.

60.

Badware

a)

is often used as a synonym of malware, but in reality, there are some subtle differences between the two terms.

b)

A hacker who attacks systems to conduct terrorist activities via networks or internet pathways.

c)

Computer software specifically designed to perform malicious or unwanted actions.

61.

Malware

a)

Computer software specifically designed to perform malicious or unwanted actions.

b)

The severity of the penalty depends on the value of the information obtained

c)

is often used as a synonym of malware, but in reality, there are some subtle differences between the two terms.

62.

Virus

a)

ALL

b)

A type of malware that is capable of activation and replication without being attached to an existing program.

c)

A type of malware that is attached to other executable programs. When activated, it replicates and propagates itself to multiple systems, spreading by multiple communications vectors. For example, a virus might send copies of itself to all users in the infected system’s e-mail program.

d)

A malware program that hides its true nature and reveals its designed behavior only when activated.

63.

Worm

a)

A malware program that hides its true nature and reveals its designed behavior only when activated.

b)

A type of malware that is capable of activation and replication without being attached to an existing program

c)

none

d)

A type of malware that is attached to other executable programs. When activated, it replicates and propagates itself to multiple systems, spreading by multiple communications vectors.

64.

Trojan horse

a)

Malware (a virus or worm) that over time changes the way it appears to antivirus software programs, making it undetectable by techniques that look for preconfigured signatures.

b)

A type of malware that is capable of activation and replication without being attached to an existing program

c)

A malware program that hides its true nature and reveals its designed behavior only when activated.

65.

Polymorphic threat

a)

Copyright Act (update to U.S. Copyright Law (17 USC)) 1976 - Protects intellectual property, including publications and softwar

b)

Malware (a virus or worm) that over time changes the way it appears to antivirus software programs, making it undetectable by techniques that look for preconfigured signatures.

c)

An attack that attempts to overwhelm a computer target’s ability to handle incoming communications, prohibiting legitimate users from accessing those systems.

66.

Denial-of-service (DoS) attack

a)

is often used as a synonym of malware, but in reality, there are some subtle differences between the two terms.

b)

Computer software specifically designed to perform malicious or unwanted actions.

c)

An attack that attempts to overwhelm a computer target’s ability to handle incoming communications, prohibiting legitimate users from accessing those systems.

d)

The severity of the penalty depends on the value of the information obtained

67.

Trespass

a)

Unauthorized entry into the real or virtual property of another party.

b)

Computer software specifically designed to perform malicious or unwanted actions.

c)

are individuals or teams of people who use technology to commit malicious activities on digital systems or networks with the intention of stealing sensitive

68.

The severity of the penalty depends on the value of the information obtained and whether the offense is judged to have been committed for the following reasons:

a)

Financial gain

b)

Fame Seeking

c)

Password attacks

d)

none

69.

In Financial gain, the offense is judged to have been committed for what following reasons:

a)

• For purposes of commercial

b)

• For private financial gain

c)

• In furtherance of a criminal act

d)

Necessary data support and structures identified

70.

Fame Seeking

a)

Computer software specifically designed to perform malicious or unwanted actions.

b)

Attempting to guess or reverse-calculate a password is often called cracking

c)

Widespread reputation, especially of a favorable character, renown

d)

all

71.

Password cracker

a)

Attempting to guess or reverse-calculate a password is often called cracking.

b)

Widespread reputation, especially of a favorable character, renown

c)

fall under the category of espionage or trespass just as lock-picking falls under breaking and entering.

d)

none

72.

In password cracker, there are a number of alternative approaches to password cracking:

a)

• Brute force

b)

• Dictionary

c)

• Rainbow tables

d)

• Social engineering

e)

•Malware

73.

Password attacks

a)

Computer software specifically designed to perform malicious or unwanted actions.

b)

A hacker who attacks systems to conduct terrorist activities via networks or internet pathways.

c)

Attempting to guess or reverse-calculate a password is often called cracking.

d)

fall under the category of espionage or trespass just as lock-picking falls under breaking and entering.

74.

Password Based attack

a)

are individuals or teams of people who use technology to commit malicious activities on digital systems or networks with the intention of stealing sensitive

b)

typically facilitated through the use of software that expedites cracking or guessing passwords

c)

fall under the category of espionage or trespass just as lock-picking falls under breaking and entering.

d)

Any various method used to maliciously authenticate into password-protected accounts

75.

Computer Ethics Institute

a)

fall under the category of espionage or trespass just as lock-picking falls under breaking and entering.

b)

Is the most prominent dedicated toward the promotion of ethical computer use in the United States

c)

none

d)

typically facilitated through the use of software that expedites cracking or guessing passwords

76.

Thou shalt not use a computer to harm other (a)   :

77.

Thou shalt not (a)   with other people's computer work

78.

Thou shalt not (a)   in other people's computer files:

79.

Thou shalt not use a computer to steal

(a)  

80.

Thou shalt not use a computer to bear (a)  

81.

Thou shalt not (a)   for which you have not paid:

82.

Thou shalt not use other people's computer resources without (a)   :

83.

Thou shalt not appropriate other people's (a)   :

84.

Thou shalt think about the social consequences of the program you are writing or the (a)  

85.

Thou shalt always use a computer in ways that ensure (a)   for your fellow humans