Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

IAS2-NW3A

Total questions: 50

Worksheet time: 50mins

Name
Class
Date
1.

Which of the following interpret requirements and apply them to specific situations?

a)

Policies

b)

Standards

c)

Guidelines

d)

Procedure

2.

Business continuity plans (BCPs) associated with organizational information systems should be developed primarily on the basis of:

a)

Available Resources

b)

Business needs

c)

Levels of Effort

d)

Projected Costs

3.

Which cybersecurity principle is most important when attempting to trace the source of malicious activity?

a)

Availability

b)

Nonrepudiation

c)

Integrity

d)

Confidentiality

4.

Outsourcing poses the greatest risk to an organization when it involves:

a)

Business Support Services

b)

Core Business Functions

c)

Technology Infrastructure

d)

Cybersecurity Capabilies

5.

Risk assessments should be performed:

a)

At the start of a program

b)

On a regular basis

c)

When an asset changes

d)

When a vulnerability is discovered

6.

During which phase of the system development lifecycle (SDLC) should security first be considered?

a)

Analysis

b)

Planning

c)

Design

d)

Implementation

7.

Who has the greatest influence over access security in a password authentication environment?

a)

System Administrators

b)

Users

c)

Business Executives

d)

Security Manager

8.

A cybersecurity architecture designed around the concept of a perimeter is said to be:

a)

Data-centric

b)

System-centric

c)

User-centric

d)

Integrated

9.

Which two factors are used to calculate the likelihood of an event?

a)

Vulnerability and Asset Value

b)

Threat and Vulnerability

c)

Asset Count and Asset Value

d)

Threat and Asset Value

10.

 _______________- includes security processes such as conducting risk management exercises, security awareness programs, policy development, and compliance efforts with laws and regulations.

a)

Tactical Management

b)

Strategic Management

c)

Operational Management

d)

Level of Controls

11.

The_____________ to management is a strategy in which the decision-making process occurs at the highest level and is then communicated to the rest of the team. This style can be applied at the project, team, or even the company level, and can be adjusted according to the particular group's needs.

a)

top-down approach

b)

bottom-up approach

c)

Outsourcing

d)

Organizational Maturity

12.

Prior to applying a top-down or bottom-up approach, an organization needs to ___________ the associated factors and costs of protecting information.

a)

secure

b)

analysis

c)

analyze

d)

protect

13.

_______________ where an information assurance management program is managed under a centralized unit with ultimate accountability and responsibility for the program.

a)

Centralized structure

b)

Distributed structure

c)

Hybrid structure

d)

Organizational maturity

14.

_____________________ is important in determining an effective information assurance program. 

a)

Centralized structure

b)

Distributed structure

c)

Hybrid structure

d)

Organizational maturity

15.

_______________ will be directly involved in the planning of local security systems.

a)

Managers

b)

Information assets

c)

Executives

d)

Employees

16.

____________________ will have a better understanding of the organization and will be able to effectively play their role and use their authority to protect information.

a)

Managers

b)

Information assets

c)

Executives

d)

Employees

17.

CIA of assets stands for_______.

a)

Confidentiality, Integration and Availability

b)

Confidentiality, Integrity and Accessibility

c)

Continuity, Integrity, and Availability

d)

Confidentiality, Integrity and Availability

18.

The _____________ is the overall process of creating, implementing, and decommissioning information systems through a multistep process from initiation, analysis, design, implementation, and maintenance to disposal.

a)

service acquisition life cycle

b)

information assurance and security

c)

risk mitigation

d)

system development life cycle

19.

In this phase, the need for a system is established, and the requirement capabilities of the system are stated.

a)

initiation

b)

acquisition and development

c)

implementation/maintenance

d)

disposal

20.

Information assurance in the system or service acquisition life cycle, under the system development the ____________ must be able to provide the solutions.

a)

information assrurance teams

b)

system developers

c)

system owners

d)

system acquisition team

21.

_____________ is the process of ensuring changes to the organization are communicated to all relevant stakeholders and impacts are understood prior to changes being implemented.

a)

Change management

b)

Configuration management

c)

Physical and environmental security

d)

Organizations benefit

22.

_____________ –is a subprocess of change management for information systems and services.

a)

Change management

b)

Configuration management

c)

Physical and environmental security

d)

Organizations benefit

23.

_____________ protects an organization’s physical infrastructure, its equipment, and its facilities, as well as its employees, from physical events, threats, or incidents.

a)

Change management

b)

Configuration management

c)

Physical and environmental security

d)

Organizations benefit

24.

The acts of sabotage or vandalism can impair hardware components. 

a)

Environmental disruption

b)

Interruptions to service

c)

Loss of system integrity

d)

Physical damage

25.

The concept of a layered defense approach which also known as _____________, is that if an intruder successfully manages to penetrate one control layer, there will be other control layers in his way before he can access the organization’s assets. 

a)

defense-in-depth approach

b)

physical security

c)

environmental security

d)

system security

26.

The first line of defense in safeguarding employees, information resources, and property is the ____________.

a)

security perimeter

b)

physical protection

c)

perimeter protection

d)

system protection

27.

_______________ also includes deploying lockable doors and windows, grills for windows, and fire escapes. 

a)

security perimeter

b)

physical protection

c)

perimeter protection

d)

system protection

28.

____________ completely erases the information stored on the magnetic surface.

a)

shredding

b)

burning

c)

degaussing

d)

disposing

29.

_________ to teach or improve an individual’s skill, knowledge, or attitude, which allows a person to carry out a specific function.

a)

training aims

b)

training environment

c)

awareness aims

d)

education context

30.

In a _________________, the employee is taught to use specific skills as part of specific job performance. 

a)

training aims

b)

training environment

c)

awareness aims

d)

education context

31.

In an ________________, the employee would be encouraged to examine and evaluate not only skills and methods of work but fundamental operating principles and tenants upon which job skills are based.

a)

training aims

b)

training environment

c)

awareness aims

d)

education context

32.

______________ is a technique for hiding information by transforming it so that only authorized individuals can access it in its original form.

a)

Cryptography

b)

Cryptographic tools

c)

Encryption techniques

d)

Firewalls

33.

_______________–for hosts range from encryption of the entire hard disk, database encryption, selective folder (group of files) encryption, or individual file encryption.

a)

Cryptography

b)

Cryptographic tools

c)

Encryption techniques

d)

Firewalls

34.

A __________________ inspects network traffic based on organizational information assurance policy and configuration. 

a)

network intrusion prevention system (NIPS)

b)

signatures

c)

anomaly-based NIPS

d)

proxy servers

35.

To detect attacks, the contents of the network packets are checked for distinctive sequences called ________________.

a)

network intrusion prevention system (NIPS)

b)

signatures

c)

anomaly-based NIPS

d)

proxy servers

36.

The simplest form of a ______________ is called a gateway. 

a)

network intrusion prevention system (NIPS)

b)

signatures

c)

anomaly-based NIPS

d)

proxy servers

37.

A _____________ is a copy of information assets: data, software, or hardware. 

a)

backup

b)

Backing up systems

c)

document

d)

restoration

38.

______________  is an effective means of mitigating information assurance risks.

a)

Change management

b)

Configuration management

c)

Patch Management

d)

Documentation

39.

______________  requires performing planned and timely system patches to maintain operational efficiency and effectiveness, mitigate information security vulnerabilities, and maintain the stability of IT systems.

a)

Change management

b)

Configuration management

c)

Patch Management

d)

Documentation

40.

If intruders are able to gain physical access to hardware components, they may be able to bypass logical access controls. 

a)

Environmental disruption

b)

Interruptions to service

c)

Loss of system integrity

d)

Physical damage

41.

Serious business interruption may cause business disaster. 

a)

Environmental disruption

b)

Interruptions to service

c)

Loss of system integrity

d)

Physical damage

42.

In handling of media, ______________ all media used to store information.

a)

secure

b)

protect

c)

safeguard

d)

dispose

43.

To ensure that an _______________ is introduced effectively, it needs to be designed and customized to the needs of the organization. 

a)

information assurance requirements

b)

information-processing systems

c)

information assurance plan

d)

information assurance enterprise architectures

44.

An information assurance policy is the basis of an effective information assurance program. 

a)

Information Assurance Awareness

b)

Obtain management commitment

c)

Appoint personnel to lead the planning process

d)

Ensure establishment of an information assurance program and associated policy

45.

Management’s commitment should be clearly stated in the information assurance policy. 

a)

Information Assurance Awareness

b)

Obtain management commitment

c)

Appoint personnel to lead the planning process

d)

Ensure establishment of an information assurance program and associated policy

46.

Organizations should assemble a team or taskforce to begin the process of planning an awareness program. 

a)

Information Assurance Awareness

b)

Obtain management commitment

c)

Appoint personnel to lead the planning process

d)

Ensure establishment of an information assurance program and associated policy

47.

The _____________ gives all teams a voice in these types of decisions.

a)

top-down approach

b)

bottom-up approach

c)

Outsourcing

d)

Organizational Maturity

48.

_______________  where roles, responsibilities, and authorities are spread throughout the organization’s business units, operations areas, and geographical locations.

a)

Centralized structure

b)

Distributed structure

c)

Hybrid structure

d)

Organizational Maturity

49.

_______________  that is a mix of the centralized and distributed structures.

a)

Centralized structure

b)

Distributed structure

c)

Hybrid structure

d)

Organizational Maturity

50.

__________________ will be securely managed by the organization as per information handling categorization. 

a)

Managers

b)

Information assets

c)

Executives

d)

Employees