wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

BSIT 3-2 - Information Assurance and Security 1

Total questions: 24

Worksheet time: 12mins

Name
Class
Date
1.

Why is it necessary for everyone to have a good understanding of Information Security policies and procedures?

a)

It helps protect users from being victims of security incidents.

b)

It provides an understanding of the patterns to follow in a security incident.

c)

It helps to understand levels of responsibility.

d)

All of the above

2.

What is a good way to create a password?

a)

Your child or pet name

b)

Using numbers or symbols

c)

A combination of upper and lowercase letters along with numbers and symbols

d)

Using some common words from the dictionary

3.

Which of the following would be the best password?

a)

MySecret

b)

Abc123

c)

Dp0si#Z$2

d)

Keyboard

4.

When did the concept of information security first emerge?

a)

In the 1940s and 1950s

b)

In the 1960s and 1970s

c)

In the 1980s and 1990s

d)

In the 2000s and 2010s

5.

Which of the following statement describes the purpose of allowing scientists and researchers to share information and resource.

a)

ARPANET

b)

R-609

c)

ARPA

d)

Department of Defense

6.

We consider these computers as “big computers” that we usually secured somewhere in a sensitive place, a really big that tend to take a lot of space, and they have lesser memory as well as less RAM, than the computers we have today. These computers are we called as ______?

a)

Computers with multi-level of physical security

b)

Information Systems

c)

Mainframe Computers

d)

MULTICS

7.

What was the main security issue with ARPANET in the 1970s?

a)

Lack of network speed

b)

Lack of user identification and authorization

c)

Lack of available data storage

d)

Lack of software compatibility

8.

What were the three main aspects of information security that evolved from the concept of computer security?

a)

Physical security, network security, and cybersecurity

b)

Safety of the data itself, limiting of random and unauthorized access to that data, and involvement of personnel from multiple levels of the organization

c)

Software security, network security, and personnel security

d)

Cybersecurity, cloud security, and mobile device security

9.

It has an important role to play in protecting critical information and data. With work and collaboration paradigm shifts, new cases of security threat arise. This security structure consists of access control, permanent active surveillance and testing, which falls under what layer of security?

a)

Physical Security

b)

Personal Security

c)

Operations Security

d)

Communications Security

10.

In the context of information security, which of the following best describes an asset, and which of the options listed is an example of an asset?

a)

A potential threat to an organization's security, such as a virus or hacker.

b)

The act of limiting access to an organization's information to only those who need it.

c)

Any employee who has access to the organization's sensitive information.

d)

Anything of value to an organization that requires protection, such as intellectual property or data

11.

An act of intentional or unintentional accessing or damaging a computer system without permission or authorization, with the goal of stealing, modifying, or destroying sensitive data or disrupting normal system operations.

a)

Exploit

b)

Risk

c)

Human Error

d)

Attacks

12.

This refers to the likelihood of an undesirable event occurring, such as a security breach or data loss. Organizations must identify and assess these undesirable events in order to implement appropriate measures.

a)

Exploit

b)

Risk

c)

Human Error

d)

Attacks

13.

Which of the following statements is true about accuracy in information security?

a)

It means that information should be presented in a way that is easy to understand.

b)

It ensures that information is protected from unauthorized access

c)

It means that information should be free from any mistake or error and meet end-users' expectations.

d)

It refers to the ability to access information when needed.

14.

Mark is an employee at a financial institution and is responsible for updating customer account details in the database. He accidentally enters incorrect information for a high-net-worth client. The incorrect information is updated in the database, and the client's account is affected. What type of breach is this?

a)

Breach of availability

b)

Breach of integrity

c)

Breach of authenticity

d)

Breach of confidentiality

15.

John is an employee at a software development company. His supervisor assigned him to work on a project that contains confidential information about the company's new product. John accidentally left his laptop in a coffee shop, and it was later discovered by a competitor who got access to the confidential information. What example is this?

a)

Breach of availability

b)

Breach of integrity

c)

Breach of authenticity

d)

Breach of confidentiality

16.

A popular online shopping website is experiencing a sudden increase in traffic due to a flash sale. As a result, the website becomes unresponsive, and customers are unable to make purchases. The company's IT team is struggling to keep up with the high volume of requests. Which of the following is the most appropriate step to ensure availability in this situation?

a)

Implement load balancing techniques to distribute the traffic across multiple servers.

b)

Block all incoming traffic to the website to avoid overloading the servers.

c)

Disable all security protocols to improve server performance.

d)

Continue to accept incoming traffic and hope that the IT team can resolve the issue.

17.

The Ubisoft Company is planning to implement a new information security system to protect its confidential data from unauthorized access. The CEO has issued a directive to the IT department to develop and implement the security system. The IT department has been given a budget, and the CIO has been appointed as the project manager. The project team is responsible for developing the policies, procedures, and processes to achieve the project goals. Which approach is Ubisoft Company using for the implementation of its information security system?

a)

Top-Down Approach

b)

Bottom-Up Approach

c)

Hybrid Approach

d)

Agile Approach

18.

Which of the following best describes the sequence of steps in the Logical Design phase of the Security SDLC?

a)

Conduct a feasibility analysis, select specific technologies, select data support and structures, select applications capable of providing needed services.

b)

Select applications capable of providing needed services, select specific technologies, conduct a feasibility analysis, select data support and structures.

c)

Select data support and structures, conduct a feasibility analysis, select specific technologies, select applications capable of providing needed services.

d)

Create a solution system for a business problem, select applications capable of providing needed services, select data support and structures, select specific technologies.

19.

Which of the following phase in Security SDLC (Systems Development Life-Cycle) outlines the project scope and goals. This phase also evaluates the existing resources and analyze the feasibility.

a)

Investigation

b)

Analysis

c)

Logical Design

d)

Physical design

20.

A company is going through the Physical Design phase of the Security SDLC. The team is evaluating different security technologies and creating a blueprint for physical security measures to support the proposed technological solutions. The team has prepared criteria to determine the definition of successful solutions, and they are conducting a feasibility study to determine the readiness of the organization for the proposed project. The champion and users will be presented with the design for approval before implementation begins. Now, what is the purpose of the feasibility study during the Physical Design phase of Security SDLC?

a)

To evaluate different security technologies and create a blueprint for physical security measures

b)

To determine the readiness of the organization for the proposed project before presenting it to the champion and users for approval.

c)

To determine the definition of successful solutions and prepare criteria for the project

d)

To ensure that upper management issues policy, procedures, and processes for the project

21.

The is primarily responsible for assessing, managing, and implementing security.

a)

Security administrator

b)

Security technician

c)

Chief information security officer

d)

Security manager

22.

Which of the following is NOT a reason why it is difficult to defend against today’s attackers?

a)

Increased speed of attacks

b)

Delays in security updating

c)

Simplicity of attack tools

d)

Greater sophistication of defense tools

23.

What is the primary responsibility of security policy developers in an information security team?

a)

To develop policies based solely on technical expertise

b)

To understand the organizational culture, policies, and requirements

c)

To focus on the development of policies without considering implementation

d)

To ensure the policies align with industry standards only.

24.

Which of the following terms best describes ensuring that the data is accessible to authorized users?

a)

Integrity

b)

Availability

c)

Accounting

d)

Confidentiality