WorksheetsBSIT 3-2 - Information Assurance and Security 1
Total questions: 24
Worksheet time: 12mins
Why is it necessary for everyone to have a good understanding of Information Security policies and procedures?
It helps protect users from being victims of security incidents.
It provides an understanding of the patterns to follow in a security incident.
It helps to understand levels of responsibility.
All of the above
What is a good way to create a password?
Your child or pet name
Using numbers or symbols
A combination of upper and lowercase letters along with numbers and symbols
Using some common words from the dictionary
Which of the following would be the best password?
MySecret
Abc123
Dp0si#Z$2
Keyboard
When did the concept of information security first emerge?
In the 1940s and 1950s
In the 1960s and 1970s
In the 1980s and 1990s
In the 2000s and 2010s
Which of the following statement describes the purpose of allowing scientists and researchers to share information and resource.
ARPANET
R-609
ARPA
Department of Defense
We consider these computers as “big computers” that we usually secured somewhere in a sensitive place, a really big that tend to take a lot of space, and they have lesser memory as well as less RAM, than the computers we have today. These computers are we called as ______?
Computers with multi-level of physical security
Information Systems
Mainframe Computers
MULTICS
What was the main security issue with ARPANET in the 1970s?
Lack of network speed
Lack of user identification and authorization
Lack of available data storage
Lack of software compatibility
What were the three main aspects of information security that evolved from the concept of computer security?
Physical security, network security, and cybersecurity
Safety of the data itself, limiting of random and unauthorized access to that data, and involvement of personnel from multiple levels of the organization
Software security, network security, and personnel security
Cybersecurity, cloud security, and mobile device security
It has an important role to play in protecting critical information and data. With work and collaboration paradigm shifts, new cases of security threat arise. This security structure consists of access control, permanent active surveillance and testing, which falls under what layer of security?
Physical Security
Personal Security
Operations Security
Communications Security
In the context of information security, which of the following best describes an asset, and which of the options listed is an example of an asset?
A potential threat to an organization's security, such as a virus or hacker.
The act of limiting access to an organization's information to only those who need it.
Any employee who has access to the organization's sensitive information.
Anything of value to an organization that requires protection, such as intellectual property or data
An act of intentional or unintentional accessing or damaging a computer system without permission or authorization, with the goal of stealing, modifying, or destroying sensitive data or disrupting normal system operations.
Exploit
Risk
Human Error
Attacks
This refers to the likelihood of an undesirable event occurring, such as a security breach or data loss. Organizations must identify and assess these undesirable events in order to implement appropriate measures.
Exploit
Risk
Human Error
Attacks
Which of the following statements is true about accuracy in information security?
It means that information should be presented in a way that is easy to understand.
It ensures that information is protected from unauthorized access
It means that information should be free from any mistake or error and meet end-users' expectations.
It refers to the ability to access information when needed.
Mark is an employee at a financial institution and is responsible for updating customer account details in the database. He accidentally enters incorrect information for a high-net-worth client. The incorrect information is updated in the database, and the client's account is affected. What type of breach is this?
Breach of availability
Breach of integrity
Breach of authenticity
Breach of confidentiality
John is an employee at a software development company. His supervisor assigned him to work on a project that contains confidential information about the company's new product. John accidentally left his laptop in a coffee shop, and it was later discovered by a competitor who got access to the confidential information. What example is this?
Breach of availability
Breach of integrity
Breach of authenticity
Breach of confidentiality
A popular online shopping website is experiencing a sudden increase in traffic due to a flash sale. As a result, the website becomes unresponsive, and customers are unable to make purchases. The company's IT team is struggling to keep up with the high volume of requests. Which of the following is the most appropriate step to ensure availability in this situation?
Implement load balancing techniques to distribute the traffic across multiple servers.
Block all incoming traffic to the website to avoid overloading the servers.
Disable all security protocols to improve server performance.
Continue to accept incoming traffic and hope that the IT team can resolve the issue.
The Ubisoft Company is planning to implement a new information security system to protect its confidential data from unauthorized access. The CEO has issued a directive to the IT department to develop and implement the security system. The IT department has been given a budget, and the CIO has been appointed as the project manager. The project team is responsible for developing the policies, procedures, and processes to achieve the project goals. Which approach is Ubisoft Company using for the implementation of its information security system?
Top-Down Approach
Bottom-Up Approach
Hybrid Approach
Agile Approach
Which of the following best describes the sequence of steps in the Logical Design phase of the Security SDLC?
Conduct a feasibility analysis, select specific technologies, select data support and structures, select applications capable of providing needed services.
Select applications capable of providing needed services, select specific technologies, conduct a feasibility analysis, select data support and structures.
Select data support and structures, conduct a feasibility analysis, select specific technologies, select applications capable of providing needed services.
Create a solution system for a business problem, select applications capable of providing needed services, select data support and structures, select specific technologies.
Which of the following phase in Security SDLC (Systems Development Life-Cycle) outlines the project scope and goals. This phase also evaluates the existing resources and analyze the feasibility.
Investigation
Analysis
Logical Design
Physical design
A company is going through the Physical Design phase of the Security SDLC. The team is evaluating different security technologies and creating a blueprint for physical security measures to support the proposed technological solutions. The team has prepared criteria to determine the definition of successful solutions, and they are conducting a feasibility study to determine the readiness of the organization for the proposed project. The champion and users will be presented with the design for approval before implementation begins. Now, what is the purpose of the feasibility study during the Physical Design phase of Security SDLC?
To evaluate different security technologies and create a blueprint for physical security measures
To determine the readiness of the organization for the proposed project before presenting it to the champion and users for approval.
To determine the definition of successful solutions and prepare criteria for the project
To ensure that upper management issues policy, procedures, and processes for the project
The is primarily responsible for assessing, managing, and implementing security.
Security administrator
Security technician
Chief information security officer
Security manager
Which of the following is NOT a reason why it is difficult to defend against today’s attackers?
Increased speed of attacks
Delays in security updating
Simplicity of attack tools
Greater sophistication of defense tools
What is the primary responsibility of security policy developers in an information security team?
To develop policies based solely on technical expertise
To understand the organizational culture, policies, and requirements
To focus on the development of policies without considering implementation
To ensure the policies align with industry standards only.
Which of the following terms best describes ensuring that the data is accessible to authorized users?
Integrity
Availability
Accounting
Confidentiality
