wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

ISC(2)

Total questions: 65

Worksheet time: 41mins

Name
Class
Date
1.
Steve is a security practitioner assigned to come up with a protective measure for ensuring cars don’t collide with pedestrians. What is probably the most effective type of control for this task? (D1, L1.3.1)
a)
A. Administrative
b)
B. Technical
c)
C. Physical
d)
D. Nuanced
2.
Chad is a security practitioner tasked with ensuring that the information on the organization’s public website is not changed by anyone outside the organization.This task is an example of ensuring _. (D1, L1.1.1)
a)
A. Confidentiality
b)
B. Integrity
c)
C. Availability
d)
D. Confirmation
3.
Which of the following is an example of a “something you know” authentication factor? (D1, L1.1.1)
a)
A. User ID
b)
B. Password
c)
C. Fingerprint
d)
D. Iris scan
4.
Which of the following is an example of a “something you are” authentication factor? (D1, L1.1.1)
a)
A. A credit card presented to a cash machine
b)
B. Your password and PIN
c)
C. A user ID
d)
D. A photograph of your face
5.
A system that collects transactional information and stores it in a record in order to show which users performed which actions is an example of providing _. (D1,L1.1.1)
a)
A. Non-repudiation
b)
B. Multifactor authentication
c)
C. Biometrics
d)
D. Privacy
6.
The European Union (EU) law that grants legal protections to individual human privacy is. (D1, L1.1.1)
a)
A. The Privacy Human Rights Act
b)
B. The General Data Protection Regulation
c)
C. The Magna Carta
d)
D. The Constitution
7.
For which of the following systems would the security concept of availability probably be most important? (D1, L1.1.1)
a)
A. Medical systems that store patient data
b)
B. Retail records of past transactions
c)
C. Online streaming of camera feeds that display historical works of art in museums around the world
d)
D. Medical systems that monitor patient condition in an intensive-care unit
8.
For which of the following assets is integrity probably the most important security aspect? (D1, L1.1.1)
a)
A. One frame of a streaming video
b)
B. The file that contains passwords used to authenticate users
c)
C. The color scheme of a marketing website
d)
D. Software that checks the spelling of product descriptions for a retail website
9.
In risk management concepts, a(n) is something a security practitioner might need to protect. (D1, L1.2.1)
a)
A. Vulnerability
b)
B. Asset
c)
C. Threat
d)
D. Likelihood
10.
In risk management concepts, a(n) is something or someone that poses risk to an organization or asset. (D1, L1.2.1)
a)
A. Fear
b)
B. Threat
c)
C. Control
d)
D. Asset
11.
Of the following, which would probably not be considered a threat? (D1, L1.2.1)
a)
A. Natural disaster
b)
B. Unintentional damage to the system caused by a user
c)
C. A laptop with sensitive data on it
d)
D. An external attacker trying to gain unauthorized access to the environment
12.
Which of the following probably poses the most risk? (D1, L1.2.1)
a)
A. A high-likelihood, high-impact event
b)
B. A high-likelihood, low-impact event
c)
C. A low-likelihood, high-impact event
d)
D. A low-likelihood, low-impact event
13.
Within the organization, who can identify risk? (D1, L1.2.2)
a)
A. The security manager
b)
B. Any security team member
c)
C. Senior management
d)
D. Anyone
14.
Kerpak works in the security office of a medium-sized entertainment company. Kerpak is asked to assess a particular threat, and he suggests that the best way to counter this threat would be to purchase and implement a particular security solution. This is an example of _. (D1, L1.2.2)
a)
A. Acceptance
b)
B. Avoidance
c)
C. Mitigation
d)
D. Transference
15.
Sophia is visiting Las Vegas and decides to put a bet on a particular number on a roulette wheel. This is an example of _. (D1, L1.2.2)
a)
A. Acceptance
b)
B. Avoidance
c)
C. Mitigation
d)
D. Transference
16.
Phrenal is selling a used laptop in an online auction. Phrenal has estimated the value of the laptop to be $100, but has seen other laptops of similar type and quality sell for both more and less than that amount. Phrenal hopes that the laptop will sell for $100 or more, but is prepared to take less for it if nobody bids that amount. This is an example of ___________. (D1, L1.2.2)
a)
A. Risk tolerance
b)
B. Risk inversion
c)
C. Threat
d)
D. Vulnerability
17.
A software firewall is an application that runs on a device and prevents specific types of traffic from entering that device. This is a type of control. (D1, L1.3.1)
a)
A. Physical
b)
B. Administrative
c)
C. Passive
d)
D. Technical
18.
Preenka works at an airport. There are red lines painted on the ground next to the runway; Preenka has been instructed that nobody can step or drive across a red line unless they request, and get specific permission from, the control tower. This is an example of a(n)______ control. (D1, L1.3.1)
a)
A. Physical
b)
B. Administrative
c)
C. Critical
d)
D. Technical
19.
A bollard is a post set securely in the ground in order to prevent a vehicle from entering an area or driving past a certain point. Bollards are an example of ______ controls. (D1, L1.3.1)
a)
A. Physical
b)
B. Administrative
c)
C. Drastic
d)
D. Technical
20.
Jengi is setting up security for a home network. Jengi decides to configure MAC address filtering on the router, so that only specific devices will be allowed to join the network. This is an example of a(n)_______ control. (D1, L1.3.1)
a)
A. Physical
b)
B. Administrative
c)
C. Substantial
d)
D. Technical
21.
Druna is a security practitioner tasked with ensuring that laptops are not stolen from the organization’s offices. Which sort of security control would probably be best for this purpose? (D1, L1.3.1)
a)
A. Technical
b)
B. Obverse
c)
C. Physical
d)
D. Administrative
22.
Triffid Corporation has a rule that all employees working with sensitive hardcopy documents must put the documents into a safe at the end of the workday, where they are locked up until the following workday. What kind of control is the process of putting the documents into the safe? (D1, L1.3.1)
a)
A. Administrative
b)
B. Tangential
c)
C. Physical
d)
D. Technical
23.
Triffid Corporation has a policy that all employees must receive security awareness instruction before using email; the company wants to make employees aware of potential phishing attempts that the employees might receive via email. What kind of control is this instruction? (D1, L1.3.1)
a)
A. Administrative
b)
B. Finite
c)
C. Physical
d)
D. Technical
24.
The city of Grampon wants to know where all its public vehicles (garbage trucks, police cars, etc.) are at all times, so the city has GPS transmitters installed in all the vehicles. What kind of control is this? (D1, L1.3.1)
a)
A. Administrative
b)
B. Entrenched
c)
C. Physical
d)
D. Technical
25.
(ISC)2 publishes a Common Body of Knowledge (CBK) that IT security practitioners should be familiar with; this is recognized throughout the industry as a set of material that is useful for practitioners to refer to. Certifications can be issued for demonstrating expertise in this Common Body of Knowledge. What kind of document is the Common Body of Knowledge? (D1, L1.4.1)
a)
A. Policy
b)
B. Procedure
c)
C. Standard
d)
D. Law
26.
The city of Grampon wants to ensure that all of its citizens are protected from malware, so the city council creates a rule that anyone caught creating and launching malware within the city limits will receive a fine and go to jail. What kind of rule is this? (D1, L1.4.1)
a)
A. Policy
b)
B. Procedure
c)
C. Standard
d)
D. Law
27.
The Triffid Corporation publishes a strategic overview of the company’s intent to secure all the data the company possesses. This document is signed by Triffid senior management. What kind of document is this? (D1, L1.4.1)
a)
A. Policy
b)
B. Procedure
c)
C. Standard
d)
D. Law
28.
The Triffid Corporation publishes a policy that states all personnel will act in a manner that protects health and human safety. The security office is tasked with writing a detailed set of processes on how employees should wear protective gear such as hardhats and gloves when in hazardous areas. This detailed set of processes is a _________. (D1, L1.4.1)
a)
A. Policy
b)
B. Procedure
c)
C. Standard
d)
D. Law
29.
Grampon municipal code requires that all companies that operate within city limits will have a set of processes to ensure employees are safe while working with hazardous materials. Triffid Corporation creates a checklist of activities employees must follow while working with hazardous materials inside Grampon city limits. The municipal code is a ______, and the Triffid checklist is a _. (D1, L1.4.2)
a)
A. Law, procedure
b)
B. Standard, law
c)
C. Law, standard
d)
D. Policy, law
30.
The senior leadership of Triffid Corporation decides that the best way to minimize liability for the company is to demonstrate the company’s commitment to adopting best practices recognized throughout the industry. Triffid management issues a document that explains that Triffid will follow the best practices published by SANS, an industry body that addresses computer and information security. The Triffid document is a ______, and the SANS documents are ________. (D1, L1.4.2)
a)
A. Law, policy
b)
B. Policy, standard
c)
C. Policy, law
d)
D. Procedure, procedure
31.
A vendor sells a particular operating system (OS). In order to deploy the OS securely on different platforms, the vendor publishes several sets of instructions on how to install it, depending on which platform the customer is using. This is an example of ________. (D1, L1.4.2)
a)
A. Rules
b)
B. Policy
c)
C. Standard
d)
D. Law
32.
The Payment Card Industry (PCI) Council is a committee made up of representatives from major credit card providers (Visa, Mastercard, American Express) in the United States. The PCI Council issues rules that merchants must follow if the merchants choose to accept payment via credit card. These rules describe best practices for securing credit card processing technology, activities for securing credit card information, and how to protect customers’ personal data. This set of rules is a _.(D1, L1.4.2)
a)
A. Law
b)
B. Procedure
c)
C. Standard
d)
D. Procedure
33.
Hoshi is an (ISC)2 member who works for the Triffid Corporation as a data manager. Triffid needs a new firewall solution, and Hoshi is asked to recommend a product for Triffid to acquire and implement. Hoshi’s cousin works for a firewall vendor; that vendor happens to make the best firewall available. What should Hoshi do? (D1, L1.5.1)
a)
A. Law
b)
B. Recommend the cousin’s product
c)
C. Hoshi should ask to be recused from the task
d)
D. Policy
34.
Siobhan is an (ISC)2 member who works for Triffid Corporation as a security analyst. Yesterday, Siobhan got a parking ticket while shopping after work. What should Siobhan do? (D1, L1.5.1)
a)
A. Do nothing
b)
B. Pay the parking ticket
c)
C. Inform supervisors at Triffid
d)
D. Run away
35.
Zarma is an (ISC)2 member and a security analyst for Triffid Corporation. One of Zarma’s colleagues is interested in getting an (ISC)2 certification and asks Zarma what the test questions are like. What should Zarma do? (D1, L1.5.1)
a)
A. Do nothing
b)
B. Explain the style and format of the questions, but no detail
c)
C. Inform the colleague’s supervisor
d)
D. Tell them the answers
36.
At Parvi’s place of work, the perimeter of the property is surrounded by a fence; there is a gate with a guard at the entrance. All inner doors only admit personnel with badges, and cameras monitor the hallways. Sensitive data and media are kept in safes when not in use. (D3, L3.1.1) This is an example of:
a)
A. Two-person integrity
b)
B. Segregation of duties
c)
C. Defense in depth
d)
D. Penetration testing
37.
Gelbi is a Technical Support analyst for Triffid, Inc. Gelbi sometimes is required to install or remove software. Which of the following could be used to describe Gelbi’s account? (D3, L3.1.1)
a)
A. Privileged
b)
B. Internal
c)
C. External
d)
D. User
38.
Trina is a security practitioner at Triffid, Inc. Trina has been tasked with selecting a new product to serve as a security control in the environment. After doing some research, Trina selects a particular product. Before that product can be purchased, a manager must review Trina’s selection and determine whether to approve the purchase. This is a description of: (D3, L3.1.1)
a)
A. Two-person integrity
b)
B. Segregation of duties
c)
C. Software
d)
D. Defense in depth
39.
Guillermo logs onto a system and open a document file. In this example, Guillermo is: (D3, L3.1.1)
a)
A. The subject
b)
B. The object
c)
C. The process
d)
D. The software
40.
Which of the following is not an appropriate control to add to privileged accounts? (D3, L3.1.1)
a)
A. Increased logging
b)
B. Multifactor authentication
c)
C. Increased auditing
d)
D. Security deposit
41.
Which of the following roles does not typically require privileged account access? (D3, L3.1.1)
a)
A. Security administrator
b)
B. Data entry professional
c)
C. System administrator
d)
D. Help Desk technician
42.
Prachi works as a database administrator for Triffid, Inc. Prachi is allowed to add or delete users, but is not allowed to read or modify the data in the database itself. When Prachi logs onto the system, an access control list (ACL) checks to determine which permissions Prachi has. In this situation, what is the ACL? (D3, L3.1.1)
a)
A. The subject
b)
B. The object
c)
C. The rule
d)
D. The firmware
43.
Prachi works as a database administrator for Triffid, Inc. Prachi is allowed to add or delete users, but is not allowed to read or modify the data in the database itself. When Prachi logs onto the system, an access control list (ACL) checks to determine which permissions Prachi has. In this situation, what is the database? (D3, L3.1.1)
a)
A. The object
b)
B. The rule
c)
C. The subject
d)
D. The site
44.
Prachi works as a database administrator for Triffid, Inc. Prachi is allowed to add or delete users, but is not allowed to read or modify the data in the database itself. When Prachi logs onto the system, an access control list (ACL) checks to determine which permissions Prachi has. this situation, what is Prachi? (D3, L3.1.1)
a)
A. The subject
b)
B. The rule
c)
C. The file
d)
D. The object
45.
Prachi works as a database administrator for Triffid, Inc. Prachi is allowed to add or delete users, but is not allowed to read or modify the data in the database itself. When Prachis logs onto the system, an access control list (ACL) checks to determine which permissions Prachi has. Which security concept is being applied in this situation? (D3, L3.1.1)
a)
A. Defense in depth
b)
B. Layered defense
c)
C. Two-person integrity
d)
D. Least privilege
46.
Larry and Fern both work in the data center. In order to enter the data center to begin their workday, they must both present their own keys (which are different) to the key reader, before the door to the data center opens. Which security concept is being applied in this situation? (D3, L3.1.1)
a)
A. Defense in depth
b)
B. Segregation of duties
c)
C. Least privilege
d)
D. Dual control
47.
Which of these is an example of a physical access control mechanism? (D3, L3.2.1)
a)
A. Software-based firewall at the perimeter of the network
b)
B. A lock on a door
c)
C. Network switches that filter according to MAC addresses
d)
D. A process that requires two people to act at the same time to perform a function
48.
Which of the following is a biometric access control mechanism? (D3, L3.2.1)
a)
A. A badge reader
b)
B. A copper key
c)
C. A fence with razor tape on it
d)
D. A door locked by a voiceprint identifier
49.
Which of the following is probably most useful at the perimeter of a property? (D3, L3.2.1)
a)
A. A safe
b)
B. A fence
c)
C. A data center
d)
D. A centralized log storage facility
50.
Visitors to a secure facility need to be controlled. Controls useful for managing visitors include all of the following except: (D3, L3.2.1)
a)
A. Sign-in sheet/tracking log
b)
B. Fence
c)
C. Badges that differ from employee badges
d)
D. Receptionist
51.
All visitors to a secure facility should be _. (D3, L3.2.1)
a)
A. Fingerprinted
b)
B. Photographed
c)
C. Escorted
d)
D. Required to wear protective equipment
52.
In order for a biometric security to function properly, an authorized person’s physiological data must be ______. (D3, L3.2.1)
a)
A. Broadcast
b)
B. Stored
c)
C. Deleted
d)
D. Modified
53.
All of the following are typically perceived as drawbacks to biometric systems, except: (D3, L3.2.1)
a)
A. Lack of accuracy
b)
B. Potential privacy concerns
c)
C. Retention of physiological data past the point of employment
d)
D. Legality
54.
A human guard monitoring a hidden camera could be considered a _______ control. (D3, L3.2.1)
a)
A. Detective
b)
B. Preventive
c)
C. Deterrent
d)
D. Logical
55.
Which of the following will have the most impact on determining the duration of log retention? (D3, L3.2.1)
a)
A. Personal preference
b)
B. Applicable laws
c)
C. Industry standards
d)
D. Type of storage media
56.
A _____ is a record of something that has occurred. (D3, L3.2.1)
a)
A. Biometric
b)
B. Law
c)
C. Log
d)
D. Firewall
57.
Network traffic originating from outside the organization might be admitted to the internal IT environment or blocked at the perimeter by a ________. (D3, L3.2.1)
a)
A. Turnstile
b)
B. Fence
c)
C. Vacuum
d)
D. Firewall
58.
Bruce is the branch manager of a bank. Bruce wants to determine which personnel at the branch can get access to systems, and under which conditions they can get access. Which access control methodology would allow Bruce to make this determination? (D)
a)
A. MAC (mandatory access control)
b)
B. DAC (discretionary access control)
c)
C. RBAC (role-based access control)
d)
D. Defense-in-depth
59.
Tekila works for a government agency. All data in the agency is assigned a particular sensitivity level, called a “classification.” Every person in the agency is assigned a “clearance” level, which determines the classification of data each person can access. What is the access control model being implemented in Tekila’s agency? (D)
a)
A. MAC (mandatory access control)
b)
B. DAC (discretionary access control)
c)
C. RBAC (role-based access control)
d)
D. FAC (formal access control)
60.
Which of the following would be considered a logical access control? (D)
a)
A. An iris reader that allows an employee to enter a controlled area
b)
B. A fingerprint reader that allows an employee to enter a controlled area
c)
C. A fingerprint reader that allows an employee to access a laptop computer
d)
D. A chain attached to a laptop computer that connects it to furniture so it cannot be taken
61.
Trina and Doug both work at Triffid, Inc. Doug is having trouble logging into the network. Trina offers to log in for Doug, using Trina’s credentials, so that Doug can get some work done. What is the problem with this? (D)
a)
A. Doug is a bad person
b)
B. If Trina logs in for Doug, then Doug will never be encouraged to remember credentials without assistance
c)
C. Anything either of them do will be attributed to Trina
d)
D. It is against the law
62.
Gary is unable to log in to the production environment. Gary tries three times and is then locked out of trying again for one hour. Why? (D)
a)
A. Gary is being punished
b)
B. The network is tired
c)
C. Users remember their credentials if they are given time to think about it
d)
D. Gary’s actions look like an attack
63.
Suvid works at Triffid, Inc. When Suvid attempts to log in to the production environment, a message appears stating that Suvid has to reset the password. What may have occurred to cause this? (D)
a)
A. Suvid broke the law
b)
B. Suvid’s password has expired
c)
C. Suvid made the manager angry
d)
D. Someone hacked Suvid’s machine
64.
Which of the following statements is true? (D)
a)
A. Logical access controls can protect the IT environment perfectly; there is no reason to deploy any other controls
b)
B. Physical access controls can protect the IT environment perfectly; there is no reason to deploy any other controls
c)
C. Administrative access controls can protect the IT environment perfectly; there is no reason to deploy any other controls
d)
D. It is best to use a blend of controls in order to provide optimum security
65.
Prina is a database manager. Prina is allowed to add new users to the database, remove current users, and create new usage functions for the users. Prina is not allowed to read the data in the fields of the database itself. This is an example of: (D)
a)
A. Role-based access controls (RBAC)
b)
B. Mandatory access controls (MAC)
c)
C. Discretionary access controls (DAC)
d)
D. Alleviating threat access controls (ATAC)