wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

BSIT 3-2 - IAS - Midterm Examination - 2023

Total questions: 35

Worksheet time: 18mins

Name
Class
Date
1.

In the Security Systems Development Life Cycle, which phase focuses on identifying and assessing potential risks and vulnerabilities within the system.

a)

Analysis Phase

b)

Logical Design

c)

Physical Design

d)

Investigation

2.

Which critical characteristic of information ensures that information is complete, accurate, and free from errors or omissions?

a)

Availability

b)

Integrity

c)

Confidentiality

d)

Authenticity

3.

Which critical characteristic of information ensures that information is genuine, trustworthy, and comes from a reliable source?

a)

Availability

b)

Integrity

c)

Confidentiality

d)

Authenticity

4.

What is the primary responsibility of the Chief Information Security Officer (CISO) in an organization?

a)

Managing daily IT operations

b)

Developing marketing strategies

c)

Overseeing the organization's information security program

d)

Conducting financial audits

5.

What role does senior management play in the organization's information security?

a)

Hands-on management of security technologies

b)

Setting the organization's security vision and priorities

c)

Implementing security awareness training for employees

d)

Conducting regular vulnerability assessments

6.

Who is responsible for making decisions regarding the classification, retention, and sharing of data within an organization?

a)

Data Owner

b)

Data Custodian

c)

Chief Information Security Officer (CISO)

d)

Data User

7.

Who is accountable for the physical protection of data assets, such as servers and storage devices?

a)

Data Owner

b)

Data Custodian

c)

Chief Information Security Officer (CISO)

d)

Data User

8.

What component of an information system refers to the guidelines and instructions followed by users and organizations?

a)

Software

b)

Hardware

c)

Data

d)

Procedures

9.

Which function of information security focuses on ensuring that applications running on the organization's IT systems operate securely and without compromise?

a)

Protecting the organization's ability to function

b)

Enabling the safe operation of applications

c)

Protecting data that organization collects

d)

Safeguarding the organization's technology assets

10.

In a scenario where a malicious attacker attempts to disrupt an organization's critical systems, which function of information security is primarily involved in mitigating the impact and ensuring the organization's ability to continue its operations?

a)

Protecting the organization's ability to function

b)

Enabling the safe operation of applications

c)

Protecting data that organization collects

d)

Safeguarding the organization's technology assets

11.

An act of intentional or unintentional accessing or damaging a computer system without permission or authorization, with the goal of stealing, modifying, or destroying sensitive data or disrupting normal system operations.

a)

Exploit

b)

Risk

c)

Human Error

d)

Attacks

12.

This refers to the likelihood of an undesirable event occurring, such as a security breach or data loss. Organizations must identify and assess these undesirable events in order to implement appropriate measures.

a)

Exploit

b)

Risk

c)

Human Error

d)

Attacks

13.

An organization is implementing a new application that will store and process sensitive customer data. Which function of information security should be given the highest priority in this case?

a)

Protecting the organization's ability to function

b)

Enabling the safe operation of applications

c)

Protecting data that organization collects

d)

Safeguarding the organization's technology assets

14.

A severe flood has damaged the organization's data center, causing a complete outage of IT systems. Which function of information security becomes crucial in this situation?

a)

Protecting the organization's ability to function

b)

Enabling the safe operation of applications

c)

Protecting data that organization collects

d)

Safeguarding the organization's technology assets

15.

A company experiences a DDoS (Distributed Denial of Service) attack, resulting in its website becoming inaccessible to users. This situation affects which aspect of the CIA triangle the most?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Authorization

16.

Which of the following measures is an example of ensuring confidentiality?

a)

Implementing strong authentication mechanisms

b)

Regularly backing up data

c)

Conducting regular vulnerability assessments

d)

Encrypting sensitive information during transmission

17.

Which aspect of the CIA triangle is most relevant in maintaining data accuracy and preventing unauthorized modifications?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Authorization

18.

A disgruntled employee intentionally deletes critical files and alters system configurations, resulting in significant damage to the organization's infrastructure. This scenario best represents which category of threat?

a)

Compromises to Intellectual Property

b)

Sabotage or Vandalism

c)

Technical Software Failures or Errors

d)

Theft

19.

Which category of threat involves unauthorized individuals gaining access to sensitive information with the intention of extracting a ransom or other forms of payment?

a)

Information Extortion

b)

Theft

c)

Espionage or Trespass

d)

Deliberate Software Attacks

20.

A severe earthquake damages the organization's data center, causing a complete loss of data and infrastructure. This scenario aligns with which category of threat?

a)

Espionage or Trespass

b)

Technical Hardware Failures or Errors

c)

Sabotage or Vandalism

d)

Forces of Nature

21.

Which category of threat involves inadequate organizational policies or planning that can lead to security vulnerabilities and breaches?

a)

Missing, Inadequate, or Incomplete Organizational Policy or Planning

b)

Missing, Inadequate, or Incomplete Controls

c)

Technological Obsolescence

d)

Deviations in Quality of Service

22.

What is a "Back Door" in the context of information security?

a)

A physical entrance used by attackers to gain unauthorized access to a facility

b)

A type of malware that disguises itself as a legitimate software program

c)

A hidden method or vulnerability intentionally inserted into a system for unauthorized access

d)

A social engineering technique used to trick individuals into revealing sensitive information

23.

Which of the following is an example of a Trojan horse?

a)

A self-replicating code that spreads through email attachments

b)

A program that disguises itself as a legitimate antivirus software

c)

A malicious script that exploits a web browser vulnerability

d)

A worm that exploits a network vulnerability to propagate

24.

This is an instance malicious code that it changes its appearance and behavior to avoid detection

a)

Trojan Horses

b)

Worms

c)

Back door

d)

Polymorphic threat

25.

Which of the following is a characteristic of a virus and worm hoax?

a)

They are harmless messages warning about non-existent threats

b)

They exploit software vulnerabilities to infect systems

c)

They use social engineering techniques to trick users into executing malicious code

d)

They encrypt files and demand a ransom for their release

26.

Which of the following attacks involves flooding a network or server with an overwhelming amount of traffic, rendering it inaccessible to legitimate users?

a)

Password cracking

b)

Man-in-the-middle attack

c)

Denial of Service (DoS)

d)

Social engineering

27.

In which type of attack does an attacker use software to guess passwords by trying multiple combinations?

a)

Man-in-the-middle attack

b)

Brute force attack

c)

Dictionary attack

d)

Phishing attack

28.

Which attack involves tricking individuals into divulging sensitive information by pretending to be a trustworthy entity?

a)

Spoofing attack

b)

Pharming attack

c)

Sniffing attack

d)

Social engineering attack

29.

Which attack involves intercepting and altering communication between two parties without their knowledge?

a)

Man-in-the-middle attack

b)

Spoofing attack

c)

Phishing attack

d)

Denial of Service (DoS) attack

30.

Which attack involves sending unsolicited bulk emails, typically for advertising or fraudulent purposes?

a)

Spam attack

b)

Mail bombing attack

c)

Denial of Service (DoS) attack

d)

Dictionary attack

31.

Which attack involves masquerading as a trusted website or entity to deceive users into providing sensitive information?

a)

Phishing attack

b)

Sniffing attack

c)

Dictionary attack

d)

Back door attack

32.

Which attack aims to gain unauthorized access to a system by systematically trying all possible words or combinations from a pre-existing list?

a)

Brute force attack

b)

Dictionary attack

c)

Pharming attack

d)

Man-in-the-middle attack

33.

Which attack involves redirecting users from a legitimate website to a malicious website without their knowledge or consent?

a)

Spoofing attack

b)

Pharming attack

c)

Sniffing attack

d)

Spam attack

34.

Lisa notices that her website's traffic has significantly increased, causing the server to slow down and become unresponsive. What type of attack is this?

a)

Dictionary attack

b)

Denial of Service (DoS) attack

c)

Spoofing attack

d)

Man-in-the-middle attack

35.

You work for a large multinational corporation that frequently deals with sensitive customer information. The company has recently experienced several phishing attacks, and the management wants to ensure that all employees are aware of the best practices to avoid falling victim to such attacks. As part of an awareness campaign, they conduct training sessions and distribute informational materials. During one of these sessions, the following question is posed. Which of the following best describes a preventive measure to avoid falling victim to phishing attacks?

a)

Clicking on email links without verifying the sender's identity.

b)

Sharing your account credentials with a coworker who requests them via email.

c)

Always reviewing and verifying the email sender's address and content before clicking on any links or providing personal information.

d)

Responding to emails requesting urgent action without verifying the authenticity of the request.