NEW
Font size
WorksheetsBSIT 3-2 - IAS - Midterm Examination - 2023
Total questions: 35
Worksheet time: 18mins
In the Security Systems Development Life Cycle, which phase focuses on identifying and assessing potential risks and vulnerabilities within the system.
Analysis Phase
Logical Design
Physical Design
Investigation
Which critical characteristic of information ensures that information is complete, accurate, and free from errors or omissions?
Availability
Integrity
Confidentiality
Authenticity
Which critical characteristic of information ensures that information is genuine, trustworthy, and comes from a reliable source?
Availability
Integrity
Confidentiality
Authenticity
What is the primary responsibility of the Chief Information Security Officer (CISO) in an organization?
Managing daily IT operations
Developing marketing strategies
Overseeing the organization's information security program
Conducting financial audits
What role does senior management play in the organization's information security?
Hands-on management of security technologies
Setting the organization's security vision and priorities
Implementing security awareness training for employees
Conducting regular vulnerability assessments
Who is responsible for making decisions regarding the classification, retention, and sharing of data within an organization?
Data Owner
Data Custodian
Chief Information Security Officer (CISO)
Data User
Who is accountable for the physical protection of data assets, such as servers and storage devices?
Data Owner
Data Custodian
Chief Information Security Officer (CISO)
Data User
What component of an information system refers to the guidelines and instructions followed by users and organizations?
Software
Hardware
Data
Procedures
Which function of information security focuses on ensuring that applications running on the organization's IT systems operate securely and without compromise?
Protecting the organization's ability to function
Enabling the safe operation of applications
Protecting data that organization collects
Safeguarding the organization's technology assets
In a scenario where a malicious attacker attempts to disrupt an organization's critical systems, which function of information security is primarily involved in mitigating the impact and ensuring the organization's ability to continue its operations?
Protecting the organization's ability to function
Enabling the safe operation of applications
Protecting data that organization collects
Safeguarding the organization's technology assets
An act of intentional or unintentional accessing or damaging a computer system without permission or authorization, with the goal of stealing, modifying, or destroying sensitive data or disrupting normal system operations.
Exploit
Risk
Human Error
Attacks
This refers to the likelihood of an undesirable event occurring, such as a security breach or data loss. Organizations must identify and assess these undesirable events in order to implement appropriate measures.
Exploit
Risk
Human Error
Attacks
An organization is implementing a new application that will store and process sensitive customer data. Which function of information security should be given the highest priority in this case?
Protecting the organization's ability to function
Enabling the safe operation of applications
Protecting data that organization collects
Safeguarding the organization's technology assets
A severe flood has damaged the organization's data center, causing a complete outage of IT systems. Which function of information security becomes crucial in this situation?
Protecting the organization's ability to function
Enabling the safe operation of applications
Protecting data that organization collects
Safeguarding the organization's technology assets
A company experiences a DDoS (Distributed Denial of Service) attack, resulting in its website becoming inaccessible to users. This situation affects which aspect of the CIA triangle the most?
Confidentiality
Integrity
Availability
Authorization
Which of the following measures is an example of ensuring confidentiality?
Implementing strong authentication mechanisms
Regularly backing up data
Conducting regular vulnerability assessments
Encrypting sensitive information during transmission
Which aspect of the CIA triangle is most relevant in maintaining data accuracy and preventing unauthorized modifications?
Confidentiality
Integrity
Availability
Authorization
A disgruntled employee intentionally deletes critical files and alters system configurations, resulting in significant damage to the organization's infrastructure. This scenario best represents which category of threat?
Compromises to Intellectual Property
Sabotage or Vandalism
Technical Software Failures or Errors
Theft
Which category of threat involves unauthorized individuals gaining access to sensitive information with the intention of extracting a ransom or other forms of payment?
Information Extortion
Theft
Espionage or Trespass
Deliberate Software Attacks
A severe earthquake damages the organization's data center, causing a complete loss of data and infrastructure. This scenario aligns with which category of threat?
Espionage or Trespass
Technical Hardware Failures or Errors
Sabotage or Vandalism
Forces of Nature
Which category of threat involves inadequate organizational policies or planning that can lead to security vulnerabilities and breaches?
Missing, Inadequate, or Incomplete Organizational Policy or Planning
Missing, Inadequate, or Incomplete Controls
Technological Obsolescence
Deviations in Quality of Service
What is a "Back Door" in the context of information security?
A physical entrance used by attackers to gain unauthorized access to a facility
A type of malware that disguises itself as a legitimate software program
A hidden method or vulnerability intentionally inserted into a system for unauthorized access
A social engineering technique used to trick individuals into revealing sensitive information
Which of the following is an example of a Trojan horse?
A self-replicating code that spreads through email attachments
A program that disguises itself as a legitimate antivirus software
A malicious script that exploits a web browser vulnerability
A worm that exploits a network vulnerability to propagate
This is an instance malicious code that it changes its appearance and behavior to avoid detection
Trojan Horses
Worms
Back door
Polymorphic threat
Which of the following is a characteristic of a virus and worm hoax?
They are harmless messages warning about non-existent threats
They exploit software vulnerabilities to infect systems
They use social engineering techniques to trick users into executing malicious code
They encrypt files and demand a ransom for their release
Which of the following attacks involves flooding a network or server with an overwhelming amount of traffic, rendering it inaccessible to legitimate users?
Password cracking
Man-in-the-middle attack
Denial of Service (DoS)
Social engineering
In which type of attack does an attacker use software to guess passwords by trying multiple combinations?
Man-in-the-middle attack
Brute force attack
Dictionary attack
Phishing attack
Which attack involves tricking individuals into divulging sensitive information by pretending to be a trustworthy entity?
Spoofing attack
Pharming attack
Sniffing attack
Social engineering attack
Which attack involves intercepting and altering communication between two parties without their knowledge?
Man-in-the-middle attack
Spoofing attack
Phishing attack
Denial of Service (DoS) attack
Which attack involves sending unsolicited bulk emails, typically for advertising or fraudulent purposes?
Spam attack
Mail bombing attack
Denial of Service (DoS) attack
Dictionary attack
Which attack involves masquerading as a trusted website or entity to deceive users into providing sensitive information?
Phishing attack
Sniffing attack
Dictionary attack
Back door attack
Which attack aims to gain unauthorized access to a system by systematically trying all possible words or combinations from a pre-existing list?
Brute force attack
Dictionary attack
Pharming attack
Man-in-the-middle attack
Which attack involves redirecting users from a legitimate website to a malicious website without their knowledge or consent?
Spoofing attack
Pharming attack
Sniffing attack
Spam attack
Lisa notices that her website's traffic has significantly increased, causing the server to slow down and become unresponsive. What type of attack is this?
Dictionary attack
Denial of Service (DoS) attack
Spoofing attack
Man-in-the-middle attack
You work for a large multinational corporation that frequently deals with sensitive customer information. The company has recently experienced several phishing attacks, and the management wants to ensure that all employees are aware of the best practices to avoid falling victim to such attacks. As part of an awareness campaign, they conduct training sessions and distribute informational materials. During one of these sessions, the following question is posed. Which of the following best describes a preventive measure to avoid falling victim to phishing attacks?
Clicking on email links without verifying the sender's identity.
Sharing your account credentials with a coworker who requests them via email.
Always reviewing and verifying the email sender's address and content before clicking on any links or providing personal information.
Responding to emails requesting urgent action without verifying the authenticity of the request.
