wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Information Security Quiz

Total questions: 100

Worksheet time: 3hrs 20mins

Name
Class
Date
1.

Information systems can be used to help individuals make decisions.

a)

True

b)

False

2.

Information systems can be used to support a business's daily operations.

a)

True

b)

False

3.

An information system is a set of interrelated components that work together to collect, process, store, and disseminate information.

a)

True

b)

False

4.

Information systems are designed to support an organization's strategic objectives.

a)

True

b)

False

5.

What is an information system?

(a)  

6.

What is an information system?

a)

A set of interrelated components that work together to collect, process, store, and disseminate information.

b)

A computer program.

c)

A device for storing information.

d)

None of the above.

7.

What is an electronic commerce system?

a)

A type of information system that enables the buying and selling of products or services over the internet.

b)

A type of information system that helps organizations collect, store, and analyze data to support informed decision making.

c)

A type of information system that helps organizations manage interactions with customers and clients.

d)

A type of information system that uses artificial intelligence to simulate the problem-solving skills of a human expert.

8.

What is a geographic information system?

a)

A type of information system that helps organizations collect, store, manipulate, and visualize data about locations on the earth's surface.

b)

A type of information system that enables the buying and selling of products or services over the internet.

c)

A type of information system that helps organizations manage interactions with customers and clients.

d)

A type of information system that uses artificial intelligence to simulate the problem-solving skills of a human expert.

9.

What is a mobile information system?

a)

A type of information system that enables the use of mobile devices to access information and perform transactions.

b)

A type of information system that helps organizations collect, store, manipulate, and visualize data about locations on the earth's surface.

c)

A type of information system that helps organizations manage interactions with customers and clients.

d)

A type of information system that uses artificial intelligence to simulate the problem-solving skills of a human expert.

10.

What are the three main components of an information system?

a)

People, hardware, and software.

b)

Data, software, and communication networks.

c)

People, data, and processes.

d)

Hardware, software, and communication networks.

11.

What is the role of information systems in decision making?

a)

To provide data and information that support decision making.

b)

To automate the decision-making process.

c)

To eliminate the need for human decision making.

d)

To provide recommendations for decision making.

12.

What is data mining?

a)

The process of searching through large amounts of data to identify patterns and relationships.

b)

A type of information system that enables the use of mobile devices to access information and perform transactions.

c)

A type of information system that helps organizations collect, store, manipulate, and visualize data about locations on the earth's surface.

d)

A type of information system that uses artificial intelligence to simulate the problem-solving skills of a human expert.

13.

What is a data warehouse?

a)

A database that is used to store large amounts of data from multiple sources.

b)

A type of information system that enables the use of mobile devices to access information and perform transactions.

c)

A type of information system that helps organizations collect, store, manipulate, and visualize data about locations on the earth's surface.

d)

A type of information system that uses artificial intelligence to simulate the problem-solving skills of a human expert.

14.
Information Security is all about C I A. CIA stands for
a)
Confidentiality, Information and Availability
b)
Confidentiality, Integrity and Availability
c)
Communication, Integrity and Availability
d)
Communication, Information and Availability
15.
One of your customer went on a foreign tour, and locked the user access. Now she has come back, and tried to login into INB site but in vain. She approaches you for solutions. As a Banker, what is your response?
a)
Ask her to unlock herself online
b)
Approach the Branch to unlock the user by submitting a duly signed letter
c)
Unlock the user by using SBI Quick application
d)
None of the above.
16.
Ensuring Integrity in Information Security means
a)
Information is available only to the authorised employees on need to know basis
b)
Employees with integrity are only allowed to access the information
c)
Safeguarding the completeness of information always
d)
Safeguarding the accuracy, completeness and processing methods always
17.
Ensuring confidentiality in Information Security means
a)
Information is available to the requested persons
b)
Information is available to all employees of the Organisation
c)
Information is available only to the authorised employees on need to know basis
d)
Information is available only to the closed group of Top Management
18.
Ensuring Availability in Information Security means
a)
Keeping the data in database in a secure manner
b)
Keeping Information Assets as per commitment when required
c)
Data is to be made available for data analysis and analytics
d)
Making Information Assets available to all people at all times
19.
Maintaining the Confidentiality, Integrity and Availability is the responsibility of
a)
Global Information Technology Centre
b)
System Officers at branches / offices and Departments
c)
Head of Departments and Branch Managers
d)
It is a collective responsibility of all employees in the Bank
20.
While you are working in CBS, your Branch Manager calls you to come urgently to his cabin to discuss some issue, relating to a valued customer of your Branch. What is your course of action?
a)
Rush to the BM's cabin as per his directive
b)
Log out from CBS and go to the BM's cabin
c)
Lock the CBS screen and go to the BM's cabin
d)
Lock the Desktop by pressing Windows+L keys together and proceed to the BM's cabin
21.

As the band width is the main concern of the Bank, we are developing many mobile applications for the use of customers. However, usage of mobile have many vulnerabilities. Which one of the following is not a drawback in securing the Mobile Devises?

a)

ADS environment is not available

b)

Screen lock can be enabled with 'pattern', 'PIN' or 'Password'

c)

Proxy server or firewall facility is not available

d)

Anti-virus set up is not available

22.
Password maintenance is the most important Information Security threat for the Bank. What is the main reason for this?
a)
It is the passport to enter into the Bank's network and various applications
b)
This aspect of information security is to be maintained by people
c)
Compromise with the password may lead to financial loss and data loss
d)
All of the above
23.
In an emergency, your colleague has accessed email at a cyber café. What is the most important precaution you will advise to your colleague as a Banker?
a)
Don't open any new email while in the café
b)
Change the password of the email immediately after coming out from café
c)
Don't open any attachment of any new mail
d)
None of the above
24.
Your colleague had recently created a Facebook account. In the profile section, he has disclosed that he is Manager of SBI. What is the Bank's IS Policy guideline applicable to this activity?
a)
Not to directly or indirectly disclose / criticise Bank
b)
Post opinions in the official capacity of the Bank
c)
Canvass for any donation
d)
Promote any business
25.
One of the following is not an effective way to prevent card skimming.
a)
Installing anti-skimming devices
b)
Using of EMV chip based cards
c)
Usage of Foreign Object Detection Technology
d)
Swiping a card at POS machine of an unknown merchant
26.
Attachments in the form of photos, videos shall not be opened while you are accessing your mail in intranet.
a)
No. Office 365 scans each email before it is received
b)
Yes. Photos or videos may contain hidden messages which cannot be seen in normal course.
27.
What are the security features of our Internet Banking?
a)
It is a secured site (secured by SSL)
b)
URL starts with http://
c)
The address bar turns red when accessed
d)
Third party is activated only upto 10.00 PM each day
28.
You are compelled to use the Internet Café for making funds transfer through INB urgently to your friend's account. To avoid the problem of key loggers, what type of security feature do you use while login?
a)
Login with OTP
b)
Use Dynamic Virtual Board for entering User ID and Password
c)
Either of the first two options
d)
Neither of the first two options
29.
Which of the following is not a security feature available for mobile apps of our Bank?
a)
Session ends as soon as you close the application
b)
Application can only be accessed after proper authentication of customer username and password / mPIN
c)
Both the first option and second option are correct
d)
Neither the first option nor the second option is correct
30.
Which of the following is not a threat for using a Debit / Credit / Prepaid Card?
a)
Unauthorised usage as a result of it being lost or stolen
b)
Duplicating / cloning legitimate cards
c)
Skimming while doing a legitimate transaction at ATM or PoS machine
d)
None of the above
31.
Which of the following is not one of the method of protecting the data stored in the mobile phone?
a)
Protecting the Mobile with access control with password, or PIN or pattern
b)
Multi-factor authentication like finger print
c)
Encrypting the data traffic using Transport Layer Security (TLS)
d)
None of the above
32.

Define Management Information System (MIS)

a)

•Identifying the system that is needed for effective conclusion in organizations

b)

•Identifying the management that is needed for efficient decision making in organizations

c)

Identifying the information that is needed for effective decision making in organizations

d)

•Identifying the information that is needed for user acceptance in organizations

33.

Activity includes in IS

a)

x : process

y : output

z : feedback

t : input

b)

x : output

y : feedback

z : input

t : process

c)

x : input

y : process

z : output

t : feedback

d)

x : feedback

y : input

z : process

t : output

34.

Define Cybersecurity

a)

Cybersecurity refers to the protection of internet-connected systems such as software, hardware, electronic data, etc., from cyber attacks. In computing text, it is referred to as protection against unauthorized access.

b)

the practice of protecting systems, networks, and programs from digital attacks.

c)

Someone with the potential to cause harm by damaging or destroying the official data of a system or organization.

d)

It refers to weaknesses in a system that makes threat outcomes more possible and even more dangerous.

e)

It refers to a combination of threat probability and impact/loss. In simple terms, it is related to potential damage or loss when a threat exploits the vulnerability.

35.

A strong password is a critical line of defense in preventing a cyberattack. Which are the criteria of new password policy:

a)

Contains at least 14 characters

b)

Reuse old passwords or add on to existing passwords

c)

Contains at least 3 of the 4: Uppercase, Lowercase, Number, Symbol

d)

Does not contain the words ‘PETRONAS’ in any form

36.

Which of these actions can contribute to ensuring the security of your passwords?

a)

Setting a password that is a combination of uppercase, lower case, special characters and numbers.

b)

Changing your password regularly.

c)

Not using personally identifiable information such as name, birthdates, and telephone numbers.

d)

Using the same password for all accounts.

37.

Criminals access someone’s computer and encrypt the user’s personal files and data. The user is unable to access this data unless they pay the criminals to decrypt the files. This is known as ...

a)

Botnet

b)

Ransomware

c)

Spam

d)

None of the above

38.

_______________ is a tools which protects company data on mobile devices without infringing into personal data.

a)

Mobile Data Management

b)

Mobile Data Administration

c)

Mobile Device Administration

d)

Mobile Device Management

39.

Is this a legitimate email?

a)

True

b)

False

40.

Below are the common feature of MFA used in our daily transactions:

i. Using a credit/debit card at an ATM or at a checkout counter, and entering a PIN

ii. Using your password to login, and then entering an OTP sent to your phone or email address

iii. Scanning MySejahtera apps prior entering any premises

iv. Validation of your identity at a government office by inserting your Identity Card and scanning a fingerprint

a)

i and ii

b)

i, ii and iii

c)

i, ii and iv

d)

ii and iii

41.

Which of the following is an example of a “phishing” attack?

a)

Sending someone an email that contains a malicious link that is disguised to look like an email from someone the person knows.

b)

Creating a fake website that looks nearly identical to a real website in order to trick users into entering their login information.

c)

Sending someone a text message that contains a malicious link that is disguised to look like a notification that the person has won a contest.

d)

All of the above

42.

What is the term for computer programs that can wreak havoc on your device?

a)

Dangerbots

b)

Problemware

c)

Malware

d)

Hyperlinks

43.

Below are the scenarios that can happen to an organization when there is poor identity access management, except:

a)

A possibility of stolen identity of a former employee to access highly confidential information and sell it illegally

b)

Company confidential data are securely safe and no exposure of data breach

c)

An employee who no longer in service of an organisation can still access the network if his enterprise access is not terminated

d)

A third party vendor can copy files from the organisation’s database, exposing confidential company data.

44.

When entering personal data such as credit card information into a website, it is important to verify the url starts with 'https" to ensure the transaction is protected by SSL encryption.

a)

True

b)

False

45.

Working at your desk, you've received an email from Paypal or Apple explaining that your password it out of date, and you must set a new one. The link within the email will guide you through it. Your next step is?

a)

Follow the link and reset your password.

b)

Ignore the email and delete it.

c)

Reset your password manually.

46.

How do you make a login secure? (Multiple choice)

a)

A combination capital letter, number and symbols/special charatcters

b)

Using a phrase like "iloveManU"

c)

Enabling 2 factor authentication

d)

using password as a password

47.

Which of the following is a type of cyber security?

a)

Cloud Security

b)

All of these

c)

Application Security

d)

Network Security

48.

Phishing means

a)

Using a phishing pole in the water & catching phish

b)

Someone should have been more careful with the spell check

c)

Websites & emails created just to trick you so cybercriminals can steal your information

d)

All of these options are correct

49.

Identity theft only occurs to

a)

adults

b)

youth who share personal information

c)

people with firewalls installed on their computers

d)

all are correct

50.

Which of the following is not an advantage of cyber security?

a)

Minimizes computer freezing and crashes

b)

Makes the system slower

c)

Gives privacy to users

d)

Protects system against viruses

51.

Identify the oldest phone hacking technique used by hackers to make free calls.

a)

Spamming

b)

Phreaking

c)

Cracking

d)

Phishing

52.

Sending personal information like a social security or credit card number by email is ok if...

a)

it's to a well-known company

b)

it's to Roscoe Middle School

c)

It's to your family

d)

none of the above

53.

Is it safe to use your real personal information for an online character?

a)

Yes. It doesn't matter

b)

Yes, but only your real name, address, & age

c)

Yes, but only once in a while

d)

It's better not to reveal person information, even when creating an online character

54.

Which of the following is defined as an attempt to steal, spy, damage or destroy computer systems, networks, or their associated information?

a)

Computer security

b)

Cyber attack

c)

Digital hacking

d)

Cryptography

55.

According to a reliable source, which industry sector saw a rise in phishing attacks?

a)

social networking

b)

gaming

c)

financial institutions

d)

none of these

56.

Chain emails are:

a)

A way to ensure you have good luck

b)

A way to stay in touch with your friends

c)

A way for you to help cybercriminals to spread scams & tricks

d)

none of these are correct

57.

Cybersecurity also be referred to as ?

a)

incident security

b)

information technology security

c)

internet security

d)

threat security

58.

You just placed an order with: Orbitz, Priceline.com, Buy.com, 1-800Flowers, Continental Airlines, and Fandango. Because you entered your email in the "free coupon" pop-up ad afterwards you get...

a)

a $10 off coupon on your next order sent to your email

b)

a $10 off coupon on your next order sent with your order

c)

a repeating charge from a "web loyalty" company on your credit card

d)

None of these are correct

59.

Pop-up ads are:

a)

funny jokes

b)

just annoying advertisements, but generally safe

c)

a way to win contests & get fun electronics

d)

none of these are correct

60.

Legitimate companies rarely send you emails that require you to enter your account name/username/password immediately or face really bad consequences. How do you check to be sure the email is really from a company you know?

a)

Open your web browser & log-on to the site the way you normally would

b)

click on the link in the email

61.

What should you do if you think you have been hacked?

a)

Report the problem to the company.

b)

Change your password.

c)

Tell your parents or a trusted adult.

d)

All of the above.

62.

Cyber-laws are incorporated for punishing all criminals only

a)

True

b)

False

63.

You receive an email with the subject “Immediate Action Required needed on your credit card account.” Why is this suspicious?

a)

Because it is illegal to send credit offers in email

b)

Because your credit card company does not use email

c)

This email is not suspicious

d)

The subject line is demanding immediate action

64.

How should you confirm the legitimacy of an email?

a)

Contact the sender through a method not described in the email

b)

Reply to the email

c)

Send a letter to the address listed in the email

d)

Call the phone number listed in the email

65.

You receive an email from Human Resources Department. The email asks for your birthdate and home address to set up your retirement account. You should:

a)

Forward the email to your financial advisor

b)

Reply to the email with the required information

c)

Ignore the email and directly contact your Human Resource representatives to see if the email is legitimate.

d)

Reply to the email to confirm with your Human Resources department and then send the requested information

66.

you receive an unexpected email from a co-worker, asking you to review an attached document. You should.

a)

Open the attachment and review it immediately

b)

Reply to the email to confirm the attachment came from your co-worker

c)

Without replying to the email, confirm that your co-worker sent the attachment

d)

Download the attachment and wait to open it until you can confirm with your co-worker

67.

What is the goal behind phishing emails?

a)

Gain private information

b)

All of these

c)

Lower your defenses

d)

Help attack other targets

68.

You receive an email explaining that you won a tablet. What should you do next?

a)

Provide the required information and request overnight shipping

b)

Ignore and delete the email

c)

Follow the links in the email to investigate the offer further

d)

Forward the email to your friend so they can receive a free tablet too

69.

You are visiting your favourite website and it warns you that your Flash plugin is out of date. What should you do next?

a)

Install the update from your favorite website

b)

Install the update using a private browsing session

c)

Only download the update from the official source

d)

Ignore updates on your computer

70.

You found a USB drive and want to return it to the owner. You wonder if information on the drive could help you find the owner. What should you do with it?

a)

Ask a qualified IT person for help

b)

Drop the flash drive into a mailbox

c)

Look for the owner information by inserting the drive and looking through the files

d)

Put the flash drive in a drawer until you have the chance to update your antivirus

71.

What might phishing emails try to get you to do?

a)

Click Links

b)

Download files

c)

All of these

d)

Fill out forms

72.

What are the three traids of cybersecurity?

a)

Confidentially, Integrity, Availability

b)

Confidentially, Intellectual, Availability

c)

Combining, Intellectual, Accessibility

d)

Combining, Integrity, Accessibility

73.

Alice told her friend about her password of wechat. What traid does she violate?

a)

Confidentially

b)

Integrity

c)

Availability

74.

Alice told her friend Bob about her email password. And then she found Bob used her email sent emails to others. Who is responsible for this case?

a)

Alice

b)

Bob

c)

Alice and Bob

75.

Alice told her friend Bob about her email password. And then she found Bob changed some her emails and sent emails to others. What traids are involved into this case?

a)

Confidentially and Integrity

b)

Integrity and Availability

c)

Confidentally and Availability

d)

Confidentally, Integrity and Availability

76.

Alice inserts a trojan program into Bob's laptop, and she found out Bob's password of his bank accounts. She did not take any money, so does she violate any laws?

a)

Yes, she violated laws of Trade Secret, Business Secret

b)

Yes, she violated laws of cybersecurity

c)

No she did not

d)

Yes, she violate the polity

77.

Alice needs to withdraw some money from ATM machine. When she takes her money out she did not have the awareness of hiding her password when she input. So her money has been stolen. What this case can tell?

a)

Alice violated confidentally traid.

b)

Alice violated Integrity traid

c)

Alice violated availability traid

d)

The guy took her money violated availability traid

78.

Can you give an example contains all CIA

4 lines
79.

In what year do passwords and multiple layers of security protection added to devices?

a)

1960s

b)

1970s

c)

1980s

d)

2010s

80.

Which among the following is not considered as information security domain?

a)

Career Development

b)

Threat Intelligence

c)

Security Operation

d)

Denial-of-Service

81.

•If developers had sufficient time, they could resolve and eliminate _.

a)

faults

b)

system calls

c)

processes

d)

firewalls

82.

Implementation of information security often described as combination of _.

a)

art and science

b)

art and math

c)

ethics and math

d)

ethics and physics

83.

Which refers to a well-informed sense of assurance that the information risks and controls are in balance?

a)

Arts

b)

Security Artisan

c)

Information Security

d)

Architecture

84.

What kind of cyber security risks can be minimised by using a Virtual Private Network (VPN)?

a)

Use of insecure Wi-Fi networks

b)

Key-Logging

c)

De-anonymization by network operators

d)

Phishing attacks

85.

An email that attempts to trick a reader into installing software that may contain a virus is:

a)

Phishing Scam

b)

Lobster trap

c)

Fishing Scam

d)

Phone Scam

86.

Which is an example of PII? (Personally Identifiable Information)

a)

Credit Card Number

b)

Name

c)

Home Address

d)

All of the above

87.

What is the best definition of Spear Phishing?

a)

"A Phishing email aimed directly at you"

b)

"A malicious virus that can encrypt or lock your computer"

c)

"A method hackers can use to guess your password"

d)

"A random Phishing email sent to a massive group"

88.

What is a step that you can take to minimise the chance and impact of a ransomware attack?

a)

"All of these answers"

b)

"Keep your computer software up to date"

c)

"Ensure that anti-virus tools are running and up to date"

d)

"Ensure that you are backing up your critical files"

89.

Who you are allowed to give your password to?

a)

"Anybody you trust"

b)

"Only supervisors and authorised IT staff if requested"

c)

"Only IT staff"

d)

"Nobody"

90.

What does compliance mean?

a)

providing secure access to user data

b)

using honest means to bypass security measures

c)

conducting tests to identify vulnerabilities in a system

d)

following the rules or standards that have been established

91.

Which of the following is not considered social engineering?

a)

dumpster diving

b)

convincing people to reveal information

c)

encrypting data to prevent user access until a fee is paid

d)

looking through social media sites for information

92.
Organisations storing your data must...
a)
Keep it up to date
b)
Keep it for no longer than 5 years after your death
c)
Ask for more data than required
d)
Wait for you to contact them to ensure its accurate
93.
How many principles does the Data Protection Act have?
a)
4
b)
8
c)
9
d)
10
94.
What is gaining unauthorised access to a computer system also known as?
a)
Hacking
b)
Spamming
c)
Phishing
d)
Logging on
95.
Why was the Computer Misuse Act of 1990 introduced?
a)
To help protect computer software
b)
To help protect computer hardware
c)
To stop the spread of computer viruses
d)
To stop people from accessing unauthorised information. 
96.
What is the name of the law that makes hacking illegal?
a)
Data Protection Act
b)
Computer Misuse Act
c)
Copyright, Designs and Patents Act
d)
Hacking Act
97.
What are the principles of the Computer Misuse Act?
a)
Authorised access,Authorised access with intent, Authorised 
b)
Unauthorised access with intent and Unauthorised modification
c)
Unauthorised access and Unauthorised modification
d)
Unauthorised access, Unauthorised access with intent, Unauthorised modification
98.

____ is a well-defined, formal process help desk staff follow to:

–Handle problem incidents

–Get information to users

–Solve user problems

–Maintain records about the incident

a)

Call management

b)

Incident management

c)

ITIL

d)

None of the above

99.

What's included in a strong password?

a)

A minimum of eight characters

b)

At least one lowercase alphabetical letter (a-z)

c)

At least one uppercase alphabetical letter (A-Z)

d)

At least one digit (0-9) and/or one special character (i.e., @ ! % & $ ^ * ( ) + = )

e)

All of the above

100.

Which of the following is a weak password?

a)

123456

b)

P@ssw0rd

c)

ILoveYou123

d)

All of the above