wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Information Assurance and Security MIDTERM

Total questions: 65

Worksheet time: 33mins

Name
Class
Date
1.

What is the main objective of Cyber Security?

a)

To ensure data protection

b)

To increase internet speed

c)

To create new software applications

d)

To promote social media usage

2.

Which type of cyber security threat involves a trial-and-error method to guess all possible combinations until the correct information is discovered?

a)

Brute Force

b)

Man-in-the-middle attack

c)

SQL Injection

d)

Phishing

3.

What is the main goal of the CIA model in Cyber Security?

a)

Data Privacy, Data Authenticity, and Data Accessibility

b)

Confidentiality, Integrity, and Availability

c)

Data Encryption, Data Integrity, and Data Availability

d)

Data Security, Network Security, and Application Security

4.

Which type of malware encrypts a user's files and demands a monetary ransom for decryption?

a)

Virus

b)

Spyware

c)

Ransomware

d)

Trojans

5.

What is the main purpose of a man-in-the-middle attack in cyber security?

a)

To disrupt targeted servers, services, or network's regular traffic

b)

To guess all possible combinations until the correct information is discovered

c)

To redirect site users to malicious websites and steal data

d)

To intercept a conversation or data transfer between two individuals

6.

Which type of cyber security threat involves cybercriminals disrupting targeted servers, services, or network's regular traffic by fulfilling legitimate requests with Internet traffic?

a)

Distributed denial of service (DDoS)

b)

Brute Force

c)

Man-in-the-middle attack

d)

Phishing

7.

What is the main benefit of implementing and maintaining cybersecurity for businesses?

a)

Unauthorized user access

b)

Data and network security

c)

Regulatory adherence

d)

Increased internet speed

8.

What is the best practice to protect against cyberattacks when using email?

a)

Open email attachments from unknown senders

b)

Use strong passwords

c)

Avoid using unsecured Wi-Fi networks in public places

d)

Do not open email attachments from unknown senders

9.

What is the main goal of identity management in cyber security?

a)

To protect the information stored in the digital environment or cloud architectures

b)

To determine the level of access that each individual has within an organization

c)

To deal with the processes, monitoring, alerts, and plans to respond to malicious activity

d)

To secure the organizational and personal data stored on mobile devices

10.

Which type of cyber security threat involves cybercriminals using phone calls, emails, text messages, and messaging apps for cyberattacks?

a)

Man-in-the-middle attack

b)

Malware

c)

Brute Force

d)

Phishing

11.

According to the principle of Economy of mechanism, security mechanisms should be:

a)

Complex and large

b)

Simple and small

c)

Redundant and inefficient

d)

Dynamic and adaptive

12.

The Fail-safe defaults principle states that the default configuration of a system should have a:

a)

Flexible protection scheme

b)

Risky protection scheme

c)

Conservative protection scheme

d)

Aggressive protection scheme

13.

What does the Least Privilege principle state?

a)

A user should have all privileges

b)

A user should have random privileges

c)

A user should have temporary privileges

d)

A user should have minimal privileges

14.

According to the Open Design principle, the security of a mechanism should not depend on the secrecy of its:

a)

Functionality

b)

Implementation

c)

Design

d)

Complexity

15.

What does the principle of Complete mediation restrict?

a)

Access to every object

b)

Authentication of access rights

c)

Caching of information

d)

Performance improvement techniques

16.

The Separation of Privilege principle states that a system should grant access permission based on:

a)

More than one condition being satisfied

b)

Random conditions being satisfied

c)

One condition being satisfied

d)

No conditions being satisfied

17.

What does the Least Common Mechanism principle minimize in systems with multiple users?

a)

Complexity of resources

b)

Access to resources

c)

Security of resources

d)

Sharing of resources

18.

According to the Psychological acceptability principle, a security mechanism should not make the resource more complicated to access if the security mechanisms were not present. This principle recognizes the human element in:

a)

Biometric security

b)

Network security

c)

Computer security

d)

Physical security

19.

What should be compared when designing a security scheme according to the Work Factor principle?

a)

Cost of circumventing a security mechanism and the resources of a potential attacker

b)

Complexity of the security mechanism and the resources of a potential attacker

c)

Performance of the security mechanism and the resources of a potential attacker

d)

Effectiveness of the security mechanism and the resources of a potential attacker

20.

The Compromise Recording principle states that sometimes it is more desirable to record the details of intrusion than to adopt a more sophisticated measure to prevent it. What is an example of a compromise recording system mentioned in the text?

a)

Intrusion detection system

b)

Firewall

c)

Antivirus software

d)

Surveillance cameras

21.

What is the purpose of a security policy in an organization?

a)

To encourage human mistakes and compromise system security

b)

To inform employees about their duties related to sensitive information

c)

To ignore the importance of responsibility in protecting sensitive data

d)

To increase the level of inconsistency

22.

Which policy helps to detect, remove, and repair the side effects of viruses and security risks by using signatures?

a)

Firewall Policy

b)

Intrusion Prevention policy

c)

LiveUpdate policy

d)

Virus and Spyware Protection policy

23.

What does the Firewall Policy do?

a)

Detects attacks by cybercriminals

b)

Does not provide any protection

c)

Adds unwanted sources of network traffic

d)

Allows unauthorized users to access systems and networks

24.

Which policy automatically detects and blocks network attacks and browser attacks?

a)

LiveUpdate policy

b)

Firewall Policy

c)

Intrusion Prevention policy

d)

Application and Device Control

25.

What does the LiveUpdate policy contain?

a)

Settings for LiveUpdate content updates

b)

Settings for virus and spyware scans

c)

Settings for host integrity

d)

Settings for application and device control

26.

What does the Application and Device Control policy protect?

a)

System's resources from applications

b)

Peripheral devices that can attach to a system

c)

Both Windows and Mac computers

d)

Only Windows clients

27.

What does the Exceptions policy provide the ability to do?

a)

Exclude applications and processes from detection by the virus and spyware scans

b)

Include applications and processes in detection by the firewall policy

c)

Exclude applications and processes from detection by the firewall policy

d)

Include applications and processes in detection by the virus and spyware scans

28.

What does the Host Integrity policy require the client system to have installed?

a)

LiveUpdate

b)

Firewall

c)

Antivirus

d)

Intrusion Prevention

29.

What is the purpose of the security policy in a business deal?

a)

To uphold discipline and accountability

b)

To provide a copy of the information security policy to other vendors

c)

To ensure security interests are not protected when dealing with smaller businesses

d)

To ignore the importance of responsibility in protecting sensitive data

30.

What does a well-written security policy act as?

a)

A contract to prove that an organization has taken steps to protect its intellectual property

b)

A contract to prove that an organization has not taken steps to protect its intellectual property

c)

A contract to prove that an organization has taken steps to compromise its intellectual property

d)

A contract to prove that an organization has not taken steps to compromise its intellectual property

31.

What is the purpose of risk analysis in an organization?

a)

To evaluate the likelihood of success in achieving the project objectives

b)

To plan for technology or equipment failure or loss from adverse events, both natural and human-caused

c)

To increase employee awareness about risks and security measures

d)

To identify gaps in information security and determine the next steps to eliminate the risks of security

32.

What is the first step in the risk analysis process?

a)

Develop a risk management plan

b)

Monitor the risks

c)

Identify the risks

d)

Conduct a risk assessment survey

33.

What is the main focus of quantitative risk analysis?

a)

To identify the impact of and prepare for changes in the enterprise environment

b)

To calculate estimates of overall project risk

c)

To evaluate the likelihood of success in achieving the project objectives

d)

To assess and evaluate the characteristics of individually identified risk

34.

What is the objective of qualitative risk analysis?

a)

To identify the impact of and prepare for changes in the enterprise environment

b)

To anticipate and reduce the effect of harmful results occurred from adverse events

c)

To evaluate the likelihood of success in achieving the project objectives

d)

To assess and evaluate the characteristics of individually identified risk

35.

What is the benefit of risk analysis concerning financial and organizational impacts?

a)

It identifies, rate and compares the overall impact of risks related to the organization

b)

It helps to identify gaps in information security and determine the next steps to eliminate the risks of security

c)

It improves security policies and procedures as well as develop cost-effective methods for implementing information security policies and procedures

d)

It increases employee awareness about risks and security measures during the risk analysis process and understands the financial impacts of potential security risks

36.

What is the purpose of the risk management plan in the risk analysis process?

a)

To develop a plan for technology or equipment failure or loss from adverse events, both natural and human-caused

b)

To anticipate and reduce the effect of harmful results occurred from adverse events

c)

To implement the measures to remove or reduce the analyses risks

d)

To evaluate whether the potential risks of a project are balanced in the decision process when evaluating to move forward with the project

37.

What is the primary goal of implementing the risk management plan?

a)

To monitor the risks

b)

To conduct a risk assessment survey

c)

To identify the risks

d)

To implement the measures to remove or reduce the analyses risks

38.

What is the purpose of conducting a risk assessment survey?

a)

To identify the risks

b)

To anticipate and reduce the effect of harmful results occurred from adverse events

c)

To plan for technology or equipment failure or loss from adverse events, both natural and human-caused

d)

To get the input from management and department heads to begin documenting the specific risks or threats within each department

39.

What is the purpose of qualitative risk analysis in a project?

a)

To identify the impact of and prepare for changes in the enterprise environment

b)

To evaluate the likelihood of success in achieving the project objectives

c)

To assess and evaluate the characteristics of individually identified risk

d)

To anticipate and reduce the effect of harmful results occurred from adverse events

40.

What is the purpose of quantitative risk analysis in a project?

a)

To identify the impact of and prepare for changes in the enterprise environment

b)

To evaluate the likelihood of success in achieving the project objectives

c)

To anticipate and reduce the effect of harmful results occurred from adverse events

d)

To provide a numerical estimate of the overall effect of risk on the project objectives

41.

What are the primary principles of the COBIT Framework?

a)

Meeting stakeholder needs

b)

Applying a single integrated framework

c)

Separating governance from management

d)

Enabling a holistic approach

42.

Which step of the NIST Risk Management Framework involves determining whether the implemented controls work as intended and produce the desired results?

a)

Authorize

b)

Categorize

c)

Assess

d)

Prepare

43.

What is the equation used to measure risk at a very high level?

a)

Risk = [Impact to the business] / [Likelihood of an adverse event]

b)

Risk = [Likelihood of an adverse event] + [Impact to the business]

c)

Risk = [Likelihood of an adverse event] X [Impact to the business]

d)

Risk = [Impact to the business] - [Likelihood of an adverse event]

44.

Which component of the Risk Management Framework involves establishing employee policies and assigning oversight responsibilities?

a)

Measuring Risk

b)

Mitigating Risk

c)

Identifying Risk

d)

Governing Risk

45.

What is the first step in the Risk Management Framework in 6 Steps?

a)

Set Business Objectives and Goals

b)

Do a Risk Impact Analysis

c)

Set Risk Tolerance

d)

Identify, Categorize, and Catalog Assets

46.

Which step of the Risk Management Framework involves reporting to leadership and the board of directors?

a)

Report to Leadership and Board of Directors

b)

Implement and Monitor Mitigating Controls

c)

Set Risk Tolerance

d)

Set Business Objectives and Goals

47.

What is the main purpose of using risk management software in the organization?

a)

To complicate manual processes

b)

To eliminate the need for monitoring controls

c)

To reduce the time spent on critical activities

d)

To increase the number of manual processes

48.

Which domain in the COBIT Framework involves governing body evaluating strategic options, directing senior management, and monitoring achievement?

a)

Evaluate, Direct, and Monitor (EDM)

b)

Align, Plan, and Organize (APO)

c)

Build, Acquire, and Implement (BAI)

d)

Deliver, Service, and Support (DSS)

49.

What is the purpose of the 'Categorize' step in the NIST Risk Management Framework?

a)

Determining whether the implemented controls work as intended and produce the desired results

b)

Using an impact analysis to organize the systems and information they process, store, and transmit

c)

Deploying controls and documenting activities

d)

Determining the controls that will protect the systems and data

50.

What is the main focus of the COBIT Framework?

a)

Technology assets

b)

Leadership's responsibilities

c)

Compliance program

d)

Oversight-oriented processes

51.

What are cybersecurity metrics?

a)

Data that a company tracks on a day-to-day basis

b)

Quantitative information to showcase efforts to protect the organization's data

c)

Bits of data that offer value but may not drive decisions

d)

Measures that have the most impact on driving the organization forward

52.

What is the difference between cybersecurity metrics and KPIs?

a)

Metrics are measures that have the most impact on driving the organization forward, while KPIs are data that a company tracks on a day-to-day basis

b)

Metrics are quantitative information to showcase efforts to protect the organization's data, while KPIs are measures that have the most impact on driving the organization forward

c)

Metrics are bits of data that a company tracks on a day-to-day basis, while KPIs are measures that have the most impact on driving the organization forward

d)

Metrics are measures that have the most impact on driving the organization forward, while KPIs are bits of data that offer value but may not drive decisions

53.

Why are cybersecurity metrics important?

a)

To measure the cost of responding to and resolving a cyberattack

b)

To track progress and review the overall cybersecurity strategy

c)

To track the volume of data transferred via the company's network

d)

To monitor the security requirements for each SSL certificate

54.

What is the 'Mean Time to Detect' (MTTD) in cybersecurity?

a)

The time taken to acknowledge the incident or data breach and begin working on resolving it

b)

The time taken to measure certain aspects pertaining to a cyberthreat

c)

The time taken to close an identified attack vector across all organization's endpoints

d)

The time taken to detect a threat or data breach

55.

What is the purpose of cybersecurity awareness training?

a)

To monitor for potential viruses infiltrating the system

b)

To track the volume of data transferred via the company's network

c)

To maintain documentation for cybersecurity awareness training within the organization

d)

To make employees aware of what phishing is and how to avoid and block it

56.

What is the 'Cost per Incident' metric in cybersecurity?

a)

The number of incorrectly configured SSL certificates

b)

The cost of responding to and resolving a cyberattack

c)

The time taken to measure certain aspects pertaining to a cyberthreat

d)

The time taken to detect a threat or data breach

57.

What does the 'Patching Cadence' metric measure in cybersecurity?

a)

The number of incorrectly configured SSL certificates

b)

The number of vulnerabilities in the organization's system

c)

The time taken to close an identified attack vector across all organization's endpoints

d)

The time between patch releases and when the organization begins implementation

58.

What is the 'First Party Security Ratings' metric used for in cybersecurity?

a)

To track the volume of data transferred via the company's network

b)

To review the organization's cybersecurity position using a letter-based grading system

c)

To monitor for potential viruses infiltrating the system

d)

To measure the cost of responding to and resolving a cyberattack

59.

What is the 'Non-human Traffic (NHT)' metric used for in cybersecurity?

a)

To identify bot attacks on the company website

b)

To measure the cost of responding to and resolving a cyberattack

c)

To track the volume of data transferred via the company's network

d)

To monitor for potential viruses infiltrating the system

60.

Why is it important to monitor the 'Data Transferred via the Corporate Network' in cybersecurity?

a)

To monitor for potential viruses infiltrating the system

b)

To measure the cost of responding to and resolving a cyberattack

c)

To identify bot attacks on the company website

d)

To track the volume of data transferred via the company's network

61.

Who is directly responsible for successfully completing a project task?

a)

Consulted

b)

Team member

c)

Informed

d)

Manager

62.

Who has final authority over the successful completion of a specific task or deliverable?

a)

Manager

b)

Accountable

c)

Consulted

d)

Informed

63.

Who is someone with unique insights the team will consult?

a)

Team member

b)

Informed

c)

Manager

d)

Consulted

64.

Who is a client or executive who isn’t directly involved, but should be kept up to speed?

a)

Consulted

b)

Informed

c)

Manager

d)

Team member

65.

Who is directly responsible for successfully completing a project task?

a)

Consulted

b)

Manager

c)

Team member

d)

Informed