NEW
Font size
WorksheetsInformation Assurance and Security MIDTERM
Total questions: 65
Worksheet time: 33mins
What is the main objective of Cyber Security?
To ensure data protection
To increase internet speed
To create new software applications
To promote social media usage
Which type of cyber security threat involves a trial-and-error method to guess all possible combinations until the correct information is discovered?
Brute Force
Man-in-the-middle attack
SQL Injection
Phishing
What is the main goal of the CIA model in Cyber Security?
Data Privacy, Data Authenticity, and Data Accessibility
Confidentiality, Integrity, and Availability
Data Encryption, Data Integrity, and Data Availability
Data Security, Network Security, and Application Security
Which type of malware encrypts a user's files and demands a monetary ransom for decryption?
Virus
Spyware
Ransomware
Trojans
What is the main purpose of a man-in-the-middle attack in cyber security?
To disrupt targeted servers, services, or network's regular traffic
To guess all possible combinations until the correct information is discovered
To redirect site users to malicious websites and steal data
To intercept a conversation or data transfer between two individuals
Which type of cyber security threat involves cybercriminals disrupting targeted servers, services, or network's regular traffic by fulfilling legitimate requests with Internet traffic?
Distributed denial of service (DDoS)
Brute Force
Man-in-the-middle attack
Phishing
What is the main benefit of implementing and maintaining cybersecurity for businesses?
Unauthorized user access
Data and network security
Regulatory adherence
Increased internet speed
What is the best practice to protect against cyberattacks when using email?
Open email attachments from unknown senders
Use strong passwords
Avoid using unsecured Wi-Fi networks in public places
Do not open email attachments from unknown senders
What is the main goal of identity management in cyber security?
To protect the information stored in the digital environment or cloud architectures
To determine the level of access that each individual has within an organization
To deal with the processes, monitoring, alerts, and plans to respond to malicious activity
To secure the organizational and personal data stored on mobile devices
Which type of cyber security threat involves cybercriminals using phone calls, emails, text messages, and messaging apps for cyberattacks?
Man-in-the-middle attack
Malware
Brute Force
Phishing
According to the principle of Economy of mechanism, security mechanisms should be:
Complex and large
Simple and small
Redundant and inefficient
Dynamic and adaptive
The Fail-safe defaults principle states that the default configuration of a system should have a:
Flexible protection scheme
Risky protection scheme
Conservative protection scheme
Aggressive protection scheme
What does the Least Privilege principle state?
A user should have all privileges
A user should have random privileges
A user should have temporary privileges
A user should have minimal privileges
According to the Open Design principle, the security of a mechanism should not depend on the secrecy of its:
Functionality
Implementation
Design
Complexity
What does the principle of Complete mediation restrict?
Access to every object
Authentication of access rights
Caching of information
Performance improvement techniques
The Separation of Privilege principle states that a system should grant access permission based on:
More than one condition being satisfied
Random conditions being satisfied
One condition being satisfied
No conditions being satisfied
What does the Least Common Mechanism principle minimize in systems with multiple users?
Complexity of resources
Access to resources
Security of resources
Sharing of resources
According to the Psychological acceptability principle, a security mechanism should not make the resource more complicated to access if the security mechanisms were not present. This principle recognizes the human element in:
Biometric security
Network security
Computer security
Physical security
What should be compared when designing a security scheme according to the Work Factor principle?
Cost of circumventing a security mechanism and the resources of a potential attacker
Complexity of the security mechanism and the resources of a potential attacker
Performance of the security mechanism and the resources of a potential attacker
Effectiveness of the security mechanism and the resources of a potential attacker
The Compromise Recording principle states that sometimes it is more desirable to record the details of intrusion than to adopt a more sophisticated measure to prevent it. What is an example of a compromise recording system mentioned in the text?
Intrusion detection system
Firewall
Antivirus software
Surveillance cameras
What is the purpose of a security policy in an organization?
To encourage human mistakes and compromise system security
To inform employees about their duties related to sensitive information
To ignore the importance of responsibility in protecting sensitive data
To increase the level of inconsistency
Which policy helps to detect, remove, and repair the side effects of viruses and security risks by using signatures?
Firewall Policy
Intrusion Prevention policy
LiveUpdate policy
Virus and Spyware Protection policy
What does the Firewall Policy do?
Detects attacks by cybercriminals
Does not provide any protection
Adds unwanted sources of network traffic
Allows unauthorized users to access systems and networks
Which policy automatically detects and blocks network attacks and browser attacks?
LiveUpdate policy
Firewall Policy
Intrusion Prevention policy
Application and Device Control
What does the LiveUpdate policy contain?
Settings for LiveUpdate content updates
Settings for virus and spyware scans
Settings for host integrity
Settings for application and device control
What does the Application and Device Control policy protect?
System's resources from applications
Peripheral devices that can attach to a system
Both Windows and Mac computers
Only Windows clients
What does the Exceptions policy provide the ability to do?
Exclude applications and processes from detection by the virus and spyware scans
Include applications and processes in detection by the firewall policy
Exclude applications and processes from detection by the firewall policy
Include applications and processes in detection by the virus and spyware scans
What does the Host Integrity policy require the client system to have installed?
LiveUpdate
Firewall
Antivirus
Intrusion Prevention
What is the purpose of the security policy in a business deal?
To uphold discipline and accountability
To provide a copy of the information security policy to other vendors
To ensure security interests are not protected when dealing with smaller businesses
To ignore the importance of responsibility in protecting sensitive data
What does a well-written security policy act as?
A contract to prove that an organization has taken steps to protect its intellectual property
A contract to prove that an organization has not taken steps to protect its intellectual property
A contract to prove that an organization has taken steps to compromise its intellectual property
A contract to prove that an organization has not taken steps to compromise its intellectual property
What is the purpose of risk analysis in an organization?
To evaluate the likelihood of success in achieving the project objectives
To plan for technology or equipment failure or loss from adverse events, both natural and human-caused
To increase employee awareness about risks and security measures
To identify gaps in information security and determine the next steps to eliminate the risks of security
What is the first step in the risk analysis process?
Develop a risk management plan
Monitor the risks
Identify the risks
Conduct a risk assessment survey
What is the main focus of quantitative risk analysis?
To identify the impact of and prepare for changes in the enterprise environment
To calculate estimates of overall project risk
To evaluate the likelihood of success in achieving the project objectives
To assess and evaluate the characteristics of individually identified risk
What is the objective of qualitative risk analysis?
To identify the impact of and prepare for changes in the enterprise environment
To anticipate and reduce the effect of harmful results occurred from adverse events
To evaluate the likelihood of success in achieving the project objectives
To assess and evaluate the characteristics of individually identified risk
What is the benefit of risk analysis concerning financial and organizational impacts?
It identifies, rate and compares the overall impact of risks related to the organization
It helps to identify gaps in information security and determine the next steps to eliminate the risks of security
It improves security policies and procedures as well as develop cost-effective methods for implementing information security policies and procedures
It increases employee awareness about risks and security measures during the risk analysis process and understands the financial impacts of potential security risks
What is the purpose of the risk management plan in the risk analysis process?
To develop a plan for technology or equipment failure or loss from adverse events, both natural and human-caused
To anticipate and reduce the effect of harmful results occurred from adverse events
To implement the measures to remove or reduce the analyses risks
To evaluate whether the potential risks of a project are balanced in the decision process when evaluating to move forward with the project
What is the primary goal of implementing the risk management plan?
To monitor the risks
To conduct a risk assessment survey
To identify the risks
To implement the measures to remove or reduce the analyses risks
What is the purpose of conducting a risk assessment survey?
To identify the risks
To anticipate and reduce the effect of harmful results occurred from adverse events
To plan for technology or equipment failure or loss from adverse events, both natural and human-caused
To get the input from management and department heads to begin documenting the specific risks or threats within each department
What is the purpose of qualitative risk analysis in a project?
To identify the impact of and prepare for changes in the enterprise environment
To evaluate the likelihood of success in achieving the project objectives
To assess and evaluate the characteristics of individually identified risk
To anticipate and reduce the effect of harmful results occurred from adverse events
What is the purpose of quantitative risk analysis in a project?
To identify the impact of and prepare for changes in the enterprise environment
To evaluate the likelihood of success in achieving the project objectives
To anticipate and reduce the effect of harmful results occurred from adverse events
To provide a numerical estimate of the overall effect of risk on the project objectives
What are the primary principles of the COBIT Framework?
Meeting stakeholder needs
Applying a single integrated framework
Separating governance from management
Enabling a holistic approach
Which step of the NIST Risk Management Framework involves determining whether the implemented controls work as intended and produce the desired results?
Authorize
Categorize
Assess
Prepare
What is the equation used to measure risk at a very high level?
Risk = [Impact to the business] / [Likelihood of an adverse event]
Risk = [Likelihood of an adverse event] + [Impact to the business]
Risk = [Likelihood of an adverse event] X [Impact to the business]
Risk = [Impact to the business] - [Likelihood of an adverse event]
Which component of the Risk Management Framework involves establishing employee policies and assigning oversight responsibilities?
Measuring Risk
Mitigating Risk
Identifying Risk
Governing Risk
What is the first step in the Risk Management Framework in 6 Steps?
Set Business Objectives and Goals
Do a Risk Impact Analysis
Set Risk Tolerance
Identify, Categorize, and Catalog Assets
Which step of the Risk Management Framework involves reporting to leadership and the board of directors?
Report to Leadership and Board of Directors
Implement and Monitor Mitigating Controls
Set Risk Tolerance
Set Business Objectives and Goals
What is the main purpose of using risk management software in the organization?
To complicate manual processes
To eliminate the need for monitoring controls
To reduce the time spent on critical activities
To increase the number of manual processes
Which domain in the COBIT Framework involves governing body evaluating strategic options, directing senior management, and monitoring achievement?
Evaluate, Direct, and Monitor (EDM)
Align, Plan, and Organize (APO)
Build, Acquire, and Implement (BAI)
Deliver, Service, and Support (DSS)
What is the purpose of the 'Categorize' step in the NIST Risk Management Framework?
Determining whether the implemented controls work as intended and produce the desired results
Using an impact analysis to organize the systems and information they process, store, and transmit
Deploying controls and documenting activities
Determining the controls that will protect the systems and data
What is the main focus of the COBIT Framework?
Technology assets
Leadership's responsibilities
Compliance program
Oversight-oriented processes
What are cybersecurity metrics?
Data that a company tracks on a day-to-day basis
Quantitative information to showcase efforts to protect the organization's data
Bits of data that offer value but may not drive decisions
Measures that have the most impact on driving the organization forward
What is the difference between cybersecurity metrics and KPIs?
Metrics are measures that have the most impact on driving the organization forward, while KPIs are data that a company tracks on a day-to-day basis
Metrics are quantitative information to showcase efforts to protect the organization's data, while KPIs are measures that have the most impact on driving the organization forward
Metrics are bits of data that a company tracks on a day-to-day basis, while KPIs are measures that have the most impact on driving the organization forward
Metrics are measures that have the most impact on driving the organization forward, while KPIs are bits of data that offer value but may not drive decisions
Why are cybersecurity metrics important?
To measure the cost of responding to and resolving a cyberattack
To track progress and review the overall cybersecurity strategy
To track the volume of data transferred via the company's network
To monitor the security requirements for each SSL certificate
What is the 'Mean Time to Detect' (MTTD) in cybersecurity?
The time taken to acknowledge the incident or data breach and begin working on resolving it
The time taken to measure certain aspects pertaining to a cyberthreat
The time taken to close an identified attack vector across all organization's endpoints
The time taken to detect a threat or data breach
What is the purpose of cybersecurity awareness training?
To monitor for potential viruses infiltrating the system
To track the volume of data transferred via the company's network
To maintain documentation for cybersecurity awareness training within the organization
To make employees aware of what phishing is and how to avoid and block it
What is the 'Cost per Incident' metric in cybersecurity?
The number of incorrectly configured SSL certificates
The cost of responding to and resolving a cyberattack
The time taken to measure certain aspects pertaining to a cyberthreat
The time taken to detect a threat or data breach
What does the 'Patching Cadence' metric measure in cybersecurity?
The number of incorrectly configured SSL certificates
The number of vulnerabilities in the organization's system
The time taken to close an identified attack vector across all organization's endpoints
The time between patch releases and when the organization begins implementation
What is the 'First Party Security Ratings' metric used for in cybersecurity?
To track the volume of data transferred via the company's network
To review the organization's cybersecurity position using a letter-based grading system
To monitor for potential viruses infiltrating the system
To measure the cost of responding to and resolving a cyberattack
What is the 'Non-human Traffic (NHT)' metric used for in cybersecurity?
To identify bot attacks on the company website
To measure the cost of responding to and resolving a cyberattack
To track the volume of data transferred via the company's network
To monitor for potential viruses infiltrating the system
Why is it important to monitor the 'Data Transferred via the Corporate Network' in cybersecurity?
To monitor for potential viruses infiltrating the system
To measure the cost of responding to and resolving a cyberattack
To identify bot attacks on the company website
To track the volume of data transferred via the company's network
Who is directly responsible for successfully completing a project task?
Consulted
Team member
Informed
Manager
Who has final authority over the successful completion of a specific task or deliverable?
Manager
Accountable
Consulted
Informed
Who is someone with unique insights the team will consult?
Team member
Informed
Manager
Consulted
Who is a client or executive who isn’t directly involved, but should be kept up to speed?
Consulted
Informed
Manager
Team member
Who is directly responsible for successfully completing a project task?
Consulted
Manager
Team member
Informed
