wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Security Principles Module 1-5

Total questions: 142

Worksheet time: 2hrs 21mins

Name
Class
Date
1.

Protect society and infrastructure

a)

Canon 1

b)

Canon 2

c)

Canon 3

d)

Canon 4

2.

ISC2 members are required to report breaches of the Code of Ethics to ISC2 for investigation

a)

True

b)

False

3.

Advance the information security profession

a)

Canon 1

b)

Canon 2

c)

Canon 3

d)

Canon 4

4.

Serve principals diligently and competently

a)

Canon 1

b)

Canon 2

c)

Canon 3

d)

Canon 4

5.

Act honorably

a)

Canon 1

b)

Canon 2

c)

Canon 3

d)

Canon 4

6.

You must have (a)   to file a complaint.

7.

(a)   may file a complaint under Canon 1 and 2

8.

Employers or (a)   may file a complaint under Canon 3

9.

(a)   may file a complaint under Canon 4

10.

Protects information from unauthorized changes

a)

Integrity

b)

Confidentiality

c)

Availability

11.

Protects information from unauthorized disclosure

a)

Integrity

b)

Confidentiality

c)

Availability

12.

Protects authorized access to systems and data

a)

Integrity

b)

Confidentiality

c)

Availability

13.

Confidentiality Concern:

a)

Snooping

Dumpster Diving

Eavesdropping

Wiretapping Social

Social Engineering

b)

Unauthorized modifications

Impersonation

Man-in-the-middle (MITM)

Replay

c)

Denial of Service (DoS)

Power outages

Hardware failures

Destruction

Service outages

d)

Protecting our own data

Educating our users

Protecting data collected by our organization

14.

Involves gathering information that is left out in the open

a)

Snooping

b)

Dumpster Diving

c)

Eavesdropping

d)

Wiretapping

e)

Social Engineering

15.

Shredding protects against (a)  

16.

Rules about sensitive conversations prevent...

a)

Snooping

b)

Dumpster Diving

c)

Eavesdropping

d)

Wiretapping

e)

Social Engineering

17.

Encryption protects against (a)  

18.

Education protects against (a)  

19.

Integrity Concerns:

a)

Unauthorized modifications

Impersonation

Man-in-the-middle (MITM)

Replay

b)

Snooping

Dumpster Diving

Eavesdropping

Wiretapping

Social Engineering

c)

Denial of Service (DoS)

Power outages

Hardware failures

Destruction

Service outages

d)

Protecting our own data

Educating our users

Protecting data collected by our organizations

20.

What attack make without permission

a)

Unauthorized modification

Attack

b)

Impersonation Attack

c)

Man-in-the-middle Attack

d)

Replay Attack

21.

What attack pretend to be someone else

a)

Impersonation Attack

b)

Unauthorized modification Attack

c)

Man-in-the-middle Attack

d)

Replay Attack

22.

What attack place the attacker in the middle of a communications

a)

Man-in-the-middle Attack

b)

Replay Attack

c)

Impersonation Attack

d)

Unauthorized modification Attack

23.

What attack eavesdrop on logins and reuse the captured credentials

a)

Replay Attack

b)

Man-in-the-middle Attack

c)

Impersonation Attack

d)

Unauthorized modification

Attack

24.

Least privileged protects against (a)  

25.

User education protects against (a)   attacks

26.

Encryption protects against ____ and ____

(a)  

27.

Protects authorized access to systems and data

a)

Availability

b)

Integrity

c)

Confidentiality

28.

Availability Concerns:

a)

Denial of Service (DoS)

Power outages

Hardware failures

Destruction

Service outages

b)

Protecting our own data

Educating our users

Protecting data collected by our organizations

c)

Dumpster Diving

Eavesdropping

Wiretapping

Social Engineering

d)

Unauthorized modifications

Impersonation

Man-in-the-middle (MITM)

Replay

29.

Both unauthorized connections to protect against (a)   attacks

30.

Redundant power and generators protect against (a)   outages

31.

Redundant components protect against (a)   failure

32.

Backup data centers protect against (a)  

33.

Resilient systems protect against (a)   outage

34.

Involves making a claim of identity

a)

Identification

b)

Authentication

c)

Authorization

d)

Accounting

35.

Electronic identification commonly uses (a)  

36.

Requires providing a claim identity

a)

Authentication

b)

Authorization

c)

Accounting

d)

Identification

37.

Ensures that an action is allowed

a)

Authorization

b)

Accounting

c)

Authentication

d)

Identification

38.

Electronic authentication commonly uses (a)  

39.

Electronic authorization commonly uses access (a)   lists

40.

Maintains logs of users activity

a)

Accounting

b)

Authorization

c)

Authentication

d)

Identification

41.

(a)   includes authentication, authorization, and accounting

42.

Requirements set a minimum number of characters

a)

Password length

b)

Password complexity

c)

Password expiration

d)

Password history

e)

Password managers

43.

Requirements describe the types of characters that must be included

a)

Password complexity

b)

Password expiration

c)

Password length

d)

Password history

e)

Password managers

44.

Requirements force password changes

a)

Password expiration

b)

Password complexity

c)

Password length

d)

Password history

e)

Password managers

45.

Requirements prevent password reuse

a)

Password history

b)

Password managers

c)

Password expiration

d)

Password complexity

e)

Password length

46.

Facilitate the use of strong, unique passwords

a)

Password managers

b)

Password history

c)

Password expiration

d)

Password length

e)

Password length

47.

Make it easy for users to change their (a)  

48.

What are 3 Authentication factors:

a)

Something you know

Something you are

Something you have

b)

Control applied

Residual risk

Control risk

c)

Preventive control

Detective control

Recovery control

d)

Policies

Standards

Guidelines

49.

"Something you know"

a)

Passwords, PINs, and security questions

b)

Biometric security mechanisms

c)

Software and hardware tokens

50.

"Something you are"

a)

Biometric security mechanism

b)

Password, PINs, and security questions

c)

Software and hardware tokens

51.

"Something you have"

a)

Software and hardware tokens

b)

Biometric security mechanisms

c)

Passwords, PINs, and security questions

52.

(a)   can steal passwords

53.

(a)   might lose smart cards

54.

(a)   authentication combines two different authentication factors

55.

Password combined with (a)   ARE multi-factor

56.

Fingerprints combined with (a)   ARE multi-factor

57.

Passwords combined with (a)   are NOT multi-factor

58.

Shares authenticated sessions across systems

a)

Single Sign-Out (SSO)

b)

Multi-Factor authentication

c)

Passwords

d)

Fingerprints

59.

Prevents someone from denying the truth

a)

Non-repudiation

b)

Privacy

c)

Internal risk

d)

Multiparty risk

60.

Signatures provide non-repudiation for (a)   documents

61.

Digital signatures provide non-repudiation for (a)   documents

62.

Privacy Concerns:

a)

Protecting our own data

Educating our users

Protecting data collected by our organization

b)

Risk avoidance

Risk transference

Risk mitigation

Risk acceptance

c)

Threat vectors

Vulnerabilities

Risk assessment

Internal risk

d)

Likelihood

Threats

Impact

Risk

63.

Relates to a specific individual

a)

Personally Identifiable Information (PII)

b)

Protected Health Information (PHI)

64.

Includes health care records

a)

Protected Health Information (PHI)

b)

Personally Identification Information (PII)

65.

You do not have a reasonable expectation of privacy in social media

a)

True

b)

False

66.

You have some expectation of privacy for private electronic communications

a)

True

b)

False

67.

You have a reasonable expectation of privacy when sharing PII with an organization

a)

True

b)

False

68.

You have no expectation of privacy when using employer reasources

a)

True

b)

False

69.

Arise from within the organizations

a)

Internal risk

b)

External risk

c)

Multiparty risks

70.

Internal controls address (a)   risks

71.

Arise from outside the organization

a)

External risk

b)

Multiparty risks

c)

Internal risk

72.

Affect more than one organization

a)

Multiparty risks

b)

Internal risk

c)

External risk

73.

Any organization using ___, consider replacing ___

(a)  

74.

Poses a risk to knowledge-based organizations

a)

Intellectual Property Theft

b)

Software license compliance

c)

Risk Assessment

d)

Vulnerabilities

75.

Issues risk fines and legal action

a)

Software license compliance

b)

Intellectual property theft

c)

Risk assessment

d)

Vulnerabilities

76.

(a)   professionals must prioritize risks

77.

The process of identifying, analysing and evaluating risk.

“Identifies and triages risks”

a)

Risk assessment

b)

Threats

c)

Vulnerabilities

d)

Controls

78.

External forces that jeopardize security

a)

Threats

b)

Risk

c)

Vulnerabilities

d)

Risk assessment

79.

(a)   vectors are methods used by attackers

80.

Weakness in your security controls

a)

Vulnerabilities

b)

Risks

c)

Threats

d)

Risk assessment

81.

The combination of a threat and vulnerability

a)

Risks

b)

Risk assessment

c)

Likelihood

d)

Impact

82.

We rank risks by ___ and ___

(a)  

83.

The probability a risk will occur

a)

Likelihood

b)

Impact

c)

Qualitative Risk Assessment

d)

Quantitative Risk Assessment

84.

The amount of damage a risk will cause

a)

Impact

b)

Likelihood

c)

Qualitative Risk Assessment

d)

Quantitative Risk Assessment

85.

Uses subjective ratings to evaluate risk likelihood and impact

a)

Qualitative Risk Assessment

b)

Quantitative Risk Assessment

c)

Likelihood

d)

Impact

86.

Uses objective numeric ratings to evaluate risk likelihood and impact

a)

Quantitative Risk Assessment

b)

Qualitative Risk Assessment

c)

Risk

d)

Vulnerabilities

87.

Include avoiding, optimizing, transferring or retaining risk.

“Analyzes and implements possible responses control risk”

a)

Risk treatment

b)

Risk avoidance

c)

Risk mitigation

d)

Risk acceptance

e)

Risk transference

88.

Changes business practices to make a risk irrelevant

a)

Risk avoidance

b)

Risk mitigation

c)

Risk acceptance

d)

Risk treatment

e)

Risk transference

89.

Insurance is a common way to (a)   risk

90.

Reduces the likelihood or impact of a risk

a)

Risk mitigation

b)

Risk acceptance

c)

Risk avoidance

d)

Risk treatment

91.

The choice to continue operations in the face of a risk

a)

Risk acceptance

b)

Risk mitigation

c)

Risk avoidance

d)

Risk treatment

e)

Risk transference

92.

An organization's (a)   profile is the set of risk that it faces

93.

The initial level of risk that exists in an organization before any controls are put in place

a)

Inherent risk

b)

Risk transference

c)

Risk mitigation

d)

Risk acceptance

94.

Restricts or blocks applications from operating in a way that puts your data at risk.

“To reduce that risk”

a)

Application control

b)

Residual risk

c)

Control risk

d)

Risk tolerance

95.

The amount of risk left over after actions have already been taken to address threats

“Reduced by controls”

a)

Residual risk

b)

Control risk

c)

Application control

d)

Risk tolerance

96.

Introduce new risk

a)

Control risk

b)

Risk tolerance

c)

Residual risk

d)

Application control

97.

The level of risk an organization is willing

a)

Risk tolerance

b)

Application control

c)

Control risk

d)

Residual risk

98.

The goal of risk management: is to make sure that the combination of the residual risk and the control risk is below the organization's risk tolerance.

a)

True

b)

False

99.

Reduce the likelihood or impact of a risk and help identify issues

a)

Security controls

b)

Defense in depth

c)

Risk tolerance

d)

Risk assessment

100.

Uses layered defensive mechanisms to protect systems and data.

"Uses overlapping security controls"

Examples: Anti-virus software, Firewalls, Intrusion detection systems, Multi-factor authentication, Data encryption, Network segmentation, Zero Trust

a)

Defense in depth

b)

Risk tolerance

c)

Control risk

d)

Control applied

101.

Stop a security issue from occurring

a)

Preventive control

b)

Detective control

c)

Recovery control

102.

Identify security issues requiring investigation

a)

Detective control

b)

Recovery control

c)

Preventive control

103.

Remediate security issues that have occurred

a)

Recovery controls

b)

Detective controls

c)

Preventive controls

104.

A measures taken to repair damage or restore resources and capabilities to their prior state following an unauthorized or unwanted activity.

"Action planned or taken to stop something from recurring."

a)

Corrective controls

b)

Preventive controls

c)

Detective controls

d)

Recovery controls

105.

Control Function Examples; Repair physical damage, Re-issue access cards, Patch a system, Terminate a process, Reboot a system, Quarantine a virus, Implement a business continuity plan or Incident response plan.

(a)  

106.

Control Function Examples; Fences, Gates, Locks, Firewall, Intrusion Prevention System (IPS), MFA solution, Antivirus Software, Hiring and Termination policies, Separation of duties, Data classification.

(a)  

107.

Control Function Examples; Closed-Circuit Television (CCTV) and Surveillance camera logs, Intrusion detection systems, Intrusion Detection System (IDS), Honeypots, Review access rights, Audit logs and Unauthorized changes.

(a)  

108.

Hardware or software mechanisms used to protect assets. "Use technology to achieve control objectives"

a)

Technical controls

b)

Administrative Controls

c)

Physical controls

109.

"Use processes to achieve control objectives"

Policies, procedures, or guidelines that define personnel or business practice with organization's security goals.

a)

Administrative controls

b)

Technical controls

c)

Physical controls

110.

Use to prevent or detect unauthorized access to physical areas, systems, or assets. "Impact the physical world"

a)

Physical controls

b)

Administrative control

c)

Technical controls

111.

Control Type Examples; Fences, Gates, Guards, Security badges and Access cards, Biometric access controls, Security lighting, CCTVs, Surveillance cameras, Motion sensors, Fire suppression, HVAC and Humidity Controls.

(a)  

112.

Control Type Examples; Employee hiring and Termination, Equipment and Internet usage, Physical access to facilities, Separation of duties, Security awareness training, Data classification and Auditing

(a)  

113.

Control Type Examples; Authentication solutions, Firewalls, Antivirus software, IDS, IPS, Constrained interfaces, Access Control Lists (ACL) and Encryption measures.

(a)  

114.

Tracks specific device settings

a)

Configuration Management

b)

Baseline

c)

Versioning

d)

Configuration Artifacts

115.

Configuration Management can track both operating system settings and the inventory of software installed on a device.

a)

True

b)

False

116.

Provide a configuration snapshot at a given point in time

a)

Baselines

b)

Versioning

c)

Configuration Management

d)

Configuration Artifacts

117.

Assigns numbers to each version

a)

Versioning

b)

Baseline

c)

Configuration Management

d)

Configuration Artifacts

118.

Diagrams serve as important (a)   artifacts

119.

Standardize Device Configurations:

a)

Naming conventions

IP addressing schemes

b)

Regulations and laws

c)

Preventive controls

Detective controls

120.

Change and configuration management help ensure a stable operating environment

a)

True

b)

False

121.

We must identify the (a)   and regulations that apply to us

122.

Many different jurisdictions may govern our operations

a)

True

b)

False

123.

Applies to EU resident information worldwide

a)

General Data Protection Regulation (GDRP)

b)

PCI DSS

124.

Security professionals should be aware of the different national, territory, and state laws that apply to their operations

a)

True

b)

False

125.

A private regulation governing credit card information

a)

PCI DSS

b)

General Data Protection Regulation (GDPR)

126.

The security policy framework includes four types of documents:

a)

Policies

Standards

Guidelines

Procedures

b)

Risk avoidance

Risk transference

Risk mitigation

Risk acceptance

c)

Canon 1

Canon 2

Canon 3

Canon 4

127.

Describe an organization's security expectations

a)

Policies

b)

Standards

c)

Guidelines

d)

Procedures

128.

What are TWO weak policy statements: (select two answers)

a)

"All sensitive information must be encrypted with AES-256 encryption."

b)

"Store all employee records in Room 225."

c)

"Sensitive information must be encrypted using approved technology."

d)

"Store all employee records in a location approved by Human Resources."

129.

What are TWO good policy statements: (select two answers)

a)

"Sensitive information must be encrypted using approved technology."

b)

"Store all employee records in a location approved by Human Resources."

c)

"All sensitive information must be encrypted with AES-256 encryption."

d)

"Store all employee records in Room 225."

130.

Describe specific security controls

a)

Standards

b)

Guidelines

c)

Procedures

d)

Policy

131.

Describe best practices

a)

Guidelines

b)

Procedures

c)

Standards

d)

Policy

132.

Step-by-step instructions

a)

Procedures

b)

Guidelines

c)

Standards

d)

Policy

133.

Compliance with policies and standards is ALWAYS (a)  

134.

Compliance with guidelines is ALWAYS (a)  

135.

Compliance with procedures can go (a)   , depending upon the organization and the specific procedure that's in question

136.

Describe authorized uses of technology

a)

Acceptable User Policies (AUP)

b)

Data handling policies

c)

Password policies

d)

Bring You Own Device (BYOD) policies

137.

Describe how to protect sensitive information

a)

Data handling policies

b)

Password policies

c)

Privacy policies

d)

Change management policies

138.

Cover password security practices

a)

Password policies

b)

Privacy policies

c)

Change management policies

d)

Data handling policies

139.

Cover use of personal devices with company information

a)

Bring Your Own Device (BYOD) policies

b)

Privacy policies

c)

Acceptable Use Policies (AUP)

d)

Change management policies

140.

Explanation of how you plan to use any personal information that you collect through your mobile app or website.

“The use of personally identifiable information”


a)

Privacy policies

b)

Change management policies

c)

Password policies

d)

Data handling policies

141.

Cover the documentation, approval, and rollback of technology changes.

a)

Change management policies

b)

Privacy policies

c)

Password policies

d)

Acceptable Use Policies (AUP)

142.

Customize policies to your (a)