wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Security Concepts

Total questions: 123

Worksheet time: 1hrs 12mins

Name
Class
Date
1.

What does the principle of confidentiality in information security ensure?

a)

Data availability

b)

Data privacy

c)

Data accessibility

d)

Data accuracy

2.

Which security principle focuses on maintaining the accuracy and trustworthiness of information?

a)

Integrity

b)

Authentication

c)

Authorization

d)

Accountability

3.

What does the principle of availability in information security ensure?

a)

Data accessibility

b)

Data accuracy

c)

Data integrity

d)

Data privacy

4.

What is the process of verifying the identity of individuals or systems to grant access based on their credentials called?

a)

Authorization

b)

Non-Repudiation

c)

Accountability

d)

Authentication

5.

What does the principle of non-repudiation in information security ensure?

a)

Data accuracy

b)

Data accessibility

c)

Data privacy

d)

Authenticity of actions or communication

6.

What is the process of identifying, assessing, and mitigating risks to protect information assets and systems called?

a)

Security Policies

b)

Security Awareness

c)

Incident Response

d)

Risk Management

7.

What is the process of developing plans and procedures to respond effectively to security incidents and breaches called?

a)

Security Policies

b)

Incident Response

c)

Security Awareness

d)

Risk Management

8.

What is the process of establishing rules and guidelines to govern security practices within an organization called?

a)

Security Awareness

b)

Security Policies

c)

Incident Response

d)

Risk Management

9.

What is the process of educating employees and users about security policies, best practices, and potential threats called?

a)

Risk Management

b)

Incident Response

c)

Security Awareness

d)

Security Policies

10.

Which security principle focuses on ensuring that information and systems are available and accessible when needed?

a)

Availability

b)

Authorization

c)

Authentication

d)

Integrity

11.

What is the process of ensuring that information and systems are available and accessible when needed called?

a)

Availability

b)

Authorization

c)

Authentication

d)

Integrity

12.

What is the process of maintaining the accuracy and trustworthiness of information called?

a)

Integrity

b)

Authentication

c)

Authorization

d)

Accountability

13.

What is the process of identifying, assessing, and mitigating risks to protect information assets and systems called?

a)

Security Policies

b)

Security Awareness

c)

Incident Response

d)

Risk Management

14.

The security of computers and users information

a)

Cybersecurity

b)

Computer virus

c)

Phishing

d)

Spam

15.

It can harm computer, control computer

a)

Crime

b)

Social network

c)

Computer Virus

d)

Cybersecurity

16.

Crimes commited by computers or network

a)

Cybersecurity

b)

Cybercrime

c)

Threat

d)

Social network

17.

People commit cybercrimes

a)

Doctors

b)

Programmers

c)

Huckers

d)

Teachers

18.

How many types of cybercrimes is there?

a)

1

b)

2

c)

3

d)

4

19.

Which is Not a type of Cybercrime?

a)

Phishing

b)

DDOS

c)

Computer virus

d)

IOS

20.

Commit

a)

Жасау/ совершать

b)

Спам

c)

Сену\ доверять

d)

жалган \ фиктивный

21.

Trust

a)

Жасау \ совершать

b)

Спам

c)

Сену\ доверять

d)

Жалган \ фиктивный

22.

Infect

a)

Жұқтыру \ заражать

b)

тарату\ распространать

c)

орналастыру\ размещать

d)

қауіп\угроза

23.

to spread

a)

тарату \ распространять

b)

урлау\ красть

c)

жуктыру\ заражать

d)

орналастыру \ размещать

24.

to post

a)

тарату \ распространять

b)

жуктыру\ заряжать

c)

қауіп \ угроза

d)

орналастыру \ размещать

25.

Update

a)

тарату \ распространять

b)

орналастыру\ размещать

c)

обновить\ жанарту

d)

жуктыру\ заражать

26.

The implementation of which security method has the greatest positive influence on security?

a)

Mature Identity & Access Management

b)

Implementation of strong password guidelines & password management

c)

Application of Secure Coding Methods

d)

Holistic People Powered Security in the organisation

27.

What is the biggest cyber security threat?

a)

The human factor

b)

Malware of any kind

c)

Unencrypted communication

d)

Theft of mobile devices

28.

What measures can be taken to minimize the attack surface for social engineering?

a)

Use of password managers

b)

Encryption of all communication and data

c)

Work exclusively in a secure environment

d)

Minimizing the communication of personal information

29.

Which password is most secure?

a)

LO4ndon7

b)

#fr41963§

c)

%27T#wbZ3

d)

LondonattheThames2019

30.

What are the consequences of a virus?

a)

It is destroying your screen.

b)

It opens your e-mail account

c)

It deletes/copies data

d)

It will help you work.

31.

Generic term for all methods used to spy on passwords.

a)

Cyber Grooming

b)

Information Diving

c)

Phishing

d)

Clustering

32.

Someone's trying to gain access to a computer network.

a)

Cyber Grooming

b)

Information Diving

c)

Pretexting

d)

Hacking

33.

A Trojan stores a file on my hard drive that redirects me to fake websites.

a)

Cyber Grooming

b)

Phishing

c)

Pharming

d)

Pretexting

34.

Generic term for methods of gaining access to passwords, etc., by researching a person's personal environment.

a)

Pharming

b)

Cyber Grooming

c)

Pretexting

d)

Social Engineering

35.

What information do cookies store?

a)

You remember the search history, what you looked at and with which email you registered.

b)

What make cookies possible?

c)

They make it possible to monitor and control a user

d)

Store data of your passwords

36.
Which of the following is an input device?
a)
speaker
b)
microphone
c)
monitor
d)
printer
37.

A strong password shouldn't contain :

a)

Capital and small letters

b)

Common marks /? ().......

c)

Numbers

d)

personal data

38.

An unskilled person who uses programs developed by others to hack.

a)

Script Kiddie

b)

Hacktivist

c)

Nation-State Hacker

d)

Cybercriminal

39.

What is one way hackers use to acquire your password?

a)

Two Factor Authentication (2FA)

b)

Thesaurus

c)

Brute force

d)

key blogger

40.

It is a form of cyber attack that attempts to make the user give up their sensitive information by disguising as a legitimate person or entity thru e-mail, messaging app, or telephone.

a)

Man-in-the-Middle Attack

b)

brute force

c)

malware attack

d)

phishing

41.

One of the biggest cyber heist in history where 81M USD was transferred to a Philippine bank.

a)

Bangladesh Bank heist

b)

South Korea Bank Heist

c)

AMEX Bank Heist

d)

India Central Bank heist

42.

Lack of awareness and ____ make the perfect set up for a successful cyber attack or cybercrime.

a)

panicking

b)

lack of awareness

c)

rushing

d)

lack of technology

43.

This is the psychological manipulation of people into performing actions or divulging confidential information.

a)

social engineering

b)

man-in-the-middle attack

c)

social disclosure

d)

eavesdropping attack

44.

A cyber attack in which the data on a victim's computer is locked, typically by encryption, and payment is demanded before the data is decrypted and access returned to the victim.

a)

DDoS Attack

b)

kidnap for ransom

c)

ransomware

d)

data hack

45.

Aside from PNP Anti-Cybercrime Group, what is the other law enforcement agency mandated to handle cybercrime cases?

a)

CICC

b)

DICT

c)

DOJ Office of Cybercrime

d)

NBI Cybercrime Division

46.

______ is a deliberate exploitation of computer systems, technology-dependent enterprises, and networks.

a)

cyber attack

b)

cybercrime

c)

cyber threat

d)

cyber incidence

47.

The best way to back-up your files.

a)

cloud

b)

external hard drive

c)

123 backup plan

d)

321 backup rule

48.

The collection of tools, policies, security concepts, etc. to protect the cyber environment.

a)

information security

b)

data security

c)

cybersecurity

d)

cyber hygiene

49.

Criminals stealing data from online accounts is

a)

Identity Theft

b)

Normality

50.

Trial and Error method of hacking passwords is called

a)

Brute Force Attack

b)

Malware Attack

51.

Unknown programs that startup when you turn on your computer is because of

a)

Computer Virus

b)

System Issue

52.

Stealing of data is Cyber Crime

a)

False

b)

True

53.

FTC stands for

a)

Federal Trade Commission

b)

Federal Telecom Community

54.

________ involves sending an innocent-looking e-mail or web site designed to fool people into revealing confidential information.

a)

Phishing

b)

Dumpster Diving

55.

A "Good" passwords should have a

a)

Minimum number of characters, include non-alphabetical characters, and numbers

b)

Common word

56.

It is used to refer to the security offered through on-line services to protect your online information.

a)

Cyber Security

b)

Human Security

c)

Social Security

d)

Network Security

57.

It is a combining form relating to information technology, the Internet, and virtual reality.

a)

Cyber

b)

Hyper

c)

Alter

d)

Booster

58.

Which of the following is not a major security problem?

a)

Hacker

b)

Hacker

c)

Malware

d)

Booster

59.

It is a “program that is loaded onto your computer without your knowledge and runs against your wishes.

a)

Hacker

b)

Hardware

c)

Booster

d)

Virus

60.

Is a person who breaks into computers, usually by gaining access to administrative controls.

a)

Hacker

b)

User

c)

Gamer

d)

Developer

61.

Which among the following is not a type of hacker?

a)

White Hat Hacker

b)

Grey Hat Hacker

c)

Black Hat Hacker

d)

Blue Hat Hacker

62.

It is any software that infects and damages a computer system without the owner's knowledge or permission.

a)

Hacker

b)

Hardware

c)

Malware

d)

Spyware

63.

These are email viruses that can duplicate themselves,

steal information, or harm the computer system.

a)

Worms

b)

Trojan Horses

c)

Rootkits

d)

Spyware

64.

These are attacks by hackers that are able to determine passwords or find passwords to different protected electronic areas and social network sites.

a)

Password Attacks

b)

Trojan Horses

c)

Viruses

d)

Spywares

65.

The word "malware" comes from the term?

a)

Malfunction Software

b)

Malicious Software

c)

Malcontent Software

d)

Maltreated Software

66.

Anny recently implemented an intrusion prevention system designed to block common network attacks from affecting his organization. What type of risk management strategy is Anny pursuing?

a)

Risk Acceptance

b)

Risk Avoidance

c)

Risk Mitigation

d)

Risk Transference

67.

Which of the following principles expects an individual to behave reasonably under any given circumstance?

a)

Due Diligence

b)

Separation of Duties

c)

Due Care

d)

Least Privilege

68.

What type of malware is characterized by spreading from system to system under its own power by exploiting vulnerabilities that do not require user intervention?

a)

Trojan Horse

b)

Virus

c)

Logic Bomb

d)

Worm

69.

Which one of the following security programs is designed to establish a minimum standard common denominator of security understanding?

a)

Training

b)

Education

c)

Indoctrination

d)

Awareness

70.

Which one of the following is an example of physical infrastructure hardening?

a)

Antivirus Software

b)

Hardware-based Network Firewall

c)

Two Factor-Authentication

d)

Fire Suppression System

71.

Which information security goal is impacted when an organization experiences a DoS or DDoS attack?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Denial

72.

What is the best way to provide accountability for the use of identities?

a)

Logging

b)

Authorization

c)

Digital Signatures

d)

Type 1 Authentication

73.

Management support is critical to the success of a business continuity plan. Which of the following should be provided to the management to obtain their support?

a)

Business Case

b)

Business Impact Analysis

c)

Risk Analysis

d)

Threat Report

74.

Which of the following is a critical first step in disaster recovery and contingency planning?

a)

Plan Testing and Drills

b)

Complete a Business Impact Analysis

c)

Determine Offsite Backup Facility Alternatives

d)

Organize and Create Relevant Documentation

75.

What type of encryption is typically used for data at rest?

a)

Asymmetric Encryption

b)

Symmetric Encryption

c)

DES

d)

OTP

76.

If Harry's organization requires him to log in with his username, a PIN, a password, and a fingerprint scan, how many distinct types of factors has he used?

a)

One

b)

Two

c)

Three

d)

Four

77.

Mr. A has worked in human relations, payroll, and customer service roles in his company over the past few years. What type of process should his company perform to ensure that he has appropriate rights?

a)

Reprovisioning

b)

Account Review

c)

Privilege Creep

d)

Account Revocation

78.

Which one of the following cryptographic goals protects against the risks posed when a device is lost or stolen?

a)

Non-repudiation

b)

Authentication

c)

Integrity

d)

Confidentiality

79.

All of the following are ways of addressing risk, except:

a)

Acceptance

b)

Reversal

c)

Mitigation

d)

Transfer

80.

Which of the following should include the process of hardening a device?

a)

Encryption the OS

b)

Updating and Patching the System

c)

Using Video Cameras

d)

Performing through Personal Background Checks

81.

The cloud deployment model that features ownership by a cloud provider, with services offered to anyone who wants to subscribe, is known as:

a)

Private

b)

Public

c)

Hybrid

d)

Latent

82.

It is important to classify and determine the relative sensitivity of assets to ensure that:

a)

The cost of protection is in proportion to the sensitivity

b)

Highly sensitive assets are protected

c)

The cost of controls is minimized

d)

Countermeasures are proportional to the risk

83.

What is the most important factor in the successful implementation of an enterprisewide information security program?

a)

Realistic Budgets Estimates

b)

Security Awareness

c)

Support of Senior Management

d)

Recalculation of the work factor

84.

Which of the following is the best approach to obtain senior management commitment to the information security program?

a)

Describe the reduction of the risk

b)

Present the emerging threat environment

c)

Benchmark against other enterprises

d)

Demonstrate the alignment of the program to business objectives

85.

The primary focus of the change control process is to ensure that the changes are:

a)

Authorized

b)

Applied

c)

Documented

d)

Tested

86.

What is a computer hacker?

a)

A virus that invades your computer and causes it to not work

b)

A person who sends lots of e-mails to people asking for money

c)

A person who uses a computer to illegally breaks into your computer and take your information

d)

A person who cuts or hacks at something

87.

What is cybersecurity?

a)

the state of being protected against the criminal or unauthorized use of electronic data,

b)

Security against breaking into your house

c)

Top secret Government security

88.

What is Phishing?

a)

Phish is a made up word

b)

Fishing for pirahnas and perch

c)

the fraudulent practice of sending emails that seem to be to be from reputable companies in order to convince individuals to reveal personal information, such as passwords and credit card numbers.

d)

The practice of breaking into a persons computer to steal their data by using a virus

89.

What is a mobile browser?

a)

a web browser built to use on mobile devices like mobile phones

b)

a search engine

c)

a person who searches for information on the Internet

90.

What is electronic data?

a)

Data that is electric

b)

answers to questions you ask on the Internet

c)

data made up of 1's and 0's

d)

data that is exchanged via electronic communication lines · digital data

91.

What is Social Engineering?

a)

manipulation of people on the Internet into giving away confidential information.

b)

Mining for peoples lost jewelry

c)

A type of engineering where you build houses for groups of people

92.

What is a password?

a)

When you pass a word around until someone gets the meaning right

b)

a secret word or phrase that must be used to gain admission to your online account

c)

A type of vocabulary football

93.

What is computer malware?

a)

A malicious attack using the mail

b)

software that is specifically designed to disrupt, damage, or gain unauthorized access to a computer system.

c)

Computer software that is made to track your movements

94.

What is a cyber attack?

a)

an attempt by hackers to damage or destroy a computer network or system.

b)

when someone shoots your computer

c)

an attack on cybers

d)

when someone robs an atm machine

95.

What is ransomware?

a)

A type of threat that holds onto your computer until you pay your fines

b)

When someone tells you what you have to wear

c)

a type of malicious software designed to block access to a computer system until a sum of money is paid.

96.

What is a computer backup?

a)

When your computer is operating very slowly

b)

copies of the original files that you have on your laptop, desktop, or external drive.

c)

When you save your original files onto your desktop

97.

What is a computer virus?

a)

When a hacker breaks into your computer system

b)

A sickness that your computer can pas on to you

c)

When your computer is infected with the flu

d)

a piece of code which is capable of copying itself and typically has a detrimental effect, such as corrupting the system or destroying data.

98.

What is encryption?

a)

A person who tricks you into giving your password

b)

converting information or data into a code to prevent unauthorized access.

c)

To upload your personal data to the cloud

d)

When there is a security breach in your data

99.

Should you share your personal information with strangers?

a)

Yes

b)

No

100.

If somebody asks you to give your password, what should you not do?

a)

Give them the password straight away

b)

Close the mail/page

c)

Call a parent

d)

Report and Block them

101.

When you receive an e-mail that has an attachment from a stranger, you should:

a)

Read it carefully and then decide.

b)

Open it straight away

102.

You should keep different and strong passwords for every site.

a)

True

b)

False

103.

If you see a site that is not secure you should:

a)

Leave the site

b)

Stay on the site

c)

Stay on the site but switch of your device

d)

Eat the phone

104.

It can harm your computer and control it

a)

Crime

b)

Social network

c)

Computer Virus

d)

Cybersecurity

105.

Why do people carry out cyber attacks?

a)

Financial Gain

b)

Fun/Challenge

c)

To disrupt the business

d)

Personal grudge

106.

Hacking is illegal

a)

True

b)

False

107.

What does unauthorised mean?

a)

Not allowed

b)

Allowed

108.

What is hacking?

a)

Accessing a computer system without permission

b)

Accessing a computer system with permission

109.

Access a computer without permission (hacking) is in breach of the...

a)

Communications Act

b)

Data Protection Act

c)

Computer Misuse Act

110.

One of the weakest points of computer systems are...

a)

Software that has not been updated

b)

Badly configured systems

c)

Users who choose weak passwords

111.

What is Two Factor Authentication?

a)

A security feature that sends a text to your phone when you try to login to a website with a code to use

b)

Asks you further security questions when you login from an unusual location

c)

A way of checking that the person logging in is the real person

112.

What should you do to help defend yourself from hackers?

a)

Use passwords with more than 6 characters

b)

Use an anti-virus program and keep it updated

c)

Keep your software up to date

d)

Use different passwords for each website you use

e)

Tell someone else your password in case you forget it

113.

What are the aims of a phishing e-mail?

a)

Trick you into thinking it is from an official source

b)

Get you to click on a link without thinking

c)

Find out your address

d)

Deactivate your anti-virus

114.

How can you spot a phishing e-mail?

a)

Correct spelling

b)

Seems too good to be true

c)

The From address does not match the sender

d)

The To field is empty

115.

How can you spot a phishing e-mail?

a)

Incorrect spelling

b)

The message is designed to make you panic and act quickly

c)

There is no personal information included in the e-mail

d)

They mention your e-mail address in the message

116.

What is Malware?

a)

Software that does bad things to your computer

b)

Software that keeps your computer safe

117.

This type of malware spreads by itself over a computer network, sometimes for quite a while without anyone noticing.

a)

Virus

b)

Trojan

c)

Worm

118.

This type of malware disguises itself as something legitimate so you download and run it without realising.

a)

Virus

b)

Trojan

c)

Worm

119.

This type of malware spreads through human interaction i.e. someone has to click it or download it.

a)

Virus

b)

Trojan

c)

Worm

120.

How can you remove malware from your computer?

a)

Ant-malware software

b)

Word processor

c)

Encryption

d)

Firewall

121.

Malware spreads through the computer network at school and infects all the connected machines. Before anyone realises, it's too late.

a)

Virus

b)

Trojan

c)

Worm

122.

Billy downloads a program to get him free Fortnite skins and it actually steals his login instead.

a)

Virus

b)

Trojan

c)

Worm

123.

Faye clicks a link to download a program that then wipes all the data on her computer

a)

Virus

b)

Trojan

c)

Worm