wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

isc2 sample questions

Total questions: 14

Worksheet time: 7mins

Name
Class
Date
1.

What is the primary goal of the risk management process?

a)
Ignore the probability or impact of unfortunate events
b)
Maximize the probability of unfortunate events
c)
Outsource the risk management process
d)

To identify the Assess and mitigate risks

2.

Which module of security principles focuses on establishing guidelines for security behavior within an organization?

a)

Module 1: Understand the Security Concepts of Information Assurance

b)

Module 2: Understand the Risk Management Process

c)

Module 3: Understand Security Controls

d)

Module 5: Understand ISC2 Code of Ethics

3.

What is the primary focus of the module that involves the identification, analysis, and prioritization of incidents in incident response?

a)

Module 1: Understand Incident Response

b)

Module 2: Understand Business Continuity

c)

Module 3: Understand Disaster Recovery

4.

What is the primary purpose of physical access controls?

a)

To restrict access to computer systems and networks

b)

To secure physical locations and assets

c)

To encrypt data transmissions

d)

To prevent malware infections

5.

Which of the following is NOT one of the CIA triad principles of information security?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Reliability

6.

What is the first step in the risk management process?

a)

Implement risk mitigation strategies.

b)

Identify and assess risks

c)

Monitor and review risks.

d)

Develop risk acceptance criteria.

7.

Which type of control is most effective in preventing unauthorized physical access to a data center?

a)

Preventive control

b)

Detective control

c)

Corrective control

d)

Recovery control

8.

What is the primary objective of an organization's security policy?

a)

To define network architecture.

b)

To outline ethical guidelines for employees.

c)

To establish clear expectations for security practices.

d)

To specify incident response procedures.

9.

A security professional discovers a critical vulnerability in a client's system. According to the ISC2 code of ethics, what is the MOST appropriate action?

a)

Inform the public immediately.

b)

Ignore the vulnerability if it doesn't affect their own systems.

c)

Report the vulnerability to the client responsibly.

d)

Exploit the vulnerability for personal gain.

10.

Which of the following is NOT a typical component of a disaster recovery plan?

a)

Data backup and restoration procedures

b)

Communication protocols

c)

Employee training and testing

d)

Marketing strategies

11.

What is the key difference between business continuity and disaster recovery?

a)

Business continuity focuses on data recovery, while disaster recovery addresses physical infrastructure.

b)

Business continuity is proactive, while disaster recovery is reactive.

c)

Business continuity focuses on technology, while disaster recovery focuses on personnel.

d)

There is no significant difference.

12.

The primary objective of an incident response plan is to

a)

Assign blame for the incident

b)

Contain the incident and minimize damage

c)

Train employees on incident prevention

d)

Update security policies

13.

What is the primary purpose of the ISC2 Code of Ethics?

a)

Define security standards

b)

Guide professional conduct

c)

Outline certification requirements

d)

Specify security controls

14.

Which type of control aims to prevent unauthorized access to information?

a)

Preventive

b)

Detective

c)

Corrective

d)

Recovery