wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

dig infra 4a

Total questions: 105

Worksheet time: 54mins

Name
Class
Date
1.

What is the purpose of the disaster recovery policy?

a)

Preventing cybersecurity incidents from occurring.

b)

Ensuring damage is quickly recovered from after an incident.

c)

Performing regular backups of all data.

d)

Analysing the cause of attacks and identifying improvements to procedures.

2.

What kind of threats can disaster recovery policies help to protect us from being impacted by?

a)

Natural disasters

b)

Malware

c)

Hardware failure

d)

All of the above.

3.

A “hot site” is a location that a business can instantly switch business operation over to after a disaster.

a)

True

b)

False

4.

Which of the following would be included in a disaster recovery policy?


Choose two options.

a)

Establishing the severity of the attack

b)

Definition of the backup process

c)

Analysis of the cause of the disaster

d)

Timeline for data recovery

5.

What action to take after an attack is described below?


Establish the cause of the attack and mistakes made and update policies and procedures.

a)

Respond

b)

Manage

c)

Recover

d)

Investigate

e)

Analyse

6.

What action to take after an attack is described below?


Identify when and why the attack happened and establish the severity of the attack.

a)

Respond

b)

Manage

c)

Recover

d)

Investigate

e)

Analyse

7.

What action to take after an attack is described below?


Implement the disaster recovery policy.

a)

Respond

b)

Manage

c)

Recover

d)

Investigate

e)

Analyse

8.

What action to take after an attack is described below?


Isolate & contain the attack and use appropriate measures to resume services.

a)

Respond

b)

Manage

c)

Recover

d)

Investigate

e)

Analyse

9.

What action to take after an attack is described below?


Inform the relevant stakeholders and authorities.

a)

Respond

b)

Manage

c)

Recover

d)

Investigate

e)

Analyse

10.

Which of the following may be common uses of location-based data?


Choose two options.

a)

Showing country-specific deals.

b)

Providing analytics on how you use a website.

c)

Planning a route on a map app.

d)

Analysing buying habits in a store.

11.

Which of the following are uses of cookies?


Choose two options.

a)

Storing data between website sessions.

b)

Showing you where to find restaurants local to you.

c)

Identifying trends in product sales.

d)

Collecting analytics, like how long you spend on a web page.

12.

Which of the following are benefits of using shared data?


Choose two options.

a)

Always accurate and safe.

b)

Is automatically protected by the data protection act.

c)

Helps businesses to better target advertising.

d)

Helps businesses make better decisions.

13.

Which of the following are drawbacks of using shared data?


Choose two options.

a)

Causes bad decisions to be made

b)

Could be fined under the DPA.

c)

Could be stolen & misused by malicious users.

d)

Is more costly than gathering the data manually.

14.

What legislation protects the use of personal data shared with businesses?

a)

Data Protection Act (1998)

b)

Data Protection Act (2018)

c)

Computer Misuse Act (1990)

d)

Computer Misuse Act (1998)

15.

Businesses have an ethical responsibility to protect shared data as otherwise they may be fined under the Data Protection Act.

a)

True

b)

False

16.

Which is a strong password?

a)

Soofmu1.

b)

123456

17.

Passwords should include? (Choose all that apply)

a)

Colour

b)

Letters

c)

Numbers

d)

Symbols

18.

After using a public computer (like in a library), you should stay logged in to everything.

a)

True

b)

False

19.

What is the role of security policies. (Choose all that apply)

a)

To allow staff to work remotely

b)

Outline how staff are expected to behave

c)

List staff responsibilities

d)

Plan for what should happen in a disaster

20.

Which of the following are features of a disaster recovery plan?

a)

Who has responsibility for tasks

b)

A list of passwords for the system

c)

Identifying potential risks

d)

What staff should and should not do.

21.

Identify the features of an AUP (Acceptable Use Policy) . (Choose all that apply)

a)

It's purpose is to reduce potential internal threats to the organisations information.

b)

It applies to all the employees in an organisation and any others who may use technology belonging to the organisations.

c)

It outlines steps to take to in the event of a disaster.

d)

It covers acceptable use of all assets eg Data, Hardware and Software

22.

Identify the behaviours that would be considered acceptable in a AUP.

a)

Download non-work related materials, software, music and video files.

b)

Use email in a professional and courteous manner

c)

Make negative comments about the organisation on social media.

d)

Report any technical issues to the technical support department

23.

Identify the behaviours that would be considered not acceptable in a AUP.

a)

Keep passwords confidential

b)

Visit inappropriate websites

c)

Make negative comments about the organisation on social media.

d)

Use equipment with care and respect.

24.

Identify examples of security policies. (Choose all that apply)

a)

Responsible use policies

b)

Disaster Recovery Policy

c)

Life Insurance policy

d)

System Security policy

25.

The steps an organisation should take after an attack include: Investigate, Respond, Manage, Recover. However one step is missing which is it?

a)

Report

b)

Disconnect

c)

Disinfect

d)

Analyse

26.

What is contingency planning?

a)

Deletion of data in information security assets

b)

Preparation to detect and react to threats to information security threats

c)

Destruction of information security assets

27.

Which of the following the components of contingency planning?

a)

Business Impact Analysis

b)

Incident Response Plan

c)

Identification Planning

d)

Disaster Recovery Plan

28.

Who are responsible in conducting Business Impact Analysis (BIA)?

a)

Business Continuity (BC) Team

b)

Incident Response (IR) Team

c)

CP Management Team

d)

Disaster Recovery (DR) Team

29.

"Set and start operations after disaster"

Which team is responsible in performing the above task?

a)

Business Continuity Team

b)

Incident Response Team

c)

Disaster Recovery Team

d)

CP Management Team

30.

How many components are there in contingency planning?

a)

3

b)

4

c)

5

d)

6

31.

How many stages are there in contingency planning?

a)

5

b)

6

c)

7

d)

8

32.

What is the duty of Incident Response Team?

a)

Detects, evaluates, and responds to incidents

b)

Responsible for re-establishing operations at the primary business site

c)

Responsible for setting up and starting off-site operations after an incident or a disaster

33.

What is the duty of Business Continuity Team?

a)

Detects, evaluates, and responds to incidents

b)

Responsible for re-establishing operations at the primary business site

c)

Responsible for setting up and starting off-site operations after an incident or a disaster

34.

What is the duty of Disaster Recovery Team?

a)

Detects, evaluates, and responds to incidents

b)

Responsible for re-establishing operations at the primary business site

c)

Responsible for setting up and starting off-site operations after an incident or a disaster

35.

What is crisis management?

a)

Steps to create problems and disaster

b)

Step to deal with people during and after a disaster

c)

Steps to create haywire

36.

What is the main objective of Business Continuity Planning (BCP) in an organization?

a)

To ensure the highest profitability in all market conditions

b)

To assess risks to organizational processes and develop policies to minimize the impact of these risks

c)

To provide training to new employees about the organizational structure

d)

To focus solely on the recovery of IT infrastructure after a disaster

37.

What is one of the primary responsibilities of individuals in charge of business continuity planning (BCP)?

a)

To immediately invest in new technology that supports remote work.

b)

To perform an analysis of the business organization to identify all departments and individuals who have a stake in the BCP process.

c)

To prioritize marketing strategies to communicate the BCP to external stakeholders.

d)

To focus exclusively on the IT department as they are typically the most affected in crisis situations.

38.

In the initial stages of business continuity planning, why is it crucial for planners to identify all departments and individuals with a stake in the BCP process?

a)

To reduce the overall budget allocated for the BCP by focusing only on key departments.

b)

To ensure comprehensive coverage and collaboration across the organization, recognizing that different departments may have unique requirements and contributions.

c)

To single out departments that are less important to the continuity plan and reduce their operational capacity.

d)

To focus primarily on external stakeholders and their expectations from the BCP.

39.

Why is the identification process of departments and individuals critical in the initial stages of Business Continuity Planning (BCP)?

a)

Because it is a regulatory requirement for all businesses to list their departments annually.

b)

Because it ensures that the most technologically advanced departments are prioritized in the plan.

c)

Because it provides the groundwork for identifying potential BCP team members and builds the foundation for the remainder of the BCP process.

d)

Because it is primarily a formality to demonstrate the organization's commitment to external stakeholders.

40.

What is a critical flaw in the approach to Business Continuity Planning (BCP) where only the IT and/or security departments are involved, with no input from other operational or support departments?

a)

It creates a plan that may be unknown to other departments until a disaster is imminent or occurs, potentially leading to inadequate preparation and response.

b)

It leads to an overemphasis on financial investment in IT infrastructure.

c)

It results in a BCP that is too comprehensive and difficult to implement.

d)

It causes unnecessary training and drills that could disrupt the daily operations of the business.

41.

Once the organizational review is validated in the Business Continuity Planning (BCP) process, what is the next critical step for the BCP team?

a)

To immediately implement the most cost-effective solutions regardless of their alignment with the organizational review.

b)

To conduct a comprehensive assessment of the resources required by the BCP effort, including personnel, technology, and financial assets.

c)

To focus solely on external partnerships and outsourcing strategies for crisis management.

d)

To disband the organizational review team and hand over responsibilities to the IT department.

42.

Which of the following best describes a significant risk in the approach to Business Continuity Planning (BCP) where the responsibility is confined exclusively to the IT and/or security departments, without the involvement of other key operational or support departments?

a)

It may lead to a lack of technical expertise in the BCP, as IT departments are often not equipped with the necessary knowledge for comprehensive planning.

b)

The involvement of only IT and/or security departments might lead to a faster and more efficient planning process, thereby increasing the overall effectiveness of the BCP.

c)

The BCP might become too IT-centric, leading to excessive financial expenditure on technological solutions while neglecting other affordable options.

d)

The plan might focus solely on IT recovery and overlook critical aspects like supply chain management, human resources, and customer relations, potentially leading to a fragmented and ineffective response in a crisis.

43.

Why is the use of a proven methodology crucial in the development of a resilient business continuity plan (BCP)?

a)

To ensure the plan is focused exclusively on technology recovery rather than the overall business processes.

b)

To guarantee a higher financial profit during the first quarter after implementing the plan.

c)

To follow a structured, systematic approach that ensures all critical aspects of business continuity are addressed effectively.

d)

To comply with international laws regarding business operations, regardless of the specific needs of the organization.

44.

What is the overall goal of Business Continuity Planning (BCP) in an organization?

a)

To ensure the organization always remains technologically advanced compared to competitors.

b)

To delegate emergency response tasks to external agencies without internal coordination.

c)

To solely focus on the prevention of potential risks without planning for response and recovery.

d)

To provide a quick, calm, and efficient response in the event of an emergency, and to enhance the organization's ability to promptly recover from a disruptive event while maintaining mission-critical tasks.

45.

What is the primary goal of Business Continuity Planning (BCP) in an organization?

a)

To ensure that the organization remains the market leader in its industry

b)

To reduce the organization's operational costs in day-to-day activities

c)

To maintain continuous operation of the business with minimal impact in the event of an emergency through a combination of policies, procedures, and processes

d)

To focus on employee performance improvement and skill development

46.

What is the purpose of a backup and recovery plan in IT disaster recovery?

a)

To slow down the recovery process

b)

To ensure that critical data and systems can be restored in the event of a disaster or data loss.

c)

To increase the risk of data loss

d)

To create unnecessary work for IT staff

47.

List and explain three common data backup methods used in IT disaster recovery.

a)

Cloud backup, local backup, and external backup

b)

Physical backup, virtual backup, and remote backup

c)

Full backup, incremental backup, and differential backup

d)

Manual backup, automatic backup, and scheduled backup

48.

Why is disaster recovery testing important in IT?

a)

To test the speed of the internet connection

b)

To practice using new software

c)

To see if the office building is up to code

d)

To ensure that systems and processes are capable of being restored in the event of a disaster or outage.

49.

What are the advantages of using cloud-based disaster recovery for IT systems?

a)

Limited storage capacity, high cost, and restricted access

b)

Inflexible, unreliable, and difficult to integrate with existing systems

c)

Advantages of using cloud-based disaster recovery include easy scalability, cost-effectiveness, and accessibility from anywhere.

d)

Difficult to implement, slow performance, and lack of security

50.

Explain the difference between hot, warm, and cold IT disaster recovery strategies.

a)

The hot IT disaster recovery strategy involves having backup systems that need to be fully configured before use, the warm strategy involves maintaining fully operational duplicate systems, and the cold strategy involves having partially operational duplicate systems.

b)

The hot IT disaster recovery strategy involves using spicy technology, the warm strategy involves using lukewarm technology, and the cold strategy involves using frozen technology.

c)

The hot IT disaster recovery strategy involves using outdated technology, the warm strategy involves using cutting-edge technology, and the cold strategy involves using average technology.

d)

The hot IT disaster recovery strategy involves maintaining fully operational duplicate systems, the warm strategy involves having partially operational duplicate systems, and the cold strategy involves having backup systems that need to be fully configured before use.

51.

What are the key components of a comprehensive backup and recovery plan?

a)

Regular data backups, offsite storage, testing of backups, documentation of recovery procedures, and a clear communication plan

b)

Storing all backups on the same server

c)

Using outdated software and hardware

d)

Not having a clear communication plan

52.

Discuss the concept of incremental backup in data backup methods.

a)

Backing up only the data that has changed since the last backup

b)

Not backing up any data at all

c)

Only backing up the most important files

d)

Backing up the entire system every time

53.

What are the challenges of implementing disaster recovery testing in IT?

a)

Lack of interest from IT staff

b)

Complexity of IT systems, specialized skills and resources, potential disruption to normal operations

c)

Minimal impact on business operations

d)

Easily accessible resources

54.

How does cloud-based disaster recovery provide scalability for IT systems?

a)

It provides scalability by limiting the capacity of IT systems

b)

It provides scalability by allowing IT systems to easily scale up or down based on the organization's needs.

c)

It provides scalability by increasing the complexity of IT systems

d)

It provides scalability by reducing the flexibility of IT systems

55.

Compare and contrast the pros and cons of on-site vs off-site data backup methods in IT disaster recovery.

a)

The number of employees in the IT department

b)

The color of the backup server

c)

The brand of the backup software

d)

The correct answer for the question is to analyze the cost, accessibility, security, and reliability of on-site vs off-site data backup methods in IT disaster recovery.

56.

What is the purpose of a backup and recovery plan in IT disaster recovery?

a)

To slow down the recovery process

b)

To ensure that critical data and systems can be restored in the event of a disaster or data loss.

c)

To increase the risk of data loss

d)

To create unnecessary work for IT staff

57.

List and explain three common data backup methods used in IT disaster recovery.

a)

Cloud backup, local backup, and external backup

b)

Physical backup, virtual backup, and remote backup

c)

Full backup, incremental backup, and differential backup

d)

Manual backup, automatic backup, and scheduled backup

58.

Why is disaster recovery testing important in IT?

a)

To test the speed of the internet connection

b)

To practice using new software

c)

To see if the office building is up to code

d)

To ensure that systems and processes are capable of being restored in the event of a disaster or outage.

59.

What are the advantages of using cloud-based disaster recovery for IT systems?

a)

Limited storage capacity, high cost, and restricted access

b)

Inflexible, unreliable, and difficult to integrate with existing systems

c)

Advantages of using cloud-based disaster recovery include easy scalability, cost-effectiveness, and accessibility from anywhere.

d)

Difficult to implement, slow performance, and lack of security

60.

Explain the difference between hot, warm, and cold IT disaster recovery strategies.

a)

The hot IT disaster recovery strategy involves having backup systems that need to be fully configured before use, the warm strategy involves maintaining fully operational duplicate systems, and the cold strategy involves having partially operational duplicate systems.

b)

The hot IT disaster recovery strategy involves using spicy technology, the warm strategy involves using lukewarm technology, and the cold strategy involves using frozen technology.

c)

The hot IT disaster recovery strategy involves using outdated technology, the warm strategy involves using cutting-edge technology, and the cold strategy involves using average technology.

d)

The hot IT disaster recovery strategy involves maintaining fully operational duplicate systems, the warm strategy involves having partially operational duplicate systems, and the cold strategy involves having backup systems that need to be fully configured before use.

61.

What are the key components of a comprehensive backup and recovery plan?

a)

Regular data backups, offsite storage, testing of backups, documentation of recovery procedures, and a clear communication plan

b)

Storing all backups on the same server

c)

Using outdated software and hardware

d)

Not having a clear communication plan

62.

Discuss the concept of incremental backup in data backup methods.

a)

Backing up only the data that has changed since the last backup

b)

Not backing up any data at all

c)

Only backing up the most important files

d)

Backing up the entire system every time

63.

What are the challenges of implementing disaster recovery testing in IT?

a)

Lack of interest from IT staff

b)

Complexity of IT systems, specialized skills and resources, potential disruption to normal operations

c)

Minimal impact on business operations

d)

Easily accessible resources

64.

How does cloud-based disaster recovery provide scalability for IT systems?

a)

It provides scalability by limiting the capacity of IT systems

b)

It provides scalability by allowing IT systems to easily scale up or down based on the organization's needs.

c)

It provides scalability by increasing the complexity of IT systems

d)

It provides scalability by reducing the flexibility of IT systems

65.

Compare and contrast the pros and cons of on-site vs off-site data backup methods in IT disaster recovery.

a)

The number of employees in the IT department

b)

The color of the backup server

c)

The brand of the backup software

d)

The correct answer for the question is to analyze the cost, accessibility, security, and reliability of on-site vs off-site data backup methods in IT disaster recovery.

66.
IT _____________ is a process that provides assurance for IT and IS and helps to mitigate risks associated with use of technology.
a)
control
b)
governance
c)
risk management
d)
review
67.
An internal audit is typically conducted by auditors who work for the organization, but this task may be outsourced to other organizations.
a)
True
b)
False
68.
Which of the following components is not part of IT governance?
a)
control planning
b)
security assessment
c)
managing incident response
d)
control development
69.
Which of the following components is not part of IT compliance?
a)
IT audit
b)
security assessment
c)
control development
d)
IT compliance assessment
70.
An audit _____________ outlines the overall authority, scope and responsibilities of the audit function.
a)
exit report
b)
comprehensive report
c)
letter of intent
d)
charter
71.
Fieldwork is part of the ______________ process
a)
assessment
b)
reporting
c)
follow-up
d)
planning
72.
The audit response verification can be obtained at the _______________ stage of an IT audit.
a)
assessment
b)
report
c)
follow-up
d)
planning
73.
The scope of an IT audit often varies, but can involve any combination of the following:
a)
organizational, compliance, application and social
b)
organizational, compliance, application and technical
c)
regional, compliance, application and technical
d)
organizational, compliance, systems and technical
74.
Which of the following is an IT security audit program goal?
a)
 Provide an objective and independent review of an organization’s policies, information systems and controls.
b)
 Provide reasonable assurance that appropriate and effective IT controls are in place.
c)
 Provide audit recommendations for both corrective actions and improvement to controls.
d)
All of the answers are correct.
75.
A threat profile refers to:
a)
what is the likelihood of the threats happening.
b)
what threats or risks will affect the asset.
c)
what impact or effect would the loss of the asset have on the operation of the organization or its personnel.
d)
All of the above are correct.
76.
The diagram above refers to:
a)
how audit goals are determined.
b)
how audit reviews are analysed.
c)
how audit reports are created.
d)
how an audit is conducted.
77.
In an IT audit, the exit meeting:
a)
discusses preliminary findings.
b)
determines all problems found.
c)
is where the chief auditor reads his/her final audit report.
d)
already determines the answers from auditees beforehand.
78.
The IS auditor must use instinct when deciding which findings to present to various levels of management.
a)
True
b)
False
79.
The IS auditor should always judge which findings are material to various levels of management and should report them accordingly.
a)
True
b)
False
80.
Audit documentation includes all of the following EXCEPT:
a)
audit program
b)
audit steps performed
c)
audit charter
d)
audit recommendations
81.

One characteristic of employee fraud is that the fraud ...............

a)

is perpetrated at a level to which internal controls do not apply

b)

involves misstating financial statements

c)

involves the direct conversion of cash or other assets tp the employee's personal benefit

d)

involves misappropriating assets in a series of complex transactions involving third parties

82.

Which of the following is not a feature of employee fraud?

a)

Concealing the crime to avoid detection

b)

Stealing something of value

c)

Misstating financial statements

d)

Converting the asset to a usable form

83.

A mailroom clerk opens envelopes containing checks and remittance advice. The clerk steals a check, cashes it, and destroys the remittance advice. What type of fraud is this?

a)

Skimming

b)

Pay-and-return-fraud

c)

Cash larceny

d)

Lapping

84.

The purchasing agent for a company XYZ places an order with a false vendor, which is himself. He then purchases the needed items from a legitimate vendor and sells them to the Company XYZ at higher that market price. What type of fraud is this?

a)

Lapping

b)

Pass through fraud

c)

Shell company

d)

Kiting

85.

For an action to be called fraudulent, all of the following conditions are required EXCEPT .........

a)

material fact

b)

false representation

c)

intent to deceive

d)

injury loss

e)

all of them are conditions

86.

What is computer forensics?

a)

It is an attempt to expose, alter, destabilize, destroy, remove to gain unauthorized access or use an asset.

b)

It is the discipline that combines the elements of law and computer science to collect and analyze data from computer Systems, network, Wireless communications and storage devices in a way that is admisible as evidence in a court of law.

87.

What are the examples of latent data? choose 3.

a)

Belkasoft Live RAM capturer

b)

Information that is in the computer's storage but is not easily mentioned in the file allocation tables.

c)

Data that has been deliberately removed.

d)

Information that the operating System or commonly used software Application cannot easily see.

88.

1. A _______ has occurred, collecting all relevant evidence is of the utmost importance in answering the questions described above.

a)

file headers.

b)

forensic investigator.

c)

cyber attack.

89.

What are the main types of computer forensics?

a)

Of operating Systems

b)

Of security

c)

Of network.

d)

On the cloud.

e)

On Mobile devices

90.

It is the process of retrieving useful Information from the computer or mobile device in questions.

a)

Of network

b)

On the cloud

c)

Of operating Systems

91.

It aims to retrieve digital evidence or relevant data from a mobile device in a way that preserves the evidence in a sound forensic condition.

a)

On the cloud

b)

Of operating Systems

c)

On mobile devices

92.

It refers to the collection, monitoring, and analysis of network activities to discover the source of attacks, viruses, intrusions, or security breaches that occur On a network or in network traffic.

a)

On the cloud

b)

On mobile devices

c)

Of operating Systems

d)

Of network

93.

Refers to any technique, device or software designed to hinder a computer investigation.

a)

Anti-forensic computing.

b)

Encryption.

c)

File headers.

94.

Focuses primarily On gathering digital forensic Information from a cloud infrastructure.

a)

On mobile devices.

b)

On the cloud.

c)

FTK Imager

95.

You use a complex set of rules called an algorithm to make data unreadable.

a)

Encryption

b)

Metadata

c)

Computer forensic analysis

96.

Is a data and image preview tool that allows you to browse files and folders on local hard drives, network drives, CD / DVD and review the content of forensic images or memory dumps.

a)

FTK Imager

b)

Volatility

c)

HashCalc

97.

Es un programa de calculadora desarrollado por SlavaSoft

a)

HashCalc

b)

Belkasoft Live RAM capturer

c)

Volatility

98.

For volatile memory analysis there are several tools such as:

a)

Volatility

b)

Belkasoft Live RAM capturer

c)

HashCalc

99.

It must be accurate, comprehensive, unbiased, recorded, repeatable, and completed within the available time frames and allocated resources.

a)

Computer forensic analysis

b)

The computer expert

c)

Volatility

100.

It is used behind the scenes in Autopsy and in many other commercial and open source forensic tools.

a)

Encase Forensics

b)

Sleuth kit

c)

SIFT Workstation 3

101.

Quickly search, identify and prioritize potential evidence, on computers and mobile devices, to determine if further investigation is warranted.

a)

Encase Forensics

b)

Digital forensics

c)

safety

d)

Forensics v6

102.

It is a group of open source free incident response and forensic tools designed to perform detailed digital forensic examinations in a variety of environments.

a)

Access Data Registry Viewer.

b)

SIFT Workstation 3

c)

Sleuthkit

103.

Provides one of the fastest and most powerful ways to locate files On a Windows computer. You can search by file Name, size, creation and modification dates, and other criteria

a)

OsForensics v6

b)

SIFT Workstation 3

c)

Forense digital

104.

Reveal when a document first appeared On a computer, when it was last edited, when it was last saved or printed, and which user performed these actions.

a)

Defense in depth

b)

Safety

c)

Computer forensic examination

105.

The implementation of this type of security model in which the principles of computer forensics are also adopted is also known as:

a)

Defense in depth

b)

Safety

c)

Criminology

d)

Vulnerability and testing