Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

IAS Midterm Reviewer

Total questions: 72

Worksheet time: 39mins

Name
Class
Date
1.

Protection of the confidentiality, integrity, and availability of information assets, whether in storage, processing, or transmission, via the application of policy, education, training and awareness, and technology.

a)
Web Development
b)
Information Security
c)
Cybersecurity
d)
Data Science
2.

The quality or state of being secure to be free from danger or harm

a)
insecurity
b)

security

c)
protection
d)

confidentiality

3.

A model designed to guide policies for information security within an organization.

a)

Software Assurance

b)

NIST Approach

c)

C.A.I Triangle

d)

C.I.A Triangle

4.

Ensures that only users with the rights, privileges, and need to access information are able to do so.

(a)  

5.

Whole, complete, and uncorrupted

a)
Integrity
b)

Availability

c)

Confidentiality

6.

Enables authorized users—people or computer systems—to access information without interference or obstruction and to receive it in the required format.

a)
Availability
b)

Confidentiality

c)

Quality

d)

Integrity

7.

Ensures that only users with the rights, privileges, and need to access information are able to do so.

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Quality

8.

It places the responsibility of successful information security on a single staff member or security department.

a)

Bottom-Up Approach

b)

Top-Down Approach

9.

It is initiated by upper management who issue policy, procedures, and processes, dictate goals and expected outcomes of project.

a)

Top-Down Approach

b)

Bottom-Up Approach

10.

A methodological approach to the development of software that seeks to build security into the development life cycle rather than address it at later stages

a)
Safe Development Method (SDM)
b)
Secure Software Development (SSD)
c)
Security Development Approach (SDA)
d)

Software Assurance (SA)

11.

It adopted a simplified SLDC for their approach, based on five phases: initiation, development/acquisition/implementation/assessment, operation/maintenance, and disposal.

a)

NIST Approach

b)

Software Assurance (SA)

c)

Security Systems Development Life Cycle

12.

CIO stands for

(a)  

13.

CISO stands for

(a)  

14.

The senior technology officer responsible for advising senior executives on strategic planning

a)
Chief Information Officer (CIO)
b)
Chief Financial Officer (CFO)
c)
Chief Marketing Officer (CMO)
d)
Chief Technology Officer (CTO)
15.

Primarily responsible for assessment, management, and implementation of IS in the organization.

a)
Chief Information Officer (CIO)
b)

Chief Information Security Officer (CISO)

c)
Chief Technology Officer (CTO)
16.

A number of individuals who are experienced in one or more facets of required technical and nontechnical areas.

a)

Information Security Project Team

b)

Team of Experts

c)

Senior Experts

17.

Responsible for the security and use of a particular set of information.

a)
Data Keeper
b)

Data Custodian

c)
Data Protector
d)

Data Owner

18.

Responsible for storage, maintenance, and protection of information

a)
Data Storage
b)
Data Protection
c)

Data Custodian

d)

Data Owner

19.

End users who work with information to perform their daily jobs supporting the mission of the organization.

a)

Data Custodian

b)

Data Analyst

c)

Data Users

20.

It is based on the way individuals perceive systems technologists since computers became commonplace.

a)

“Security Artisan” Idea

b)

“Authority Artisan” Idea

c)

“Service Artisan” Idea

21.

A website hosted by Mitre that serves as a tool that security professionals can use to understand attacks.

a)

Common Attack Pattern Enumeration and Classification (CAPEC)

b)

Common Security Pattern Enumeration and Classification (CSPEC)

c)

Common Attack Pattern Information and Classification (CAPIC)

22.

The unauthorized duplication, installation, or distribution of copyrighted computer software, which is a violation of intellectual property.

a)
Digital counterfeiting
b)
Software theft
c)
Program plagiarism
d)
Software piracy
23.

When an unauthorized person gains access to information an organization is trying to protect.

a)

Espionage or Trespass

b)
Data leak
c)
Information breach
d)
Unauthorized access
24.

A person who stealthily manipulates a maze of computer networks, systems, and data to find information.

a)
cracker
b)
hacker
c)
cyberterrorist
d)
decoder
25.

Master of several programming languages, networking protocols, and operating systems, and exhibits a mastery of the technical environment of the chosen targeted system.

a)

Decoder

b)

Cracker

c)

Expert Hacker

d)

Cybersecurity Hacker

26.

Commonly associated with software copyright bypassing and password decryption.

a)
phishing
b)
malware
c)
virus
d)

cracker

27.

The application of computing and network resources to try every possible password combination.

a)
Social Engineering
b)
Rainbow Table Attack
c)
Brute Force Attack
d)
Dictionary Attack
28.

A variation of the brute force attack that narrows the field by using a dictionary of common passwords and includes information related to the target user.

a)
Social engineering attack
b)
Rainbow attack
c)
Brute force attack
d)
Dictionary attack
29.

Hash values are used to gain access to an encrypted password file

a)

Dictionary Attacks

b)

Rainbow Tables

c)

Brute Force

d)

Social Engineering Password Attacks

30.

Human error or failure is used as a mechanism to gain password information

a)

Phishing attack

b)

Shoulder surfing attack

c)

Malware attack

d)

Social engineering password attack

31.

It is called “acts of God” as it presents the most dangerous threats that occur with little warning and beyond control of people.

a)
Man-made disasters
b)

Forces of nature

c)
Supernatural events
d)
Acts of government
32.

Acts performed without intent or malicious purpose or in ignorance by an authorized user.

a)
Negligent violation
b)
Unintentional breach
c)
Accidental transgression
d)

Human Error of Failure

33.

It is called cyberextortion and common in the theft pf credit card numbers.

a)
Phishing
b)

Cyberextortion

c)

Information Extortion

d)
Ransomware
34.

to destroy an asset or damage the image of an organization

a)
slander
b)
enhance
c)
sabotage
35.

Accessing systems and damaging destroying critical data.

a)
Phishing attacks
b)
Malware infections
c)
Physical security breaches
d)

Online Activism

36.

Unlawful attacks and threats of attacks against computers, networks and the information stored therein when done to intimidate or coerce a government or its people in furtherance of political or social objectives.

a)
Virtual espionage
b)
Digital sabotage
c)
Cyberterrorism
d)

Online Activism

37.

Leveraging social media to perform fundraising, raise awareness of social issues, gather support for legitimate causes, and promote involvement.

a)
Traditional advertising
b)

Positive Online Activism

c)
Online shopping
d)
Social media marketing
38.

It consists of specially crafted software that attackers trick users into installing on their systems to overwhelm the processing capabilities of online systems or to gain access to protected systems by hidden means.

a)
Spyware
b)
Ransomware
c)
Malware
d)

Software Attacks

39.

Occur when a manufacturer distributes equipment containing defects that can cause the system to perform outside of expected parameters, resulting in unreliable service or lack of availability.

a)
Manufacturing excellence
b)
Performance enhancement
c)
Service reliability
d)

Technical Hardware Failures

40.

Purposeful shortcuts perceived as bugs or errors left by programmers for benign or malign reasons.

a)
Glitches
b)
Bugs
c)

Technical Hardware Failures

d)

Technical Software Failures

41.

The legal obligation of an entity extending beyond criminal or contract law; includes the legal obligation to make restitution.

a)

Policy

b)

Liability

c)

Jurisdiction

d)

Due Care

42.

The legal standard requiring a prudent organization to act legally and ethically and know the consequences of actions.

a)

Due care

b)
Responsibility of awareness
c)
Obligation of caution
d)

Due Diligence

43.

The court’s right to hear a case if the wrong was committed in its territory or involved its citizenry.

a)
Jurisdiction
b)
Territoriality
c)
Citizenship
d)
Venue
44.

It functions as organizational laws that must be crafted and implemented with care to ensure they are complete, appropriate, and fairly applied to everyone.

(a)  

45.

Strongly promotes education and provides discounts for student members.

a)

Association of Computing Machinery (ACM)

b)

International Information Systems Security Certification Consortium, Inc. (ISC)

c)

System Administration, Networking, and Security (SANS) Institute

d)

Information Systems Audit and Control Association (ISACA)

46.

Focuses on the development and implementation of information security certifications and credentials.

a)

International Information Systems Security Certification Consortium, Inc. (ISC)

b)

System Administration, Networking, and Security (SANS) Institute

c)

Information Systems Audit and Control Association (ISACA)

d)

Association of Computing Machinery (ACM)

47.

Professional research and education cooperative organization that offers a set of certifications called the Global Information Assurance Certification (GIAC).

a)

System Administration, Networking, and Security (SANS) Institute

b)

Information Systems Audit and Control Association (ISACA)

c)

Information Systems Security Association (ISSA)

48.

Provides IT control practices and standards, and includes many information security components within its areas of concentration.

a)

Information Systems Audit and Control Association (ISACA)

b)

System Administration, Networking, and Security (SANS) Institute

c)

Information Systems Security Association (ISSA)

49.

Its primary mission is to bring together qualified information security practitioners for information exchange and educational development.

a)

Information Systems Security Association (ISSA)

b)

Information Systems Audit and Control Association (ISACA)

c)

. System Administration, Networking, and Security (SANS) Institute

50.

It sets the long-term direction to be taken by the organization and each of its component parts.

a)
tactical planning
b)
financial planning
c)
strategic planning
d)
operational planning
51.

It focuses on short-term undertakings that will be completed within one or two years.

a)
Long-term planning
b)

Strategic Planning

c)

Tactical Planning

d)
Short-term planning
52.

It is derived from tactical planning to organize the ongoing, day-to-day performance of tasks.

a)
Tactical planning
b)
Strategic planning
c)
Financial planning
d)
Operational planning
53.

It represents the strategic controlling function of an organization’s senior management, which is designed to ensure informed, prudent strategic decisions made in the best interest of the organization.

(a)  

54.

According to Information Technology Governance Institute (ITGI), it includes all of the accountabilities and methods undertaken by the board of directors and executive management.

a)

Information Security Operations

b)

Information Security Governance

c)

Information Security Management

55.

Oversee overall corporate security posture

a)

Chief Executive Officer

b)

Chief Security Officer

c)

Chief Information Officer

56.

Standards in actuality, are adopted widely by an industry and its customers.

a)

De facto Standards

b)

De jure Standards

c)

Facto Standards

57.

Standards that are according to law and endorsed by a formal standards organization.

a)

De facto standards

b)

De jure standards

c)

Jure Standards

d)

Facto Standards

58.

also known as general security policy, organizational security policy, IT security policy, or information security policy.

a)

Enterprise Information Security Policy

b)

Issue-specific Security Policy

c)

Systems-Specific Security Policy

59.

It requires frequent updates, and contains a statement about the organization’s position on a specific issue.

a)

Issue-specific Security Policy

b)

Systems-Specific Security Policy

c)

Enterprise Information Security Policy

60.

It functions as standards or procedures to be used when configuring or maintaining systems.

a)

Systems-Specific Security Policy

b)

Issue-specific Security Policy

c)

Enterprise Information Security Policy

61.

It is the responsibility of the CISO and is a control measure designed to reduce incidents of accidental security breaches by employees

a)

Security Education, Training and Awareness (SETA) Program

b)

Contingency Planning (CP)

c)

Business Impact Analysis (BIA)

d)

Disaster Recovery Planning (DR)

62.

It provides strategic planning to assure the continuous availability of information systems and in preparation for adverse events that become incidents or disasters.

a)

Contingency Planning (CP)

b)

Business Impact Analysis (BIA)

c)

Disaster Recovery Planning (DR)

d)

Crisis Management

63.

A systematic process to determine and evaluate the potential effects of an interruption to critical business operations as a result of a disaster, accident or emergency.

a)
Business Interruption Analysis
b)
Disaster Recovery Plan
c)
Emergency Response Assessment
d)
Business Impact Analysis (BIA)
64.

The process of preparing an organization to handle a disaster and recover from it, whether the disaster is natural or man-made.

a)

Disaster Recovery Planning (DR)

b)

Business Continuity Planning

c)

Crisis Management

65.

prepares an organization to reestablish or relocate critical business operations during a disaster that affects operations at the primary site.

a)

Business Continuity Planning

b)

Disaster Recovery Planning (DR)

c)

Business Impact Analysis (BIA)

d)

Crisis Management

66.

It focuses first and foremost on the people involved.

a)

Risk Identification

b)

Risk Assessment

c)

Risk Control

67.

Determination of the extent to which the organization’s information assets are exposed or at risk.

a)

Risk Identification

b)

Risk Control

c)

Risk Assessment

68.

Application of controls to reduce the risks to an organization’s data and information systems.

a)

Risk Assessment

b)

Risk Control

c)

Risk Identification

69.

Describes an assessment of the likelihood of an attack combined with its expected probability of success if it targets your organization (attack success probability).

a)

Loss Frequency

b)
Threat analysis
c)
Security audit
d)
Vulnerability assessment
70.

Determining how much of an information asset could be lost in a successful attack.

a)

Loss Magnitude

b)

Loss Event Frequency

c)

Attack Success Probability

71.

Process of seeking out and studying the practices used in other organizations that product

(a)  

72.

Sometimes enforced in civil courts, where large damages can be awarded to plaintiffs who bring suits against organizations.

a)

Law

b)

Policy

c)

Lawsuits