Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

IAP301

Total questions: 20

Worksheet time: 11mins

Name
Class
Date
1.

You review how you are going to manage your IT investment such as contracts, new policy ideas, service level agreements (SLAs) which are stated commitment to provide a specific service level". In which phase of COBIT 5.0 does this situation belong to?

a)

a. Align, Plan, and Organize

b)

b. Build, Acquire, and Implement

c)

c. Deliver, Service, and Support

d)

d. Monitor, Evaluate, and Assess

2.

Alice sends an email to Bob that says "I agree to purchase 100 widgets at $10 each." Bob receives the email and it is digitally signed by Alice's private key. The signature verifies that the email came from Alice. Later, Alice claims she never sent that email agreeing to purchase the widgets. However, Bob has the digitally signed email which proves the message came from Alice. What is the issue here ?

a)

a. Unauthorized access to the system

b)

b. Integrity of the data

c)

c. Availability of the data

d)

d. Nonrepudiation of the data

e)

e. Unauthorized use of the system

3.

A major retailer recently began offering an augmented reality (AR) shopping app that allows customers to visualize products in their homes. During a routine security audit, the app developer uncovered that hackers could potentially access the smartphone cameras of users. Further, analysis showed that certain camera permissions were not configured properly, allowing malicious actors a way to activate cameras without the user's knowledge. Which of the following best describes the problem?

a)

a. A new threat was discovered.

.

b)

b. A new vulnerability was discovered.

c)

c. A new risk was discovered.

d)

d. A new breach was discovered

4.

A company is developing a new web application and wants to ensure it follows industry standards for security, accessibility, and interoperability. For security, they decide to implement authentication following the OpenID Connect standard. This allows users to login with their existing accounts from Google, Facebook etc. rather than creating new credentials. For accessibility, they ensure the application complies with guidelines. This covers aspects like color contrast, keyboard navigation, and screen reader functionality. For interoperability, they use common web standards like HTTP, HTML5, CSS, and JavaScript. What does the company apply?

a)

a. Policy

b)

b. Standard

c)

c. Procedure

d)

d. Guildline

5.

An audit that is done by government agencies that assess the company's

compliance with laws and regulations is called ________.

a)

a. Self-Assessment

b)

b. Internal Audit

c)

c. External Audit

.

d)

d. Regulator Audit

6.

A hospital implements a new electronic health record (EHR) system. Shortly after deployment, nurses report that the system is very slow during peak hours of the day, delaying access to patient records. The hospital's IT team investigates and determines the EHR system is undersized for the number of concurrent users during busy shifts, causing performance lag. Which control should they apply to mitigate the problem?

a)

a. Preventative

b)

b. Correlative

c)

c. Detective

d)

d. Corrective

7.

What is an detective control?

a. A control that stops behavior immediately and does not rely on human decisions

b. A control that does not stop behavior immediately and relies on human decisions

c. A control that does not stop behavior immediately but automates notification of incident

d. A control that stops behavior immediately and relies on human decisions

a)

a

b)

b

c)

c

d)

d

8.

While a company encrypt data and has security controls around data transmission/storage, there is still a risk that data could be inadvertently exposed or stolen in a sophisticated cyberattack. Which of the following best describes the problem?

a. risk exposure

b. risk appetite

c. residual risk

d. risk tolerance

a)

a

b)

b

c)

c

d)

d

9.

A publicly traded company is preparing its quarterly financial statements. The CEO pressures the CFO to manipulate revenue numbers to make the company's growth appear stronger than it actually was to boost the stock price. The CFO reluctantly agrees to falsify the financials. This is a act of __________ violation.

a)

a. Health Insurance Portability and Accountability Act (HIPAA)

b)

b. Gramm-Leach-Bliley Act (GLBA)

c)

c. Sarbanes-Oxley Act (SOX)

d)

d. Family Educational Rights and Privacy Act (FERPA)

10.

Which of the following are control objectives for Payment Card Industry Data Security Standard (PCI DSS)?

a)

a. Maintain an information security policy

b)

b. Protect cardholder data

c)

c. Alert when credit cards are illegally used

d)

d. Build and maintain a secure network

11.

Nation-state attacks that attempt to disrupt a country's critical infrastructure are sometimes referred to as _________.

a. Black Hacker

b. Hackactivist

c. Cyberterrorism

d. Terrorist

a)

a

b)

b

c)

c

d)

d

12.

Which of the seven domains refers to the technique that connects the organization’s infrastructure and allows end users to surf the Internet?

a)

a. Remote Access Domain

b)

b. LAN-to-WAN Domain

c)

c. World Area Network Domain

d)

d. System/Application Domain

13.

A small business has a network with 15 employees. They have a single router connecting them to the internet. All of the employees' computers, printers, servers, and other devices are connected through unmanaged switches. Which type of network does the company use?

a)

a. Flat network

b)

b. Segmented network

c)

c. Hierarchical network

d)

d. Mesh network

14.

What kind of workstation management refers to knowing which devices are on the network and how often they connect to the LAN?

a)

a. Inventory management

b)

b. Patch management

c)

c. Security management

d)

d. Discovery management

15.

A large financial services company has offices across multiple locations and stores sensitive customer data in multiple databases and file shares. They want to ensure this data is properly secured and monitored to prevent any potential unauthorized leaks. What should they use to catalog all the locations where sensitive data is stored and processed?

a)

a. Data Leakage Protection Inventory

b)

b. DLP Encryption Key

c)

c. Data Loss Protection Perimeter

d)

d. DLP Trojans

16.

Authentication is one of the most important components of the __________ Domain.

a)

a. User

b)

b. LAN to WAN

c)

c. LAN

d)

d. WAN

17.

Where is a demilitarized zone (DMZ) usually located?

a)

a. Inside the private LAN

b)

b. Within the WAN

c)

c. Between the private LAN and public WAN

d)

d. Within the mail server

e)

e. Workstation Domain

18.

Which personality type often going out of their way to help others, sometimes taking on tasks beyond their bandwidth, seeking validation and praise from others, having difficulty identifying and asking for what they need or want?

a)

a. Attackers

b)

b. Commanders

c)

c. Analyticals

d)

d. Pleasers

19.

__________ refers user with lack of interest, enthusiasm, or concern demonstrated by users or customers towards a product, service, or information system.

a)

a. User Apathy

b)

b. User Resistance

c)

c. User Discomfort

d)

d. Learned Helplessness

20.

What is the best measurement of whether employees are following policies?

a)

a. The actual reduction in risk

b)

b. The number of people aware of the policy

c)

c. Many players are involved in the process of security policy implementation

d)

d. The number of employees understand the security policy concepts