wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

MidExam InfoAssuSec2

Total questions: 50

Worksheet time: 25mins

Name
Class
Date
1.

What are the Five Information Assurance Pillars?

a)

Confidentiality, Integrity, Availability, Authentication, Authorization

b)

Confidentiality, Integrity, Availability, Authorization, Non-Repudiation

c)

Confidentiality, Integrity, Availability, Authentication, Non-Repudiation

d)

Confidentiality, Integrity, Availability, Authentication, Accountability

2.

What is the main goal of Information Assurance?

a)


To ensure the confidentiality, integrity, and availability of information

b)

To delete all information

c)

To provide unlimited access to information

d)

To restrict access to information

3.

What is the main purpose of Security Countermeasures in Information Assurance?

a)

To slow down information processing

b)

To protect information systems from threats

c)


To expose information to unauthorized parties

d)


To increase vulnerabilities

4.

What does Defense in Depth refer to?

a)

Securing the physical door

b)

Security through layers of a building

c)

Securing only the external perimeter

d)

Securing only the internal part of a building

5.

Which of the following is part of the CIA Triangle?

a)

Confidentiality, Integrity, and Authorization

b)

Confidentiality, Integrity, and Authentication

c)


Confidentiality, Integrity, and Accountability

d)

Confidentiality, Integrity, and Availability

6.

What is the main goal of Non-repudiation?

a)


Proving the legitimacy of a message or data transfer

b)


Ensuring data is accurate and valid

c)


Protecting data from unauthorized changes

d)

Providing undeniable evidence of authenticity and integrity

7.

What are Assets in the context of information security?

a)


Organizational resources being protected

b)

Weaknesses in data confidentiality

c)

Probabilities of threats becoming realities

d)


Parameters implemented to protect data

8.

What is a Threat in the context of information security?

a)

An organizational resource being protected

b)


The act of verifying identification

c)


A weakness in data confidentiality

d)


A possibility of data or systems being compromised

9.

What do Security Controls refer to?

a)


Regulations on user access levels

b)

Processes to limit or allow access based on roles

c)

Parameters implemented to protect data

d)

Safeguards or countermeasures used to protect data and infrastructure

10.

What is the purpose of Administrative Network Security?

a)


Manage user access levels within the network

b)

Focus on protecting data within the network

c)

Prevent unauthorized personnel from accessing network components

d)


Implement measures to ensure only authorized individuals interact with network elements

11.

What is Cryptology concerned with?

a)

Providing confidentiality, integrity, and accuracy

b)


Transforming information into a form that is impossible to duplicate

c)

Converting plaintext into cipher text

d)


Storing data in secure and secret form

12.

What do Security Tools refer to?

a)


Software applications and solutions designed to enhance the security of computer systems, networks, and data.

b)

Act as a barrier between a trusted internal network and untrusted external networks, controlling incoming and outgoing traffic based on predefined security rules.

c)

Detect, prevent, and remove malicious software from a computer system.

d)

Monitor network traffic for suspicious activity or unauthorized access attempts and alert administrators.

13.

What do Security Tools refer to?What is the purpose of Firewalls?

a)


Software applications and solutions designed to enhance the security of computer systems, networks, and data.

b)

Act as a barrier between a trusted internal network and untrusted external networks, controlling incoming and outgoing traffic based on predefined security rules.

c)

Detect, prevent, and remove malicious software from a computer system.

d)

Monitor network traffic for suspicious activity or unauthorized access attempts and alert administrators.

14.

What is the function of Antivirus/Anti-malware Software?

a)


Software applications and solutions designed to enhance the security of computer systems, networks, and data.

b)

Act as a barrier between a trusted internal network and untrusted external networks, controlling incoming and outgoing traffic based on predefined security rules.

c)

Detect, prevent, and remove malicious software from a computer system.

d)

Monitor network traffic for suspicious activity or unauthorized access attempts and alert administrators.

15.

What do Intrusion Detection Systems (IDS) do?

a)


Software applications and solutions designed to enhance the security of computer systems, networks, and data.

b)

Act as a barrier between a trusted internal network and untrusted external networks, controlling incoming and outgoing traffic based on predefined security rules.

c)

Detect, prevent, and remove malicious software from a computer system.

d)

Monitor network traffic for suspicious activity or unauthorized access attempts and alert administrators.

16.

What do Vulnerability Scanners help organizations with?

a)

Assist in bookkeeping and accounting.

b)

Measure body temperature.

c)


Scan barcodes at a supermarket.

d)

Identify security weaknesses in systems, applications, or networks.

17.

What do Data Loss Prevention (DLP) tools prevent?

a)

Unauthorized access, transmission, or leakage of sensitive data by monitoring and enforcing data usage policies.

b)


Manage user identities, permissions, and access rights within an organization's IT environment.

c)

Individual devices such as computers, laptops, smartphones, and tablets from malware, unauthorized access, and other security threats.

d)

Collect, analyze, and correlate security event data from various sources across an organization's IT infrastructure.

18.

What is the function of Identity and Access Management (IAM) solutions?

a)

Unauthorized access, transmission, or leakage of sensitive data by monitoring and enforcing data usage policies.

b)


Manage user identities, permissions, and access rights within an organization's IT environment.

c)

Individual devices such as computers, laptops, smartphones, and tablets from malware, unauthorized access, and other security threats.

d)

Collect, analyze, and correlate security event data from various sources across an organization's IT infrastructure.

19.

What is the goal of vulnerability analysis?

a)


To identify, assess, and prioritize weaknesses in systems

b)


To ignore security risks

c)

To create new vulnerabilities in organizations

d)

To hack into networks and applications

20.

Which type of vulnerability analysis focuses on network infrastructure?

a)

Web Application Vulnerability Analysis

b)

Host-based Vulnerability Analysis

c)

Network Vulnerability Analysis

d)

Physical Security Vulnerability Analysis

21.

What does Network Device Security refer to?

a)

Optimizing network speed

b)


Controlling network bandwidth usage

c)

Securing physical access points only

d)


Monitoring and protecting internet-connected devices within a network

22.

What is the difference between a software firewall and a hardware firewall?

a)


Software firewalls are more secure than hardware firewalls

b)

Software firewalls are only used for cloud deployment, while hardware firewalls are for physical deployment

c)


Hardware firewalls are more cost-effective than software firewalls

d)


Software firewalls are installed on servers or virtual machines, while hardware firewalls are physical devices

23.

What is the purpose of Content Filtering?

a)

Providing unlimited access to all websites

b)

Blocking all incoming traffic

c)

Increasing network speed

d)

Helping users filter or categorize content according to certain parameters

24.

What is the function of Blacklisting?

a)

Blocking items by adding them to a banned list

b)


Allowing all content

c)


Increasing network security

d)


Monitoring user activity

25.

What does Whitelisting do?

a)


Provides unlimited access to all websites

b)


Increases network speed

c)


Blocks all content

d)

Allows content by adding items to an allowed list

26.

What is the purpose of a honeypot in network security?

a)

To provide free internet access

b)


To increase network speed

c)


To block legitimate users

d)


To trap hackers within the system

27.

What does NAT stand for in network security?

a)

Network Authentication Token

b)


Network Analysis Tool

c)

Network Access Terminal

d)

Network Address Translation

28.

What is the purpose of protocol spoofing in network attacks?

a)

To improve network performance

b)

To enhance network security

c)

To create a secure tunnel over a public network

d)


To misrepresent a network protocol to attack a network

29.

What is the role of IPsec in network security?

a)

To analyze network packets

b)


To manage network traffic

c)

To provide free internet access

d)

To protect data by creating an encrypted tunnel

30.

What is the purpose of network sniffing tools?

a)

To block all incoming connections

b)


To increase network speed

c)

To trap hackers within the system

d)


To analyze data packets in a network

31.

What are the main threats for physical and environmental security?

a)

Cyber attacks, phishing, and malware

b)

Financial fraud, insider threats, and espionage

c)

Energy, equipment, fire, and human threats

d)

Water, air, and soil pollution

32.

What do Content Filters control in the context of Preventive Information Assurance Tools?

a)


Access to streaming platforms

b)

Access to online shopping websites

c)

Access to specific portions of the Internet based on policy

d)


Access to social media websites

33.

What is the primary function of Cryptographic Protocols and Tools in information security?

a)

To hide information and provide confidentiality, integrity, and nonrepudiation protection

b)


To provide physical security to buildings

c)

To manage user access control

d)

To monitor network traffic for anomalies

34.

What is the purpose of Firewalls in information assurance technology?

a)

To encrypt data transmissions

b)

To act as a primary control for network security

c)

To establish virtual private networks

d)

To provide secure communication over public networks

35.

What is the role of a Network Intrusion Prevention System (NIPS) in preventing attacks?

a)

To manage hardware and software configurations

b)


To act as a proxy server

c)

To provide secure communication between clients and the Internet

d)

To inspect network traffic based on organizational policy and detect attacks

36.

What is the purpose of a Virtual Private Network (VPN) in network security?

a)


To act as a backup system for data

b)


To provide secure communication over public networks

c)

To manage configuration changes in IT systems

d)

To monitor and prevent network intrusions

37.

Why is Change Management important in organizations?

a)

To provide IT support for day-to-day operations

b)

To ensure proper labeling of media

c)


To establish secure communication channels

d)


To manage and implement changes to IT infrastructure in a controlled manner

38.

What is the purpose of Backups in information assurance?

a)


To provide a copy of information assets and ensure business continuity

b)

To track changes to configuration items

c)

To act as a proxy server for network connections

d)


To prevent unauthorized access to media

39.

What do Media Controls and Documentation address in information security?

a)


Protection against natural disasters

b)

Safeguarding all media including tapes, disks, and printouts

c)


Ensuring proper encryption of data transmissions

d)

Managing hardware and software configurations

40.

What is the purpose of Patch Management in maintaining IT systems?

a)

To ensure standardized methods and procedures for implementing changes

b)

To provide IT support for day-to-day operations

c)

To perform planned and timely system patches to mitigate security vulnerabilities

d)


To track changes to configuration items

41.

What is the main purpose of an access control system?

a)

To enhance system speed

b)


To improve network connectivity

c)


To prevent actions on an object by unauthorized individuals

d)


To increase system storage capacity

42.

Which type of access control model uses a centrally managed set of rules based on subject roles?

a)

Discretionary Access Control Model

b)


Mandatory Access Control Model

c)

Role-Based Access Control Model

d)


Access Control Matrix

43.

What is the benefit of using a Role-Based Access Control (RBAC) model?

a)


It is only suitable for small organizations

b)

It simplifies access management as subjects acquire permissions through their roles

c)

It requires constant maintenance and monitoring

d)


It allows subjects to directly assign permissions to objects

44.

What is the benefit of using a Role-Based Access Control (RBAC) model?

a)


It is only suitable for small organizations

b)

It simplifies access management as subjects acquire permissions through their roles

c)

It requires constant maintenance and monitoring

d)


It allows subjects to directly assign permissions to objects

45.

Which technique uses simple rules to determine the privileges a subject can have over an object?

a)


Access Control Matrix

b)

Rule-Based Access Control

c)

Access Control Lists

d)

Capability Tables

46.

What is the purpose of a Constrained User Interface in access control?

a)

To provide unlimited access to all subjects

b)

To limit access to resources based on subject roles

c)

To restrict access to specific resources based on subject privileges

d)


To grant access to all resources without any restrictions

47.

In which access control model does the system decide on access control based on information security classification and policy rules?

a)


Role-Based Access Control Model

b)

Discretionary Access Control Model

c)

Access Control Matrix

d)

Mandatory Access Control Model

48.

Which mode of access control administration gives control to people closer to the objects?

a)

Role-Based Access Control Administration

b)

Decentralized Access Control Administration

c)

Centralized Access Control Administration

d)

Mandatory Access Control Administration

49.

What is the purpose of an Access Control Matrix?

a)

To use simple rules to determine privileges

b)

To control access based on information security classification

c)

To determine access rights based on subject roles

d)

To represent accessibility using individual or group permissions

50.

Which technique aims at controlling the availability of information by means of views in databases?

a)


Access Control Lists

b)


Rule-Based Access Control

c)


Context-Dependent Access Control

d)

Content-Dependent Access Control