wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Information Security Quiz

Total questions: 75

Worksheet time: 38mins

Name
Class
Date
1.

What does the acronym "CIA" stand for in the context of information security?

a)

Confidentiality, Integrity, Availability

b)

Central Intelligence Agency

c)

Computing Interface Application

d)

Continuous Internal Assessment

2.

Which component of the CIA Triad focuses on preventing unauthorized access to information?

a)

Integrity

b)

Availability

c)

Confidentiality

d)

Authentication

3.

What aspect of the CIA Triad ensures that information is accurate and free from unauthorized modifications?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Encryption

4.

Which part of the CIA Triad is concerned with ensuring reliable access to information by authorized users?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Non-repudiation

5.

What is the primary purpose of confidentiality in data security?

a)

To ensure data is always available

b)

To keep data private and restrict access from unauthorized users

c)

To make data easily accessible to everyone

d)

To corrupt data for unauthorized users

6.

Which of the following is NOT an example of a means to ensure confidentiality?

a)

Firewall

b)

Credentials (username & password)

c)

Public Wi-Fi access

d)

Encryption

7.

What is encryption in the context of data security?

a)

The physical locking of data storage devices

b)

The process of making data unreadable to everyone

c)

The encoding of data to be decoded by the intended user(s)

d)

The transfer of data over secure networks only

8.

What is required to encrypt and decrypt data in an encryption algorithm?

a)

A password

b)

A firewall

c)

A key

d)

A user agreement

9.

Which type of encryption uses different keys for encryption and decryption?

a)

Symmetric Encryption

b)

Asymmetric Encryption

c)

Single-Key Encryption

d)

Dual-Key Encryption

10.

How many keys are required for symmetric encryption according to the image?

a)

One key

b)

Two keys

c)

Three keys

d)

No keys

11.

Which type of encryption is described as less secure due to one key?

a)

Symmetric Encryption

b)

Asymmetric Encryption

c)

Both

d)

None

12.

What is a characteristic of asymmetric encryption not shared with symmetric encryption?

a)

Fast encryption

b)

Confidentiality

c)

Non-Repudiation

d)

Uses DES, 3DES, AES, RC4

13.

Which of the following algorithms is associated with asymmetric encryption?

a)

AES

b)

RC4

c)

RSA

d)

DES

14.

What is a common feature of symmetric encryption?

a)

Slow encryption

b)

Requires public and private keys

c)

Fast encryption

d)

Non-Repudiation

15.

Which encryption standard is described as using a 56-bit key?

a)

AES

b)

DES

c)

RSA

d)

ECC

16.

What does the acronym PGP stand for in the context of encryption?

a)

Pretty Good Privacy

b)

Public General Protocol

c)

Private Gateway Protection

d)

Personal Guarded Password

17.

Which of the following is not a symmetric encryption algorithm?

a)

3DES

b)

AES

c)

RSA

d)

DES

18.

Which algorithm uses public key infrastructure for authentication and encryption?

a)

Diffie-Hellman

b)

RSA

c)

ECC

d)

El Gamal

19.

What type of encryption does ECC represent?

a)

Elliptical Curve Cryptography

b)

Encrypted Code Communication

c)

Enhanced Cybersecurity Cipher

d)

Essential Cloud Cryptography

20.

What is the role of the "Secret Key" in the diagram of Symmetric Encryption?

a)

It is used to convert the cipher text back to plain text only.

b)

It is used to encrypt the plain text and decrypt the cipher text using the same key.

c)

It generates different keys for encryption and decryption.

d)

It is not necessary for the encryption process.

21.

In the Symmetric Encryption process, what does the "Cipher Text" represent?

a)

The original unencrypted information.

b)

The format in which the key is written.

c)

The encrypted version of the plain text.

d)

The process of converting encrypted text into plain text.

22.

What is the primary function of asymmetric encryption as depicted in the diagram?

a)

To compress plain text into a smaller format

b)

To convert plain text into cipher text using two different keys

c)

To verify the authenticity of a digital document

d)

To create a backup of the original data

23.

In the process of asymmetric encryption, what is the role of the public key?

a)

It is used to decrypt the cipher text back into plain text

b)

It is used to encrypt the plain text into cipher text

c)

It is used to generate the secret key

d)

It is used to authenticate the sender

24.

What does the cipher text represent in the context of asymmetric encryption?

a)

The original unencrypted data

b)

The format in which data is stored for efficiency

c)

The encrypted version of the plain text

d)

A digital signature of the document

25.

Which key is used for decryption in asymmetric encryption?

a)

The public key

b)

The private key

c)

The secret key

d)

Any of the above

26.

What is the primary purpose of data integrity in information security?

a)

To ensure data is accessible at all times

b)

To confirm data has not been modified in transit

c)

To encrypt data for secure storage

d)

To speed up data transfer rates

27.

Which algorithm is used to guarantee data integrity by using a secret key?

a)

MD5 Message Digest

b)

SHA-1 Secure Hash Algorithm

c)

HMAC Hashed Message Authentication Code

d)

RSA Encryption Algorithm

28.

What is the bit length of the MD5 hashing algorithm?

a)

128 bit

b)

160 bit

c)

256 bit

d)

512 bit

29.

Which of the following is NOT a hashing algorithm mentioned in the material?

a)

MD5

b)

SHA-1

c)

SHA-256

d)

AES

30.

What is the primary purpose of comparing hash digests in the context of data security?

a)

To increase the data size

b)

To verify the integrity of data

c)

To encrypt the data

d)

To speed up data transfer

31.

What happens if the recalculated hash digest does not match the original hash stored on the servers?

a)

Access is granted

b)

Data is rehashed

c)

Login is denied

d)

Data is deleted

32.

According to the image, how can hashes be altered?

a)

By changing the hashing algorithm

b)

By modifying the data

c)

By deleting the hash

d)

By compressing the data

33.

What does the term "availability" in data security refer to?

a)

The protection of data from unauthorized access

b)

The measure of how often data is accessible when needed

c)

The encryption level of data

d)

The physical security of data storage devices

34.

What is meant by the term "five nines availability"?

a)

Data is available 99.999% of the time

b)

Data is available 95% of the time

c)

Data is available 90% of the time

d)

Data is available 99.9% of the time

35.

Which of the following is NOT a component of the CIA triad in cybersecurity as shown in the image?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Authentication

36.

What is the definition of threats in the context of cybersecurity?

a)

Actions that lead to unauthorized data access

b)

The potential possibility of a negative event

c)

Software tools used by cybercriminals

d)

Protocols to prevent data breaches

37.

Which of the following is considered an internal threat?

a)

Cybercriminals

b)

Employees

c)

Nation state-sponsored attackers

d)

Hacktivists

38.

What type of threat do 'Contractors' represent?

a)

External

b)

Internal

c)

Virtual

d)

Physical

39.

Which category does 'Nation state-sponsored attackers' fall under?

a)

Insider threats

b)

Outsider threats

c)

Accidental threats

d)

Natural threats

40.

What distinguishes 'Hacktivists' in the context of threat sources?

a)

They are primarily motivated by profit.

b)

They are typically government agents.

c)

They are driven by ideological beliefs.

d)

They operate only within internal systems.

41.

What is described as a vulnerability due to poor practices in user verification and identity confirmation?

a)

Misconfigured system components

b)

Inadequate authentication

c)

Sensitive data exposure

d)

Insider threat

42.

Which type of vulnerability arises from errors within the programming code itself?

a)

Psychological vulnerability

b)

Injection flaws

c)

Vulnerabilities in the source code

d)

Trust configurations

43.

What type of security vulnerability is associated with the improper handling and protection of sensitive data?

a)

Weak credentialing practices

b)

Sensitive data exposure

c)

Lack of strong encryption

d)

Shared tenancy vulnerabilities

44.

Which vulnerability is related to the potential risks from individuals within the organization?

a)

Insider threat

b)

Misconfigured system components

c)

Psychological vulnerability

d)

Inadequate authentication

45.

What is a Zero Day Attack in the context of cybersecurity?

a)

An attack that occurs on the same day a vulnerability is disclosed to the public.

b)

A type of malware that self-replicates by copying itself to other programs.

c)

Vulnerabilities that have not yet been discovered or disclosed.

d)

An attack that disables security software on the day of its release.

46.

According to the Zero Day Vulnerability Timeline, what is the first step after a vulnerability is discovered?

a)

Vendor releases a fix.

b)

Vulnerability disclosed to vendor.

c)

Vendor works on a fix.

d)

Vulnerability is exploited by attackers.

47.

What does the 'Windows of Vulnerability' in the diagram represent?

a)

The period when a vulnerability is actively being exploited.

b)

The time frame from the discovery of a vulnerability to the release of a fix.

c)

The operating systems affected by zero day attacks.

d)

The duration for which a vendor is aware of the vulnerability.

48.

What does CVE stand for in cybersecurity contexts?

a)

Common Vulnerability Enumeration

b)

Common Vulnerability and Exposures

c)

Common Virus Exposure

d)

Critical Vulnerability and Exposure

49.

What is the purpose of the CVSS?

a)

To provide a list of all known viruses

b)

To score the impact of computer viruses

c)

To score the severity of vulnerabilities from 0 to 10

d)

To track the number of security breaches

50.

What is an exploit in the context of cybersecurity?

a)

A tool to detect vulnerabilities

b)

The act of fixing vulnerabilities

c)

The act of exposing vulnerabilities, leading to a security breach

d)

A software update

51.

Refer to the diagram explaining the process of an exploit affecting a PC. What is the first step in the depicted exploit process?

a)

The exploit page chooses specific exploits

b)

Your PC is infected

c)

You visit a compromised webpage

d)

The webpage contacts a malicious exploit kit page

52.

What does the principle of "least privilege" in cybersecurity entail?

a)

Users are granted all the permissions they request

b)

Users are assigned minimal access or permission

c)

Users are monitored by advanced tracking systems

d)

Users are given temporary access that expires every hour

53.

What is the main idea behind the "Zero trust" security model?

a)

Trusting all network devices by default

b)

Minimal verification of identities

c)

Trusting nothing and requiring strict identity verification

d)

Using traditional security measures without updates

54.

Which of the following is NOT an example of role-based access?

a)

Guest

b)

Employee

c)

Vendor

d)

Anonymous

55.

What does the phrase "Never trust, always verify" suggest in the context of cybersecurity?

a)

Trust is necessary for effective security

b)

Verification is optional in network security

c)

Trust is considered a vulnerability in network security

d)

Trust should be given after proper training

56.

Refer to the diagram below. What does it primarily illustrate about network security?

a)

The effectiveness of no security measures

b)

The layout of a typical corporate network

c)

The concept of Zero Trust architecture in preventing unauthorized access

d)

The process of granting permissions based on roles

57.

What is the primary focus of the "Defense-in-depth" strategy as depicted in the diagram?

a)

Focusing solely on physical security measures

b)

Using a single security method for protection

c)

Implementing multiple layers of security controls

d)

Prioritizing only network security

58.

Which of the following is NOT listed as a component of Defense-in-depth in the diagram?

a)

Application and Data Security

b)

Host Security

c)

Biometric Security

d)

Physical Security

59.

According to the diagram, what does "Host Security" specifically emphasize?

a)

Firewall and sandboxing

b)

ID cards and CCTV

c)

Timely patching of AV and restricting unwanted services

d)

Risk management and incident response

60.

What is the role of "Network Security" in the Defense-in-depth strategy as shown in the diagram?

a)

Monitoring and alerting

b)

Encrypting sensitive data

c)

Incident response management

d)

CCTV surveillance

61.

What does a triple-homed firewall, also known as a screened subnet or DMZ, utilize in its network architecture?

a)

Two network interfaces

b)

Three network interfaces

c)

Four network interfaces

d)

No network interfaces

62.

What is the primary purpose of a DMZ (Demilitarized Zone) in network architecture?

a)

To provide a secure area for servers that need to be accessible from the internet

b)

To increase the speed of the internal network

c)

To serve as the only access point for internal users

d)

To monitor data usage and limit bandwidth

63.

What is the purpose of implementing separation of duties in cybersecurity?

a)

To ensure that multiple people are responsible for a single task

b)

To prevent any single person from having complete control over a transaction

c)

To allow one person to control all aspects of a transaction

d)

To make the system less secure

64.

What is a honeypot primarily used for in cybersecurity?

a)

To increase the efficiency of internal network servers

b)

To serve as the main defense against external attacks

c)

To attract, detect, and deflect cybercriminals from legitimate targets

d)

To store large amounts of data securely

65.

According to the diagram, what role does the firewall play in the network security setup involving a honeypot?

a)

It acts as the primary storage for data

b)

It serves as a barrier between the attacker and the internal network

c)

It is used to directly attract cybercriminals

d)

It replaces the need for a honeypot

66.

What is required for Multi-Factor Authentication (MFA) to verify identity?

a)

Passcode, Biometrics, Smart Card, VPN Connection

b)

Username, Password, Security Questions

c)

Email Verification, Phone Call, Security Token

d)

Fingerprint, Eye Scan, Voice Recognition

67.

What does SSO stand for in authentication systems?

a)

Single Sign-On

b)

Secure Socket Layer

c)

System Sign-Out

d)

Server-Side Operations

68.

What is the primary use of LDAP in network environments?

a)

Encrypting data transmissions

b)

Accessing and maintaining directory information

c)

Monitoring network traffic

d)

Filtering spam emails

69.

What port number is used by LDAP for directory access?

a)

443

b)

389

c)

80

d)

25

70.

Which protocol uses port number 636 for secure directory access?

a)

HTTPS

b)

LDAPS

c)

FTPS

d)

SMTPS

71.

What protocol does RADIUS use at the transport layer?

a)

TCP

b)

SSL

c)

UDP

d)

HTTP

72.

Which port does RADIUS use for authentication?

a)

49

b)

1812

c)

1813

d)

80

73.

What does TACACS+ use to encrypt data?

a)

Encrypts passwords only

b)

Encrypts the entire packet

c)

Does not encrypt data

d)

Encrypts using SSL only

74.

Which of the following is a characteristic of TACACS+?

a)

It is a lightweight protocol

b)

It uses UDP

c)

It is a Cisco proprietary protocol

d)

It mainly uses for Network Access

75.

What unique feature does RADIUS protocol combine?

a)

Authentication and Encryption

b)

Authentication and Authorization

c)

Encryption and Compression

d)

Authorization and Accounting