NEW
Font size
WorksheetsChapter Seven Practice Quiz - Info Sec
Total questions: 62
Worksheet time: 31mins
What does OPSEC stand for in military and government circles?
Operational Security
Operations Security
Operational Safety
Operations Safety
What is the first and most important step in the operations security process?
Implementing security measures
Analyzing threats
Identifying critical information
Evaluating vulnerabilities
Which of the following is NOT a part of the operations security process?
Identifying critical information
Analyzing threats
Implementing encryption
Evaluating vulnerabilities
Why is it important to identify what you need to protect and what to protect it against in operations security?
To save time
To avoid overprotecting low-value resources
To comply with regulations
To reduce costs
What should you do after identifying critical information in the operations security process?
Implement security measures
Analyze threats
Evaluate vulnerabilities
Apply encryption
What might be considered critical information for a soft drink company?
Their marketing strategy
Their secret recipe
Their employee list
Their annual revenue
What is the purpose of analyzing threats in the operations security process?
To identify potential harm to critical information
To implement security measures
To comply with government regulations
To reduce operational costs
What is an example of critical information for a software company?
Marketing strategies
Proprietary source code
Employee schedules
Office layout
What might attackers do if they gain access to a company's proprietary source code?
Improve the software
Generate license keys and develop pirating utilities
Increase the company's revenue
Enhance the software's security
What is the third step in operations security?
Identifying critical information
Analyzing vulnerabilities
Assessing risks
Implementing security measures
What might happen if the security controls on the source code are not rigorous?
The source code will be automatically updated
The source code might be copied, tampered with, or deleted
The source code will be more secure
The source code will be easier to manage
What could lead to serious security breaches according to the text?
Regular software updates
Lack of policies on source code storage and protection
Frequent employee training
Using open-source software
What is required for a risk to occur in the context of operations security?
A matching threat and vulnerability
A strong security policy
Regular software updates
High-level encryption
In the software source code example, what was one of the threats mentioned?
Unauthorized physical access to the server
Potential exposure of the application source code
Lack of user authentication
Poor network configuration
What could poor controls on access to the source code lead to?
Increased software performance
Exposure of critical information to competitors or attackers
Improved user experience
Enhanced data encryption
What is a countermeasure in the context of operations security?
A method to enhance software features
A set of measures to mitigate risks
A way to increase user engagement
A technique to improve code readability
What should you do if you cannot mitigate the threat itself without changing the nature of your application?
Ignore the threat
Mitigate the vulnerability
Redesign the application
Increase the threat level
What is the purpose of repeating the risk management cycle?
To increase the complexity of the system
To fully mitigate any issues and adjust solutions for greater security
To reduce the number of users
To decrease the system's performance
Who distilled the operations security process into three rules called the laws of OPSEC?
Kurt Haase
John Doe
Jane Smith
Michael Johnson
What is the first law of operations security?
Know the Threats
Know What to Protect
Evaluate Countermeasures
Implement Security Measures
According to the first law of operations security, what must you be aware of?
Actual and potential threats
Security measures
Countermeasures
Data classification
What does the second law of operations security emphasize?
Knowing what to protect
Implementing security measures
Evaluating countermeasures
Identifying threats
What is a common practice in most government environments regarding information?
Identification and classification of information
Implementation of security measures
Evaluation of countermeasures
Replication of data across multiple areas
What is the third and last law of operations security?
If you are not protecting the information, the dragon wins.
If you are not protecting the information, the tiger wins.
If you are not protecting the information, the lion wins.
If you are not protecting the information, the eagle wins.
What was the result of the breach of the California-based email marketing company SaverSpy discovered in September 2018?
More than 43GB of user data was exposed.
More than 50GB of user data was exposed.
More than 30GB of user data was exposed.
More than 20GB of user data was exposed.
What is one of the indicators that a house is unoccupied and vulnerable?
No lights on at night.
Mailbox is empty.
Windows are open.
Car is parked in the driveway.
What is a common cause of security breaches according to the text?
Simple carelessness and noncompliance with basic security measures.
Advanced hacking techniques.
Insider threats.
Natural disasters.
What did the security researcher discover while sifting through compromised servers on Shodan?
The servers containing the data were wide open and unprotected on the internet.
The servers were protected by advanced security measures.
The servers were located in a secure facility.
The servers were only partially compromised.
What is one way to make it seem like someone is home when you are away?
Leave all the lights on
Set timers on your lights
Lock all the doors
Turn off all electronic devices
What can you do to prevent mail and newspapers from stacking up while you are away?
Cancel your subscriptions
Have a friend collect them
Leave them in the mailbox
Ignore them
What is a bad practice from an operational security standpoint when using social media?
Posting about your lunch
Updating your status
Sharing your location
Using location awareness functionality
What is one way to mitigate security threats to your personal information?
Share your information freely
Shred mail containing sensitive information
Trust all organizations with your data
Ignore security breaches
What can you do to monitor your credit reports in case of a breach?
Ignore the breach
Trust organizations to handle it
Put monitoring services in place
Share your credit report online
Who was Sun Tzu?
A Chinese military general who lived in the sixth century BCE
The first president of the United States
A modern-day cybersecurity expert
A famous philosopher from ancient Greece
What is the main idea of Sun Tzu's work "The Art of War" as it relates to operations security?
To promote peace and diplomacy
To provide a guide for conducting military operations
To discuss the economic strategies of ancient China
To explore the philosophical aspects of war
According to Sun Tzu, what is the highest pitch you can attain when making tactical dispositions?
To attack the enemy directly
To conceal your own dispositions
To gather as much information as possible
To form alliances with other nations
What does George Washington's quote about "even minutiae should have a place in our collection" imply?
Only major information is important in operations security
Small items of information can lead to valuable conclusions
Collecting information is a waste of time
Information should be discarded if it seems insignificant
What is the foundational concept of operations security as mentioned in the text?
It is a recent idea implemented by the US government
It is an ancient concept applicable to military and commercial organizations
It is only relevant to modern cybersecurity
It was first developed in the 20th century
What are the three main items of information that constitute an identity?
A. Name, address, and phone number
B. Name, address, and Social Security number
C. Name, phone number, and Social Security number
D. Address, phone number, and Social Security number
What did Washington mean by "For upon Secrecy, Success depends in most enterprises of the kind, and for want of it, they are generally defeated"?
A. The importance of keeping business strategies secret
B. The need to keep intelligence gathering programs secret
C. The necessity of maintaining personal privacy
D. The value of confidentiality in personal relationships
What was the purpose of the study code-named Purple Dragon during the Vietnam War?
A. To develop new military strategies
B. To discover the cause of information leaks
C. To train soldiers in combat techniques
D. To improve communication systems
What does the acronym OPSEC stand for?
A. Operations Security
B. Operational Security
C. Operations Secrecy
D. Operational Secrecy
Who published the book titled "Competitive Strategy: Techniques for Analyzing" in 1980?
A. Michael E. Porter
B. Michael E. Smith
C. Michael E. Johnson
D. Michael E. Brown
What is competitive intelligence generally defined as?
Conducting intelligence gathering and analysis to support business decisions
Conducting intelligence gathering and analysis to support military operations
Conducting intelligence gathering and analysis to support educational research
Conducting intelligence gathering and analysis to support medical research
Which organization is mentioned as a professional group related to competitive intelligence?
Strategic and Competitive Intelligence Professionals (SCIP)
National Security Agency (NSA)
Central Intelligence Agency (CIA)
Federal Bureau of Investigation (FBI)
What was the name of the group that conducted Purple Dragon and developed the government OPSEC principles?
Interagency OPSEC Support Staff
Central Intelligence Agency
Federal Bureau of Investigation
National Security Agency
In what year did President Ronald Reagan sign the Interagency OPSEC Support Staff (IOSS) into being?
1988
1985
1990
1982
Which historical figure's writings are mentioned as espousing principles related to operational security?
Sun Tzu
Julius Caesar
Alexander the Great
Napoleon Bonaparte
How many major steps does the operations security process consist of?
Five
Three
Seven
Ten
What is the first step in the operations security process?
Identifying your most critical information
Analyzing your situation
Determining threats and vulnerabilities
Implementing security measures
What is the purpose of analyzing your situation in the operations security process?
To determine what threats and vulnerabilities exist in your environment
To implement security measures
To train staff on security protocols
To gather intelligence
What is the role of the Interagency OPSEC Support Staff (IOSS) today?
Responsible for a wide variety of OPSEC awareness training efforts
Conducting military operations
Managing national security policies
Overseeing intelligence agencies
Why is it important to identify your critical information?
To increase productivity
To identify potential threats
To improve communication
To enhance customer service
What is the first law of OPSEC?
Identify your critical information
Implement security measures
Assess vulnerabilities
Monitor threats
What is the function of the IOss?
To manage financial records
To oversee operational security
To handle customer inquiries
To develop marketing strategies
What part did George Washington play in the creation of operations security?
He wrote the first OPSEC manual
He implemented the first OPSEC measures
He developed the concept of OPSEC
He trained the first OPSEC officers
In the operations security process, what is the difference between assessing threats and assessing vulnerabilities?
Threats are external, vulnerabilities are internal
Threats are internal, vulnerabilities are external
Threats are potential risks, vulnerabilities are weaknesses
Threats are weaknesses, vulnerabilities are potential risks
Why might you want to use information classification?
To reduce storage costs
To improve data retrieval speed
To protect sensitive information
To enhance user experience
When you have cycled through the entire operations security process, are you finished?
Yes, the process is complete
No, it is an ongoing process
Yes, but only if no new threats arise
No, it needs to be repeated annually
From where did the first formal OPSEC methodology security process arise?
The military
The government
The private sector
The academic community
What is the origin of operations security?
Ancient Rome
The Cold War
World War II
The Industrial Revolution
Define competitive counterintelligence.
Gathering information about competitors
Protecting against espionage
Analyzing market trends
Developing new products
