wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Chapter Seven Practice Quiz - Info Sec

Total questions: 62

Worksheet time: 31mins

Name
Class
Date
1.

What does OPSEC stand for in military and government circles?

a)

Operational Security

b)

Operations Security

c)

Operational Safety

d)

Operations Safety

2.

What is the first and most important step in the operations security process?

a)

Implementing security measures

b)

Analyzing threats

c)

Identifying critical information

d)

Evaluating vulnerabilities

3.

Which of the following is NOT a part of the operations security process?

a)

Identifying critical information

b)

Analyzing threats

c)

Implementing encryption

d)

Evaluating vulnerabilities

4.

Why is it important to identify what you need to protect and what to protect it against in operations security?

a)

To save time

b)

To avoid overprotecting low-value resources

c)

To comply with regulations

d)

To reduce costs

5.

What should you do after identifying critical information in the operations security process?

a)

Implement security measures

b)

Analyze threats

c)

Evaluate vulnerabilities

d)

Apply encryption

6.

What might be considered critical information for a soft drink company?

a)

Their marketing strategy

b)

Their secret recipe

c)

Their employee list

d)

Their annual revenue

7.

What is the purpose of analyzing threats in the operations security process?

a)

To identify potential harm to critical information

b)

To implement security measures

c)

To comply with government regulations

d)

To reduce operational costs

8.

What is an example of critical information for a software company?

a)

Marketing strategies

b)

Proprietary source code

c)

Employee schedules

d)

Office layout

9.

What might attackers do if they gain access to a company's proprietary source code?

a)

Improve the software

b)

Generate license keys and develop pirating utilities

c)

Increase the company's revenue

d)

Enhance the software's security

10.

What is the third step in operations security?

a)

Identifying critical information

b)

Analyzing vulnerabilities

c)

Assessing risks

d)

Implementing security measures

11.

What might happen if the security controls on the source code are not rigorous?

a)

The source code will be automatically updated

b)

The source code might be copied, tampered with, or deleted

c)

The source code will be more secure

d)

The source code will be easier to manage

12.

What could lead to serious security breaches according to the text?

a)

Regular software updates

b)

Lack of policies on source code storage and protection

c)

Frequent employee training

d)

Using open-source software

13.

What is required for a risk to occur in the context of operations security?

a)

A matching threat and vulnerability

b)

A strong security policy

c)

Regular software updates

d)

High-level encryption

14.

In the software source code example, what was one of the threats mentioned?

a)

Unauthorized physical access to the server

b)

Potential exposure of the application source code

c)

Lack of user authentication

d)

Poor network configuration

15.

What could poor controls on access to the source code lead to?

a)

Increased software performance

b)

Exposure of critical information to competitors or attackers

c)

Improved user experience

d)

Enhanced data encryption

16.

What is a countermeasure in the context of operations security?

a)

A method to enhance software features

b)

A set of measures to mitigate risks

c)

A way to increase user engagement

d)

A technique to improve code readability

17.

What should you do if you cannot mitigate the threat itself without changing the nature of your application?

a)

Ignore the threat

b)

Mitigate the vulnerability

c)

Redesign the application

d)

Increase the threat level

18.

What is the purpose of repeating the risk management cycle?

a)

To increase the complexity of the system

b)

To fully mitigate any issues and adjust solutions for greater security

c)

To reduce the number of users

d)

To decrease the system's performance

19.

Who distilled the operations security process into three rules called the laws of OPSEC?

a)

Kurt Haase

b)

John Doe

c)

Jane Smith

d)

Michael Johnson

20.

What is the first law of operations security?

a)

Know the Threats

b)

Know What to Protect

c)

Evaluate Countermeasures

d)

Implement Security Measures

21.

According to the first law of operations security, what must you be aware of?

a)

Actual and potential threats

b)

Security measures

c)

Countermeasures

d)

Data classification

22.

What does the second law of operations security emphasize?

a)

Knowing what to protect

b)

Implementing security measures

c)

Evaluating countermeasures

d)

Identifying threats

23.

What is a common practice in most government environments regarding information?

a)

Identification and classification of information

b)

Implementation of security measures

c)

Evaluation of countermeasures

d)

Replication of data across multiple areas

24.

What is the third and last law of operations security?

a)

If you are not protecting the information, the dragon wins.

b)

If you are not protecting the information, the tiger wins.

c)

If you are not protecting the information, the lion wins.

d)

If you are not protecting the information, the eagle wins.

25.

What was the result of the breach of the California-based email marketing company SaverSpy discovered in September 2018?

a)

More than 43GB of user data was exposed.

b)

More than 50GB of user data was exposed.

c)

More than 30GB of user data was exposed.

d)

More than 20GB of user data was exposed.

26.

What is one of the indicators that a house is unoccupied and vulnerable?

a)

No lights on at night.

b)

Mailbox is empty.

c)

Windows are open.

d)

Car is parked in the driveway.

27.

What is a common cause of security breaches according to the text?

a)

Simple carelessness and noncompliance with basic security measures.

b)

Advanced hacking techniques.

c)

Insider threats.

d)

Natural disasters.

28.

What did the security researcher discover while sifting through compromised servers on Shodan?

a)

The servers containing the data were wide open and unprotected on the internet.

b)

The servers were protected by advanced security measures.

c)

The servers were located in a secure facility.

d)

The servers were only partially compromised.

29.

What is one way to make it seem like someone is home when you are away?

a)

Leave all the lights on

b)

Set timers on your lights

c)

Lock all the doors

d)

Turn off all electronic devices

30.

What can you do to prevent mail and newspapers from stacking up while you are away?

a)

Cancel your subscriptions

b)

Have a friend collect them

c)

Leave them in the mailbox

d)

Ignore them

31.

What is a bad practice from an operational security standpoint when using social media?

a)

Posting about your lunch

b)

Updating your status

c)

Sharing your location

d)

Using location awareness functionality

32.

What is one way to mitigate security threats to your personal information?

a)

Share your information freely

b)

Shred mail containing sensitive information

c)

Trust all organizations with your data

d)

Ignore security breaches

33.

What can you do to monitor your credit reports in case of a breach?

a)

Ignore the breach

b)

Trust organizations to handle it

c)

Put monitoring services in place

d)

Share your credit report online

34.

Who was Sun Tzu?

a)

A Chinese military general who lived in the sixth century BCE

b)

The first president of the United States

c)

A modern-day cybersecurity expert

d)

A famous philosopher from ancient Greece

35.

What is the main idea of Sun Tzu's work "The Art of War" as it relates to operations security?

a)

To promote peace and diplomacy

b)

To provide a guide for conducting military operations

c)

To discuss the economic strategies of ancient China

d)

To explore the philosophical aspects of war

36.

According to Sun Tzu, what is the highest pitch you can attain when making tactical dispositions?

a)

To attack the enemy directly

b)

To conceal your own dispositions

c)

To gather as much information as possible

d)

To form alliances with other nations

37.

What does George Washington's quote about "even minutiae should have a place in our collection" imply?

a)

Only major information is important in operations security

b)

Small items of information can lead to valuable conclusions

c)

Collecting information is a waste of time

d)

Information should be discarded if it seems insignificant

38.

What is the foundational concept of operations security as mentioned in the text?

a)

It is a recent idea implemented by the US government

b)

It is an ancient concept applicable to military and commercial organizations

c)

It is only relevant to modern cybersecurity

d)

It was first developed in the 20th century

39.

What are the three main items of information that constitute an identity?

a)

A. Name, address, and phone number

b)

B. Name, address, and Social Security number

c)

C. Name, phone number, and Social Security number

d)

D. Address, phone number, and Social Security number

40.

What did Washington mean by "For upon Secrecy, Success depends in most enterprises of the kind, and for want of it, they are generally defeated"?

a)

A. The importance of keeping business strategies secret

b)

B. The need to keep intelligence gathering programs secret

c)

C. The necessity of maintaining personal privacy

d)

D. The value of confidentiality in personal relationships

41.

What was the purpose of the study code-named Purple Dragon during the Vietnam War?

a)

A. To develop new military strategies

b)

B. To discover the cause of information leaks

c)

C. To train soldiers in combat techniques

d)

D. To improve communication systems

42.

What does the acronym OPSEC stand for?

a)

A. Operations Security

b)

B. Operational Security

c)

C. Operations Secrecy

d)

D. Operational Secrecy

43.

Who published the book titled "Competitive Strategy: Techniques for Analyzing" in 1980?

a)

A. Michael E. Porter

b)

B. Michael E. Smith

c)

C. Michael E. Johnson

d)

D. Michael E. Brown

44.

What is competitive intelligence generally defined as?

a)

Conducting intelligence gathering and analysis to support business decisions

b)

Conducting intelligence gathering and analysis to support military operations

c)

Conducting intelligence gathering and analysis to support educational research

d)

Conducting intelligence gathering and analysis to support medical research

45.

Which organization is mentioned as a professional group related to competitive intelligence?

a)

Strategic and Competitive Intelligence Professionals (SCIP)

b)

National Security Agency (NSA)

c)

Central Intelligence Agency (CIA)

d)

Federal Bureau of Investigation (FBI)

46.

What was the name of the group that conducted Purple Dragon and developed the government OPSEC principles?

a)

Interagency OPSEC Support Staff

b)

Central Intelligence Agency

c)

Federal Bureau of Investigation

d)

National Security Agency

47.

In what year did President Ronald Reagan sign the Interagency OPSEC Support Staff (IOSS) into being?

a)

1988

b)

1985

c)

1990

d)

1982

48.

Which historical figure's writings are mentioned as espousing principles related to operational security?

a)

Sun Tzu

b)

Julius Caesar

c)

Alexander the Great

d)

Napoleon Bonaparte

49.

How many major steps does the operations security process consist of?

a)

Five

b)

Three

c)

Seven

d)

Ten

50.

What is the first step in the operations security process?

a)

Identifying your most critical information

b)

Analyzing your situation

c)

Determining threats and vulnerabilities

d)

Implementing security measures

51.

What is the purpose of analyzing your situation in the operations security process?

a)

To determine what threats and vulnerabilities exist in your environment

b)

To implement security measures

c)

To train staff on security protocols

d)

To gather intelligence

52.

What is the role of the Interagency OPSEC Support Staff (IOSS) today?

a)

Responsible for a wide variety of OPSEC awareness training efforts

b)

Conducting military operations

c)

Managing national security policies

d)

Overseeing intelligence agencies

53.

Why is it important to identify your critical information?

a)

To increase productivity

b)

To identify potential threats

c)

To improve communication

d)

To enhance customer service

54.

What is the first law of OPSEC?

a)

Identify your critical information

b)

Implement security measures

c)

Assess vulnerabilities

d)

Monitor threats

55.

What is the function of the IOss?

a)

To manage financial records

b)

To oversee operational security

c)

To handle customer inquiries

d)

To develop marketing strategies

56.

What part did George Washington play in the creation of operations security?

a)

He wrote the first OPSEC manual

b)

He implemented the first OPSEC measures

c)

He developed the concept of OPSEC

d)

He trained the first OPSEC officers

57.

In the operations security process, what is the difference between assessing threats and assessing vulnerabilities?

a)

Threats are external, vulnerabilities are internal

b)

Threats are internal, vulnerabilities are external

c)

Threats are potential risks, vulnerabilities are weaknesses

d)

Threats are weaknesses, vulnerabilities are potential risks

58.

Why might you want to use information classification?

a)

To reduce storage costs

b)

To improve data retrieval speed

c)

To protect sensitive information

d)

To enhance user experience

59.

When you have cycled through the entire operations security process, are you finished?

a)

Yes, the process is complete

b)

No, it is an ongoing process

c)

Yes, but only if no new threats arise

d)

No, it needs to be repeated annually

60.

From where did the first formal OPSEC methodology security process arise?

a)

The military

b)

The government

c)

The private sector

d)

The academic community

61.

What is the origin of operations security?

a)

Ancient Rome

b)

The Cold War

c)

World War II

d)

The Industrial Revolution

62.

Define competitive counterintelligence.

a)

Gathering information about competitors

b)

Protecting against espionage

c)

Analyzing market trends

d)

Developing new products