wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

IT311

Total questions: 70

Worksheet time: 35mins

Name
Class
Date
1.

Which category of threat involves events such as earthquakes and floods?

a)
a) Human Error
b)
b) Natural Disasters
c)
C Cyber Attacks
d)
d) Technical Failures
2.

What is the primary focus of Information Security Threats as defined in the book?

a)
a) Financial losses
b)
b) Unauthorized data access
c)
c) Physical damage
d)
d) Reputation management
3.

Which of the following is NOT classified as an Information Security Attack according to the book?

a)
a) Ransomware
b)
b) Data Breach
c)
c) Phishing
d)
d) Fire
4.

Which type of attack is characterized by overwhelming a system to prevent legitimate access?

a)
a) Phishing
b)
b) SQL Injection
c)
c) Denial of Service (DoS)
d)
d) Spoofing
5.

Which category of threats includes errors made by employees or users?

a)
a) Technical Failures
b)
b) Natural Disasters
c)
c) Human Error
d)
d) Cyber Attacks
6.

Which threat category could be caused by a power outage?

a)
a) Natural Disasters
b)
b) Technical Failures
c)
c) Human Error
d)
d) Cyber Attacks
7.

Phishing attacks typically target which aspect of security?

a)
a) Physical systems
b)
b) Network infrastructure
c)
c) Personal information
d)
d) Data encryption
8.

Which of the following is a key feature of a Denial of Service (DoS) attack?

a)
a) Data alteration
b)
b) Service interruption
c)
c) Data theft
d)
d) Unauthorized access
9.

Which attack involves tricking users into providing sensitive information through deceptive means?

a)
a) Phishing
b)
b) Malware
c)
c) Ransomware
d)
d) Trojan
10.

Natural Disasters are considered part of the Technical Failures threat category.

a)
True
b)
False
11.

Human Error can include mistakes made during data entry or system configuration.

a)
True
b)
False
12.

A Data Breach involves unauthorized access to sensitive information.

a)
True
b)
False
13.

Ransomware is a type of malware that demands payment in exchange for restoring access to encrypted data.

a)
True
b)
False
14.

SQL Injection attacks are designed to exploit weaknesses in physical security measures.

a)
True
b)
False
15.

Denial of Service (DoS) attacks aim to disrupt the normal functioning of a service or network.

a)
True
b)
False
16.

Technical Failures are threats that arise from human interactions with systems.

a)
True
b)
False
17.

Phishing attacks can be carried out via email or fraudulent websites.

a)
True
b)
False
18.

Social Engineering is classified under Cyber Attacks as it involves manipulating people rather than systems.

a)
False
b)
True
19.

Data Tampering is an example of an Information Security Threat.

a)
True
b)
False
20.
What is the difference between intrinsic value and acquired value?
a)
A. Intrinsic value refers to the natural importance of an asset, while acquired value is based on the cost incurred to protect it.
b)
B. Intrinsic value is the inherent worth of an asset, while acquired value is the worth assigned based on external factors, such as market demand or investment.
c)
C. Intrinsic value is the worth given by a company policy, while acquired value is based on depreciation rates.
21.
What is a qualitative risk assessment?
a)
A. A risk assessment method that uses numerical values and formulas to calculate risk levels.
b)
B. A risk assessment technique that uses subjective judgment to evaluate the likelihood and impact of risks.
c)
C. An evaluation process focused solely on physical security measures.
22.
Which group is responsible for setting the risk appetite in an organization?
a)
A. Users
b)
B. IT Security Team
c)
C. Auditors
d)
D. Management
23.
What is the role of the Risk Management Policy within an organization?
a)
A. To establish the organization’s approach to managing risks
b)
B. To define how the organization will avoid risks
c)
C. To provide detailed technical solutions for all risks
d)
D. To set guidelines for resource allocation
24.
What does "risk appetite" refer to in the context of risk management?
a)
A. The total number of risks an organization faces
b)
B. The organization’s strategy for avoiding all risks
c)
C. The amount of risk the organization is willing to accept
d)
D. The cost of mitigating a particular risk
25.
What is the primary purpose of the Risk Management Framework (RMF)?
a)
A. To eliminate all risks
b)
B. To identify, assess, and manage risks
c)
C. To increase profitability
d)
D. To implement new technologies
26.
What does the mitigation strategy focus on?
a)
A. Removing the risk entirely
b)
B. Transferring the risk to another party
c)
C. Reducing or eliminating the risk by adding controls
27.
How does technology contribute to the mitigation strategy?
a)
A. By completely removing the risk
b)
B. By offering insurance
c)
C. By implementing firewalls and security systems
28.
What is the goal of Security Education, Training, and Awareness (SETA)?
a)
A. To ignore security risks
b)
B. To teach employees why security practices are important
c)
C. To remove all risks at once
29.
Which of the following is an example of a mitigation technique?
a)
A. Outsourcing IT security
b)
B. Implementing strong password policies
c)
C. Accepting a risk without action
30.
How are Sun Tzu's principles from "The Art of War" relevant to risk management in information security?
a)
A. By focusing on constant offensive measures
b)
B. By applying strategic planning to anticipate and manage risks
c)
C. By eliminating all potential threats immediately
31.
Which community of interest usually takes the lead in information asset risk management, and which community of interest usually provides the resources used for this process?
a)
A. InfoSec takes the lead; IT community provides the resources
b)
B. IT community takes the lead; InfoSec provides the resources
c)
C. Upper management takes the lead; InfoSec provides the resources
32.
According to Sun Tzu, what two things must be achieved to successfully secure information assets?
a)
A. Implementing strict security policies and training employees
b)
B. Avoiding risk and monitoring threats
c)
C. Knowing the enemy and knowing yourself
33.
It is the process of identifying risk, assessing its relative magnitude, and taking steps to reduce it to an acceptable level.
a)
A. Risk Mitigation
b)
B. Risk Management
c)
C. Risk Identification
34.
Cost avoidance is the financial savings from using the mitigation risk treatment strategy to implement a control and eliminate the financial ramifications of an incident.
a)
True
b)
False
35.
Cost-benefit analysis (CBA) is the formal assessment and presentation of the economic expenditures needed for a particular security control, contrasted with its projected value to the organization; also known as an economic feasibility study.
a)
True
b)
False
36.
Asset Valuation is the process of assigning financial value to information assets.
a)
True
b)
False
37.
Single Loss Expectancy (SLE) In a cost-benefit analysis, the calculated value associated with the least likely loss from an attack; the SLE is the product of the asset’s value and a random exposure factor.
a)
True
b)
False
38.
Annualized Rate of Occurrence (ARO) In a cost-benefit analysis, the expected frequency of an attack, expressed on a per-decade basis.
a)
True
b)
False
39.
Annualized Loss Expectancy (ALE) In a cost-benefit analysis, the product of the annualized rate of occurrence and total asset value, disregarding the single loss expectancy.
a)
True
b)
False
40.

What is the process of defining and specifying the long-term direction of an organization, and the allocation and acquisition of resources needed to pursue this effort?

a)
Operational management
b)
Strategic planning
c)
Risk assessment
d)
Tactical development
41.

What is the primary responsibility of the CISO in an organization?

a)
Managing IT services
b)
Ensuring customer satisfaction
c)
Creating a strategic plan for information security
d)
Handling financial audits
42.

What is the purpose of Governance, Risk Management, and Compliance (GRC) in information security?

a)
To focus solely on IT security
b)
To separate governance, risk management, and compliance efforts
c)
To integrate governance, risk management, and compliance into a unified approach
d)
To manage physical security
43.

Which term describes the actions taken by management to specify intermediate goals and objectives to achieve strategic goals, along with estimates and schedules for resource allocation?

a)
Strategic Planning
b)
Operational Planning
c)
Tactical Planning
d)
Contingency Planning
44.

Which of the following is a key goal of information security governance?

a)
Strategic alignment of InfoSec with business strategy
b)
Maximizing short-term profits
c)
Ignoring risk management
d)
Eliminating the need for IT security
45.

How does operational planning differ from tactical planning in information security?

a)
Operational planning focuses on long-term goals, while tactical planning handles day-to-day tasks.
b)
Tactical planning is broader and sets yearly objectives, while operational planning focuses on daily tasks.
c)
Operational planning manages strategic goals, while tactical planning manages employee performance.
d)
Tactical planning is used only for IT, while operational planning is used for finance.
46.

What is the role of information security governance in an organization?

a)
To only handle IT-related information security
b)
To oversee the protection of all organizational information assets
c)
To replace the IT department's function
d)
To manage only physical security risks
47.

What are non mandatory recommendations that employees may use as a reference in complying with a policy called?

a)
Policies
b)
Standards
c)
Guidelines
d)
Procedures
48.

What are detailed statements of what must be done to comply with a policy, which may be informal or part of an organization's culture?

a)
Policies
b)
Standards
c)
Guidelines
d)
Procedures
49.

Which organizational element functions like laws by dictating acceptable and unacceptable behavior, as well as the penalties for failure to comply?

a)
Policies
b)
Standards
c)
Guidelines
d)
Procedures
50.

What is the primary purpose of an information security policy?

a)
To restrict employees from using technology
b)
To provide written instructions from management about proper behavior concerning information and assets
c)
To control access to the workplace
d)
To provide legal guidelines for external vendors
51.

What is the primary role of an Enterprise Information Security Policy (EISP)?

a)
To define specific procedures for system maintenance
b)
To set the strategic direction, scope, and tone for all of an organization's security efforts
c)
To outline individual user responsibilities and conduct
d)
To detail technical specifications for security controls
52.

Which type of policy provides detailed, targeted guidance to instruct all members of the organization in the use of a resource, such as one of its processes or technologies?

a)
Enterprise Information Security Policy (EISP)
b)
System-Specific Security Policy (SysSP)
c)
Security Program Policy
d)
Issue-Specific Security Policy (ISSP)
53.

What is the term for a list that contains details about user access, use permissions, and privileges for an organizational asset or resource, such as a file storage system or network device?

a)
Access Control List (ACL)
b)
Security Access Report
c)
Permission Management Document
d)
User Privilege Ledger
54.

Which type of policy functions as standards or procedures for configuring or maintaining systems and can be divided into managerial guidance and technical specifications?

a)
Issue-Specific Security Policy (ISSP)
b)
Enterprise Information Security Policy (EISP)
c)
Security Awareness Policy
d)
System-Specific Security Policy (SysSP)
55.

What is the primary goal of a Security Education, Training, and Awareness (SETA) program?

a)
To reduce the number of IT staff needed for security
b)
To improve employee awareness, skills, and knowledge regarding information security
c)
To increase the complexity of security protocols
d)
To implement more firewalls and antivirus software
56.

Who is primarily responsible for implementing and managing the SETA program in an organization?

a)
Chief Executive Officer (CEO)
b)
Human Resources (HR) Manager
c)
IT Support Team
d)
Chief Information Security Officer (CISO)
57.

What are the three elements of the SETA program?

a)
Security audits, training, and system management
b)
Security policies, risk assessment, and compliance
c)
Security education, security training, and security awareness
d)
Security infrastructure, development, and awareness
58.

Which of the following is true about security training for employees?

a)
Security training provides detailed information and hands-on instruction to prepare employees to perform their duties securely.
b)
Security training must always be outsourced to professional agencies.
c)
Industry training conferences and programs offered by agencies like SANS, (ISC), and ISSA are not useful for continuing education.
d)
Formal training programs are unnecessary if employees attend technical industry conferences.
59.

Which of the following is an example of a Security Awareness activity?

a)
A poster reminding employees not to open suspicious emails
b)
A course on how to build secure applications
c)
A hands-on workshop on using encryption software
d)
A seminar explaining the organization’s security framework
60.

What serves as the plan and foundation for the design, selection, and implementation of all elements in a security program, including policies, risk management, education, training, technological controls, and program maintenance?

a)
Risk Management Framework
b)
Information Security Blueprint
c)
Systems-Specific Security Policy (SysSP)
d)
Security Awareness Program
61.

What refers to a well-recognized information security framework, typically promoted by a government agency, standards organization, or industry group?

a)
Information Security Policy
b)
Risk Management Framework
c)
Information Security Model
d)
Security Awareness Program
62.

What term refers to a specification of a model to be followed during the design, selection, and implementation of all security controls, including policies, education, training programs, and technological controls?

a)
Risk Management Framework
b)
Information Security Blueprint
c)
Information Security Framework
d)
Security Domain
63.

Which of the following levels of control focuses on tactical and technical implementations of security, such as identification, authentication, authorization, accountability, cryptography, and asset classification?

a)
Managerial controls
b)
Operational controls
c)
Technical controls
d)
Strategic controls
64.

Which level of control is responsible for setting the direction and scope of the security process, including risk management and legal compliance?

a)
Managerial controls
b)
Operational controls
c)
Technical controls
d)
Administrative controls
65.

Which level of control focuses on personnel security, physical security, and the development of education, training, and awareness programs?

a)
Technical controls
b)
Operational controls
c)
Managerial controls
d)
Compliance controls
66.

What term refers to a strategy for protecting information assets by using multiple layers and different types of controls for optimal protection?

a)
Security Perimeter
b)
Defense in Depth
c)
Redundancy
d)
Risk Management
67.

Which of the following refers to the use of multiple types and instances of technology to ensure that the failure of one system does not compromise information security?

a)
Redundancy
b)
Defense in Depth
c)
Security Perimeter
d)
Incident Response
68.

What term describes the boundary within a network where an organization maintains security controls to protect against threats from untrusted network areas?

a)
Defense in Depth
b)
Risk Management Framework
c)
Security Perimeter
d)
Redundancy
69.

What is an area of trust within which information assets share the same level of protection, and where communication between these areas requires evaluation of communication traffic?

a)
Security Domain
b)
Security Perimeter
c)
Defense in Depth
d)
Risk Management Zone
70.

A company is migrating its data to a cloud service provider. The IT department is responsible for ensuring that sensitive information remains secure during and after the migration. What is a critical consideration when selecting a cloud service provider?

a)

The provider's marketing strategy

b)

The provider’s compliance with relevant regulations (e.g., GDPR, HIPAA)

c)

The provider's pricing model

d)

The provider's customer support rating