WorksheetsIT311
Total questions: 70
Worksheet time: 35mins
Which category of threat involves events such as earthquakes and floods?
What is the primary focus of Information Security Threats as defined in the book?
Which of the following is NOT classified as an Information Security Attack according to the book?
Which type of attack is characterized by overwhelming a system to prevent legitimate access?
Which category of threats includes errors made by employees or users?
Which threat category could be caused by a power outage?
Phishing attacks typically target which aspect of security?
Which of the following is a key feature of a Denial of Service (DoS) attack?
Which attack involves tricking users into providing sensitive information through deceptive means?
Natural Disasters are considered part of the Technical Failures threat category.
Human Error can include mistakes made during data entry or system configuration.
A Data Breach involves unauthorized access to sensitive information.
Ransomware is a type of malware that demands payment in exchange for restoring access to encrypted data.
SQL Injection attacks are designed to exploit weaknesses in physical security measures.
Denial of Service (DoS) attacks aim to disrupt the normal functioning of a service or network.
Technical Failures are threats that arise from human interactions with systems.
Phishing attacks can be carried out via email or fraudulent websites.
Social Engineering is classified under Cyber Attacks as it involves manipulating people rather than systems.
Data Tampering is an example of an Information Security Threat.
What is the process of defining and specifying the long-term direction of an organization, and the allocation and acquisition of resources needed to pursue this effort?
What is the primary responsibility of the CISO in an organization?
What is the purpose of Governance, Risk Management, and Compliance (GRC) in information security?
Which term describes the actions taken by management to specify intermediate goals and objectives to achieve strategic goals, along with estimates and schedules for resource allocation?
Which of the following is a key goal of information security governance?
How does operational planning differ from tactical planning in information security?
What is the role of information security governance in an organization?
What are non mandatory recommendations that employees may use as a reference in complying with a policy called?
What are detailed statements of what must be done to comply with a policy, which may be informal or part of an organization's culture?
Which organizational element functions like laws by dictating acceptable and unacceptable behavior, as well as the penalties for failure to comply?
What is the primary purpose of an information security policy?
What is the primary role of an Enterprise Information Security Policy (EISP)?
Which type of policy provides detailed, targeted guidance to instruct all members of the organization in the use of a resource, such as one of its processes or technologies?
What is the term for a list that contains details about user access, use permissions, and privileges for an organizational asset or resource, such as a file storage system or network device?
Which type of policy functions as standards or procedures for configuring or maintaining systems and can be divided into managerial guidance and technical specifications?
What is the primary goal of a Security Education, Training, and Awareness (SETA) program?
Who is primarily responsible for implementing and managing the SETA program in an organization?
What are the three elements of the SETA program?
Which of the following is true about security training for employees?
Which of the following is an example of a Security Awareness activity?
What serves as the plan and foundation for the design, selection, and implementation of all elements in a security program, including policies, risk management, education, training, technological controls, and program maintenance?
What refers to a well-recognized information security framework, typically promoted by a government agency, standards organization, or industry group?
What term refers to a specification of a model to be followed during the design, selection, and implementation of all security controls, including policies, education, training programs, and technological controls?
Which of the following levels of control focuses on tactical and technical implementations of security, such as identification, authentication, authorization, accountability, cryptography, and asset classification?
Which level of control is responsible for setting the direction and scope of the security process, including risk management and legal compliance?
Which level of control focuses on personnel security, physical security, and the development of education, training, and awareness programs?
What term refers to a strategy for protecting information assets by using multiple layers and different types of controls for optimal protection?
Which of the following refers to the use of multiple types and instances of technology to ensure that the failure of one system does not compromise information security?
What term describes the boundary within a network where an organization maintains security controls to protect against threats from untrusted network areas?
What is an area of trust within which information assets share the same level of protection, and where communication between these areas requires evaluation of communication traffic?
A company is migrating its data to a cloud service provider. The IT department is responsible for ensuring that sensitive information remains secure during and after the migration. What is a critical consideration when selecting a cloud service provider?
The provider's marketing strategy
The provider’s compliance with relevant regulations (e.g., GDPR, HIPAA)
The provider's pricing model
The provider's customer support rating
