wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Physical Security, Disruption/Deception Tech + 2024

Total questions: 56

Worksheet time: 28mins

Name
Class
Date
1.

What is the purpose of a mantrap in physical security?

a)

To trap malicious users caught in sensitive areas

b)

To get people on camera

c)

To allow easy entry for emergency services

d)

To control access to sensitive systems, areas, and information

2.

Which of the following is NOT a type of biometric authentication?

a)

Fingerprint scan

b)

Iris recognition

c)

Key card (RFID)

d)

Facial recognition

3.

What is a primary function of video surveillance (CCTV) in physical security?

a)

To monitor employee performance

b)

To detect environmental hazards

c)

To observe and record activities around secure areas

d)

To control access to sensitive information

4.

Which type of access control system uses physical characteristics to grant access?

a)

Keycard

b)

PIN code

c)

Biometrics

d)

Security guard

5.

Which component of physical security is responsible for tracking the distribution and use of keys?

a)

Video Surveillance

b)

Key Management

c)

Security Guards

d)

Alarms

6.

What is the main function of environmental controls in a physical security plan?

a)

To provide authentication for access

b)

To protect against fire and flooding

c)

To monitor employee behavior

d)

o restrict access to unauthorized users

7.

What type of lock system allows only authorized personnel to enter a secure area after an authentication process?

a)

Mechanical lock

b)

Electronic lock

c)

Deadbolt

d)

Combination lock

8.

What is the role of security guards in a physical security strategy?

a)

To manage access control systems

b)

To monitor surveillance footage

c)

To enforce security policies and respond to incidents

d)

To conduct audits of security measures

9.

Which of the following is an example of a physical barrier in security?

a)

Password protection

b)

Video surveillance

c)

Fences and walls

d)

Security policies

10.

What should be done to mitigate internal threats to physical security?

a)

Provide unrestricted access to all employees

b)

Implement strict access controls and monitoring

c)

Rely solely on video surveillance

d)

Reduce the number of security guards

11.

What is the main purpose of an alarm system in a physical security framework?

a)

To provide access control

b)

To deter potential intruders

c)

To alert security personnel to unauthorized access or environmental threats

d)

To monitor employee productivity

12.

Which component is primarily responsible for ensuring the secure storage of sensitive information?

a)

Alarms

b)

Security Guards

c)

Access Control

d)

Environmental Controls

13.

What type of physical security measure requires individuals to present an ID badge to enter a secure area?

a)

Security Guards

b)

Biometrics

c)

Access Control

d)

Locks

14.

Which of the following describes a situation that may trigger an alarm in a secure facility?

a)

A scheduled maintenance visit

b)

A power outage

c)

Unauthorized entry through a restricted door

d)

Employees exiting the building

15.

What is the purpose of a security audit in physical security?

a)

To collect user data

b)

To assess and improve security measures

c)

To reduce security staff

d)

To install surveillance cameras

16.

Which physical security measure can help prevent unauthorized access to a server room?

a)

Fire extinguishers

b)

Mantraps

c)

Employee training

d)

Office signage

17.

In what way can climate control systems contribute to physical security?

a)

They restrict access to sensitive areas.

b)

They prevent equipment failure due to environmental conditions.

c)

They monitor employee behavior.

d)

They assist in identifying internal threats.

18.

Which component of physical security helps deter theft and vandalism in high-risk areas?

a)

Security Guards

b)

Access Control Systems

c)

Video Surveillance

d)

All of the above

19.

What type of security is specifically aimed at protecting the physical assets of an organization?

a)

Internet security

b)

Information security

c)

Physical security

d)

Application security

20.

Which of the following measures is least effective for protecting against environmental threats?

a)

Fire suppression systems

b)

Key management policies

c)

Flood barriers

d)

Climate control systems

21.

What is the primary goal of using deception technologies in cybersecurity?

a)

To secure sensitive data

b)

To mislead attackers and gather intelligence

c)

To replace traditional security measures

d)

To enhance employee productivity

22.

What is a honeypot?

a)

A physical barrier for unauthorized access

b)

A decoy system designed to lure and analyze attackers

c)

A video surveillance system

d)

A type of environmental control

23.

What type of data can honeytokens be?

a)

Real user credentials

b)

Fake data used to detect unauthorized access

c)

Employee performance metrics

d)

Backup system configurations

24.

Which of the following best describes a honeynet?

a)

A single decoy system

b)

A network of honeypots designed to gather intelligence on attackers

c)

A data backup solution

d)

A security guard monitoring system

25.

What is the primary function of a honeyfile?

a)

To provide secure storage for sensitive data

b)

To serve as a decoy file that alerts when accessed by attackers

c)

To track employee access to sensitive areas

d)

To backup important documents

26.

Why are deception technologies important in cybersecurity?

a)

They eliminate the need for physical security.

b)

They provide a real-time defense against malware.

c)

They help detect and analyze attacker behavior.

d)

They replace traditional firewalls.

27.

Which of the following is NOT a characteristic of a honeypot?

a)

It mimics real systems.

b)

It is heavily monitored.

c)

It has high production value.

d)

It collects logs of attacker interactions.

28.

What is the primary advantage of using a honeynet over a single honeypot?

a)

Easier to manage

b)

More comprehensive data collection

c)

Lower cost

d)

Simpler to deploy

29.

What is the primary advantage of using a honeynet over a single honeypot?

a)

Easier to manage

b)

More comprehensive data collection

c)

Lower cost

d)

Simpler to deploy

30.

What should be the primary focus when designing a honeytoken?

a)

Complexity of the data

b)

Realism of the data

c)

Volume of data

d)

Security of real data

31.

Which scenario best illustrates the use of deception technologies?

a)

An organization uses firewalls to block intrusions.

b)

A company sets up fake login pages to capture attacker information.

c)

Employees receive training on phishing attacks.

d)

Antivirus software is installed on all systems.

32.

What is a primary use of honeyfiles in a security strategy?

a)

To provide secure access to files

b)

To distract attackers from real data

c)

To enhance employee productivity

d)

To serve as backup storage

33.

Which of the following best describes the concept of “deception” in cybersecurity?

a)

Using advanced encryption methods

b)

Implementing strict access controls

c)

Misleading attackers to reveal their techniques

d)

Creating complex passwords for all systems

34.

What are the ethical considerations associated with deploying deception technologies?

a)

Risk of harming legitimate users

b)

Increased workload for IT staff

c)

Higher costs for implementation

d)

Legal implications of data capture

35.

Which type of information can organizations gather from analyzing honeypot interactions?

a)

Employee performance metrics

b)

Trends in attacker behavior and tactics

c)

Customer satisfaction data

d)

Hardware inventory

36.

What is one potential drawback of using honeypots in a security strategy?

a)

They can provide valuable data on attacks.

b)

They may require significant resources to manage.

c)

They are easy to set up and maintain.

d)

They are always effective against all types of attacks.

37.

What can trigger an alert when a honeytoken is accessed?

a)

An employee opening a legitimate file

b)

A scheduled software update

c)

Unauthorized access to fake credentials

d)

Normal system maintenance

38.

In which scenario would a honeypot be most effective?

a)

Protecting against natural disasters

b)

Detecting insider threats

c)

Luring external attackers to study their methods

d)

Monitoring employee productivity

39.

What is a significant benefit of utilizing honeytokens in an organization?

a)

They eliminate the need for user training.

b)

They provide a way to detect unauthorized access.

c)

They enhance physical security measures.

d)

They can replace traditional firewalls.

40.

What distinguishes a honeypot from a standard network device?

a)

Honeypots are designed to provide real services.

b)

Honeypots collect data on unauthorized access attempts.

c)

Honeypots require complex user authentication.

d)

Honeypots cannot be monitored remotely.

41.

What is the primary purpose of a honeytoken within an organization?

a)

To authenticate user identities

b)

To monitor employee productivity

c)

To detect unauthorized access through fake data

d)

To enhance backup solutions

42.

Which of the following is the first step in conducting a Gap Analysis?

a)

Create an action plan

b)

Define the target state

c)

Assess the current state

d)

Identify risks

43.

A company conducts a Gap Analysis and finds that its password policies are not aligned with industry standards. What should be the next step?

a)

Patch outdated software

b)

Conduct a vulnerability scan

c)

Update the password policy

d)

Remove all administrator accounts

44.

Why is monitoring and reviewing the effectiveness of solutions important after completing a Gap Analysis?

a)

To identify potential internal threats

b)

To ensure gaps do not reoccur

c)

To prevent data breaches

d)

To lower the cost of compliance

45.

How does Gap Analysis contribute to risk management?

a)

It reduces the need for encryption

b)

It ensures data is always available

c)

It identifies vulnerabilities and compliance issues

d)

It automatically patches security flaws

46.

The core principle of the Zero Trust model is:

a)

Trust but verify

b)

Implicit trust of internal networks

c)

Never trust, always verify

d)

Minimal encryption

47.

Zero Trust applies to which of the following areas of cybersecurity?

a)

Network security only

b)

User identity only

c)

All areas: users, devices, networks, applications, and data

d)

Physical security only

48.

Which of the following technologies would best support a Zero Trust model?

a)

Anti-virus software

b)

Firewall

c)

Multi-Factor Authentication (MFA)

d)

Single-factor password authentication

49.

What does Non-Repudiation ensure in a communication or transaction?

a)

That sensitive information is accessed only by authorized individuals.

b)

That information remains unaltered and accurate.

c)

That both the sender of a message and the recipient cannot deny having sent or received the message.

d)

That systems and data are accessible when needed.

50.

What is a digital signature used for in the context of Non-Repudiation?

a)

To verify the authenticity and integrity of a message or document.

b)

To encrypt sensitive information.

c)

To ensure systems and data are accessible when needed.

d)

To create backups of important data.

51.

How does non-repudiation support integrity?

a)

By encrypting data

b)

By using digital signatures and hashing mechanisms

c)

By marking the time of actions

d)

By verifying the sender's identity

52.

What is the purpose of the AAA security concept?

a)

To encrypt data

b)

To provide a framework for controlling access to resources and tracking user activities

c)

To ensure data availability

d)

To prevent data breaches

53.

Which of the following is a primary function of the AAA framework in cybersecurity?

a)

Authentication of users

b)

Data backup

c)

Firewall configuration

d)

System updates

54.

Which of the following is a primary goal of the CIA triad?

a)

To ensure data is encrypted

b)

To ensure data is only accessible to authorized users

c)

To ensure data is backed up regularly

d)

To ensure data is shared widely

55.

Which of the following is the best example of a loss of Availability?

a)

Unauthorized access to sensitive data

b)

Data being modified without permission

c)

Denial of Service (DoS) attack on a web server

d)

Sensitive data being encrypted using strong algorithms

56.

What method can be used to ensure Availability in the event of a natural disaster?

a)

Public-key cryptography

b)

Offsite backups

c)

Strong password policies

d)

Integrity checks