wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Infasec Reviewer

Total questions: 56

Worksheet time: 42mins

Name
Class
Date
1.

Includes acts performed without intent or malicious purpose

(a)  

2.

is far more sophisticated and potentially much faster password attack is possible if the attacker can gain access to an encrypted password file, such as the Security Account Manager (SAM) data file.

(a)  

3.

Malware payload that provides access to a system by bypasssing normal access controls

(a)  

4.

is a long term increase in electrical power availability

(a)  

5.

is a software program or hardware appliance that can intercept, copy, and interpret network traffic.

(a)  

6.

is an alert or alarm that occurs in the absence of an actual attack

(a)  

7.

Competitive Intelligence is the collection and analysis of information about an organization's competitors through illegal means.

a)

True

b)

False

8.

The top-down approach has a higher probability of success.

a)

True

b)

False

9.

is the probability of an unwanted occurrence, such as an adverse event or loss.

(a)  

10.

is a collection of related data stored in structure form.

(a)  

11.

The classic perpetrator of espionage or trespass is the (a)   who is frequently

glamorized in fictional accounts as a person who stealthily manipulates a maze of computer

networks, systems, and data to find information that solves the mystery and heroically saves

the day.

12.

is a category of entities or circumstances that poses a potential danger to an asset.

(a)  

13.

is abstract in nature and concerned with the management of perceptions of a target.

(a)  

14.

is a long term interruption in electric power availability.

(a)  

15.

A technique used to compromise a system.

(a)  

16.

Security mechanisms, policies, or

procedures that can successfully counter

attacks, reduce risk, resolve

vulnerabilities, and otherwise improve

security within an organization.

(a)  

17.

The entire set of controls and safeguards,

including policy, education, training and

awareness, and technology, that the

organization implements to protect the

asset.

(a)  

18.

An intentional or unintentional act that

can damage or otherwise compromise

information and the systems that support

it.

(a)  

19.

is a set of practices intended to keep data secure from unauthorized access or alterations, both when it's being stored and when it's being transmitted from one machine or physical location to another.

(a)  

20.

is a subset of information security that focuses on the assessment and protection of information stored in data repositories.

(a)  

21.

Large quantities of computer code are written, debugged, published, and sold after all their

bugs are detected and resolved.

a)

True

b)

False

22.

A mail bomb is a undesired email typically commercial advertising sent in bulk.

a)

True

b)

False

23.

Information security is the protection of all media, technology, and content.

a)

True

b)

False

24.

It is about protecting your information assets from destruction, degradation, manipulation and exploitation

by an opponent.

a)

ISO

b)

IA

c)

IAS

d)

IO

25.

Antiquated or Outdated infrastructure can lead to unreliable and untrustworthy systems.

a)

True

b)

False

26.

The three communities of interest: general management, IT management, and physical

security management

a)

True

b)

False

27.

Physical Theft can be controlled easily using a wide variety of measures, from locked doors to trained security personnel, and installation of alarm systems.

a)

True

b)

False

28.

A Trusted VPN, also known as legacy VPN, uses leased circuits from a service provider and conducts packet...

a)

True

b)

False

29.

Secure VPNs, uses security protocols like IPsec to encrypt traffic, transmitted across unsecured network.

a)

True

b)

False

30.

A network IDPS monitors and analyzes wireless network traffic

a)

True

b)

False

31.

A network based IDPS (NIDPS) consists of a specialized hardware appliance and/or software designed.

a)

True

b)

False

32.

Scanning tools are typically used as part of an attack protocol to collect information that an attacker needs.

a)

True

b)

False

33.

Modification of an asset means that some unauthorized party tampers with the asset

a)

True

b)

False

34.

it is an occurence of an event caused by a threat agent

(a)  

35.

Threat event is a category of objects, people, or other entities that represents the origin of danger to an asset- in other words, a category of threat agents.

a)

True

b)

False

36.

The HMG Strategy for IA defines it as: Actions taken that protect and defend information and information

systems by ensuring their availability, integrity, authentication, confidentiality and nonrepudiation. This

includes providing for restoration of information systems by incorporating protection, detection and

reaction capabilities.

a)

True

b)

False

37.

The growth of the Internet currently allows organisations around the globe to communicate with each other

in ways that were not previously heard of.

a)

True

b)

False

38.

Many organizations create or support the development of intellectual property (IP) as part of

their business operations.

a)

True

b)

False

39.

Attack protocls are tools that can either perform generic scans or those for specific types.

a)

True

b)

False

40.

Any business, educational institution, or government agency that operates within the modern

context of connected and responsive services does not rely on information systems.

a)

True

b)

False

41.

The confidentiality of information is the quality or state of ownership or control.

a)

True

b)

False

42.

It is the preservation of confidentiality, integrity, and availability of information

a)

Information Operations

b)

Information Assurance

c)

Information Assets

d)

Information Security

43.

Footprinting refers to the activities that scan network locales for active systems and then identify the network services offered by the host systems.

a)

True

b)

False

44.

An IDPS is capable of interdirecting the attack by itself, without human intervention. This could be accomplished by:

a)

Terminating the user session or network connection

b)

Blocking Access to the target system or system

c)

Blocking all access to the targeted infromation

d)

Gives Contractual assurance thta no one else is allowed to use

e)

Can set up tunneling points across the internet

45.

An information asset of the system becomes unusable, unavailable or lost.

a)

Interruption

b)

Fabrication

c)

Modification

d)

Interception

46.

Information assurance is sometimes referred to as information operations (10s) that protect and defend

information systems by ensuring their:

a)

Availability

b)

Integrity

c)

Authentication

d)

Confidentiality

e)

Non-repudiation

47.

is the process of adjusting an IDPS to maximize its efficiency in detecting true positives, while minimizing both false positives and false negatives.

(a)  

48.

are items or fact collected by an organization

(a)  

49.

It is often the most valuable asset of an

organization and therefore is the main

target of intentional attacks.

(a)  

50.

It is often overlooked in computer

security considerations, it have always

been a threat to information security.

(a)  

51.

It is the IS component that created much

of the need for increased computer and

information security.

(a)  

52.

These are written instructions for

accomplishing a specific task.

(a)  

53.

can include legal activities, such as marketing and advertising, and illegal activities such as espionage and hacking. Information operations are performed in the context of a strategy that has a desired objective (or end state) that may be achieved by influencing a target (the object of influence).

(a)  

54.

Wireless IDPS can detect the following types of events:

a)

Unauthorized WLANs

b)

Poorly Secured WLAN devices

c)

Unusual usage patterns

d)

The use of wireless network scanners

e)

DoS attacks and conditions

55.

In order for an information consumer to acquire information it has to know:

a)

Why use only one source of information in its decision-making proce

b)

Where that information can be obtained

c)

What information has been validated

d)

How much the consumer is to pay to obtain that information

e)

Who should attempt to validate that information

56.

Information security performs important functions for an organization:

a)

Ensuring that information assets remain safe and useful.

b)

Protecting the data and information the organization collects and uses, whether physical

or electronic

c)

Protecting the organization's ability to function

d)

Enabling the safe operation of applications running on the organization's IT systems

e)

Safeguarding the organization's business reputation