wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

IAS REVIEW

Total questions: 60

Worksheet time: 30mins

Name
Class
Date
1.
Which of the following is not part of the CIA triad in security objectives?
a)
Confidentiality
b)
Integrity
c)
Accessibility
d)
Availability
2.
What is the primary purpose of security objectives?
a)
To provide encryption methods
b)
To define security attacks
c)
To ensure the confidentiality, integrity, and availability of data
d)
To manage network traffic
3.
What does confidentiality ensure in terms of data?
a)
Data is encrypted at all times
b)
Information is not disclosed to unauthorized entities
c)
Only specific files are available to users
d)
Systems perform their intended functions
4.
Which term refers to ensuring that data is only changed in an authorized manner?
a)
Data integrity
b)
System integrity
c)
Data authenticity
d)
Nonrepudiation
5.
What does system integrity ensure?
a)
Data is encrypted before transmission
b)
The system performs its intended function without unauthorized interference
c)
Users are authenticated before accessing the system
d)
Messages are received as sent
6.
Which of the following describes availability in the context of security?
a)
Ensures data is not modified
b)
Prevents unauthorized disclosure of information
c)
Ensures that systems work promptly and services are not denied to authorized users
d)
Traces all system actions to a responsible entity
7.
What is authenticity concerned with in a security system?
a)
Data confidentiality
b)
Verifying that users are who they claim to be
c)
Detecting passive attacks
d)
System accessibility
8.
Accountability supports all of the following except:
a)
Intrusion detection
b)
Nonrepudiation
c)
Fault isolation
d)
Data encryption
9.
Which of the following attacks involves eavesdropping on communications?
a)
Replay attack
b)
Passive attack
c)
Denial-of-service
d)
Masquerade
10.
What is the goal of a passive attack?
a)
To prevent access to a service
b)
To modify the contents of a message
c)
To obtain transmitted information without altering it
d)
To block network access
11.
Which security method is best for preventing passive attacks?
a)
Message reordering
b)
Strong encryption
c)
Masquerading
d)
Fault isolation
12.
An attacker who captures and retransmits a data packet to produce unauthorized effects is performing which type of attack?
a)
Masquerade
b)
Replay
c)
Traffic analysis
d)
Denial-of-service
13.
Which of the following is an example of an active attack?
a)
Eavesdropping on an email conversation
b)
Delaying a message to cause disruption
c)
Monitoring communication for metadata
d)
Observing network traffic patterns
14.
Which type of active attack involves pretending to be another entity?
a)
Replay
b)
Modification of messages
c)
Masquerade
d)
Denial-of-service
15.
What is a denial-of-service attack aimed at?
a)
Gaining unauthorized access to files
b)
Preventing the normal use of communication facilities
c)
Monitoring encrypted messages
d)
Modifying legitimate messages
16.
Which security service ensures that a message is truly from the source it claims to be?
a)
Authentication service
b)
Data confidentiality
c)
Access control
d)
Nonrepudiation
17.
Which of the following controls access to systems and applications?
a)
Data confidentiality
b)
Access control
c)
Nonrepudiation
d)
Integrity service
18.
Data integrity is concerned with preventing all of the following except:
a)
Message duplication
b)
Unauthorized message reordering
c)
Unauthorized message modification
d)
Encrypted message content
19.
Which of these services prevents a sender or receiver from denying a transmitted message?
a)
Authentication
b)
Nonrepudiation
c)
Availability
d)
Integrity
20.
What does the availability service ensure?
a)
Data is always encrypted
b)
System resources are accessible upon demand by authorized users
c)
Only authenticated users can access data
d)
System breaches are always recorded
21.
Which of these attacks attempts to prevent access to a particular network destination?
a)
Denial-of-service
b)
Replay
c)
Traffic analysis
d)
Masquerade
22.
Which attack involves monitoring the content of messages without altering them?
a)
Replay
b)
Traffic analysis
c)
Release of message contents
d)
Denial-of-service
23.
What is a key characteristic of passive attacks?
a)
They modify data in transit
b)
They are easily detected
c)
They occur without altering the data
d)
They prevent system access
24.
Which attack involves changing the contents of a legitimate message?
a)
Modification of messages
b)
Traffic analysis
c)
Masquerade
d)
Denial-of-service
25.
What service ensures that information is modified only by authorized persons?
a)
Availability
b)
Data integrity
c)
Access control
d)
Authentication
26.
What does online privacy primarily refer to?
a)
Privacy concerns related to personal communication
b)
Privacy concerns related to user interaction with Internet services
c)
Privacy concerns related to hardware devices
d)
Privacy concerns related to financial transactions
27.
Which of the following is an example of explicit information collection by websites?
a)
Cookies
b)
Tracking technologies
c)
Registration pages
d)
Browser settings
28.
What are data brokers known for?
a)
Compiling large amounts of personal data and selling it to other data users
b)
Protecting data from cyberattacks
c)
Collecting information directly from consumers
d)
Securing network connections for businesses
29.
Which of these is a typical source of information for data brokers?
a)
Security audits
b)
Network encryption data
c)
Public records and loyalty card programs
d)
ISP traffic logs
30.
What is a primary security concern for web-based services?
a)
Misconfigured mobile devices
b)
Untrained users unaware of security risks
c)
Lack of firewall protection
d)
Low bandwidth availability
31.
Which type of security issue involves vulnerabilities and threats associated with the platform that hosts a website?
a)
Web server security
b)
Web browser security
c)
Web application security
d)
Network security
32.
Which of the following describes the role of public app stores?
a)
To provide software licenses to enterprises
b)
To ensure that apps are free of malware and do not cause unwanted behavior
c)
To secure network connections
d)
To restrict access to online services
33.
What is the role of an enterprise mobility management system?
a)
To restrict access to cloud-based services
b)
To manage mobile devices and their components within an organization
c)
To track the location of mobile devices
d)
To enforce browser security policies
34.
What does the app vetting process begin with?
a)
The deployment of apps
b)
Acquiring an app from a public or enterprise store
c)
Assigning apps to users
d)
Running data security checks
35.
Who is responsible for ensuring that installed apps conform to an organization’s security requirements?
a)
Administrator
b)
Data broker
c)
Client user
d)
Security auditor
36.
What is a key responsibility of an auditor in the app vetting process?
a)
Fixing malware in the app
b)
Reviewing security reports and risk assessments
c)
Deploying apps on all devices
d)
Managing network traffic
37.
Which of these privacy threats is associated with failing to promptly delete personal data after its intended use?
a)
User-side data leakage
b)
Non-transparent policies
c)
Insufficient deletion of personal data
d)
Outdated personal data
38.
Which of the following is a privacy risk related to the sharing of data without user consent?
a)
Collection of data not required for the primary purpose
b)
Sharing of data with a third party
c)
User-side data leakage
d)
Non-transparent policies
39.
What is the main concern with insecure data transfer?
a)
Loss of session data
b)
Transmission over unsecured channels leading to potential data leaks
c)
Access to outdated data
d)
Insufficient deletion of files
40.
Which of these is a privacy risk in web applications due to vulnerability issues?
a)
Insufficient data breach response
b)
Web application vulnerabilities
c)
Outdated personal data
d)
Insecure browser settings
41.
What is the main risk of using third-party app stores?
a)
Limited availability of apps
b)
Uncertainty about malware presence in apps
c)
High costs of app downloads
d)
Compatibility issues
42.
Which threat involves the failure to inform affected persons about a data breach?
a)
Insecure network communications
b)
Outdated personal data
c)
Insufficient data breach response
d)
Non-transparent policies
43.
Which issue arises when descriptive data not needed for the primary purpose is collected?
a)
Insecure data storage
b)
Inappropriate user authentication
c)
Collection of data not required for the primary purpose
d)
Insufficient encryption
44.
What should mobile apps do to prevent man-in-the-middle attacks?
a)
Encrypt network communications
b)
Implement outdated libraries
c)
Disable browser extensions
d)
Use untested code
45.
Why are third-party software libraries a concern for mobile app security?
a)
They increase app size
b)
They may introduce vulnerabilities affecting multiple apps
c)
They are difficult to install
d)
They cannot be updated
46.
What is the purpose of non-transparent policies?
a)
To mislead users
b)
To prevent data access
c)
To withhold information on data collection, processing, and storage
d)
To control network access
47.
Which security category focuses on vulnerabilities associated with applications accessible via the Web?
a)
Web server security
b)
Web application security
c)
Web browser security
d)
Physical security
48.
Which ecosystem element involves managing policies and monitoring device state in a business?
a)
Device and OS vendor infrastructure
b)
Enterprise mobility management systems
c)
Public application stores
d)
User-side management
49.
What type of communication infrastructure is typically used by modern mobile devices?
a)
Ethernet networks
b)
Cellular and Wi-Fi networks
c)
Satellite communications
d)
Optical fiber networks
50.
What is one method to prevent insecure data transfer in mobile apps?
a)
Using VPNs and encryption
b)
Collecting user feedback
c)
Limiting app downloads
d)
Updating device firmware
51.
A company has been experiencing an increase in data breaches from employees using unsecured Wi-Fi networks while working remotely. Which method would be most effective in preventing passive attacks like eavesdropping on their communications?
a)
Require all employees to use stronger passwords
b)
Encrypt all network communications and use VPNs
c)
Limit access to the company’s web server during non-business hours
d)
Encourage employees to use public Wi-Fi cautiously
52.
You are tasked with securing a web server that your company uses to host a public-facing website. What would be the most appropriate focus area to ensure that no vulnerabilities can be exploited by attackers?
a)
Secure the web application code only
b)
Regularly update the browser on your client computers
c)
Strengthen the security of the web server platform, including the OS and database system
d)
Restrict access to the company’s Wi-Fi
53.
Your team is developing a mobile app that stores sensitive customer data. To prevent man-in-the-middle attacks during data transmission, which action should your team prioritize?
a)
Avoid using third-party libraries
b)
Implement session expiration mechanisms
c)
Encrypt network communications and authenticate the remote server
d)
Ensure that personal data is deleted after its intended use
54.
A company finds that its employees are accidentally leaking sensitive customer data by accessing unsecured websites while on company computers. As the IT manager, what is the first step you should take to prevent user-side data leakage?
a)
Provide training on securing browser settings
b)
Implement stronger web application security measures
c)
Install tracking cookies on all employee devices
d)
Introduce policies for strict encryption and secure data handling
55.
During a security audit, it was discovered that a web application vulnerability allowed unauthorized users to access confidential user data. Which action would best resolve this issue?
a)
Encrypt all traffic between the client and server
b)
Implement access control measures on the web server
c)
Update the app with a security patch to fix the vulnerability
d)
Introduce new features to enhance user experience
56.
A malicious user captures and retransmits a data packet in order to gain unauthorized access to a system. What type of attack is this, and how can you best prevent it?
a)
Replay attack; implement strong encryption and session management
b)
Masquerade attack; verify user credentials frequently
c)
Traffic analysis; install firewalls
d)
Denial-of-service attack; increase server bandwidth
57.
A mobile application from a third-party developer is flagged for potential security risks during your company's app vetting process. What should the app administrator do before approving the app for deployment?
a)
Skip the vetting process and approve it for a trial period
b)
Request an updated version from the developer and approve it immediately
c)
Submit the app to the testing facility for a thorough security analysis
d)
Deploy the app on select devices for feedback
58.
Your organization has been alerted that outdated customer data has led to inaccurate reports and potential privacy violations. Which action should you take to prevent future issues?
a)
Encrypt the data transmission
b)
Regularly update customer data and implement a policy for prompt deletion of outdated information
c)
Strengthen session expiration protocols
d)
Limit third-party access to the web server
59.
A business wants to ensure that users have full transparency regarding how their personal data is collected and used. What should the company implement to address this issue?
a)
Share data collection details only with authorized users
b)
Develop clear and easily understandable policies, terms, and conditions
c)
Use encryption on all client-side data
d)
Ensure the deletion of personal data after use
60.
Your company’s web server has been compromised, allowing an attacker to access data from the connected database. Which type of attack does this represent, and what should be your next course of action?
a)
Masquerade attack; block the attacker’s IP address
b)
Denial-of-service attack; increase server capacity
c)
Web server attack; strengthen server and database security
d)
Traffic analysis; monitor all future communications