wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Information Security Quiz

Total questions: 57

Worksheet time: 29mins

Name
Class
Date
1.

NIST 800-171 focuses on securing __________ in non-federal systems and organizations.

a)

controlled unclassified information

b)

publicly available information

c)

classified information

d)

personal identifiable information

2.

Defense in Depth is a security strategy that involves __________ layers of defense to protect an organization's assets.

a)

multiple

b)

single

c)

no

d)

few

3.

Acceptable Use Policy (AUP) defines the __________ behavior for personnel regarding the use of the organization's resources.

a)

acceptable

b)

unacceptable

c)

optional

d)

random

4.

A Service Level Agreement (SLA) defines the __________ provided to a client, including support expectations and liability.

a)

level of service

b)

cost of service

c)

duration of contract

d)

type of client

5.

Automation is often enhanced through __________, which allows specific tasks to be performed automatically under certain conditions.

a)

conditional logic

b)

manual intervention

c)

random selection

d)

user input

6.

Scalability refers to the ability of a computing environment to gracefully fulfill its ever-increasing __________ needs.

a)

workload

b)

storage

c)

bandwidth

d)

memory

7.

Elasticity allows a computing environment to adjust its resources in response to both increasing and decreasing __________.

a)

demands

b)

costs

c)

users

d)

errors

8.

Redundancy ensures that a system has additional __________ to maintain operations in the event of a failure.

a)

backups

b)

resources

c)

components

d)

support

9.

Fault Tolerance enables a system to continue providing service despite the failure of certain __________.

a)

components in the system

b)

users of the system

c)

external networks

d)

software updates

10.

Cloud Computing refers to the delivery of computing services over the __________, offering flexibility and economies of scale.

a)

internet

b)

local network

c)

USB drive

d)

personal computer

11.

SAAS (Software as a Service) provides users with cloud-based __________ without the need for installation or maintenance.

a)

applications

b)

hardware

c)

databases

d)

networking

12.

PAAS (Platform as a Service) provides users with __________ platforms for building, testing, and deploying applications.

a)

cloud-based

b)

local

c)

desktop

d)

offline

13.

IAAS (Infrastructure as a Service) provides users access to physical or virtual computing infrastructure such as __________.

a)

servers, storage, and networking

b)

software applications

c)

user interfaces

d)

data analytics tools

14.

CapEx (Capital Expenditure) involves upfront spending on physical infrastructure, while OpEx (Operational Expenditure) involves spending on products or services as a __________ model.

a)

pay-as-you-go

b)

one-time purchase

c)

subscription

d)

lease

15.

Identity and Access Management (IAM) is a process for managing identity, __________, and authorization for organizational assets.

a)

authentication

b)

encryption

c)

networking

d)

storage

16.

Multi-Factor Authentication (MFA) enhances security by combining multiple __________ methods for access.

a)

verification

b)

authentication

c)

identification

d)

authorization

17.

Provisioning refers to the process of _________ access rights to users within a system.

a)

granting or assigning

b)

revoking

c)

monitoring

d)

denying

18.

Rule-Based Access Control (RBAC) determines access based on predefined _________ such as time of day or location.

a)

criteria

b)

users

c)

permissions

d)

roles

19.

A Retinal Scanner scans the blood vessels in the retina, which are unique and rarely change except due to _________ or injury.

a)

disease

b)

aging

c)

genetic mutation

d)

environmental factors

20.

A Common Access Card (CAC) is used by DoD personnel for secure, _________-based authentication.

a)

PKI

b)

password

c)

biometric

d)

token

21.

Active Directory (AD) is a service that stores _________ information and manages access in a networked environment.

a)

user account

b)

financial

c)

weather

d)

geographical

22.

Single Sign-On (SSO) allows users to log in once and gain access to multiple systems without needing to _________.

a)

re-enter credentials

b)

log out

c)

change passwords

d)

create new accounts

23.

Tunneling is a data transport technique that encrypts and _________ data within another data packet for secure transmission.

a)

encapsulates

b)

compresses

c)

decrypts

d)

transmits

24.

A One-Time Password is generated using an algorithm that applies a _________-based message authentication code for security.

a)

HMAC Hash-based Message Authentication Code

b)

CMAC Cipher-based Message Authentication Code

c)

PMAC Prefix-based Message Authentication Code

d)

GMAC Galois Message Authentication Code

25.

The Challenge Handshake Authentication Protocol (CHAP) is used to control access to _________ servers through encrypted authentication.

a)

remote access

b)

local

c)

web

d)

database

26.

Identification, Authentication, Authorization, and Accounting are key processes for controlling and tracking access to __________.

a)

computer resources

b)

financial records

c)

personal data

d)

physical locations

27.

Kerberos is an authentication protocol that uses time-sensitive __________ to grant access to systems.

a)

tickets

b)

passwords

c)

certificates

d)

tokens

28.

Privileged User Accounts have more __________ than regular user accounts, which makes them attractive targets for attackers.

a)

access rights

b)

restrictions

c)

limitations

d)

passwords

29.

Group Policy Objects (GPOs) in Active Directory are used to manage the __________ and configuration of user accounts and systems.

a)

settings

b)

hardware

c)

network

d)

software

30.

SAML and SPML are both standards for managing user __________ and access in distributed environments.

a)

authentication

b)

identification

c)

authorization

d)

encryption

31.

A Trusted Platform Module (TPM) is a hardware-based specification for generating and storing __________ securely.

a)

cryptographic keys

b)

user passwords

c)

network configurations

d)

software licenses

32.

Endpoint Security ensures that only authorized devices can connect to a network and addresses potential __________ at these endpoints.

a)

vulnerabilities

b)

enhancements

c)

improvements

d)

upgrades

33.

Endpoint Detection and Response (EDR) continuously monitors endpoint activity for security __________ and can respond accordingly.

a)

threats

b)

updates

c)

logs

d)

backups

34.

Log Monitoring automates the review of logs to identify potential __________ behavior in the system.

a)

anomalous

b)

normal

c)

expected

d)

routine

35.

Host Vulnerabilities refer to security weaknesses in the ___ systems of a network.

a)

host

b)

network

c)

application

d)

database

36.

Patch Management is the process of regularly updating software to address ___ and improve security.

a)

vulnerabilities

b)

performance issues

c)

user interface

d)

network speed

37.

Type 1 Hypervisors run directly on hardware, while Type 2 Hypervisors require a ___ operating system to manage virtual machines.

a)

host

b)

guest

c)

virtual

d)

network

38.

Privilege Escalation occurs when an attacker exploits vulnerabilities to gain higher-level ___.

a)

permissions

b)

access

c)

control

d)

privileges

39.

Data in Transit Encryption ensures that information being transmitted over a network is encrypted to protect it from ___.

a)

unauthorized parties

b)

data corruption

c)

network congestion

d)

server overload

40.

Symmetric Encryption uses the same key for both ___ and decryption.

a)

encryption

b)

compression

c)

hashing

d)

signing

41.

Asymmetric Encryption uses a pair of keys (one public, one private) for ___ and decryption.

a)

encryption

b)

compression

c)

hashing

d)

encoding

42.

A Digital Signature provides authentication of a message by using the sender’s ___ key.

a)

private

b)

public

c)

shared

d)

symmetric

43.

Collisions in Cryptography occur when two different inputs produce the same ___ in a hash function.

a)

output

b)

input

c)

key

d)

algorithm

44.

Rainbow Tables are precomputed tables used to reverse cryptographic ________ functions, making password cracking faster.

a)

hash

b)

encryption

c)

compression

d)

encoding

45.

The Key Elements of PKI (Public Key Infrastructure) include __________ authorities, digital certificates, and certificate revocation lists.

a)

certificate

b)

registration

c)

validation

d)

encryption

46.

In PKI, the Realm of Trust refers to the relationship between entities that trust a __________ certificate authority.

a)

root

b)

intermediate

c)

external

d)

local

47.

For a company with 99 employees, the number of keys required for Symmetric Encryption would be __________.

a)

4851

b)

100

c)

198

d)

4950

48.

Certificates in PKI are typically issued in a standard format called __________.

a)

X.509

b)

SSL

c)

TLS

d)

PEM

49.

In PKI, the main difference between a CRL (Certificate Revocation List) and OCSP (Online Certificate Status Protocol) is that CRL provides a list of revoked certificates, while OCSP checks the __________ of a single certificate.

a)

revocation status

b)

expiration date

c)

issuer details

d)

certificate type

50.

Wildcard Certificates are used to secure multiple __________ within the same domain.

a)

subdomains

b)

domains

c)

protocols

d)

servers

51.

S/MIME is a standard for securing __________ communications using encryption and digital signatures.

a)

email

b)

phone

c)

fax

d)

postal

52.

TLS (Transport Layer Security) provides encryption for __________ communications, securing data in transit.

a)

network

b)

email

c)

file

d)

voice

53.

Steganography hides information within __________ media such as images or audio files.

a)

digital

b)

physical

c)

printed

d)

analog

54.

A Brute Force Key Attack in cryptography involves trying all possible __________ until the correct one is found.

a)

encryption keys

b)

decryption methods

c)

hash functions

d)

cipher texts

55.

Clipping Level refers to a threshold for triggering an alert or lockout after multiple __________ attempts.

a)

failed

b)

successful

c)

random

d)

delayed

56.

The Birthday Attack is a cryptographic technique that exploits the mathematics of __________ functions to find collisions.

a)

hash

b)

encryption

c)

compression

d)

sorting

57.

The Avalanche Effect in cryptography describes how a small change in input drastically changes the resulting __________.

a)

output

b)

input

c)

key

d)

algorithm