NEW
Font size
WorksheetsCyber Security Quiz
Total questions: 55
Worksheet time: 28mins
What is the role of the CISO according to the CEA Cyber Security Regulations 2024?
Monitoring physical security of facilities
Overseeing cyber security initiatives and reporting to the CEO
Managing financial aspects of the organization
Designing electrical infrastructure
Which document must be reviewed and approved by the board of an entity?
Cyber Crisis Management Plan (CCMP)
Employee Training Plan
Vendor Selection Protocol
Power Supply Audit
According to the draft regulations, who must complete cyber security training courses?
All employees of the entity
Only IT department personnel
Personnel operating IT and OT systems
Board members only
CSIRT-Power is primarily responsible for which of the following?
Financial auditing
Creating SOPs for incident response activities
Monitoring physical access to OT systems
Managing human resources
The Cyber Security Policy of an entity must include which of the following elements?
Physical layout of facilities
Access control and vulnerability management processes
Budget allocation for each department
Supply chain logistics
What is the minimum retention period for cybersecurity incident logs as per the regulations?
30 days
60 days
90 days
180 days
Which certificate should Responsible Entities acquire according to the draft regulations?
ISO/IEC 27001
ISO 9001
IEEE 1588
ANSI Z10
The draft regulations require vendors to provide a Software Bill of Materials for what purpose?
To outline the software components used in critical applications
To track financial expenditures
To list employee assignments
To define maintenance schedules
What should the Cyber Security Policy address in terms of data protection?
Data encryption and privacy protocols
Data sharing across international borders
Only physical copies of data
Limiting employee data access
According to the draft, how frequently should an IT system cyber security audit occur?
Once every three years
Once every year
Twice a year
Quarterly
Which of the following must be physically isolated from the Internet as per the draft regulations?
Email servers
Employee desktops
Critical OT systems
Cloud storage solutions
What is the main purpose of the Cyber Crisis Management Plan (CCMP)?
To regulate financial practices during crises
To set guidelines for employee conduct
To manage cyber incidents and ensure coordinated responses
To ensure compliance with power generation protocols
Who approves the Cyber Crisis Management Plan (CCMP) in an organization?
IT Department
Board of Directors
Human Resources Department
Legal Department
Which agency is responsible for issuing directives to CSIRT-Power?
Ministry of Health
CERT-In
Ministry of Education
Department of Labor
What are 'Critical Assets' as defined in the CEA Cyber Security Regulations?
Systems necessary for the reliable operation of the power system
Employee workstations
Office supplies
Non-essential systems in the organization
Under the CEA Cyber Security Regulations, what specific responsibility does the Information Security Division (ISD) have concerning Cyber Security audits?
Conduct quarterly audits of employee performance
Review audit reports and ensure implementation of audit recommendations
Prepare financial reports related to cyber security
Develop marketing strategies for cyber security tools
What is required from vendors regarding security patches under the CEA Cyber Security in Power Sector Regulations?
Vendors must provide patches only at the start of the contract
Vendors must make patches available for all system components during the contract duration
Vendors need to ensure patches are applied automatically
Vendors are not responsible for patches according to the regulations
What is the main purpose of Perfect Forward Secrecy (PFS) in cryptographic communications?
Ensuring that encrypted data remains secure even if the server’s private key is compromised
Allowing symmetric keys to be reused for faster decryption
Maintaining long-term storage of cryptographic keys for auditing purposes
Encrypting data at rest to prevent unauthorized access
What is the stipulated process for remote access in the Responsible Entities' Cyber Security Policy?
Remote access should be allowed only for international users
Multi-factor authentication and least-privilege access should be ensured
Remote access is to be granted on a temporary basis without authentication
No specific access controls are mentioned
What is the minimum cybersecurity course requirement for CISO and ISD members per the regulations?
At least five person-days per year
Only one training session per year
Ten person-days per year or as directed by the authority
No mandatory training requirement specified
According to the regulations, what is the role of CSIRT-Power in collaborating with CERT-In and NCIIPC?
To enhance financial transparency in the power sector
To resolve cyber incidents and develop incident response procedures
To streamline supply chain logistics
To manage power distribution systems directly
What type of separation is required between IT and OT systems if physical separation is not possible?
The two systems must be connected via public networks
Logical separation with hardened security measures must be implemented
No separation is required if they are in the same location
Use of basic firewall protocols suffices for separation
What does the Cyber Security Policy mandate regarding outdated or obsolete cyber assets?
They must be discarded immediately upon reaching end-of-life
A phase-out plan must be defined, with secure disposal procedures in place
They should be repurposed for non-critical functions
No action is required until they are non-operational
What are the responsibilities of the ISD concerning inventory management as outlined in the regulations?
ISD should manage physical assets only, excluding cyber assets
ISD must keep an updated inventory of IT and OT assets with network architecture documentation
ISD should outsource inventory management to third parties
ISD should periodically update inventory every 5 years
In terms of incident reporting, within what timeframe must incidents involving cyber sabotage in Critical Systems be reported to CSIRT-Power?
Within 48 hours
Within 7 days
Immediately, or within 24 hours
Only after a formal investigation is complete
What is the primary function of an Electronic Security Perimeter in the context of the Draft CEA Cyber Security Regulations?
To define the physical boundary of critical assets
To logically isolate networks connected to cyber systems of the power system
To facilitate controlled public access to critical systems
To manage vendor communications for IT systems
Which of the following is not a stipulated responsibility of CSIRT-Power?
Implementing Cyber Crisis Management Plans
Conducting financial audits for cybersecurity expenditures
Developing SOPs in consultation with CERT-In and NCIIPC
Sharing cyber threat intelligence within the power sector
What specific feature must firewalls used in critical systems include as per the draft regulations?
A user-friendly interface for employee training
Capability to identify behavioral anomalies
Integration with physical access systems
Auto-updates without administrator intervention
What is a Software Bill of Materials (SBOM), and why is it mandated in the draft regulations?
A cost estimate document for software procurement
A list detailing supply chain components of software to ensure security
An operational guide for system maintenance
A document outlining software vendor terms
In the case of an identified cyber security vulnerability, what is the maximum allowable time to address critical vulnerabilities?
One month
Three months
Six weeks
Before the next audit period
What is the minimum required frequency for updating firmware and software in critical systems as per the regulations?
Monthly
Quarterly, with digitally signed OEM patches only
Biannually, during audit periods
Only when vulnerabilities are discovered
What critical requirement is stipulated for all control and operation of power system elements?
They must use public networks for efficient communication
Control must occur entirely within national boundaries
Operators must have remote access capabilities at all times
Real-time operational data must be shared with international entities
What is the main purpose of the Cyber Supply Chain Risk Management (CSCRM) plan under the regulations?
To identify budget constraints in the procurement process
To include cybersecurity requirements in outsourcing and NDA in SLA agreements
To enhance vendor operational efficiency
To optimize delivery timelines of equipment
Which of the following represents the correct order of actions in a certification scheme?
Selection → Determination → Decision → Review → Certification
Review → Selection → Certification → Determination → Decision
Selection → Determination → Review → Decision → Certification
Certification → Selection → Decision → Review → Determination
What is explicitly prohibited regarding data related to grid operations?
Sharing grid operational data with domestic entities
Transferring real-time operational data across national borders
Using encrypted communication channels for data sharing
Storing operational data on cloud systems
Which entity is responsible for approving the Cyber Security Policy of a Responsible Entity?
Ministry of Power
Board of Directors of the Responsible Entity
CERT-In
CSIRT-Power
What is the minimum interval between two IT system cybersecurity audits in the same financial year?
Three months
Four months
Six months
Nine months
What action must a Responsible Entity take if a CISO position becomes vacant?
Assign the role to the alternate CISO immediately
Suspend all cybersecurity operations until the role is filled
Leave the role vacant temporarily
Outsource the CISO responsibilities to a third-party consultant
What must all personnel engaged in IT and OT operations sign as per the regulations?
Employment contract
Non-disclosure agreement
Vendor compliance form
Risk assessment report
Who is responsible for implementing the Cyber Crisis Management Plan (CCMP) in a Responsible Entity?
IT Manager
Chief Information Security Officer (CISO)
External cybersecurity consultants
Board of Directors
What is a key characteristic of an Advanced Persistent Threat (APT)?
Immediate and large-scale impact on systems
Focus on financial gain through ransomware
Persistent and covert operations over a long period
Solely targeting end-user devices
Which cryptographic algorithm is considered quantum-resistant?
RSA
ECC
Lattice-based cryptography
SHA-256
What does the principle of "least privilege" entail in access control?
Assigning minimal permissions necessary for a user to perform their job
Allowing full access to senior employees regardless of their role
Periodically rotating user credentials to prevent breaches
Denying access to all users by default
What is the main purpose of a honey pot in cybersecurity?
To secure critical data using encryption
To trap attackers and study their tactics without affecting actual systems
To scan the network for vulnerabilities
To protect against Distributed Denial of Service (DDoS) attacks
Which of the following represents an example of a buffer overflow attack?
Flooding a server with traffic to exhaust resources
Injecting malicious SQL queries into a database
Overwriting adjacent memory locations due to excessive data input
Stealing session cookies for user impersonation
What is the primary difference between symmetric and asymmetric encryption?
Symmetric encryption uses two keys, while asymmetric uses one key
Symmetric encryption uses one key for both encryption and decryption, while asymmetric uses a pair of keys
Asymmetric encryption is faster than symmetric encryption
Asymmetric encryption is less secure than symmetric encryption
In the context of cybersecurity, what is a "zero-day" vulnerability?
A vulnerability that is detected during system testing
A vulnerability exploited by attackers on the same day it is patched
A vulnerability unknown to the software vendor and unpatched at the time of exploitation
A vulnerability introduced on the first day of system deployment
What type of attack relies on repeatedly guessing a password until the correct one is found?
Phishing
Brute-force attack
Man-in-the-middle attack
Cross-site scripting
What does Multi-Factor Authentication (MFA) typically combine?
Username and password
Something the user knows, something the user has, and something the user is
Encrypted data and session tokens
Passwords and session cookies
Which of the following is a characteristic of a polymorphic virus?
It hides in the boot sector of a hard drive
It self-replicates without user interaction
It modifies its code to avoid detection by antivirus software
It targets only specific file types like .exe files
Which of the following is an example of social engineering?
A user clicks on a malicious email link that installs malware
An attacker exploits a software vulnerability
A network is flooded with traffic to cause a denial of service
A person poses as IT support to obtain user credentials
What is the purpose of a firewall in network security?
To encrypt sensitive data in storage
To prevent unauthorized access to or from a private network
To detect malware on endpoints
To manage software updates across devices
Which of the following best describes phishing?
Scanning networks for open ports
Using fake communication to trick users into revealing sensitive information
Infecting systems with ransomware
Exploiting software vulnerabilities for privilege escalation
What does "patch management" refer to in cybersecurity?
Testing software compatibility with different operating systems
Applying updates to software to fix vulnerabilities or improve functionality
Monitoring network traffic for anomalies
Identifying and removing malware from systems
What does the CIA triad stand for in cybersecurity?
Communication, Information, Accessibility
Confidentiality, Integrity, Availability
Cybersecurity, Intelligence, Authentication
Control, Identification, Authorization
