Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

ITE 370 - IAS 2 Quiz

Total questions: 17

Worksheet time: 26mins

Name
Class
Date
1.
Choose your block
a)
Block 1
b)
Block 2
c)
Block 3
d)
Block 4
e)
Block 5
2.
This step focuses on the action performed when managing risks
a)
Identifying
b)
Assessing
c)
Treatment
d)
Communication
e)
Re-identification
3.
This step refers to figuring out how much focus we should give on isolating or eliminating a risk.
a)
Identifying
b)
Assessing
c)
Treatment
d)
Communication
e)
Re-identification
4.
Incident 1: During a routine inspection of the ITS department, they noticed an unauthorized access to sensitive student records. After further investigation, they found out that the activity was traced to a student's personal laptop. The student had obtained the login credential of a teacher and used them to gain access to confidential files Incident 2: A security guard at the main entrance notices an abandoned backpack near the school gate. After reviewing the cameras, it was discovered that the bag was left by a stranger who is neither a student nor a staff member. The person was seen walking away quickly after leaving the bag.
a)
Both incident are internal threats
b)
Both incidents are external threats
c)
Incident 1 is internal, and Incident 2 is external
d)
Incident 1 is external, and incident 2 is internal
5.
This refers to removing the source of the risk entirely, which is often impractical since it could involve disposing of valuable
a)
Risk Transfer
b)
Reduction
c)
Remediation
d)
Avoidance
6.
This step involves continually revisiting and re-evaluating the risks even if you already solved it, rather than treating it as a one time task.
a)
Assessing
b)
Treatment
c)
Re-identification
d)
Communication
7.
Incident 1: During a routine network monitoring session, the IT team identified an intruder attempting to gain unauthorized access to the company's main server through a brute force attack. The attacker was actively trying different password combinations to break into the system. Incident 2: An employee reported unusual activity on their workstation. Upon investigation, it was discovered that an attacker had exploited a vulnerability in the company's VPN system. This exploitation allowed the attacker to gain access to sensitive files and data from the compromised workstation.
a)
Both incidents are direct attacks
b)
Both incidents are indirect attacks
c)
Incident 1 is a direct attack, and Incident 2 is an indirect attack
d)
Incident 1 is an indirect attack, and Incident 2 is a direct attack
8.

What is the primary goal of security architecture design?

a)

Ensuring confidentiality of data

b)

Achieving high system availability

c)

Minimizing risk and protecting information systems

d)

Enforcing strict access control policies

9.

The purpose of data protection is solely to ensure physical security of the organization's premises, and it does not involve tools like firewalls or intrusion detection systems.

a)

True

b)

False

10.

What is the general purpose of a risk assessment in security architecture design?

a)

Developing access control policies

b)

Identifying and mitigating potential risks and vulnerabilities

c)

Conducting penetration testing

d)

Implementing secure coding practices

11.

It is crucial for you to memorize each and every detail of the Security Architecture Design, rather than understanding them

a)

True

b)

False

12.

What is the primary purpose of an IT Disaster Recovery Plan (IT DRP)?

a)

To prevent all disasters from occurring

b)

To identify and fix vulnerabilities in software code

c)

To ensure systems are restored and operational after a disaster

d)

To manage physical security of the organization

13.

Which of the following is NOT an example of a solution in an IT Disaster Recovery Plan?

a)

Backup servers

b)

Hiring more employees

c)

Testing and drills

d)

Restarting a malfunctioning server

14.

What step in creating an IT Disaster Recovery Plan involves identifying

a)

Determining the criticality of the activity

b)

Risk identification

c)

Creating backup systems

d)

Investigating the root cause

15.

How does business continuity relate to an IT Disaster Recovery Plan?

a)

It is a separate process unrelated to disaster recovery

b)

It ensures the organization can continue operations after a disaster

c)

It only applies to physical disasters like earthquakes

d)

It eliminates the need for disaster recovery plans

16.

What is the purpose of testing and exercising an IT Disaster Recovery Plan?

a)

To identify physical security vulnerabilities

b)

To evaluate the impact of a disaster on employees

c)

To ensure the plan is effective and actionable during a real disaster

d)

To replace outdated hardware

17.

After enacting the solution to a disaster, what is the next step in an IT Disaster Recovery Plan?

a)

Develop new IT infrastructure

b)

Investigate the root cause and report to appropriate personnel

c)

Stop all operations until the issue is resolved

d)

Create an entirely new disaster recovery plan