Font size
WorksheetsTopic 1-12 Cybersecurity Quiz
Total questions: 142
Worksheet time: 1hrs 11mins
What is the primary aim of the cybersecurity course?
Focusing solely on physical security
Covering policy and procedures for securing large systems
Teaching programming skills
Analyzing software development lifecycle
What are the three major threats to information security?
Hardware, software, and users
Confidentiality, integrity, and availability
Networking, data storage, and access control
Authentication, authorization, and auditing
What has led to an increased need for security in modern organizations?
Limited connectivity
Simple computing models
Pervasive computing and advanced technology
Decreased user interaction
What were mainframes typically used for in the past?
Handling elaborate computing tasks
Providing user-friendly access
Performing specialized jobs with controlled access
Supporting mobile devices
What is a drawback of a compromised security system?
Increased data integrity
Improved user experience
Short- and long-term damage
Decreased need for monitoring
What type of attacks involve manipulating people to reveal confidential information?
Malware attacks
Phishing attacks
Social engineering attacks
Brute-force attacks
Which factor is not a reason for increased security challenges in organizations?
Distributed computing
Increased data connectivity
Limited computing capabilities
Mobile computing growth
What was the primary goal of mainframe operators in early computing models?
Ensuring user satisfaction
Providing open access to everyone
Maintaining system control and limited access
Enhancing user interaction
Why is data considered a critical component in modern organizations?
It is easy to replace
Both public and private sectors rely on it
It requires minimal security
It is not a valuable resource
Which of the following is not a type of threat that organizations face online?
Phishing attacks
Malware attacks
Ransomware
Local database failure
What is a cybersecurity framework designed to do?
Simplify data processing
Set guidelines to assess, monitor, and mitigate risks
Minimize the need for documentation
Provide hardware for security
What does ITIL stand for?
Information Technology Infrastructure Library
Information Transmission and Logistics
International Technical Integration Level
Internet Technology Implementation Lab
What is the purpose of ISO 27001?
Define mandatory risk controls
Provide guidelines for implementing controls
Explain software requirements
List basic software licenses
Which stage in ISO 27000 involves assessing risk and handling parameters?
Implementation
Planning
Act
Monitor
Which process is critical for achieving compliance in ISO 27000?
Documentation
Redundancy
User training
Equipment maintenance
What does ISMS stand for in ISO 27000?
Information Security Management System
Internet Security Module System
International Safety Management System
Integrated Security Management System
Which ISO 27000 stage focuses on incident handling?
Act
Monitor
Plan
Document
What is a drawback of not having continuous evaluation in ISO 27000?
Excessive compliance
Over-reliance on outdated documentation
Inconsistent security
Lower equipment costs
What is the purpose of an audit in the ISO 27000 framework?
To streamline cost-effectiveness
To test and improve processes
To replace security policies
To increase network connectivity
What is a key component of certification in ISO 27000?
Compliance with outdated standards
Incident handling without review
Risk assessment and implementation order
Simplifying risk mitigation
Who is typically involved in an organizational security system?
Only senior management
Only IT users
Senior management, security staff, IT users, and third parties
Only third parties
What do security policies define in an organization?
Step-by-step implementation instructions
Broad statements about organizational objectives
Specific hardware configurations
Guidelines for financial investments
What is the goal of 'Defense in Depth' in organizational security?
Simplify all security measures
Provide multiple layers of defense
Reduce security redundancy
Increase system complexity
Which model is core to most organizational security frameworks?
Physical security
Client-server
Layered security
Single-level security
Who develops security policies in an organization?
IT users
Only external consultants
Senior management
Only third parties
What type of security document is not mandatory but encouraged to follow?
Security policies
Security standards
Security guidelines
Security procedures
What strategic goal does an organizational security model aim to achieve?
IT support
Risk assessment and compliance
Simplified data processing
Limited user access
What does ISO 27002 focus on?
Developing software
Implementing security guidelines
Eliminating user roles
Increasing IT costs
What question should a security policy address during development?
What assets should be protected?
What is the policy effective date?
Who enforces the policy?
All of the above
Which security component is essential for continuity in organizational security?
Redundancy
Limited connectivity
Low-cost solutions
Minimum compliance
What is a vulnerability in cybersecurity terms?
A strong password
A weakness in systems or procedures
An external attack
A user error
What is a threat vector?
A secured pathway
A means to access a system via a vulnerability
A list of software updates
A type of firewall
What is the first step in handling risk?
Ignore the risk
Transfer the risk
Identify the risk
Retain the risk
What is risk mitigation?
Ignoring risk
Eliminating all risks
Reducing the impact of risks
Transferring risks
What does qualitative risk assessment focus on?
Quantifying cost-related risks
Measuring subjective factors
Eliminating all risks
Improving system performance
What does risk retention mean?
Ignoring the risk
Budgeting for potential claims or losses
Transferring risk to another party
Reducing risk exposure
What factor is not typically considered in asset assessment?
Cost to obtain the asset
Value to opponents
Number of users
Replacement cost
What is a key objective of risk analysis?
Reducing maintenance cost
Simplifying network infrastructure
Enabling cost vs. benefit evaluation
Ignoring user activity
What is one aim of a risk plan?
To eliminate all organizational risks
To reduce risks to an acceptable level
To monitor software updates only
To avoid asset replacement
What does risk transfer typically involve?
Eliminating risk
Keeping risk in-house
Utilizing insurance or third parties
Ignoring the risk
What does ISO 27002 provide?
Guidelines on asset inventory
Description of requirements for external party dealings
IT support policies
Employee guidelines
What is a key aspect in dealing with third parties?
Customer satisfaction
Legal compliance
Risk assessment and re-evaluation of controls
Financial stability
Why is access to assets granted to external parties?
For software/hardware development
For advertising purposes
For inventory management
For legal counsel
Who are considered Curtin University's clients?
Contractors
Alumni
Staff and students
Security personnel
What must the outside party specify regarding security arrangements?
Data transfer protocols
Security compliance methods
Asset valuation metrics
Database structures
Outsourcing affects the organization by transferring what to an external party?
Financial obligations
Security of information and services
Customer data only
Payroll systems
Which of the following is an example of physical access control?
Passwords
Firewalls
Video cameras
Encryption
What must organizations carefully evaluate before granting customer access to assets?
The value of shared data
The total cost of the contract
Marketing potential
Client satisfaction
What kind of access is typically required by partners?
Administrative access
Shared information access
Physical building access
Financial data access
In case of customer access, what must organizations determine?
The value of customer feedback
The best asset protection methods
The total inventory of assets
The organization's social media reach
What is critical to do before contracting out services?
Increase marketing efforts
Conduct a detailed assessment
Survey employee satisfaction
Update the company website
What is required of the owner of an asset?
Monthly reporting
Maintenance and integrity of the asset
Marketing of the asset
Legal analysis
What is a form of documentation required by ISO 27002?
Financial projections
Outsourced service contracts
Record of asset ownership
Product marketing plans
Who might require access to source code?
Developers
Security personnel
Financial analysts
Maintenance staff
What should be in place for any data-related outsourcing?
Standard advertising formats
Data protection policies
Financial documents
Legal marketing contracts
Why is asset ownership classified and documented?
To promote the asset's visibility
To manage the asset more cost-effectively
To meet marketing demands
To improve staff compliance
What must organizations consider when sharing data with an external party?
Contract duration
Cost of service
Access control
Marketing value
Which type of control involves limiting access to confidential information?
Marketing control
Access control
Financial control
Security clearance
What is the primary aim of ISO 27002 in terms of human resources security?
Increase productivity
Enhance employee engagement
Reduce losses from human error or malicious activity
Improve training efficiency
According to ISO 27000, what type of checks must be conducted on all staff?
Annual performance reviews
Legal compliance checks
Character and CV checks
Social media checks
Why should a credit check be conducted regularly for certain roles?
To ensure they meet financial stability
To prevent identity theft
To safeguard access to privileged information
To assess productivity
Which ISO standard addresses the physical and environmental aspects of security systems?
ISO 27001
ISO 9001
ISO 14000
ISO 31000
What is a common pitfall in physical security management?
Excessive documentation
Neglecting infrastructure security controls
Overstaffing security teams
Lack of regular audits
Which type of security model involves multiple layers working together to protect an asset?
Open source security model
Multi-layer physical security model
Zero-trust security model
Cloud security model
What is required for compliance with ISO 27001's physical security requirements?
Unrestricted access to secure areas
Fire safety training
Documented risk assessment for auditors
Third-party outsourcing for security
Which threat type is NOT part of physical security challenges mentioned?
Environmental threats
Supply threats
Technological threats
Politically motivated threats
According to ISO 27002, what must all staff wear in a secure facility?
Uniforms
Name tags or identification
Body armor
Protective gloves
Why should privileged information be stored in secure areas?
To avoid data redundancy
To meet compliance standards
To provide an additional layer of protection
To facilitate easy access
Which type of physical security threat is most likely to cause significant damage due to access knowledge?
Insider threat
Environmental threat
Outside threat
Digital threat
ISO 27001 recommends monitoring fire doors to allow only:
Two-way access
Outward opening
Limited use during business hours
One-way opening
According to ISO 27002, who should supervise visitors in secure areas?
Human resources staff
Security guards
IT personnel
Cleaning staff
Which measure is essential in the physical security approach for securing information?
Reducing staff training
Limiting software updates
Implementing perimeter barriers
Centralizing IT support
What should facilities handling confidential information avoid?
High visibility and advertisement of their role
Central locations within the building
Secure locks on all doors
Regular risk assessments
Where should equipment with data access capabilities be positioned?
Near windows
In common areas
Away from visibility by unauthorized users
By the main entrance
What is a crucial factor for ensuring continuous working order of sensitive equipment?
Employee training sessions
Regular software updates
Continuous environmental monitoring
Increased physical size of equipment
Equipment to be taken off-site must be:
Logged and provided with a detailed responsibility checklist
Stored in non-secure areas
Shared among different employees
Taken without approval
When disposing of equipment, ISO 27002 specifies:
Minimal documentation is needed
Disposal must ensure no data recovery is possible
Disposal can be completed off-site without supervision
Disposal records are unnecessary
In terms of facility security, what should access to daily office equipment require?
Enhanced privileges
Basic privileges only
Shared passwords
No restrictions
Why should dangerous materials be stored in separate locations?
To reduce equipment maintenance costs
To comply with storage requirements
To ensure safety and minimize risks
To increase accessibility
What type of access is recommended for backup system media?
Immediate access for all staff
Accessible only within the secure area
Stored off-site from backup equipment
Full access for contractors
What should be restricted when dealing with outside parties in secure processing facilities?
Shared software usage
Multiple entry points
Access to phones and privileged information
Open communication policies
Who is primarily responsible for equipment repairs and upgrades in a secure facility?
Contractors
Security guards
Cleared staff following risk assessment
General employees
Which ISO 27002 control is aimed at preventing unauthorized viewing of data on monitors?
Increased screen brightness
Data encryption
Strategic equipment positioning
Security camera installation
What is the main goal of communications security?
To reduce network traffic
To ensure confidentiality, integrity, and availability of information
To increase the speed of data transfer
To minimize hardware costs
Which area is NOT included in network security management?
Cryptosecurity
Emission security
Data replication
Traffic-flow security
What is cryptosecurity primarily concerned with?
Monitoring data traffic
Using cryptographic techniques to protect communication content
Blocking unauthorized access to devices
Creating backup data copies
ISO 27001 recommends starting cryptographic control implementation with which step?
Key management
Encryption algorithm selection
Risk assessment
Access control setup
Which of the following is an essential part of proper key management in cryptosecurity?
Disabling key rotation
Random key generation
Storing keys securely
Publishing keys publicly
Transmission security aims to protect data while it is:
Stored on hard drives
In use by applications
Being transmitted
Archived in servers
Which protocol is commonly used to secure web traffic?
IPsec
FTP
HTTP
SSL/TLS
What does emission security, also known as TEMPEST, aim to prevent?
Data redundancy
Electromagnetic emissions from being intercepted
Unauthorized network access
Inadequate encryption protocols
Which organization publishes lists of approved TEMPEST testing labs?
United Nations
NSA-USA
FCC
ISO
Traffic-flow security protects which type of information?
The content of communications
The metadata associated with communications
Network bandwidth
File encryption keys
Why is it important to conceal metadata about communications?
To reduce server load
To prevent traffic analysis attacks
To increase data throughput
To save storage space
What is the benefit of segregating networks into domains?
Improved cryptographic security
Faster data transmission
Reduced hardware costs
Increased number of access points
How should sensitive information be handled in voicemail systems?
Allowed to be shared freely
Avoided to prevent unauthorized access
Recorded on public servers
Open to all employees
What is a key element in information exchange agreements?
Assigning responsibilities for handling sensitive information
Allowing unrestricted information flow
Random labeling of data
Frequent policy updates
Why are technical controls for traceability and non-repudiation essential in information exchange?
To prevent data loss
To prove information was sent and received as claimed
To reduce data encryption costs
To ensure faster data transfer
What is required when couriers are used for physical information transfer?
No identification needed
Standard delivery protocol
Identification procedures to verify courier authenticity
Open access to all employees
For sensitive information exchange, an agreement on which of the following is recommended?
File format and encryption standards
Storage capacity requirements
Open access policies
Color coding of documents
What should be consistent with the receiving organization's internal labeling system?
Encryption method
Labeling system for protection levels
Internet access settings
User roles
Information exchange policies should align protection methods with:
Employee preferences
Financial goals
Information classification levels
Network load capacity
Which procedure is essential for securely disposing of traffic-flow data?
Copying the data to external devices
Following data retention and disposal policies
Encrypting all archived data
Releasing data to public domain
What is essential for implementing an effective security system for staff?
Limiting staff access
Regular security training
Keeping staff informed about security changes
Restricting all online access
ISO 27002 suggests that which platform can help staff access security information?
Social media
Intranet
Local server
External drive
Which of the following is a common type of malware?
Firewall
Antivirus
Worm
VPN
Viruses have which key characteristic?
Self-replication and host dependency
Independence from a host
Block all system files
Only affects network traffic
Which type of malware does NOT need a host to spread?
Virus
Worm
Spyware
Trojan
What is a defining feature of spyware?
Automatically cleans up data
Collects information about the system
Encrypts files for security
Only affects Windows operating systems
What is a botnet?
A network of infected machines
A type of antivirus software
A secure network protocol
A form of firewall protection
According to ISO 27002, what should organizations prohibit to prevent malware?
Use of unauthorized software
Access to the internet
External email access
File transfers within the network
What is required for handling files from external sources?
Ignore security checks
Archive files immediately
Check files for malware
Install additional software
Why is it essential to monitor email attachments according to malware procedures?
To reduce email load
To protect against malware infections
To enable faster data access
To increase email storage
ISO 27002 recommends which approach to manage mobile code security?
Install mobile code on all devices
Block mobile code entirely
Limit mobile code to its intended environment
Share mobile code across all devices
What is the primary objective of back-up mechanisms?
To store data off-site only
To ensure data recovery in case of loss
To increase storage space
To improve network speed
Where should back-up data ideally be stored?
On the local server
On external hard drives
Off-site
In cloud storage only
Which technology does ISO 27002 suggest using for critical servers?
Firewall
RAID
Proxy
DNS
What should be tested regularly to ensure effective back-up?
Software licenses
Network speeds
Recovery procedures
Email attachments
What type of information also requires off-site back-up according to ISO 27002?
Personal emails
Music files
Paper-based information
Unclassified digital files
What is the common target platform for viruses?
Linux
macOS
Android
Windows
What characteristic distinguishes worms from viruses?
Need for user action to spread
Dependence on a host
Ability to replicate independently
Only affecting emails
What is the primary purpose of spyware?
Encrypts all files
Deletes unauthorized software
Collects and sends data from the infected system
Optimizes system performance
What kind of activity is a botnet often used for?
Regular system updates
Denial-of-Service (DDOS) attacks
Data backups
System encryption
What measure does ISO 27002 recommend for handling malware in downloaded files?
Immediate download and storage
Ignoring unknown files
Documenting malware check findings
Direct file sharing across the network
Which type of malware has the ability to mutate and change its code?
Standard virus
Worm
Polymorphic malware
Spyware
Which method is recommended to mitigate mobile device risks in an organization?
Block all mobile access
Limit internet access on mobile devices
Limit execution of mobile code
Allow open access on devices
What is an effective control for preventing botnet attacks?
Allowing unrestricted network access
Implementing access controls and monitoring
Avoiding software updates
Disabling antivirus programs
What is one way to ensure unauthorized software use is prevented?
Allowing all downloads
Enforcing software compliance
Increasing download speeds
Allowing free data transfer
Which approach provides the best outcome for software control?
Application only
Database control only
Operating system only
All three in combination
What is a common issue with poorly configured security packages?
They don't require maintenance
They allow high user functionality
They may cause more harm than good
They require minimal specialist knowledge
ISO 27002 recommends which control for database access?
Unrestricted user access
Asset or data ownership only
Isolating critical systems
Unlimited privileges for all users
Which of the following is NOT a function of the NIST Cyber Security Framework?
Identifying incidents
Limiting incident damage
Ensuring data redundancy
Restoring capabilities
Which control method is recommended by ISO 27002 for application input validation?
Buffer Overflow Management
Batch, Balancing, and Integrity checks
Only Batch processing
Selective Application Logs
Which protocol ensures a secure internet connection and prevents data modification?
IPSec
SSL
S/MIME
SMTP
What is the primary issue with social engineering attacks in e-commerce?
It increases site traffic
It leverages insider information
It uses knowledge from the internet
It requires face-to-face interaction
Which ISO standard is relevant to e-commerce security and internet use?
ISO 9001
ISO 27001
ISO 14000
ISO 31000
How does IPSec contribute to secure e-commerce?
It provides SSL certificates
It authenticates payment transactions
It encrypts IP packets and authenticates their source
It monitors data streams
Which aspect is NOT covered in an organization's acceptable internet usage policy?
Allowed download activities
Privacy and monitoring rules
Staff salaries
Consequences for policy breaches
Which activity is part of the monitoring phase in incident response?
Creating user accounts
Setting up virtual meetings
Monitoring unauthorized access attempts
Updating HR records
ISO27002 requires which type of clock synchronization for accurate incident recording?
Pacific Time
Daylight Saving Time
Local Office Time
Universal Coordinated Time (UCT)
Incident response responsibilities include:
System start-up updates
User ID configuration
Communication with affected parties
Financial budgeting
What does a tabletop exercise in business continuity planning involve?
Real-life recovery testing
A theoretical plan walkthrough
Physical equipment handling
Financial simulations
