wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Sec+ Day 7

Total questions: 49

Worksheet time: 25mins

Name
Class
Date
1.

Which of the following is NOT included in governance for security policies?

a)

Clearly defining roles and responsibilities

b)

Setting security standards

c)

Ensuring compliance with legal and regulatory requirements

d)

Configuring Dynamic Routing Protocols

2.

What is the primary responsibility of Governance Boards?

a)

Implementing marketing strategies

b)

Overseeing an organization's security policies and practices

c)

Managing financial accounts

d)

Developing new products

3.

Who typically makes up Governance Boards?

a)

Junior employees and interns

b)

Marketing and sales teams

c)

Senior executives and stakeholders

d)

CIRT Team & Legal Representatives

4.

What do Governance Boards ensure regarding security measures?

a)

They are cost-effective

b)

They align with the organization's objectives and regulatory requirements

c)

They are innovative and unique

d)

They are easy to implement

5.

Who are strategic plans primarily defined by?

a)

Junior employees

b)

Middle management

c)

Senior management

d)

External consultants

6.

What is the main purpose of strategic plans?

a)

To address short-term issues

b)

To meet long-term goals

c)

To increase daily productivity

d)

To reduce costs immediately

7.

Which of the following might be included in a strategic security plan?

a)

Increase sales by 10%

b)

Ensure our customers know their data is safe

c)

Hire more staff

d)

Transfer sensitive databases into a secure cloud environment

8.

What are tactical plans designed to meet?

a)

Specific strategic objectives

b)

Long-term goals

c)

Personal development goals

d)

Financial targets

9.

To whom may tactical plans be delegated?

a)

Mid-level management

b)

Entry-level employees

c)

External consultants

d)

Customers

10.

What is an example of a tactical plan?

a)

Assuring the public that all HIPAA and PCI DSS regulations will be strictly adhered to

b)

Increasing annual revenue by 20%

c)

Bringing the customer database into compliance with new privacy law

d)

Expanding into international markets

11.

What do operational plans describe?

a)

How to perform day-to-day operations in ways that meet higher-level plans

b)

How to create long-term strategic goals

c)

How to manage financial resources

d)

How to develop marketing strategies

12.

Who typically creates or administers operational plans?

a)

Top-level management

b)

Low-level management

c)

External consultants

d)

Middle-level management

13.

What is an example of an operational plan?

a)

Updating database software

b)

Setting company vision

c)

Developing a new product line

d)

Conducting market research

14.

What is the primary purpose of organizational policies?

a)

To increase profits

b)

To guide operations, decision-making, and behaviors

c)

To reduce employee workload

d)

To enhance marketing strategies

15.

What is governance in the context of organizational policies?

a)

The process of hiring new employees

b)

The processes used to direct and control an organization

c)

The method of increasing sales

d)

The strategy for increasing network uptime and reducing maintenance window times

16.

Which of the following is an example of a common organizational policy?

a)

Marketing Strategy Policy

b)

Acceptable Use Policy (AUP)

c)

Employee Satisfaction Policy

d)

Product Development Policy

17.

What does compliance ensure in an organization?

a)

Increased profits

b)

Adherence to regulations, policies, standards, and laws

c)

Better customer service

d)

Faster product development

18.

What is the purpose of Information Security Policies?

a)

To ensure IT users comply with security rules and guidelines.

b)

To focus on critical processes during and after disruptions.

c)

To detail steps for recovering from catastrophic events.

d)

To govern software development processes.

19.

What does Business Continuity & Continuity of Operations Plans (COOP) focus on?

a)

Critical processes during and after disruptions.

b)

Software development processes.

c)

Steps for recovering from catastrophic events.

d)

How IT system and software changes are managed.

20.

What is the main goal of Disaster Recovery?

a)

To restore operations quickly and efficiently.

b)

To protect information within the organization’s control.

c)

To ensure software meets efficiency, reliability, and security standards.

d)

To outline processes after security breaches or cyber-attacks.

21.

What does Incident Response outline?

a)

Processes after security breaches or cyber-attacks.

b)

How IT system and software changes are managed.

c)

Steps for recovering from catastrophic events.

d)

Software development processes.

22.

What is the purpose of the Software Development Life Cycle (SDLC)?

a)

To govern software development processes.

b)

To ensure operations remain functional during events like natural disasters.

c)

To detail steps for identifying, investigating, controlling, and mitigating incidents.

d)

To outline how IT system and software changes are managed.

23.

What does Change Management outline?

a)

How IT system and software changes are managed.

b)

Steps for recovering from catastrophic events.

c)

How network devices are deployed during peak hours

d)

Critical processes during and after disruptions.

24.

What are Information Security Policies?

a)

Informal guidelines for IT users

b)

Formal documents outlining rules and procedures

c)

Technical manuals for software installation

d)

Marketing strategies for IT companies

25.

What do Information Security Policies define?

a)

Secure device configurations and patching schedules

b)

Acceptable use of resources, security measures, and responsibilities of employees

c)

Tactical goals for encrypting PII

d)

Customer service protocols

26.

What does BCP stand for in the context of business operations?

a)

Business Continuity Plan

b)

Business Communication Plan

c)

Business Compliance Plan

d)

Business Coordination Plan

27.

What is the primary focus of COOP?

a)

Long-term business growth

b)

Maintaining mission-essential functions during emergencies

c)

Enhancing customer satisfaction

d)

Reducing operational costs

28.

Which of the following is a characteristic of BCP?

a)

Short-term continuity focus

b)

Covers all critical business operations

c)

Primarily for emergency situations

d)

Focuses on customer service

29.

What is the main difference between BCP and COOP?

a)

BCP is for short-term, COOP is for long-term

b)

BCP covers all operations, COOP focuses on mission-essential functions

c)

BCP is for emergencies, COOP is for regular operations

d)

BCP is more specific, COOP is broader

30.

What is the primary goal of change management in IT systems?

a)

To increase the speed of system updates

b)

To minimize disruptions and ensure security

c)

To reduce the cost of system changes

d)

To eliminate the need for documentation

31.

Which of the following is a key component of change management?

a)

Change Elimination

b)

Change Request

c)

Change Ignorance

d)

Change Delay

32.

What does the Change Control Board (CCB) do?

a)

Implement changes directly

b)

Review and approve change requests

c)

Apply best practices and increase delays for change requests

d)

Delay change implementation

33.

Why is testing important before implementing a change?

a)

To ensure it works as expected

b)

To increase the complexity of the system

c)

To reduce the number of stakeholders

d)

To eliminate the need for documentation

34.

What is the final step in the change management process?

a)

Planning

b)

Documentation

c)

Implementation

d)

Review

35.

What is the purpose of a back-out plan in change management?

a)

To ensure all changes are documented

b)

To reverse changes due to unforeseen issues

c)

To test changes in a sandbox environment

d)

To implement changes during maintenance

36.

Why is documentation important in the change management process?

a)

It reduces the time it takes for future changes on newly acquired systems

b)

It keeps detailed records of the change process

c)

It speeds up the implementation of changes

d)

It eliminates the need for testing

37.

Which of the following is NOT a step in the change management process for updating firmware on a router?

a)

Submitting a change request

b)

Implementing the update without testing

c)

Testing the update in a sandbox environment

d)

Documenting the entire process

38.

What is one of the benefits of effective change management?

a)

It increases the frequency of changes

b)

It prevents unauthorized changes

c)

It eliminates the need for maintenance

d)

It reduces the need for documentation

39.

What are guidelines primarily used for in a job role or department?

a)

To enforce strict rules and regulations

b)

To provide recommendations that steer actions

c)

To replace policies entirely

d)

To eliminate the need for discretion

40.

How do guidelines differ from policies?

a)

Guidelines are more rigid than policies

b)

Guidelines are mandatory rules

c)

Guidelines allow for flexibility and individual discretion

d)

Guidelines eliminate the need for policies

41.

What is one purpose of guidelines?

a)

To enforce penalties for non-compliance

b)

To provide best practices and suggestions for achieving goals

c)

To replace all existing policies

d)

To restrict individual judgment

42.

Which of the following is an example of a guideline for help desk support?

a)

Mandatory use of a specific software

b)

Recommended response times

c)

Strict adherence to a single communication method

d)

Elimination of email support

43.

What is the primary goal of security policies?

a)

To increase company profits

b)

To ensure the organization follows best practices to protect its informational assets

c)

To reduce employee workload

d)

To expand the organization's market reach

44.

What are external requirements in a governance-based approach?

a)

Preferences of the CEO

b)

Requirements set by outside stakeholders

c)

Suggestions from employees

d)

Feedback from customers

45.

What is often the most complex and time-consuming regulatory challenge?

a)

Internal audits

b)

Regulations imposed by governmental agencies or industry bodies

c)

Employee training programs

d)

Customer satisfaction surveys

46.

What must organizations comply with according to compliance obligations?

a)

Only local laws

b)

All relevant national, state, or territory laws

c)

Only international laws

d)

Only industry standards

47.

What is the purpose of step-by-step instructions and checklists?

a)

To ensure tasks are completed quickly

b)

To ensure consistency, compliance, and repeatability

c)

To reduce the number of employees needed

d)

To increase the complexity of tasks

48.

What do playbooks typically serve as in Security Operations Centers (SOC)?

a)

A guide for financial planning

b)

A guide for responding to various scenarios and incidents

c)

A guide for recovering from a honeynet breach

d)

A guide for employee training

49.

Which of the following is an example of a procedure?

a)

Marketing Analysis

b)

Onboarding/Offboarding

c)

Product Design

d)

Financial Auditing