wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Security Domain

Total questions: 20

Worksheet time: 2hrs 40mins

Name
Class
Date
1.

All of the following items should be included in a Business Impact Analysis (BIA) questionnaire EXCEPT questions that

a)

determine the risk of a business interruption occurring

b)

determine the technological dependence of the business processes

c)

Identify the operational impacts of a business interruption

d)

Identify the financial impacts of a business interruption

2.

Which of the following represents the GREATEST risk to data confidentiality?

a)

Network redundancies are not implemented

b)

Security awareness training is not completed

c)

Backup tapes are generated unencrypted

d)

Users have administrative privileges

3.

A While investigating a malicious event, only six days of audit logs from the last month were available. Whatpolicy should be updated to address this problem

a)

Retention

b)

Reporting

c)

Recovery

d)

Remediation

4.

When assessing an organization’s security policy according to standards established by the International Organization for Standardization (ISO) 27001 and 27002, when can management responsibilities be defined?

a)

Only when assets are clearly defined

b)

Only when standards are defined

c)

Only when controls are put in place

d)

Only procedures are defined

5.

An important principle of defense in depth is that achieving information security requires a balanced focus on which PRIMARY elements?

a)

Development, testing, and deployment

b)

Prevention, detection, and remediation

c)

People, technology, and operations

d)

Certification, accreditation, and monitoring

6.

A control to protect from a Denial-of-Service (DoS) attach has been determined to stop 50% of attacks, and additionally reduces the impact of an attack by 50%. What is the residual risk?

a)

25%

b)

50%

c)

75%

d)

100%

7.

Which of the following entails identification of data and links to business processes, applications, and data stores as well as assignment of ownership responsibilities?

a)

Security Governance

b)

Risk Management

c)

Security Portfolio Management

d)

Risk Assessment

8.

Which of the following mandates the amount and complexity of security controls applied to a security risk?

a)

Security Vulnerability

b)

Risk Tolerate

c)

Risk Mitigation

d)

Security Staff

9.

A security professional determines that a number of outsourcing contracts inherited from a previous merger do not adhere to the current security requirements. Which of the following BEST minimizes the risk of this happening again?

a)

Define additional security controls directly after the merger

b)

Include a procurement officer in the merger team

c)

Verify all contracts before a merger occurs

d)

Assign a compliancy officer to review the merger conditions

10.

Which of the following is a direct monetary cost of a security incident?

a)

Morale

b)

Reputation

c)

Equipment

d)

Information

11.

An effective information security policy should include:

a)
  • Detailed technical instructions for device configuration.

b)
  • General guidelines and security objectives for the organization.

c)
  • A list of approved and prohibited software.

d)
  • Specific technical standards for each department.

12.

Risk management in information security should:

a)
  • Eliminate all risks to protect organizational information.

b)
  • Reduce risks to an acceptable level in line with the organization's risk tolerance.

c)
  • Ignore risks that are deemed small or insignificant.

d)
  • Be solely the responsibility of the IT team.

13.

Under ISO 31000, the first step in the risk management cycle is:

a)
  • Evaluating the effectiveness of existing controls.

b)
  • Assessing the impact of each risk.

c)
  • Identifying relevant risks.

d)
  • Developing a risk mitigation plan.

14.

In the context of information security, what does Due Diligence mean?

a)
  • Taking proactive steps to reduce risk.

b)
  • Periodically reviewing policies and procedures.

c)
  • Legal responsibility to implement reasonable security practices.

d)
  • Ignoring risks based on low impact.

15.

In a legal framework, compliance refers to:

a)
  • An organization's obligation to meet internal technical standards.

b)
  • Meeting external standards and regulations applicable to the organization.

c)
  • Enforcing policies on individuals who violate them.

d)
  • Fulfilling all customer requests without exception.

16.

The concept of risk transference in risk management can be applied by:

a)
  • A. Ignoring risks that are too costly to manage.

b)
  • Insuring organizational assets against certain losses.

c)
  • Moving high-risk assets to a safer location.

d)
  • Enhancing hardware security across the board.

17.

Which of the following is a part of the CIA Triad?

a)

Non-repudiation

b)

Audit Control

c)

Incident Response

d)

Accounting

18.

In the context of information security governance, who is responsible for setting policy direction?

a)
  • IT managers.

b)
  • The board of directors or senior leaders.

c)
  • External security auditors.

d)
  • The information security team.

19.

Residual risk is:

a)

  • The risk that remains after all controls are applied.

b)
  • A risk that can be ignored due to minimal impact.

c)
  • A new risk that emerges after policy changes.

d)
  • A risk that only applies to financial planning.

20.

Which of the following is an example of a preventive control in information security?

a)
  • A. Intrusion Detection System (IDS)

b)
  • Strict password policies.

c)
  • User activity monitoring logs.

d)
  • D. Disaster recovery plan.