wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Information Assurance & Security Practice Questions

Total questions: 75

Worksheet time: 13mins

Name
Class
Date
1.

What are the three components of the CIA triad?

a)

Control, Integrity, Assurance

b)

Confidentiality, Integrity, Availability

c)

Cybersecurity, Information, Access

d)
  • Compliance, Identification, Authorization

2.

Which of the following security principles states that users should only have the minimum permissions necessary to perform their tasks?

a)

Least Privilege

b)

Defense in Depth

c)

Fail-Safe Defaults

d)

Separation of Duties

3.

The Bell-LaPadula security model enforces which type of security control?

a)

Integrity

b)

Confidentiality

c)

Availability

d)

Nonrepudiation

4.

In the Biba Integrity Model, the “No Write Up” policy ensures:

a)

Lower integrity levels cannot modify higher integrity levels.

b)

Users can only modify data at their security level.

c)

Users cannot write data to any system.

d)

Data can be accessed freely across security levels.

5.

What is the primary purpose of a mantrap in physical security?

a)

To prevent tailgating into secure areas

b)

To trap intruders permanently

c)

To reinforce network security

d)

To eliminate security guards

6.

Which fire suppression system is most appropriate for protecting sensitive computer equipment?

a)

Water-based sprinkler system

b)

Halon-based system

c)

Clean-agent system (FM-200, Inergen)

d)

Carbon dioxide extinguisher

7.

What is the primary security risk associated with USB flash drives?

a)

They are too expensive for general use.

b)

They can be used to easily bypass security controls.

c)

They can be used to easily bypass security controls.

d)

They require special drivers to function.

8.

Which type of access control system is considered “something you have”?

a)

Biometrics

b)

Passwords

c)

Smart Cards

d)

Security Questions

9.

What is the primary goal of an Acceptable Use Policy (AUP)?

a)

To outline how employees should use company resources

b)

To prevent employees from using personal devices

c)

To set password expiration policies

d)

To establish financial policies for the company

10.

Which security principle ensures that no single person has complete control over a critical process?

a)

Least Privilege

b)

Separation of Duties

c)

Zero Trust

d)
  • Need to Know

11.

What type of agreement defines the level of service expected between a provider and a customer?

a)

Memorandum of Understanding (MOU)

b)

Interconnection Security Agreement (ISA)

c)

Service Level Agreement (SLA)

d)

Non-Disclosure Agreement (NDA)

12.

Which of the following describes the process of requiring employees to take a mandatory vacation to detect fraud?

a)

Role-based training

b)

Clean desk policy

c)

Job rotation

d)

Mandatory vacations

13.

Which PKI component is responsible for issuing digital certificates?

a)

Registration Authority (RA)

b)

Certificate Authority (CA)

c)

Online Certificate Status Protocol (OCSP)

d)

Key Escrow

14.

A digital certificate primarily binds what two elements together?

a)

A private key and a password

b)

A user’s identity and a public key

c)

A certificate policy and an encryption key

d)

A registration authority and a certificate

15.

What is the purpose of a Certificate Revocation List (CRL)?

a)

To store expired certificates

b)

To provide a list of revoked certificates

c)

To generate new public keys

d)

To validate certificates in real-time

16.

Which trust model consists of a single root Certificate Authority (CA) that issues certificates to subordinate CAs?

a)

Peer-to-Peer Trust Model

b)

Hierarchical Trust Model

c)

Cross-Certification Trust Model

d)

Distributed Trust Model

17.

What is the first step in the policy lifecycle?

a)

Develop policies and procedures

b)

Implement policies

c)

Plan for security needs

d)

Evaluate policy effectiveness

18.

In a Zero Trust model, what is the fundamental security assumption?

a)

Users inside the network are trusted by default.

b)

All access must be continuously verified and never assumed.

c)

Firewalls are sufficient for security.

d)
  • Network segmentation is unnecessary.

19.

Which of the following is an example of a social engineering attack?

a)

A hacker exploiting a software vulnerability

b)

A phishing email tricking an employee into revealing credentials

c)

A brute force attack on a login page

d)

A denial-of-service attack

20.

What is the primary purpose of role-based training in cybersecurity?

a)

To ensure that all employees receive identical security training

b)

To tailor security training based on an employee’s job role

c)

To replace security awareness campaigns

d)

To provide advanced technical skills to all employees

21.

The principle of Defense in Depth refers to:

a)

Using multiple, layered security measures to protect assets.

b)

Only using physical security controls to secure networks.

c)

Relying solely on firewalls for network protection.

d)

Encrypting all data to prevent unauthorized access.

22.

What does the term Zero Trust mean in security?

a)

No device or user is trusted by default, and all access must be verified.

b)

All internal employees are automatically trusted.

c)

Firewalls alone provide complete security.

d)

Once authenticated, users can access everything freely.

23.

What is the main function of CCTV cameras in security?

a)

To automatically prevent security breaches

b)

To monitor and record activity for security investigations

c)

To replace security guards

d)

To provide lighting in dark areas

24.

What is the main disadvantage of biometric access control?

a)

It cannot be used in physical security

b)

Biometrics cannot be changed if compromised

c)

It is less secure than passwords

d)

It does not require user authentication

25.

Which policy requires employees to secure sensitive documents before leaving their workstations?

a)

Clean Desk Policy

b)

Password Policy

c)

Acceptable Use Policy

d)

Social Media Policy

26.

What is the primary advantage of a Hierarchical Trust Model in PKI?

a)

It has no central authority.

b)

It allows easy delegation of trust through subordinate CAs.

c)

It eliminates the need for certificates.

d)

It allows users to self-sign their certificates.

27.

What is the purpose of a Non-Disclosure Agreement (NDA)?

a)

To define how employees should behave online

b)

To outline penalties for noncompliance

c)

To protect confidential company information

d)

To establish data retention policies

28.

Job rotation is primarily used to:

a)

Train employees in multiple departments

b)

Reduce fraud by ensuring no one has complete control over a process

c)

Improve teamwork and communication

d)

Replace traditional hiring procedures

29.

Which of the following is NOT a component of a security policy?

a)

Procedures

b)

Guidelines

c)

Employee salary details

d)

Standards

30.

What is the best way to enforce an organization’s security policies?

a)

Rely on employees to follow rules voluntarily

b)

Conduct frequent security awareness training and audits

c)

Use strong technical controls only

d)
  • Restrict access to company resources permanently

31.

What is the main difference between Due Care and Due Diligence?

a)

Due Care refers to policies, while Due Diligence refers to risk assessments

b)

Due Care means taking action, while Due Diligence means assessing risks before acting

c)

Due Care is legally binding, while Due Diligence is optional

d)
  • There is no difference between them

32.

Which agreement is specifically designed to document the security requirements for IT system interconnections?

a)

Service Level Agreement (SLA)

b)

Interconnection Security Agreement (ISA)

c)

Non-Disclosure Agreement (NDA)

d)

Business Partnership Agreement (BPA)

33.

What is the function of an Online Certificate Status Protocol (OCSP)?

a)

To generate encryption keys

b)

To provide real-time verification of certificate validity

c)

To store digital certificates in an offline environment

d)
  • To create backup copies of encryption keys

34.

Key escrow is used for:

a)

Recovering lost encryption keys

b)

Revoking compromised digital certificates

c)

Encrypting data using public key cryptography

d)

Storing passwords securely

35.

What does a Registration Authority (RA) do in PKI?

a)

Manages user access control

b)

Validates certificate requests before forwarding them to the Certificate Authority

c)

Encrypts all network traffic

d)

Stores private keys for end-users

36.

Which PKI trust model relies on each Certificate Authority (CA) trusting another CA without a single root authority?

a)

Peer-to-Peer Trust Model

b)

Hierarchical Trust Model

c)

Cross-Certification Trust Model

d)

Distributed Trust Model

37.

What is the primary goal of security awareness training?

a)

To ensure employees can configure security settings

b)

To help employees recognize and prevent security threats

c)

To improve computer programming skills

d)

To eliminate the need for technical security controls

38.

Which of the following is NOT a recommended security awareness practice?

a)

Regular phishing simulations

b)

Annual security training

c)

Providing security policies only on request

d)

Mandatory security certifications for employees

39.

An employee who never takes time off might be involved in:

a)

Social engineering

b)

Fraudulent activity

c)

Network hacking

d)

Incident response training

40.

Which of the following is a sign of a potential insider threat?

a)

Frequent failed login attempts from an external IP address

b)

Unauthorized access to sensitive data by an employee

c)

A network vulnerability being exploited remotely

d)
  • A Denial-of-Service (DoS) attack on the firewall\

41.

What is the purpose of an Incident Response Plan (IRP)?

a)

To prevent all cyberattacks

b)

To outline how an organization will detect, respond to, and recover from security incidents

c)

To create encryption policies for an organization

d)

To establish guidelines for hiring security personnel

42.

Which of the following should be included in an organization's security awareness training?

a)

Recognizing phishing emails

b)

Secure password creation and management

c)

Proper handling of confidential data

d)

All of the above

43.

Which of the following best describes authentication?

a)

Determining what actions a user can perform

b)

Verifying the identity of a user

c)

Protecting information from unauthorized access

d)
  • Preventing data from being altered

44.

The CIA Triad consists of which three components?

a)

Control, Integrity, Authentication

b)

Confidentiality, Integrity, Availability

c)

Cryptography, Identity, Authorization

d)

Access, Protection, Authentication

45.

Which security principle ensures that users have only the minimum level of access necessary to perform their tasks?

a)

Defense in Depth

b)

Least Privilege

c)

Separation of Duties

d)

Security through Obscurity

46.

What is cryptanalysis?

a)

The process of encrypting data

b)

The method used to generate cryptographic keys

c)

The process of analyzing encrypted data to recover plaintext

d)

A form of hashing used in digital signatures

47.

Which of the following is an example of a substitution cipher?

a)

Caesar Cipher

b)

Diffie-Hellman

c)

Transposition Cipher

d)

RSA

48.

Which cryptographic method uses a pair of keys, one public and one private?

a)

Symmetric encryption

b)

Hashing

c)

Asymmetric encryption

d)

Stream cipher

49.

Which of the following is the most secure hashing algorithm?

a)

MD5

b)

SHA-1

c)

SHA-256

d)

RC4

50.

Which encryption algorithm is known as the "gold standard" for symmetric encryption?

a)

DES

b)

AES

c)

RSA

d)

Blowfish

51.

What is the main advantage of asymmetric encryption over symmetric encryption?

a)

Faster processing

b)

Stronger encryption strength

c)

Solves the key exchange problem

d)

Uses fewer computational resources

52.

What does Diffie-Hellman primarily enable?

a)

Encrypting data at rest

b)

Secure key exchange

c)

Generating digital signatures

d)
  • Hashing passwords

53.

Which of the following best describes Perfect Forward Secrecy?

a)

The ability to recover lost encryption keys

b)

Ensures that past communications remain secure even if a key is compromised

c)

A method for performing brute force attacks

d)

A type of symmetric encryption

54.

Which type of key storage is considered the most secure?

a)

USB flash drive

b)

Hard drive

c)

Trusted Platform Module (TPM)

d)

Cloud storage

55.

Which attack attempts to find two different messages that produce the same hash value?

a)

Brute-force attac

b)

Collision attack

c)

Side-channel attack

d)

Man-in-the-middle attack

56.

What is a key factor in making brute force attacks less effective?

a)

Using shorter keys

b)

Using weak passphrases

c)

Increasing key length

d)

Storing keys in plaintext

57.

Which type of cipher encrypts data one bit or byte at a time?

a)

Block cipher

b)

Stream cipher

c)

Hash function

d)

Digital signature

58.

Which security principle ensures users have only the necessary access to perform their tasks?

a)

Psychological Acceptability

b)

Least Privilege

c)

Open Design

d)

Security Through Obscurity

59.

What does the Bell-LaPadula Model enforce?

a)

No Read Up, No Write Down

b)

No Write Up, No Read Down

c)

Least Privilege

d)

Role-Based Access Control

60.

Which of the following is an example of an asymmetric encryption algorithm?

a)

AES

b)

DES

c)

RSA

d)

Blowfish

61.

What is the primary issue with symmetric encryption?

a)

It is too slow for modern applications.

b)

Key exchange is difficult.

c)

It is insecure against brute-force attacks.

d)
  • It does not support hashing.

62.

Which hashing algorithm is considered the most secure?

a)

MD5

b)

SHA-1

c)

SHA-256

d)

DES

63.

What is the difference between a stream cipher and a block cipher?

a)

A block cipher encrypts data bit by bit, while a stream cipher encrypts in fixed-size blocks.

b)

A stream cipher encrypts data bit by bit, while a block cipher encrypts in fixed-size blocks.

c)

Block ciphers are only used in asymmetric encryption.

d)

Stream ciphers are always more secure.

64.

Which of the following describes the purpose of a Certificate Authority (CA)?

a)

Encrypts data using a private key

b)

Issues digital certificates for identity verification

c)

Generates symmetric encryption keys

d)
  • Performs brute-force attacks on cryptographic keys

65.

Which cryptographic method is used to securely exchange keys?

a)

AES

b)

RSA

c)

Diffie-Hellman

d)

MD5

66.

Which of the following best describes Perfect Forward Secrecy?

a)

It ensures past communications remain secure even if a key is compromised.

b)

It allows a key to be reused for multiple encryption sessions.

c)

It increases key length for enhanced security.

d)

It requires multi-factor authentication.

67.

What is the main benefit of quantum cryptography?

a)

Faster encryption speeds

b)

Resistance to traditional decryption methods

c)

Uses existing cryptographic algorithms

d)

Reduces power consumption

68.

Which of the following is NOT a core function of the NIST Cybersecurity Framework 2.0?

a)

Identify

b)

Govern

c)

Encrypt

d)

Respond

69.

What is a key characteristic of an ephemeral key?

a)

It is used for multiple encryption sessions.

b)

It is stored indefinitely for reuse.

c)

It is generated for one-time use and then discarded.

d)
  • It replaces a digital certificate in asymmetric encryption.

70.

Which of the following best describes key escrow?

a)

A process of permanently revoking cryptographic keys.

b)

Securely storing keys for possible future recovery.

c)

A method of hashing sensitive data.

d)

Using multiple keys in a single encryption algorithm.

71.

Which cipher uses a continuously generated keystream to encrypt data bit by bit?

a)

AES

b)

RSA

c)

Stream cipher

d)

Block cipher

72.

What does a Memorandum of Understanding (MOU) typically define?

a)

A legally binding contract between two organizations

b)

A non-binding agreement outlining intended actions between parties

c)

A set of regulations governing data classification

d)
  • An encryption method used in block ciphers

73.

What is the primary purpose of hashing in cryptography?

a)

Encrypting data for secure transmission

b)

Generating a unique, fixed-length representation of data

c)

Creating a pair of public and private keys

d)
  • Exchanging encryption keys between users

74.

Which of the following is an advantage of symmetric encryption?

a)

It uses smaller key sizes for stronger security.

b)

It is faster and more efficient for large data transfers.

c)

It does not require key management.

d)

It eliminates the need for encryption keys altogether.

75.

Which of the following is a significant security concern with quantum computing?

a)

It will increase brute-force attack times.

b)

It can break current encryption methods much faster.

c)

It eliminates the need for encryption in secure communication.

d)

It only affects symmetric encryption methods.