NEW
Font size
WorksheetsInformation Assurance & Security Practice Questions
Total questions: 75
Worksheet time: 13mins
What are the three components of the CIA triad?
Control, Integrity, Assurance
Confidentiality, Integrity, Availability
Cybersecurity, Information, Access
Compliance, Identification, Authorization
Which of the following security principles states that users should only have the minimum permissions necessary to perform their tasks?
Least Privilege
Defense in Depth
Fail-Safe Defaults
Separation of Duties
The Bell-LaPadula security model enforces which type of security control?
Integrity
Confidentiality
Availability
Nonrepudiation
In the Biba Integrity Model, the “No Write Up” policy ensures:
Lower integrity levels cannot modify higher integrity levels.
Users can only modify data at their security level.
Users cannot write data to any system.
Data can be accessed freely across security levels.
What is the primary purpose of a mantrap in physical security?
To prevent tailgating into secure areas
To trap intruders permanently
To reinforce network security
To eliminate security guards
Which fire suppression system is most appropriate for protecting sensitive computer equipment?
Water-based sprinkler system
Halon-based system
Clean-agent system (FM-200, Inergen)
Carbon dioxide extinguisher
What is the primary security risk associated with USB flash drives?
They are too expensive for general use.
They can be used to easily bypass security controls.
They can be used to easily bypass security controls.
They require special drivers to function.
Which type of access control system is considered “something you have”?
Biometrics
Passwords
Smart Cards
Security Questions
What is the primary goal of an Acceptable Use Policy (AUP)?
To outline how employees should use company resources
To prevent employees from using personal devices
To set password expiration policies
To establish financial policies for the company
Which security principle ensures that no single person has complete control over a critical process?
Least Privilege
Separation of Duties
Zero Trust
Need to Know
What type of agreement defines the level of service expected between a provider and a customer?
Memorandum of Understanding (MOU)
Interconnection Security Agreement (ISA)
Service Level Agreement (SLA)
Non-Disclosure Agreement (NDA)
Which of the following describes the process of requiring employees to take a mandatory vacation to detect fraud?
Role-based training
Clean desk policy
Job rotation
Mandatory vacations
Which PKI component is responsible for issuing digital certificates?
Registration Authority (RA)
Certificate Authority (CA)
Online Certificate Status Protocol (OCSP)
Key Escrow
A digital certificate primarily binds what two elements together?
A private key and a password
A user’s identity and a public key
A certificate policy and an encryption key
A registration authority and a certificate
What is the purpose of a Certificate Revocation List (CRL)?
To store expired certificates
To provide a list of revoked certificates
To generate new public keys
To validate certificates in real-time
Which trust model consists of a single root Certificate Authority (CA) that issues certificates to subordinate CAs?
Peer-to-Peer Trust Model
Hierarchical Trust Model
Cross-Certification Trust Model
Distributed Trust Model
What is the first step in the policy lifecycle?
Develop policies and procedures
Implement policies
Plan for security needs
Evaluate policy effectiveness
In a Zero Trust model, what is the fundamental security assumption?
Users inside the network are trusted by default.
All access must be continuously verified and never assumed.
Firewalls are sufficient for security.
Network segmentation is unnecessary.
Which of the following is an example of a social engineering attack?
A hacker exploiting a software vulnerability
A phishing email tricking an employee into revealing credentials
A brute force attack on a login page
A denial-of-service attack
What is the primary purpose of role-based training in cybersecurity?
To ensure that all employees receive identical security training
To tailor security training based on an employee’s job role
To replace security awareness campaigns
To provide advanced technical skills to all employees
The principle of Defense in Depth refers to:
Using multiple, layered security measures to protect assets.
Only using physical security controls to secure networks.
Relying solely on firewalls for network protection.
Encrypting all data to prevent unauthorized access.
What does the term Zero Trust mean in security?
No device or user is trusted by default, and all access must be verified.
All internal employees are automatically trusted.
Firewalls alone provide complete security.
Once authenticated, users can access everything freely.
What is the main function of CCTV cameras in security?
To automatically prevent security breaches
To monitor and record activity for security investigations
To replace security guards
To provide lighting in dark areas
What is the main disadvantage of biometric access control?
It cannot be used in physical security
Biometrics cannot be changed if compromised
It is less secure than passwords
It does not require user authentication
Which policy requires employees to secure sensitive documents before leaving their workstations?
Clean Desk Policy
Password Policy
Acceptable Use Policy
Social Media Policy
What is the primary advantage of a Hierarchical Trust Model in PKI?
It has no central authority.
It allows easy delegation of trust through subordinate CAs.
It eliminates the need for certificates.
It allows users to self-sign their certificates.
What is the purpose of a Non-Disclosure Agreement (NDA)?
To define how employees should behave online
To outline penalties for noncompliance
To protect confidential company information
To establish data retention policies
Job rotation is primarily used to:
Train employees in multiple departments
Reduce fraud by ensuring no one has complete control over a process
Improve teamwork and communication
Replace traditional hiring procedures
Which of the following is NOT a component of a security policy?
Procedures
Guidelines
Employee salary details
Standards
What is the best way to enforce an organization’s security policies?
Rely on employees to follow rules voluntarily
Conduct frequent security awareness training and audits
Use strong technical controls only
Restrict access to company resources permanently
What is the main difference between Due Care and Due Diligence?
Due Care refers to policies, while Due Diligence refers to risk assessments
Due Care means taking action, while Due Diligence means assessing risks before acting
Due Care is legally binding, while Due Diligence is optional
There is no difference between them
Which agreement is specifically designed to document the security requirements for IT system interconnections?
Service Level Agreement (SLA)
Interconnection Security Agreement (ISA)
Non-Disclosure Agreement (NDA)
Business Partnership Agreement (BPA)
What is the function of an Online Certificate Status Protocol (OCSP)?
To generate encryption keys
To provide real-time verification of certificate validity
To store digital certificates in an offline environment
To create backup copies of encryption keys
Key escrow is used for:
Recovering lost encryption keys
Revoking compromised digital certificates
Encrypting data using public key cryptography
Storing passwords securely
What does a Registration Authority (RA) do in PKI?
Manages user access control
Validates certificate requests before forwarding them to the Certificate Authority
Encrypts all network traffic
Stores private keys for end-users
Which PKI trust model relies on each Certificate Authority (CA) trusting another CA without a single root authority?
Peer-to-Peer Trust Model
Hierarchical Trust Model
Cross-Certification Trust Model
Distributed Trust Model
What is the primary goal of security awareness training?
To ensure employees can configure security settings
To help employees recognize and prevent security threats
To improve computer programming skills
To eliminate the need for technical security controls
Which of the following is NOT a recommended security awareness practice?
Regular phishing simulations
Annual security training
Providing security policies only on request
Mandatory security certifications for employees
An employee who never takes time off might be involved in:
Social engineering
Fraudulent activity
Network hacking
Incident response training
Which of the following is a sign of a potential insider threat?
Frequent failed login attempts from an external IP address
Unauthorized access to sensitive data by an employee
A network vulnerability being exploited remotely
A Denial-of-Service (DoS) attack on the firewall\
What is the purpose of an Incident Response Plan (IRP)?
To prevent all cyberattacks
To outline how an organization will detect, respond to, and recover from security incidents
To create encryption policies for an organization
To establish guidelines for hiring security personnel
Which of the following should be included in an organization's security awareness training?
Recognizing phishing emails
Secure password creation and management
Proper handling of confidential data
All of the above
Which of the following best describes authentication?
Determining what actions a user can perform
Verifying the identity of a user
Protecting information from unauthorized access
Preventing data from being altered
The CIA Triad consists of which three components?
Control, Integrity, Authentication
Confidentiality, Integrity, Availability
Cryptography, Identity, Authorization
Access, Protection, Authentication
Which security principle ensures that users have only the minimum level of access necessary to perform their tasks?
Defense in Depth
Least Privilege
Separation of Duties
Security through Obscurity
What is cryptanalysis?
The process of encrypting data
The method used to generate cryptographic keys
The process of analyzing encrypted data to recover plaintext
A form of hashing used in digital signatures
Which of the following is an example of a substitution cipher?
Caesar Cipher
Diffie-Hellman
Transposition Cipher
RSA
Which cryptographic method uses a pair of keys, one public and one private?
Symmetric encryption
Hashing
Asymmetric encryption
Stream cipher
Which of the following is the most secure hashing algorithm?
MD5
SHA-1
SHA-256
RC4
Which encryption algorithm is known as the "gold standard" for symmetric encryption?
DES
AES
RSA
Blowfish
What is the main advantage of asymmetric encryption over symmetric encryption?
Faster processing
Stronger encryption strength
Solves the key exchange problem
Uses fewer computational resources
What does Diffie-Hellman primarily enable?
Encrypting data at rest
Secure key exchange
Generating digital signatures
Hashing passwords
Which of the following best describes Perfect Forward Secrecy?
The ability to recover lost encryption keys
Ensures that past communications remain secure even if a key is compromised
A method for performing brute force attacks
A type of symmetric encryption
Which type of key storage is considered the most secure?
USB flash drive
Hard drive
Trusted Platform Module (TPM)
Cloud storage
Which attack attempts to find two different messages that produce the same hash value?
Brute-force attac
Collision attack
Side-channel attack
Man-in-the-middle attack
What is a key factor in making brute force attacks less effective?
Using shorter keys
Using weak passphrases
Increasing key length
Storing keys in plaintext
Which type of cipher encrypts data one bit or byte at a time?
Block cipher
Stream cipher
Hash function
Digital signature
Which security principle ensures users have only the necessary access to perform their tasks?
Psychological Acceptability
Least Privilege
Open Design
Security Through Obscurity
What does the Bell-LaPadula Model enforce?
No Read Up, No Write Down
No Write Up, No Read Down
Least Privilege
Role-Based Access Control
Which of the following is an example of an asymmetric encryption algorithm?
AES
DES
RSA
Blowfish
What is the primary issue with symmetric encryption?
It is too slow for modern applications.
Key exchange is difficult.
It is insecure against brute-force attacks.
It does not support hashing.
Which hashing algorithm is considered the most secure?
MD5
SHA-1
SHA-256
DES
What is the difference between a stream cipher and a block cipher?
A block cipher encrypts data bit by bit, while a stream cipher encrypts in fixed-size blocks.
A stream cipher encrypts data bit by bit, while a block cipher encrypts in fixed-size blocks.
Block ciphers are only used in asymmetric encryption.
Stream ciphers are always more secure.
Which of the following describes the purpose of a Certificate Authority (CA)?
Encrypts data using a private key
Issues digital certificates for identity verification
Generates symmetric encryption keys
Performs brute-force attacks on cryptographic keys
Which cryptographic method is used to securely exchange keys?
AES
RSA
Diffie-Hellman
MD5
Which of the following best describes Perfect Forward Secrecy?
It ensures past communications remain secure even if a key is compromised.
It allows a key to be reused for multiple encryption sessions.
It increases key length for enhanced security.
It requires multi-factor authentication.
What is the main benefit of quantum cryptography?
Faster encryption speeds
Resistance to traditional decryption methods
Uses existing cryptographic algorithms
Reduces power consumption
Which of the following is NOT a core function of the NIST Cybersecurity Framework 2.0?
Identify
Govern
Encrypt
Respond
What is a key characteristic of an ephemeral key?
It is used for multiple encryption sessions.
It is stored indefinitely for reuse.
It is generated for one-time use and then discarded.
It replaces a digital certificate in asymmetric encryption.
Which of the following best describes key escrow?
A process of permanently revoking cryptographic keys.
Securely storing keys for possible future recovery.
A method of hashing sensitive data.
Using multiple keys in a single encryption algorithm.
Which cipher uses a continuously generated keystream to encrypt data bit by bit?
AES
RSA
Stream cipher
Block cipher
What does a Memorandum of Understanding (MOU) typically define?
A legally binding contract between two organizations
A non-binding agreement outlining intended actions between parties
A set of regulations governing data classification
An encryption method used in block ciphers
What is the primary purpose of hashing in cryptography?
Encrypting data for secure transmission
Generating a unique, fixed-length representation of data
Creating a pair of public and private keys
Exchanging encryption keys between users
Which of the following is an advantage of symmetric encryption?
It uses smaller key sizes for stronger security.
It is faster and more efficient for large data transfers.
It does not require key management.
It eliminates the need for encryption keys altogether.
Which of the following is a significant security concern with quantum computing?
It will increase brute-force attack times.
It can break current encryption methods much faster.
It eliminates the need for encryption in secure communication.
It only affects symmetric encryption methods.
