Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

IAS_REVIEWER

Total questions: 136

Worksheet time: 1hrs 8mins

Name
Class
Date
1.

addresses the threats, vulnerabilities, and countermeasures that can be utilized to physically protect an enterprise’s resources and sensitive information.

a)

PHYSICAL SECURITY

b)

SECURING WORKPLACES

c)

SECURING NETWORK INFRASTRACTURE

d)

PROTECTING COMMUNICATION LINES

2.

a centers house servers, storage devices, and networking equipment that store and process sensitive data.

a)

PROTECTING DATA CENTERS

b)

SECURING WORKPLACES

c)

SECURING NETWORK INFRASTRACTURE

d)

PROTECTING COMMUNICATION LINES

3.

essential for safeguarding office spaces and workstations where employees access and use digital assets.

a)

PROTECTING DATA CENTERS

b)

SECURING WORKPLACES

c)

SECURING NETWORK INFRASTRACTURE

d)

PROTECTING COMMUNICATION LINES

4.

including backup power systems, environmental controls, and fire suppression systems, help ensure the continuous operation of data centers and IT infrastructure

a)

PROTECTING DATA CENTERS

b)

SECURING WORKPLACES

c)

SECURING NETWORK INFRASTRACTURE

d)

ENSURING BUSINESS CONTINUITY

5.

Networking equipment, including routers, switches, and cabling, forms the backbone of an organization's digital communication.

a)

PROTECTING DATA CENTERS

b)

SECURING WORKPLACES

c)

SECURING NETWORK INFRASTRACTURE

d)

ENSURING BUSINESS CONTINUITY

6.

helps prevent theft of physical devices that contain sensitive information, such as laptops, smartphones, and removable storage media.

a)

PROTECTING DATA CENTERS

b)

PREVENTING PHYSICAL THEFT

c)

SECURING NETWORK INFRASTRACTURE

d)

PROTECTING COMMUNICATION LINES

7.

extends to the protection of communication lines, such as fiber optic or copper cables. Damage to these lines can disrupt connectivity and impact data transfer, emphasizing the importance of securing physical infrastructure

a)

PROTECTING DATA CENTERS

b)

PREVENTING PHYSICAL THEFT

c)

SECURING NETWORK INFRASTRACTURE

d)

PROTECTING COMMUNICATION LINES

8.

including key cards, biometrics, and smart locks, ensure that only authorized individuals can enter secure areas or gain physical access to devices. This prevents unauthorized personnel from tampering with or compromising information systems.

a)

MANAGING PHYSICAL ACCESS

b)

ENVIRONMENTAL CONTROLS

c)

PHYSICAL INTRUSION DETECTION

d)

VISITOR AND CROWD MANAGEMENT

9.

Managing the entry and movement of visitors within an organization's premises is essential for maintaining security. Visitor logs, badges, and escort policies are part of physical security practices.

a)

MANAGING PHYSICAL ACCESS

b)

ENVIRONMENTAL CONTROLS

c)

PHYSICAL INTRUSION DETECTION

d)

VISITOR AND CROWD MANAGEMENT

10.

such as temperature and humidity regulation, protect servers and storage devices from environmental factors that could lead to hardware failure and data loss.

a)

MANAGING PHYSICAL ACCESS

b)

ENVIRONMENTAL CONTROLS

c)

PHYSICAL INTRUSION DETECTION

d)

VISITOR AND CROWD MANAGEMENT

11.

can detect unauthorized physical access or tampering attempts, triggering alarms or alerts for rapid response.

a)

MANAGING PHYSICAL ACCESS

b)

ENVIRONMENTAL CONTROLS

c)

PHYSICAL INTRUSION DETECTION

d)

VISITOR AND CROWD MANAGEMENT

12.

can include strategies for disaster recovery, such as offsite backups and secure storage of critical data, to ensure data can be recovered in case of physical disasters like fires or floods

a)

MANAGING PHYSICAL ACCESS

b)

ENVIRONMENTAL CONTROLS

c)

DISASTER RECOVERY

d)

VISITOR AND CROWD MANAGEMENT

13.

a concept in physical security enforcement, is a strategy aimed at discouraging potential threats or malicious actors from attempting unauthorized actions, intrusions, or security breaches.

a)

DETERRENCE

b)

DELAY

14.

steps done to address a security breach, incident, or threat in order to ameliorate the situation and safeguard resources, people, and information are referred to as response, which is a crucial part of physical security enforcement. In order to reduce the effects of security incidents and swiftly resume normal operations, an efficient reaction is essential.

a)

DETERRENCE

b)

RESPONSE

c)

DETECTION

15.

a physical security enforcement strategy, is focused on slowing down or impeding unauthorized individuals or threats from accessing secured areas, assets, or information. Delay measures are intended to provide security personnel with more time to respond to an intrusion or threat, thereby enhancing overall security

a)

DETERRENCE

b)

DELAY

16.

is a proactive and continuing procedure used as part of physical security enforcement with the goal of identifying and analyzing potential security risks and weaknesses.

a)

DETERRENCE

b)

ASSESSMENT

c)

DETECTION

17.

a tactic for enforcing physical security, detection concentrates on locating and warning security systems or employees of potential threats. In order to respond quickly to security issues and mitigate them, detection aims to quickly identify suspicious activity or security violations.

a)

DETERRENCE

b)

DELAY

c)

DETECTION

18.

which serves as the bridge between hardware and software, providing the necessary interface for users and applications to interact with computer resources

a)

OPERATING SYSTEM

b)

OPERATING SYSTEM SECURITY

19.

refers to the operating systems-based implementation of measures essential for safeguarding sensitive data, preventing cyberattacks, ensuring regulatory compliance, maintaining system availability, and protecting desktop computer or laptop

a)

OPERATING SYSTEM

b)

OPERATING SYSTEM SECURITY

20.

Controlled Access Points

a)

Security Layers: Delay

b)

Security Layers: Detection

21.

Locks and Barriers

a)

Security Layers: Delay

b)

Security Layers: Detection

22.

Mantrap

a)

Security Layers: Delay

b)

Security Layers: Detection

23.

Security Fencing

a)

Security Layers: Delay

b)

Security Layers: Detection

24.

Electronic Access Control Systems

a)

Security Layers: Delay

b)

Security Layers: Detection

25.

Security Glazing

a)

Security Layers: Delay

b)

Security Layers: Detection

26.

Safe Rooms

a)

Security Layers: Delay

b)

Security Layers: Detection

27.

Vehicle Barriers

a)

Security Layers: Delay

b)

Security Layers: Detection

28.

Vaults and Secure Storage

a)

Security Layers: Delay

b)

Security Layers: Detection

29.

Access Control Procedures

a)

Security Layers: Delay

b)

Security Layers: Detection

30.

Surveillance Cameras

a)

Security Layers: Delay

b)

Security Layers: Detection

31.

Intrusion Detection System

a)

Security Layers: Delay

b)

Security Layers: Detection

32.

Access Control Logs

a)

Security Layers: Delay

b)

Security Layers: Detection

33.

Biometric Systems

a)

Security Layers: Delay

b)

Security Layers: Detection

34.

Motion Sensors

a)

Security Layers: Delay

b)

Security Layers: Detection

35.

Environmental Sensors

a)

Security Layers: Delay

b)

Security Layers: Detection

36.

Perimeter Security ❖ Sound Detection

a)

Security Layers: Delay

b)

Security Layers: Detection

37.

Radio Frequency Identification (RFID) ❖ Security Personnel

a)

Security Layers: Delay

b)

Security Layers: Detection

38.

Behavioral analytics ❖ Duress Alarms

a)

Security Layers: Delay

b)

Security Layers: Detection

39.

❖Physical Damage

❖ Disruption of services

❖ Physical Theft

❖ Unauthorized Disclosure of Data

❖ Loss of System Integrity

a)

Physical Security Threats

b)

Categories of Physical Security Threats

40.

❖Natural Environment Threats

❖ Supply system Threats

❖ Manmade Threats

❖ Politically Motivated Threats

a)

Physical Security Threats

b)

Categories of Physical Security Threats

41.

3 Common Example of Desktop Operating System except.

a)

Microsoft Windows

b)

MacOS

c)

Linux

d)

Yahoo

42.
  • - often referred to as user-level or user space, is one of the privilege levels in the security architecture of an operating system

a)

USER MODE

b)

RESTRICTED/ LEAST PRIVELEGES

c)

ISOLATION

d)

SYSTEM CALLS

43.
  • - applications and user-level processes run with restricted privileges and have limited access to system resources.

a)

USER MODE

b)

RESTRICTED/ LEAST PRIVELEGES

c)

ISOLATION

d)

SYSTEM CALLS

44.
  • User mode processes operate with a lower level of privilege compared to the kernel mode. They are not allowed to execute sensitive or privileged operations directly, such as accessing hardware resources or modifying the operating system kerne

a)

USER MODE

b)

RESTRICTED/ LEAST PRIVELEGES

c)

ISOLATION

d)

SYSTEM CALLS

45.
  • Each user mode process runs in its own isolated environment, ensuring that one process cannot interfere with or directly access the memory or resources of another process.

a)

USER MODE

b)

RESTRICTED/ LEAST PRIVELEGES

c)

ISOLATION

d)

SYSTEM CALLS

46.
  • User mode processes can interact with the kernel and request access to system resources through system calls or API functions. These system calls act as gateways to kernel-level operations and are carefully controlled and validated by the operating system to prevent misuse.

a)

USER MODE

b)

RESTRICTED/ LEAST PRIVELEGES

c)

ISOLATION

d)

SYSTEM CALLS

47.

The operating system manages and allocates system resources, such as memory, CPU time, and I/O devices, on behalf of user mode processes.

a)

RESOURCE MANAGEMENT

b)

ERROR HANDLING

c)

USER ACCOUNT CONTEXT

d)

APPLICATION SANDBOX

e)

KERNEL MODE

48.

exceptions that occur in user mode processes typically do not disrupt the entire system

a)

RESOURCE MANAGEMENT

b)

ERROR HANDLING

c)

USER ACCOUNT CONTEXT

d)

APPLICATION SANDBOX

e)

KERNEL MODE

49.

User mode processes execute within the context of a specific user account. Access to files, directories, and other resources is determined by the permissions associated with that user's account, as well as system-wide access control policies.

a)

RESOURCE MANAGEMENT

b)

ERROR HANDLING

c)

USER ACCOUNT CONTEXT

d)

APPLICATION SANDBOX

e)

KERNEL MODE

50.

Some operating systems or security tools implement application sandboxing techniques to further isolate and control the behavior of user mode applications

a)

RESOURCE MANAGEMENT

b)

ERROR HANDLING

c)

USER ACCOUNT CONTEXT

d)

APPLICATION SANDBOX

e)

KERNEL MODE

51.

known as supervisor mode or privileged mode, is one of the two primary privilege levels in the security architecture of an operating system. It operates at the highest privilege level and is responsible for managing and controlling the core functions of the operating system and hardware resources.

a)

RESOURCE MANAGEMENT

b)

ERROR HANDLING

c)

USER ACCOUNT CONTEXT

d)

APPLICATION SANDBOX

e)

KERNEL MODE

52.

- Kernel mode operates with full privileges, allowing it to access and control all hardware resources and execute sensitive and privileged instructions. It has unrestricted access to system memory and can execute instructions that user mode processes cannot

a)

HIGHEST PRIVILEGE

b)

SYSTEM RESOURCE MANAGEMENT

c)

SYSTEM CALLS

d)

DEVICE DRIVERS

53.

The kernel is responsible for managing and allocating system resources, including CPU time, memory, input/output devices, and peripheral hardware. It ensures efficient resource utilization and fairness among processes.

a)

HIGHEST PRIVILEGE

b)

SYSTEM RESOURCE MANAGEMENT

c)

SYSTEM CALLS

d)

DEVICE DRIVERS

54.

User mode processes interact with the kernel through system calls or API functions to request access to hardware resources and perform privileged operations. The kernel validates and enforces access control policies for these system calls to prevent unauthorized actions.

a)

HIGHEST PRIVILEGE

b)

SYSTEM RESOURCE MANAGEMENT

c)

SYSTEM CALLS

d)

DEVICE DRIVERS

55.

which enable communication between the operating system and hardware devices, typically run in kernel mode. This allows them to directly access and control hardware components.

a)

HIGHEST PRIVILEGE

b)

SYSTEM RESOURCE MANAGEMENT

c)

SYSTEM CALLS

d)

DEVICE DRIVERS

56.

Kernel mode enforces security policies and access control mechanisms to protect system resources and ensure data integrity. It verifies user authentication, enforces file and directory permissions, and handles security-related operations.

a)

OPERATING SYSTEM CORE

b)

MEMORY PROTECTION

c)

ERROR HANDLING

d)

SECURITY ENFORCEMENT

57.

mode is responsible for handling critical system errors and exceptions. If a user mode process encounters a severe error, it may trigger a context switch to kernel mode for proper error handling and recovery

a)

OPERATING SYSTEM CORE

b)

MEMORY PROTECTION

c)

ERROR HANDLING

d)

SECURITY ENFORCEMENT

58.

Kernel mode processes are isolated from user mode processes to prevent unauthorized access or interference. Memory protection mechanisms, such as virtual memory and hardware memory management units (MMUs), help enforce this isolation

a)

OPERATING SYSTEM CORE

b)

MEMORY PROTECTION

c)

ERROR HANDLING

d)

SECURITY ENFORCEMENT

59.

The core components of the operating system, including the scheduler, file system, memory manager, and process manager, operate in kernel mode. These components are essential for the proper functioning of the operating system

a)

OPERATING SYSTEM CORE

b)

MEMORY PROTECTION

c)

ERROR HANDLING

d)

SECURITY ENFORCEMENT

60.

Kernel mode can execute privileged CPU instructions that user mode cannot. These instructions allow the kernel to manage hardware resources directly and control system behavior.

a)

PRIVILEGE INSTRUCTION

b)

SYSTEM INTEGRITY

c)

ERROR HANDLING

d)

SECURITY ENFORCEMENT

61.

refers to the delivery of computing services, such as storage, processing power, and applications, over the internet

a)

CLOUD COMPUTING

b)

REMOTE WORK

62.

also known as telecommuting or teleworking, involves employees working outside the traditional office environment, often enabled by cloud technologies.

a)

CLOUD COMPUTING

b)

REMOTE WORK

63.

- Ensuring the integrity of the kernel is paramount. Any compromise of the kernel could lead to security breaches, system instability, or unauthorized access to sensitive data.

a)

PRIVILEGE INSTRUCTION

b)

SYSTEM INTEGRITY

c)

ERROR HANDLING

d)

SECURITY ENFORCEMENT

64.

sensitivity refers to the degree of confidentiality, importance, or potential harm associated with specific pieces of data. It indicates how critical it is to protect and control access to certain information to prevent unauthorized disclosure, misuse, or loss.

a)

INFORMATION SENSITIVITY

b)

COMPLIANCE WITH REGULATIONS

c)

RISK REDUCTION

d)

ENHANCEMENT OF BUSINESS OPERATIONS

e)

GAINING COMPETITIVE ADVANTAGE

65.

a critical aspect of ensuring information assurance and security. Many industries and sectors are subject to specific laws, regulations, and standards that mandate how sensitive information should be handled, protected, and secured. Non-compliance can lead to legal penalties, reputational damage, and loss of trust

a)

INFORMATION SENSITIVITY

b)

COMPLIANCE WITH REGULATIONS

c)

RISK REDUCTION

d)

ENHANCEMENT OF BUSINESS OPERATIONS

e)

GAINING COMPETITIVE ADVANTAGE

66.

a fundamental concept in the realm of information assurance and security. It involves taking proactive measures to minimize the potential negative impacts of threats and vulnerabilities on an organization's information assets.

a)

INFORMATION SENSITIVITY

b)

COMPLIANCE WITH REGULATIONS

c)

RISK REDUCTION

d)

ENHANCEMENT OF BUSINESS OPERATIONS

e)

GAINING COMPETITIVE ADVANTAGE

67.

IAS can help businesses to improve their operations by reducing downtime, improving efficiency, and increasing productivity.

a)

INFORMATION SENSITIVITY

b)

COMPLIANCE WITH REGULATIONS

c)

RISK REDUCTION

d)

ENHANCEMENT OF BUSINESS OPERATIONS

e)

GAINING COMPETITIVE ADVANTAGE

68.

Businesses that implement strong IAS can gain a competitive advantage by protecting their information assets and demonstrating their commitment to security.

a)

INFORMATION SENSITIVITY

b)

COMPLIANCE WITH REGULATIONS

c)

RISK REDUCTION

d)

ENHANCEMENT OF BUSINESS OPERATIONS

e)

GAINING COMPETITIVE ADVANTAGE

69.

is a central objective of information assurance and security. Protection against cyber threats is an ongoing effort that requires constant vigilance, adaptation to new threats, and collaboration among various stakeholders

a)

Protecting Against Cyber Threats

b)

Preservation of Privacy

c)

Mitigation of Data Breaches

d)

Safeguarding Intellectual Property (IP)

70.

y is not only a legal requirement in many jurisdictions but also an ethical responsibility. Organizations that prioritize privacy protection build trust with customers and demonstrate their commitment to responsible data handling practices.

a)

Protecting Against Cyber Threats

b)

Preservation of Privacy

c)

Mitigation of Data Breaches

d)

Safeguarding Intellectual Property (IP)

71.

is a critical aspect of information assurance and security. Data breaches can lead to significant financial losses, reputational damage, legal liabilities, and loss of customer trust

a)

Protecting Against Cyber Threats

b)

Preservation of Privacy

c)

Mitigation of Data Breaches

d)

Safeguarding Intellectual Property (IP)

72.

is a critical aspect of information assurance and security, particularly for organizations that rely on innovation, research, and proprietary knowledge for their competitive advantage

a)

Protecting Against Cyber Threats

b)

Preservation of Privacy

c)

Mitigation of Data Breaches

d)

Safeguarding Intellectual Property (IP)

73.

is a crucial goal of information assurance and security.

a)

Ensuring Business Continuity

b)

Legal Compliance

c)

Trust and Reputation

d)

Global Connectivity

e)

Cloud Computing and Remote Work

74.

are subject to regulations regarding data protection and privacy. Compliance with these regulations is not only necessary to avoid penalties but also to protect customers' rights

a)

Ensuring Business Continuity

b)

Legal Compliance

c)

Trust and Reputation

d)

Global Connectivity

e)

Cloud Computing and Remote Work

75.

are invaluable assets that organizations can build and maintain through effective information assurance and security practices. Demonstrating strong information security practices builds trust and enhances an organization's reputation.

a)

Ensuring Business Continuity

b)

Legal Compliance

c)

Trust and Reputation

d)

Global Connectivity

e)

Cloud Computing and Remote Work

76.

is commonly-defined as the process of preventing unauthorized individuals from accessing, using, disclosing, disrupting, altering, or destroying digital information and data

a)

Ensuring Business Continuity

b)

Legal Compliance

c)

Information Security

d)

Global Connectivity

e)

Cloud Computing and Remote Work

77.

refers to the interconnectedness of people, organizations, devices, and systems across the world through various communication networks and technologies. It enables the seamless exchange of information, data, and resources on a global scale

a)

Ensuring Business Continuity

b)

Legal Compliance

c)

Trust and Reputation

d)

Global Connectivity

e)

Cloud Computing and Remote Work

78.

is a primary goal of information assurance and security for organizations. Effective security measures can help mitigate risks associated with cyber threats, data breaches, and other security incidents that can lead to significant financial damage.

a)

Ensuring Business Continuity

b)

Legal Compliance

c)

Preventing Financial Losses

d)

Global Connectivity

e)

Cloud Computing and Remote Work

79.

Governments and critical infrastructure rely on secure information systems to ensure national security and public safety .
- requires a comprehensive approach that involves government agencies, law enforcement, intelligence organizations, military forces, and private sector partners.

a)

Protecting National Security

b)

Education and Awareness

c)

Cloud Computing and Remote Work

d)

Preventing Financial Loses

80.

are foundational pillars of information assurance and security. By educating people about best practices, potential risks, and the importance of security measures, we can collectively enhance the overall cybersecurity posture.

a)

Protecting National Security

b)

Education and Awareness

c)

Cloud Computing and Remote Work

d)

Preventing Financial Loses

81.

are weaknesses in the physical security of an organization that can be exploited by attackers to gain unauthorized access to sensitive information or systems

a)

Physical Security Vulnerabilities

b)

Insider Threats

c)

Malware

d)

Phishing and Social Engineering

e)

Data Breaches

82.

are security risks that arise from malicious or unintentional actions by individuals who have authorized access to an organization's systems and data. Insider threats can be costly and disruptive, and they can damage an organization's resources.

a)

Physical Security Vulnerabilities

b)

Insider Threats

c)

Malware

d)

Phishing and Social Engineering

e)

Data Breaches

83.

is any software that is designed to harm a computer system. Malware can be installed on a computer through a variety of means, such as clicking on a malicious link, opening an infected attachment, or downloading a file from an untrusted source.

a)

Physical Security Vulnerabilities

b)

Insider Threats

c)

Malware

d)

Phishing and Social Engineering

e)

Data Breaches

84.

a more general term that refers to any attempt to trick someone into giving up their personal information or taking an action that they would not normally do

a)

Physical Security Vulnerabilities

b)

Insider Threats

c)

Social Engineering

d)

Phishing

e)

Data Breaches

85.

type of social engineering attack that involves sending emails or text messages that appear to be from a legitimate source, such as a bank or credit card company

a)

Physical Security Vulnerabilities

b)

Insider Threats

c)

Social Engineering

d)

Phishing

e)

Data Breaches

86.

an incident in which sensitive, confidential, or protected data is exposed to an unauthorized individual or entity. Unauthorized access to sensitive data, either through cyberattacks or human error, can result in data leaks and financial losses

a)

Physical Security Vulnerabilities

b)

Insider Threats

c)

Social Engineering

d)

Phishing

e)

Data Breaches

87.

a type of cyber-attack that is characterized by its sophistication, stealth, and duration. APTs are typically launched by nationstate actors or well-funded criminal organizations, and they often target high-value targets, such as government agencies, financial institutions, and critical infrastructure organizations

a)

Advance Persistent Threats

b)

Denial of Service (DoS) Attacks

c)

Unpatched Software

d)

Weak Authentication

e)

Mobile Device Vulnerabilities

88.

attack is an attempt to make a computer system or network unavailable to its intended users

a)

Advance Persistent Threats

b)

Denial of Service (DoS) Attacks

c)

Unpatched Software

d)

Weak Authentication

e)

Mobile Device Vulnerabilities

89.

weaknesses in the design or implementation of mobile devices that can be exploited by attackers to gain unauthorized access to the device or its data.

a)

Advance Persistent Threats

b)

Denial of Service (DoS) Attacks

c)

Unpatched Software

d)

Weak Authentication

e)

Mobile Device Vulnerabilities

90.

a type of authentication that is easy for attackers to bypass. Weak authentication methods often rely on easily guessed passwords or other easily compromised factors, such as security questions

a)

Advance Persistent Threats

b)

Denial of Service (DoS) Attacks

c)

Unpatched Software

d)

Weak Authentication

e)

Mobile Device Vulnerabilities

91.

e that has not been updated with the latest security patches

a)

Advance Persistent Threats

b)

Denial of Service (DoS) Attacks

c)

Unpatched Software

d)

Weak Authentication

e)

Mobile Device Vulnerabilities

92.

are weaknesses in the design or implementation of IoT devices that can be exploited by attackers to gain unauthorized access to the device or its data

a)

Advance Persistent Threats

b)

Denial of Service (DoS) Attacks

c)

IoT Vulnerabilities

d)

Supply Chain Risks

e)

Mobile Device Vulnerabilities

93.

risks are the potential for disruptions in the flow of goods and services from suppliers to manufacturers to distributors to consumers. Vulnerabilities in third-party software, hardware, or services can affect an organization's security posture.

a)

Advance Persistent Threats

b)

Denial of Service (DoS) Attacks

c)

IoT Vulnerabilities

d)

Supply Chain Risks

e)

Mobile Device Vulnerabilities

94.

are the potential for harm that can come from using social media platforms.

a)

Advance Persistent Threats

b)

Social Media Risks

c)

IoT Vulnerabilities

d)

Supply Chain Risks

e)

Mobile Device Vulnerabilities

95.

is the absence of or inadequate training given to employees to perform their job duties effectively

a)

Lack of Employee Training

b)

Rogue Software

c)

Data Loss

d)

Legal and Regulatory NonCompliance

96.

type of malware that misleads users into believing that their computer is infected with a virus or other security threat

a)

Lack of Employee Training

b)

Rogue Software

c)

Data Loss

d)

Legal and Regulatory NonCompliance

97.

is when data is deleted, corrupted, or otherwise rendered inaccessible. Accidental or intentional deletion of data, hardware failures, or inadequate backup practices can result in data loss

a)

Lack of Employee Training

b)

Rogue Software

c)

Data Loss

d)

Legal and Regulatory NonCompliance

98.

evolving threats, such as zero-day vulnerabilities, require continuous monitoring and adaptation of security measures.

a)

Lack of Employee Training

b)

Rogue Software

c)

Emerging Threats

d)

Legal and Regulatory NonCompliance

99.

occurs when an organization fails to comply with the laws and regulations that govern its activities.

a)

Lack of Employee Training

b)

Rogue Software

c)

Emerging Threats

d)

Legal and Regulatory NonCompliance

100.

the state of being free from danger or threat

a)

SECURITY

b)

ASURANCE

c)

INFORMATION ASSURANCE

101.

a positive declaration intended to give confidence; a promise

a)

SECURITY

b)

ASSURANCE

c)

INFORMATION ASSURANCE

102.

refers to the systematic and comprehensive approach to safeguarding sensitive and critical information from unauthorized access, alteration, disruption, or destruction.

a)

SECURITY

b)

ASSURANCE

c)

INFORMATION ASSURANCE

103.

This law regulates the processing of personal data by private and public entities. It requires organizations to obtain consent from individuals before collecting, using, or disclosing their personal data. It also imposes security measures to protect personal data from unauthorized access, use, or disclosure.

a)

Data Privacy Act of 2012 (DPA)

b)

Bank Secrecy Act of 1975

c)

3. Electronic Commerce Act of 2000

d)

Cybercrime Prevention Act of 2012

e)

Civil Code of the Philippines

104.

This law prohibits banks and other financial institutions from disclosing information about their customers' accounts, except in certain circumstances, such as when required by law or when there is a legitimate business reason to do so.

a)

Data Privacy Act of 2012 (DPA)

b)

Bank Secrecy Act of 1975

c)

3. Electronic Commerce Act of 2000

d)

Cybercrime Prevention Act of 2012

e)

Civil Code of the Philippines

105.

This law regulates electronic transactions, including the use of electronic signatures and the storage of electronic data. It requires organizations to take reasonable security measures to protect electronic data from unauthorized access, use, or disclosure.

a)

Data Privacy Act of 2012 (DPA)

b)

Bank Secrecy Act of 1975

c)

Electronic Commerce Act of 2000

d)

Cybercrime Prevention Act of 2012

e)

Civil Code of the Philippines

106.

law prohibits a number of cybercrimes, including unauthorized access to a computer system, data theft, and cyberstalking. It also imposes penalties for the breach of confidentiality of personal data.

a)

Data Privacy Act of 2012 (DPA)

b)

Bank Secrecy Act of 1975

c)

Electronic Commerce Act of 2000

d)

Cybercrime Prevention Act of 2012

e)

Civil Code of the Philippines

107.

This law provides for the protection of privacy and confidentiality. It states that "every person shall respect the dignity, personality, privacy and peace of mind of his neighbors and other persons." It also prohibits the disclosure of confidential information obtained by a person in the course of his or her employment or profession.

a)

Data Privacy Act of 2012 (DPA)

b)

Bank Secrecy Act of 1975

c)

Electronic Commerce Act of 2000

d)

Cybercrime Prevention Act of 2012

e)

Civil Code of the Philippines

108.

Philippine Medical Association states that "physicians shall respect the confidentiality of all information obtained in the course of their professional practice."

a)

Data Privacy Act of 2012 (DPA)

b)

Bank Secrecy Act of 1975

c)

Electronic Commerce Act of 2000

d)

Cybercrime Prevention Act of 2012

e)

Other Professional Code of ETHICS

109.

means being whole and with no incomplete parts. The information must be accurate and complete

a)

INTEGRITY

b)

DATA INFORMATION INTEGRITY

c)

AVAILABILITY

d)

CONFIDENTIALITY

110.

Verifying the identity of users, devices, or systems to prevent unauthorized access. Authentication mechanisms include passwords, usernames, CAPTCHA, certificates, badges, biometrics, and multi-factor authentication

a)

AUTHENTICATION

b)

AUTHORIZATION

c)

AVAILABILITY

d)

CONFIDENTIALITY

111.

Granting appropriate permissions and privileges to authorized users, limiting their access to only the data and resources they need. Authorization may come in several forms like in permissions, privileges, roles, responsibilities, access control/revocation, audit and accountability

a)

AUTHENTICATION

b)

AUTHORIZATION

c)

AVAILABILITY

d)

CONFIDENTIALITY

112.

Ensuring that data and systems are accessible and usable when needed. And inversely, same data set must be kept inaccessible when not needed. This involves practices like redundancy checks, disaster recovery planning, and network resilience

a)

INTEGRITY

b)

DATA INFORMATION INTEGRITY

c)

AVAILABILITY

d)

CONFIDENTIALITY

113.

refers to the wholeness of data as when it was generated. Preventing unauthorized modifications or alterations of data. Data integrity measures include checksums, digital signatures, and version controls.

a)

INTEGRITY

b)

DATA INFORMATION INTEGRITY

c)

AVAILABILITY

d)

CONFIDENTIALITY

114.

Ensuring that data and/or information is only accessible to authorized, verified, identified or properly-certified individuals or entities. This involves measures such as access controls, encryption, and data classification.

a)

INTEGRITY

b)

DATA INFORMATION INTEGRITY

c)

AVAILABILITY

d)

CONFIDENTIALITY

115.

refer to the accuracy, reliability, and consistency of data over its entire lifecycle.

a)

INTEGRITY

b)

DATA INFORMATION INTEGRITY

c)

AVAILABILITY

d)

CONFIDENTIALITY

116.

The information must be accessible to authorized individuals or entities when needed. And inversely, data must be not available when not needed or when users access data in unauthorized manners.

a)

INTEGRITY

b)

DATA INFORMATION INTEGRITY

c)

AVAILABILITY

d)

CONFIDENTIALITY

117.

The originator or sender of the information cannot deny having sent it. Systems must have in them some built-in mechanisms to ensure that data interchanges and their corresponding metadata are recorded and are quite accessible to both sender and receiver

a)

INTEGRITY

b)

DATA INFORMATION INTEGRITY

c)

NON-REPUDIATION

d)

DYNAMISM

118.

refers to the constantly evolving and changing nature of information security threats and the need for security measures to adapt and respond in real-time to these evolving threats, requiring a flexible and proactive approach to protect information systems effectively.

a)

INTEGRITY

b)

DATA INFORMATION INTEGRITY

c)

NON-REPUDIATION

d)

DYNAMISM

119.

The information must be kept secret from unauthorized individuals or entities

a)

INTEGRITY

b)

DATA INFORMATION INTEGRITY

c)

AVAILABILITY

d)

CONFIDENTIALITY

120.

IA approaches are not always easy to achieve. There is always a trade-off between security and usability. For example, making information more secure may make it more difficult to access. The inverse is also corollary: easier access means greater security risks

a)

MUTUAL INCLUSIVITY

b)

COMPLEXITY AND FEASIBILITY

c)

AVAILABILITY

d)

CONFIDENTIALITY

121.

IA principles are not always mutually exclusive. For example, it is possible to have both confidentiality and availability of information. And it is usually a requirement among information systems to be available at a highly secured manner.

a)

MUTUAL INCLUSIVITY

b)

COMPLEXITY AND FEASIBILITY

c)

AVAILABILITY

d)

CONFIDENTIALITY

122.

Ways to determine _________________:

❑ Verification of Source

❑ Requiring digital signature

❑ Timestamps

❑ Utilizing Authentication Protocols

❑ Public Key Infrastructures

a)

INTEGRITY

b)

AUTHENTICITY

c)

AVAILABILITY

d)

CONFIDENTIALITY

123.

Ways to determine _______:

❑ Watermarking and Seals

❑ Declaration of Chain of Custody

❑ Having Secure Data Transmission

❑ Provision of Audit Trails

a)

INTEGRITY

b)

AUTHENTICITY

c)

AVAILABILITY

d)

CONFIDENTIALITY

124.

Protecting networks from unauthorized access, cyberattacks, and malicious activities using firewalls, intrusion detection systems, and intrusion prevention systems.

a)

NETWORK SECURITY

b)

ENDPOINT SECURITY

c)

SECURITY AWARENESS TRAINING

d)

INCIDENT RESPONSE

125.

Securing individual devices like computers, smartphones, and IoT devices to prevent malware infections, data breaches, and unauthorized access. It also involves other measures such as blacklisting/whitelisting, security updates, device controls, etc.

a)

NETWORK SECURITY

b)

ENDPOINT SECURITY

c)

SECURITY AWARENESS TRAINING

d)

INCIDENT RESPONSE

126.

Educating employees and users about security best practices, phishing awareness, and the importance of data protection.

a)

NETWORK SECURITY

b)

ENDPOINT SECURITY

c)

SECURITY AWARENESS TRAINING

d)

INCIDENT RESPONSE

127.

When something untoward happens in the information systems, admins should already have in place certain ways to respond to or deal with them. Since information systems are subject to attacks, it should no longer be a surprise for admins when such incidents occur.

a)

NETWORK SECURITY

b)

ENDPOINT SECURITY

c)

SECURITY AWARENESS TRAINING

d)

INCIDENT RESPONSE

128.

Identifying and patching vulnerabilities in software and systems to prevent exploitation by malicious actors. Penetration testing (pen test) is the most common means of identifying and dealing with vulnerabilities

a)

SECURITY POLICIES AND COMPLIANCE

b)

VULNERABILITY MANAGEMENT

c)

THREAT DETECTION AND PREVENTION

d)

SECURITY AUDITS AND ASSESSMENT

129.

Establishing standards, and guidelines , security policies to ensure that security measures align with industry regulations and best practices. Procedures are put in place to guide admins, staff, technicians and users as to the proper utilization of the systems

a)

SECURITY POLICIES AND COMPLIANCE

b)

VULNERABILITY MANAGEMENT

c)

THREAT DETECTION AND PREVENTION

d)

SECURITY AUDITS AND ASSESSMENT

130.

Using tools like intrusion detection systems, antivirus software, and behavior analytics to identify and prevent security threats.

a)

SECURITY POLICIES AND COMPLIANCE

b)

VULNERABILITY MANAGEMENT

c)

THREAT DETECTION AND PREVENTION

d)

SECURITY AUDITS AND ASSESSMENT

131.

Using tools like intrusion detection systems, antivirus software, and behavior analytics to identify and prevent security threats.

a)

SECURITY POLICIES AND COMPLIANCE

b)

VULNERABILITY MANAGEMENT

c)

THREAT DETECTION AND PREVENTION

d)

SECURITY AUDITS AND ASSESSMENT

132.
a)

SCOPE AND PURPOSE

b)

APPROACHES

c)

GOALS

d)

RISK MANAGEMENT

e)

COMPLIANCE AND GOVERNANCE

133.
a)

SCOPE AND PURPOSE

b)

APPROACHES

c)

GOALS

d)

RISK MANAGEMENT

e)

COMPLIANCE AND GOVERNANCE

134.
a)

SCOPE AND PURPOSE

b)

APPROACHES

c)

GOALS

d)

RISK MANAGEMENT

e)

COMPLIANCE AND GOVERNANCE

135.
a)

SCOPE AND PURPOSE

b)

APPROACHES

c)

GOALS

d)

RISK MANAGEMENT

e)

COMPLIANCE AND GOVERNANCE

136.
a)

SCOPE AND PURPOSE

b)

APPROACHES

c)

GOALS

d)

RISK MANAGEMENT

e)

COMPLIANCE AND GOVERNANCE

Similar Resources on Wayground