wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

InfoSec Quiz 1

Total questions: 15

Worksheet time: 8mins

Name
Class
Date
1.

A software company wants to adopt a security framework that ensures compliance with industry regulations and improves its overall security posture.

Which of the following frameworks should they consider?

a)

NIST Cybersecurity Framework

b)

COBIT

c)

ISO/IEC 27001

d)

All of the above

2.

A user reports that their files have become inaccessible and are displaying a message demanding payment for decryption.
What type of malware is involved?

a)

Spyware

b)

Trojan horse

c)

Ransomware

d)

Adware

3.

A company's IT team discovers an attacker has gained unauthorized access to their internal systems through a vulnerability that had a patch released three months ago but was never applied.

What could have prevented this security breach?

a)

Regular software updates and patch management

b)

Disabling all network connections

c)

Encrypting all incoming emails

d)

Blocking all remote access

4.

An attacker bombards a company's web server with a massive amount of fake traffic, causing it to crash.

Which type of attack is taking place?

a)

SQL Injection

b)

Denial-of-service (DoS)

c)

Insider threat

d)

Phishing

5.

A company wants to ensure its data remains available to employees even in the event of a cyberattack.
Which security principle does this align with?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Redundancy

6.

An employee working remotely logs into a company system using only a simple password. Later, unauthorized access is detected from an unknown device.
What security measure could have prevented this incident?

a)

Multi-factor authentication (MFA)

b)

Disabling employee remote access

c)

Allowing password reuse

d)

Using a default VPN

7.

A company's database containing customer information was accessed by an unauthorized individual. The company discovered that a weak default password was still being used for administrative access.
Which security vulnerability contributed to this breach?

a)

Social engineering

b)

Outdated antivirus software

c)

Use of default credentials

d)

Secure encryption protocols

8.

A company employee receives an email warning that their account will be locked unless they click a link to verify their credentials. The email appears to be from the IT department but contains spelling errors and an unusual sender address.
What type of attack is this?

a)

Ransomware

b)

Phishing

c)

Denial-of-service

d)

Malware

9.

What is the primary purpose of Information Security?

a)

To protect physical company assets

b)

To ensure data confidentiality, integrity, and availability

c)

To improve network speed

d)

To enhance user experience

10.

Which of the following best describes the concept of Information Security?

a)

The protection of physical assets from theft

b)

The protection of information from unauthorized access, use, disclosure, alteration, or destruction

c)

The development of new software programs for businesses

d)

The process of encrypting all online content for user privacy

11.

Which of the following is NOT a core principle of the CIA Triad?

a)

Confidentiality

b)

Integrity

c)

Authentication

d)

Availability

12.

Which security framework is known for its five core functions: Identify, Protect, Detect, Respond, and Recover?

a)

ISO/IEC 27001

b)

COBIT

c)

NIST Cybersecurity Framework

d)

ITIL

13.

Which of these is an example of a social engineering attack?

a)

A hacker breaking into a system using brute force attacks

b)

An attacker tricking employees into providing sensitive information via email

c)

A ransomware attack encrypting a company's files

d)

A denial-of-service attack overwhelming a company's server

14.

Which of the following is NOT considered an information security vulnerability?

a)

Weak passwords

b)

Outdated software

c)

Using multi-factor authentication

d)

Employees unaware of phishing threats

15.

Which of these is a key benefit of implementing the ISO/IEC 27001 framework?

a)

Reducing software development costs

b)

Improving physical security in buildings

c)

Establishing a structured approach to managing information security risks

d)

Increasing the speed of network connections