WorksheetsInfoSec Quiz 1
Total questions: 15
Worksheet time: 8mins
A software company wants to adopt a security framework that ensures compliance with industry regulations and improves its overall security posture.
Which of the following frameworks should they consider?
NIST Cybersecurity Framework
COBIT
ISO/IEC 27001
All of the above
A user reports that their files have become inaccessible and are displaying a message demanding payment for decryption.
What type of malware is involved?
Spyware
Trojan horse
Ransomware
Adware
A company's IT team discovers an attacker has gained unauthorized access to their internal systems through a vulnerability that had a patch released three months ago but was never applied.
What could have prevented this security breach?
Regular software updates and patch management
Disabling all network connections
Encrypting all incoming emails
Blocking all remote access
An attacker bombards a company's web server with a massive amount of fake traffic, causing it to crash.
Which type of attack is taking place?
SQL Injection
Denial-of-service (DoS)
Insider threat
Phishing
A company wants to ensure its data remains available to employees even in the event of a cyberattack.
Which security principle does this align with?
Confidentiality
Integrity
Availability
Redundancy
An employee working remotely logs into a company system using only a simple password. Later, unauthorized access is detected from an unknown device.
What security measure could have prevented this incident?
Multi-factor authentication (MFA)
Disabling employee remote access
Allowing password reuse
Using a default VPN
A company's database containing customer information was accessed by an unauthorized individual. The company discovered that a weak default password was still being used for administrative access.
Which security vulnerability contributed to this breach?
Social engineering
Outdated antivirus software
Use of default credentials
Secure encryption protocols
A company employee receives an email warning that their account will be locked unless they click a link to verify their credentials. The email appears to be from the IT department but contains spelling errors and an unusual sender address.
What type of attack is this?
Ransomware
Phishing
Denial-of-service
Malware
What is the primary purpose of Information Security?
To protect physical company assets
To ensure data confidentiality, integrity, and availability
To improve network speed
To enhance user experience
Which of the following best describes the concept of Information Security?
The protection of physical assets from theft
The protection of information from unauthorized access, use, disclosure, alteration, or destruction
The development of new software programs for businesses
The process of encrypting all online content for user privacy
Which of the following is NOT a core principle of the CIA Triad?
Confidentiality
Integrity
Authentication
Availability
Which security framework is known for its five core functions: Identify, Protect, Detect, Respond, and Recover?
ISO/IEC 27001
COBIT
NIST Cybersecurity Framework
ITIL
Which of these is an example of a social engineering attack?
A hacker breaking into a system using brute force attacks
An attacker tricking employees into providing sensitive information via email
A ransomware attack encrypting a company's files
A denial-of-service attack overwhelming a company's server
Which of the following is NOT considered an information security vulnerability?
Weak passwords
Outdated software
Using multi-factor authentication
Employees unaware of phishing threats
Which of these is a key benefit of implementing the ISO/IEC 27001 framework?
Reducing software development costs
Improving physical security in buildings
Establishing a structured approach to managing information security risks
Increasing the speed of network connections
