wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Information Assurance and Security Exam FINALS

Total questions: 47

Worksheet time: 24mins

Name
Class
Date
1.

What does a firewall primarily do?

a)

Encrypt data

b)

Monitor network traffic

c)

Filter incoming and outgoing traffic

d)

Store passwords

2.

Which of the following is an example of an Intrusion Detection System (IDS)?

a)

Antivirus software

b)

Network traffic monitor

c)

Firewall

d)

Backup system

3.

What is the purpose of a Virtual Private Network (VPN)?

a)

Enhance internet speed

b)

Secure data transmission over a public network

c)

Reduce software installation time

d)

Store data on remote servers

4.

Which protocol is typically used to secure communications in VPNs?

a)

HTTP

b)

FTP

c)

IPsec

d)

SMTP

5.

What does the term "network segmentation" refer to?

a)

Dividing networks into different geographical areas

b)

Restricting network access to administrators only

c)

Splitting a network into smaller, isolated segments

d)

Increasing bandwidth for a specific application

6.

WPA2 utilizes which type of encryption?

a)

DES

b)

RSA

c)

AES

d)

Blowfish

7.

In which situation is an Intrusion Prevention System (IPS) most effective?

a)

When analyzing user behavior

b)

When blocking malicious traffic in real-time

c)

When recording network logs

d)

When performing backups

8.

What type of attack is a Denial of Service (DoS)?

a)

Credential theft

b)

Data interception

c)

Service disruption

d)

Database injection

9.

What is the primary purpose of Multi-Factor Authentication (MFA)?

a)

Simplify user login

b)

Increase password complexity

c)

Enhance overall security by requiring multiple verification methods

d)

Encrypt user data

10.

What does the Principle of Least Privilege state?

a)

Users should have access to all system resources

b)

Users only need access to resources necessary for their roles

c)

All data should be encrypted at rest

d)

Access should be denied for all non-employees

11.

Which of the following is NOT a form of biometrics?

a)

Fingerprint recognition

b)

Voice recognition

c)

Passwords

d)

Facial recognition

12.

What does a Role-Based Access Control (RBAC) model do?

a)

Grants access based on user identity

b)

Provides universal access to all data

c)

Assigns access rights based on user roles

d)

Limits access to IT staff only

13.

Single Sign-On (SSO) allows users to:

a)

Only log into one application

b)

Authenticate once to access multiple applications

c)

Change passwords easily

d)

Avoid all authentication methods

14.

What is the first step in a typical risk assessment process?

a)

Analyze risks

b)

Identify risks

c)

Evaluate risk appetite

d)

Implement controls

15.

Which of the following is a risk mitigation strategy?

a)

Avoidance

b)

Acceptance

c)

Transfer

d)

All of the above

16.

What is the main goal of a security policy?

a)

To provide legal protections

b)

To outline how to manage and protect organizational assets

c)

To restrict employee access

d)

To monitor employee productivity

17.

Which regulation focuses on data protection in the European Union?

a)

HIPAA

b)

PCI-DSS

c)

GDPR

d)

SOX

18.

What method can be employed to quantify the potential impact of risks?

a)

Qualitative assessment

b)

Quantitative assessment

c)

Subjective judgment

d)

Intuitive analysis

19.

What is the purpose of an incident response plan?

a)

To document security events

b)

To define how to respond to and recover from security incidents

c)

To train employees

d)

To increase network bandwidth

20.

The NIST Cybersecurity Framework provides guidelines for:

a)

Managing physical security

b)

Managing and reducing cybersecurity risk

c)

Employee training programs

d)

Network performance optimization

21.

Which of the following is a component of the COBIT framework?

a)

Risk Management

b)

Incident Response

c)

Performance Monitoring

d)

All of the above

22.

The Bell-LaPadula Model primarily focuses on:

a)

Data integrity

b)

Data confidentiality

c)

Authentication protocols

d)

User experience

23.

What does Defense-in-Depth refer to?

a)

Multiple layers of security controls

b)

Physical security in data centers

c)

Encryption of data

d)

Single access point for security management

24.

What is a primary purpose of physical security controls?

a)

To prevent data breaches

b)

To limit network access

c)

To protect physical assets from theft and damage

d)

To improve system performance

25.

Which of the following is NOT a physical security measure?

a)

Biometric scanners

b)

Firewall configurations

c)

Video surveillance

d)

Security personnel

26.

What environmental threat requires fire detection and suppression systems?

a)

Flood

b)

Cyber attack

c)

Fire

d)

Electrical outages

27.

Uninterruptible Power Supplies (UPS) are used to:

a)

Beautify data centers

b)

Create backups for data

c)

Provide temporary power during outages

d)

Facilitate remote access

28.

Which policy would be most relevant for an organization's physical security?

a)

Acceptable Use Policy

b)

Data Retention Policy

c)

Physical Security Policy

d)

Change Management Policy

29.

Which of the following is an advantage of using a VPN?

a)

Faster internet speeds

b)

Ability to bypass geographic restrictions

c)

Decreased data security

d)

None of the above

30.

What is the confidentiality principle of the CIA triad?

a)

Ensuring data is accessible

b)

Ensuring data is accurate

c)

Ensuring data is only accessible to authorized users

d)

None of the above

31.

What does the term "social engineering" refer to?

a)

A method to manipulate users into disclosing confidential information

b)

An approach to using social networks for marketing

c)

Networking techniques to improve connection speeds

d)

None of the above

32.

Which type of control is a biometric authentication system?

a)

Administrative control

b)

Physical control

c)

Technical control

d)

Procedural control

33.

In risk management, what is the role of regular audits?

a)

To enhance user experiences

b)

To evaluate adherence to policies and identify vulnerabilities

c)

To maintain hardware

d)

To increase revenue

34.

Which of the following is an example of environmental security?

a)

Installing antivirus software

b)

Backup power generators

c)

Creating strong passwords

d)

Firewall configurations

35.

What is the main risk of using shared passwords across multiple systems?

a)

Increased flexibility

b)

Enhanced security

c)

Potential for widespread compromise if one system is breached

d)

Easier employee access

36.

Which best practices help to ensure strong password security?

a)

Use of simple and easy-to-remember passwords

b)

Using unique passwords for every account

c)

Sharing passwords with colleagues

d)

Avoiding multi-factor authentication

37.

What does an organization's risk appetite refer to?

a)

The ideal number of risks

b)

Willingness to accept risk in pursuit of objectives

c)

Maximum financial loss acceptable

d)

All types of risks accepted

38.

What is the function of data encryption?

a)

Minimize storage requirements

b)

Protect data confidentiality by converting it into a coded format

c)

Enhance data access speed

d)

Create backups of data

39.

What is a significant benefit of having an incident response team?

a)

To avoid the economic costs of incidents

b)

To ensure all employees have extracted data

c)

To minimize response time and manage incidents effectively

d)

To delegate responsibilities for monitoring systems

40.

Which model emphasizes data integrity?

a)

Bell-LaPadula

b)

Biba

c)

Clark-Wilson

d)

DFD (Data Flow Diagram)

41.

In the context of business operations, which term describes an unanticipated event that negatively affects the organization?

a)

Opportunity

b)

Risk

c)

Threat

d)

Vulnerability

42.

Which of the following can serve as a physical security barrier?

a)

Software firewalls

b)

Locks and access control systems

c)

Encryption keys

d)

Network protocols

43.

What is the role of patches in security?

a)

Increase software complexity

b)

Fix bugs and vulnerabilities in software

c)

Limit user accessibility

d)

None of the above

44.

Who is responsible for managing access controls in a network?

a)

Users only

b)

IT administrators and security teams

c)

Network hardware

d)

All employees

45.

What makes a security framework effective?

a)

Clarity of policies and procedures

b)

Flexibility to adapt to changes

c)

Alignment with organizational goals

d)

All of the above

46.

What does the physical security concept of "layered security" involve?

a)

Protecting data only through encryption

b)

Using multiple physical controls to enhance security

c)

Relying solely on surveillance cameras

d)

None of the above

47.

Which kind of risk assessment technique uses subjective judgments based on estimates?

a)

Quantitative assessment

b)

Qualitative assessment

c)

Technical assessment

d)

Risk analysis