NEW
Font size
WorksheetsInformation Assurance and Security Exam FINALS
Total questions: 47
Worksheet time: 24mins
What does a firewall primarily do?
Encrypt data
Monitor network traffic
Filter incoming and outgoing traffic
Store passwords
Which of the following is an example of an Intrusion Detection System (IDS)?
Antivirus software
Network traffic monitor
Firewall
Backup system
What is the purpose of a Virtual Private Network (VPN)?
Enhance internet speed
Secure data transmission over a public network
Reduce software installation time
Store data on remote servers
Which protocol is typically used to secure communications in VPNs?
HTTP
FTP
IPsec
SMTP
What does the term "network segmentation" refer to?
Dividing networks into different geographical areas
Restricting network access to administrators only
Splitting a network into smaller, isolated segments
Increasing bandwidth for a specific application
WPA2 utilizes which type of encryption?
DES
RSA
AES
Blowfish
In which situation is an Intrusion Prevention System (IPS) most effective?
When analyzing user behavior
When blocking malicious traffic in real-time
When recording network logs
When performing backups
What type of attack is a Denial of Service (DoS)?
Credential theft
Data interception
Service disruption
Database injection
What is the primary purpose of Multi-Factor Authentication (MFA)?
Simplify user login
Increase password complexity
Enhance overall security by requiring multiple verification methods
Encrypt user data
What does the Principle of Least Privilege state?
Users should have access to all system resources
Users only need access to resources necessary for their roles
All data should be encrypted at rest
Access should be denied for all non-employees
Which of the following is NOT a form of biometrics?
Fingerprint recognition
Voice recognition
Passwords
Facial recognition
What does a Role-Based Access Control (RBAC) model do?
Grants access based on user identity
Provides universal access to all data
Assigns access rights based on user roles
Limits access to IT staff only
Single Sign-On (SSO) allows users to:
Only log into one application
Authenticate once to access multiple applications
Change passwords easily
Avoid all authentication methods
What is the first step in a typical risk assessment process?
Analyze risks
Identify risks
Evaluate risk appetite
Implement controls
Which of the following is a risk mitigation strategy?
Avoidance
Acceptance
Transfer
All of the above
What is the main goal of a security policy?
To provide legal protections
To outline how to manage and protect organizational assets
To restrict employee access
To monitor employee productivity
Which regulation focuses on data protection in the European Union?
HIPAA
PCI-DSS
GDPR
SOX
What method can be employed to quantify the potential impact of risks?
Qualitative assessment
Quantitative assessment
Subjective judgment
Intuitive analysis
What is the purpose of an incident response plan?
To document security events
To define how to respond to and recover from security incidents
To train employees
To increase network bandwidth
The NIST Cybersecurity Framework provides guidelines for:
Managing physical security
Managing and reducing cybersecurity risk
Employee training programs
Network performance optimization
Which of the following is a component of the COBIT framework?
Risk Management
Incident Response
Performance Monitoring
All of the above
The Bell-LaPadula Model primarily focuses on:
Data integrity
Data confidentiality
Authentication protocols
User experience
What does Defense-in-Depth refer to?
Multiple layers of security controls
Physical security in data centers
Encryption of data
Single access point for security management
What is a primary purpose of physical security controls?
To prevent data breaches
To limit network access
To protect physical assets from theft and damage
To improve system performance
Which of the following is NOT a physical security measure?
Biometric scanners
Firewall configurations
Video surveillance
Security personnel
What environmental threat requires fire detection and suppression systems?
Flood
Cyber attack
Fire
Electrical outages
Uninterruptible Power Supplies (UPS) are used to:
Beautify data centers
Create backups for data
Provide temporary power during outages
Facilitate remote access
Which policy would be most relevant for an organization's physical security?
Acceptable Use Policy
Data Retention Policy
Physical Security Policy
Change Management Policy
Which of the following is an advantage of using a VPN?
Faster internet speeds
Ability to bypass geographic restrictions
Decreased data security
None of the above
What is the confidentiality principle of the CIA triad?
Ensuring data is accessible
Ensuring data is accurate
Ensuring data is only accessible to authorized users
None of the above
What does the term "social engineering" refer to?
A method to manipulate users into disclosing confidential information
An approach to using social networks for marketing
Networking techniques to improve connection speeds
None of the above
Which type of control is a biometric authentication system?
Administrative control
Physical control
Technical control
Procedural control
In risk management, what is the role of regular audits?
To enhance user experiences
To evaluate adherence to policies and identify vulnerabilities
To maintain hardware
To increase revenue
Which of the following is an example of environmental security?
Installing antivirus software
Backup power generators
Creating strong passwords
Firewall configurations
What is the main risk of using shared passwords across multiple systems?
Increased flexibility
Enhanced security
Potential for widespread compromise if one system is breached
Easier employee access
Which best practices help to ensure strong password security?
Use of simple and easy-to-remember passwords
Using unique passwords for every account
Sharing passwords with colleagues
Avoiding multi-factor authentication
What does an organization's risk appetite refer to?
The ideal number of risks
Willingness to accept risk in pursuit of objectives
Maximum financial loss acceptable
All types of risks accepted
What is the function of data encryption?
Minimize storage requirements
Protect data confidentiality by converting it into a coded format
Enhance data access speed
Create backups of data
What is a significant benefit of having an incident response team?
To avoid the economic costs of incidents
To ensure all employees have extracted data
To minimize response time and manage incidents effectively
To delegate responsibilities for monitoring systems
Which model emphasizes data integrity?
Bell-LaPadula
Biba
Clark-Wilson
DFD (Data Flow Diagram)
In the context of business operations, which term describes an unanticipated event that negatively affects the organization?
Opportunity
Risk
Threat
Vulnerability
Which of the following can serve as a physical security barrier?
Software firewalls
Locks and access control systems
Encryption keys
Network protocols
What is the role of patches in security?
Increase software complexity
Fix bugs and vulnerabilities in software
Limit user accessibility
None of the above
Who is responsible for managing access controls in a network?
Users only
IT administrators and security teams
Network hardware
All employees
What makes a security framework effective?
Clarity of policies and procedures
Flexibility to adapt to changes
Alignment with organizational goals
All of the above
What does the physical security concept of "layered security" involve?
Protecting data only through encryption
Using multiple physical controls to enhance security
Relying solely on surveillance cameras
None of the above
Which kind of risk assessment technique uses subjective judgments based on estimates?
Quantitative assessment
Qualitative assessment
Technical assessment
Risk analysis
