WorksheetsBTEC DIT LAC Policy
Total questions: 57
Worksheet time: 29mins
What is one of the main reasons companies assign specific roles to IT staff or management?
To increase company profits
To ensure accountability and awareness
To reduce the number of employees
To improve customer satisfaction
Which of the following is an aspect of assigned responsibilities in a company?
Deciding company profits
Who is responsible for what
Setting employee salaries
Choosing office locations
Why is it important for staff to be aware of their responsibilities?
To increase their workload
To ensure they know the actions they need to take
To allow them to work independently
To reduce the need for management
Who is typically responsible for implementing cybersecurity policies in an organization?
Marketing staff
IT staff
Human resources
Sales team
What should staff do if they have a concern over a possible issue with a policy?
Ignore it
Contact a defined person responsible
Discuss it with a colleague
Wait for a meeting
Why is it important for staff to be aware of security policies and procedures?
To increase sales
To ensure policies are secure
To improve customer service
To reduce workload
What is the purpose of defining security parameters in cybersecurity policies?
To enhance the overall security of a system
To increase the speed of the internet
To reduce the cost of software
To improve the design of hardware
Which of the following is NOT mentioned as a security parameter in the document?
Password policy
Acceptable software policy
Network speed policy
Device hardening parameters
What is the purpose of a password policy?
To define rules for setting and protecting passwords
To create complex passwords for users
To store passwords securely
To share passwords among employees
Which of the following is NOT considered in a password policy?
The don’ts of password creation
The dos of password creation
Protection of passwords
Sharing passwords with others
What is a key characteristic of a good password according to the password policy?
It should be guessable.
It should contain personal information.
It should be at least 8 characters long.
It should be the same for multiple systems.
Which of the following is NOT recommended when creating a password?
Using common words.
Using a mix of upper-case and lower-case letters.
Including numbers and special characters.
Making it at least 8 characters long.
How should passwords be stored according to the password policy?
Written down somewhere.
In a secure database.
Shared with friends.
On a sticky note.
What should you do if a password is generated automatically?
Share it with others.
Write it down.
Change it immediately.
Use it for multiple accounts.
What is the purpose of an acceptable software policy?
To allow unrestricted software installation
To control and restrict software installation
To promote downloading unauthorized material
To ensure all employees have admin rights
How can IT staff enforce the acceptable software policy?
By giving all employees admin rights
By configuring an employee’s access rights to block installation
By allowing all software downloads
By removing all software from the system
What might happen to employees who breach the acceptable software policy?
They receive a bonus
They are given more access rights
They may face a warning, suspension, or restriction
They are promoted
What must employees do to install new software according to the Acceptable Software Policy?
Install it themselves without permission.
Request the software from IT staff.
Download it from the internet.
Use any available software.
What is a potential downside of the Acceptable Software Policy?
It increases productivity.
It allows immediate software installation.
It can take several months, harming productivity.
It reduces the need for IT staff.
What is the primary purpose of an acceptable use policy in a company?
To define what a user can and cannot do on a company’s IT systems.
To allow employees to play video games during work hours.
To encourage employees to use personal email during company time.
To eliminate all IT systems in the company.
Why is it important to have an acceptable use policy?
To keep company IT systems safe from threats.
To allow unrestricted access to all websites.
To ensure employees can use personal devices at work.
To promote the use of social media during work hours.
What does an acceptable use policy typically include?
A series of dos and don’ts for employees.
Instructions to ignore company IT systems.
Guidelines to increase personal email usage.
Steps to remove all security measures.
Which of the following actions is prohibited according to the Acceptable Use Policy?
Creating or transmitting offensive images
Sharing your own creative work
Accessing public websites
Using your own password
What is not allowed regarding other users' data according to the Acceptable Use Policy?
Sharing it with permission
Corrupting or destroying it
Backing it up
Viewing it with consent
According to the Acceptable Use Policy, what should you avoid doing with another person's files?
Backing them up
Examining or changing them
Organizing them
Sharing them with permission
What is a violation of privacy according to the Acceptable Use Policy?
Viewing public profiles
Violating the privacy of other users
Sending a friend request
Commenting on a public post
What is the purpose of device hardening?
To enhance the device's physical appearance
To improve the device's processing speed
To protect a system's data from harm
To increase the device's storage capacity
What do cybersecurity policies define in relation to device hardening?
The device's color and design
Device hardening parameters and technologies
The device's battery life
The device's brand and model
What is the benefit of implementing and enforcing device hardening?
It makes the device more user-friendly
It protects systems from cybersecurity threats
It reduces the device's weight
It increases the device's market value
What time must virus definitions be updated on all IT systems?
9 p.m.
10 p.m.
11 p.m.
12 a.m.
Which ports must remain open on the firewall?
21, 80, 110
53, 443, 80
25, 110, 143
22, 8080, 3306
When must full backups of company data be performed?
Every Saturday at 1 a.m.
Every Sunday at 1 a.m.
Every Monday at 1 a.m.
Every Friday at 1 a.m.
At what time are incremental backups of changes made every day?
9 p.m.
10 p.m.
11 p.m.
12 a.m.
What is the primary purpose of a disaster recovery policy?
To ensure an organisation's readiness to respond to a disaster
To increase profits during a disaster
To prevent all types of disasters
To eliminate the need for cybersecurity
Which of the following is NOT mentioned as an incident that disaster recovery is effective against?
Data loss
Environmental threats
Hardware failure
Increased sales
What is one of the benefits of keeping a detailed, well-documented disaster recovery plan?
It guarantees no data will ever be lost
Business service can be resumed as soon as possible
It prevents all natural disasters
It eliminates the need for insurance
What is the purpose of defining the responsibility of different staff in a disaster recovery policy?
To ensure accountability and reduce confusion
To increase workload
To eliminate the need for training
To delay response time
What should staff do immediately in the event of a disaster according to the policy?
Report an incident to the incident response lead
Wait for further instructions
Ignore the incident
Contact the media
What does the backup policy define in a disaster recovery plan?
The type of data to be backed up, frequency, timing, and location
The cost of data recovery
The software used for data backup
The number of employees involved in the backup process
Why might weekly backups on Sunday evening be insufficient for some businesses?
Because they are too frequent
Because they are not frequent enough
Because they are too costly
Because they require too much storage space
What does the timeline for data recovery indicate in a disaster recovery policy?
The cost of recovery
The order and time it takes to recover each system
The software used for recovery
The number of employees needed for recovery
What is the purpose of a "hot site" in disaster recovery policies?
To provide a backup location for data storage
To instantly switch business operations after a disaster
To train employees on disaster recovery procedures
To store old hardware and software
What does a disaster recovery policy typically define regarding alternative provision?
The cost of new hardware
The location of additional hardware, software, and personnel
The timeline for disaster recovery
The number of employees needed for recovery
What is the first step a business should take after an attack?
Respond
Investigate
Manage
Recover
Why is it important for employees to be aware of actions to take after an attack?
To increase profits
To resume functionality and minimize damage
To hire more staff
To expand the business
Which of the following is NOT a step mentioned for actions after an attack?
Investigate
Respond
Expand
Analyse
What is the first step to take after an attack according to the document?
Investigate the attributes of the attack
Ignore the attack
Immediately inform the media
Shut down all systems
Why is it important to inform customers after a data breach?
To sell them new products
To require action from their end
To increase company profits
To avoid legal issues
What should be established to decide the level of response required after an attack?
The severity of the attack
The cost of the attack
The location of the attack
The number of attackers
Who should be informed about an attack besides customers?
Relevant stakeholders and authorities
Only the CEO
The general public
Competitors
What is the first step to take after an attack to prevent further damage?
Implement a disaster recovery policy
Isolate and contain the attack
Establish new plans for future attacks
Restore the most recent backup
Which of the following is an example of targeting the problem after an attack?
Restoring the most recent backup
Establishing new plans for future attacks
Using a firewall to block malicious traffic
Implementing a disaster recovery policy
What should be implemented to correct any damage caused by an incident?
Isolate and contain the attack
Use a firewall to block traffic
Implement the disaster recovery policy
Establish new plans for future attacks
What might be involved in recovering from an attack to prevent similar future incidents?
Isolating and containing the attack
Using a firewall to block traffic
Establishing new plans
Restoring the most recent backup
What is one of the first steps to take after an attack to help prevent future threats?
Work with employees to establish information about the attack.
Ignore the attack and continue as usual.
Immediately update all software without analysis.
Fire the employees involved.
Why is it important to analyze the attack after it occurs?
To assess what changes can be made.
To blame someone for the attack.
To delete all data related to the attack.
To ensure it never happened.
What should be updated as a result of analyzing an attack?
Policies and procedures.
Employee salaries.
Office furniture.
Company logo.
