Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

BTEC DIT LAC Policy

Total questions: 57

Worksheet time: 29mins

Name
Class
Date
1.

What is one of the main reasons companies assign specific roles to IT staff or management?

a)

To increase company profits

b)

To ensure accountability and awareness

c)

To reduce the number of employees

d)

To improve customer satisfaction

2.

Which of the following is an aspect of assigned responsibilities in a company?

a)

Deciding company profits

b)

Who is responsible for what

c)

Setting employee salaries

d)

Choosing office locations

3.

Why is it important for staff to be aware of their responsibilities?

a)

To increase their workload

b)

To ensure they know the actions they need to take

c)

To allow them to work independently

d)

To reduce the need for management

4.

Who is typically responsible for implementing cybersecurity policies in an organization?

a)

Marketing staff

b)

IT staff

c)

Human resources

d)

Sales team

5.

What should staff do if they have a concern over a possible issue with a policy?

a)

Ignore it

b)

Contact a defined person responsible

c)

Discuss it with a colleague

d)

Wait for a meeting

6.

Why is it important for staff to be aware of security policies and procedures?

a)

To increase sales

b)

To ensure policies are secure

c)

To improve customer service

d)

To reduce workload

7.

What is the purpose of defining security parameters in cybersecurity policies?

a)

To enhance the overall security of a system

b)

To increase the speed of the internet

c)

To reduce the cost of software

d)

To improve the design of hardware

8.

Which of the following is NOT mentioned as a security parameter in the document?

a)

Password policy

b)

Acceptable software policy

c)

Network speed policy

d)

Device hardening parameters

9.

What is the purpose of a password policy?

a)

To define rules for setting and protecting passwords

b)

To create complex passwords for users

c)

To store passwords securely

d)

To share passwords among employees

10.

Which of the following is NOT considered in a password policy?

a)

The don’ts of password creation

b)

The dos of password creation

c)

Protection of passwords

d)

Sharing passwords with others

11.

What is a key characteristic of a good password according to the password policy?

a)

It should be guessable.

b)

It should contain personal information.

c)

It should be at least 8 characters long.

d)

It should be the same for multiple systems.

12.

Which of the following is NOT recommended when creating a password?

a)

Using common words.

b)

Using a mix of upper-case and lower-case letters.

c)

Including numbers and special characters.

d)

Making it at least 8 characters long.

13.

How should passwords be stored according to the password policy?

a)

Written down somewhere.

b)

In a secure database.

c)

Shared with friends.

d)

On a sticky note.

14.

What should you do if a password is generated automatically?

a)

Share it with others.

b)

Write it down.

c)

Change it immediately.

d)

Use it for multiple accounts.

15.

What is the purpose of an acceptable software policy?

a)

To allow unrestricted software installation

b)

To control and restrict software installation

c)

To promote downloading unauthorized material

d)

To ensure all employees have admin rights

16.

How can IT staff enforce the acceptable software policy?

a)

By giving all employees admin rights

b)

By configuring an employee’s access rights to block installation

c)

By allowing all software downloads

d)

By removing all software from the system

17.

What might happen to employees who breach the acceptable software policy?

a)

They receive a bonus

b)

They are given more access rights

c)

They may face a warning, suspension, or restriction

d)

They are promoted

18.

What must employees do to install new software according to the Acceptable Software Policy?

a)

Install it themselves without permission.

b)

Request the software from IT staff.

c)

Download it from the internet.

d)

Use any available software.

19.

What is a potential downside of the Acceptable Software Policy?

a)

It increases productivity.

b)

It allows immediate software installation.

c)

It can take several months, harming productivity.

d)

It reduces the need for IT staff.

20.

What is the primary purpose of an acceptable use policy in a company?

a)

To define what a user can and cannot do on a company’s IT systems.

b)

To allow employees to play video games during work hours.

c)

To encourage employees to use personal email during company time.

d)

To eliminate all IT systems in the company.

21.

Why is it important to have an acceptable use policy?

a)

To keep company IT systems safe from threats.

b)

To allow unrestricted access to all websites.

c)

To ensure employees can use personal devices at work.

d)

To promote the use of social media during work hours.

22.

What does an acceptable use policy typically include?

a)

A series of dos and don’ts for employees.

b)

Instructions to ignore company IT systems.

c)

Guidelines to increase personal email usage.

d)

Steps to remove all security measures.

23.

Which of the following actions is prohibited according to the Acceptable Use Policy?

a)

Creating or transmitting offensive images

b)

Sharing your own creative work

c)

Accessing public websites

d)

Using your own password

24.

What is not allowed regarding other users' data according to the Acceptable Use Policy?

a)

Sharing it with permission

b)

Corrupting or destroying it

c)

Backing it up

d)

Viewing it with consent

25.

According to the Acceptable Use Policy, what should you avoid doing with another person's files?

a)

Backing them up

b)

Examining or changing them

c)

Organizing them

d)

Sharing them with permission

26.

What is a violation of privacy according to the Acceptable Use Policy?

a)

Viewing public profiles

b)

Violating the privacy of other users

c)

Sending a friend request

d)

Commenting on a public post

27.

What is the purpose of device hardening?

a)

To enhance the device's physical appearance

b)

To improve the device's processing speed

c)

To protect a system's data from harm

d)

To increase the device's storage capacity

28.

What do cybersecurity policies define in relation to device hardening?

a)

The device's color and design

b)

Device hardening parameters and technologies

c)

The device's battery life

d)

The device's brand and model

29.

What is the benefit of implementing and enforcing device hardening?

a)

It makes the device more user-friendly

b)

It protects systems from cybersecurity threats

c)

It reduces the device's weight

d)

It increases the device's market value

30.

What time must virus definitions be updated on all IT systems?

a)

9 p.m.

b)

10 p.m.

c)

11 p.m.

d)

12 a.m.

31.

Which ports must remain open on the firewall?

a)

21, 80, 110

b)

53, 443, 80

c)

25, 110, 143

d)

22, 8080, 3306

32.

When must full backups of company data be performed?

a)

Every Saturday at 1 a.m.

b)

Every Sunday at 1 a.m.

c)

Every Monday at 1 a.m.

d)

Every Friday at 1 a.m.

33.

At what time are incremental backups of changes made every day?

a)

9 p.m.

b)

10 p.m.

c)

11 p.m.

d)

12 a.m.

34.

What is the primary purpose of a disaster recovery policy?

a)

To ensure an organisation's readiness to respond to a disaster

b)

To increase profits during a disaster

c)

To prevent all types of disasters

d)

To eliminate the need for cybersecurity

35.

Which of the following is NOT mentioned as an incident that disaster recovery is effective against?

a)

Data loss

b)

Environmental threats

c)

Hardware failure

d)

Increased sales

36.

What is one of the benefits of keeping a detailed, well-documented disaster recovery plan?

a)

It guarantees no data will ever be lost

b)

Business service can be resumed as soon as possible

c)

It prevents all natural disasters

d)

It eliminates the need for insurance

37.

What is the purpose of defining the responsibility of different staff in a disaster recovery policy?

a)

To ensure accountability and reduce confusion

b)

To increase workload

c)

To eliminate the need for training

d)

To delay response time

38.

What should staff do immediately in the event of a disaster according to the policy?

a)

Report an incident to the incident response lead

b)

Wait for further instructions

c)

Ignore the incident

d)

Contact the media

39.

What does the backup policy define in a disaster recovery plan?

a)

The type of data to be backed up, frequency, timing, and location

b)

The cost of data recovery

c)

The software used for data backup

d)

The number of employees involved in the backup process

40.

Why might weekly backups on Sunday evening be insufficient for some businesses?

a)

Because they are too frequent

b)

Because they are not frequent enough

c)

Because they are too costly

d)

Because they require too much storage space

41.

What does the timeline for data recovery indicate in a disaster recovery policy?

a)

The cost of recovery

b)

The order and time it takes to recover each system

c)

The software used for recovery

d)

The number of employees needed for recovery

42.

What is the purpose of a "hot site" in disaster recovery policies?

a)

To provide a backup location for data storage

b)

To instantly switch business operations after a disaster

c)

To train employees on disaster recovery procedures

d)

To store old hardware and software

43.

What does a disaster recovery policy typically define regarding alternative provision?

a)

The cost of new hardware

b)

The location of additional hardware, software, and personnel

c)

The timeline for disaster recovery

d)

The number of employees needed for recovery

44.

What is the first step a business should take after an attack?

a)

Respond

b)

Investigate

c)

Manage

d)

Recover

45.

Why is it important for employees to be aware of actions to take after an attack?

a)

To increase profits

b)

To resume functionality and minimize damage

c)

To hire more staff

d)

To expand the business

46.

Which of the following is NOT a step mentioned for actions after an attack?

a)

Investigate

b)

Respond

c)

Expand

d)

Analyse

47.

What is the first step to take after an attack according to the document?

a)

Investigate the attributes of the attack

b)

Ignore the attack

c)

Immediately inform the media

d)

Shut down all systems

48.

Why is it important to inform customers after a data breach?

a)

To sell them new products

b)

To require action from their end

c)

To increase company profits

d)

To avoid legal issues

49.

What should be established to decide the level of response required after an attack?

a)

The severity of the attack

b)

The cost of the attack

c)

The location of the attack

d)

The number of attackers

50.

Who should be informed about an attack besides customers?

a)

Relevant stakeholders and authorities

b)

Only the CEO

c)

The general public

d)

Competitors

51.

What is the first step to take after an attack to prevent further damage?

a)

Implement a disaster recovery policy

b)

Isolate and contain the attack

c)

Establish new plans for future attacks

d)

Restore the most recent backup

52.

Which of the following is an example of targeting the problem after an attack?

a)

Restoring the most recent backup

b)

Establishing new plans for future attacks

c)

Using a firewall to block malicious traffic

d)

Implementing a disaster recovery policy

53.

What should be implemented to correct any damage caused by an incident?

a)

Isolate and contain the attack

b)

Use a firewall to block traffic

c)

Implement the disaster recovery policy

d)

Establish new plans for future attacks

54.

What might be involved in recovering from an attack to prevent similar future incidents?

a)

Isolating and containing the attack

b)

Using a firewall to block traffic

c)

Establishing new plans

d)

Restoring the most recent backup

55.

What is one of the first steps to take after an attack to help prevent future threats?

a)

Work with employees to establish information about the attack.

b)

Ignore the attack and continue as usual.

c)

Immediately update all software without analysis.

d)

Fire the employees involved.

56.

Why is it important to analyze the attack after it occurs?

a)

To assess what changes can be made.

b)

To blame someone for the attack.

c)

To delete all data related to the attack.

d)

To ensure it never happened.

57.

What should be updated as a result of analyzing an attack?

a)

Policies and procedures.

b)

Employee salaries.

c)

Office furniture.

d)

Company logo.