Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

قواعد 9

Total questions: 93

Worksheet time: 48mins

Name
Class
Date
1.

Changing data values for reasons of sabotage, crime or ignorance which may be enabled by inadequate security mechanisms, or sharing of passwords or password guessing

a)
Data encryption
b)
Data backup
c)

Unauthorized modification

d)
Data analysis
2.

Which of the following can enable unauthorized modification?

a)

Sharing passwords

b)

Password guessing

c)

Secure protocols

d)

Strong passwords

3.

Unauthorized modification can happen because of ignorance.

a)

True

b)

False

4.

Strong security mechanisms help prevent unauthorized access

a)

True

b)

False

5.

When information that should not have been disclosed has been disclosed. A general issue of crucial importance, which can be accidental or deliberate.

a)
Data breach
b)
Information leak
c)
Privacy violation
d)

Unauthorized disclosure

6.

Unauthorized disclosure can be:

a)

Only accidental

b)

Only deliberate

c)

Either accidental or deliberate

7.

What does "loss of availability" refer to?

a)

System downtime

b)

Unauthorized modification

8.

Another name for "loss of availability" is:

a)

Data encryption

b)

Denial of Service

9.

Even short downtime can be a threat to system availability.

a)

True

b)

False

10.

Most financial losses through fraud arise from employees.

a)

True

b)

False

11.

Most financial losses through fraud come from:

a)

Hackers

b)

Employees

12.

What do access controls help with?

a)

Preventing fraud and tracking harmful actions

b)

Speeding up the internet

13.

What can access controls record?

a)

Only successful attacks

b)

Only failed attempts

c)

Both successful and failed harmful attempts

14.

Access controls can help prevent internal fraud

a)

True

b)

False

15.

is data about an identifiable individual.

a)
Public data
b)
Personal data
c)
Confidential information
d)
Statistical data
16.

Often the individual has to be live but the method of identification is not prescribed

a)

True

b)

False

17.

What is personal data?

a)

Data about any company

b)

Data about an identifiable individual

18.

Can a postal code identify someone?

a)

Only if it's shared by many people

b)

Yes, if only one person lives at that address

19.

Personal data should be:

a)

Backed up monthly

b)

Handled and controlled carefully

20.

A postal code can be considered personal data in some cases.

a)

True

b)

False

21.

What is an example of computer misuse?

a)

Updating antivirus software

b)

Accessing the system with permission

c)

Introducing viruses to a system

22.

Computer misuse includes:

a)

Protecting user data

b)

Improving software performance

c)

Violating access controls

23.

One goal of computer misuse is to:

a)

Cause damage or disruption

b)

Increase speed

24.

What do audit requirements help determine?

a)

Future software updates

b)

Who did what and when

25.

These are operational constraints built around the need to know who did what, who tried to do what, and where and when everything happened.

a)
Evaluating customer satisfaction.
b)
Tracking of financial transactions.
c)
Monitoring employee attendance.
d)

Audit requirements

26.

Audit logs can be used for:

a)

Entertainment purposes

b)

Legal defense or prosecution

27.

Audit requirements usually involve:

a)

Blocking users automatically

b)

Monitoring and logging system activity

28.

Audit logs can provide evidence of unauthorized actions.

a)

True

b)

False

29.

What can OS-level utilities allow someone to do?

a)

Directly access and damage the database

b)

Improve graphics performance

30.

What is a good security practice mentioned in the text?

a)

Increase communication channels

b)

Minimize and isolate system communications

31.

Access to OS utilities can lead to copying or damaging the database.

a)

True

b)

False

32.

Reducing communication channels helps protect against unnecessary threats.

a)

True

b)

False

33.

is the process of converting text and data into a form that can only be read by the recipient of that data or text, who has to know how to convert it back to a clear message.

a)
encryption
b)
decryption
c)
compression
d)
translation
34.

Encryption is the process of:

a)

Deleting data permanently

b)

Making data visible to everyone

c)

Converting readable data into unreadable form

35.

What is typically encrypted?

a)

Only user passwords

b)

Both data and the schema

36.

Who can read encrypted data?

a)

All administrators

b)

Only the person with the right decryption method

37.

What is a security model used for?

a)

To create passwords

b)

To organize thoughts about security

38.

Which of the following is NOT part of the major categories in a security model?

a)

Threats

b)

Weather

c)

Impact

d)

Loss

39.

Security models vary depending on:

a)

The color of the software

b)

User roles and purpose

40.

A security model helps in organizing security-related ideas.

a)

True

b)

False

41.

Threats, impact, and loss are key categories in a security model.

a)

True

b)

False

42.

Which of the following is considered a security asset?

a)

Screensaver

b)

Data quality

43.

What is the correct way to view security risks?

a)

As ways to improve design

b)

As potential loss of assets

44.

Which of the following is typically considered an asset in security?

a)
  • Hardware

b)
  • Data

c)
  • Credibility

d)

Decoration

e)

Business benefit

45.

Which of the following is typically considered an asset in security?

a)
Network protocols
b)
Firewalls
c)
User permissions
d)

Hardware

e)

Software

46.

To structure thoughts on security, you need a model of security.

a)

True

b)

False

47.

model of security come in various forms that depend on

a)

purpose

b)

size

c)

degree

d)

roles

48.

are to be seen in terms of the loss of assets.

a)
Gain of assets
b)

Security risks

c)
Asset depreciation
d)
Increase in liabilities
49.

What is the primary concern mentioned in this context?

a)

Hardware

b)

Decorations

c)

Data and data quality

50.

A threat to one asset:

a)

Only affects that asset

b)
  • Can impact other assets

51.

Data and data quality are the main security concerns in this context.

a)

True

b)

False

52.

A threat to one asset never affects other assets.

a)

True

b)

False

53.

Knowing which asset needs protection is not necessary.

a)

False

b)

True

54.

Identifying the asset helps in focusing protection efforts.

a)

True

b)

False

55.

Which tool is used to address reliability issues?

a)

Logging

b)

Recover from corruption, loss, and damage

c)

Validation rules

56.

What technique helps with access security?

a)

Checkpoints

b)

Passwords

c)

Constraints

d)

Back-up

57.

To ensure internal consistency of data, we use:

a)

Logging

b)

Validation rules and constraints

58.

Logging and checkpoints are techniques for improving access security.

a)

True

b)

False

59.

Control Access is the tool used for Access Security.

a)

True

b)

False

60.

Ensuring internal consistency is part of schema security.

a)

True

b)

False

61.

Passwords are used to maintain data integrity.

a)

True

b)

False

62.

What is always true about security?

a)

It can be perfect

b)

There is always some risk

63.

What should be done in preparation for possible security issues?

a)

Hope nothing happens

b)

Prepare for worst-case scenarios

64.

Which of the following is NOT recommended in security planning?

a)

Spending more than the asset's value on security

b)

Planning recovery from damage

c)

Minimizing impact of attacks

d)

Ensuring security doesn't affect normal use

65.

Security can always be made 100% perfect

a)

True

b)

False

66.

It is wise to prepare for the worst possible outcome in security.

a)

True

b)

False

67.

Security should cost more than the asset being protected.

a)

True

b)

False

68.

Proper security must balance protection and system usability.

a)

True

b)

False

69.

What is the main purpose of a security model?

a)

To replace databases

b)

To set external criteria for examining security

70.

What do specific DBMSs have regarding security?

a)

Identical global settings

b)

Their own security models

71.

What is a possible result of faults in the security model?

a)

Faster operation

b)

Insecure or clumsy systems

72.

What is one drawback of access control?

a)

It is always free

b)

It can be expensive to analyze and operate

73.

Access control is typically applied to:

a)

Unknown environments

b)

Random users

c)

Known situations with known standards

74.

Control must always be:

a)

Strict regardless of context

b)

Appropriate to the situation

75.

Access control is free and easy to implement.

a)

True

b)

False

76.

Control measures should be appropriate to the situation.

a)

True

b)

False

77.

What is the goal of authentication?

a)

Verify the identity of client and server

b)

Increase storage

78.

What is commonly used for authentication?

a)

Shared printers

b)

Shared secrets like passwords or biometrics

79.

Authentication is a prerequisite for authorization.

a)

True

b)

False

80.

Authentication does not give any privileges for particular tasks.

a)

True

b)

False

81.

Authentication cannot be shared or transferred between systems.

a)

True

b)

False

82.

What does authentication confirm?

a)

The user’s trust level

b)

The identity of the user and system

83.

Which of the following is not true about authentication?

a)

It gives specific permissions to the user

b)

It comes before authorization

c)
  • It proves who the user is

d)

It helps the DBMS know who is connecting

84.

What is a prerequisite for authorization?

a)

Encryption

b)

Authentication

85.

Authentication helps both the user and the system trust each other.

a)

True

b)

False

86.

What does authorization control?

a)

User's identity

b)

User permissions for transactions

87.

Which of the following operations can be managed through authorization?

a)

Reading data

b)

Writing data

c)

Both A and B

d)

Logging out

88.

What is an example of an authorization vector?

a)

Authorization(item, auth-id, operation)

b)

SELECT * FROM table

89.

Authorization gives users permissions to access or modify data.

a)

True

b)

False

90.

Authentication and authorization are the same.

a)

True

b)

False

91.

A vector in authorization defines what operations a user can perform.

a)

True

b)

False

92.

Authorization is optional in database systems.

a)

True

b)

False

93.

is a sequence of data values at a known location in the system.

a)
List
b)
Set
c)
Map
d)

vector