wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Information Security Controls Quiz

Total questions: 22

Worksheet time: 11mins

Name
Class
Date
1.

Which of the following is considered a technical control in information security?

a)

Security policy enforcement

b)

Intrusion Detection System (IDS)

c)

User training program

d)

Security camera installation

2.

An organization installs a badge reader and surveillance cameras at all facility entrances. What type of control is this?

a)

Operational

b)

Managerial

c)

Technical

d)

Physical

3.

Which security control type includes activities such as incident response planning and access reviews?

a)

Physical

b)

Operational

c)

Managerial

d)

Preventive

4.

Which of the following controls is designed to alert administrators to a security incident?

a)

Preventive

b)

Corrective

c)

Detective

d)

Compensating

5.

What is the main purpose of a compensating control?

a)

To prevent unauthorized access

b)

To detect unusual activity

c)

To serve as an alternative when primary controls fail

d)

To guide user behavior through policies

6.

Which component of the Zero Trust model evaluates access policies before granting access?

a)

Policy Enforcement Point

b)

Policy Administrator

c)

Policy Engine

d)

Security Token Service

7.

What role does non-repudiation play in cybersecurity?

a)

Prevents data interception

b)

Ensures system redundancy

c)

Proves an action or communication occurred

d)

Encrypts user credentials

8.

What is the purpose of an impact analysis in the change management process?

a)

To reduce implementation cost

b)

To assess how a change affects systems and security

c)

To train staff on security best practices

d)

To monitor compliance with data retention policies

9.

Which security tool aggregates and analyzes logs to detect security threats?

a)

Patch Management

b)

Data Loss Prevention (DLP)

c)

Security Information and Event Management (SIEM)

d)

Access Control List (ACL)

10.

Why is alert tuning important in security monitoring?

a)

To save bandwidth during log transmission

b)

To improve network throughput

c)

To reduce false positives and prioritize real threats

d)

To increase patching frequency

11.

Which of the following best describes the Preventive type of security control?

a)

Identifies and records incidents

b)

Discourages non-compliance

c)

Stops incidents from occurring in the first place

d)

Responds to an incident after detection

12.

What is the purpose of directive controls in a security environment?

a)

Detect and report anomalies

b)

Prevent unauthorized actions

c)

Provide guidance on expected behavior

d)

Repair systems after a breach

13.

What does the AAA framework stand for in security?

a)

Audit, Access, Authorization

b)

Authentication, Authorization, Accounting

c)

Assurance, Availability, Authentication

d)

Assessment, Access, Accounting

14.

Which term best represents the security concept of ensuring that only authorized individuals can access sensitive data?

a)

Integrity

b)

Availability

c)

Confidentiality

d)

Redundancy

15.

Which of the following is an example of a deterrent control?

a)

Antivirus software

b)

Surveillance cameras with warning signs

c)

Disaster recovery plans

d)

Authentication logs

16.

Which of the following is a key benefit of using a SIEM tool?

a)

Enforces policies across multiple departments

b)

Blocks unauthorized inbound network traffic

c)

Centralizes log data for correlation and alerting

d)

Encrypts confidential data in storage

17.

In a security audit, which type of control would a training program for new employees be considered?

a)

Technical

b)

Operational

c)

Physical

d)

Preventive

18.

Why is version control important in change management?

a)

It reduces the time needed to deploy changes

b)

It ensures all system changes are documented and traceable

c)

It prevents users from editing secure files

d)

It updates antivirus definitions automatically

19.

Which of the following describes the Zero Trust principle?

a)

Trust but verify user identities

b)

All devices inside the network are safe

c)

Never trust, always verify

d)

Block all external traffic automatically

20.

What is the purpose of a backout plan in the change management process?

a)

To finalize security documentation

b)

To track user activity

c)

To revert systems to their previous state if a change fails

d)

To train users on new software

21.

Which type of control is used to discourage malicious actors from attempting to breach a network?

a)

Preventative

b)

Detective

c)

Deterrent

d)

Physical

22.

Which of the following physical security controls would be the most effective in preventing an attacker from driving a vehicle through the glass doors at the front of the organization's headquarters?

a)

Security guards

b)

Bollards

c)

Intrusion alarm

d)

Mantraps