NEW
Font size
WorksheetsInformation Security Controls Quiz
Total questions: 22
Worksheet time: 11mins
Which of the following is considered a technical control in information security?
Security policy enforcement
Intrusion Detection System (IDS)
User training program
Security camera installation
An organization installs a badge reader and surveillance cameras at all facility entrances. What type of control is this?
Operational
Managerial
Technical
Physical
Which security control type includes activities such as incident response planning and access reviews?
Physical
Operational
Managerial
Preventive
Which of the following controls is designed to alert administrators to a security incident?
Preventive
Corrective
Detective
Compensating
What is the main purpose of a compensating control?
To prevent unauthorized access
To detect unusual activity
To serve as an alternative when primary controls fail
To guide user behavior through policies
Which component of the Zero Trust model evaluates access policies before granting access?
Policy Enforcement Point
Policy Administrator
Policy Engine
Security Token Service
What role does non-repudiation play in cybersecurity?
Prevents data interception
Ensures system redundancy
Proves an action or communication occurred
Encrypts user credentials
What is the purpose of an impact analysis in the change management process?
To reduce implementation cost
To assess how a change affects systems and security
To train staff on security best practices
To monitor compliance with data retention policies
Which security tool aggregates and analyzes logs to detect security threats?
Patch Management
Data Loss Prevention (DLP)
Security Information and Event Management (SIEM)
Access Control List (ACL)
Why is alert tuning important in security monitoring?
To save bandwidth during log transmission
To improve network throughput
To reduce false positives and prioritize real threats
To increase patching frequency
Which of the following best describes the Preventive type of security control?
Identifies and records incidents
Discourages non-compliance
Stops incidents from occurring in the first place
Responds to an incident after detection
What is the purpose of directive controls in a security environment?
Detect and report anomalies
Prevent unauthorized actions
Provide guidance on expected behavior
Repair systems after a breach
What does the AAA framework stand for in security?
Audit, Access, Authorization
Authentication, Authorization, Accounting
Assurance, Availability, Authentication
Assessment, Access, Accounting
Which term best represents the security concept of ensuring that only authorized individuals can access sensitive data?
Integrity
Availability
Confidentiality
Redundancy
Which of the following is an example of a deterrent control?
Antivirus software
Surveillance cameras with warning signs
Disaster recovery plans
Authentication logs
Which of the following is a key benefit of using a SIEM tool?
Enforces policies across multiple departments
Blocks unauthorized inbound network traffic
Centralizes log data for correlation and alerting
Encrypts confidential data in storage
In a security audit, which type of control would a training program for new employees be considered?
Technical
Operational
Physical
Preventive
Why is version control important in change management?
It reduces the time needed to deploy changes
It ensures all system changes are documented and traceable
It prevents users from editing secure files
It updates antivirus definitions automatically
Which of the following describes the Zero Trust principle?
Trust but verify user identities
All devices inside the network are safe
Never trust, always verify
Block all external traffic automatically
What is the purpose of a backout plan in the change management process?
To finalize security documentation
To track user activity
To revert systems to their previous state if a change fails
To train users on new software
Which type of control is used to discourage malicious actors from attempting to breach a network?
Preventative
Detective
Deterrent
Physical
Which of the following physical security controls would be the most effective in preventing an attacker from driving a vehicle through the glass doors at the front of the organization's headquarters?
Security guards
Bollards
Intrusion alarm
Mantraps
