wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Information Security and Risk Management Quiz

Total questions: 57

Worksheet time: 29mins

Name
Class
Date
1.

Which of the following best defines a "threat" in information security?

a)

A physical device used to protect a system

b)

A potential danger to an asset

c)

A software update

d)

A user policy

2.

Which of the following is a type of malicious code that replicates itself without human interaction?

a)

Virus

b)

Trojan

c)

Worm

d)

Spyware

3.

What is the primary goal of risk mitigation as a control strategy?

a)

Transfer the risk to another party

b)

Ignore the risk

c)

Reduce the impact or likelihood of the risk

d)

Document the risk

4.

Which risk control strategy involves purchasing insurance or outsourcing to manage risk?

a)

Mitigation

b)

Transference

c)

Avoidance

d)

Acceptance

5.

Which component of a contingency plan focuses on identifying the impact of a disruption to business operations?

a)

IRP

b)

BIA

c)

DRP

d)

BCP

6.

Which of the following best defines “Incident Response Planning (IRP)”?

a)

Planning for business growth

b)

Planning how to detect and respond to security incidents

c)

Planning for financial investments

d)

Planning for system upgrades

7.

What is the main focus of Disaster Recovery Planning (DRP)?

a)

Avoiding all risks

b)

Continuing normal business operations

c)

Restoring IT systems and data after a disaster

d)

Promoting company mission

8.

Which term refers to a formal statement that defines the organization's objectives and direction?

a)

Standard

b)

Vision

c)

Policy

d)

Control

9.

An "asset" in information security is any resource that has value to the organization.

a)

True

b)

False

10.

A virus needs user interaction to spread, unlike a worm which spreads automatically.

a)

True

b)

False

11.

Business Continuity Planning (BCP) ensures that business functions can continue during and after a disruption.

a)

True

b)

False

12.

Which of the following is a core responsibility of the Contingency Planning Management Team (CPMT)?

a)

Writing user manuals

b)

Managing marketing campaigns

c)

Developing and maintaining the contingency plan

d)

Installing operating systems

13.

Which CPMT position typically holds a high-level oversight role?

a)

CP Coordinator

b)

IT Representative

c)

Business Unit Representative

d)

Executive Manager

14.

Which term refers to the maximum time allowed to recover a system after a disruption?

a)

Downtime limit

b)

Recovery point objective (RPO)

c)

Data retention period

d)

Recovery time objective (RTO)

15.

Which of the following is NOT a key principle of information security?

a)

Confidentiality

b)

Profitability

c)

Availability

d)

Integrity

16.

System logs and financial reports help evaluate the impact of system disruptions.

a)

True

b)

False

17.

Recovery point objective (RPO) defines how long it takes to restore operations.

a)

True

b)

False

18.

The three key stages of a Business Impact Analysis (BIA) are data collection, impact analysis, and reporting.

a)

True

b)

False

19.

What is the primary purpose of a Business Resumption Plan (BRP)?

a)

To prevent cyberattacks

b)

To restore normal business operations after a disruption

c)

To configure firewall settings

d)

To conduct financial audits

20.

When should data be archived instead of backed up?

a)

For short-term restoration

b)

When data must be permanently deleted

c)

For long-term storage and compliance

d)

When data is corrupted

21.

Which backup site is fully equipped and ready to operate immediately?

a)

Cold site

b)

Warm site

c)

Mobile site

d)

Hot site

22.

What does RAID 0 provide?

a)

Full redundancy and fault tolerance

b)

Data striping without redundancy

c)

Mirrored data across locations

d)

Offsite backup storage

23.

What is a key characteristic of Network-Attached Storage (NAS)?

a)

Connected directly to CPUs

b)

Accessible over a network by multiple users

c)

Primarily for long-term archives

d)

Requires no power source

24.

What is a virtual machine (VM)?

a)

A physical device used for backup

b)

A type of virus scanner

c)

Software-based emulation of a physical computer

d)

A portable flash drive

25.

Hot, warm, and cold servers are used based on how quickly systems need to be restored.

a)

True

b)

False

26.

Cold sites are more expensive than hot sites because they are faster to restore.

a)

True

b)

False

27.

Time-share agreements provide shared backup facilities but may not be reliable during widespread disasters.

a)

True

b)

False

28.

Mutual agreements and service agreements define shared responsibilities and performance expectations.

a)

True

b)

False

29.

A nondisclosure agreement (NDA) ensures that shared sensitive information stays confidential.

a)

True

b)

False

30.

Which of the following is not one of the typical incident planning stages?

a)

Plan development

b)

Detection and analysis

c)

Financial auditing

d)

Recovery and post-incident

31.

What is the first step in forming the Incident Response Planning (IRP) team?

a)

Conducting forensic analysis

b)

Selecting members from key departments

c)

Purchasing backup systems

d)

Writing post-incident reports

32.

Which term refers to the formal guidelines that define how incidents are handled?

a)

Incident Response Activation

b)

Incident Response Policy

c)

CSIRT Charter

d)

Detection Protocol

33.

Which training delivery method typically has the highest cost?

a)

Self-paced online learning

b)

Printed manuals

c)

Instructor-led classroom training

d)

Email reminders

34.

A CSIRT reaction force is a rapid-response team that addresses urgent security incidents.

a)

True

b)

False

35.

Forensic analysis and after-action reviews (AAR) are part of planning for after an incident.

a)

True

b)

False

36.

Self-paced training is generally more expensive than instructor-led training.

a)

True

b)

False

37.

What is a precursor in incident detection?

a)

A confirmed sign of an attack

b)

A historical log entry

c)

An early sign that an incident might occur

d)

A patch for vulnerable systems

38.

Which of the following is considered a definite indicator of an incident?

a)

Suspicious email subject line

b)

Malware detected on a host

c)

Abnormally high web traffic

d)

A slow network connection

39.

Which method does a network-based IDPS use to detect known threats?

a)

Behavioral analysis

b)

Machine learning

c)

Signature matching

d)

Random sampling

40.

What is a honeypot used for in automated response?

a)

Backing up data

b)

Running intrusion scans

c)

Luring attackers to observe behavior

d)

Encrypting files

41.

Which of the following best describes anomaly-based IDPS?

a)

Uses known attack patterns

b)

Only monitors outbound traffic

c)

Detects deviations from normal behavior

d)

Requires no configuration

42.

Trap-and-trace systems help track and identify intruders after detection.

a)

True

b)

False

43.

Signature matching can be used to detect DNS cache poisoning attacks.

a)

True

b)

False

44.

Real incidents always match known signatures.

a)

True

b)

False

45.

What is the IRP team’s main responsibility?

a)

Drafting budget reports

b)

Managing and responding to security incidents

c)

Installing antivirus software

d)

Conducting physical security audits

46.

What is the first step in building a formal CSIRT?

a)

Purchasing security tools

b)

Appointing a CSIRT champion

c)

Conducting training sessions

d)

Writing technical procedures

47.

Who typically acts as the CSIRT champion in the initial stage?

a)

An external consultant

b)

A senior executive or sponsor

c)

A junior security analyst

d)

The marketing director

48.

Which CSIRT structure has a single team serving the whole organization?

a)

Distributed CSIRTs

b)

Coordinating Team

c)

Central CSIRT

d)

Regional Response Unit

49.

Which CSIRT structure focuses on linking and supporting multiple CSIRTs?

a)

Central CSIRT

b)

Coordinating Team

c)

Isolated Unit

d)

Unified Command

50.

What distinguishes fully outsourced CSIRT models?

a)

Entirely handled by an external provider

b)

No technical skills required

c)

Maintained by in-house personnel only

d)

Only used during normal operations

51.

What is a partially outsourced CSIRT model?

a)

Only vendors are involved

b)

Internal staff handle everything

c)

Shared responsibility between internal staff and providers

d)

Limited to regulatory audits

52.

Which CSIRT service category includes vulnerability scanning and patch management?

a)

Reactive Services

b)

Proactive Services

c)

Emergency Support

d)

Legal Compliance Services

53.

Which CSIRT service category involves digital forensics and incident response?

a)

Security Awareness Services

b)

Security Quality Management Services

c)

Reactive Services

d)

Policy Development Services

54.

What is the goal of Security Quality Management Services?

a)

Develop marketing plans

b)

Enhance and measure overall security practices

c)

Respond to active attacks

d)

Build network hardware

55.

What does “Identifying Your Constituency” involve?

a)

Choosing an antivirus vendor

b)

Understanding the systems you plan to protect

c)

Building a disaster recovery site

d)

Running regular maintenance checks

56.

Which of the following is a service typically offered when selecting CSIRT services for a constituency?

a)

Product advertising

b)

Vulnerability assessment

c)

Social media management

d)

Legal arbitration

57.

What is the purpose of a technology watch service in a CSIRT?

a)

Monitor staff activity

b)

Track emerging security trends and threats

c)

Manage company finances

d)

Repair broken hardware