NEW
Font size
WorksheetsInformation Security and Risk Management Quiz
Total questions: 57
Worksheet time: 29mins
Which of the following best defines a "threat" in information security?
A physical device used to protect a system
A potential danger to an asset
A software update
A user policy
Which of the following is a type of malicious code that replicates itself without human interaction?
Virus
Trojan
Worm
Spyware
What is the primary goal of risk mitigation as a control strategy?
Transfer the risk to another party
Ignore the risk
Reduce the impact or likelihood of the risk
Document the risk
Which risk control strategy involves purchasing insurance or outsourcing to manage risk?
Mitigation
Transference
Avoidance
Acceptance
Which component of a contingency plan focuses on identifying the impact of a disruption to business operations?
IRP
BIA
DRP
BCP
Which of the following best defines “Incident Response Planning (IRP)”?
Planning for business growth
Planning how to detect and respond to security incidents
Planning for financial investments
Planning for system upgrades
What is the main focus of Disaster Recovery Planning (DRP)?
Avoiding all risks
Continuing normal business operations
Restoring IT systems and data after a disaster
Promoting company mission
Which term refers to a formal statement that defines the organization's objectives and direction?
Standard
Vision
Policy
Control
An "asset" in information security is any resource that has value to the organization.
True
False
A virus needs user interaction to spread, unlike a worm which spreads automatically.
True
False
Business Continuity Planning (BCP) ensures that business functions can continue during and after a disruption.
True
False
Which of the following is a core responsibility of the Contingency Planning Management Team (CPMT)?
Writing user manuals
Managing marketing campaigns
Developing and maintaining the contingency plan
Installing operating systems
Which CPMT position typically holds a high-level oversight role?
CP Coordinator
IT Representative
Business Unit Representative
Executive Manager
Which term refers to the maximum time allowed to recover a system after a disruption?
Downtime limit
Recovery point objective (RPO)
Data retention period
Recovery time objective (RTO)
Which of the following is NOT a key principle of information security?
Confidentiality
Profitability
Availability
Integrity
System logs and financial reports help evaluate the impact of system disruptions.
True
False
Recovery point objective (RPO) defines how long it takes to restore operations.
True
False
The three key stages of a Business Impact Analysis (BIA) are data collection, impact analysis, and reporting.
True
False
What is the primary purpose of a Business Resumption Plan (BRP)?
To prevent cyberattacks
To restore normal business operations after a disruption
To configure firewall settings
To conduct financial audits
When should data be archived instead of backed up?
For short-term restoration
When data must be permanently deleted
For long-term storage and compliance
When data is corrupted
Which backup site is fully equipped and ready to operate immediately?
Cold site
Warm site
Mobile site
Hot site
What does RAID 0 provide?
Full redundancy and fault tolerance
Data striping without redundancy
Mirrored data across locations
Offsite backup storage
What is a key characteristic of Network-Attached Storage (NAS)?
Connected directly to CPUs
Accessible over a network by multiple users
Primarily for long-term archives
Requires no power source
What is a virtual machine (VM)?
A physical device used for backup
A type of virus scanner
Software-based emulation of a physical computer
A portable flash drive
Hot, warm, and cold servers are used based on how quickly systems need to be restored.
True
False
Cold sites are more expensive than hot sites because they are faster to restore.
True
False
Time-share agreements provide shared backup facilities but may not be reliable during widespread disasters.
True
False
Mutual agreements and service agreements define shared responsibilities and performance expectations.
True
False
A nondisclosure agreement (NDA) ensures that shared sensitive information stays confidential.
True
False
Which of the following is not one of the typical incident planning stages?
Plan development
Detection and analysis
Financial auditing
Recovery and post-incident
What is the first step in forming the Incident Response Planning (IRP) team?
Conducting forensic analysis
Selecting members from key departments
Purchasing backup systems
Writing post-incident reports
Which term refers to the formal guidelines that define how incidents are handled?
Incident Response Activation
Incident Response Policy
CSIRT Charter
Detection Protocol
Which training delivery method typically has the highest cost?
Self-paced online learning
Printed manuals
Instructor-led classroom training
Email reminders
A CSIRT reaction force is a rapid-response team that addresses urgent security incidents.
True
False
Forensic analysis and after-action reviews (AAR) are part of planning for after an incident.
True
False
Self-paced training is generally more expensive than instructor-led training.
True
False
What is a precursor in incident detection?
A confirmed sign of an attack
A historical log entry
An early sign that an incident might occur
A patch for vulnerable systems
Which of the following is considered a definite indicator of an incident?
Suspicious email subject line
Malware detected on a host
Abnormally high web traffic
A slow network connection
Which method does a network-based IDPS use to detect known threats?
Behavioral analysis
Machine learning
Signature matching
Random sampling
What is a honeypot used for in automated response?
Backing up data
Running intrusion scans
Luring attackers to observe behavior
Encrypting files
Which of the following best describes anomaly-based IDPS?
Uses known attack patterns
Only monitors outbound traffic
Detects deviations from normal behavior
Requires no configuration
Trap-and-trace systems help track and identify intruders after detection.
True
False
Signature matching can be used to detect DNS cache poisoning attacks.
True
False
Real incidents always match known signatures.
True
False
What is the IRP team’s main responsibility?
Drafting budget reports
Managing and responding to security incidents
Installing antivirus software
Conducting physical security audits
What is the first step in building a formal CSIRT?
Purchasing security tools
Appointing a CSIRT champion
Conducting training sessions
Writing technical procedures
Who typically acts as the CSIRT champion in the initial stage?
An external consultant
A senior executive or sponsor
A junior security analyst
The marketing director
Which CSIRT structure has a single team serving the whole organization?
Distributed CSIRTs
Coordinating Team
Central CSIRT
Regional Response Unit
Which CSIRT structure focuses on linking and supporting multiple CSIRTs?
Central CSIRT
Coordinating Team
Isolated Unit
Unified Command
What distinguishes fully outsourced CSIRT models?
Entirely handled by an external provider
No technical skills required
Maintained by in-house personnel only
Only used during normal operations
What is a partially outsourced CSIRT model?
Only vendors are involved
Internal staff handle everything
Shared responsibility between internal staff and providers
Limited to regulatory audits
Which CSIRT service category includes vulnerability scanning and patch management?
Reactive Services
Proactive Services
Emergency Support
Legal Compliance Services
Which CSIRT service category involves digital forensics and incident response?
Security Awareness Services
Security Quality Management Services
Reactive Services
Policy Development Services
What is the goal of Security Quality Management Services?
Develop marketing plans
Enhance and measure overall security practices
Respond to active attacks
Build network hardware
What does “Identifying Your Constituency” involve?
Choosing an antivirus vendor
Understanding the systems you plan to protect
Building a disaster recovery site
Running regular maintenance checks
Which of the following is a service typically offered when selecting CSIRT services for a constituency?
Product advertising
Vulnerability assessment
Social media management
Legal arbitration
What is the purpose of a technology watch service in a CSIRT?
Monitor staff activity
Track emerging security trends and threats
Manage company finances
Repair broken hardware
