wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Chapter Summary

Total questions: 71

Worksheet time: 36mins

Name
Class
Date
1.

What is the process of protecting the value of data as the organization creates, stores, shares, uses, modifies, archives, and finally destroys that data called?

a)

Data (information) security

b)

Data mining

c)

Data visualization

d)

Data redundancy

2.

During data handling, which of the following is NOT one of the steps an organization takes?

a)

Classifies data

b)

Categorizes data

c)

Encrypts data

d)

Retains data

e)

Destroys data

3.

A best practice for securing data is ________ the data.

a)

encrypting

b)

deleting

c)

sharing

d)

printing

4.

Hashing is a process that takes an input set of data and returns a ________ result called the hash value.

a)

fixed-length

b)

variable-length

c)

random

d)

encrypted

5.

System hardening is the process of applying secure configurations to reduce the ________ surface.

a)

attack

b)

display

c)

storage

d)

network

6.

Which of the following is NOT a best practice security policy mentioned in the chapter?

a)

Data handling

b)

Password

c)

Acceptable use

d)

Social engineering

e)

Change management

7.

Change management practices address documentation, approval, and rollback as core activities.

a)

True

b)

False

8.

Why is security awareness training important for an organization?

a)

It reduces the internal threat to an organization by educating, training, and raising awareness among employees.

b)

It increases the number of cyber attacks on the organization.

c)

It decreases employee productivity by distracting them from their main tasks.

d)

It makes the organization completely immune to all security threats.

9.

Which topic is covered in Module 1?

a)

Understand System Hardening

b)

Understand Data Security

c)

Understand Best Practice Security Policies

d)

Understand Security Awareness Training

10.

Module 2 covers which topic?

a)

Understand System Hardening

b)

Network Security Basics

c)

Incident Response Procedures

d)

Cloud Computing Fundamentals

11.

Which module covers 'Understand Best Practice Security Policies'?

a)

Module 1

b)

Module 2

c)

Module 3

d)

Module 4

12.

Module 4 is associated with which domains?

a)

5.1, 5.1.1, 5.1.2, 5.1.3

b)

5.2, 5.2.1

c)

5.3, 5.3.1, 5.3.2, 5.3.3, 5.3.4, 5.3.5, 5.3.6

d)

5.4, 5.4.1, 5.4.2, 5.3.2

13.

State one of the learning objectives:

a)

Explain concepts of security operations.

b)

Describe the process of software installation.

c)

List the types of network cables.

d)

Identify common office equipment.

14.

State one of the learning objectives:

a)

Discuss data handling best practices.

b)

Describe the process of photosynthesis.

c)

Explain the laws of motion.

d)

Identify the capitals of European countries.

15.

State one of the learning objectives:

a)

Identify key concepts of logging and monitoring.

b)

Describe the process of photosynthesis.

c)

Explain the laws of thermodynamics.

d)

List the capitals of European countries.

16.

State one of the learning objectives:

a)

Summarize the different types of encryption and their common uses.

b)

Describe the process of photosynthesis in plants.

c)

Explain the causes of the French Revolution.

d)

List the major planets in our solar system.

17.

State one of the learning objectives:

a)

Describe the concepts of configuration management.

b)

Explain the process of software testing.

c)

List the types of computer networks.

d)

Summarize the history of programming languages.

18.

State one of the learning objectives:

a)

Explain the application of common security policies.

b)

Describe the process of software installation.

c)

List the types of computer hardware.

d)

Identify popular social media platforms.

19.

State one of the learning objectives:

a)

Discuss the importance of security awareness training.

b)

List the steps to install a software update.

c)

Describe the process of hardware recycling.

d)

Explain the basics of network cabling.

20.

State one of the learning objectives:

a)

Practice the terminology of and review the concepts of network operations.

b)

Memorize unrelated historical dates.

c)

Learn advanced calculus techniques.

d)

Study the anatomy of plants.

21.

Which of the following is NOT a step in the data handling process?

a)

Create

b)

Store

c)

Encrypt

d)

Destroy

22.

Fill in the blank: The data handling process includes Create, Store, Share, Use, Modify, Archive, and _____

a)

Destroy

b)

Encrypt

c)

Transfer

d)

Analyze

23.

Which data sensitivity level could put the organization’s future existence at risk if compromised?

a)

Highly restricted

b)

Moderately restricted

c)

Low sensitivity

d)

Unrestricted public data

24.

Fill in the blank: Compromise of data with a _____ sensitivity label could lead to loss of temporary competitive advantage, loss of revenue, or disruption of planned investments or activities.

a)

Moderately restricted

b)

Public

c)

Highly confidential

d)

Unclassified

25.

Unrestricted public data, if compromised, can cause substantial loss of life or property damage.

a)

True

b)

False

26.

Which of the following is an ingress monitoring tool?

a)

Email

b)

Firewalls

c)

FTP

d)

APIs

27.

Fill in the blank: IDS/IPS tools are used for _____ monitoring.

a)

Ingress

b)

Egress

c)

Physical

d)

Application

28.

Which of the following is an egress monitoring data type?

a)

Gateways

b)

SIEM solutions

c)

Email (content and attachments)

d)

Anti-malware solutions

29.

Fill in the blank: Applications/application programming interfaces (APIs) are monitored as part of _____ data types.

a)

Egress monitoring

b)

Ingress monitoring

c)

Static analysis

d)

Data encryption

30.

Which type of encryption uses the same key for both encryption and decryption?

a)

Symmetric

b)

Asymmetric

31.

Fill in the blank: Asymmetric encryption uses _____ keys.

a)

different

b)

identical

c)

public-only

d)

shared

32.

Which of the following is a function of a cryptographic hash?

a)

It is easy to compute the hash value for any given message.

b)

It is easy to reverse the hash process.

c)

It is easy to modify a message and produce the same hash value.

d)

It is easy to find two messages that hash to the same value.

33.

Fill in the blank: It is computationally infeasible to reverse the hash process or otherwise derive the original plaintext of a message from its hash value. This property is called ________.

a)

Nonreversible

b)

Deterministic

c)

Commutative

d)

Associative

34.

Content integrity assurance means it is computationally infeasible to modify a message such that re-applying the hash function will produce the original hash value.

a)

True

b)

False

35.

Which property of a cryptographic hash ensures that it is computationally infeasible to find two or more different, sensible messages that hash to the same value?

a)

Useful

b)

Nonreversible

c)

Unique

d)

Deterministic

36.

Fill in the blank: The same input will always generate the same hash, when using the same hashing algorithm. This property is called ________.

a)

Deterministic

b)

Randomness

c)

Volatility

d)

Ambiguity

37.

Which of the following is NOT a configuration management procedure?

a)

A) Identification

b)

B) Baseline

c)

C) Change control

d)

D) Encryption

38.

Which of the following are elements of configuration management?

a)

Version control and change control

b)

Testing and debugging

c)

User interface design and documentation

d)

Marketing and sales

39.

Which of the following is a best practice security policy?

a)

Data handling

b)

Password

c)

Acceptable use

d)

All of the above

40.

Fill in the blank: Appropriate use of personal devices is covered under the ________ policy.

a)

Bring your own device

b)

Acceptable use

c)

Privacy

d)

Remote work

41.

Change management is about the appropriate transition from current state to a future state.

a)

True

b)

False

42.

Which of the following is NOT a data handling policy procedure?

a)

Classify

b)

Categorize

c)

Encrypt

d)

Hash

43.

Fill in the blank: The process of protecting data by converting it into a coded format is called ________.

a)

Encrypt

b)

Compress

c)

Format

d)

Backup

44.

Which of the following are data handling policy procedures?

a)

Data encryption and regular backups

b)

Data visualization and chart making

c)

Data entry and data deletion

d)

Data mining and data analysis

45.

Which of the following is encouraged for password creation?

a)

Short passwords

b)

Longer passphrases

c)

Using the same password everywhere

d)

Writing down your password

46.

Passwords cannot be the same or similar to other passwords used on any other ________, system, application or personal account.

a)

websites

b)

documents

c)

printers

d)

folders

47.

Passwords should not be a single word or a commonly used phrase.

a)

True

b)

False

48.

Which of the following should be avoided when creating passwords?

a)

Names and birthdays of friends and family

b)

Favorite bands

c)

Catchphrases

d)

All of the above

49.

Dictionary words and phrases should be ________ when creating passwords.

a)

avoided

b)

used

c)

preferred

d)

encouraged

50.

Default installation passwords must be changed ________ after installation is complete.

a)

immediately

b)

after one week

c)

after one month

d)

whenever convenient

51.

User passwords must be changed on a schedule established by the ________.

a)

organization

b)

user

c)

software

d)

network

52.

True or False: Previously used passwords may be reused according to best practice security policies.

a)

True

b)

False

53.

System-level passwords must be changed according to a schedule established by ________.

a)

the organization

b)

the government

c)

the software vendor

d)

the user

54.

Passwords must not be shared with anyone, even ________ or supervisors.

a)

IT staff

b)

friends

c)

family members

d)

colleagues

55.

Which of the following is NOT an acceptable use policy (AUP) procedure?

a)

Data access

b)

System access

c)

Passwords

d)

Cooking recipes

56.

Which of the following devices can be included in a bring your own device (BYOD) policy?

a)

Cell phone

b)

Tablet

c)

Laptop

d)

All of the above

57.

Privacy policy protects which of the following?

a)

PII

b)

ePHI

c)

Bank/credit card information

d)

All of the above

58.

GDPR is a privacy regulation in which region?

a)

EU

b)

Asia

c)

South America

d)

Australia

59.

Personal Information Protection and Electronic Documents Act (PIPEDA) is a privacy law in which country?

a)

Canada

b)

United States

c)

Australia

d)

United Kingdom

60.

Change management policy consists of three major activities. Fill in the blank: The first activity is _________.

a)

Deciding to change

b)

Implementing the change

c)

Evaluating the outcome

d)

Communicating the change

61.

Change management policy consists of three major activities. Fill in the blank: The second activity is _________.

a)

Making the change

b)

Identifying the stakeholders

c)

Evaluating the risks

d)

Documenting the process

62.

Change management policy consists of three major activities. Fill in the blank: The third activity is _________

a)

Confirming that the change has been correctly accomplished

b)

Initiating the change request

c)

Documenting the change for future reference

d)

Assigning roles to the change team

63.

Which of the following is a type of security awareness training?

a)

Education

b)

Monitoring

c)

Auditing

d)

Enforcement

64.

Which of the following is a type of security awareness training?

a)

Training

b)

Auditing

c)

Enforcement

d)

Monitoring

65.

Which of the following is a type of security awareness training?

a)

Awareness

b)

Auditing

c)

Enforcement

d)

Monitoring

66.

Which of the following is a social engineering technique?

a)

Baiting

b)

Encryption

c)

Firewalling

d)

Logging

67.

Which of the following is a social engineering technique?

a)

Phone phishing or vishing

b)

Encryption

c)

Firewalling

d)

Logging

68.

Which of the following is a social engineering technique?

a)

Pretexting

b)

Encryption

c)

Firewalling

d)

Logging

69.

Which of the following is a social engineering technique?

a)

Quid pro quo

b)

Encryption

c)

Firewalling

d)

Logging

70.

Which of the following is a social engineering technique?

a)

A) Tailgating

b)

B) Encryption

c)

C) Firewalling

d)

D) Logging

71.

Which of the following is a social engineering technique?

a)

False flag or false front operations

b)

Encryption

c)

Firewalling

d)

Logging