Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Information Security and Cybersecurity Quiz

Total questions: 47

Worksheet time: 31mins

Name
Class
Date
1.

A computer virus consists of segments of code that perform (a)   actions.

2.

Intellectual property is defined as “the creation, ownership, and control of ideas as well as the representation of those ideas.” ______

a)

True

b)

False

3.

The ______ hijacking attack uses IP spoofing to enable an attacker to impersonate another entity on the network.

a)

WWW

b)

TCP

c)

FTP

d)

HTTP

4.

When voltage levels lag (experience a momentary increase), the extra voltage can severely damage or destroy equipment. ______

a)

True

b)

False

5.

In the context of information security, ______ is the process of using social skills to convince people to reveal access credentials or other valuable information to the attacker.

4 lines
6.

Suppose an act of theft performed by a hacker was accompanied by defacement actions to delay discovery. The first act is obviously in the category of “theft” but the second act is another category—in this case it is a “force of nature.”

a)

True

b)

False

7.

Information security’s primary mission is to ensure that systems and their contents retain their confidentiality at any cost.

a)

True

b)

False

8.

The malicious code attack includes the execution of viruses, worms, Trojan horses, and active Web scripts with the intent to destroy or steal information. ______

a)

True

b)

False

9.

Software code known as a(n) cookie can allow an attacker to track a victim's activity on Web sites. ______

a)

True

b)

False

10.

______ occurs when an application running on a Web server inserts commands into a user’s browser session and causes information to be sent to a hostile server.

4 lines
11.

When information gatherers employ techniques that cross a legal or ethical threshold, they are conducting ______.

a)

industrial espionage

b)

competitive intelligence

c)

opposition research

d)

hostile investigation

12.

Cyberterrorists hack systems to conduct terrorist activities via network or Internet pathways. ______

a)

True

b)

False

13.

Web hosting services are usually arranged with an agreement defining minimum service levels known as a(n) ____.

a)

SSL

b)

SLA

c)

MSL

d)

MIN

14.

A(n) (a)   hacks the public telephone network to make free calls or disrupt services.

15.

______ are malware programs that hide their true nature and reveal their designed behavior only when activated.

a)

Viruses

b)

Worms

c)

Spam

d)

Trojan horses

16.

A device (or a software program on a computer) that can monitor data traveling on a network is known as a socket sniffer. ______

a)

True

b)

False

17.

A(n) (a)   is an act against an asset that could result in a loss.

18.

______ are compromised systems that are directed remotely (usually by a transmitted command) by the attacker to participate in an attack.

a)

Drones

b)

Helpers

c)

Zombies

d)

Servants

19.

Much human error or failure can be prevented with effective training and ongoing awareness activities.

a)

True

b)

False

20.

Microsoft acknowledged that if you type a res:// URL (a Microsoft-devised type of URL) longer than ______ characters in Internet Explorer 4.0, the browser will crash.

a)

64

b)

128

c)

256

d)

512

21.

One form of e-mail attack that is also a DoS attack is called a mail spoof, in which an attacker overwhelms the receiver with excessive quantities of e-mail. ______

a)

True

b)

False

22.

Which of the following is an example of a Trojan horse program?

a)

Netsky

b)

MyDoom

c)

Klez

d)

Happy99.exe

23.

A momentary low voltage is called a(n) (a)   .

24.

A number of technical mechanisms—digital watermarks and embedded code, copyright codes, and even the intentional placement of bad sectors on software media—have been used to deter or prevent the theft of software intellectual property.

a)

True

b)

False

25.

Hackers are “persons who access systems and information without authorization and often illegally.” ______

a)

True

b)

False

26.

What is the purpose of the SETA program?

4 lines
27.

Within security perimeters the organization can establish security redundancies, each with differing levels of security, between which traffic must be screened. _____

a)

True

b)

False

28.

The global information security community has universally agreed with the justification for the code of practices as identified in the ISO/IEC 17799.

a)

True

b)

False

29.

(a)   controls are security processes that are designed by strategic planners and implemented by the security administration of the organization.

30.

The security framework is a more detailed version of the security blueprint.

a)

True

b)

False

31.

The ISSP is a plan which sets out the requirements that must be met by the information security blueprint or framework.

a)

True

b)

False

32.

In early 2014, in response to Executive Order 13636, NIST published the Cybersecurity Framework, which intends to allow organizations to _____.

a)

identify and prioritize opportunities for improvement within the context of a continuous and repeatable process

b)

assess progress toward a recommended target state

c)

communicate among local, state, and national agencies about cybersecurity risk

d)

None of these

33.

To remain viable, security policies must have a responsible manager, a schedule of reviews, a method for making recommendations for reviews, and a policy issuance and revision date. _____

a)

True

b)

False

34.

Systems-specific security policies are organizational policies that provide detailed, targeted guidance to instruct all members of the organization in the use of a resource, such as one of its processes or technologies. _____

a)

True

b)

False

35.

A policy should state that if employees violate a company policy or any law using company technologies, the company will protect them, and the company will provide for the employee's legal defense.

a)

True

b)

False

36.

To remain viable, security policies must have a responsible individual, a schedule of reviews, a method for making recommendations for reviews, and policy issuance and planned revision dates.

a)

True

b)

False

37.

_____often function as standards or procedures to be used when configuring or maintaining systems.

a)

ESSPs

b)

EISPs

c)

ISSPs

d)

SysSPs

38.

The goals of information security governance include all but which of the following?

a)

Regulatory compliance by using information security knowledge and infrastructure to support minimum standards of due care

b)

Strategic alignment of information security with business strategy to support organizational objectives

c)

Risk management by executing appropriate measures to manage and mitigate threats to information resources

d)

Performance measurement by measuring, monitoring, and reporting information security governance metrics to ensure that organizational objectives are achieved

39.

(a)   controls are information security safeguards focusing on lower-level planning that deals with the functionality of the organization’s security. These safeguards include disaster recovery and incident response planning.

40.

The process of (a)   planning is that of defining and specifying the long-term direction to be taken by an organization.

41.

NIST 800-14's Principles for Securing Information Technology Systems can be used to make sure the needed key elements of a successful effort are factored into the design of an information security program and to produce a blueprint for an effective security architecture.

a)

True

b)

False

42.

The SETA program is a control measure designed to reduce the instances of _____ security breaches by employees.

a)

intentional

b)

external

c)

accidental

d)

physical

43.

_____ controls cover security processes that are designed by strategic planners and implemented by the security administration of the organization.

a)

Managerial

b)

Technical

c)

Operational

d)

Informational

44.

A security (a)   defines the boundary between the outer limit of an organization’s security and the beginning of the outside world.

45.

The stated purpose of ISO/IEC 27002 is to offer guidelines and voluntary directions for information security management. _____

a)

True

b)

False

46.

Technical controls are the tactical and technical implementations of security in the organization. _____

a)

True

b)

False

47.

The key components of the security perimeter include firewalls, DMZs (demilitarized zones), Web servers, and IDPSs. _____

a)

True

b)

False