wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Fortress IQ: The ISMS Quest

Total questions: 25

Worksheet time: 13mins

Name
Class
Date
1.

Which objective of the ISMS Policy focuses specifically on the encryption of sensitive data?

a)

Improve Employee Awareness

b)

Enhance Data Protection Measures

c)

Strengthen Access Control

d)

Improve Incident Response Time

2.

What is the primary goal of an Information Security Management System (ISMS)?

a)

Increase sales

b)

Protect information assets

c)

Improve marketing

d)

Replace all software annually

3.

Which three core principles does information security aim to protect?

a)

Accountability, Accuracy, Affordability

b)

Confidentiality, Integrity, Availability

c)

Risk, Return, Resilience

d)

Planning, Execution, Monitoring

4.

Which of the following is NOT an acceptable practice as per the password policy of Tribastion?

a)

Using a password that includes a family member’s name

b)

Setting a password with a mix of upper and lower case letters

c)

Configuring systems to store passwords in encrypted form

d)

Using multi-factor authentication for privileged accounts

5.

Which group is responsible for reporting brute-force attacks or credential compromises?

a)

Human Resources

b)

Cyber Intelligence and Defence Centre

c)

Finance Department

d)

Legal and Compliance Team

6.

What happens after five consecutive failed login attempts on Tribastion systems, unless exceptions apply?

a)

The user is prompted to reset the password

b)

The account is permanently locked

c)

The account is temporarily locked

d)

A warning email is sent to IT

7.

Select the option that best represents a strong password, based on what you learned:

a)

Abc123

b)

P@ssw0rd

c)

Summer2024

d)

W!nT3r#42Z

8.

Which of the following best describes the primary goal of a Clear Desk Policy?

a)

To make workspaces look tidy for management visits

b)

To reduce electricity costs

c)

To prevent unauthorized access to sensitive information

d)

To ensure documents are available for quick access

9.

Which of the following violates the Clear Desk Policy?

a)

Shredding confidential documents before disposal

b)

Locking printed reports in your drawer

c)

Leaving printouts face-down on your desk overnight

d)

Using a screen privacy filter

10.

What is the most appropriate way to dispose of a document that contains sensitive information?

a)

Tear it in half and throw it in the bin

b)

Recycle it

c)

Shred it using a cross-cut shredder

d)

Save it in a folder for future use

11.

Which of the following is required after meetings that involve sensitive information?

a)

Take a group photo for documentation

b)

Leave notes on the whiteboard for the next meeting

c)

Erase whiteboards and remove sticky notes or notebooks

d)

Email the notes to yourself

12.

Which classification level requires mandatory labeling and regular backup, but only allows sharing on a need-to-know basis?

a)

Public

b)

Internal Use Only

c)

Confidential

d)

None

13.

According to the data handling requirements, which combination is correct for data classified as “Restricted”?

a)

Access: Authorized staff, Encryption: Required, Labelling: Mandatory, Sharing: Internal only

b)

Access: Strictly limited access, Encryption: Not required, Backup: Optional, Sharing: Freely allowed

c)

Access: Named individuals, Encryption: Required, Labelling: Optional, Backup: Regular

d)

Access: Strictly limited access, Encryption: Required, Labelling: Mandatory, Sharing: Highly controlled

14.

Which of the following actions is strictly prohibited on Tribastion-managed devices unless explicitly authorized?

a)

Accessing work email

b)

Posting content on LinkedIn about Tribastion’s success

c)

Installing and using unauthorized and non-secure messaging platforms

d)

Viewing internal HR policies

15.

Which statement about employees’ use of social media in relation to Tribastion is TRUE?

a)

Employees can use and share Tribastion's logo wherever they want

b)

You should engage with and address any inappropriate or misleading content related to Tribastion found on social media platforms.

c)

Posting photos, videos, audio, or written content related to Tribastion premises, property, equipment, internal events, employees, customers, or vendors is prohibited unless they are pre-approved and aligned with TRIBASTION HR Handbook.

d)

Employees can register personal social media accounts using their Tribastion email if they mark them private.

16.

Which of the following is a direct violation of Tribastion Technologies’ Acceptable Use Policy?

a)

Locking your computer screen when leaving your desk

b)

Using an officially approved VPN to access company systems remotely

c)

Sharing company data through personal email without approval

d)

Reporting a suspicious email to the IT team

17.

Which statement accurately reflects Tribastion Technologies’ IT security and access control policies?

a)

Employees may access classified data on personal USB drives if encrypted.

b)

Social media apps are allowed on company devices if not used during work hours.

c)

Employees must not access IT systems using other employees’ credentials under any circumstances.

d)

Public Wi-Fi is permitted for remote work without a VPN, as long as sensitive data is not accessed.

18.

What action is allowed under Tribastion’s Email Usage Policy?

a)

Sharing internal mailing lists with external vendors

b)

Sending personal emails using a Tribastion email address

c)

Encrypting sensitive company data before emailing

d)

Opening unknown email attachments if received internally

19.

Which of the following email activities would not violate Tribastion Technologies’ email policy?

a)

Sending a .exe file to a colleague as part of a troubleshooting discussion

b)

Logging in to Tribastion email from a shared public internet café terminal and saving credentials

c)

Including the official Tribastion disclaimer in an email that contains unprofessional language

d)

Reporting a suspicious email with a malicious attachment to the IT Team immediately

20.

What is the maximum allowed time before access must be revoked for a user after they leave the organization or change roles?

a)

Within 1 hour

b)

Immediately

c)

Within 24 hours

d)

Within 30 minutes

21.

Which of the following is a violation of Tribastion’s access control mechanisms policy?

a)

Using role-based access control to grant permissions

b)

Allowing users to select alternate routes bypassing firewalls to connect to services

c)

Disabling user accounts inactive for more than 60 days

d)

Reviewing access control matrices quarterly

22.

Which data classification level requires encryption both during transmission and at rest?

a)

Internal Use Only

b)

Public

c)

Confidential and Restricted

d)

Restricted only

23.

Which of the following activities is a direct violation of Tribastion's DLP policy?

a)

Using screen capture tools for internal documentation

b)

Sharing Confidential data via a personal cloud account without approval

c)

Monitoring data-in-rest using DLP controls

d)

Conducting regular training on data classification

24.

Which of the following is a mandatory security requirement for all remote access connections to Tribastion’s infrastructure?

a)

Using freeware tools for support without approval

b)

Multi-factor authentication using Secure Token

c)

Connecting via personal hotspot only

d)

Disabling antivirus before connecting remotely

25.

Under which of the following circumstances must remote access be de-provisioned according to Tribastion’s policy?

a)

When the user travels internationally

b)

When antivirus definitions are outdated

c)

When a temporary access period ends and no renewal is submitted

d)

When the user accesses Microsoft SharePoint online