NEW
Font size
WorksheetsFortress IQ: The ISMS Quest
Total questions: 25
Worksheet time: 13mins
Which objective of the ISMS Policy focuses specifically on the encryption of sensitive data?
Improve Employee Awareness
Enhance Data Protection Measures
Strengthen Access Control
Improve Incident Response Time
What is the primary goal of an Information Security Management System (ISMS)?
Increase sales
Protect information assets
Improve marketing
Replace all software annually
Which three core principles does information security aim to protect?
Accountability, Accuracy, Affordability
Confidentiality, Integrity, Availability
Risk, Return, Resilience
Planning, Execution, Monitoring
Which of the following is NOT an acceptable practice as per the password policy of Tribastion?
Using a password that includes a family member’s name
Setting a password with a mix of upper and lower case letters
Configuring systems to store passwords in encrypted form
Using multi-factor authentication for privileged accounts
Which group is responsible for reporting brute-force attacks or credential compromises?
Human Resources
Cyber Intelligence and Defence Centre
Finance Department
Legal and Compliance Team
What happens after five consecutive failed login attempts on Tribastion systems, unless exceptions apply?
The user is prompted to reset the password
The account is permanently locked
The account is temporarily locked
A warning email is sent to IT
Select the option that best represents a strong password, based on what you learned:
Abc123
P@ssw0rd
Summer2024
W!nT3r#42Z
Which of the following best describes the primary goal of a Clear Desk Policy?
To make workspaces look tidy for management visits
To reduce electricity costs
To prevent unauthorized access to sensitive information
To ensure documents are available for quick access
Which of the following violates the Clear Desk Policy?
Shredding confidential documents before disposal
Locking printed reports in your drawer
Leaving printouts face-down on your desk overnight
Using a screen privacy filter
What is the most appropriate way to dispose of a document that contains sensitive information?
Tear it in half and throw it in the bin
Recycle it
Shred it using a cross-cut shredder
Save it in a folder for future use
Which of the following is required after meetings that involve sensitive information?
Take a group photo for documentation
Leave notes on the whiteboard for the next meeting
Erase whiteboards and remove sticky notes or notebooks
Email the notes to yourself
Which classification level requires mandatory labeling and regular backup, but only allows sharing on a need-to-know basis?
Public
Internal Use Only
Confidential
None
According to the data handling requirements, which combination is correct for data classified as “Restricted”?
Access: Authorized staff, Encryption: Required, Labelling: Mandatory, Sharing: Internal only
Access: Strictly limited access, Encryption: Not required, Backup: Optional, Sharing: Freely allowed
Access: Named individuals, Encryption: Required, Labelling: Optional, Backup: Regular
Access: Strictly limited access, Encryption: Required, Labelling: Mandatory, Sharing: Highly controlled
Which of the following actions is strictly prohibited on Tribastion-managed devices unless explicitly authorized?
Accessing work email
Posting content on LinkedIn about Tribastion’s success
Installing and using unauthorized and non-secure messaging platforms
Viewing internal HR policies
Which statement about employees’ use of social media in relation to Tribastion is TRUE?
Employees can use and share Tribastion's logo wherever they want
You should engage with and address any inappropriate or misleading content related to Tribastion found on social media platforms.
Posting photos, videos, audio, or written content related to Tribastion premises, property, equipment, internal events, employees, customers, or vendors is prohibited unless they are pre-approved and aligned with TRIBASTION HR Handbook.
Employees can register personal social media accounts using their Tribastion email if they mark them private.
Which of the following is a direct violation of Tribastion Technologies’ Acceptable Use Policy?
Locking your computer screen when leaving your desk
Using an officially approved VPN to access company systems remotely
Sharing company data through personal email without approval
Reporting a suspicious email to the IT team
Which statement accurately reflects Tribastion Technologies’ IT security and access control policies?
Employees may access classified data on personal USB drives if encrypted.
Social media apps are allowed on company devices if not used during work hours.
Employees must not access IT systems using other employees’ credentials under any circumstances.
Public Wi-Fi is permitted for remote work without a VPN, as long as sensitive data is not accessed.
What action is allowed under Tribastion’s Email Usage Policy?
Sharing internal mailing lists with external vendors
Sending personal emails using a Tribastion email address
Encrypting sensitive company data before emailing
Opening unknown email attachments if received internally
Which of the following email activities would not violate Tribastion Technologies’ email policy?
Sending a .exe file to a colleague as part of a troubleshooting discussion
Logging in to Tribastion email from a shared public internet café terminal and saving credentials
Including the official Tribastion disclaimer in an email that contains unprofessional language
Reporting a suspicious email with a malicious attachment to the IT Team immediately
What is the maximum allowed time before access must be revoked for a user after they leave the organization or change roles?
Within 1 hour
Immediately
Within 24 hours
Within 30 minutes
Which of the following is a violation of Tribastion’s access control mechanisms policy?
Using role-based access control to grant permissions
Allowing users to select alternate routes bypassing firewalls to connect to services
Disabling user accounts inactive for more than 60 days
Reviewing access control matrices quarterly
Which data classification level requires encryption both during transmission and at rest?
Internal Use Only
Public
Confidential and Restricted
Restricted only
Which of the following activities is a direct violation of Tribastion's DLP policy?
Using screen capture tools for internal documentation
Sharing Confidential data via a personal cloud account without approval
Monitoring data-in-rest using DLP controls
Conducting regular training on data classification
Which of the following is a mandatory security requirement for all remote access connections to Tribastion’s infrastructure?
Using freeware tools for support without approval
Multi-factor authentication using Secure Token
Connecting via personal hotspot only
Disabling antivirus before connecting remotely
Under which of the following circumstances must remote access be de-provisioned according to Tribastion’s policy?
When the user travels internationally
When antivirus definitions are outdated
When a temporary access period ends and no renewal is submitted
When the user accesses Microsoft SharePoint online
