wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

sayberases

Total questions: 100

Worksheet time: 50hrs 31mins

Name
Class
Date
1.

Steve is a security practitioner assigned to come up with a protective measure for ensuring that cars don't collide with pedestrians. What is probably the most effective type of control for this task?

a)

Technical

b)

Physical

c)

Nuanced

d)

Administrative

2.

Chad is a security practitioner tasked with ensuring that the information on the organization's public website is not changed by anyone outside the organization. Which concept does this task demonstrate?

a)

Availability

b)

Integrity

c)

Confirmation

d)

Confidentiality

3.

Which of the following is an example of a 'Something you know' authentication factor?

a)

User ID

b)

Fingerprint

c)

Iris scan

d)

Password

4.

Which of the following is an example of a 'Something you are' authentication factor?

a)

A photograph of your face

b)

A credit card presented to a cash machine

c)

Your password and PIN

d)

A user ID

5.

A system collects transactional information and stores it in a record in order to show which users performed which actions. Which concept does this demonstrate?

a)

Privacy

b)

Multifactor authentication

c)

Biometrics

d)

Non-repudiation

6.

What is the European Union (EU) law that grants legal protections to individual human privacy?

a)

The Schengen Agreement

b)

The Maastricht Treaty (the Treaty on European Union)

c)

The Privacy Human Rights Act

d)

The General Data Protection Regulation

7.

For which of the following systems would the security concept of availability be considered MOST important?

a)

Retail records of past transactions

b)

Medical systems that store patient data

c)

Online streaming of camera feeds that display historical works of art in museums around the world

d)

Medical systems that monitor patient conditions in an intensive-care unit

8.

For which of the following assets is integrity probably the MOST important security aspect?

a)

Software that checks the spelling of product descriptions for a retail website

b)

The file that contains passwords used to authenticate users

c)

One frame of a streaming video

d)

The color scheme of a marketing website

9.

In risk management, which concept reflects something a security practitioner might need to protect?

a)

Vulnerability

b)

Likelihood

c)

Asset

d)

Threat

10.

In risk management concepts, what is something or someone that poses risk to an organization or asset?

a)

Threat

b)

Fear

c)

Asset

d)

Control

11.

Of the following, which would probably NOT be considered a threat?

a)

A laptop with sensitive data on it

b)

An external attacker trying to gain unauthorized access to the environment

c)

Unintentional damage to the system caused by a user

d)

Natural disaster

12.

Which of the following probably poses the MOST risk?

a)

A low-likelihood, high-impact event

b)

A high-likelihood, low-impact event

c)

A low-likelihood, low-impact event

d)

A high-likelihood, high-impact event

13.

Within the organization, who can identify risk?

a)

Anyone

b)

Any security team member

c)

Senior management

d)

The security manager

14.

Kerpak works in the security office of a medium-sized entertainment company. Kerpak is asked to assess a particular threat, and he suggests that the best way to counter this threat would be to purchase and implement a particular security solution. What concept does Kerpak's solution demonstrate?

a)

Transference

b)

Avoidance

c)

Mitigation

d)

Acceptance

15.

Fill in the missing word: Sophia is visiting Las Vegas and decides to put a bet on a particular number on a roulette wheel. This is an example of _________.

a)
Transference
b)

Acceptance

c)

Mitigation

d)

Avoidance

16.

Phrenal is selling a used laptop in an online auction. Phrenal has estimated the value of the laptop to be $100, but has seen other laptops of similar type and quality sell for both more and less than that amount. Phrenal hopes that the laptop will sell for $100 or more, but is prepared to take less for it if nobody bids that amount. What concept does this demonstrate?

a)

Threat

b)

Risk inversion

c)

Risk tolerance

d)

Vulnerability

17.

A software firewall is an application that runs on a device and prevents specific types of traffic from entering that device. Which type of control is this?

a)

Passive

b)

Technical

c)

Administrative

d)

Physical

18.

At the airport, there are red lines painted on the ground next to the runway, which prohibits traffic from crossing it. Which type of control does this exemplify?

a)

Physical

b)

Administrative

c)

Critical

d)

Technical

19.

A bollard is a post set securely in the ground in order to prevent a vehicle from entering an area or driving past a certain point. Bollards are an example of which type of control?

a)

Technical

b)

Administrative

c)

Critical

d)

Physical

20.

Druna is a security practitioner tasked with ensuring that laptops are not stolen from the organization's offices. Which kind of security control would probably be BEST for this purpose?

a)

Physical

b)

Obverse

c)

Technical

d)

Administrative

21.

Triffid Corporation has a policy that all employees must receive security awareness instruction before using email; the company wants to make employees aware of potential phishing attempts that the employees might receive via email. What kind of control is this instruction?

a)

Physical

b)

Technical

c)

Administrative

d)

Finite

22.

ISC2 publishes a Common Body of Knowledge (CBK) that IT security practitioners should be familiar with; this is recognized throughout the industry as a valuable resource for practitioners. Certifications can be issued for demonstrating expertise in this Common Body of Knowledge. What kind of document is the Common Body of Knowledge?

a)

Procedure

b)

Standard

c)

Law

d)

Policy

23.

The city of San Jose wants to ensure that all of its citizens are protected from malware, so the city council creates a rule that anyone caught creating and launching malware within the city limits will receive a fine and go to jail. What kind of rule is this?

a)

Law

b)

Policy

c)

Standard

d)

Procedure

24.

The Triffid Corporation publishes a strategic overview of the company's intent to secure all the data the company possesses. This document is signed by Triffid's senior management. What kind of document is this?

a)

Policy

b)

Standard

c)

Law

d)

Procedure

25.

San Jose municipal code requires that all companies operating within city limits have a set of processes to ensure that employees are safe while working with hazardous materials. Triffid Corporation creates a checklist of activities that employees must follow while working with hazardous materials inside San Jose city limits. The municipal code is a ______, and the Triffid checklist is a ________.

a)

Standard, law

b)

Law, standard

c)

Policy, law

d)

Law, procedure

26.

The Payment Card Industry (PCI) Council is a committee made up of representatives from major credit card providers (Visa, Mastercard, American Express) in the United States. The PCI Council issues rules that merchants must follow if the merchants choose to accept payment via credit card. These rules describe best practices for securing credit card processing technology, activities for securing credit card information, and how to protect personal data of customers. Which of the following describes this set of rules?

a)

Policy

b)

Standard

c)

Law

d)

Procedure

27.

Hoshi is an ISC2 member who works for the Triffid Corporation as a data manager. Triffid needs a new firewall solution, and Hoshi is asked to recommend a product for Triffid to acquire and implement. Hoshi's cousin works for a firewall vendor; that vendor happens to make the best firewall available. What should Hoshi do?

a)

Recommend a different vendor/product

b)

Recommend the cousin's product

c)

Disclose the relationship, but recommend the vendor/product

d)

Hoshi should ask to be recused from the task

28.

Olaf is a member of ISC2 and a security analyst for Triffid Corporation. During an audit, Olaf is asked whether Triffid is currently following a particular security practice. Olaf knows that Triffid is not adhering to that standard in that particular situation, but that saying this to the auditors will reflect poorly on Triffid. What should Olaf do?

a)

Lie to the auditors

b)

Ask supervisors for guidance

c)

Ask ISC2 for guidance

d)

Tell the auditors the truth

29.

Aphrodite is a member of ISC2 and a data analyst for Triffid Corporation. While Aphrodite is reviewing user log data, Aphrodite discovers that another Triffid employee is violating the acceptable use policy and watching streaming videos during work hours. What should Aphrodite do?

a)

Inform Triffid management

b)

Nothing

c)

Inform law enforcement

d)

Inform ISC2

30.

You are reviewing log data from a router; there is an entry showing that a user sent traffic through the router at 11:45 a.m., local time, yesterday. Which of the following does this exemplify?

a)

Event

b)

Incident

c)

Attack

d)

Threat

31.

An attacker outside the organization attempts to gain access to the organization’s internal files. Which of the following does this scenario exemplify?

a)

Publication

b)

Intrusion

c)

Disclosure

d)

Exploit

32.

Who approves the incident response policy?

a)

The investors

b)

ISC2

c)

senior management

d)

The security manager

33.

Which of the following are NOT typically involved in incident detection?

a)

Users

b)

Security Analysis

c)

Automated Tools

d)

Regulators

34.

What is the goal of Business Continuity efforts?

a)

Keep critical business functions operational

b)

Impress customers

c)

Save money

d)

Ensure all IT systems continue to operate

35.

Which of the following is likely to be included in the business continuity plan?

a)

Alternate work areas for personnel affected by a natural disaster

b)

The organization’s strategic security approach

c)

Log data from all systems

d)

Last year’s budget information

36.

What is the MOST important goal of a business continuity effort?

a)

Preserve health and human safety

b)

Ensure all business activities are preserved during a potential disaster

c)

Ensure the organization survives a disaster

d)

Ensure all IT systems function during a potential interruption

37.

What is the overall objective of a disaster recovery (DR) effort?

a)

Enhance public perception of the organization

b)

Return to normal, full operations

c)

Save money

d)

Preserve critical business functions during a disaster

38.

What is the risk associated with resuming full normal operations too soon after a DR effort?

a)

The danger posed by the disaster might still be present

b)

The organization could save money

c)

Regulators might disapprove

d)

Investors might be upset

39.

What is the risk associated with delaying resumption of full normal operations after a disaster?

a)

People might be put in danger

b)

The impact of running alternate operations for extended periods

c)

Competition

d)

A new disaster might emerge

40.

Gelbi is a Technical Support analyst for Triffid, Inc. Gelbi sometimes is required to install or remove software.

Which of the following could be used to describe Gelbi's account?

a)

Internal

b)

External

c)

Privileged

d)

User

41.

Guillermo logs on to a system and opens a document file. Guillermo is an example of what?

a)

The subject

b)

The object

c)

The software

d)

The process

42.

Which of the following is NOT an appropriate control to add to privileged accounts?

a)

Multi-factor authentication

b)

Security deposit

c)

Increased logging

d)

Increased auditing

43.

Prachi works as a database administrator for Triffid, Inc. Prachi is allowed to add or delete users, but is not allowed to read or modify the data in the database itself. When Prachi logs on to the system, an access control list (ACL) checks to determine which permissions he has.

In this situation, what is the ACL?

a)

The rule

b)

The firmware

c)

The subject

d)

The object

44.

Prachi works as a database administrator for Triffid, Inc. Prachi is allowed to add or delete users, but is not allowed to read or modify the data in the database itself. When Prachi logs on to the system, an access control list (ACL) checks to determine which permissions he has.

In this situation, Prachi represents what?

a)

The rule

b)

The subject

c)

The object

d)

The file

45.

Larry and Fern both work in the data center. In order to enter the data center to begin their workday, they must both present their own keys (which are different) to the key reader, before the door to the data center opens.

Which security concept is being applied in this situation?

a)

Dual control

b)

Segregation of duties

c)

Defense in depth

d)

Least privilege

46.

Which of the following is a biometric access control mechanism?

a)

A fence with razor tape on it

b)

A badge reader

c)

A door locked by a voiceprint identifier

d)

A copper key

47.

Which of the following is the BEST recommendation for all individuals visiting a secure facility?

a)

Require visitors to wear protective gear

b)

Escort visitors

c)

Fingerprint visitors

d)

Photograph visitors

48.

All of the following are typically perceived as drawbacks to biometric systems, except:

a)

Potential privacy concerns

b)

Lack of accuracy

c)

Legality

d)

Retention of physiological data past the point of employment

49.

A human guard monitoring a hidden camera could be considered which type of control?

a)

Logical

b)

Preventive

c)

Deterrent

d)

Detective

50.

Which of the following is a record of something that has occurred?

a)

Log

b)

Biometric

c)

Firewall

d)

Law

51.

Mila works for a government agency. All data in the agency is assigned a particular sensitivity level, called a classification. Every person in the agency is assigned a clearance level, which determines the classification of data each person can access and is controlled at the system level.

What is the access control model being implemented in Mila's agency?

a)

RBAC (role-based access control)

b)

DAC (discretionary access control)

c)

MAC (mandatory access control)

d)

FAC (formal access control)

52.

Which of the following would be considered a logical access control?

a)

A fingerprint reader that allows an employee to enter a controlled area

b)

A chain attached to a laptop computer that connects it to furniture so it cannot be taken

c)

A fingerprint reader that allows an employee to access a laptop computer

d)

An iris reader that allows an employee to enter a controlled area

53.

Trina and Doug both work at Triffid, Inc. Doug is having trouble logging in to the network. Trina offers to log in for Doug, using her credentials, so that Doug can get some work done.

What is the problem with this?

a)

It is against the law

b)

Anything either of them do will be attributed to Trina

c)

Doug is a bad person

d)

If Trina logs in for Doug, then Doug will never be encouraged to remember credentials without assistance

54.

Gary is unable to log in to the production environment. Gary tries three times and is then locked out of trying again for one hour. Why could this be?

a)

Gary's actions look like an attack

b)

The network is tired

c)

Users remember their credentials if they are given time to think about it

d)

Gary is being punished

55.

Suvid works at Triffid, Inc. When Suvid attempts to log in to the production environment, a message appears stating that he has to reset his password. What may have occurred to cause this?

a)

Suvid's password has expired

b)

Suvid made the manager angry

c)

Suvid broke the law

d)

Someone hacked Suvid's machine

56.

Prina is a database manager. Prina is allowed to add new users to the database, remove current users, and create new usage functions for the users. Prina is not allowed to read the data in the fields of the database itself. This is an example of what?

a)

Role-based access controls (RBAC)

b)

Alleviating threat access controls (ATAC)

c)

Discretionary access controls (DAC)

d)

Mandatory access controls (MAC)

57.

Handel is a senior manager at Triffid, Inc., and is in charge of implementing a new access control scheme for the company. Handel wants to ensure that operational managers have the utmost personal choice in determining which employees get access to which systems/data. Which method should Handel select?

a)

Discretionary access controls (DAC)

b)

Role-based access controls (RBAC)

c)

Security policy

d)

Mandatory access controls (MAC)

58.

Handel is a senior manager at Triffid, Inc., and is in charge of implementing a new access control scheme for the company. Handel wants to ensure that employees transferring from one department to another, getting promoted, or cross-training to new positions can get access to the different assets they'll need for their new positions, in the most efficient manner. Which method should Handel select?

a)

Discretionary access controls (DAC)

b)

Barbed wire

c)

Mandatory access controls (MAC)

d)

Role-based access controls (RBAC)

59.

Handel is a senior manager at Triffid, Inc., and is in charge of implementing a new access control scheme for the company. Handel wants to ensure that employees who are assigned to new positions in the company do not retain whatever access they had in their old positions. Which method should Handel select?

a)

Mandatory access controls (MAC)

b)

Role-based access controls (RBAC)

c)

Logging

d)

Discretionary access controls (DAC)

60.

Which term refers to the logical address of a device connected to the network or internet?

a)

Media access control (MAC) address

b)

Internet Protocol (IP) address

c)

Geophysical address

d)

Terminal address

61.

What type of device filters network traffic in order to enhance overall security/performance?

a)

Firewall

b)

MAC (Media Access Control)

c)

Laptop

d)

Endpoint

62.

What protocol should Barry use when he wants to upload a series of files to a web-based storage service?

a)

SMTP (Simple Mail Transfer Protocol)

b)

SNMP (Simple Network Management Protocol)

c)

SFTP (Secure File Transfer Protocol)

d)

FTP (File Transfer Protocol)

63.

A type of device typically accessed by multiple users and often intended for a single purpose, such as managing email or web pages, is referred to as what?

a)

Switch

b)

Laptop

c)

Server

d)

Router

64.

Carol is browsing the Web. Which of the following ports is she probably using?

a)

999

b)

12

c)

80

d)

247

65.

Cyril wants to ensure all the devices on his company's internal IT environment are properly synchronized. Which of the following protocols would aid in this effort?

a)

NTP (Network Time Protocol)

b)

HTTP (Hypertext Transfer Protocol)

c)

FTP

d)

SMTP (Simple Mail Transfer Protocol)

66.

Ludwig is a security analyst at Triffid, Inc. Ludwig notices network traffic that might indicate an attack designed to affect the availability of the environment. Which of the following might be the attack Ludwig sees?

a)

DDOS (distributed denial of service)

b)

Exfiltrating stolen data

c)

Spoofing

d)

An insider sabotaging the power supply

67.

Gary is an attacker. Gary is able to get access to the communication wire between Dauphine's machine and Linda's machine and can then surveil the traffic between the two when they're communicating. What kind of attack is this?

a)

DDOS

b)

Physical

c)

Side channel

d)

On-path

68.

Bert wants to add a flashlight capability to a smartphone. Bert searches the internet for a free flashlight app, and downloads it to the phone. The app allows Bert to use the phone as a flashlight, but also steals Bert's contacts list. What kind of app is this?

a)

Trojan

b)

DDOS

c)

On-path

d)

Side channel

69.

Triffid, Inc., has many remote workers who use their own IT devices to process Triffid's information. The Triffid security team wants to deploy some sort of sensor on user devices in order to recognize and identify potential security issues. Which of the following is probably most appropriate for this specific purpose?

a)

NIDS (network-based intrusion-detection systems)

b)

LIDS (logistical intrusion-detection systems)

c)

Firewalls

d)

HIDS (host-based intrusion-detection systems)

70.

Inbound traffic from an external source seems to indicate much higher rates of communication than normal, to the point where the internal systems might be overwhelmed. Which security solution can often identify and potentially counter this risk?

a)

Firewall

b)

Badge system

c)

Anti-malware

d)

Turnstile

71.

What tool aggregates log data from multiple sources, typically analyzes it, and reports potential threats?

a)

SIEM

b)

HIDS

c)

Anti-malware

d)

Router

72.

What type of solution typically inspects outbound communications traffic to check for unauthorized exfiltration of sensitive

4 lines
73.

What type of solution typically inspects outbound communications traffic to check for unauthorized exfiltration of sensitive/valuable information?

a)

NIDS (network-based intrusion-detection systems)

b)

Anti-malware

c)

Firewall

d)

DLP (data loss prevention)

74.

What type of tool is used to monitor local devices with the aim of reducing potential threats from hostile software?

a)

Firewall

b)

DLP (data loss prevention)

c)

Anti-malware

d)

NIDS (network-based intrusion-detection systems)

75.

Which activity is usually part of the configuration management process, but is also extremely helpful in countering potential attacks?

a)

Conferences with senior leadership

b)

Updating and patching systems

c)

Annual budgeting

d)

The annual shareholders' meeting

76.

Which type of fire-suppression system is typically the SAFEST for humans?

a)

Gaseous

b)

Water

c)

Oxygen-depletion

d)

Dirt

77.

Which common cloud service model offers the customer the MOST control of the cloud environment?

a)

Infrastructure as a service (IaaS)

b)

Function as a Service (FaaS)

c)

Software as a service (SaaS)

d)

Platform as a service (PaaS)

78.

What is the section of the IT environment that is closest to the external world; where we locate IT systems that communicate with the Internet?

a)

VLAN

b)

DMZ

c)

RBAC

d)

MAC

79.

An IoT (Internet of Things) device is typically characterized by its effect on or use of which environment?

a)

Physical

b)

Remote

c)

Development

d)

Internal

80.

What type of device is commonly advisable to have on the perimeter between two networks?

a)

Camera

b)

User laptop

c)

Firewall

d)

IoT

81.

Which of the following describes when archiving is typically done?

a)

When data has lost all value

b)

When data is ready to be destroyed

c)

When data is not needed for regular work purposes

d)

When data has become illegal

82.

Which concept does this demonstrate? Every document owned by Triffid, Inc., whether hardcopy or electronic, has a clear, 24-point word at the top and bottom. Only three words can be used: 'Sensitive', 'Proprietary', and 'Public'.

a)

Inverting

b)

Labeling

c)

Secrecy

d)

Privacy

83.

To what data does security need to be provided?

a)

All of the answers

b)

Restricted

c)

Private

d)

Illegal

84.

Data retention periods apply to which kind of data?

a)

All of the answers

b)

Sensitive

c)

Medical

d)

Secret

85.

What should be done when data has reached the end of the retention period?

a)

It should be archived

b)

It should be destroyed

c)

It should be enhanced

d)

It should be sold

86.

Which of the following describes data that is left behind on systems/media after normal deletion procedures have been attempted?

a)

Residue

b)

Remanence

c)

Packets

d)

Fragments

87.

Where should log data be kept?

a)

On a device other than where it was captured

b)

In airtight containers

c)

In an underground bunker

d)

On the device that the log data was captured from

88.

What should security controls on log data reflect?

a)

The sensitivity of the source device

b)

The price of the storage device

c)

The local culture where the log data is stored

d)

The organization's commitment to customer service

89.

How often should logs be reviewed?

a)

Every Thursday

b)

Continually

c)

Once per calendar year

d)

Once per fiscal year

90.

Dieter wants to send a message to Lupa and wants to be sure that Lupa knows the message has not been modified in transit. Which technique/tool could Dieter use to assist in this effort?

a)

Antivirus software

b)

Hashing

c)

Symmetric encryption

d)

Asymmetric encryption

91.

Triffid, Inc., wants to host streaming video files for the company's remote users, but wants to ensure that the data is protected while it's streaming. Which method is probably BEST for this purpose?

a)

Asymmetric encryption

b)

Symmetric encryption

c)

VLANs

d)

Hashing

92.

Which of the following is used to ensure that configuration management activities are effective and enforced?

a)

Baseline

b)

Identification

c)

Inventory

d)

Verification and audit

93.

What must an organization always be prepared to do when applying a patch?

a)

Pay for the updated content

b)

Rollback

c)

Settle lawsuits

d)

Buy a new system

94.

Why is the proper alignment of security policy and business goals within the organization important?

a)

Bad security policy can be illegal

b)

Security should always be as strict as possible

c)

Security policy that conflicts with business goals can inhibit productivity

d)

Security is more important than business

95.

An organization should keep on file a copy of every signed Acceptable Use Policy (AUP). To whom should a copy be issued?

a)

Lawmakers

b)

The user who signed it

c)

The Public Relations office

d)

The regulators overseeing that industry

96.

What is the MOST crucial element of any security instruction program?

a)

Ensure availability of IT systems

b)

Preserve health and human safety

c)

Preserve shareholder value

d)

Protect assets

97.

Which one of the following is a benefit of computer-based training (CBT)?

a)

Interacting with other participants

b)

Expensive

c)

Personal interaction with instructor

d)

Scalable

98.

Which of the following describes the output of a hashing algorithm?

a)

It's the same characters

b)

It's the same length

c)

It's different when the same input is used

d)

It's the same language

99.

Hashing is often used to provide what?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Value

100.

If two people want to use asymmetric communication to conduct a confidential conversation, how many keys do they need?

a)

1

b)

8

c)

4

d)

11