Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Sec+ 701 Final Review Quiz

Total questions: 50

Worksheet time: 25mins

Name
Class
Date
1.

Which protocol is commonly used to securely transfer files over a network?

a)

FTP

b)

SFTP

c)

Telnet

d)

SMTP

2.

What does the acronym CIA stand for in information security?

a)

Confidentiality, Integrity, Availability

b)

Control, Inspection, Authorization

c)

Confidentiality, Inspection, Access

d)

Control, Integrity, Authentication

3.

Which of the following is an example of a physical security control?

a)

Firewall

b)

Security badge

c)

Antivirus software

d)

Encryption

4.

Which access control model is based on predefined roles within an organization?

a)

Discretionary Access Control (DAC)

b)

Mandatory Access Control (MAC)

c)

Role-Based Access Control (RBAC)

d)

Rule-Based Access Control

5.

What is the primary purpose of a risk assessment in the risk management framework?

a)

To eliminate all risks

b)

To identify and evaluate potential threats and vulnerabilities

c)

To create user accounts

d)

To install security patches

6.

Which cryptographic algorithm is classified as symmetric?

a)

RSA

b)

AES

c)

ECC

d)

DSA

7.

Which document outlines the acceptable use of organizational resources by employees?

a)

Incident Response Plan

b)

Acceptable Use Policy

c)

Disaster Recovery Plan

d)

Business Continuity Plan

8.

Which of the following best describes the first step in the incident response process?

a)

Containment

b)

Eradication

c)

Identification

d)

Recovery

9.

A company wants to ensure that only authorized users can access sensitive data. Which access control model should they implement to assign permissions based on job functions?

a)

Discretionary Access Control (DAC)

b)

Role-Based Access Control (RBAC)

c)

Mandatory Access Control (MAC)

d)

Attribute-Based Access Control (ABAC)

10.

You are tasked with configuring a firewall to block all incoming traffic except for web services. Which ports should you allow?

a)

21 and 22

b)

80 and 443

c)

25 and 110

d)

53 and 8080

11.

An organization is developing a new security policy. Which step should be taken to ensure the policy is effective and enforceable?

a)

Distribute the policy without review

b)

Involve stakeholders in the policy development process

c)

Only consult IT staff

d)

Skip the approval process

12.

A security analyst is reviewing logs and notices multiple failed login attempts from a single IP address. What is the most appropriate next step?

a)

Ignore the activity

b)

Block the IP address and investigate further

c)

Reboot the server

d)

Delete the logs

13.

Which of the following best demonstrates the application of the principle of least privilege?

a)

Granting all users administrator access

b)

Allowing users access only to the resources necessary for their job

c)

Disabling all user accounts

d)

Sharing passwords among team members

14.

A company is considering whether to use symmetric or asymmetric encryption for secure email communication. What is a key advantage of asymmetric encryption in this scenario?

a)

Faster encryption and decryption

b)

No need to share private keys

c)

Uses the same key for encryption and decryption

d)

Requires less computational power

15.

A security team is planning how to respond to a ransomware attack. Which of the following actions should be prioritized to minimize damage?

a)

Immediately pay the ransom

b)

Disconnect affected systems from the network

c)

Inform the media

d)

Delete all encrypted files

16.

An organization is evaluating the risk of a new cloud service provider. What factors should be considered to assess the provider’s security posture?

a)

The provider’s marketing materials

b)

The provider’s security certifications and audit reports

c)

The provider’s office location

d)

The provider’s logo design

17.

A company has experienced a data breach. As part of the incident response, how should the team determine the scope and impact of the breach?

a)

Review only the affected user accounts

b)

Analyze logs, interview stakeholders, and assess affected systems

c)

Immediately notify all customers without investigation

d)

Ignore the incident

18.

You are tasked with designing a security policy for remote workers. What strategic considerations should you include to ensure both security and productivity?

a)

Require all remote workers to use personal devices without restrictions

b)

Mandate VPN usage, multi-factor authentication, and regular security training

c)

Allow unrestricted access to all company resources

d)

Prohibit remote work entirely

19.

A network administrator must choose between implementing a MAC or DAC model for a highly sensitive environment. What reasoning supports the selection of MAC over DAC?

a)

MAC allows users to set their own permissions

b)

MAC enforces strict, centrally controlled access policies, reducing insider threats

c)

DAC is more secure than MAC

d)

MAC is less complex to manage

20.

A company is developing a business continuity plan. What evidence-based steps should be taken to ensure critical operations can continue during a disaster?

a)

Only back up data once a year

b)

Identify critical systems, perform risk assessments, and establish recovery procedures

c)

Rely solely on insurance policies

d)

Ignore potential threats

21.

Which policy defines the rules for creating and managing strong passwords within an organization?

a)

Acceptable Use Policy

b)

Business Continuity Plan

c)

Incident Response Plan

d)

Password Policy

22.

Which cryptographic method uses a pair of keys, one public and one private, for secure communication?

a)

Symmetric encryption

b)

Asymmetric encryption

c)

Hashing

d)

Steganography

23.

What is the main goal of implementing the principle of least privilege in an organization?

a)

To allow users access to all resources

b)

To minimize the risk of unauthorized access by limiting permissions

c)

To increase network speed

d)

To simplify user account management

24.

Which of the following is a key benefit of implementing multi-factor authentication (MFA) in an organization?

a)

It reduces the number of user accounts needed

b)

It allows users to share credentials safely

c)

It provides an additional layer of security by requiring more than one form of verification

d)

It eliminates the need for passwords

25.

What is the primary purpose of a business continuity plan (BCP)?

a)

To monitor network traffic for suspicious activity

b)

To provide guidelines for software development

c)

To ensure critical business functions can continue during and after a disruption

d)

To enforce password complexity requirements

26.

Which of the following best describes the function of a firewall in network security?

a)

Physically secures the server room

b)

Manages user passwords and authentication

c)

Monitors and controls incoming and outgoing network traffic based on predetermined security rules

d)

Encrypts all data stored on a server

27.

Which of the following is the most effective way to prevent unauthorized access to sensitive company data?

a)

Allow all employees unrestricted access

b)

Disable all user accounts

c)

Implement role-based access controls and regular permission reviews

d)

Share passwords among team members

28.

What is the primary function of a disaster recovery plan (DRP) in an organization?

a)

To enforce password expiration policies

b)

To manage physical access to the building

c)

To monitor employee internet usage

d)

To outline steps for restoring IT systems and data after a major incident

29.

Which of the following best describes multi-factor authentication (MFA)?

a)

Disabling account lockout features

b)

Allowing users to bypass security questions

c)

Using a single password for all accounts

d)

Requiring two or more types of credentials for user verification

30.

Which document provides guidelines for responding to security incidents within an organization?

a)

Incident Response Plan

b)

Acceptable Use Policy

c)

Business Continuity Plan

d)

Password Policy

31.

What is the main goal of implementing the principle of least privilege in access control?

a)

To allow users access to all company resources

b)

To minimize the risk of unauthorized access by limiting permissions to only what is necessary

c)

To simplify user account management

d)

To increase the number of administrators

32.

Which of the following is a key component of a strong password policy?

a)

Disabling password expiration

b)

Permitting the use of common words as passwords

c)

Requiring passwords to be changed regularly and include a mix of character types

d)

Allowing passwords with only lowercase letters

33.

Which of the following best enforces the principle of least privilege in an organization?

a)

Allowing users to choose their own access levels

b)

Assigning permissions based on specific job roles and responsibilities

c)

Granting all users administrator access

d)

Sharing login credentials among team members

34.

What is the primary benefit of conducting regular permission reviews in an access control system?

a)

To ensure that only authorized users retain necessary access rights

b)

To increase the number of users with elevated privileges

c)

To simplify password requirements

d)

To allow unrestricted access to sensitive data

35.

Which of the following is an example of multi-factor authentication?

a)

Answering a single security question

b)

Logging in from a trusted device without credentials

c)

Using a fingerprint scan and a password to log in

d)

Entering a username and password only

36.

Which of the following is the most effective method to ensure only authorized personnel access sensitive areas within a company?

a)

Posting warning signs

b)

Implementing biometric access controls

c)

Leaving doors unlocked during business hours

d)

Allowing visitors to roam freely

37.

What is the primary objective of conducting a tabletop exercise as part of an incident response plan?

a)

To practice and evaluate the effectiveness of response procedures

b)

To test the speed of the network

c)

To install new security software

d)

To update user passwords

38.

Which of the following best describes the purpose of encryption in data security?

a)

To allow public access to sensitive information

b)

To increase data storage capacity

c)

To make data unreadable to unauthorized users

d)

To prevent data from being deleted

39.

Which of the following is a primary benefit of implementing a business continuity plan (BCP)?

a)

It increases employee productivity through automation

b)

It helps maintain essential operations during unexpected disruptions

c)

It eliminates the need for regular data backups

d)

It ensures compliance with all software licenses

40.

What is the main purpose of conducting regular security awareness training for employees?

a)

To reduce the risk of security incidents caused by human error

b)

To increase the number of IT support tickets

c)

To allow unrestricted access to sensitive data

d)

To teach employees how to develop software

41.

Which of the following best describes the function of an incident response team?

a)

To approve expense reports

b)

To coordinate actions and manage resources during a security incident

c)

To monitor employee attendance

d)

To develop marketing strategies

42.

Which of the following is a key component of a business continuity plan (BCP)?

a)

Instructions for organizing company events

b)

Strategies for maintaining critical operations during disruptions

c)

Guidelines for employee dress code

d)

Procedures for regular software updates

43.

What is the main advantage of using multi-factor authentication (MFA) over single-factor authentication?

a)

It eliminates the need for user training

b)

It reduces the need for passwords

c)

It allows users to share credentials

d)

It provides an additional layer of security by requiring more than one form of verification

44.

Which of the following best describes the purpose of an access control list (ACL) in network security?

a)

To encrypt all outgoing emails

b)

To specify which users or systems are granted or denied access to network resources

c)

To manage employee work schedules

d)

To monitor physical entry to the building

45.

Which of the following is a primary objective of access control in information security?

a)

To ensure only authorized individuals can access specific resources

b)

To increase the number of user accounts

c)

To allow unrestricted data sharing

d)

To simplify software installation

46.

What is the main function of encryption in protecting sensitive information?

a)

To manage user permissions

b)

To prevent physical theft of devices

c)

To convert data into a format unreadable without proper authorization

d)

To monitor network traffic

47.

Which of the following best describes a security policy?

a)

A record of network outages

b)

A software update schedule

c)

A list of employee birthdays

d)

A set of guidelines outlining acceptable and unacceptable behaviors regarding organizational resources

48.

Which of the following is the most effective way to protect data in transit over a public network?

a)

Using a secure VPN connection

b)

Disabling all firewalls

c)

Sharing files via unsecured email

d)

Storing data on a local hard drive

49.

What is the primary purpose of implementing regular security awareness training for employees?

a)

To increase the number of help desk tickets

b)

To eliminate the need for technical controls

c)

To reduce the risk of social engineering attacks

d)

To allow unrestricted access to sensitive data

50.

Which of the following best describes the function of a security audit?

a)

To increase network bandwidth

b)

To develop new software applications

c)

To monitor employee productivity

d)

To evaluate and verify the effectiveness of security controls