WorksheetsSec+ 701 Final Review Quiz
Total questions: 50
Worksheet time: 25mins
Which protocol is commonly used to securely transfer files over a network?
FTP
SFTP
Telnet
SMTP
What does the acronym CIA stand for in information security?
Confidentiality, Integrity, Availability
Control, Inspection, Authorization
Confidentiality, Inspection, Access
Control, Integrity, Authentication
Which of the following is an example of a physical security control?
Firewall
Security badge
Antivirus software
Encryption
Which access control model is based on predefined roles within an organization?
Discretionary Access Control (DAC)
Mandatory Access Control (MAC)
Role-Based Access Control (RBAC)
Rule-Based Access Control
What is the primary purpose of a risk assessment in the risk management framework?
To eliminate all risks
To identify and evaluate potential threats and vulnerabilities
To create user accounts
To install security patches
Which cryptographic algorithm is classified as symmetric?
RSA
AES
ECC
DSA
Which document outlines the acceptable use of organizational resources by employees?
Incident Response Plan
Acceptable Use Policy
Disaster Recovery Plan
Business Continuity Plan
Which of the following best describes the first step in the incident response process?
Containment
Eradication
Identification
Recovery
A company wants to ensure that only authorized users can access sensitive data. Which access control model should they implement to assign permissions based on job functions?
Discretionary Access Control (DAC)
Role-Based Access Control (RBAC)
Mandatory Access Control (MAC)
Attribute-Based Access Control (ABAC)
You are tasked with configuring a firewall to block all incoming traffic except for web services. Which ports should you allow?
21 and 22
80 and 443
25 and 110
53 and 8080
An organization is developing a new security policy. Which step should be taken to ensure the policy is effective and enforceable?
Distribute the policy without review
Involve stakeholders in the policy development process
Only consult IT staff
Skip the approval process
A security analyst is reviewing logs and notices multiple failed login attempts from a single IP address. What is the most appropriate next step?
Ignore the activity
Block the IP address and investigate further
Reboot the server
Delete the logs
Which of the following best demonstrates the application of the principle of least privilege?
Granting all users administrator access
Allowing users access only to the resources necessary for their job
Disabling all user accounts
Sharing passwords among team members
A company is considering whether to use symmetric or asymmetric encryption for secure email communication. What is a key advantage of asymmetric encryption in this scenario?
Faster encryption and decryption
No need to share private keys
Uses the same key for encryption and decryption
Requires less computational power
A security team is planning how to respond to a ransomware attack. Which of the following actions should be prioritized to minimize damage?
Immediately pay the ransom
Disconnect affected systems from the network
Inform the media
Delete all encrypted files
An organization is evaluating the risk of a new cloud service provider. What factors should be considered to assess the provider’s security posture?
The provider’s marketing materials
The provider’s security certifications and audit reports
The provider’s office location
The provider’s logo design
A company has experienced a data breach. As part of the incident response, how should the team determine the scope and impact of the breach?
Review only the affected user accounts
Analyze logs, interview stakeholders, and assess affected systems
Immediately notify all customers without investigation
Ignore the incident
You are tasked with designing a security policy for remote workers. What strategic considerations should you include to ensure both security and productivity?
Require all remote workers to use personal devices without restrictions
Mandate VPN usage, multi-factor authentication, and regular security training
Allow unrestricted access to all company resources
Prohibit remote work entirely
A network administrator must choose between implementing a MAC or DAC model for a highly sensitive environment. What reasoning supports the selection of MAC over DAC?
MAC allows users to set their own permissions
MAC enforces strict, centrally controlled access policies, reducing insider threats
DAC is more secure than MAC
MAC is less complex to manage
A company is developing a business continuity plan. What evidence-based steps should be taken to ensure critical operations can continue during a disaster?
Only back up data once a year
Identify critical systems, perform risk assessments, and establish recovery procedures
Rely solely on insurance policies
Ignore potential threats
Which policy defines the rules for creating and managing strong passwords within an organization?
Acceptable Use Policy
Business Continuity Plan
Incident Response Plan
Password Policy
Which cryptographic method uses a pair of keys, one public and one private, for secure communication?
Symmetric encryption
Asymmetric encryption
Hashing
Steganography
What is the main goal of implementing the principle of least privilege in an organization?
To allow users access to all resources
To minimize the risk of unauthorized access by limiting permissions
To increase network speed
To simplify user account management
Which of the following is a key benefit of implementing multi-factor authentication (MFA) in an organization?
It reduces the number of user accounts needed
It allows users to share credentials safely
It provides an additional layer of security by requiring more than one form of verification
It eliminates the need for passwords
What is the primary purpose of a business continuity plan (BCP)?
To monitor network traffic for suspicious activity
To provide guidelines for software development
To ensure critical business functions can continue during and after a disruption
To enforce password complexity requirements
Which of the following best describes the function of a firewall in network security?
Physically secures the server room
Manages user passwords and authentication
Monitors and controls incoming and outgoing network traffic based on predetermined security rules
Encrypts all data stored on a server
Which of the following is the most effective way to prevent unauthorized access to sensitive company data?
Allow all employees unrestricted access
Disable all user accounts
Implement role-based access controls and regular permission reviews
Share passwords among team members
What is the primary function of a disaster recovery plan (DRP) in an organization?
To enforce password expiration policies
To manage physical access to the building
To monitor employee internet usage
To outline steps for restoring IT systems and data after a major incident
Which of the following best describes multi-factor authentication (MFA)?
Disabling account lockout features
Allowing users to bypass security questions
Using a single password for all accounts
Requiring two or more types of credentials for user verification
Which document provides guidelines for responding to security incidents within an organization?
Incident Response Plan
Acceptable Use Policy
Business Continuity Plan
Password Policy
What is the main goal of implementing the principle of least privilege in access control?
To allow users access to all company resources
To minimize the risk of unauthorized access by limiting permissions to only what is necessary
To simplify user account management
To increase the number of administrators
Which of the following is a key component of a strong password policy?
Disabling password expiration
Permitting the use of common words as passwords
Requiring passwords to be changed regularly and include a mix of character types
Allowing passwords with only lowercase letters
Which of the following best enforces the principle of least privilege in an organization?
Allowing users to choose their own access levels
Assigning permissions based on specific job roles and responsibilities
Granting all users administrator access
Sharing login credentials among team members
What is the primary benefit of conducting regular permission reviews in an access control system?
To ensure that only authorized users retain necessary access rights
To increase the number of users with elevated privileges
To simplify password requirements
To allow unrestricted access to sensitive data
Which of the following is an example of multi-factor authentication?
Answering a single security question
Logging in from a trusted device without credentials
Using a fingerprint scan and a password to log in
Entering a username and password only
Which of the following is the most effective method to ensure only authorized personnel access sensitive areas within a company?
Posting warning signs
Implementing biometric access controls
Leaving doors unlocked during business hours
Allowing visitors to roam freely
What is the primary objective of conducting a tabletop exercise as part of an incident response plan?
To practice and evaluate the effectiveness of response procedures
To test the speed of the network
To install new security software
To update user passwords
Which of the following best describes the purpose of encryption in data security?
To allow public access to sensitive information
To increase data storage capacity
To make data unreadable to unauthorized users
To prevent data from being deleted
Which of the following is a primary benefit of implementing a business continuity plan (BCP)?
It increases employee productivity through automation
It helps maintain essential operations during unexpected disruptions
It eliminates the need for regular data backups
It ensures compliance with all software licenses
What is the main purpose of conducting regular security awareness training for employees?
To reduce the risk of security incidents caused by human error
To increase the number of IT support tickets
To allow unrestricted access to sensitive data
To teach employees how to develop software
Which of the following best describes the function of an incident response team?
To approve expense reports
To coordinate actions and manage resources during a security incident
To monitor employee attendance
To develop marketing strategies
Which of the following is a key component of a business continuity plan (BCP)?
Instructions for organizing company events
Strategies for maintaining critical operations during disruptions
Guidelines for employee dress code
Procedures for regular software updates
What is the main advantage of using multi-factor authentication (MFA) over single-factor authentication?
It eliminates the need for user training
It reduces the need for passwords
It allows users to share credentials
It provides an additional layer of security by requiring more than one form of verification
Which of the following best describes the purpose of an access control list (ACL) in network security?
To encrypt all outgoing emails
To specify which users or systems are granted or denied access to network resources
To manage employee work schedules
To monitor physical entry to the building
Which of the following is a primary objective of access control in information security?
To ensure only authorized individuals can access specific resources
To increase the number of user accounts
To allow unrestricted data sharing
To simplify software installation
What is the main function of encryption in protecting sensitive information?
To manage user permissions
To prevent physical theft of devices
To convert data into a format unreadable without proper authorization
To monitor network traffic
Which of the following best describes a security policy?
A record of network outages
A software update schedule
A list of employee birthdays
A set of guidelines outlining acceptable and unacceptable behaviors regarding organizational resources
Which of the following is the most effective way to protect data in transit over a public network?
Using a secure VPN connection
Disabling all firewalls
Sharing files via unsecured email
Storing data on a local hard drive
What is the primary purpose of implementing regular security awareness training for employees?
To increase the number of help desk tickets
To eliminate the need for technical controls
To reduce the risk of social engineering attacks
To allow unrestricted access to sensitive data
Which of the following best describes the function of a security audit?
To increase network bandwidth
To develop new software applications
To monitor employee productivity
To evaluate and verify the effectiveness of security controls
