WorksheetsCSP Unit2.1 Quiz
Total questions: 25
Worksheet time: 13mins
Which of the following is NOT a core principle of security management?
Confidentiality
Usability
Integrity
Availability
The primary goal of information security management is to:
Increase system speed
Protect data confidentiality, integrity, and availability
Manage staff productivity
Design user interfaces
Which principle refers to giving users the minimum level of access required?
Least privilege
Maximum access
Role reversal
Full trust
Which one is a preventive control in security?
Audit log
Firewall
Alarm
Investigation
Security policy is a type of:
Preventive control
Directive control
Corrective control
Detective control
Which of the following is considered an administrative control?
Firewalls
Encryption
Security awareness training
Biometrics
Which security principle ensures no single person has full control over a critical process?
Need to know
Separation of duties
Defense in depth
Accountability
Security governance defines:
Physical controls only
How IT security supports business objectives
Only technical rules
None of the above
Which term refers to the consistent application of policies and procedures?
Compliance
Audit
Risk
Control
Risk that remains after controls are applied is called:
Inherent risk
Residual risk
Accepted risk
Total risk
GRC stands for:
Governance, Regulation, and Control
Governance, Risk, and Compliance
General Rules and Controls
Governance, Risk, and Cyberlaw
Which of the following is NOT a benefit of a GRC framework?
Enhances communication
Aligns IT with business goals
Increases data duplication
Reduces risk exposure
In GRC, "Compliance" refers to:
Risk estimation
Following legal and regulatory standards
Reducing employee count
Increasing profits
Governance in GRC primarily involves:
Managing vendors
Defining authority and accountability
Installing software
Encrypting data
Risk in GRC context means:
Opportunity for innovation
Probability of a threat exploiting vulnerability
Software installation
Employee turnover
Which framework helps implement GRC across an organization?
CMMI
NIST
COBIT
Six Sigma
A key output of the governance function in GRC is:
Patching systems
Creating firewalls
Defining roles and responsibilities
Scanning for viruses
Which of these relates to IT risk management within GRC?
Vendor selection
Threat analysis
System configuration
Hardware procurement
Which domain of GRC ensures legal compliance?
Governance
Risk
Compliance
Architecture
The main goal of a GRC framework is to:
Replace traditional audits
Create new networks
Integrate security practices across the enterprise
Hire consultants
Risk is defined as:
Possibility of hardware upgrade
Probability of threat exploiting a vulnerability
Encryption of data
Implementation of firewalls
A threat is:
A known user
A potential cause of harm
An antivirus software
A server update
Which risk assessment method uses numerical values?
Qualitative
Quantitative
Empirical
Predictive
A qualitative risk assessment relies on:
Statistical calculations
Personal judgment and experience
Machine learning
None of the above
ALE stands for:
Automated Log Entry
Annual Loss Expectancy
Application Layer Encryption
Access Level Enforcement
