wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CSP Unit2.1 Quiz

Total questions: 25

Worksheet time: 13mins

Name
Class
Date
1.

Which of the following is NOT a core principle of security management?

a)

Confidentiality

b)

Usability

c)

Integrity

d)

Availability

2.

The primary goal of information security management is to:

a)

Increase system speed

b)

Protect data confidentiality, integrity, and availability

c)

Manage staff productivity

d)

Design user interfaces

3.

Which principle refers to giving users the minimum level of access required?

a)

Least privilege

b)

Maximum access

c)

Role reversal

d)

Full trust

4.

Which one is a preventive control in security?

a)

Audit log

b)

Firewall

c)

Alarm

d)

Investigation

5.

Security policy is a type of:

a)

Preventive control

b)

Directive control

c)

Corrective control

d)

Detective control

6.

Which of the following is considered an administrative control?

a)

Firewalls

b)

Encryption

c)

Security awareness training

d)

Biometrics

7.

Which security principle ensures no single person has full control over a critical process?

a)

Need to know

b)

Separation of duties

c)

Defense in depth

d)

Accountability

8.

Security governance defines:

a)

Physical controls only

b)

How IT security supports business objectives

c)

Only technical rules

d)

None of the above

9.

Which term refers to the consistent application of policies and procedures?

a)

Compliance

b)

Audit

c)

Risk

d)

Control

10.

Risk that remains after controls are applied is called:

a)

Inherent risk

b)

Residual risk

c)

Accepted risk

d)

Total risk

11.

GRC stands for:

a)

Governance, Regulation, and Control

b)

Governance, Risk, and Compliance

c)

General Rules and Controls

d)

Governance, Risk, and Cyberlaw

12.

Which of the following is NOT a benefit of a GRC framework?

a)

Enhances communication

b)

Aligns IT with business goals

c)

Increases data duplication

d)

Reduces risk exposure

13.

In GRC, "Compliance" refers to:

a)

Risk estimation

b)

Following legal and regulatory standards

c)

Reducing employee count

d)

Increasing profits

14.

Governance in GRC primarily involves:

a)

Managing vendors

b)

Defining authority and accountability

c)

Installing software

d)

Encrypting data

15.

Risk in GRC context means:

a)

Opportunity for innovation

b)

Probability of a threat exploiting vulnerability

c)

Software installation

d)

Employee turnover

16.

Which framework helps implement GRC across an organization?

a)

CMMI

b)

NIST

c)

COBIT

d)

Six Sigma

17.

A key output of the governance function in GRC is:

a)

Patching systems

b)

Creating firewalls

c)

Defining roles and responsibilities

d)

Scanning for viruses

18.

Which of these relates to IT risk management within GRC?

a)

Vendor selection

b)

Threat analysis

c)

System configuration

d)

Hardware procurement

19.

Which domain of GRC ensures legal compliance?

a)

Governance

b)

Risk

c)

Compliance

d)

Architecture

20.

The main goal of a GRC framework is to:

a)

Replace traditional audits

b)

Create new networks

c)

Integrate security practices across the enterprise

d)

Hire consultants

21.

Risk is defined as:

a)

Possibility of hardware upgrade

b)

Probability of threat exploiting a vulnerability

c)

Encryption of data

d)

Implementation of firewalls

22.

A threat is:

a)

A known user

b)

A potential cause of harm

c)

An antivirus software

d)

A server update

23.

Which risk assessment method uses numerical values?

a)

Qualitative

b)

Quantitative

c)

Empirical

d)

Predictive

24.

A qualitative risk assessment relies on:

a)

Statistical calculations

b)

Personal judgment and experience

c)

Machine learning

d)

None of the above

25.

ALE stands for:

a)

Automated Log Entry

b)

Annual Loss Expectancy

c)

Application Layer Encryption

d)

Access Level Enforcement