WorksheetsIAS2 QUIZ CH 4-6
Total questions: 60
Worksheet time: 30mins
Name
Class
Date
1.
Which IA element ensures only authorized individuals access sensitive data?
a)
Confidentiality
b)
Integrity
c)
Availability
d)
Non-repudiation
2.
A hospital encrypts patient records. Which IA element is being strengthened?
a)
Confidentiality
b)
Availability
c)
Authenticity
d)
Accountability
3.
Which element guarantees that information remains accurate and unaltered?
a)
Integrity
b)
Availability
c)
Authentication
d)
Confidentiality
4.
An e-commerce site experiences frequent downtime. Which IA element is at risk?
a)
Availability
b)
Integrity
c)
Non-repudiation
d)
Confidentiality
5.
Which IA element ensures a sender cannot later deny sending a message?
a)
Non-repudiation
b)
Accountability
c)
Confidentiality
d)
Authentication
6.
In online banking, requiring fingerprint login best supports which IA element?
a)
Authentication
b)
Integrity
c)
Availability
d)
Confidentiality
7.
Which IA element ensures individuals are held responsible for their actions?
a)
Accountability
b)
Confidentiality
c)
Integrity
d)
Authenticity
8.
A system that validates whether a digital signature is genuine supports which element?
a)
Authenticity
b)
Availability
c)
Confidentiality
d)
Integrity
9.
Which does NOT belong to the core IA elements?
a)
Holiday scheduling
b)
Confidentiality
c)
Integrity
d)
Availability
10.
If a company loses access to customer records during a cyberattack, which IA element failed?
a)
Availability
b)
Authenticity
c)
Non-repudiation
d)
Integrity
11.
Which IA element relates most directly to the principle of “trust but verify”?
a)
Authentication
b)
Integrity
c)
Availability
d)
Confidentiality
12.
An employee alters financial data without detection. Which IA element was violated?
a)
Integrity
b)
Availability
c)
Confidentiality
d)
Accountability
13.
Which IA element assures information remains usable when needed?
a)
Availability
b)
Confidentiality
c)
Non-repudiation
d)
Authenticity
14.
Why is accountability critical in multi-user systems?
a)
It ensures traceability of actions
b)
It reduces storage needs
c)
It limits internet speed
d)
It automates backups
15.
When IA is mapped to the CIA triad, which three elements are included?
a)
Confidentiality, Integrity, Availability
b)
Authentication, Privacy, Cost
c)
Accuracy, Speed, Trust
d)
Integrity, Access, Non-repudiation
16.
A lawyer sends a signed contract by email. Which IA element makes the signature binding?
a)
Non-repudiation
b)
Availability
c)
Authentication
d)
Integrity
17.
Which IA element is MOST challenged by phishing attacks?
a)
Authentication
b)
Availability
c)
Integrity
d)
Confidentiality
18.
What IA element is at risk when backups are not regularly tested?
a)
Availability
b)
Integrity
c)
Confidentiality
d)
Authenticity
19.
If customers doubt whether digital messages truly come from their bank, which IA element is questioned?
a)
Authenticity
b)
Integrity
c)
Availability
d)
Confidentiality
20.
Which IA element is MOST crucial in ensuring audit trails can identify user actions?
a)
Accountability
b)
Confidentiality
c)
Non-repudiation
d)
Integrity
21.
A bank discovers that outdated servers cannot handle new encryption. What is the BEST first step in risk management?
a)
Identify and assess the risk
b)
Immediately replace all servers
c)
Train staff on new encryption
d)
Ignore until a breach occurs
22.
Which activity ensures that risks are ranked by likelihood and impact before deciding controls?
a)
Risk assessment
b)
Risk mitigation
c)
Risk transfer
d)
Risk avoidance
23.
If a company buys cyber insurance to cover data breach costs, which risk response strategy is applied?
a)
Risk transfer
b)
Risk acceptance
c)
Risk mitigation
d)
Risk elimination
24.
A school identifies phishing emails targeting teachers. What is the BEST mitigation?
a)
Conduct awareness training
b)
Shut down email permanently
c)
Ignore unless money is lost
d)
Block all internet access
25.
Which risk response accepts the possibility of occurrence but prepares contingency plans?
a)
Risk acceptance
b)
Risk transfer
c)
Risk elimination
d)
Risk avoidance
26.
An organization sets up backup servers in another city. Which risk management step is this?
a)
Risk mitigation
b)
Risk acceptance
c)
Risk transfer
d)
Risk identification
27.
During risk assessment, what should be prioritized?
a)
High likelihood and high impact risks
b)
Low likelihood risks
c)
Only legal risks
d)
All risks equally
28.
If a hospital does not patch vulnerabilities due to budget limits, what risk decision is being made?
a)
Risk acceptance
b)
Risk transfer
c)
Risk avoidance
d)
Risk mitigation
29.
Which is the BEST justification for ongoing risk management reviews?
a)
Threats and vulnerabilities change over time
b)
Budgets never change
c)
Employees dislike reviews
d)
It avoids meetings
30.
A company encrypts customer data to prevent breaches. Which risk approach is used?
a)
Risk mitigation
b)
Risk transfer
c)
Risk avoidance
d)
Risk acceptance
31.
What is the MAIN benefit of conducting a business impact analysis?
a)
Identify critical processes and recovery priorities
b)
Eliminate all risks
c)
Reduce staff workload
d)
Comply with all audits
32.
If an IA officer creates a heat map of risks based on impact vs likelihood, what tool is being used?
a)
Risk matrix
b)
Risk transfer model
c)
Backup chart
d)
Threat elimination list
33.
Which of the following is NOT a typical risk response?
a)
Risk ignorance
b)
Risk transfer
c)
Risk avoidance
d)
Risk mitigation
34.
Why is risk identification considered the foundation of risk management?
a)
You cannot manage what you do not recognize
b)
It guarantees no risks will occur
c)
It reduces cafeteria costs
d)
It avoids hiring experts
35.
Which example BEST reflects risk avoidance?
a)
Choosing not to store sensitive data online
b)
Encrypting online data
c)
Buying cyber insurance
d)
Training staff
36.
A retail company outsources payment processing to a third party. What risk response is shown?
a)
Risk transfer
b)
Risk acceptance
c)
Risk avoidance
d)
Risk mitigation
37.
When a company decides to prioritize patching high-risk systems over low-risk systems, what principle is applied?
a)
Risk prioritization
b)
Risk elimination
c)
Risk sharing
d)
Risk ignorance
38.
Which IA risk management activity involves estimating cost of risk vs cost of control?
a)
Cost-benefit analysis
b)
Business impact analysis
c)
Threat mapping
d)
Risk elimination
39.
If executives only approve controls that align with business goals, what principle is reflected?
a)
Risk-based decision making
b)
Risk elimination
c)
Risk ignorance
d)
Risk transfer
40.
A logistics firm adds redundancy in its GPS tracking system to prevent disruption. Which risk action is this?
a)
Risk mitigation
b)
Risk avoidance
c)
Risk acceptance
d)
Risk transfer
41.
Which is the MAIN purpose of an Information Assurance Plan?
a)
Provide a roadmap for protecting information
b)
Replace IT staff
c)
Focus only on compliance
d)
Store backups in one place
42.
If an IA plan is never updated, which principle is ignored?
a)
Living document
b)
Risk assessment
c)
Conciseness
d)
Authenticity
43.
What is the BEST reason to align IA planning with organizational strategy?
a)
Ensure security supports business goals
b)
Make IT independent of the business
c)
Reduce training costs
d)
Focus only on audits
44.
An IA plan that describes executive, tactical, and operational roles reflects which principle?
a)
Strategic-tactical-operational alignment
b)
Short-term planning
c)
Only IT oversight
d)
Vendor lock-in
45.
Which does NOT belong in an effective IA plan?
a)
Personal hobbies
b)
Risk assessment
c)
Legal requirements
d)
Roles and responsibilities
46.
A bank updates its IA plan after a new phishing attack. This action reflects what principle?
a)
Periodic reassessment
b)
One-time planning
c)
Cost avoidance
d)
Vendor loyalty
47.
Which element of IA planning ensures the plan adapts to emerging threats?
a)
Extensibility
b)
Conciseness
c)
Independence
d)
Authenticity
48.
What is the MOST critical first step in building an IA plan?
a)
Defining scope and objectives
b)
Buying antivirus software
c)
Hiring consultants
d)
Installing hardware
49.
A company includes communication protocols for data breaches in its IA plan. What is this all about?
a)
Incident response planning
b)
Employee morale
c)
Vendor contracts
d)
Holiday schedules
50.
Which belongs to the core components of IA planning?
a)
Risk assessment
b)
Birthday celebrations
c)
Office decorations
d)
Leisure activities
51.
What quality ensures an IA plan avoids unnecessary jargon and confusion?
a)
Conciseness
b)
Extensibility
c)
Risk ignorance
d)
Vendor bias
52.
When leadership changes, which attribute helps the IA plan remain valuable?
a)
Long life span
b)
Temporary guide
c)
Static framework
d)
Short-term outlook
53.
If an IA plan ignores cost-benefit balance, what risk arises?
a)
Unsustainable implementation
b)
Employee satisfaction
c)
Reduced data volume
d)
Increased internet speed
54.
Which part of IA planning identifies “who is responsible for what”?
a)
Roles and responsibilities
b)
Legal penalties
c)
Backups
d)
Entertainment policy
55.
A university writes a 5-page IA plan focusing only on compliance laws. What is missing?
a)
Comprehensive coverage
b)
Legal compliance
c)
Conciseness
d)
Audit trail
56.
Which principle makes IA planning credible in regulatory audits?
a)
Alignment with laws and regulations
b)
Vendor dependence
c)
Only IT participation
d)
Branding slogans
57.
What is the BEST reason for treating IA planning as a continuous process?
a)
Threats and technologies evolve
b)
Budgets remain fixed
c)
Audits never change
d)
Employees never leave
58.
If the IA plan is treated as IT-only, what critical element is weakened?
a)
Organizational significance
b)
Independence
c)
Conciseness
d)
Extensibility
59.
An IA officer integrates staff training, legal obligations, and audits in the plan. This shows what principle?
a)
Holistic approach
b)
One-time compliance
c)
Short-term focus
d)
Risk ignorance
60.
Which is the BEST description of IA planning overall?
a)
Systematic preparation for protecting assets and managing risks
b)
Short-term cost reduction exercise
c)
Optional IT hobby
d)
Marketing tool
100 %
