wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

MidtermExam-ITSecurity-MakScie

Total questions: 100

Worksheet time: 2hrs 40mins

Name
Class
Date
1.

A bank introduces a policy requiring dual approval before large fund transfers. Which principle of IT security is being enforced?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Accountability

2.

A company installs redundant power supplies to ensure services are always available. Which part of the CIA triad is addressed?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Authentication

3.

An organization implements encryption for email communication. Which primary security objective is achieved?

a)

Integrity

b)

Availability

c)

Confidentiality

d)

Accountability

4.

The IT manager mandates strong passwords and multifactor authentication. Which security control type does this represent?

a)

Physical

b)

Administrative

c)

Technical

d)

Environmental

5.

An internal audit finds that employees are not following the security policy. What should management do first?

a)

Punish the employees

b)

Conduct security awareness training

c)

Remove all user accounts

d)

Ignore the issue

6.

A government agency uses ISO/IEC 27001 to guide its security program. What does this represent?

a)

Risk avoidance

b)

Security framework adoption

c)

Incident handling

d)

Firewall configuration

7.

A university installs CCTV cameras around its server room. This measure primarily addresses:

a)

Technical control

b)

Physical control

c)

Administrative control

d)

Preventive control

8.

A company uses ITIL to align IT services with business needs. Which best describes this?

a)

Governance framework

b)

IT service management

c)

Security policy

d)

Risk assessment

9.

The CIO demands quarterly reports on security status and incidents. This request relates to:

a)

Security monitoring

b)

Security governance

c)

Security implementation

d)

Security operations only

10.

An online retailer requires systems to be operational 24/7 during holiday sales. Which security requirement is most critical?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Privacy

11.

A startup documents rules on data handling and acceptable use of IT systems. What is being developed?

a)

Firewall rule set

b)

Security policy

c)

Incident report

d)

Access log

12.

A company introduces role-based access controls so employees can only access resources relevant to their job. Which concept applies?

a)

Least privilege

b)

Separation of duties

c)

Defense in depth

d)

Availability

13.

After a ransomware attack, the board asks for a structured recovery approach. Which management process is most relevant?

a)

Incident response

b)

Risk avoidance

c)

System hardening

d)

Security awareness

14.

A hospital encrypts patient data and restricts access to authorized doctors. Which law compliance aspect does this address?

a)

Workplace safety

b)

Data privacy regulations

c)

Environmental laws

d)

Labor codes

15.

A company locks its server racks to prevent unauthorized access. What type of control is this?

a)

Physical preventive

b)

Technical corrective

c)

Administrative detective

d)

Logical compensating

16.

Management ensures backups are stored offsite for disaster recovery. This practice supports:

a)

Availability

b)

Integrity

c)

Confidentiality

d)

Authentication

17.

A financial institution regularly audits security controls to ensure compliance with regulations. This activity represents:

a)

Incident handling

b)

Security governance

c)

Risk transfer

d)

Penetration testing

18.

A software company enforces code reviews before software release to detect vulnerabilities. This ensures:

a)

Integrity of software

b)

Availability of system

c)

Confidentiality of data

d)

Authentication of users

19.

An IT department deploys intrusion detection systems across the network. This is an example of:

a)

Preventive control

b)

Detective control

c)

Corrective control

d)

Compensating control

20.

The CEO requires IT security strategies to align with company growth plans. This represents:

a)

Tactical planning

b)

Strategic alignment

c)

Operational management

d)

Risk acceptance

21.

A law firm loses sensitive client files due to poor backup practices. Which key principle of information security was violated?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Authentication

22.

A hospital is fined for unauthorized access to patient data. This highlights the importance of:

a)

Physical security

b)

Data privacy and confidentiality

c)

Software licensing

d)

Backup and recovery

23.

An e-commerce site suffers from altered product prices by attackers. Which principle is compromised?

a)

Confidentiality

b)

Availability

c)

Integrity

d)

Accountability

24.

A company uses cloud-based services but ensures encryption keys remain internal. This action emphasizes:

a)

Risk transfer

b)

Confidentiality

c)

Availability

d)

Cost reduction

25.

An airline's booking system crashes, preventing customers from purchasing tickets. Which impact does this show?

a)

Integrity impact

b)

Availability impact

c)

Confidentiality impact

d)

Accountability impact

26.

A breach reveals trade secrets of a manufacturing firm. What's the most significant consequence?

a)

Reduced system uptime

b)

Loss of competitive advantage

c)

Increased training needs

d)

Regulatory compliance improvement

27.

A retail company mandates secure handling of credit card data to comply with PCI-DSS. Why is this important?

a)

To reduce storage costs

b)

To meet international security standards

c)

To prevent software bugs

d)

To increase network speed

28.

Employees are trained to identify phishing emails. This action emphasizes:

a)

Confidentiality importance

b)

Human element in security

c)

Backup strategies

d)

Vendor risk management

29.

A government agency faces a ransomware attack. What's the most important reason to invest in security beforehand?

a)

To reduce employee headcount

b)

To ensure mission-critical services are not disrupted

c)

To increase marketing budget

d)

To avoid cloud migration

30.

A school secures student records to prevent identity theft. This measure supports:

a)

Integrity

b)

Confidentiality

c)

Availability

d)

Usability

31.

An IT service provider implements a disaster recovery site to resume operations quickly. This is important for:

a)

Confidentiality

b)

Business continuity

c)

Integrity

d)

Authentication

32.

A software company faces reputational damage after a data breach. What does this highlight?

a)

Security impacts extend beyond financial loss

b)

Only availability is important

c)

IT risks do not affect reputation

d)

Reputation is unrelated to security

33.

A financial institution ensures tamper-proof logging for transactions. This highlights:

a)

Accountability importance

b)

Availability importance

c)

Confidentiality importance

d)

Cost reduction

34.

An airline encrypts customer passports stored in its database. Which principle is prioritized?

a)

Availability

b)

Confidentiality

c)

Integrity

d)

Accountability

35.

A hospital ensures that lab results are accurate and not modified by unauthorized users. Which principle applies?

a)

Integrity

b)

Availability

c)

Confidentiality

d)

Usability

36.

A logistics company deploys backup internet connections to prevent service downtime. This highlights the importance of:

a)

Availability

b)

Confidentiality

c)

Integrity

d)

Cost reduction

37.

A company loses customer trust after repeated breaches. Why is security important in this case?

a)

Trust and reputation are vital business assets

b)

Security is only about compliance

c)

Only availability matters to customers

d)

Security reduces hardware needs

38.

A university invests in cybersecurity insurance. This reflects:

a)

Integrity focus

b)

Confidentiality focus

c)

Risk transfer importance

d)

Risk acceptance importance

39.

A multinational enforces strict access control on R&D data. The importance of security here is:

a)

Protecting intellectual property

b)

Reducing energy use

c)

Preventing redundancy

d)

Improving entertainment options

40.

A cloud provider guarantees data availability via SLA agreements. Which aspect of importance does this demonstrate?

a)

Integrity of data

b)

Availability assurance

c)

Confidentiality enforcement

d)

Authentication guarantee

41.

A hacker exploits a weak password to gain access to a company's database. What is the weak password considered?

a)

Threat

b)

Vulnerability

c)

Risk

d)

Control

42.

An employee accidentally sends sensitive files to the wrong client. This incident is best classified as:

a)

Insider threat (unintentional)

b)

Insider threat (malicious)

c)

External threat

d)

Risk transfer

43.

A company identifies that outdated software could be exploited by malware. Which term describes this situation?

a)

Threat

b)

Risk

c)

Vulnerability

d)

Safeguard

44.

A DDoS attack overwhelms an e-commerce site, causing downtime. This represents:

a)

Loss of confidentiality

b)

Threat to availability

c)

Integrity violation

d)

Risk transfer

45.

An attacker sends fake invoices to finance staff, tricking them into paying. What type of threat is this?

a)

Malware

b)

Social engineering

c)

Denial of Service

d)

Insider attack

46.

An organization stores critical data on a server with no backup. The absence of a backup represents:

a)

Risk avoidance

b)

Vulnerability

c)

Control

d)

Threat

47.

A disgruntled employee installs spyware on company laptops. This is an example of:

a)

Internal threat

b)

External threat

c)

Accidental error

d)

Vulnerability

48.

An IT auditor notes that employees share their login credentials. What does this practice create?

a)

Control

b)

Vulnerability

c)

Threat

d)

Safeguard

49.

A security analyst discovers that a mobile app stores passwords in plain text. This is an example of:

a)

Control

b)

Vulnerability

c)

Threat

d)

Safeguard

50.

An attacker floods a web server with traffic from multiple compromised systems. This type of attack is:

a)

SQL injection

b)

Man-in-the-middle

c)

Distributed Denial of Service (DDoS)

d)

Buffer overflow

51.

A security analyst discovers that a mobile app stores passwords in plain text. This is an example of:

a)

Threat

b)

Vulnerability

c)

Risk treatment

d)

Safeguard

52.

A company hosts data on a third-party cloud service. The risk here is mainly due to:

a)

Risk transference

b)

Shared responsibility vulnerabilities

c)

Firewall misconfiguration

d)

Incident response failure

53.

A virus infects an employee's laptop after opening a malicious email attachment. The virus is a:

a)

Threat

b)

Vulnerability

c)

Safeguard

d)

Control

54.

An airport Wi-Fi network does not require encryption. What is this called?

a)

Safeguard

b)

Threat

c)

Vulnerability

d)

Control

55.

A business keeps critical customer data in a single server with no redundancy. Which risk is most likely?

a)

Data tampering

b)

System unavailability

c)

Malware infection

d)

Insider threat

56.

A company allows USB devices to connect without restrictions. Which type of weakness is this?

a)

Technical vulnerability

b)

Administrative control

c)

Physical control

d)

Safeguard

57.

Hackers exploit a software flaw in a web app to steal customer data. The flaw is considered:

a)

Threat

b)

Vulnerability

c)

Safeguard

d)

Control

58.

A cybercriminal creates fake login pages to steal credentials. This is an example of:

a)

Phishing attack

b)

Malware infection

c)

Insider attack

d)

Social engineering (non-technical)

59.

A security team identifies that weak encryption was used in data storage. This weakness is:

a)

Threat

b)

Vulnerability

c)

Control

d)

Safeguard

60.

A company detects unusual outbound traffic from its server. What does this indicate?

a)

Preventive control

b)

Possible data exfiltration threat

c)

Availability assurance

d)

Corrective action

61.

An organization determines that if a server fails, it will cause financial loss. What term describes this?

a)

Threat

b)

Risk

c)

Control

d)

Safeguard

62.

A bank evaluates the potential impact if its ATM system fails. This activity is part of:

a)

Threat modeling

b)

Risk assessment

c)

Risk transfer

d)

Vulnerability patching

63.

A hospital estimates the damage cost if patient data is leaked. Which risk assessment step is this?

a)

Risk identification

b)

Impact analysis

c)

Threat detection

d)

Vulnerability scanning

64.

An IT team lists all critical assets and classifies them by importance. Which stage of risk assessment is this?

a)

Asset identification

b)

Threat analysis

c)

Risk mitigation

d)

Control selection

65.

A company calculates the likelihood and potential loss of a ransomware attack. What is this process called?

a)

Business continuity planning

b)

Risk quantification

c)

Control implementation

d)

Safeguard monitoring

66.

During an audit, a financial firm identifies insider threats as high probability but low impact. This classification refers to:

a)

Risk prioritization

b)

Safeguard assignment

c)

Threat elimination

d)

Policy enforcement

67.

A retail store ranks risks from highest to lowest based on likelihood and impact. What technique is used?

a)

Risk transference

b)

Risk ranking / prioritization

c)

Risk avoidance

d)

Incident response

68.

A bank assigns numerical values to estimate potential yearly loss from cyber fraud. This is called:

a)

Qualitative risk analysis

b)

Quantitative risk analysis

c)

Residual risk analysis

d)

Vulnerability testing

69.

A company uses heat maps to show risk levels visually. Which risk assessment method is this?

a)

Quantitative

b)

Qualitative

c)

Preventive

d)

Corrective

70.

A manager asks, "What is the chance this system will be attacked, and what is the potential damage?" This refers to:

a)

Risk appetite

b)

Risk assessment

c)

Control monitoring

d)

Incident detection

71.

A company performs penetration testing to identify weak spots. This helps in:

a)

Risk identification

b)

Risk transfer

c)

Risk acceptance

d)

Risk avoidance

72.

A hospital assesses if an outdated firewall could allow intrusions. Which factor is analyzed?

a)

Threat

b)

Vulnerability

c)

Impact

d)

Control effectiveness

73.

A cloud provider evaluates how service downtime would affect customers. This is an example of:

a)

Availability risk assessment

b)

Vulnerability analysis

c)

Threat elimination

d)

Technical control

74.

A company finds its online payment system vulnerable but unlikely to be exploited. How should this be classified?

a)

High risk

b)

Medium risk

c)

Low risk

d)

No risk

75.

A government agency calculates annualized loss expectancy (ALE) from data breaches. Which assessment method is used?

a)

Qualitative

b)

Quantitative

c)

Compensating

d)

Corrective

76.

A school rates the risk of ransomware as "high" without exact numbers. This is:

a)

Quantitative analysis

b)

Qualitative analysis

c)

Residual analysis

d)

Technical assessment

77.

A company measures how long it can continue operations during a disaster. Which concept applies?

a)

Mean Time Between Failures (MTBF)

b)

Maximum Tolerable Downtime (MTD)

c)

Residual risk

d)

Business continuity testing

78.

A bank uses past incident data to estimate future risks. This approach is:

a)

Predictive risk analysis

b)

Preventive control

c)

Detective control

d)

Residual risk estimation

79.

A retail company identifies credit card fraud as its top risk. What comes next in risk assessment?

a)

Control implementation

b)

Risk transfer

c)

Risk mitigation planning

d)

Risk monitoring

80.

An audit reveals that even after applying controls, some risk remains. This is called:

a)

Residual risk

b)

Accepted risk

c)

Avoided risk

d)

Eliminated risk

81.

A hospital compares risks against its tolerance levels. This is defining:

a)

Risk appetite

b)

Risk assessment

c)

Risk transfer

d)

Incident response

82.

A company installs firewalls and IDS to reduce cyber-attack chances. This strategy is:

a)

Risk transfer

b)

Risk avoidance

c)

Risk mitigation

d)

Risk acceptance

83.

A bank moves its data to a third-party insured cloud provider. This represents:

a)

Risk transfer

b)

Risk avoidance

c)

Risk mitigation

d)

Risk elimination

84.

A business discontinues an insecure online service to avoid attacks. This is:

a)

Risk transfer

b)

Risk avoidance

c)

Risk acceptance

d)

Risk mitigation

85.

A startup accepts minor risks because mitigation costs are higher than potential loss. Which strategy is this?

a)

Risk transfer

b)

Risk avoidance

c)

Risk mitigation

d)

Risk acceptance

86.

A hospital uses insurance to cover financial losses from data breaches. This is an example of:

a)

Risk mitigation

b)

Risk acceptance

c)

Risk transfer

d)

Risk avoidance

87.

A company installs UPS and backup generators to reduce downtime. Which strategy is applied?

a)

Risk avoidance

b)

Risk mitigation

c)

Risk transfer

d)

Risk acceptance

88.

A firm decommissions an old server that poses security risks. Which strategy is this?

a)

Risk acceptance

b)

Risk avoidance

c)

Risk transfer

d)

Risk mitigation

89.

A bank decides not to patch a minor software bug since the impact is negligible. This is:

a)

Risk acceptance

b)

Risk transfer

c)

Risk mitigation

d)

Risk avoidance

90.

A government agency outsources security operations to a managed service provider. This is:

a)

Risk transfer

b)

Risk avoidance

c)

Risk mitigation

d)

Risk acceptance

91.

A company invests in staff training to prevent phishing attacks. Which strategy is applied?

a)

Risk mitigation

b)

Risk transfer

c)

Risk avoidance

d)

Risk acceptance

92.

An online retailer uses redundant servers across multiple regions. This demonstrates:

a)

Risk avoidance

b)

Risk mitigation

c)

Risk transfer

d)

Risk acceptance

93.

A business uses cyber insurance but also implements firewalls. Which approach is used?

a)

Mixed (transfer + mitigation)

b)

Avoidance only

c)

Acceptance only

d)

No strategy

94.

A manufacturing company stops using outdated software with known flaws. Which risk strategy is applied?

a)

Risk mitigation

b)

Risk avoidance

c)

Risk transfer

d)

Risk acceptance

95.

A retailer accepts the risk of small-scale fraud as part of operations. This is an example of:

a)

Risk avoidance

b)

Risk mitigation

c)

Risk acceptance

d)

Risk transfer

96.

A firm encrypts data to reduce damage if intercepted. Which risk strategy is this?

a)

Risk mitigation

b)

Risk transfer

c)

Risk avoidance

d)

Risk acceptance

97.

A university disables a vulnerable online portal permanently. This is:

a)

Risk avoidance

b)

Risk mitigation

c)

Risk transfer

d)

Risk acceptance

98.

A company outsources its payroll system to a secure third-party vendor. This represents:

a)

Risk transfer

b)

Risk mitigation

c)

Risk acceptance

d)

Risk avoidance

99.

A small business buys insurance but also accepts minimal risks for cost savings. This is:

a)

Risk avoidance

b)

Risk mitigation

c)

Risk transfer + acceptance

d)

No strategy

100.

A hospital prioritizes investing in backup power over cosmetic website updates. This shows:

a)

Risk prioritization and mitigation

b)

Risk acceptance only

c)

Risk avoidance only

d)

Risk transfer