WorksheetsMidtermExam-ITSecurity-MakScie
Total questions: 100
Worksheet time: 2hrs 40mins
A bank introduces a policy requiring dual approval before large fund transfers. Which principle of IT security is being enforced?
Confidentiality
Integrity
Availability
Accountability
A company installs redundant power supplies to ensure services are always available. Which part of the CIA triad is addressed?
Confidentiality
Integrity
Availability
Authentication
An organization implements encryption for email communication. Which primary security objective is achieved?
Integrity
Availability
Confidentiality
Accountability
The IT manager mandates strong passwords and multifactor authentication. Which security control type does this represent?
Physical
Administrative
Technical
Environmental
An internal audit finds that employees are not following the security policy. What should management do first?
Punish the employees
Conduct security awareness training
Remove all user accounts
Ignore the issue
A government agency uses ISO/IEC 27001 to guide its security program. What does this represent?
Risk avoidance
Security framework adoption
Incident handling
Firewall configuration
A university installs CCTV cameras around its server room. This measure primarily addresses:
Technical control
Physical control
Administrative control
Preventive control
A company uses ITIL to align IT services with business needs. Which best describes this?
Governance framework
IT service management
Security policy
Risk assessment
The CIO demands quarterly reports on security status and incidents. This request relates to:
Security monitoring
Security governance
Security implementation
Security operations only
An online retailer requires systems to be operational 24/7 during holiday sales. Which security requirement is most critical?
Confidentiality
Integrity
Availability
Privacy
A startup documents rules on data handling and acceptable use of IT systems. What is being developed?
Firewall rule set
Security policy
Incident report
Access log
A company introduces role-based access controls so employees can only access resources relevant to their job. Which concept applies?
Least privilege
Separation of duties
Defense in depth
Availability
After a ransomware attack, the board asks for a structured recovery approach. Which management process is most relevant?
Incident response
Risk avoidance
System hardening
Security awareness
A hospital encrypts patient data and restricts access to authorized doctors. Which law compliance aspect does this address?
Workplace safety
Data privacy regulations
Environmental laws
Labor codes
A company locks its server racks to prevent unauthorized access. What type of control is this?
Physical preventive
Technical corrective
Administrative detective
Logical compensating
Management ensures backups are stored offsite for disaster recovery. This practice supports:
Availability
Integrity
Confidentiality
Authentication
A financial institution regularly audits security controls to ensure compliance with regulations. This activity represents:
Incident handling
Security governance
Risk transfer
Penetration testing
A software company enforces code reviews before software release to detect vulnerabilities. This ensures:
Integrity of software
Availability of system
Confidentiality of data
Authentication of users
An IT department deploys intrusion detection systems across the network. This is an example of:
Preventive control
Detective control
Corrective control
Compensating control
The CEO requires IT security strategies to align with company growth plans. This represents:
Tactical planning
Strategic alignment
Operational management
Risk acceptance
A law firm loses sensitive client files due to poor backup practices. Which key principle of information security was violated?
Confidentiality
Integrity
Availability
Authentication
A hospital is fined for unauthorized access to patient data. This highlights the importance of:
Physical security
Data privacy and confidentiality
Software licensing
Backup and recovery
An e-commerce site suffers from altered product prices by attackers. Which principle is compromised?
Confidentiality
Availability
Integrity
Accountability
A company uses cloud-based services but ensures encryption keys remain internal. This action emphasizes:
Risk transfer
Confidentiality
Availability
Cost reduction
An airline's booking system crashes, preventing customers from purchasing tickets. Which impact does this show?
Integrity impact
Availability impact
Confidentiality impact
Accountability impact
A breach reveals trade secrets of a manufacturing firm. What's the most significant consequence?
Reduced system uptime
Loss of competitive advantage
Increased training needs
Regulatory compliance improvement
A retail company mandates secure handling of credit card data to comply with PCI-DSS. Why is this important?
To reduce storage costs
To meet international security standards
To prevent software bugs
To increase network speed
Employees are trained to identify phishing emails. This action emphasizes:
Confidentiality importance
Human element in security
Backup strategies
Vendor risk management
A government agency faces a ransomware attack. What's the most important reason to invest in security beforehand?
To reduce employee headcount
To ensure mission-critical services are not disrupted
To increase marketing budget
To avoid cloud migration
A school secures student records to prevent identity theft. This measure supports:
Integrity
Confidentiality
Availability
Usability
An IT service provider implements a disaster recovery site to resume operations quickly. This is important for:
Confidentiality
Business continuity
Integrity
Authentication
A software company faces reputational damage after a data breach. What does this highlight?
Security impacts extend beyond financial loss
Only availability is important
IT risks do not affect reputation
Reputation is unrelated to security
A financial institution ensures tamper-proof logging for transactions. This highlights:
Accountability importance
Availability importance
Confidentiality importance
Cost reduction
An airline encrypts customer passports stored in its database. Which principle is prioritized?
Availability
Confidentiality
Integrity
Accountability
A hospital ensures that lab results are accurate and not modified by unauthorized users. Which principle applies?
Integrity
Availability
Confidentiality
Usability
A logistics company deploys backup internet connections to prevent service downtime. This highlights the importance of:
Availability
Confidentiality
Integrity
Cost reduction
A company loses customer trust after repeated breaches. Why is security important in this case?
Trust and reputation are vital business assets
Security is only about compliance
Only availability matters to customers
Security reduces hardware needs
A university invests in cybersecurity insurance. This reflects:
Integrity focus
Confidentiality focus
Risk transfer importance
Risk acceptance importance
A multinational enforces strict access control on R&D data. The importance of security here is:
Protecting intellectual property
Reducing energy use
Preventing redundancy
Improving entertainment options
A cloud provider guarantees data availability via SLA agreements. Which aspect of importance does this demonstrate?
Integrity of data
Availability assurance
Confidentiality enforcement
Authentication guarantee
A hacker exploits a weak password to gain access to a company's database. What is the weak password considered?
Threat
Vulnerability
Risk
Control
An employee accidentally sends sensitive files to the wrong client. This incident is best classified as:
Insider threat (unintentional)
Insider threat (malicious)
External threat
Risk transfer
A company identifies that outdated software could be exploited by malware. Which term describes this situation?
Threat
Risk
Vulnerability
Safeguard
A DDoS attack overwhelms an e-commerce site, causing downtime. This represents:
Loss of confidentiality
Threat to availability
Integrity violation
Risk transfer
An attacker sends fake invoices to finance staff, tricking them into paying. What type of threat is this?
Malware
Social engineering
Denial of Service
Insider attack
An organization stores critical data on a server with no backup. The absence of a backup represents:
Risk avoidance
Vulnerability
Control
Threat
A disgruntled employee installs spyware on company laptops. This is an example of:
Internal threat
External threat
Accidental error
Vulnerability
An IT auditor notes that employees share their login credentials. What does this practice create?
Control
Vulnerability
Threat
Safeguard
A security analyst discovers that a mobile app stores passwords in plain text. This is an example of:
Control
Vulnerability
Threat
Safeguard
An attacker floods a web server with traffic from multiple compromised systems. This type of attack is:
SQL injection
Man-in-the-middle
Distributed Denial of Service (DDoS)
Buffer overflow
A security analyst discovers that a mobile app stores passwords in plain text. This is an example of:
Threat
Vulnerability
Risk treatment
Safeguard
A company hosts data on a third-party cloud service. The risk here is mainly due to:
Risk transference
Shared responsibility vulnerabilities
Firewall misconfiguration
Incident response failure
A virus infects an employee's laptop after opening a malicious email attachment. The virus is a:
Threat
Vulnerability
Safeguard
Control
An airport Wi-Fi network does not require encryption. What is this called?
Safeguard
Threat
Vulnerability
Control
A business keeps critical customer data in a single server with no redundancy. Which risk is most likely?
Data tampering
System unavailability
Malware infection
Insider threat
A company allows USB devices to connect without restrictions. Which type of weakness is this?
Technical vulnerability
Administrative control
Physical control
Safeguard
Hackers exploit a software flaw in a web app to steal customer data. The flaw is considered:
Threat
Vulnerability
Safeguard
Control
A cybercriminal creates fake login pages to steal credentials. This is an example of:
Phishing attack
Malware infection
Insider attack
Social engineering (non-technical)
A security team identifies that weak encryption was used in data storage. This weakness is:
Threat
Vulnerability
Control
Safeguard
A company detects unusual outbound traffic from its server. What does this indicate?
Preventive control
Possible data exfiltration threat
Availability assurance
Corrective action
An organization determines that if a server fails, it will cause financial loss. What term describes this?
Threat
Risk
Control
Safeguard
A bank evaluates the potential impact if its ATM system fails. This activity is part of:
Threat modeling
Risk assessment
Risk transfer
Vulnerability patching
A hospital estimates the damage cost if patient data is leaked. Which risk assessment step is this?
Risk identification
Impact analysis
Threat detection
Vulnerability scanning
An IT team lists all critical assets and classifies them by importance. Which stage of risk assessment is this?
Asset identification
Threat analysis
Risk mitigation
Control selection
A company calculates the likelihood and potential loss of a ransomware attack. What is this process called?
Business continuity planning
Risk quantification
Control implementation
Safeguard monitoring
During an audit, a financial firm identifies insider threats as high probability but low impact. This classification refers to:
Risk prioritization
Safeguard assignment
Threat elimination
Policy enforcement
A retail store ranks risks from highest to lowest based on likelihood and impact. What technique is used?
Risk transference
Risk ranking / prioritization
Risk avoidance
Incident response
A bank assigns numerical values to estimate potential yearly loss from cyber fraud. This is called:
Qualitative risk analysis
Quantitative risk analysis
Residual risk analysis
Vulnerability testing
A company uses heat maps to show risk levels visually. Which risk assessment method is this?
Quantitative
Qualitative
Preventive
Corrective
A manager asks, "What is the chance this system will be attacked, and what is the potential damage?" This refers to:
Risk appetite
Risk assessment
Control monitoring
Incident detection
A company performs penetration testing to identify weak spots. This helps in:
Risk identification
Risk transfer
Risk acceptance
Risk avoidance
A hospital assesses if an outdated firewall could allow intrusions. Which factor is analyzed?
Threat
Vulnerability
Impact
Control effectiveness
A cloud provider evaluates how service downtime would affect customers. This is an example of:
Availability risk assessment
Vulnerability analysis
Threat elimination
Technical control
A company finds its online payment system vulnerable but unlikely to be exploited. How should this be classified?
High risk
Medium risk
Low risk
No risk
A government agency calculates annualized loss expectancy (ALE) from data breaches. Which assessment method is used?
Qualitative
Quantitative
Compensating
Corrective
A school rates the risk of ransomware as "high" without exact numbers. This is:
Quantitative analysis
Qualitative analysis
Residual analysis
Technical assessment
A company measures how long it can continue operations during a disaster. Which concept applies?
Mean Time Between Failures (MTBF)
Maximum Tolerable Downtime (MTD)
Residual risk
Business continuity testing
A bank uses past incident data to estimate future risks. This approach is:
Predictive risk analysis
Preventive control
Detective control
Residual risk estimation
A retail company identifies credit card fraud as its top risk. What comes next in risk assessment?
Control implementation
Risk transfer
Risk mitigation planning
Risk monitoring
An audit reveals that even after applying controls, some risk remains. This is called:
Residual risk
Accepted risk
Avoided risk
Eliminated risk
A hospital compares risks against its tolerance levels. This is defining:
Risk appetite
Risk assessment
Risk transfer
Incident response
A company installs firewalls and IDS to reduce cyber-attack chances. This strategy is:
Risk transfer
Risk avoidance
Risk mitigation
Risk acceptance
A bank moves its data to a third-party insured cloud provider. This represents:
Risk transfer
Risk avoidance
Risk mitigation
Risk elimination
A business discontinues an insecure online service to avoid attacks. This is:
Risk transfer
Risk avoidance
Risk acceptance
Risk mitigation
A startup accepts minor risks because mitigation costs are higher than potential loss. Which strategy is this?
Risk transfer
Risk avoidance
Risk mitigation
Risk acceptance
A hospital uses insurance to cover financial losses from data breaches. This is an example of:
Risk mitigation
Risk acceptance
Risk transfer
Risk avoidance
A company installs UPS and backup generators to reduce downtime. Which strategy is applied?
Risk avoidance
Risk mitigation
Risk transfer
Risk acceptance
A firm decommissions an old server that poses security risks. Which strategy is this?
Risk acceptance
Risk avoidance
Risk transfer
Risk mitigation
A bank decides not to patch a minor software bug since the impact is negligible. This is:
Risk acceptance
Risk transfer
Risk mitigation
Risk avoidance
A government agency outsources security operations to a managed service provider. This is:
Risk transfer
Risk avoidance
Risk mitigation
Risk acceptance
A company invests in staff training to prevent phishing attacks. Which strategy is applied?
Risk mitigation
Risk transfer
Risk avoidance
Risk acceptance
An online retailer uses redundant servers across multiple regions. This demonstrates:
Risk avoidance
Risk mitigation
Risk transfer
Risk acceptance
A business uses cyber insurance but also implements firewalls. Which approach is used?
Mixed (transfer + mitigation)
Avoidance only
Acceptance only
No strategy
A manufacturing company stops using outdated software with known flaws. Which risk strategy is applied?
Risk mitigation
Risk avoidance
Risk transfer
Risk acceptance
A retailer accepts the risk of small-scale fraud as part of operations. This is an example of:
Risk avoidance
Risk mitigation
Risk acceptance
Risk transfer
A firm encrypts data to reduce damage if intercepted. Which risk strategy is this?
Risk mitigation
Risk transfer
Risk avoidance
Risk acceptance
A university disables a vulnerable online portal permanently. This is:
Risk avoidance
Risk mitigation
Risk transfer
Risk acceptance
A company outsources its payroll system to a secure third-party vendor. This represents:
Risk transfer
Risk mitigation
Risk acceptance
Risk avoidance
A small business buys insurance but also accepts minimal risks for cost savings. This is:
Risk avoidance
Risk mitigation
Risk transfer + acceptance
No strategy
A hospital prioritizes investing in backup power over cosmetic website updates. This shows:
Risk prioritization and mitigation
Risk acceptance only
Risk avoidance only
Risk transfer
