wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Security + "Information Security" Quiz

Total questions: 35

Worksheet time: 1hrs 10mins

Name
Class
Date
1.

What principle of the CIA Triad is compromised when an attacker alters transaction logs?

a)

Availability

b)

Confidentiality

c)

Integrity

d)

Authentication

2.

Which tool supports confidentiality in information systems?

a)

Hashing

b)

MFA

c)

Backup

d)

IDS

3.

What does hashing primarily protect?

a)

Availability

b)

Confidentiality

c)

Integrity

d)

Usability

4.

Why is encryption important for confidentiality?

a)

It prevents data loss

b)

It ensures data accuracy

c)

It restricts unauthorized access

d)

It improves system speed

5.

Which CIA principle is targeted by a DDoS attack?

a)

Integrity

b)

Availability

c)

Confidentiality

d)

Authentication

6.

Which framework helps organizations assess and improve cybersecurity

a)

ISO 9001

b)

NIST CSF

c)

GDPR

d)

HIPAA

7.

What does ISO/IEC 27001 focus on?

a)

Financial auditing

b)

Data encryption

c)

Information Security Management Systems

d)

Employee training

8.

What is the purpose of CIS Controls?

a)

Legal compliance

b)

Strategic budgeting

c)

Prioritized cybersecurity actions

d)

Marketing analytics

9.

Observe this Scenario:

"FashionForward," a mid-sized online retailer, processes thousands of credit card transactions daily. To win a

major contract, they must prove compliance with the Payment Card Industry Data Security Standard (PCI

DSS), which is built upon the principles of the CIA Triad. They use the NIST CSF as their guide.

In the FashionForward scenario, what does the “Identify” phase involve?

a)

Encrypting data

b)

Cataloging assets

c)

Monitoring logs

d)

Practicing incident response

10.

What compensating control could protect unpatchable legacy systems?

a)

Encryption

b)

MFA

c)

Network segmentation

d)

Antivirus software

11.

What is the goal of a gap analysis?

a)

To increase revenue

b)

To compare current security to desired standards

c)

To monitor employee behavior

d)

To install firewalls

12.

What risk does “shadow IT” introduce?

a)

Improved productivity

b)

Enhanced visibility

c)

Data exposure

d)

Faster backups

13.

What tool helps communicate gap severity to non-technical stakeholders?

a)

Firewall

b)

Heat map

c)

IDS

d)

Encryption

14.

What is a common vulnerability found in gap analyses?

a)

Overuse of MFA

b)

Unpatched systems

c)

Excessive encryption

d)

Too many backups

15.

What should be prioritized when addressing gaps?

a)

Cost

b)

Employee feedback

c)

Risk level

d)

Vendor preference

16.

What is the purpose of a control objective?

a)

To increase system speed

b)

To define desired security outcomes

c)

To reduce employee turnover

d)

To monitor financial performance

17.

Which of the following is a technical preventive control?

a)

Surveillance camera

b)

SIEM

c)

Encryption

d)

Backup policy

18.

What type of control is a security awareness training program?

a)

Technical / Corrective

b)

Administrative / Preventive

c)

Physical / Detective

d)

Technical / Detective

19.

What control type is represented by a motion sensor?

a)

Physical / Detective

b)

Technical / Preventive

c)

Administrative / Corrective

d)

Technical / Corrective

20.

What is the role of a backup policy?

a)

Preventive

b)

Detective

c)

Corrective

d)

Administrative

21.

Who activates the Incident Response Plan during a phishing attack?

a)

Executive Management

b)

Legal Counsel

c)

End User

d)

CISO

22.

What is the role of Legal & Compliance during a breach?

a)

Isolate systems

b)

Notify customers

c)

Determine regulatory obligations

d)

Train employees

23.

Who is responsible for reporting suspicious emails?

a)

IT Department

b)

CISO

c)

End User

d)

HR

24.

What is the responsibility of HR in a security incident?

a)

Patch systems

b)

Communicate with affected employees

c)

Monitor network traffic

d)

Encrypt data

25.

Who approves the security budget?

a)

IT Department

b)

CISO

c)

Executive Management

d)

Legal Counsel

26.

Scenario: Defending the University's Research Data

A university needs to protect groundbreaking but ethically sensitive AI research. The Control Objective is: "Ensure the confidentiality and integrity of AI research data."

In the university scenario, what control ensures data is only accessed by authorized roles?

a)

IDS

b)

RBAC

c)

Backup

d)

Heat map

27.

What control detects unusual file access at 3 AM?

a)

Encryption

b)

Biometric lock

c)

SIEM

d)

MFA

28.

What control helps recover data after ransomware?

a)

MFA

b)

Encrypted backups

c)

IDS

d)

RBAC

29.

What physical control protects the server room?

a)

Surveillance camera

b)

Biometric lock

c)

Motion sensor

d)

Badge logs

30.

Scenario: Defending the University's Research Data

A university needs to protect groundbreaking but ethically sensitive AI research. The Control Objective is:

"Ensure the confidentiality and integrity of AI research data."

What administrative control is used in the university scenario?

a)

IDS

b)

SIEM

c)

Security training

d)

Encryption

31.

What factor should guide the decision to shut down a core app during an incident?

a)

Employee satisfaction

b)

Revenue impact vs. threat containment

c)

Marketing strategy

d)

Software licensing

32.

What is a detective control?

a)

Prevents incidents

b)

Finds incidents

c)

Fixes incidents

d)

Encrypts data

33.

What is the first step in the NIST CSF?

a)

Protect

b)

Detect

c)

Identify

d)

Respond

34.

What is the role of HR in insider threat management?

a)

Patch systems

b)

Conduct background checks

c)

Encrypt data

d)

Monitor logs

35.

What is the role of Legal & Compliance in a phishing incident?

a)

Notify regulators

b)

Isolate systems

c)

Train employees

d)

Encrypt data