NEW
Font size
WorksheetsSecurity + "Information Security" Quiz
Total questions: 35
Worksheet time: 1hrs 10mins
What principle of the CIA Triad is compromised when an attacker alters transaction logs?
Availability
Confidentiality
Integrity
Authentication
Which tool supports confidentiality in information systems?
Hashing
MFA
Backup
IDS
What does hashing primarily protect?
Availability
Confidentiality
Integrity
Usability
Why is encryption important for confidentiality?
It prevents data loss
It ensures data accuracy
It restricts unauthorized access
It improves system speed
Which CIA principle is targeted by a DDoS attack?
Integrity
Availability
Confidentiality
Authentication
Which framework helps organizations assess and improve cybersecurity
ISO 9001
NIST CSF
GDPR
HIPAA
What does ISO/IEC 27001 focus on?
Financial auditing
Data encryption
Information Security Management Systems
Employee training
What is the purpose of CIS Controls?
Legal compliance
Strategic budgeting
Prioritized cybersecurity actions
Marketing analytics
Observe this Scenario:
"FashionForward," a mid-sized online retailer, processes thousands of credit card transactions daily. To win a
major contract, they must prove compliance with the Payment Card Industry Data Security Standard (PCI
DSS), which is built upon the principles of the CIA Triad. They use the NIST CSF as their guide.
In the FashionForward scenario, what does the “Identify” phase involve?
Encrypting data
Cataloging assets
Monitoring logs
Practicing incident response
What compensating control could protect unpatchable legacy systems?
Encryption
MFA
Network segmentation
Antivirus software
What is the goal of a gap analysis?
To increase revenue
To compare current security to desired standards
To monitor employee behavior
To install firewalls
What risk does “shadow IT” introduce?
Improved productivity
Enhanced visibility
Data exposure
Faster backups
What tool helps communicate gap severity to non-technical stakeholders?
Firewall
Heat map
IDS
Encryption
What is a common vulnerability found in gap analyses?
Overuse of MFA
Unpatched systems
Excessive encryption
Too many backups
What should be prioritized when addressing gaps?
Cost
Employee feedback
Risk level
Vendor preference
What is the purpose of a control objective?
To increase system speed
To define desired security outcomes
To reduce employee turnover
To monitor financial performance
Which of the following is a technical preventive control?
Surveillance camera
SIEM
Encryption
Backup policy
What type of control is a security awareness training program?
Technical / Corrective
Administrative / Preventive
Physical / Detective
Technical / Detective
What control type is represented by a motion sensor?
Physical / Detective
Technical / Preventive
Administrative / Corrective
Technical / Corrective
What is the role of a backup policy?
Preventive
Detective
Corrective
Administrative
Who activates the Incident Response Plan during a phishing attack?
Executive Management
Legal Counsel
End User
CISO
What is the role of Legal & Compliance during a breach?
Isolate systems
Notify customers
Determine regulatory obligations
Train employees
Who is responsible for reporting suspicious emails?
IT Department
CISO
End User
HR
What is the responsibility of HR in a security incident?
Patch systems
Communicate with affected employees
Monitor network traffic
Encrypt data
Who approves the security budget?
IT Department
CISO
Executive Management
Legal Counsel
Scenario: Defending the University's Research Data
A university needs to protect groundbreaking but ethically sensitive AI research. The Control Objective is: "Ensure the confidentiality and integrity of AI research data."
In the university scenario, what control ensures data is only accessed by authorized roles?
IDS
RBAC
Backup
Heat map
What control detects unusual file access at 3 AM?
Encryption
Biometric lock
SIEM
MFA
What control helps recover data after ransomware?
MFA
Encrypted backups
IDS
RBAC
What physical control protects the server room?
Surveillance camera
Biometric lock
Motion sensor
Badge logs
Scenario: Defending the University's Research Data
A university needs to protect groundbreaking but ethically sensitive AI research. The Control Objective is:
"Ensure the confidentiality and integrity of AI research data."
What administrative control is used in the university scenario?
IDS
SIEM
Security training
Encryption
What factor should guide the decision to shut down a core app during an incident?
Employee satisfaction
Revenue impact vs. threat containment
Marketing strategy
Software licensing
What is a detective control?
Prevents incidents
Finds incidents
Fixes incidents
Encrypts data
What is the first step in the NIST CSF?
Protect
Detect
Identify
Respond
What is the role of HR in insider threat management?
Patch systems
Conduct background checks
Encrypt data
Monitor logs
What is the role of Legal & Compliance in a phishing incident?
Notify regulators
Isolate systems
Train employees
Encrypt data
