NEW
Font size
WorksheetsGovernance & ManagementBeginner Quiz
Total questions: 30
Worksheet time: 15mins
Which term describes the system by which an organization directs and controls IT security and determines who is authorized to make decisions?
IT Security Management
IT Security Governance
Risk Mitigation
Technical Control
The primary responsibility of IT security Management is concerned with:
Specifying the accountability framework.
Determining who has the final decision-making power.
Making decisions to mitigate risks and implementing controls.
Aligning security strategies with business objectives.
Which of the following activities is generally considered part of the Governance Process according to the COBIT domains mentioned?
Plan
Build
Direct
Run
IT Security Governance ensures that security strategies are aligned with which organizational element?
Employee training schedules
Incident response technical tools
Business objectives and regulations
Financial audit reports
Which body is typically an elected group of individuals that represents shareholders and sets policies for corporate management and oversight?
Steering Committee
Project Manager
Board of Directors
Incident Response Team
Which type of control involves a training program, policy, or procedure designed to change the behavior of people?
Physical Control
Technical Control
Compensating Control
Administrative Control
A strict security policy stating severe consequences for employees if violated is an example of which type of deterrent control?
Physical
Technical
Administrative
Detective
Which of the following is an example of a Physical Control?
Access Control Lists (ACLs)
Encryption
Security Guards
Antivirus software
A proxy server that redirects a user to a warning page when they attempt to access a restricted site is an example of a:
Physical Deterrent Control
Administrative Detective Control
Technical Deterrent Control
Physical Preventive Control
Encryption and Smart Cards are examples of which broad category of security controls?
Administrative Controls
Physical Controls
Technical Controls
Detective Controls
Which document type details specific steps/requirements to fulfill policy objectives and is generally more detailed than a policy?
Framework
Procedure
Standard
Baseline
Compliance is the adherence of a company to a certain standard or guidelines and is typically driven by regulatory requirements (law) or which internal requirement?
Standards
Frameworks
Procedures
Policies
Which well-known regulatory framework sets security standards for organizations that process or store credit card information?
GDPR
HIPAA
PCI DSS
ISO 27001
Which document type consists of a set sequence of necessary activities that performs a specific security task or function, designed to be followed as a consistent, repetitive cycle?
Policy
Standard
Procedure
Framework
What is the leading international standard that details requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS)?
NIST Cybersecurity Framework
ISO/IEC 27001
PCI DSS
HIPAA
A cybersecurity framework, such as NIST or ISO 27000, serves primarily as a roadmap to organize which type of activities for an organization?
System Development Life Cycle (SDLC) activities
Employee onboarding and offboarding activities
Cybersecurity risk management activities
Vendor selection and procurement activities
The NIST Cybersecurity Framework identifies five core functions. Which of the following is NOT one of the five functions?
Protect
Detect
Mitigate
Recover
The process of managing information security risks for an organization is known as:
Incident Handling
Operational Security (OPSEC)
Risk Management
Compliance Auditing
Which term is defined as a known weakness of an asset that can be exploited by one or more attackers?
Risk
Threat
Vulnerability
Incident
Which term refers to a potential circumstance or event that is measured by the extent to which an entity is threatened, typically a function of adverse impact and likelihood of occurrence?
Threat
Vulnerability
Risk
Control
Which risk mitigating strategy involves not performing any activity that may carry risk, such as declining to take a stake in a high-risk industry?
Risk Acceptance
Risk Transference
Risk Limitation
Risk Avoidance
Which step of the Operational Security (OPSEC) process involves identifying sensitive data, intellectual property, and customer/employee information?
Identify possible threats
Analyze security holes
Get countermeasures in place
Identify your sensitive data
Which step in the NIST Cybersecurity Framework involves making a list of all equipment, software, and data the business uses?
Protect
Identify
Detect
Respond
In the RACI matrix, the letter 'A' stands for the role that has the final decision-making authority and accountability for completion, with only one person assigned this per task. What does 'A' represent?
Adviser
Accountable
Authorized
Analyst
According to the RACI matrix, which role is an adviser or subject matter expert who is consulted before a decision or action?
Responsible
Accountable
Consulted
Informed
Incident Handling is defined as the summary of processes and predefined procedural actions to effectively and actionably manage an incident, focusing on which aspects?
Technical analysis and containment tools
Logistics, communication, and coordination
Code review and patch deployment
External law enforcement reporting
Which incident handling stage involves performing a root cause analysis, process review, and formally documenting lessons learned?
Containment
Investigation
Recovery
Follow-up
Which risk mitigating strategy involves the contractual shifting of a pure risk from one party to another, such as purchasing an insurance policy?
Risk Limitation
Risk Avoidance
Risk Acceptance
Risk Transference
According to the COBIT domains, which two activities fall under the Management Processes and relate to ensuring performance, compliance, and control?
Direct and Evaluate
Plan and Build
Run and Monitor
Acquire and Implement
A Steering Committee is described as an advisory body whose guiding principles include giving Strategic Direction and performing what other key action?
Implementing technical controls
Appointing executive officers
Supporting the Project/Programme Manager
Designing the network architecture
