wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Governance & ManagementBeginner Quiz

Total questions: 30

Worksheet time: 15mins

Name
Class
Date
1.

Which term describes the system by which an organization directs and controls IT security and determines who is authorized to make decisions?

a)

IT Security Management

b)

IT Security Governance

c)

Risk Mitigation

d)

Technical Control

2.

The primary responsibility of IT security Management is concerned with:

a)

Specifying the accountability framework.

b)

Determining who has the final decision-making power.

c)

Making decisions to mitigate risks and implementing controls.

d)

Aligning security strategies with business objectives.

3.

Which of the following activities is generally considered part of the Governance Process according to the COBIT domains mentioned?

a)

Plan

b)

Build

c)

Direct

d)

Run

4.

IT Security Governance ensures that security strategies are aligned with which organizational element?

a)

Employee training schedules

b)

Incident response technical tools

c)

Business objectives and regulations

d)

Financial audit reports

5.

Which body is typically an elected group of individuals that represents shareholders and sets policies for corporate management and oversight?

a)

Steering Committee

b)

Project Manager

c)

Board of Directors

d)

Incident Response Team

6.

Which type of control involves a training program, policy, or procedure designed to change the behavior of people?

a)

Physical Control

b)

Technical Control

c)

Compensating Control

d)

Administrative Control

7.

A strict security policy stating severe consequences for employees if violated is an example of which type of deterrent control?

a)

Physical

b)

Technical

c)

Administrative

d)

Detective

8.

Which of the following is an example of a Physical Control?

a)

Access Control Lists (ACLs)

b)

Encryption

c)

Security Guards

d)

Antivirus software

9.

A proxy server that redirects a user to a warning page when they attempt to access a restricted site is an example of a:

a)

Physical Deterrent Control

b)

Administrative Detective Control

c)

Technical Deterrent Control

d)

Physical Preventive Control

10.

Encryption and Smart Cards are examples of which broad category of security controls?

a)

Administrative Controls

b)

Physical Controls

c)

Technical Controls

d)

Detective Controls

11.

Which document type details specific steps/requirements to fulfill policy objectives and is generally more detailed than a policy?

a)

Framework

b)

Procedure

c)

Standard

d)

Baseline

12.

Compliance is the adherence of a company to a certain standard or guidelines and is typically driven by regulatory requirements (law) or which internal requirement?

a)

Standards

b)

Frameworks

c)

Procedures

d)

Policies

13.

Which well-known regulatory framework sets security standards for organizations that process or store credit card information?

a)

GDPR

b)

HIPAA

c)

PCI DSS

d)

ISO 27001

14.

Which document type consists of a set sequence of necessary activities that performs a specific security task or function, designed to be followed as a consistent, repetitive cycle?

a)

Policy

b)

Standard

c)

Procedure

d)

Framework

15.

What is the leading international standard that details requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS)?

a)

NIST Cybersecurity Framework

b)

ISO/IEC 27001

c)

PCI DSS

d)

HIPAA

16.

A cybersecurity framework, such as NIST or ISO 27000, serves primarily as a roadmap to organize which type of activities for an organization?

a)

System Development Life Cycle (SDLC) activities

b)

Employee onboarding and offboarding activities

c)

Cybersecurity risk management activities

d)

Vendor selection and procurement activities

17.

The NIST Cybersecurity Framework identifies five core functions. Which of the following is NOT one of the five functions?

a)

Protect

b)

Detect

c)

Mitigate

d)

Recover

18.

The process of managing information security risks for an organization is known as:

a)

Incident Handling

b)

Operational Security (OPSEC)

c)

Risk Management

d)

Compliance Auditing

19.

Which term is defined as a known weakness of an asset that can be exploited by one or more attackers?

a)

Risk

b)

Threat

c)

Vulnerability

d)

Incident

20.

Which term refers to a potential circumstance or event that is measured by the extent to which an entity is threatened, typically a function of adverse impact and likelihood of occurrence?

a)

Threat

b)

Vulnerability

c)

Risk

d)

Control

21.

Which risk mitigating strategy involves not performing any activity that may carry risk, such as declining to take a stake in a high-risk industry?

a)

Risk Acceptance

b)

Risk Transference

c)

Risk Limitation

d)

Risk Avoidance

22.

Which step of the Operational Security (OPSEC) process involves identifying sensitive data, intellectual property, and customer/employee information?

a)

Identify possible threats

b)

Analyze security holes

c)

Get countermeasures in place

d)

Identify your sensitive data

23.

Which step in the NIST Cybersecurity Framework involves making a list of all equipment, software, and data the business uses?

a)

Protect

b)

Identify

c)

Detect

d)

Respond

24.

In the RACI matrix, the letter 'A' stands for the role that has the final decision-making authority and accountability for completion, with only one person assigned this per task. What does 'A' represent?

a)

Adviser

b)

Accountable

c)

Authorized

d)

Analyst

25.

According to the RACI matrix, which role is an adviser or subject matter expert who is consulted before a decision or action?

a)

Responsible

b)

Accountable

c)

Consulted

d)

Informed

26.

Incident Handling is defined as the summary of processes and predefined procedural actions to effectively and actionably manage an incident, focusing on which aspects?

a)

Technical analysis and containment tools

b)

Logistics, communication, and coordination

c)

Code review and patch deployment

d)

External law enforcement reporting

27.

Which incident handling stage involves performing a root cause analysis, process review, and formally documenting lessons learned?

a)

Containment

b)

Investigation

c)

Recovery

d)

Follow-up

28.

Which risk mitigating strategy involves the contractual shifting of a pure risk from one party to another, such as purchasing an insurance policy?

a)

Risk Limitation

b)

Risk Avoidance

c)

Risk Acceptance

d)

Risk Transference

29.

According to the COBIT domains, which two activities fall under the Management Processes and relate to ensuring performance, compliance, and control?

a)

Direct and Evaluate

b)

Plan and Build

c)

Run and Monitor

d)

Acquire and Implement

30.

A Steering Committee is described as an advisory body whose guiding principles include giving Strategic Direction and performing what other key action?

a)

Implementing technical controls

b)

Appointing executive officers

c)

Supporting the Project/Programme Manager

d)

Designing the network architecture