WorksheetsIAS MIDTERM
Total questions: 100
Worksheet time: 58mins
Name
Class
Date
1.
Which principle of the CIA triad ensures data is not modified without authorization?
a)
Integrity
b)
Availability
c)
Confidentiality
d)
Authenticity
e)
Accountability
2.
What is the main purpose of information assurance?
a)
To ensure confidentiality, integrity, and availability of data
b)
To design faster networks
c)
To improve software usability
d)
To upgrade hardware
e)
To replace outdated policies
3.
Which approach uses multiple layers of protection to secure systems?
a)
Defense in depth
b)
Access minimization
c)
Privileged escalation
d)
Static protection
e)
Single-tier strategy
4.
Which component of the CIA triad focuses on restricting data disclosure?
a)
Confidentiality
b)
Availability
c)
Integrity
d)
Auditability
e)
Adaptability
5.
The principle of least privilege helps an organization by
a)
Reducing access to only what is necessary for each user
b)
Allowing unlimited access to admins
c)
Increasing employee collaboration
d)
Disabling multi-factor authentication
e)
Sharing all accounts
6.
Which term describes a flaw that an attacker could exploit?
a)
Vulnerability
b)
Threat
c)
Impact
d)
Incident
e)
Control
7.
A potential event that could exploit a system weakness is called a
a)
Threat
b)
Control
c)
Policy
d)
Incident
e)
Exposure
8.
The likelihood of a threat exploiting a vulnerability represents
a)
Risk
b)
Policy
c)
Backup
d)
Countermeasure
e)
Recovery
9.
Which of the following is an example of a preventive control?
a)
Firewall
b)
Audit report
c)
Incident review
d)
Backup restoration
e)
Detection system
10.
Which control identifies an incident after it happens?
a)
Detective
b)
Preventive
c)
Corrective
d)
Compensating
e)
Directive
11.
A company purchases cybersecurity insurance. Which risk strategy is applied?
a)
Transfer
b)
Avoidance
c)
Mitigation
d)
Acceptance
e)
Retention
12.
What is the main focus of risk mitigation?
a)
Reducing the impact or likelihood of a risk
b)
Accepting all possible threats
c)
Documenting events only
d)
Disabling controls
e)
Delaying detection
13.
Which of the following is a corrective control?
a)
Data restoration from backup
b)
Firewall installation
c)
Password setup
d)
Training program
e)
Log audit
14.
Which organization provides the NIST SP 800 series guidelines?
a)
NIST
b)
ISO
c)
IEEE
d)
ISACA
e)
COBIT
15.
Which organization manages COBIT standards?
a)
ISACA
b)
ISO
c)
NIST
d)
IEEE
e)
ITIL
16.
Which international body created the ISO 27001 standard?
a)
ISO
b)
(ISC)²
c)
NIST
d)
ITIL
e)
CERT
17.
Which organization administers CISSP certification?
a)
(ISC)²
b)
ISACA
c)
NIST
d)
IEEE
e)
ISO
18.
The PDCA cycle stands for
a)
Plan, Do, Check, Act
b)
Prepare, Defend, Control, Audit
c)
Plan, Develop, Correct, Apply
d)
Prevent, Detect, Control, Assess
e)
Plan, Decide, Check, Apply
19.
During which PDCA phase are controls implemented?
a)
Do
b)
Plan
c)
Check
d)
Act
e)
Review
20.
The “Check” stage in PDCA focuses on
a)
Evaluating effectiveness of implemented controls
b)
Creating new security goals
c)
Documenting team structure
d)
Training new employees
e)
Backing up old systems
21.
The final “Act” phase of PDCA involves
a)
Applying corrective actions based on evaluations
b)
Planning additional layers
c)
Revising hardware
d)
Archiving test data
e)
Designing future standards
22.
Which document guides how an organization responds to security breaches?
a)
Incident Response Plan
b)
Risk Register
c)
Disaster Checklist
d)
Network Map
e)
Access Matrix
23.
What is the main objective of continuous monitoring?
a)
To detect deviations from expected security performance
b)
To speed up CPU processing
c)
To maintain user satisfaction
d)
To upgrade operating systems
e)
To reduce internet costs
24.
Which control type focuses on restoring normal operations after an incident?
a)
Corrective
b)
Detective
c)
Preventive
d)
Directive
e)
Physical
25.
The principle ensuring users are who they claim to be is called
a)
Authentication
b)
Authorization
c)
Auditing
d)
Identification
e)
Availability
26.
Which IA element defines actions allowed for an authenticated user?
a)
Authorization
b)
Accounting
c)
Integrity
d)
Validation
e)
Confidentiality
27.
The process of tracking and recording system activities is known as
a)
Auditing
b)
Authentication
c)
Availability
d)
Accounting
e)
Adaptation
28.
What term describes the remaining risk after controls are applied?
a)
Residual risk
b)
Inherited risk
c)
Avoided risk
d)
Latent risk
e)
Secondary risk
29.
Which statement best describes integrity?
a)
Assuring data is accurate and unchanged
b)
Ensuring information is accessible
c)
Protecting system speed
d)
Restricting user roles
e)
Recording login attempts
30.
Which of the following represents accountability in IAAA?
a)
Auditing
b)
Authentication
c)
Availability
d)
Adaptability
e)
Authorization
31.
Which type of threat exploits system software vulnerabilities?
a)
Technical threat
b)
Procedural threat
c)
Environmental threat
d)
Natural threat
e)
Accidental threat
32.
A fire damaging servers is an example of which threat type?
a)
Physical
b)
Technical
c)
Logical
d)
Intentional
e)
Social
33.
Which of the following demonstrates defense in depth?
a)
Firewall, antivirus, user training, and encryption
b)
Single password login
c)
Antivirus alone
d)
One admin account
e)
Policy without hardware support
34.
In IA, data that must remain accessible to users illustrates which principle?
a)
Availability
b)
Integrity
c)
Confidentiality
d)
Authenticity
e)
Auditing
35.
Which organization issues the Certified Information Security Manager (CISM) credential?
a)
ISACA
b)
(ISC)²
c)
ISO
d)
NIST
e)
IEEE
36.
Which of the following best defines risk management?
a)
Identifying, analyzing, and controlling threats to assets
b)
Installing anti-malware software
c)
Improving communication only
d)
Reporting to external vendors
e)
Disabling unused ports
37.
Which concept in IA prevents users from denying actions they performed?
a)
Non-repudiation
b)
Confidentiality
c)
Authorization
d)
Integrity
e)
Availability
38.
The main benefit of adopting international IA standards is
a)
Consistency with global best practices
b)
Reduced system redundancy
c)
Fewer employee trainings
d)
Faster downloads
e)
Lower internet fees
39.
Which PDCA phase identifies areas for improvement?
a)
Check
b)
Plan
c)
Do
d)
Act
e)
Execute
40.
The organization that created IT governance frameworks used worldwide is
a)
ISACA
b)
NIST
c)
COBIT
d)
ISO
e)
IEEE
41.
What is the goal of an Information Security Management System (ISMS)?
a)
To manage and improve data security systematically
b)
To train new programmers
c)
To install antivirus software
d)
To improve design layouts
e)
To produce business reports
42.
The term “availability” refers to
a)
Ensuring authorized users can access information when needed
b)
Restricting system uptime
c)
Encrypting all stored data
d)
Allowing public access
e)
Archiving unused accounts
43.
Which activity is most related to auditing?
a)
Reviewing system logs for compliance
b)
Blocking internet access
c)
Configuring firewalls
d)
Running encryption tasks
e)
Installing printers
44.
What is an example of a physical control?
a)
Security cameras
b)
Access passwords
c)
Encryption keys
d)
Firewall rules
e)
Incident logs
45.
Which organization is responsible for IT auditing and control certifications?
a)
ISACA
b)
NIST
c)
IEEE
d)
(ISC)²
e)
ISO
46.
What is the best example of a detective control in a network?
a)
Intrusion Detection System (IDS)
b)
Firewall
c)
Encryption
d)
Password rotation
e)
Locked server room
47.
The purpose of an access control policy is to
a)
Define who can access what information and under what conditions
b)
Store user passwords offline
c)
Upgrade computer hardware
d)
Eliminate all risk
e)
Reduce physical threats
48.
Which type of control verifies that implemented measures work as intended?
a)
Detective
b)
Corrective
c)
Preventive
d)
Directive
e)
Physical
49.
Which of the following is an example of a compensating control?
a)
Alternate safeguard used when primary controls are impractical
b)
A lengthy backup routine scheduled every quarter
c)
A redundant database replicated nightly in another region
d)
A costly biometric system not suited for small businesses
e)
A security checklist used only during audits
50.
In the risk management process, the first step is to
a)
Identify assets and potential threats
b)
Implement software-based countermeasures after incidents
c)
Train all personnel on regulatory frameworks before assessment
d)
Monitor system performance metrics continuously
e)
Conduct internal compliance reviews semiannually
51.
Which IA concept focuses on confirming that data originates from a trusted source?
a)
Authenticity
b)
Comprehensive encryption applied across multiple tiers
c)
Deep-packet inspection combined with signature verification
d)
A network design focusing on redundant paths
e)
A multilevel monitoring architecture for reliability
52.
A password combined with a fingerprint scan demonstrates
a)
Multi-factor authentication
b)
A policy encouraging complex phrase-based passwords only
c)
A standalone hardware-based identity validation token
d)
A fully automated login script to reduce human input
e)
A network-wide single sign-on system integrating cloud services
53.
What is the purpose of user awareness training in IA?
a)
Reduce human error and social-engineering risks
b)
Teach employees to configure advanced firewall scripts
c)
Require every staff member to memorize full regulatory codes
d)
Ensure that employees can manually patch all endpoints
e)
Help management redesign organizational structures
54.
Which statement best describes risk acceptance?
a)
Acknowledging a risk and deciding to tolerate it without further action
b)
Building layered mitigation plans that consume most of the budget
c)
Transferring liability completely to an external insurance partner
d)
Expanding technical infrastructure to absorb performance impact
e)
Documenting detailed threat trees for every asset category
55.
What is the role of a Business Continuity Plan (BCP)?
a)
Ensure essential operations continue after disruption
b)
Provide exhaustive vendor-selection procedures for hardware purchases
c)
Outline advertising strategies during technology downtime
d)
Serve as a communication script for stakeholder interviews
e)
Describe cost-benefit analyses for equipment maintenance
56.
Which control type aims to discourage potential security violations?
a)
Deterrent
b)
Preventive measures that isolate data inside secured vault environments
c)
Technical mechanisms monitoring transactions in real time
d)
Corrective activities performed during restoration phases
e)
Administrative responses addressing incident escalation paths
57.
The main objective of access control is to
a)
Regulate who or what can view or use resources
b)
Design complex authentication systems that require multiple passwords
c)
Ensure all users have identical resource visibility across departments
d)
Remove manual approval from every access process
e)
Integrate access policies directly into marketing campaigns
58.
In IA, “availability” is achieved primarily through
a)
Redundancy and reliable infrastructure
b)
Encrypted protocols with expanded packet sizes
c)
Strict endpoint isolation without redundancy
d)
Extensive documentation of hardware serial records
e)
Monthly replacement of all local servers
59.
Which scenario best illustrates integrity in information assurance?
a)
Data remains unchanged during transmission between systems
b)
Users repeatedly attempt unauthorized logins despite lockout
c)
Archived data is encrypted using long symmetric keys
d)
Backups are stored offsite every quarter
e)
Firewall logs show consistent packet drops for anomalies
60.
A company evaluates how a cyberattack could affect profits. This step reflects
a)
Risk impact assessment
b)
Long-term asset depreciation scheduling
c)
Quarterly financial balancing unrelated to threats
d)
Post-incident review for insurance reimbursements
e)
External vendor performance evaluation reports
61.
Which organization creates international information security standards?
a)
ISO
b)
National agencies that license consumer technologies
c)
Independent auditors specializing in forensic data recovery
d)
Private corporations providing cloud-based testing platforms
e)
Professional associations issuing local hardware guidelines
62.
The ISMS framework aims to
a)
Establish and improve security management systems
b)
Focus narrowly on network throughput optimization
c)
Create vendor-specific compliance audits for publicity
d)
Develop marketing dashboards for reporting uptime
e)
Serve as a hardware-maintenance planning document
63.
What is the importance of the “Check” phase in PDCA?
a)
Assess performance and compliance with policies
b)
Initiate hardware procurement for the next fiscal year
c)
Document promotional achievements for management reports
d)
Expand user privileges temporarily for testing
e)
Record the depreciation of software assets monthly
64.
Which organization provides COBIT for IT governance?
a)
ISACA
b)
Corporations that specialize in antivirus distribution
c)
National legislative boards drafting technology acts
d)
University consortiums coordinating open-source projects
e)
Private certification companies focused on cloud storage
65.
In the IAAA model, which process verifies identity before granting access?
a)
Authentication
b)
Auditing function that reviews account logs weekly
c)
Authorization sequence allocating resource permissions
d)
A debriefing mechanism following incident closure
e)
A redundancy test conducted during maintenance windows
66.
Which control responds immediately to an ongoing attack?
a)
Reactive
b)
Preventive defense embedded in organizational policies
c)
Administrative audit executed post-incident
d)
Strategic communication guideline for crisis management
e)
Quarterly review of vendor security certifications
67.
A company that encrypts sensitive data in transit is practicing
a)
Confidentiality
b)
Availability reinforced through multiple redundant circuits
c)
Integrity maintained via checksum replication
d)
Audit logging for access frequency analysis
e)
Accountability through employee tracking dashboards
68.
Which activity belongs to the “Plan” stage of PDCA?
a)
Setting objectives and defining security policies
b)
Collecting metrics after project completion
c)
Performing backup restoration of archived databases
d)
Conducting staff exit interviews at cycle end
e)
Publishing annual marketing reports
69.
The “Act” stage of PDCA emphasizes
a)
Improving and updating security processes
b)
Executing data entry to align accounting records
c)
Outsourcing documentation to external consultants
d)
Rotating encryption keys without verification
e)
Archiving internal communications for compliance only
70.
Which is the main goal of auditing in IA?
a)
Ensure compliance and accountability
b)
Analyze visual dashboards for executive reports
c)
Create new encryption algorithms for endpoints
d)
Enhance color-coded system documentation
e)
Prepare marketing insights for branding purposes
71.
Which of the following best defines a deterrent control?
a)
Discourages security violations through awareness and warnings
b)
Performs forensic evidence collection post-attack
c)
Implements data masking for confidential records
d)
Automates encryption on portable devices only
e)
Validates biometric access tokens quarterly
72.
Which risk management approach involves avoiding all actions that cause risk?
a)
Risk avoidance
b)
Comprehensive asset diversification to reduce losses
c)
Creating dual infrastructure for redundancy
d)
Delegating responsibility to external regulators
e)
Merging departments to share accountability
73.
When is residual risk calculated?
a)
After applying all security controls
b)
During recruitment of compliance officers
c)
Before reviewing external vendor contracts
d)
At the start of asset acquisition planning
e)
Before annual budgeting sessions
74.
What distinguishes ISACA from (ISC)²?
a)
ISACA focuses on governance and audit, (ISC)² on security certification
b)
(ISC)² oversees national technology legislation
c)
ISACA develops academic curricula for universities
d)
ISACA certifies industrial hardware engineers
e)
(ISC)² manages consumer-product cybersecurity policies
75.
Which certification demonstrates expertise in managing enterprise IT risk?
a)
CRISC
b)
A CISM credential focused on governance leadership
c)
A CISSP designation for advanced practitioners
d)
A vendor-specific certification for cloud networks
e)
A regional award for auditing excellence
76.
Which document defines who is responsible for protecting information assets?
a)
Security policy
b)
A corporate brochure listing departmental roles
c)
A quarterly review highlighting staff achievements
d)
A budget summary describing resource allocation
e)
A maintenance schedule for physical servers
77.
In IA, which element ensures data remains accurate during storage and transfer?
a)
Integrity
b)
Auditability through extended event logging
c)
Availability guaranteed by redundant links
d)
Confidentiality supported by multifactor controls
e)
Authenticity established via certificates
78.
A company conducts log reviews every week. This activity is a
a)
Detective control
b)
A preventive configuration designed before operations begin
c)
A corrective measure performed after outage resolution
d)
A deterrent policy intended to change behavior
e)
A compensating process filling design gaps
79.
Which statement best defines an ISMS?
a)
Structured framework for managing information security
b)
Document repository for system change requests
c)
Collection of proprietary encryption keys
d)
A periodic evaluation checklist for accountants
e)
Manual describing cloud-storage pricing
80.
The ISOIEC 27000 family of standards relates to
a)
Information Security Management
b)
Hardware energy optimization
c)
Software licensing enforcement
d)
Telecommunication billing processes
e)
Project portfolio administration
81.
Which of the following controls reduces damage after a breach?
a)
Corrective
b)
Preventive rule ensuring no unauthorized logins
c)
Directive regulation outlining future policies
d)
Detective alert used during audits
e)
Physical barrier isolating hardware rooms
82.
What is the main purpose of incident response?
a)
Minimize impact and restore operations
b)
Generate reports for corporate social responsibility
c)
Document supplier logistics in procurement
d)
Track financial statements for investors
e)
Expand marketing outreach to customers
83.
The process of verifying user identity and tracking actions is known as
a)
Authentication and Auditing
b)
Authorization and Validation
c)
Accounting and Review
d)
Integrity and Certification
e)
Access and Enumeration
84.
A strong password policy addresses which IA principle?
a)
Confidentiality
b)
Availability enhanced by redundancy
c)
Integrity maintained through data hashing
d)
Authenticity confirmed via encryption
e)
Auditability validated by reports
85.
Which organization sets federal cybersecurity standards in the United States?
a)
NIST
b)
ISO committee focusing on trade facilitation
c)
Private auditing boards evaluating corporations
d)
Regional associations designing ITIL templates
e)
Professional groups offering ethics seminars
86.
Which of the following demonstrates accountability?
a)
Recording user actions in audit logs
b)
Expanding unrestricted user privileges
c)
Removing trace logs after reviews
d)
Sharing one password among employees
e)
Deactivating monitoring to save power
87.
The main difference between preventive and detective controls is that
a)
Preventive controls stop events; detective controls identify them
b)
Detective controls occur before risk identification
c)
Preventive measures are purely administrative
d)
Detective measures eliminate all threats
e)
Preventive actions are entirely physical
88.
What is the goal of corrective controls?
a)
Restore normal operations after incidents
b)
Detect suspicious activity in real time
c)
Reduce costs of user training sessions
d)
Authorize temporary resource privileges
e)
Design long password requirements
89.
What is the function of a deterrent control?
a)
Discourage violations through warning or awareness
b)
Correct errors in archived transaction data
c)
Encrypt database tables for redundancy
d)
Repair corrupted firmware after outage
e)
Calibrate biometric scanners monthly
90.
What is the function of ISO 27005?
a)
Risk management in information security
b)
A user training outline for remote workers
c)
A vendor compliance checklist for procurement
d)
A hardware reliability testing guide
e)
A digital marketing data framework
91.
Which of the following is part of the IAAA model?
a)
Authorization
b)
Encryption standard applied to cloud storage
c)
Backup schedule used for archives
d)
Incident report template for analysis
e)
Training program for password resets
92.
What is the function of the “Monitor” step in the MSR model?
a)
Track and evaluate security performance
b)
Archive unused configuration data
c)
Plan future recruitment cycles
d)
Prepare promotional materials for stakeholders
e)
Disable redundant backup systems
93.
What is the importance of business impact analysis?
a)
Identifies critical functions and recovery priorities
b)
Determines tax obligations for technology assets
c)
Outlines vendor billing structures
d)
Measures customer satisfaction post-incident
e)
Evaluates electricity consumption across sites
94.
Which of the following best represents confidentiality?
a)
Protecting information from unauthorized disclosure
b)
Ensuring system reports are publicly accessible
c)
Guaranteeing nonstop availability regardless of maintenance
d)
Providing data redundancy to multiple third parties
e)
Encrypting archives for faster retrieval
95.
Which professional certification focuses on information systems auditing?
a)
CISA
b)
CISM
c)
CISSP
d)
CRISC
e)
ITIL
96.
Which PDCA phase ensures ongoing improvement?
a)
Act
b)
Plan
c)
Do
d)
Check
e)
Execute
97.
Which term best describes a process of assigning user rights?
a)
Authorization
b)
Authentication
c)
Auditing
d)
Integrity
e)
Documentation
98.
Which of the following best defines information assurance?
a)
Managing information risks to ensure data protection and reliability
b)
Installing faster computer hardware across the organization
c)
Developing custom applications for end users
d)
Testing prototypes of web-based systems
e)
Enhancing visual interfaces for mobile devices
99.
Explain how the principles of the CIA Triad (Confidentiality, Integrity, and Availability) can be applied in designing a secure e-commerce platform..
4 lines
100.
Describe how the PDCA (Plan-Do-Check-Act) cycle can be effectively implemented in establishing and maintaining an Information Security Management System (ISMS) within an organization.
4 lines
100 %
