wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

ITS 105 Cybersecurity - Obj 1.1 - Common Security Principals

Total questions: 11

Worksheet time: 6mins

Name
Class
Date
1.

A proactive cybersecurity process that involves configuring systems, networks, and applications to reduce vulnerabilities and minimize the attack surface, making them more resistant to unauthorized access and cyberattacks

a)

Security Principal Hardening (1.1)

b)

Network Access Control (1.1)

c)

Security Threat Monitoring (1.1)

d)

Data Encryption Protocol (1.1)

2.

The Center for Internet Security (CIS) published the CIS Critical Security Controls (CSC) to help organizations better defend against known attacks by distilling key security concepts into actionable controls to achieve greater overall cybersecurity defense.

a)

OWASP Security Guidelines (1.2)

b)

NIST Cybersecurity Framework (1.2)

c)

CIS Critical Security Controls (1.2)

d)

COBIT Security Controls (1.2)

3.

______ Is to layer multiple, varied security controls across physical, technical, and administrative domains, creating redundancy so that if one layer of defense fails, others remain to stop or slow an attack.

a)

Basic Security Measures (1.1)

b)

Defense-in-Depth (1.1)

c)

Minimal Security Approach (1.1)

d)

Single-Layer Security (1.1)

4.

Is a central model for developing effective security policies and controls within organizations.

a)

CIS Critical Security Controls (1.2)

b)

NIST Cybersecurity Framework (CSF) (1.2)

c)

ISO/IEC 2700 (1.2)

d)

CIA Triad (1.1)

5.

Establishes the rules, responsibilities, and processes necessary to protect an organization’s information assets. It ensures that cybersecurity efforts align with the organization’s goals and comply with legal and regulatory requirements.

a)

Cybersecurity Audit Framework (1.1)

b)

Security Compliance Procedures (1.1)

c)

Security Governance Principles (1.1)

d)

Information Security Training (1.1)

6.

_______ Is a structured approach to categorizing personal data within an organization based on its sensitivity, value, and regulatory requirements. This policy helps organizations identify, handle, and protect data effectively, ensuring compliance with GDPR and other data protection regulations.

a)

Data Classification & Retention Policies (1.1)

b)

CIS Critical Security Controls (1.2)

c)

NIST Cybersecurity Framework (CSF) (1.2)

d)

Security Governance Principles (1.1)

7.

Requires every person and every device that accesses a network must be secured regardless if it is within the organization or outside of it.

a)

Zero Trust Security (1.1)

b)

Implicit Access Security (1.1)

c)

Network Perimeter Security (1.1)

d)

Traditional Trust Model (1.1)

8.

______ Is a set of guidelines developed by the U.S. National Institute of Standards and Technology (NIST) to help organizations manage and mitigate cybersecurity risks. It draws from existing standards, guidelines, and best practices to provide a flexible and scalable approach to cybersecurity. The framework provides a high-level taxonomy of cybersecurity outcomes and offers a methodology for assessing and managing those outcomes

a)

NIST Cybersecurity Framework (CSF) (1.2)

b)

Data Classification & Retention Policies (1.1)

c)

Zero Trust Security (1.1)

d)

CIS Critical Security Controls (1.2)

9.

_______ Emphasizes the importance of identifying and assessing information security risks. Organizations are required to implement risk management processes to identify potential threats, evaluate their impact, and develop appropriate mitigation strategies

a)

ISO/IEC 27002 Guidelines (1.2)

b)

ISO/IEC 2700 (1.2)

c)

ISO/IEC 27003 Standards (1.2)

d)

ISO/IEC 27001 Certification (1.2)

10.

AI privacy refers to how artificial intelligence systems collect, store, and use personal data. Key concerns include surveillance, data misuse, and lack of transparency. Laws like GDPR and CCPA aim to protect users but enforcement varies.

a)

Transparency (including AI use cases) (1.1)

b)

Accessibility (including AI use cases) (1.1

c)

Integrity (including AI use cases) (1.1)

d)

Privacy (including AI use cases) (1.1)

11.

Outlines moral principals for professionals, emphasizing principals like Honesty, Confidentiality, Integrity, and societal well-being to guide ethical decision-making and protect data, systems, and networks from harm.

a)

Security Compliance Framework (1.1)

b)

Ethical Hacking Guidelines (1.1)

c)

Code of Ethics (1.1)

d)

Data Protection Policy (1.1)