wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Midterm Prep Prt 1

Total questions: 66

Worksheet time: 33mins

Name
Class
Date
1.

There are three general causes of unethical and illegal behavior: _____, Accident, and Intent.

a)

Curiosity

b)

Revenge

c)

Ignorance

d)

None of the other answers are correct

2.

Security _____ are the areas of trust within which users can freely communicate.

a)

layers

b)

perimeters

c)

rectangles

d)

domains

3.

_____ is a professional association that focuses on auditing, control, and security. The membership comprises both technical and managerial professionals.

a)

ISACA

b)

EC-Council

c)

Information Systems Security Association (ISSA)

4.

_____ uses a number of hard drives to store information across multiple drive units.

a)

Legacy backup

b)

Virtualization

c)

Continuous database protection

d)

RAID

5.

The CPMT should include a _____ who is a high-level manager to support, promote, and endorse the findings of the project and could be the COO or (ideally) the CEO/president.

a)

project manager

b)

executive-in-charge

c)

project instigator

d)

champion

6.

_________ of information is the quality or state of being genuine or original.

a)

Authorization

b)

Confidentiality

c)

Authenticity

d)

Spoofing

7.

_________ security addresses the issues necessary to protect the tangible items, objects, or areas of an organization from unauthorized access and misuse.

a)

Object

b)

Physical

c)

Standard

8.

_______ security addresses the issues necessary to protect the tangible items, objects, or areas of an organization from unauthorized access and misuse.

a)

Object

b)

Physical

c)

Standard

d)

Personal

9.

The _____ hijacking attack uses IP spoofing to enable an attacker to impersonate another entity on the network.

a)

FTP

b)

HTTP

c)

TCP

d)

WWW

10.

_____ equals the probability of a successful attack multiplied by the expected loss from a successful attack plus an element of uncertainty.

a)

Risk

b)

Loss frequency

c)

Loss magnitude

11.

Each of the following is a role for the crisis management response team EXCEPT:

a)

Keeping the public informed about the event

b)

Communicating with major customers and other stakeholders

c)

Supporting personnel and their loved ones during the crisis

d)

Informing local emergency services to respond to the crisis

12.

In the TVA worksheet, assets are placed into a matrix with threats and then the exposure of the assets to specific threats is explored by documenting _____

a)

value

b)

vulnerabilities

c)

variables

d)

verifications

13.

Which of the following is an example of a Trojan horse program?

a)

Klez

b)

Happy99.exe

c)

MyDoom

d)

Netsky

14.

People with the primary responsibility for administering the systems that house the information used by the organization perform the role of ____.

a)

End users

b)

Security professionals

15.

Which of these is NOT a unique function of information security management?

a)

hardware

b)

programs

c)

planning

d)

policy

16.

In 2002, Congress passed the Federal Information Security Management Act (FISMA), which mandates that all federal agencies _____

a)

provide security awareness training

b)

develop policies and procedures based on risk assessments

c)

periodic assessment of risk

d)

all of the other answers are correct

17.

The _____ is the high-level information security policy that sets the strategic direction, scope, and tone for all of an organization’s security efforts.

a)

GSP

b)

EISP

c)

ISSP

d)

SysSP

18.

In a _____, assets or threats can be prioritized by identifying criteria with differing levels of importance, assigning a score for each of the criteria, and then summing and ranking those scores.

a)

risk management program

b)

threat assessment

c)

data classification scheme

d)

weighted table analysis

19.

Flaws or weaknesses in an information asset, security procedure, design, or control that can be exploited accidentally or on purpose to breach security are known as _____

a)

threats

b)

exploits

c)

vulnerabilities

d)

events

20.

In 1993, the first _____ conference was held in Las Vegas. Originally, it was established as a gathering for people interested in information security, including authors, lawyers, government employees, and law enforcement officials.

a)

CyberCom

b)

DEFCON

c)

World Security

21.

A threat _____ is an evaluation of the threats to information assets, including a determination of their likelihood of occurrence and potential impact of an attack.

a)

search

b)

review

c)

assessment

d)

investigation

22.

Which of the following is NOT one of the categories recommended for categorizing information assets?

a)

Firmware

b)

Hardware

c)

Procedures

d)

People

23.

A technique used to compromise a system is known as a(n) ___________.

a)

access method

b)

exploit

c)

risk

d)

asset

24.

The _____ risk treatment strategy attempts to eliminate or reduce any remaining uncontrolled risk through the application of additional controls and safeguards.

a)

acceptance

b)

transference

c)

termination

d)

mitigation

25.

A(n) _____ is an authorization issued by an organization for the repair, modification, or update of a piece of equipment.

a)

CTO

b)

IP

c)

HTTP

d)

FCO

26.

The transfer of transaction data in real time to an off-site facility is called ____.

a)

electronic vaulting

b)

remote journaling

c)

off-site storage

d)

database shadowing

27.

Individuals who are assigned the task of managing a particular set of information and coordinating its protection, storage, and use are known as data _________?

a)

owners

b)

users

c)

analysts

d)

processors

28.

The maximum amount of time that a system resource can remain unavailable before there is an unacceptable impact on other system resources is ____.

a)

maximum tolerable downtime (MTD)

b)

work recovery time (WRT)

c)

recovery point objective (RPO)

d)

recovery time objective (RTO)

29.

An organization aggregates all local backups to a central repository and then backs up that repository to an online vendor with a ____ backup strategy.

a)

differential

b)

RAID

c)

disk-to-disk-to-tape

d)

disk-to-disk-to-cloud

30.

Which of the following acts is also widely known as the Gramm-Leach-Bliley Act?

a)

Communications Act

b)

Computer Security Act

c)

Health Insurance Portability and Accountability Act

d)

Financial Services Modernization Act

31.

______ is a network project that preceded the Internet.

a)

NIST

b)

ARPANET

c)

DES

d)

FIPS

32.

Standards may be published, scrutinized, and ratified by a group, as in formal or ____ standards.

a)

de facto

b)

de jure

c)

de formale

d)

de public

33.

Advance-Fee fraud is an example of a ______ attack.

a)

spam

b)

social engineering

c)

virus

d)

worm

34.

34. ______ are compromised systems that are directed remotely (usually by a transmitted command) by the attacker to participate in an attack.

a)

botnets

b)

firewalls

c)

proxies

d)

honeypots

35.

Which of the following is a term used to describe computers that have been compromised and are controlled remotely by an attacker?

a)

Helpers

b)

Drones

c)

Zombies

d)

Servants

36.

The _____ risk treatment strategy is the choice to do nothing to protect a vulnerability and to accept the outcome of its exploitation.

a)

mitigation

b)

defense

c)

acceptance

d)

transference

37.

Risk _____ is the application of security mechanisms to reduce the risks to an organization’s data and information systems.

a)

identification

b)

avoidance

c)

assessment

d)

treatment

38.

The redirection of legitimate user Web traffic to illegitimate Web sites with the intent to collect personal information is known as ______.

a)

phishing

b)

sniffing

c)

pharming

d)

spoofing

39.

An information system is the entire set of __________, people, procedures, and networks that enable the use of information resources in the organization.

a)

software

b)

hardware

c)

data

d)

All of the above

40.

The goals of information security governance include all but which of the following?

a)

Regulatory compliance by using information security knowledge and infrastructure to support minimum standards of due care

b)

Risk management by executing appropriate measures to manage and mitigate threats to information resources

c)

Strategic alignment of information security with business strategy to support organizational objectives

d)

Performance measurement by measuring, monitoring, and reporting information security governance metrics to ensure that organizational objectives are achieved

41.

The SETA program is a control measure designed to reduce the instances of _____ security breaches by employees.

a)

accidental

b)

intentional

c)

physical

d)

external

42.

A table of hash values and their corresponding plaintext values that can be used to look up password values if an attacker is able to steal a system’s encrypted password file is known as a(n) _____

a)

crack file

b)

crib

c)

dictionary

d)

rainbow table

43.

A _____ site provides only rudimentary services and facilities.

a)

warm

b)

commercial

c)

hot

d)

cold

44.

The Digital _____ Copyright Act is the American contribution to an international effort by the World Intellectual Properties Organization (WIPO) to reduce the impact of copyright, trademark, and privacy infringement.

a)

Information

b)

Master

c)

Millennium

d)

Management

45.

According to NIST SP 800-14's security principles, security should _____

a)

support the mission of the organization

b)

require a comprehensive and integrated approach

c)

be cost-effective

d)

All of the above

46.

Microsoft acknowledged that if you type a res:// URL (a Microsoft-devised type of URL) longer than _____ characters in Internet Explorer 4.0, the browser will crash.

a)

128

b)

64

c)

512

d)

256

47.

The average amount of time between hardware failures, calculated as the total amount of operation time for a specified number of units divided by the total number of failures, is known as ______.

a)

mean time to diagnose (MTTD)

b)

mean time to repair (MTTR)

c)

mean time between failure (MTBF)

d)

mean time to failure (MTTF)

48.

An information security _____ is a specification of a model to be followed during the design, selection, and initial and ongoing implementation of all subsequent security controls, including information security policies, security education, and training.

a)

model

b)

plan

c)

policy

d)

framework

49.

A _____ is an attack in which a coordinated stream of requests is launched against a target from many locations at the same time.

a)

virus

b)

spam

c)

distributed denial-of-service

d)

denial-of-service

50.

A(n) _____ plan is a plan for the organization’s intended efforts over the next several years (long-term).

a)

tactical

b)

strategic

c)

operational

d)

standard

51.

The _____ is a respected professional society that was established in 1947. Today it is “the world’s largest educational and scientific computing society.”

a)

EC-Council

b)

International Information Systems Security Certification Consortium, Inc.

c)

Information Systems Security Association (ISSA)

d)

Association for Computing Machinery

52.

A(n) _____ scheme is a formal access control methodology used to assign a level of confidentiality to an information asset and thus restrict the number of people who can access it.

a)

risk management

b)

security clearance

c)

data recovery

53.

_____ is simply how often you expect a specific type of attack to occur.

a)

ALE

b)

CBA

c)

SLE

d)

ARO

54.

Risk _____ defines the quantity and nature of risk that organizations are willing to accept as they evaluate the trade-offs between perfect security and unlimited accessibility.

a)

appetite

b)

benefit

c)

residual

d)

acceptance

55.

The _____ defines stiffer penalties for prosecution of terrorism-related activities.

a)

Gramm-Leach-Bliley Act

b)

USA PATRIOT Act

c)

Economic Espionage Act

d)

Sarbanes-Oxley Act

56.

Understanding the _____ context means understanding the impact of elements such as the business environment, the legal/regulatory/compliance environment, as well as the threat environment.

a)

internal

b)

external

c)

design

d)

risk evaluation

57.

The stated purpose of ISO/IEC 27002:2013 is to give guidelines for organizational information security standards and information security _____ practices.

a)

management

b)

implementation

c)

certification

d)

accreditation

58.

The Health Insurance Portability and Accountability Act of 1996, also known as the _____ Act, protects the confidentiality and security of health-care data by establishing and enforcing standards and by standardizing electronic data interchange.

a)

Gramm-Leach-Bliley

b)

Privacy

c)

Kennedy-Kessebaum

59.

The point in time before a disruption or system outage to which business process data can be recovered after an outage is ____.

a)

recovery point objective (RPO)

b)

maximum tolerable downtime (MTD)

c)

work recovery time (WRT)

d)

recovery time objective (RTO)

60.

A ____ is an agency that provides physical facilities in the event of a disaster for a fee.

a)

mobile site

b)

service bureau

c)

time-share

d)

cold site

61.

____ law comprises a wide variety of laws pertaining to relationships among individuals and organizations.

a)

Civil

b)

Criminal

c)

Constitutional

d)

Statutory

62.

________ was the first operating system to integrate security as one of its core functions.

a)

DOS

b)

UNIX

c)

ARPANET

d)

MULTICS

63.

____ is the rapid determination of the scope of the breach in the confidentiality, integrity, and availability of information and information assets during or just following an incident.

a)

Disaster assessment

b)

Damage assessment

c)

Incident response

d)

Containment development

64.

As each information asset is identified, categorized, and classified, a(n) ____ value must be assigned to it.

a)

relative

b)

positional

c)

secondary

d)

significant

65.

Digital forensics involves the _____, identification, extraction, documentation, and interpretation of digital media.

a)

preservation

b)

investigation

c)

confiscation

d)

determination

66.

The most common schedule for tape-based backup is a _____ backup, either incremental or differential, with a weekly off-site full backup.

a)

daily on-site

b)

hourly off-site

c)

daily off-site

d)

12-hour on-site