wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

IS116-CHAPTER5 LONG QUIZ

Total questions: 21

Worksheet time: 21mins

Name
Class
Date
1.

What is the primary driver for the constant threat of security breaches?

a)

Lack of security software on the market

b)

Cyber threats advancing faster than existing frameworks

c)

Employees refusing to follow security protocols

d)

The high cost of implementing security measures

2.

The Information Security Management Life Cycle (ISML) is important because it:

a)

Is a one-time project that secures an organization permanently.

b)

Replaces the need for a dedicated IT security team.

c)

Moves security from a one-time project to a continuous business function.

d)

Focuses solely on recovering from incidents after they happen.

3.

Which of the following best describes a strategic goal in information security?

a)

Deploy a new firewall by the end of the quarter.

b)

Implement a governance framework to minimize organizational security risk.

c)

Require all employees to change their passwords every 90 days.

d)

Install encryption software on all company laptops.

4.

A tactical action in information security is:

a)

Aligning security goals with business objectives.

b)

Conducting employee security training this quarter.

c)

Developing a long-term vision for data protection.

d)

Deciding to adopt the COBIT framework.

5.

The COBIT framework is primarily focused on:

a)

Providing a detailed code of practice for information security controls.

b)

Bridging the gap between business risks and technical controls.

c)

Offering a framework solely for responding to cyber-incidents.

d)

Certifying the physical security of data centers.

6.

Which framework is described as an "internationally recognized standard for establishing and maintaining an Information Security Management System (ISMS)"?

a)

NIST Cybersecurity Framework

b)

COBIT

c)

ISO/IEC 27002

d)

ITIL

7.

The NIST Cybersecurity Framework's core functions include:

a)

Identify, Protect, Detect, Respond, Recover

b)

Plan, Do, Check, Act

c)

Confidentiality, Integrity, Availability

d)

Strategize, Implement, Monitor, Improve

8.

A key role of a Technology Manager in governance is to:

a)

Solely focus on writing code for security applications.

b)

Translate high-level framework guidelines into actionable technical policies.

c)

Take full and sole responsibility for all security breaches.

d)

prevent the business leadership from being involved in security decisions.

9.

Integrating security early and throughout the system development lifecycle is a philosophy known as:

a)

Waterfall Development

b)

"Shifting Left" or DevSecOps

c)

Agile Scrambling

d)

Total Quality Management

10.

What is the relationship between strategy and the ISML?

a)

Strategy is a separate concept and has no relation to the ISML.

b)

The strategy sets the direction for the entire lifecycle.

c)

Tactics define the strategy, which then defines the ISML.

d)

The ISML is only concerned with tactical, day-to-day operations.

11.

The most appropriate framework for an information security office is often:

a)

NIST, due to its focus on critical infrastructure.

b)

ISO/IEC 27002, due to its detailed control sections.

c)

COBIT, due to its comprehensive approach to IT governance and business alignment.

d)

A custom framework developed in-house.

12.

Which function is NOT part of the implied core components of the Information Security Management Life Cycle?

a)

Implement security controls

b)

Ignore minor security threats

c)

Identify assets and risks

d)

Monitor security effectiveness

13.

Confidentiality, Integrity, and Availability in Information Security refers to:

(a)  

14.

What is a primary benefit of integrating risk management into the ISML?

a)

It allows an organization to completely eliminate all risks.

b)

It helps prioritize security actions based on identified vulnerabilities.

c)

It is a one-time activity that doesn't need repetition.

d)

It removes the need for security frameworks.

15.

The tactic of "deploying encryption for all data in transit" directly supports the strategic goal of:

a)

Reducing IT staffing costs.

b)

Improving network speed.

c)

Implementing controls to protect information confidentiality.

d)

Developing new software products.

16.

Which framework provides a "prioritized, flexible, and risk-based approach" for organizations?

a)

COBIT

b)

ISO/IEC 27002

c)

NIST Cybersecurity Framework

d)

ITIL

17.

From a manager's perspective, what is a key advantage of using a recognized framework like COBIT or ISO 27002?

a)

It guarantees that no security breaches will occur.

b)

It provides a structured way to demonstrate compliance and align IT with business goals.

c)

It automatically implements all necessary technical controls.

d)

It removes the need for employee security training.

18.

The concept of "Integrating security early in the development process" in DevSecOps means:

(a)  

19.

Why is information considered one of the most valuable assets of an organization?

4 lines
20.

The role of a Technology Manager as an "Alignment Champion" involves:

a)

Ensuring the IT department's goals are separate from the business's goals.

b)

Demonstrating how IT security supports and enables core business objectives.

c)

Championing for a lower IT budget.

d)

Aligning only with other technology vendors.

21.

Organizations must adapt a (a)   approach to information security: