wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Topic 9: Principles of Secure Design (PP)

Total questions: 40

Worksheet time: 40mins

Name
Class
Date
1.

Fill in the blank: A policy is a (a)   document that outlines rules, guidelines, and principles for behavior within a specific context.

2.

Fill in the blank: Policies help to enforce (a)   and ensure that actions are aligned with established objectives, protecting sensitive information and resources.

3.

Fill in the blank: The first step in defining a security policy is to (a)   .

4.

Fill in the blank: The step that describes the technical and administrative measures to be implemented is called (a)   .

5.

Fill in the blank: A security policy outlines procedures for secure access, data handling, and (a)   response, ensuring consistency and accountability.

6.

Fill in the blank: This framework fosters a secure environment, reduces risks, and minimises potential (a)   .

7.

According to the passage, what does a user policy define?

a)

The acceptable use of IT resources for end-users

b)

The salary of employees

c)

The design of IT systems

d)

The marketing strategy

8.

According to the passage, user policies outline rules, guidelines, and responsibilities for which of the following groups?

a)

A) Employees, contractors, and other authorised individuals

b)

B) Only managers

c)

C) Only IT staff

d)

D) Customers only

9.

What is the purpose of User Account Management?

a)

To manage network devices

b)

To establish rules and procedures

c)

To monitor internet usage

d)

To set password requirements

10.

What do Password Policies dictate?

a)

Guidelines for acceptable behavior

b)

Minimum password length, complexity requirements, and expiration intervals to enhance security and prevent unauthorized access

c)

Procedures for deleting user accounts

d)

Rules for software installation

11.

What do Acceptable Use Policies define?

a)

Password expiration intervals

b)

Guidelines for acceptable behavior and activities when using company resources, including network access, computers, and software

c)

Procedures for creating user accounts

d)

Rules for hardware maintenance

12.

Selecting a password should follow which best practice?

a)

Use a combination of letters, numbers, and special characters

b)

Use your birthdate as your password

c)

Use the word 'password' as your password

d)

Use the same password for all accounts

13.

Password policies can enforce rules like minimum password length, special character requirements, and (a)  

14.

Acceptable use policies emphasise (a)   and legal use of technology.

15.

What do Acceptable Use Policies (AUPs) outline for users accessing an organization's network and systems?

a)

The hardware requirements for users

b)

The permissible and prohibited activities for users

c)

The cost of network access

d)

The physical security measures in place

16.

What is the purpose of Administrative Access Control? Fill in the blank: Administrative access control is critical for protecting sensitive systems. It ensures that only (a)   personnel can access system resources and manage them.

17.

What does Role-Based Access Control ensure? Fill in the blank: Role-based access control assigns permissions to users based on their roles within the organization. This ensures that users only have access to the (a)   they need to perform their duties.

18.

What is required in Multi-Factor Authentication? Fill in the blank: Multi-factor authentication requires users to provide multiple forms of (a)   before granting access. This helps prevent unauthorized access even if one factor is compromised.

19.

What is the purpose of Auditing and Logging? Fill in the blank: Auditing and logging track all administrative actions, providing a record of who accessed what and when. This helps identify potential security breaches and hold individuals (a)   .

20.

Access control is a fundamental security principle, which is implemented to prevent (a)   access to sensitive data and resources. (Fill in the blank)

21.

Which of the following is NOT mentioned as a layer of security in a robust access control system?

a)

A) Authentication

b)

B) Authorisation

c)

C) Encryption

d)

D) Least privilege

22.

Fill in the blank: Authentication verifies a user's identity through (a)   , multi-factor authentication, or biometrics.

23.

Fill in the blank: Authorization grants users access to specific resources based on their (a)   , permissions, and privileges.

24.

Fill in the blank: The Least Privilege Principle states that users should only have access to the resources they need to perform their jobs, minimizing the risk of (a)   access.

25.

Fill in the blank: Secure coding practices are essential for developing (a)   applications. They involve incorporating security considerations into every phase of the software development lifecycle.

26.

Which of the following is NOT mentioned as a vulnerability that secure coding helps prevent?

a)

A) SQL injection

b)

B) Cross-site scripting

c)

C) Buffer overflows

d)

D) Phishing attacks

27.

Organizations must implement secure coding standards and educate developers on best practices.

a)

True

b)

False

28.

Fill in the blank: Security testing should be an integral part of the software development lifecycle. Ensure the software is secure against (a)   and vulnerabilities.

29.

Fill in the blank: Standardise and document security practices to improve consistency and ensure (a)   to best practices.

30.

Which of the following offers a comprehensive framework for securing an organisation's digital assets?

a)

Security standards, guidelines, and procedures

b)

Financial audits

c)

Marketing strategies

d)

Customer feedback

31.

What do Compliance Frameworks provide to ensure organizations meet security requirements, such as PCI DSS for payment card data?

(a)  

32.

What do industry standards encompass to provide guidelines for organizations to implement security measures effectively?

(a)  

33.

Technical Standards cover technical aspects of security. Name one example mentioned in the list.

(a)  

34.

Industry standards may align with which type of requirements to ensure compliance with legal and ethical obligations?

(a)  

35.

Which of the following is detailed in internal security guidelines for handling sensitive data, ensuring confidentiality and integrity?

a)

Data Protection

b)

Access Control

c)

Incident Response

d)

Best Practices

36.

Which protocol is included in internal security guidelines for responding to security incidents, such as data breaches or unauthorized access?

a)

Data Protection

b)

Incident Response

c)

Best Practices

d)

Access Control

37.

What do Standard Operating Procedures (SOPs) provide for security tasks?

a)

Step-by-step instructions for security tasks,

b)

Emergency plans for security incidents

c)

Training programs for employees

d)

Audit procedures for security assessments

38.

Which documented security procedure defines actions to take during security incidents, including communication protocols, escalation procedures, and mitigation strategies?

a)

Security Audit Procedures

b)

Emergency Response Plans

c)

Security Awareness Training

d)

Standard Operating Procedures (SOPs)

39.

Security Audit Procedures outline the process for conducting regular security assessments to identify vulnerabilities and non-compliance with security policies.

a)

True

b)

False

40.

What is the main purpose of Security Awareness Training?

(a)