Font size
WorksheetsTopic 9: Principles of Secure Design (PP)
Total questions: 40
Worksheet time: 40mins
Fill in the blank: A policy is a (a) document that outlines rules, guidelines, and principles for behavior within a specific context.
Fill in the blank: Policies help to enforce (a) and ensure that actions are aligned with established objectives, protecting sensitive information and resources.
Fill in the blank: The first step in defining a security policy is to (a) .
Fill in the blank: The step that describes the technical and administrative measures to be implemented is called (a) .
Fill in the blank: A security policy outlines procedures for secure access, data handling, and (a) response, ensuring consistency and accountability.
Fill in the blank: This framework fosters a secure environment, reduces risks, and minimises potential (a) .
According to the passage, what does a user policy define?
The acceptable use of IT resources for end-users
The salary of employees
The design of IT systems
The marketing strategy
According to the passage, user policies outline rules, guidelines, and responsibilities for which of the following groups?
A) Employees, contractors, and other authorised individuals
B) Only managers
C) Only IT staff
D) Customers only
What is the purpose of User Account Management?
To manage network devices
To establish rules and procedures
To monitor internet usage
To set password requirements
What do Password Policies dictate?
Guidelines for acceptable behavior
Minimum password length, complexity requirements, and expiration intervals to enhance security and prevent unauthorized access
Procedures for deleting user accounts
Rules for software installation
What do Acceptable Use Policies define?
Password expiration intervals
Guidelines for acceptable behavior and activities when using company resources, including network access, computers, and software
Procedures for creating user accounts
Rules for hardware maintenance
Selecting a password should follow which best practice?
Use a combination of letters, numbers, and special characters
Use your birthdate as your password
Use the word 'password' as your password
Use the same password for all accounts
Password policies can enforce rules like minimum password length, special character requirements, and (a)
Acceptable use policies emphasise (a) and legal use of technology.
What do Acceptable Use Policies (AUPs) outline for users accessing an organization's network and systems?
The hardware requirements for users
The permissible and prohibited activities for users
The cost of network access
The physical security measures in place
What is the purpose of Administrative Access Control? Fill in the blank: Administrative access control is critical for protecting sensitive systems. It ensures that only (a) personnel can access system resources and manage them.
What does Role-Based Access Control ensure? Fill in the blank: Role-based access control assigns permissions to users based on their roles within the organization. This ensures that users only have access to the (a) they need to perform their duties.
What is required in Multi-Factor Authentication? Fill in the blank: Multi-factor authentication requires users to provide multiple forms of (a) before granting access. This helps prevent unauthorized access even if one factor is compromised.
What is the purpose of Auditing and Logging? Fill in the blank: Auditing and logging track all administrative actions, providing a record of who accessed what and when. This helps identify potential security breaches and hold individuals (a) .
Access control is a fundamental security principle, which is implemented to prevent (a) access to sensitive data and resources. (Fill in the blank)
Which of the following is NOT mentioned as a layer of security in a robust access control system?
A) Authentication
B) Authorisation
C) Encryption
D) Least privilege
Fill in the blank: Authentication verifies a user's identity through (a) , multi-factor authentication, or biometrics.
Fill in the blank: Authorization grants users access to specific resources based on their (a) , permissions, and privileges.
Fill in the blank: The Least Privilege Principle states that users should only have access to the resources they need to perform their jobs, minimizing the risk of (a) access.
Fill in the blank: Secure coding practices are essential for developing (a) applications. They involve incorporating security considerations into every phase of the software development lifecycle.
Which of the following is NOT mentioned as a vulnerability that secure coding helps prevent?
A) SQL injection
B) Cross-site scripting
C) Buffer overflows
D) Phishing attacks
Organizations must implement secure coding standards and educate developers on best practices.
True
False
Fill in the blank: Security testing should be an integral part of the software development lifecycle. Ensure the software is secure against (a) and vulnerabilities.
Fill in the blank: Standardise and document security practices to improve consistency and ensure (a) to best practices.
Which of the following offers a comprehensive framework for securing an organisation's digital assets?
Security standards, guidelines, and procedures
Financial audits
Marketing strategies
Customer feedback
What do Compliance Frameworks provide to ensure organizations meet security requirements, such as PCI DSS for payment card data?
(a)
What do industry standards encompass to provide guidelines for organizations to implement security measures effectively?
(a)
Technical Standards cover technical aspects of security. Name one example mentioned in the list.
(a)
Industry standards may align with which type of requirements to ensure compliance with legal and ethical obligations?
(a)
Which of the following is detailed in internal security guidelines for handling sensitive data, ensuring confidentiality and integrity?
Data Protection
Access Control
Incident Response
Best Practices
Which protocol is included in internal security guidelines for responding to security incidents, such as data breaches or unauthorized access?
Data Protection
Incident Response
Best Practices
Access Control
What do Standard Operating Procedures (SOPs) provide for security tasks?
Step-by-step instructions for security tasks,
Emergency plans for security incidents
Training programs for employees
Audit procedures for security assessments
Which documented security procedure defines actions to take during security incidents, including communication protocols, escalation procedures, and mitigation strategies?
Security Audit Procedures
Emergency Response Plans
Security Awareness Training
Standard Operating Procedures (SOPs)
Security Audit Procedures outline the process for conducting regular security assessments to identify vulnerabilities and non-compliance with security policies.
True
False
What is the main purpose of Security Awareness Training?
(a)
