NEW
Font size
WorksheetsSECURITY (LO1)
Total questions: 10
Worksheet time: 20mins
WHAT IS MEAN BY SECURITY
Security means the protection against threats and unauthorized access.
WHICH OF THE FOLLOWING IS A SECURITY BEST PRACTICE?
Ignoring security alerts
Regularly updating software and systems
Using the same password for multiple accounts
Sharing passwords with colleagues
What type of attack involves intercepting data transmission without altering it?
A. Masquerade attack
B. Eavesdropping
C. Replay attack
D. Denial-of-Service attack
What is the key difference between Information Security and Cyber Security?
A. Cyber Security focuses only on physical data
B. Information Security is a subset of Cyber Security
C. Cyber Security is a subset of Information Security
D. They are identical fields with no distinction
Which of the following statements about DDoS (Distributed Denial of Service) and DoS is most accurate in the LO1 context?
A. DoS and DDoS are identical in that they always originate from a single internal user
B. DoS typically originates from a single source and is easier to trace; DDoS uses multiple compromised systems (botnet), making attribution and mitigation more difficult
C. DDoS attacks never affect availability as defined in the CIA triad
D. DoS attacks are only passive and do not cause service disruption
An organisation discovers sensitive customer data was copied to a removable USB by an employee who was authorised to access the system. Which classification best fits this risk?
A. External risk — malware exfiltration
B. Internal risk — insider misuse of authorised access
C. Physical risk — theft of hardware
D. Environmental risk — natural disaster causing data loss
Which control combination is the best compensating control set when multi-factor authentication (MFA) cannot be deployed immediately?
A. Remove passwords entirely and leave accounts open for simplicity
B. Strong password policy + shortened password rotation + increased monitoring of authentication logs + restricted remote access
C. Rely only on physical access controls (locks) while ignoring remote access
D. Disable logging to reduce alert fatigue
Which item is not primarily an administrative control?
A. Security awareness training for staff
B. Access control policy and role definition
C. Configuring a network firewall to block incoming ports
D. Incident response policy and escalation matrix
Which is the most accurate description of a compensating control?
A. A temporary or alternative control used when the main recommended control cannot be implemented
B. A control that fully replaces organisational security policies
C. A permanent replacement for encryption
D. A control used only after an incident occurs
Which of the following best represents an internal, non-malicious threat highlighted in IT risk discussions?
A. A malware-infected USB dropped outside the office
B. An employee accidentally emailing confidential data to the wrong recipient
C. A hacker exploiting an internet-facing server
D. A competitor conducting targeted reconnaissance
