wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

SECURITY (LO1)

Total questions: 10

Worksheet time: 20mins

Name
Class
Date
1.

WHAT IS MEAN BY SECURITY

a)
Security refers to the financial stability of a company.
b)
Security means the ability to access information freely.
c)

Security means the protection against threats and unauthorized access.

d)
Security is the process of enhancing product features.
2.

WHICH OF THE FOLLOWING IS A SECURITY BEST PRACTICE?

a)

Ignoring security alerts

b)

Regularly updating software and systems

c)

Using the same password for multiple accounts

d)

Sharing passwords with colleagues

3.

What type of attack involves intercepting data transmission without altering it?

a)

A. Masquerade attack


b)

B. Eavesdropping

c)

C. Replay attack

d)

D. Denial-of-Service attack

4.

What is the key difference between Information Security and Cyber Security?

a)

A. Cyber Security focuses only on physical data


b)

B. Information Security is a subset of Cyber Security

c)

C. Cyber Security is a subset of Information Security

d)

D. They are identical fields with no distinction

5.

Which of the following statements about DDoS (Distributed Denial of Service) and DoS is most accurate in the LO1 context?

a)

A. DoS and DDoS are identical in that they always originate from a single internal user


b)

B. DoS typically originates from a single source and is easier to trace; DDoS uses multiple compromised systems (botnet), making attribution and mitigation more difficult

c)

C. DDoS attacks never affect availability as defined in the CIA triad

d)

D. DoS attacks are only passive and do not cause service disruption

6.

An organisation discovers sensitive customer data was copied to a removable USB by an employee who was authorised to access the system. Which classification best fits this risk?

a)

A. External risk — malware exfiltration


b)

B. Internal risk — insider misuse of authorised access

c)

C. Physical risk — theft of hardware

d)

D. Environmental risk — natural disaster causing data loss

7.

Which control combination is the best compensating control set when multi-factor authentication (MFA) cannot be deployed immediately?

a)

A. Remove passwords entirely and leave accounts open for simplicity

b)

B. Strong password policy + shortened password rotation + increased monitoring of authentication logs + restricted remote access

c)

C. Rely only on physical access controls (locks) while ignoring remote access

d)

D. Disable logging to reduce alert fatigue

8.

Which item is not primarily an administrative control?

a)

A. Security awareness training for staff

b)

B. Access control policy and role definition

c)

C. Configuring a network firewall to block incoming ports

d)

D. Incident response policy and escalation matrix

9.

Which is the most accurate description of a compensating control?

a)

A. A temporary or alternative control used when the main recommended control cannot be implemented


b)

B. A control that fully replaces organisational security policies

c)

C. A permanent replacement for encryption

d)

D. A control used only after an incident occurs

10.

Which of the following best represents an internal, non-malicious threat highlighted in IT risk discussions?

a)

A. A malware-infected USB dropped outside the office


b)

B. An employee accidentally emailing confidential data to the wrong recipient

c)

C. A hacker exploiting an internet-facing server

d)

D. A competitor conducting targeted reconnaissance