Font size
S
M
L
XL
WorksheetsCombined U11, 14, 8 BASELINE
Total questions: 90
Worksheet time: 1hrs 18mins
Name
Class
Date
1.
What distinguishes a perceptive forensic analysis from a basic incident review?
a)
The number of evidence types examined and volume of data collected
b)
The ability to establish causal relationships between evidence and identify attack methodology
c)
The use of advanced forensic tools and automated analysis techniques
d)
The technical complexity of the investigation methodology
2.
What is the primary difference between symmetric and asymmetric encryption in terms of computational overhead and security implications?
a)
Symmetric encryption requires more computational resources than asymmetric encryption
b)
Asymmetric encryption uses the same key for encryption and decryption
c)
Symmetric encryption uses a single shared key while asymmetric uses key pairs, but symmetric is significantly faster
d)
Symmetric and asymmetric encryption provide identical security levels with different key distribution methods
3.
How should risk severity, probability, and potential loss be evaluated to produce a meaningful risk assessment?
a)
Using standardised ratings (High, Medium, Low) based primarily on potential financial loss
b)
Conducting quantitative analysis that assigns numerical values based on historical data and specific organisational context
c)
Making subjective assessments based on security team expertise
d)
Comparing against industry average incident rates and typical financial impacts
4.
What characterises an effective review of security weaknesses following an incident?
a)
Identifying all possible weaknesses regardless of their relevance to the incident
b)
Balancing analysis of forensic procedures, protection measures, and security documentation
c)
Focusing only on the specific vulnerability that was exploited
d)
Comparing the organisation's security posture to industry standards
5.
What does DDoS stand for?
a)
Distributed Denial of Service
b)
Digital Denial of Service
c)
Domain Denial of Service
d)
Denial of Database Service
6.
Which encryption key management practice is most crucial for maintaining long-term data confidentiality?
a)
Using the strongest available encryption algorithms
b)
Regular key rotation and secure destruction of outdated keys
c)
Implementing quantum-resistant encryption algorithms
d)
Centralizing all encryption keys in a single secure location
7.
What is phishing?
a)
A technique to steal user data by pretending to be a trustworthy entity
b)
An attack that crashes servers with multiple requests
c)
An attack that targets physical infrastructure
d)
A method of securing network communications
8.
What is the role of a CSIRT (Computer Security Incident Response Team)?
a)
To coordinate response activities to security incidents
b)
To develop security policies for an organization
c)
To train employees on security best practices
d)
To recover lost data after an attack
9.
What is the purpose of penetration testing?
a)
To test system performance under heavy load
b)
To identify and address security vulnerabilities before attackers do
c)
To monitor network traffic
d)
To assess employee security awareness
10.
What is two-factor authentication (2FA)?
a)
A security method requiring two different forms of identification to access a resource
b)
Using two devices to log into a system
c)
Using two passwords for the same account
d)
A system that requires regular password changes
11.
What factors determine the credibility of conclusions in a forensic incident analysis?
a)
The credentials and experience of the forensic analyst
b)
The logical consistency of the narrative constructed from the evidence
c)
The amount of supporting evidence available
d)
The reputation and authority of the forensic investigation team
12.
Which secure software development practice is most effective against injection-based vulnerabilities?
a)
Code obfuscation to hide implementation details
b)
Input validation and parameterized queries
c)
Regular penetration testing by third-party security firms
d)
Relying on web application firewalls exclusively
13.
What distinguishes a robust security measure from a basic security control?
a)
The complexity of implementation and technical sophistication
b)
Its effectiveness in addressing specific, high-priority threats identified in the risk assessment
c)
The degree to which it aligns with recognised security standards and frameworks
d)
The number and variety of security controls implemented
14.
What elements must be included in effective justification of a cyber security solution?
a)
Focusing primarily on technical effectiveness of the solution
b)
Providing a detailed technical specification of all security controls
c)
Emphasising cost-benefit analysis and resource requirements
d)
Comparing security approaches to competitors or industry standards
15.
What is the purpose of a forensic investigation following a cyber security incident?
a)
To collect and analyze evidence to determine the extent and impact of an incident
b)
To restore systems to their pre-attack state
c)
To punish those responsible for the incident
d)
To improve public relations after an incident
16.
What is the purpose of a security policy?
a)
To provide guidelines and rules for protecting an organization's information assets
b)
To assign blame after security incidents occur
c)
To enforce data backup procedures
d)
To reduce system downtime during attacks
17.
Which risk analysis methodology quantifies both the likelihood of occurrence and the potential impact of various cyber threats?
a)
Qualitative analysis using expert judgment and categorical rankings
b)
FAIR (Factor Analysis of Information Risk) framework
c)
Simple risk matrix plotting probability against impact
d)
Quantitative analysis using specific numerical values for risk components
18.
Which UK law covers unauthorized access to computer systems?
a)
Data Protection Act 2018
b)
Computer Misuse Act 1990
c)
Freedom of Information Act 2000
d)
Copyright, Designs and Patents Act 1988
19.
What is network segmentation in cyber security?
a)
Dividing a network into smaller segments to improve security and control
b)
Installing multiple firewalls on a network
c)
Using different operating systems on a network
d)
Physically separating sensitive systems from the internet
20.
What is a zero-day vulnerability?
a)
A security flaw unknown to the software developer until exploited
b)
A vulnerability that has been patched but not disclosed publicly
c)
A vulnerability that exists in legacy systems
d)
A vulnerability that results from user error
21.
What is the purpose of a security policy?
a)
To provide guidelines and rules for protecting an organization's information assets
b)
To assign blame after security incidents occur
c)
To enforce data backup procedures
d)
To reduce system downtime during attacks
22.
How should improvements to security measures be prioritised following a security incident?
a)
Implementing the most technically advanced solutions for all identified weaknesses
b)
Based on addressing the specific vulnerabilities exploited in the incident
c)
Based on implementation cost and resource requirements
d)
According to industry best practices regardless of incident specifics
23.
How should alternative explanations be considered in cyber security incident analysis?
a)
Acknowledging alternative explanations exist but focusing on the most obvious cause
b)
Exploring multiple possible explanations and evaluating each against the available evidence
c)
Ranking alternative explanations based on probability but presenting only the most likely
d)
Dismissing alternative explanations once a plausible cause is identified
24.
Which attack methodology leverages legitimate authentication credentials while avoiding traditional intrusion detection triggers?
a)
Exploiting buffer overflow vulnerabilities in application code
b)
Using legitimate credentials obtained through social engineering or insider threats
c)
Attacking through unpatched vulnerabilities in internet-facing services
d)
Performing DDoS attacks to disguise data exfiltration activities
25.
What is social engineering?
a)
Using technology to manipulate people
b)
Programming malicious code
c)
Manipulating people to divulge confidential information
d)
Writing malicious code to attack systems
26.
How should complex technical security concepts be communicated to non-technical stakeholders?
a)
Converting all concepts to non-technical language to ensure understanding
b)
Using analogies and metaphors that simplify complex concepts while maintaining accuracy
c)
Creating separate versions of documentation for technical and non-technical audiences
d)
Restricting technical details to confidential appendices
27.
What is a man-in-the-middle attack?
a)
An attack where a third party intercepts communications between two parties
b)
An attack where systems are flooded with traffic
c)
An attack that exploits unpatched software
d)
A method of data encryption
28.
How would you justify the selection of specific security controls based on risk assessment outcomes?
a)
Select controls that have the lowest implementation cost
b)
Select controls based on industry standards only
c)
Select controls solely based on their technical complexity
d)
Implementing all possible security controls without prioritization
29.
What is the first step in creating a cyber security plan?
a)
Installing antivirus software
b)
Defining acceptable use policies
c)
Performing a risk assessment
d)
Installing CCTV cameras
30.
What is the primary purpose of a firewall?
a)
To detect and remove viruses
b)
To block unauthorized access to networks
c)
To encrypt sensitive data
d)
To back up data regularly
31.
What is meant by "root cause analysis" in IT troubleshooting?
a)
A systematic process to identify the fundamental cause of a problem
b)
A quick fix to get systems running again
c)
Documenting every step taken to resolve an issue
d)
Replacing faulty hardware immediately
32.
How would you develop a comprehensive disaster recovery plan for an organization's IT infrastructure?
a)
Identify critical systems, establish recovery time objectives, create backup strategies, define roles and responsibilities, and test the plan regularly
b)
Focus exclusively on data backup procedures
c)
Depend entirely on cloud services for disaster recovery
d)
Relying solely on staff training to handle disaster scenarios
33.
How would you design an effective knowledge management system for an IT support department?
a)
Integrating documentation, searchable solutions database, collaboration tools, process workflows, and continuous knowledge update mechanisms
b)
Creating a centralized document repository without search capabilities
c)
Relying exclusively on senior technicians to share knowledge verbally
d)
Building separate knowledge bases for different technical teams with no integration
34.
How do effective capacity management processes enhance IT service delivery?
a)
They prevent resource bottlenecks by forecasting future requirements and scaling accordingly
b)
They primarily focus on reducing current infrastructure costs
c)
They primarily address disaster recovery requirements
d)
They only matter when deploying new applications
35.
What are the key considerations for implementing a new system?
a)
User needs, existing infrastructure, budget, and timeline
b)
Cost only
c)
Vendor recommendations only
d)
Management preferences only
36.
What is the purpose of system monitoring tools?
a)
To continuously monitor system performance and alert on issues
b)
To back up system data automatically
c)
To restrict user access to certain websites
d)
To generate reports on system usage
37.
How should data and information requirements be addressed in an IT service delivery solution?
a)
Prioritising data security measures above all other considerations
b)
Creating comprehensive specifications for data flows, storage, backup, and access controls
c)
Focusing primarily on security and compliance requirements
d)
Prioritising scalability and future expansion capabilities
38.
What is meant by "escalation" in IT support?
a)
Transferring an issue to a higher support level when it cannot be resolved
b)
Notifying management about system issues
c)
Closing a support ticket without resolution
d)
Adding more technical support staff
39.
What is a common method for prioritizing support requests?
a)
Based on impact and urgency
b)
First-come, first-served
c)
Based on the user's position in the company
d)
Based on which technician is available
40.
How do predictive analytics capabilities transform traditional reactive IT support models?
a)
They enable automated remediation of issues before they impact users
b)
They eliminate the need for support staff intervention
c)
They simply visualize existing support metrics in more appealing formats
d)
They only apply to large enterprise environments with dedicated data science teams
41.
What is the purpose of user training in IT support?
a)
To reduce support calls by enabling users to solve basic problems
b)
To ensure users can operate equipment properly
c)
To comply with regulatory requirements only
d)
To generate reports about system usage
42.
How should operational impacts of an IT service delivery solution be assessed?
a)
Calculating efficiency improvements in technical processes
b)
Evaluating impacts on workflows, processes, and productivity across the organisation
c)
Identifying departmental responsibilities for implementation
d)
Focusing on change management and user adoption strategies
43.
What strategic factors should guide decisions about in-house versus outsourced IT support functions?
a)
Cost considerations, required service levels, and strategic importance of the functions
b)
Always keeping strategic functions in-house and outsourcing commodity services
c)
Selecting vendors based primarily on technical capabilities
d)
Maintaining a fixed ratio of in-house to outsourced support functions
44.
What is a help desk ticketing system?
a)
A system for tracking, recording, and managing support requests
b)
A database of known errors and solutions
c)
A monitoring system for network traffic
d)
A tool for measuring internet speed
45.
What does BYOD stand for?
a)
Bring Your Own Device
b)
Back Your Own Data
c)
Build Your Own Database
d)
Before You Order Device
46.
What does ITIL stand for?
a)
Information Technology Infrastructure Library
b)
International Technical Information License
c)
Integrated Technology Information Link
d)
Internet Technology Implementation Library
47.
What is a common method for prioritizing support requests?
a)
Based on impact and urgency
b)
First-come, first-served
c)
Based on the user's position in the company
d)
Based on which technician is available
48.
What is meant by "incident management" in IT support?
a)
The process of identifying, analyzing, and resolving IT incidents
b)
The process of implementing new systems
c)
The process of planning system upgrades
d)
The process of hiring IT personnel
49.
What factors most significantly impact mean time to resolution (MTTR) in IT support operations?
a)
Technical skill level of support staff and availability of subject matter experts
b)
Ticket routing efficiency and escalation procedures
c)
Availability of accurate documentation and knowledge base articles
d)
Incident complexity and the number of teams involved in resolution
50.
What techniques are most effective for identifying the root cause of intermittent IT system failures?
a)
Analyzing system logs during periods of normal operation and failure
b)
Focusing exclusively on the most recently reported occurrences of the issue
c)
Deploying monitoring agents on all user devices to capture intermittent behaviors
d)
Replicating issues in isolated test environments with controlled variables
51.
How should service names and descriptions be developed to demonstrate sound understanding of organisational requirements?
a)
Creating standardised descriptions that can be reused across different organisations
b)
Tailoring descriptions to show how services address specific organisational requirements
c)
Using industry-standard terminology from ITIL or other frameworks
d)
Creating detailed descriptions of the technical implementation
52.
What is the purpose of asset management in IT support?
a)
To track and manage hardware and software assets throughout their lifecycle
b)
To maintain software license compliance
c)
To perform security audits
d)
To generate financial reports
53.
What approach should be taken when identifying and evaluating alternative solutions?
a)
Identifying alternatives that represent current industry trends
b)
Comparing alternatives based on their ability to meet specific organisational requirements
c)
Identifying the most cost-effective alternatives only
d)
Focusing on alternatives that minimise implementation risk
54.
How would you develop a comprehensive IT service strategy that addresses specific business requirements?
a)
Using generic IT service frameworks without adaptation to the specific organisation
b)
Developing a strategy directly aligned with specific business objectives and organisational needs
c)
Adopting existing IT frameworks without modification
d)
Creating separate strategies for each department without integration
55.
What considerations are important when developing an IT support strategy that aligns with business objectives?
a)
Align with strategic goals, consider business processes, analyze user needs, evaluate technology landscape, and establish governance framework
b)
Focus primarily on cost reduction in IT operations
c)
Implementing the latest technologies without considering business needs
d)
Let each department determine their own IT support requirements
56.
What is change management in IT support?
a)
The process of managing modifications to IT systems and infrastructure
b)
The process of replacing old equipment with new equipment
c)
The process of training users on new systems
d)
The process of documenting system configurations
57.
How does a perceptive IT service delivery solution demonstrate awareness of organisational context?
a)
Incorporating the latest technological trends regardless of organisational fit
b)
Creating solutions that directly address the specific challenges identified in the scenario
c)
Demonstrating alignment with industry best practices and standards
d)
Minimising changes to existing processes to reduce implementation resistance
58.
What is a service level agreement (SLA)?
a)
A contract between a service provider and customer outlining expected service levels
b)
A list of software licenses owned by the company
c)
A maintenance schedule for hardware
d)
A warranty for hardware devices
59.
What approach creates the most comprehensive analysis of IT service delivery implications?
a)
Identifying all potential risks associated with implementation
b)
Balancing benefits, challenges, risks, and success factors in a forward-looking assessment
c)
Focusing on implementation challenges and change management processes
d)
Emphasising short-term implementation challenges over long-term benefits
60.
What considerations should be made when specifying hardware and software for an IT service solution?
a)
Selecting components from a single vendor to ensure compatibility
b)
Evaluating hardware and software based on compatibility with business requirements
c)
Selecting the most cost-effective components regardless of performance
d)
Choosing components based on support availability and vendor reputation
61.
What is the difference between 2D and 3D games?
a)
2D games use flat graphics, 3D games use depth and perspective
b)
2D games use pixel art, 3D games use realistic graphics
c)
2D games are for mobile, 3D games are for consoles
d)
2D games have fewer features than 3D games
62.
What is user interface (UI) design in games?
a)
The design of elements that allow players to interact with the game
b)
The process of creating game instructions
c)
The final testing phase before release
d)
Only the visual appearance of menu screens
63.
What is a finite state machine in game development?
a)
A model for representing different states of game objects and transitions between them
b)
A programming language specific to GameMaker
c)
A type of game controller
d)
The main character of a game
64.
Which view in GameMaker is used to create the visual layout of game levels?
a)
The Code View
b)
The Object View
c)
The Room Editor
d)
The Sprite Editor
65.
What is a room in GameMaker?
a)
A level or stage in the game where objects are placed
b)
The menu screen
c)
The player's inventory
d)
A cutscene between levels
66.
What is procedural generation in games?
a)
Creating game content algorithmically rather than manually
b)
Using pre-made assets in game development
c)
Creating games using only player-generated content
d)
Copying content from other games
67.
How would you design game systems that facilitate user-generated content while maintaining quality and consistency?
a)
Providing robust creation tools with defined parameters, community curation systems, and clear technical constraints
b)
Allowing all user content without any moderation or guidelines
c)
Restricting user-generated content to cosmetic elements only
d)
Implementing strict templates that allow minimal user customization
68.
What is the primary purpose of a game engine like GameMaker?
a)
To simplify game development by providing pre-built functions and tools
b)
To create 3D models
c)
To publish games on app stores
d)
To design hardware specifications for games
69.
What is meant by "game balance" in game development?
a)
Ensuring gameplay elements are neither too easy nor too difficult
b)
Making sure all players have equal advantages
c)
Ensuring games have equal numbers of characters
d)
Making sure all games have the same difficulty
70.
What specific techniques would you implement to optimize loading times in open-world games?
a)
Using background loading, asset streaming, procedural generation, and memory management optimization
b)
Reducing visual quality until loading times improve
c)
Using longer loading screens with entertainment elements to distract players
d)
Removing open-world elements to create smaller, discrete levels
71.
How would you approach accessibility features in game design while maintaining core gameplay experiences?
a)
Implementing customizable difficulty, control remapping, visual/audio alternatives, and ensuring compatibility with assistive technologies
b)
Adding a single accessibility mode that changes multiple game parameters simultaneously
c)
Focusing only on visual accessibility and ignoring other accessibility needs
d)
Making separate versions of the game for different accessibility needs
72.
What is a sprite in GameMaker?
a)
A visual element or graphic that can be animated
b)
A background image
c)
A character in the game
d)
A game level
73.
What is the function of the Step event in GameMaker?
a)
It runs once per frame to update game logic
b)
It runs when a game starts
c)
It only runs when an error occurs
d)
It only runs when a key is pressed
74.
What techniques would you implement to create effective game tutorials that teach mechanics without disrupting immersion?
a)
Using contextual hints during gameplay, progressive complexity introduction, and allowing experimentation in low-risk environments
b)
Providing a separate tutorial level that must be completed before the main game
c)
Providing a digital manual that players must read before playing
d)
Explaining all mechanics through non-interactive cutscenes
75.
What approaches would you take to implement a save system appropriate for different game genres?
a)
Matching save frequency and player control to genre expectations, risk of progress loss, and session length assumptions
b)
Using a single save system approach for all game types
c)
Implementing checkpoints only at major game milestones
d)
Relying exclusively on auto-save without player control
76.
What should be included in a test plan for a game?
a)
Test cases for functionality, performance, usability, and compatibility
b)
Only testing for bugs
c)
Only player feedback
d)
Only technical specifications
77.
How would you approach the implementation of artificial intelligence in a game?
a)
Determining AI purposes, selecting appropriate algorithms, balancing challenge and fairness, optimizing performance, and testing with diverse player behaviors
b)
Using pre-built AI systems without customization
c)
Implementing AI only for enemy characters
d)
Creating overly complex AI systems that slow down the game
78.
What approaches would you use to optimize a game to meet client requirements?
a)
Analyzing performance issues, refactoring code for efficiency, optimizing graphics, improving user interface, and enhancing gameplay based on testing feedback
b)
Making the game more difficult to increase playtime
c)
Adding more features regardless of performance impact
d)
Focusing only on visual aspects of the game
79.
How would you evaluate the effectiveness of different monetization strategies in relation to specific game genres and target audiences?
a)
Evaluating alignment with target demographic spending habits, game session length, retention impact, and competitive landscape
b)
Always implementing the monetization model most common in similar games
c)
Focusing exclusively on initial purchase price to maximize early revenue
d)
Implementing all possible monetization methods simultaneously
80.
What specific approaches would you implement to optimize a graphics-intensive game for multiple platform capabilities?
a)
Implementing scalable asset pipelines with multiple detail levels, adaptive rendering systems, and platform-specific optimization
b)
Creating a single version optimized for the most powerful platform
c)
Developing for the lowest common denominator platform only
d)
Releasing on only one platform to avoid optimization challenges
81.
What does FPS stand for in the context of games?
a)
Frames Per Second
b)
First Person Shooter
c)
Fast Processing System
d)
File Processing System
82.
What is a game loop in game development?
a)
A continuous cycle of processing input, updating game state, and rendering
b)
The path a player takes to finish the game
c)
The storyline of the game
d)
The credits at the end of the game
83.
What is a game loop?
a)
The cycle of updating game state and rendering graphics repeatedly
b)
The time it takes to complete a game
c)
The process of completing levels in order
d)
The narrative structure of a game
84.
What is meant by "game balance" in game development?
a)
Ensuring gameplay elements are neither too easy nor too difficult
b)
Making sure all players have equal advantages
c)
Ensuring games have equal numbers of characters
d)
Making sure all games have the same difficulty
85.
What are shaders used for in game development?
a)
To create special visual effects by manipulating how graphics are rendered
b)
To compress game files
c)
To optimize game performance
d)
Only to create realistic lighting
86.
What is the purpose of events in GameMaker?
a)
To trigger specific code when certain conditions are met
b)
To create animations
c)
To create 3D models
d)
To connect to online servers
87.
What is user interface (UI) design in games?
a)
The design of elements that allow players to interact with the game
b)
The process of creating game instructions
c)
The final testing phase before release
d)
Only the visual appearance of menu screens
88.
How would you evaluate the effectiveness of different narrative structures in creating meaningful player experiences?
a)
Analyzing how different structures (linear, branching, emergent) affect player agency, emotional investment, and replay value
b)
Using the same narrative approach for all game genres
c)
Focusing exclusively on plot complexity rather than player agency
d)
Eliminating narrative elements to focus purely on gameplay mechanics
89.
How would you design an adaptive difficulty system that maintains player engagement without frustrating different skill levels?
a)
Creating difficulty that adjusts based on player performance metrics, offering optional assists, and clearly communicating challenge levels
b)
Making all games extremely difficult to appeal to hardcore players
c)
Implementing a static difficulty selection at the start of the game only
d)
Removing all challenge to make games accessible to everyone
90.
Which view in GameMaker is used to create the visual layout of game levels?
a)
The Code View
b)
The Object View
c)
The Room Editor
d)
The Sprite Editor
Reset
