WorksheetsComputer Security Quiz
Total questions: 100
Worksheet time: 50mins
Which of the following best defines computer security?
The protection of the items you value, called assets, in a computer or computer system.
The process of speeding up computer performance.
The method of installing new software on a computer.
The act of deleting unnecessary files from a computer.
Which of the following is NOT considered a type of asset in computer security?
Hardware
Software
Data
Weather
According to the material, what must be identified first to determine what to protect in computer security?
The fastest computer
What has value and to whom
The cheapest software
The largest data file
Which of the following is an example of hardware that may require security protection?
Operating system
Disk drive
Photo editing application
Why do computer systems—hardware, software, and data—deserve security protection?
Because they are expensive to replace
Because they have value
Because they are always online
Because they are used for entertainment
Given the list of assets (hardware, software, data), which combination would be most important to protect for a student working on a class project?
Only hardware
Only software
Hardware and data
Hardware, software, and data
Which of the following statements best describes how the value of an asset is determined?
The value of an asset is always based on its monetary cost.
The value of an asset depends on the asset owner's or user's perspective and may be independent of monetary cost.
The value of an asset is determined by how old it is.
The value of an asset is only based on its physical appearance.
Which of the following is considered a hardware asset?
Documents
Operating system
Computer
Photos
According to the diagram, which type of asset is described as "unique; irreplaceable"?
Network gear
Commercial applications
Individual applications
Documents
Why are asset values often considered imprecise?
Because they are always based on market price.
Because they are personal, time dependent, and can vary.
Because they are determined by government regulations.
Because they are always the same for everyone.
Which of the following is NOT listed as a type of data asset in the material?
Photos
Music, videos
Printer
Class projects
Value-based decisions regarding assets can occur even when we are not aware of them. Which statement best explains why this happens?
Value-based decisions only occur when we consciously think about asset value.
We make value-based decisions frequently, even when we are not aware of them, because asset value is personal and may not be tied to monetary cost.
Value-based decisions are only made by financial experts.
Value-based decisions are always based on the age of the asset.
What is the primary goal of computer security according to the Vulnerability–Threat–Control Paradigm?
To protect valuable assets.
To increase system speed.
To reduce software costs.
To improve user interface design.
Which of the following best defines a vulnerability in a computer system?
A weakness in the system that might be exploited to cause loss or harm.
A software update that improves performance.
A backup copy of important files.
A user account with strong authentication.
What is a threat to a computing system?
A set of circumstances that has the potential to cause loss or harm.
A new software feature.
A type of hardware upgrade.
A method for data backup.
The Vulnerability–Threat–Control Paradigm helps in studying computer security by:
It provides a framework to describe how assets may be harmed and how to counter or mitigate that harm.
It focuses only on hardware improvements.
It eliminates the need for user training.
It only deals with software updates.
What is an attack in the context of system security?
An action that exploits a vulnerability in a system
A device that protects a system
A procedure that removes threats
A technique for improving system performance
Which of the following best describes a control or countermeasure?
An action, device, procedure, or technique that removes or reduces a vulnerability
A threat to a system
A vulnerability in a system
A method for launching attacks
What blocks a threat according to the provided material?
Control of a vulnerability
Launching an attack
Increasing system performance
Ignoring the threat
Why is it important to know the kinds of harm before protecting assets?
To understand what we need to protect assets against
To increase the value of assets
To make assets more vulnerable
To launch attacks on other systems
Controls prevent threats from exercising which of the following?
Vulnerabilities
Countermeasures
Assets
Procedures
Which of the following best defines a threat in the context of a system or organization?
A potential cause of an unwanted impact
A guaranteed event that improves security
A routine maintenance procedure
A method for increasing system performance
Which of the following is NOT a category of threats mentioned in the material?
Financial threats
Natural threats
Human threats
Environmental threats
What are the two perspectives from which threats can harm assets?
What bad things can happen to assets, and who or what can cause or allow those bad things to happen
How assets are created, and how assets are destroyed
Who owns the assets, and who manages the assets
What assets are valuable, and what assets are replaceable
Which property refers to the ability of a system to ensure that an asset can be used by any authorized parties?
Availability
Integrity
Confidentiality
Reliability
If a system ensures that an asset is modified only by authorized parties, which property is being protected?
Integrity
Availability
Confidentiality
Accessibility
Confidentiality in a system means:
An asset is viewed only by authorized parties
An asset is available to everyone
An asset is modified by anyone
An asset is destroyed after use
Which of the following is an effective way to address the threat of unauthorized access to confidential information in a security system?
Allow all employees unrestricted access to all information
Implement access controls and encryption to ensure only authorized parties can view confidential information
Ignore the threat and focus on system performance
Share confidential information with external parties for transparency
Given the definitions of availability, integrity, and confidentiality, which property would be most affected if a system is frequently offline and authorized users cannot access assets?
Availability
Integrity
Confidentiality
Usability
Which of the following is NOT one of the main objectives of information security?
Confidentiality
Integrity
Availability
Profitability
What does the term "confidentiality" refer to in the context of information security?
Ensuring information is always accurate
Making information available to everyone
Preventing unauthorized access to information
Allowing information to be changed freely
Which objective of information security focuses on safeguarding the accuracy and completeness of assets?
Confidentiality
Integrity
Availability
Accessibility
If a system ensures that information is accessible and usable on demand by an authorized entity without delay, which objective of information security is being addressed?
Confidentiality
Integrity
Availability
Privacy
A hospital wants to ensure that patient records are not disclosed to unauthorized staff, that the records are accurate, and that doctors can access them whenever needed. Which three objectives of information security are being addressed in this scenario?
Confidentiality, Integrity, Availability
Privacy, Accuracy, Accessibility
Security, Usability, Completeness
Authorization, Authentication, Accounting
Which of the following best defines confidentiality in the context of information security?
Limiting access to information only to those who need it and preventing access by those who do not
Allowing everyone to access information freely
Ensuring information is always available to authorized users
Making information public for transparency
Which of the following is NOT a measure used to protect the confidentiality of information?
Information classification
Secure document and data storage
Application of general security policies
Public sharing of sensitive data
Why is cryptography (encryption) important for maintaining confidentiality?
It makes information unreadable to unauthorized users
It deletes information permanently
It increases the speed of data transmission
It allows anyone to access the information
Suppose an organization fails to educate its information custodians and end users about security policies. What potential risk does this pose to confidentiality?
Increased likelihood of unauthorized access to information
Improved security of information
Reduced need for encryption
Enhanced classification of information
If unauthorized individuals or systems can view information, what has occurred?
Confidentiality has been breached
Information has been classified
Encryption has been applied
Security policies have been enforced
Which of the following best describes a failure of data confidentiality?
An unauthorized person accesses a data item.
A person authorized to access a data item uses it for its intended purpose.
Data is lost due to hardware failure.
Data is encrypted before transmission.
Which scenario is an example of a specialized failure of data confidentiality?
A person authorized to access certain data accesses other data not authorized.
A person authorized to access data shares it with another authorized person.
Data is backed up regularly.
Data is stored in a secure location.
If an unauthorized person learns that a company is developing a new product, which property of data confidentiality has failed?
The existence of a piece of data has been disclosed.
The data has been deleted.
The data has been encrypted.
The data has been backed up.
A person does not know someone’s exact salary but knows it falls within a certain range. What type of data confidentiality failure does this represent?
Access to an approximate data value.
Complete data loss.
Data integrity failure.
Data availability failure.
An unauthorized process accessing a data item is considered a failure of data confidentiality because:
Confidentiality requires that only authorized entities can access data.
Confidentiality is not related to data access.
Authorized processes are allowed to access any data.
Unauthorized processes always delete data.
What term is used to refer to a person, process, or program that is authorized to access a data item?
Subject
Object
Access mode
Policy
In the context of confidentiality, what is the term for the data item being accessed?
Subject
Object
Access mode
Policy
Which of the following best describes "access mode" in the context of confidentiality?
The person accessing the data
The type of access such as read, write, or execute
The data item being accessed
The authorization for access
What is the term for the authorization that determines whether access to a data item is allowed?
Subject
Object
Access mode
Policy
Given a scenario: A user attempts to write to a file. According to the confidentiality pattern described, identify the subject, object, access mode, and policy in this scenario.
Subject: user; Object: file; Access mode: write; Policy: authorization to write
Subject: file; Object: user; Access mode: read; Policy: authorization to read
Subject: user; Object: file; Access mode: read; Policy: authorization to execute
Subject: process; Object: data; Access mode: execute; Policy: authorization to write
Which three elements are combined in an access control policy to determine if access is granted?
Who, What, How
When, Where, Why
Who, When, Where
What, Why, When
In the context of access control, what does the term "subject" refer to?
The person or entity requesting access
The file or resource being accessed
The method of access
The security policy
According to the diagram, what does "object" represent in access control?
The resource or item being accessed
The person accessing the system
The password used
The network connection
If a policy is defined as "Who + What + How = Yes/No", what is the primary purpose of this policy in access control?
To determine whether access should be granted or denied
To monitor network traffic
To encrypt data
To create user accounts
Given a scenario where a user tries to open a file using a specific application, how would the access control policy components apply?
The user is the subject, the file is the object, and the application is the mode of access
The file is the subject, the user is the object, and the application is the policy
The application is the subject, the user is the object, and the file is the mode of access
The user is the object, the file is the subject, and the application is the policy
Which of the following best defines the concept of integrity in information security?
The ability to access information from anywhere at any time
The completeness and authenticity of information, protected from corruption and unauthorized modification
The process of encrypting data to prevent unauthorized access
The speed at which information can be transmitted over a network
According to Welke and Mayfield, which of the following is NOT one of the three particular aspects of integrity?
Authorized actions
Separation and protection of resources
Error detection and correction
Data encryption
Which of the following is a sign that the integrity of an item has been preserved?
The item is modified only by unauthorized people
The item is internally consistent and meaningful
The item is frequently corrupted by computer viruses
The item is always encrypted
What is a common threat to the integrity of information during transmission?
Data compression
Computer viruses and worms
Increased bandwidth
User authentication
Which procedure can help enforce integrity in information systems, similar to confidentiality?
Allowing unrestricted access to all resources
Rigorous control of who or what can access which resources in what ways
Disabling error detection mechanisms
Ignoring unauthorized modifications
What does "availability of information" mean?
Information can be accessed by authorized users in a usable format.
Information is always accessible to any user.
Information is only accessible to system administrators.
Information is never accessible to users.
Which of the following is NOT a requirement for a service to be considered available?
The service is present in a usable form.
The service has enough capacity to meet needs.
The service is completed in an acceptable period of time.
The service is only accessible to unauthorized users.
Availability applies to which of the following?
Only to data
Only to services
Both data and services (information and information processing)
Only to hardware
A service is thought to be available if it is making clear progress and, if in wait mode, it has which of the following?
Unlimited waiting time
Bounded waiting time
No waiting time
Random waiting time
Why does availability not imply that information is accessible to any user?
Because information should only be accessed by authorized users when needed.
Because information is always public.
Because information is never stored in a usable format.
Because information is only for system administrators.
A service is present in a usable form but does not have enough capacity to meet the service’s needs. Is it considered available?
No, because availability requires enough capacity to meet the service’s needs.
Yes, as long as it is present in a usable form.
Yes, if it is completed in an acceptable period of time.
No, because only data availability matters.
Which of the following is a criterion for defining availability in a system?
There is a timely response to our request.
The system is always online.
The system uses the latest technology.
The system is only accessible to administrators.
Why is fair allocation of resources important for system availability?
It ensures that some requesters are not favored over others.
It increases the speed of the system.
It reduces the cost of operation.
It allows only one user at a time.
Which concept is involved in controlling concurrency for system availability?
Simultaneous access, deadlock management, and exclusive access
Only allowing one user at a time
Disabling all network connections
Ignoring user requests
A system that follows a philosophy of fault tolerance will:
Gracefully cease service or provide workarounds during hardware or software faults
Crash immediately when a fault occurs
Ignore all faults and continue operating
Require manual intervention for every fault
Which of the following best describes a system with high availability?
It can be used easily and in the way it was intended to be used.
It requires complex procedures for every operation.
It is only accessible during business hours.
It frequently loses information during faults.
Given a scenario where a system experiences a hardware fault, what should a highly available system do according to the criteria listed?
Provide a workaround or gracefully cease service rather than crash and lose information.
Immediately shut down and lose all data.
Ignore the fault and continue as normal.
Require users to manually fix the issue before continuing.
Which of the following is the correct term for the mode of access that involves viewing a data item in computer security?
Integrity
Availability
Confidentiality
Usability
In computer security, what does modifying a data item refer to?
Confidentiality
Integrity
Fault Tolerance
Capacity
Which mode of access does computer security seek to preserve when a person or system uses a data item?
Performance
Availability
Capacity
Confidentiality
Based on the diagram, which aspect is at the center and is related to capacity, performance, fault tolerance, and usability?
Integrity
Confidentiality
Availability
Performance
The concepts of confidentiality, integrity, and availability work together to preserve computer security by:
Focusing only on preventing unauthorized access.
Ensuring data can be viewed, modified, and used securely.
Being unrelated aspects of computer security.
Applying only to physical security measures.
Which of the following is commonly referred to as the foundation for thinking about security in computer systems?
C-I-A triad
OSI model
TCP/IP stack
Moore's Law
According to ISO 7498-2, which property allows a system to confirm the identity of a sender?
Authentication
Confidentiality
Integrity
Availability
What is the main purpose of nonrepudiation or accountability in computer security?
To ensure a sender cannot convincingly deny having sent something
To encrypt data during transmission
To prevent unauthorized access to data
To increase system performance
Which property, as added by the U.S. Department of Defense, allows a system to trace all actions related to a given asset?
Auditability
Confidentiality
Authentication
Availability
How do authenticity and nonrepudiation extend security notions in network communications?
By confirming sender identity and preventing denial of sent messages
By encrypting all network traffic
By increasing network speed
By reducing the need for passwords
Why is auditability important in computer security?
It establishes individual accountability for computer activity
It prevents viruses from infecting the system
It increases the speed of data transmission
It allows unlimited access to resources
Strategically, why might an organization prioritize implementing auditability in their security framework?
To trace all actions and establish accountability for computer activity
To reduce hardware costs
To improve user interface design
To increase the number of users
Which of the following best describes the concept of "Confidentiality" in the context of company email communication?
Ensuring that only intended recipients can access the contents of email communication.
Making sure emails are sent quickly.
Allowing all employees to read any email.
Modifying emails before sending them.
What does "Integrity" mean in the context of company email communication?
Emails are not modified from their original form when received or sent.
Emails are always available to users.
Only authorized users can access emails.
Emails are deleted after being read.
Why is "Availability" important for a company's email service?
Because email communication must be accessible at all times for business operations.
So that emails can be modified easily.
To ensure only managers can access emails.
To prevent emails from being sent.
A company wants to ensure that only the intended recipients can read the contents of an email. Which principle of the CIA triad does this address?
Confidentiality
Integrity
Availability
Accountability
If an employee receives an email that has been altered from its original form, which aspect of the CIA triad has been compromised?
Integrity
Availability
Confidentiality
Authenticity
A company’s email service goes down for several hours, impacting communication. Which part of the CIA triad is most affected?
Availability
Integrity
Confidentiality
Reliability
Given the scenario where a company shares reports and communicates with customers via email, which CIA principle ensures that the information in the emails remains unchanged during transmission?
Integrity
Confidentiality
Availability
Accessibility
Which of the following is an example of maintaining confidentiality in email communication?
Using strong passwords known only to the user.
Allowing anyone to access the email server.
Modifying the content of emails before sending.
Making emails available only during business hours.
If a company ensures its email service is operational 24/7, which CIA principle is being prioritized?
Availability
Integrity
Confidentiality
Scalability
Which of the following acts can cause harm to assets according to the CIA perspective?
Interception, interruption, modification, and fabrication
Encryption, deletion, duplication, and restoration
Authentication, authorization, accounting, and auditing
Prevention, detection, correction, and recovery
What aspect of security is compromised if someone intercepts data?
Confidentiality
Availability
Integrity
Accountability
If a flow of data or access to a computer is interrupted, which security principle is affected?
Availability
Integrity
Confidentiality
Authenticity
Which act can lead to the failure of integrity in a computer system?
Modification or fabrication of data
Interception of data
Interruption of data flow
Encryption of data
How can understanding the four acts of harm (interception, interruption, modification, fabrication) help in computer security?
It helps determine what threats might exist against the computers you are trying to protect.
It helps in designing faster computer hardware.
It helps in improving user interface design.
It helps in reducing the cost of computer systems.
Which of the following is NOT one of the main goals of computer security?
Confidentiality
Integrity
Availability
Profitability
Computer security aims to prevent unauthorized viewing of data. What is this principle called?
Integrity
Confidentiality
Availability
Accessibility
Computer security must balance preventing unauthorized modification of data with preserving access. Which of the following best illustrates a situation where both data integrity and availability are considered?
By making all data public and accessible to everyone at all times.
By ensuring only authorized users can modify data, but all users can access it at any time; for example, in online banking, users must be able to view their account (availability) but only authorized changes are allowed (integrity).
By restricting access to all data, preventing both viewing and modification.
By allowing anyone to modify data as long as they can access it.
