wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Computer Security Quiz

Total questions: 100

Worksheet time: 50mins

Name
Class
Date
1.

Which of the following best defines computer security?

a)

The protection of the items you value, called assets, in a computer or computer system.

b)

The process of speeding up computer performance.

c)

The method of installing new software on a computer.

d)

The act of deleting unnecessary files from a computer.

2.

Which of the following is NOT considered a type of asset in computer security?

a)

Hardware

b)

Software

c)

Data

d)

Weather

3.

According to the material, what must be identified first to determine what to protect in computer security?

a)

The fastest computer

b)

What has value and to whom

c)

The cheapest software

d)

The largest data file

4.

Which of the following is an example of hardware that may require security protection?

a)

Operating system

b)

Disk drive

c)

Email

d)

Photo editing application

5.

Why do computer systems—hardware, software, and data—deserve security protection?

a)

Because they are expensive to replace

b)

Because they have value

c)

Because they are always online

d)

Because they are used for entertainment

6.

Given the list of assets (hardware, software, data), which combination would be most important to protect for a student working on a class project?

a)

Only hardware

b)

Only software

c)

Hardware and data

d)

Hardware, software, and data

7.

Which of the following statements best describes how the value of an asset is determined?

a)

The value of an asset is always based on its monetary cost.

b)

The value of an asset depends on the asset owner's or user's perspective and may be independent of monetary cost.

c)

The value of an asset is determined by how old it is.

d)

The value of an asset is only based on its physical appearance.

8.

Which of the following is considered a hardware asset?

a)

Documents

b)

Operating system

c)

Computer

d)

Photos

9.

According to the diagram, which type of asset is described as "unique; irreplaceable"?

a)

Network gear

b)

Commercial applications

c)

Individual applications

d)

Documents

10.

Why are asset values often considered imprecise?

a)

Because they are always based on market price.

b)

Because they are personal, time dependent, and can vary.

c)

Because they are determined by government regulations.

d)

Because they are always the same for everyone.

11.

Which of the following is NOT listed as a type of data asset in the material?

a)

Photos

b)

Music, videos

c)

Printer

d)

Class projects

12.

Value-based decisions regarding assets can occur even when we are not aware of them. Which statement best explains why this happens?

a)

Value-based decisions only occur when we consciously think about asset value.

b)

We make value-based decisions frequently, even when we are not aware of them, because asset value is personal and may not be tied to monetary cost.

c)

Value-based decisions are only made by financial experts.

d)

Value-based decisions are always based on the age of the asset.

13.

What is the primary goal of computer security according to the Vulnerability–Threat–Control Paradigm?

a)

To protect valuable assets.

b)

To increase system speed.

c)

To reduce software costs.

d)

To improve user interface design.

14.

Which of the following best defines a vulnerability in a computer system?

a)

A weakness in the system that might be exploited to cause loss or harm.

b)

A software update that improves performance.

c)

A backup copy of important files.

d)

A user account with strong authentication.

15.

What is a threat to a computing system?

a)

A set of circumstances that has the potential to cause loss or harm.

b)

A new software feature.

c)

A type of hardware upgrade.

d)

A method for data backup.

16.

The Vulnerability–Threat–Control Paradigm helps in studying computer security by:

a)

It provides a framework to describe how assets may be harmed and how to counter or mitigate that harm.

b)

It focuses only on hardware improvements.

c)

It eliminates the need for user training.

d)

It only deals with software updates.

17.

What is an attack in the context of system security?

a)

An action that exploits a vulnerability in a system

b)

A device that protects a system

c)

A procedure that removes threats

d)

A technique for improving system performance

18.

Which of the following best describes a control or countermeasure?

a)

An action, device, procedure, or technique that removes or reduces a vulnerability

b)

A threat to a system

c)

A vulnerability in a system

d)

A method for launching attacks

19.

What blocks a threat according to the provided material?

a)

Control of a vulnerability

b)

Launching an attack

c)

Increasing system performance

d)

Ignoring the threat

20.

Why is it important to know the kinds of harm before protecting assets?

a)

To understand what we need to protect assets against

b)

To increase the value of assets

c)

To make assets more vulnerable

d)

To launch attacks on other systems

21.

Controls prevent threats from exercising which of the following?

a)

Vulnerabilities

b)

Countermeasures

c)

Assets

d)

Procedures

22.

Which of the following best defines a threat in the context of a system or organization?

a)

A potential cause of an unwanted impact

b)

A guaranteed event that improves security

c)

A routine maintenance procedure

d)

A method for increasing system performance

23.

Which of the following is NOT a category of threats mentioned in the material?

a)

Financial threats

b)

Natural threats

c)

Human threats

d)

Environmental threats

24.

What are the two perspectives from which threats can harm assets?

a)

What bad things can happen to assets, and who or what can cause or allow those bad things to happen

b)

How assets are created, and how assets are destroyed

c)

Who owns the assets, and who manages the assets

d)

What assets are valuable, and what assets are replaceable

25.

Which property refers to the ability of a system to ensure that an asset can be used by any authorized parties?

a)

Availability

b)

Integrity

c)

Confidentiality

d)

Reliability

26.

If a system ensures that an asset is modified only by authorized parties, which property is being protected?

a)

Integrity

b)

Availability

c)

Confidentiality

d)

Accessibility

27.

Confidentiality in a system means:

a)

An asset is viewed only by authorized parties

b)

An asset is available to everyone

c)

An asset is modified by anyone

d)

An asset is destroyed after use

28.

Which of the following is an effective way to address the threat of unauthorized access to confidential information in a security system?

a)

Allow all employees unrestricted access to all information

b)

Implement access controls and encryption to ensure only authorized parties can view confidential information

c)

Ignore the threat and focus on system performance

d)

Share confidential information with external parties for transparency

29.

Given the definitions of availability, integrity, and confidentiality, which property would be most affected if a system is frequently offline and authorized users cannot access assets?

a)

Availability

b)

Integrity

c)

Confidentiality

d)

Usability

30.

Which of the following is NOT one of the main objectives of information security?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Profitability

31.

What does the term "confidentiality" refer to in the context of information security?

a)

Ensuring information is always accurate

b)

Making information available to everyone

c)

Preventing unauthorized access to information

d)

Allowing information to be changed freely

32.

Which objective of information security focuses on safeguarding the accuracy and completeness of assets?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Accessibility

33.

If a system ensures that information is accessible and usable on demand by an authorized entity without delay, which objective of information security is being addressed?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Privacy

34.

A hospital wants to ensure that patient records are not disclosed to unauthorized staff, that the records are accurate, and that doctors can access them whenever needed. Which three objectives of information security are being addressed in this scenario?

a)

Confidentiality, Integrity, Availability

b)

Privacy, Accuracy, Accessibility

c)

Security, Usability, Completeness

d)

Authorization, Authentication, Accounting

35.

Which of the following best defines confidentiality in the context of information security?

a)

Limiting access to information only to those who need it and preventing access by those who do not

b)

Allowing everyone to access information freely

c)

Ensuring information is always available to authorized users

d)

Making information public for transparency

36.

Which of the following is NOT a measure used to protect the confidentiality of information?

a)

Information classification

b)

Secure document and data storage

c)

Application of general security policies

d)

Public sharing of sensitive data

37.

Why is cryptography (encryption) important for maintaining confidentiality?

a)

It makes information unreadable to unauthorized users

b)

It deletes information permanently

c)

It increases the speed of data transmission

d)

It allows anyone to access the information

38.

Suppose an organization fails to educate its information custodians and end users about security policies. What potential risk does this pose to confidentiality?

a)

Increased likelihood of unauthorized access to information

b)

Improved security of information

c)

Reduced need for encryption

d)

Enhanced classification of information

39.

If unauthorized individuals or systems can view information, what has occurred?

a)

Confidentiality has been breached

b)

Information has been classified

c)

Encryption has been applied

d)

Security policies have been enforced

40.

Which of the following best describes a failure of data confidentiality?

a)

An unauthorized person accesses a data item.

b)

A person authorized to access a data item uses it for its intended purpose.

c)

Data is lost due to hardware failure.

d)

Data is encrypted before transmission.

41.

Which scenario is an example of a specialized failure of data confidentiality?

a)

A person authorized to access certain data accesses other data not authorized.

b)

A person authorized to access data shares it with another authorized person.

c)

Data is backed up regularly.

d)

Data is stored in a secure location.

42.

If an unauthorized person learns that a company is developing a new product, which property of data confidentiality has failed?

a)

The existence of a piece of data has been disclosed.

b)

The data has been deleted.

c)

The data has been encrypted.

d)

The data has been backed up.

43.

A person does not know someone’s exact salary but knows it falls within a certain range. What type of data confidentiality failure does this represent?

a)

Access to an approximate data value.

b)

Complete data loss.

c)

Data integrity failure.

d)

Data availability failure.

44.

An unauthorized process accessing a data item is considered a failure of data confidentiality because:

a)

Confidentiality requires that only authorized entities can access data.

b)

Confidentiality is not related to data access.

c)

Authorized processes are allowed to access any data.

d)

Unauthorized processes always delete data.

45.

What term is used to refer to a person, process, or program that is authorized to access a data item?

a)

Subject

b)

Object

c)

Access mode

d)

Policy

46.

In the context of confidentiality, what is the term for the data item being accessed?

a)

Subject

b)

Object

c)

Access mode

d)

Policy

47.

Which of the following best describes "access mode" in the context of confidentiality?

a)

The person accessing the data

b)

The type of access such as read, write, or execute

c)

The data item being accessed

d)

The authorization for access

48.

What is the term for the authorization that determines whether access to a data item is allowed?

a)

Subject

b)

Object

c)

Access mode

d)

Policy

49.

Given a scenario: A user attempts to write to a file. According to the confidentiality pattern described, identify the subject, object, access mode, and policy in this scenario.

a)

Subject: user; Object: file; Access mode: write; Policy: authorization to write

b)

Subject: file; Object: user; Access mode: read; Policy: authorization to read

c)

Subject: user; Object: file; Access mode: read; Policy: authorization to execute

d)

Subject: process; Object: data; Access mode: execute; Policy: authorization to write

50.

Which three elements are combined in an access control policy to determine if access is granted?

a)

Who, What, How

b)

When, Where, Why

c)

Who, When, Where

d)

What, Why, When

51.

In the context of access control, what does the term "subject" refer to?

a)

The person or entity requesting access

b)

The file or resource being accessed

c)

The method of access

d)

The security policy

52.

According to the diagram, what does "object" represent in access control?

a)

The resource or item being accessed

b)

The person accessing the system

c)

The password used

d)

The network connection

53.

If a policy is defined as "Who + What + How = Yes/No", what is the primary purpose of this policy in access control?

a)

To determine whether access should be granted or denied

b)

To monitor network traffic

c)

To encrypt data

d)

To create user accounts

54.

Given a scenario where a user tries to open a file using a specific application, how would the access control policy components apply?

a)

The user is the subject, the file is the object, and the application is the mode of access

b)

The file is the subject, the user is the object, and the application is the policy

c)

The application is the subject, the user is the object, and the file is the mode of access

d)

The user is the object, the file is the subject, and the application is the policy

55.

Which of the following best defines the concept of integrity in information security?

a)

The ability to access information from anywhere at any time

b)

The completeness and authenticity of information, protected from corruption and unauthorized modification

c)

The process of encrypting data to prevent unauthorized access

d)

The speed at which information can be transmitted over a network

56.

According to Welke and Mayfield, which of the following is NOT one of the three particular aspects of integrity?

a)

Authorized actions

b)

Separation and protection of resources

c)

Error detection and correction

d)

Data encryption

57.

Which of the following is a sign that the integrity of an item has been preserved?

a)

The item is modified only by unauthorized people

b)

The item is internally consistent and meaningful

c)

The item is frequently corrupted by computer viruses

d)

The item is always encrypted

58.

What is a common threat to the integrity of information during transmission?

a)

Data compression

b)

Computer viruses and worms

c)

Increased bandwidth

d)

User authentication

59.

Which procedure can help enforce integrity in information systems, similar to confidentiality?

a)

Allowing unrestricted access to all resources

b)

Rigorous control of who or what can access which resources in what ways

c)

Disabling error detection mechanisms

d)

Ignoring unauthorized modifications

60.

What does "availability of information" mean?

a)

Information can be accessed by authorized users in a usable format.

b)

Information is always accessible to any user.

c)

Information is only accessible to system administrators.

d)

Information is never accessible to users.

61.

Which of the following is NOT a requirement for a service to be considered available?

a)

The service is present in a usable form.

b)

The service has enough capacity to meet needs.

c)

The service is completed in an acceptable period of time.

d)

The service is only accessible to unauthorized users.

62.

Availability applies to which of the following?

a)

Only to data

b)

Only to services

c)

Both data and services (information and information processing)

d)

Only to hardware

63.

A service is thought to be available if it is making clear progress and, if in wait mode, it has which of the following?

a)

Unlimited waiting time

b)

Bounded waiting time

c)

No waiting time

d)

Random waiting time

64.

Why does availability not imply that information is accessible to any user?

a)

Because information should only be accessed by authorized users when needed.

b)

Because information is always public.

c)

Because information is never stored in a usable format.

d)

Because information is only for system administrators.

65.

A service is present in a usable form but does not have enough capacity to meet the service’s needs. Is it considered available?

a)

No, because availability requires enough capacity to meet the service’s needs.

b)

Yes, as long as it is present in a usable form.

c)

Yes, if it is completed in an acceptable period of time.

d)

No, because only data availability matters.

66.

Which of the following is a criterion for defining availability in a system?

a)

There is a timely response to our request.

b)

The system is always online.

c)

The system uses the latest technology.

d)

The system is only accessible to administrators.

67.

Why is fair allocation of resources important for system availability?

a)

It ensures that some requesters are not favored over others.

b)

It increases the speed of the system.

c)

It reduces the cost of operation.

d)

It allows only one user at a time.

68.

Which concept is involved in controlling concurrency for system availability?

a)

Simultaneous access, deadlock management, and exclusive access

b)

Only allowing one user at a time

c)

Disabling all network connections

d)

Ignoring user requests

69.

A system that follows a philosophy of fault tolerance will:

a)

Gracefully cease service or provide workarounds during hardware or software faults

b)

Crash immediately when a fault occurs

c)

Ignore all faults and continue operating

d)

Require manual intervention for every fault

70.

Which of the following best describes a system with high availability?

a)

It can be used easily and in the way it was intended to be used.

b)

It requires complex procedures for every operation.

c)

It is only accessible during business hours.

d)

It frequently loses information during faults.

71.

Given a scenario where a system experiences a hardware fault, what should a highly available system do according to the criteria listed?

a)

Provide a workaround or gracefully cease service rather than crash and lose information.

b)

Immediately shut down and lose all data.

c)

Ignore the fault and continue as normal.

d)

Require users to manually fix the issue before continuing.

72.

Which of the following is the correct term for the mode of access that involves viewing a data item in computer security?

a)

Integrity

b)

Availability

c)

Confidentiality

d)

Usability

73.

In computer security, what does modifying a data item refer to?

a)

Confidentiality

b)

Integrity

c)

Fault Tolerance

d)

Capacity

74.

Which mode of access does computer security seek to preserve when a person or system uses a data item?

a)

Performance

b)

Availability

c)

Capacity

d)

Confidentiality

75.

Based on the diagram, which aspect is at the center and is related to capacity, performance, fault tolerance, and usability?

a)

Integrity

b)

Confidentiality

c)

Availability

d)

Performance

76.

The concepts of confidentiality, integrity, and availability work together to preserve computer security by:

a)

Focusing only on preventing unauthorized access.

b)

Ensuring data can be viewed, modified, and used securely.

c)

Being unrelated aspects of computer security.

d)

Applying only to physical security measures.

77.

Which of the following is commonly referred to as the foundation for thinking about security in computer systems?

a)

C-I-A triad

b)

OSI model

c)

TCP/IP stack

d)

Moore's Law

78.

According to ISO 7498-2, which property allows a system to confirm the identity of a sender?

a)

Authentication

b)

Confidentiality

c)

Integrity

d)

Availability

79.

What is the main purpose of nonrepudiation or accountability in computer security?

a)

To ensure a sender cannot convincingly deny having sent something

b)

To encrypt data during transmission

c)

To prevent unauthorized access to data

d)

To increase system performance

80.

Which property, as added by the U.S. Department of Defense, allows a system to trace all actions related to a given asset?

a)

Auditability

b)

Confidentiality

c)

Authentication

d)

Availability

81.

How do authenticity and nonrepudiation extend security notions in network communications?

a)

By confirming sender identity and preventing denial of sent messages

b)

By encrypting all network traffic

c)

By increasing network speed

d)

By reducing the need for passwords

82.

Why is auditability important in computer security?

a)

It establishes individual accountability for computer activity

b)

It prevents viruses from infecting the system

c)

It increases the speed of data transmission

d)

It allows unlimited access to resources

83.

Strategically, why might an organization prioritize implementing auditability in their security framework?

a)

To trace all actions and establish accountability for computer activity

b)

To reduce hardware costs

c)

To improve user interface design

d)

To increase the number of users

84.

Which of the following best describes the concept of "Confidentiality" in the context of company email communication?

a)

Ensuring that only intended recipients can access the contents of email communication.

b)

Making sure emails are sent quickly.

c)

Allowing all employees to read any email.

d)

Modifying emails before sending them.

85.

What does "Integrity" mean in the context of company email communication?

a)

Emails are not modified from their original form when received or sent.

b)

Emails are always available to users.

c)

Only authorized users can access emails.

d)

Emails are deleted after being read.

86.

Why is "Availability" important for a company's email service?

a)

Because email communication must be accessible at all times for business operations.

b)

So that emails can be modified easily.

c)

To ensure only managers can access emails.

d)

To prevent emails from being sent.

87.

A company wants to ensure that only the intended recipients can read the contents of an email. Which principle of the CIA triad does this address?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Accountability

88.

If an employee receives an email that has been altered from its original form, which aspect of the CIA triad has been compromised?

a)

Integrity

b)

Availability

c)

Confidentiality

d)

Authenticity

89.

A company’s email service goes down for several hours, impacting communication. Which part of the CIA triad is most affected?

a)

Availability

b)

Integrity

c)

Confidentiality

d)

Reliability

90.

Given the scenario where a company shares reports and communicates with customers via email, which CIA principle ensures that the information in the emails remains unchanged during transmission?

a)

Integrity

b)

Confidentiality

c)

Availability

d)

Accessibility

91.

Which of the following is an example of maintaining confidentiality in email communication?

a)

Using strong passwords known only to the user.

b)

Allowing anyone to access the email server.

c)

Modifying the content of emails before sending.

d)

Making emails available only during business hours.

92.

If a company ensures its email service is operational 24/7, which CIA principle is being prioritized?

a)

Availability

b)

Integrity

c)

Confidentiality

d)

Scalability

93.

Which of the following acts can cause harm to assets according to the CIA perspective?

a)

Interception, interruption, modification, and fabrication

b)

Encryption, deletion, duplication, and restoration

c)

Authentication, authorization, accounting, and auditing

d)

Prevention, detection, correction, and recovery

94.

What aspect of security is compromised if someone intercepts data?

a)

Confidentiality

b)

Availability

c)

Integrity

d)

Accountability

95.

If a flow of data or access to a computer is interrupted, which security principle is affected?

a)

Availability

b)

Integrity

c)

Confidentiality

d)

Authenticity

96.

Which act can lead to the failure of integrity in a computer system?

a)

Modification or fabrication of data

b)

Interception of data

c)

Interruption of data flow

d)

Encryption of data

97.

How can understanding the four acts of harm (interception, interruption, modification, fabrication) help in computer security?

a)

It helps determine what threats might exist against the computers you are trying to protect.

b)

It helps in designing faster computer hardware.

c)

It helps in improving user interface design.

d)

It helps in reducing the cost of computer systems.

98.

Which of the following is NOT one of the main goals of computer security?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Profitability

99.

Computer security aims to prevent unauthorized viewing of data. What is this principle called?

a)

Integrity

b)

Confidentiality

c)

Availability

d)

Accessibility

100.

Computer security must balance preventing unauthorized modification of data with preserving access. Which of the following best illustrates a situation where both data integrity and availability are considered?

a)

By making all data public and accessible to everyone at all times.

b)

By ensuring only authorized users can modify data, but all users can access it at any time; for example, in online banking, users must be able to view their account (availability) but only authorized changes are allowed (integrity).

c)

By restricting access to all data, preventing both viewing and modification.

d)

By allowing anyone to modify data as long as they can access it.