Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

IAS FQ TOF 50

Total questions: 50

Worksheet time: 25mins

Name
Class
Date
1.

STRIDE identifies threats by categorizing attacker motivations.

a)

True

b)

False

2.

DREAD measures threat severity using five scoring factors.

a)

True

b)

False

3.

OCTAVE focuses more on technical vulnerabilities than organizational risks.

a)

True

b)

False

4.

RMF’s “Monitor” step occurs after system authorization.

a)

True

b)

False

5.

Spoofing refers to unauthorized data modification.

a)

True

b)

False

6.

A vulnerability alone already causes risk even without threats.

a)

True

b)

False

7.

Backups are considered preventive controls.

a)

True

b)

False

8.

Impact refers to how likely an attack will occur.

a)

True

b)

False

9.

Antivirus software is designed primarily as a preventive control.

a)

True

b)

False

10.

Attack Trees visually show multiple possible attack paths.

a)

True

b)

False

11.

MFA is an example of a corrective control.

a)

True

b)

False

12.

Discoverability measures how easy it is to detect an attack after it occurs.

a)

True

b)

False

13.

RMF requires selecting controls before implementing them.

a)

True

b)

False

14.

Information disclosure involves modifying stored data.

a)

True

b)

False

15.

Phishing emails represent vulnerabilities in an organization.

a)

True

b)

False

16.

Assets are any resources requiring protection.

a)

True

b)

False

17.

A failed login attempt is automatically a threat.

a)

True

b)

False

18.

DREAD’s Affected Users factor considers the number of impacted individuals.

a)

True

b)

False

19.

OCTAVE evaluates asset value during the assessment.

a)

True

b)

False

20.

Preventive controls detect anomalies.

a)

True

b)

False

21.

Tampering refers to altering data without authorization.

a)

True

b)

False

22.

RMF’s “Authorize” step guarantees security forever.

a)

True

b)

False

23.

Threats and vulnerabilities must both exist to produce risk.

a)

True

b)

False

24.

Cost-benefit analysis ensures that only cheap controls are selected.

a)

True

b)

False

25.

PASTA simulates possible attacker activities.

a)

True

b)

False

26.

Attack Trees give details on financial impacts of risks.

a)

True

b)

False

27.

Repudiation means denying involvement in an action.

a)

True

b)

False

28.

DREAD’s Damage Potential measures how destructive a threat can be.

a)

True

b)

False

29.

Monitoring logs is a detective control.

a)

True

b)

False

30.

Risk identification includes locating possible weaknesses.

a)

True

b)

False

31.

NIST RMF requires ongoing monitoring of controls.

a)

True

b)

False

32.

Backups restore systems after incidents.

a)

True

b)

False

33.

A threat cannot exist without vulnerabilities.

a)

True

b)

False

34.

Attack Trees use a root node to represent the final attacker objective.

a)

True

b)

False

35.

Impact refers to potential consequences of a threat.

a)

True

b)

False

36.

User training is considered a detective control.

a)

True

b)

False

37.

STRIDE is most often used for system design threat modeling.

a)

True

b)

False

38.

The OCTAVE model is typically used by small home users.

a)

True

b)

False

39.

Vulnerabilities always come from external attackers.

a)

True

b)

False

40.

RMF requires implementing controls before assessing them.

a)

True

b)

False

41.

Cost-benefit analysis measures if a control’s advantages exceed its total cost.

a)

True

b)

False

42.

Spoofing includes pretending to be another user.

a)

True

b)

False

43.

Discoverability measures how easy it is to find a weakness.

a)

True

b)

False

44.

A risk with low impact can still be considered high priority.

a)

True

b)

False

45.

STRIDE includes Denial of Service as one category.

a)

True

b)

False

46.

OCTAVE only applies to physical security threats.

a)

True

b)

False

47.

Detective controls help discover unusual or unauthorized activity.

a)

True

b)

False

48.

Impact assessment happens before vulnerability identification.

a)

True

b)

False

49.

An asset must always be a physical device.

a)

True

b)

False

50.

Backups are essential for critical systems to minimize data loss.

a)

True

b)

False