wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CPTECH COE221 Midterm Exam

Total questions: 66

Worksheet time: 26mins

Name
Class
Date
1.

1)      Security controls are implemented in the risk management to

a)

Mitigate the risk to an acceptable level

b)

Eliminate all vulnerabilities

c)

Ensure that a cyberattack would be impossible

d)

All of the above

2.

1)      Security controls are implemented in the risk management to

a)

Mitigate the risk to an acceptable level

b)

Eliminate all vulnerabilities

c)

Ensure that a cyberattack would be impossible

d)

All of the above

3.

 As an information security professional, you are expected to uphold

a)

Secrecy and confidentiality

b)

Just enough ethical standards and professional integrity

c)

Honorable, honest, just, and responsible within legal conduct

d)

Produce the fastest results with high impact

4.

It means that systems and data are accessible at the time users need them

a)

Integrity

b)

Availability

c)

Confidentiality

d)

None of the above

5.

Example of “something you know” authentication factor

a)

Passphrase

b)

Fingerprint

c)

UserID

d)

Iris scan

6.

What is redbook?

a)

An outlined procedure for employees

b)

Hard copy accessible outside the facility

c)

Back up copy for business continuity plan

d)

Document to be distributed to employees

7.

Another term for incident management

a)

Crisis management

b)

Incident report

c)

Crisis response

d)

Safety management

8.

Which is NOT a common component of comprehensive business plan continuity?

a)

Notification systems

b)

Guidance for management

c)

Immediate response

d)

Contact numbers of employees

9.

What is the key outcome of Business Impact Analysis (BIA)

a)

 Transition to permanent office space

b)

 Immediate effect on other areas of work

c)

Importance of customer staff

d)

 Identification of functions and dependencies

10.

It refers to restoring the information technology and communication services and systems needed by the organization

a)

Disaster recovery

b)

Business function

c)

Continuity plan

d)

Business preparation

11.

Which of the following is very likely to be used in a disaster recovery (DR) effort?

a)

 Contact personnel

b)

Data backups

c)

Anti-malware solutions

d)

 All of the above

12.

What is the purpose of the Executive Summary in a Disaster Recovery Plan?

a)

To list department-specific plans

b)

To serve as a checklist for critical team members

c)

To offer a high-level overwiew of the plan

d)

All of the above

13.

Who must provide support for business continuity planning efforts?

a)

Frontline employees

b)

External consultants

c)

Executive management and an executive sponsor

d)

Middle management

14.

Which of the following components is very likely to be instrumental to any disaster recovery report?

a)

Backups

b)

Firewall

c)

Router

d)

Laptops

15.

Why is it necessary to consider not only the server level but also the database and dependencies on other systems in disaster recovery plans for complex systems?

a)

To reduce storage costs

b)

To streamline the disaster recovery process

c)

To comply with legal regulations

d)

To address the intricate dependencies of the systems

16.

What is the next step after detection and analysis in the incident response process?

a)

Finding the appropriate containment strategy

b)

External investigation involving law enforcement

c)

Internal audit of the organization

d)

Identifying attackers and their motives

17.

What is the definition of an object in the context of access controls?

a)

A device with onboard firmware

b)

An entity that responds to a request for service

c)

Anything that initiates a request for service

d)

Something that contains its own access control logic

18.

What is the strategy that integrates people, technology, and operations capabilities to establish variable barriers across multiple layers and missions of an organization?

a)
  1. Layered Defense

b)
  1. Cyberattack Prevention

c)

  1. Multi-Factor Authentication

d)

Single Point of Failure

19.

How does privileged access management implement the principle of least privilege?

a)

By providing access based on seniority

b)

By restricting access to only the most critical information

c)

By granting maximum access to all users

d)

By granting each user access only to the items they need

20.

Which is NOT an example of a logical access control method?

a)
  1. Password

b)
  1. Biometrics on a smartphone

c)
  1. Badge/token readers

d)
  1. Presentation of ID cards

21.

Limiting access to data on the network would be considered which of the following controls?

a)

Physical controls

b)

Administrative controls

c)

Virtualization controls

d)

Logical or technical controls

22.

What would be considered an administrative control in the context of seat belt usage?

a)

Attaching the seat belt to the car

b)

Building a car with seat belts

c)

Passing a law requiring seat belt use

d)

Using the seat belt

23.

What alternative control could be used if biometric locks on multiple doors are not necessary and access does not need to be audited?

a)

Installing a permanent wall

b)

Replacing doors with deadbolt locks

c)

Removing doors and securing the area permanently

d)

Implementing biometric scanners on all doors

24.

In what type of environment does role-based access control work well?

a)

Low-staff turnover

b)

Limited access requirements for all personnel

c)

Single personnel with unique access requirements

d)

High-staff turnover and similar access requirements

25.

What term is used to describe the situation where someone inherits expanded permissions that are not appropriate for their role in Role-based Access Control (RBAC)?

a)

Privilege creep

b)

Permissions anomaly

c)

Role deviation

d)

Access overflow

26.

What is the key feature of just-in-time privileged access management?

a)

Role-based subsets of privileges

b)

Unrestricted access

c)

Permanent administrative access

d)

Static privileges

27.

In Mandatory Access Control (MAC), what determines the level of access to certain areas in certain government agencies?

a)

Individual judgment

b)

Owner's discretion

c)

On a request basis

d)

Government policy and security clearance

28.

Who can modify security rules in a system governed by Mandatory Access Control (MAC)?

a)

All subjects within the system

b)

Randomly selected users

c)

Object owners at their discretion

d)

Trusted subjects designated as security administrators

29.

Which of these combinations of physical security controls share a single point of failure?

a)

Dogs and bollards

b)

High-illumination lighting and cameras

c)

Guards and fences

d)

Badge readers and walls

30.

Which of the following is an example of a physical access control?

a)
  1. Motion detectors

b)
  1. Firewalls

c)
  1. Encryption algorithms

d)
  1. Antivirus software

31.

Duncan and Mira work in the data center at Triffid, Inc. There is a policy in place that requires both to be present in the data center at the same time. If one has to leave for any reason, the other must step out, too, until they can both re-enter. This is called ________.

a)
  1. Blockade

b)
  1. Two-person integrity

c)
  1. Defense in depth

d)
  1. Multifactor authentication

32.

Why is Discretionary Access Control (DAC) not considered very scalable?

a)

It is a hardware-intensive approach

b)

It relies on the discretion of individual object owners

c)

It relies on mandatory access controls

d)

It uses advanced encryption techniques

33.

What is the two-person rule in the context of security strategy?

a)

Two people must have the same combination

b)

Two people must have access to the same information

c)

Two people must be in an area together

d)

Two people must perform the same duties

34.

Why is it recommended to disable accounts for a period before deletion when an employee leaves the company?

a)

To preserve the integrity of audit trails or files

b)

To allow the separated employee access to dat

c)

So the ex-employee can't steal secrets

d)

To speed up the account deletion process

35.

What is user provisioning in identity management?

a)

Ensuring a user can always control what they want to access

b)

Managing access to resources and information systems

c)

Enabling the option to delete a users account

d)

Ensuring that users are conducting regular antivirus scans

36.

Which of the following is the responsibility of systems administrators who use privileged accounts?

a)

Managing financial transactions

b)

Handling customer service

c)

Operating systems and applications

d)

Marketing and promotions

37.

What does behavioral biometrics measure?

a)

User actions, such as voiceprints and keystroke dynamics

b)

Physiological attributes

c)

Characteristics like fingerprint and iris scan

d)

Environmental design elements

38.

Which is a physical control that prevents "piggybacking" or "tailgating," when an unauthorized person follows an authorized person into a controlled area?

a)
  1. Wall

b)
  1. Turnstile

c)
  1. Fence

d)
  1. Bollard

39.

Which of the following best describes a security control?

a)

A method for creating user accounts in a system

b)

A safeguard designed to preserve the Confidentiality, Integrity, and Availability of data

c)

A protocol for sending emails securely

d)

A process to speed up network traffic

40.

Which of the following statements correctly distinguishes subjects from objects in access control?

a)

Subjects are passive and objects are active in accessing resources

b)

Subjects and objects are always the same entity in access control

c)

Objects have clearance levels, while subjects store data

d)

Subjects initiate requests for services, while objects respond to these requests

41.

Example of “something you know” authentication factor

a)

Passphrase

b)

Fingerprint

c)

UserID

d)

Iris scan

42.

It means that systems and data are accessible at the time users need them.

a)

Availability

b)

Integrity

c)

Confidentiality

d)

None of the above

43.

As an information security professional, you are expected to uphold

a)

Honorable, honest, just, and responsible within legal conduct

b)

Secrecy and confidentiality

c)

Just enough ethical standards and professional integrity

d)

Produce the fastest results with high impact

44.

Security controls are implemented in the risk management.

a)

Mitigate the risk to an acceptable level

b)

Eliminate all vulnerabilities

c)

Ensure that a cyberattack would be impossible

d)

All of the above

45.

In an analogy, if the attack vector would be their technique and approach, a pickpocket is considered _____

a)

vulnerabilities

b)

stolen goods

c)

liabilities

d)

treat

46.

Which of the following best distinguishes machine learning from traditional programming?

a)

Machine learning requires data

b)

Machine learning systems learn patterns from data instead of following explicit rules

c)

Machine learning programs are always faster

d)

Machine learning use algorithms

47.

Which algorithm is an example of supervised learning?

a)

 K-means clustering

b)

Principal Component Analysis (PCA)

c)

Linear regression

d)

Apriori algorithm

48.

In deep learning, what is the primary function of an activation function?

a)

To initialize weights

b)

To reduce training time

c)

To introduce non-linearity into the model

d)

To normalize the dataset

49.

What is feature engineering primarily concerned with?

a)

Transforming raw data into meaningful input features

b)

Selecting hardware for computation

c)

Training the model faster

d)

Deploying models into production

50.

Which model architecture is most commonly associated with modern generative AI systems?

a)

Decision Trees

b)


Support Vector Machines

c)

Naive Bayes

d)

Transformers

51.

Which of the following is a real-world application of AI in healthcare?

a)

Manual record keeping

b)

Image-based disease diagnosis

c)

Paper-based scheduling

d)

Handwritten prescriptions

52.

What is a key consideration when deploying AI models in real-world systems?

a)

Model accuracy only

b)

Ethical, security, and scalability concerns

c)

The number of training epochs

d)

The color of the user interface

53.

Which sensor is commonly used for measuring distance in mobile robots?

a)

Gyroscope

b)

Temperature sensor

c)

Ultrasonic sensor

d)

Load cell

54.

What is the primary function of an actuator in a robotic system?

a)

To process data

b)

To sense the environment

c)

To store energy

d)

To convert electrical signals into physical motion

55.

Which programming framework is widely used for robot software development?

a)

TensorFlow

b)

Hadoop

c)

ROS (Robot Operating System)

d)

MATLAB Excel

56.

Which of the following is a common application of robotics in industry?

a)

Automated assembly lines

b)

Automated data entry

c)

Automated handwritten documentation

d)

Automated voice-based translation

57.

Which task is a common application of Natural Language Processing?

a)

Image segmentation

b)

Signal amplification

c)

Hardware acceleration

d)

Sentiment analysis of text

58.

A smartphone uses facial recognition to unlock the device. Which machine learning approach is most commonly used for this real-life application?

a)

Linear regression

b)

Decision trees

c)

Convolutional Neural Networks (CNNs)

d)

K-means clustering

59.

The loss of control, compromise,
unauthorized disclosure, unauthorized
acquisition, or any similar occurrence where:
a person other than an authorized user
accesses or potentially accesses personally
identifiable information; or an authorized
user accesses personally identifiable
information for other than an authorized
purpose.

(a)  

60.

(a)   is any observable occurrence in a network
or system


61.

  (a)   is an instruction developed to allow or deny access to an object by comparing the validated identity of the subject to an access control list.


62.

(a)   is a monitoring example that maintains sign-in sheet maintained by a security guard, or even a log created by an electronic system that manages physical access.

63.

To authenticate a user’s identity, (a)   use characteristics unique to the individual seeking access.

64.

What are the two key physical security measures that help maintain overall organizational security, including access control, monitoring of personnel and equipment, and the auditing and logging of physical security events?

a)

logs

b)

Network firewall

c)

Data backup computers

d)

Security Guards

e)

Installation of computers with antivirus software

65.

Why is robot simulation used before deploying a robot program on physical hardware?

a)

To permanently replace physical robots

b)

To increase robot speed

c)

To test and debug programs safely and reduce hardware damage

d)

To eliminate the need for programming

66.

Which ethical concern is most relevant when deploying robots in workplaces alongside human workers?

a)

Worker safety and job displacement

b)

Battery charging time

c)

Robot processing speed

d)

Programming language compatibility