Font size
WorksheetsCPTECH COE221 Midterm Exam
Total questions: 66
Worksheet time: 26mins
1) Security controls are implemented in the risk management to
Mitigate the risk to an acceptable level
Eliminate all vulnerabilities
Ensure that a cyberattack would be impossible
All of the above
1) Security controls are implemented in the risk management to
Mitigate the risk to an acceptable level
Eliminate all vulnerabilities
Ensure that a cyberattack would be impossible
All of the above
As an information security professional, you are expected to uphold
Secrecy and confidentiality
Just enough ethical standards and professional integrity
Honorable, honest, just, and responsible within legal conduct
Produce the fastest results with high impact
It means that systems and data are accessible at the time users need them
Integrity
Availability
Confidentiality
None of the above
Example of “something you know” authentication factor
Passphrase
Fingerprint
UserID
Iris scan
What is redbook?
An outlined procedure for employees
Hard copy accessible outside the facility
Back up copy for business continuity plan
Document to be distributed to employees
Another term for incident management
Crisis management
Incident report
Crisis response
Safety management
Which is NOT a common component of comprehensive business plan continuity?
Notification systems
Guidance for management
Immediate response
Contact numbers of employees
What is the key outcome of Business Impact Analysis (BIA)
Transition to permanent office space
Immediate effect on other areas of work
Importance of customer staff
Identification of functions and dependencies
It refers to restoring the information technology and communication services and systems needed by the organization
Disaster recovery
Business function
Continuity plan
Business preparation
Which of the following is very likely to be used in a disaster recovery (DR) effort?
Contact personnel
Data backups
Anti-malware solutions
All of the above
What is the purpose of the Executive Summary in a Disaster Recovery Plan?
To list department-specific plans
To serve as a checklist for critical team members
To offer a high-level overwiew of the plan
All of the above
Who must provide support for business continuity planning efforts?
Frontline employees
External consultants
Executive management and an executive sponsor
Middle management
Which of the following components is very likely to be instrumental to any disaster recovery report?
Backups
Firewall
Router
Laptops
Why is it necessary to consider not only the server level but also the database and dependencies on other systems in disaster recovery plans for complex systems?
To reduce storage costs
To streamline the disaster recovery process
To comply with legal regulations
To address the intricate dependencies of the systems
What is the next step after detection and analysis in the incident response process?
Finding the appropriate containment strategy
External investigation involving law enforcement
Internal audit of the organization
Identifying attackers and their motives
What is the definition of an object in the context of access controls?
A device with onboard firmware
An entity that responds to a request for service
Anything that initiates a request for service
Something that contains its own access control logic
What is the strategy that integrates people, technology, and operations capabilities to establish variable barriers across multiple layers and missions of an organization?
Layered Defense
Cyberattack Prevention
Multi-Factor Authentication
Single Point of Failure
How does privileged access management implement the principle of least privilege?
By providing access based on seniority
By restricting access to only the most critical information
By granting maximum access to all users
By granting each user access only to the items they need
Which is NOT an example of a logical access control method?
Password
Biometrics on a smartphone
Badge/token readers
Presentation of ID cards
Limiting access to data on the network would be considered which of the following controls?
Physical controls
Administrative controls
Virtualization controls
Logical or technical controls
What would be considered an administrative control in the context of seat belt usage?
Attaching the seat belt to the car
Building a car with seat belts
Passing a law requiring seat belt use
Using the seat belt
What alternative control could be used if biometric locks on multiple doors are not necessary and access does not need to be audited?
Installing a permanent wall
Replacing doors with deadbolt locks
Removing doors and securing the area permanently
Implementing biometric scanners on all doors
In what type of environment does role-based access control work well?
Low-staff turnover
Limited access requirements for all personnel
Single personnel with unique access requirements
High-staff turnover and similar access requirements
What term is used to describe the situation where someone inherits expanded permissions that are not appropriate for their role in Role-based Access Control (RBAC)?
Privilege creep
Permissions anomaly
Role deviation
Access overflow
What is the key feature of just-in-time privileged access management?
Role-based subsets of privileges
Unrestricted access
Permanent administrative access
Static privileges
In Mandatory Access Control (MAC), what determines the level of access to certain areas in certain government agencies?
Individual judgment
Owner's discretion
On a request basis
Government policy and security clearance
Who can modify security rules in a system governed by Mandatory Access Control (MAC)?
All subjects within the system
Randomly selected users
Object owners at their discretion
Trusted subjects designated as security administrators
Which of these combinations of physical security controls share a single point of failure?
Dogs and bollards
High-illumination lighting and cameras
Guards and fences
Badge readers and walls
Which of the following is an example of a physical access control?
Motion detectors
Firewalls
Encryption algorithms
Antivirus software
Duncan and Mira work in the data center at Triffid, Inc. There is a policy in place that requires both to be present in the data center at the same time. If one has to leave for any reason, the other must step out, too, until they can both re-enter. This is called ________.
Blockade
Two-person integrity
Defense in depth
Multifactor authentication
Why is Discretionary Access Control (DAC) not considered very scalable?
It is a hardware-intensive approach
It relies on the discretion of individual object owners
It relies on mandatory access controls
It uses advanced encryption techniques
What is the two-person rule in the context of security strategy?
Two people must have the same combination
Two people must have access to the same information
Two people must be in an area together
Two people must perform the same duties
Why is it recommended to disable accounts for a period before deletion when an employee leaves the company?
To preserve the integrity of audit trails or files
To allow the separated employee access to dat
So the ex-employee can't steal secrets
To speed up the account deletion process
What is user provisioning in identity management?
Ensuring a user can always control what they want to access
Managing access to resources and information systems
Enabling the option to delete a users account
Ensuring that users are conducting regular antivirus scans
Which of the following is the responsibility of systems administrators who use privileged accounts?
Managing financial transactions
Handling customer service
Operating systems and applications
Marketing and promotions
What does behavioral biometrics measure?
User actions, such as voiceprints and keystroke dynamics
Physiological attributes
Characteristics like fingerprint and iris scan
Environmental design elements
Which is a physical control that prevents "piggybacking" or "tailgating," when an unauthorized person follows an authorized person into a controlled area?
Wall
Turnstile
Fence
Bollard
Which of the following best describes a security control?
A method for creating user accounts in a system
A safeguard designed to preserve the Confidentiality, Integrity, and Availability of data
A protocol for sending emails securely
A process to speed up network traffic
Which of the following statements correctly distinguishes subjects from objects in access control?
Subjects are passive and objects are active in accessing resources
Subjects and objects are always the same entity in access control
Objects have clearance levels, while subjects store data
Subjects initiate requests for services, while objects respond to these requests
Example of “something you know” authentication factor
Passphrase
Fingerprint
UserID
Iris scan
It means that systems and data are accessible at the time users need them.
Availability
Integrity
Confidentiality
None of the above
As an information security professional, you are expected to uphold
Honorable, honest, just, and responsible within legal conduct
Secrecy and confidentiality
Just enough ethical standards and professional integrity
Produce the fastest results with high impact
Security controls are implemented in the risk management.
Mitigate the risk to an acceptable level
Eliminate all vulnerabilities
Ensure that a cyberattack would be impossible
All of the above
In an analogy, if the attack vector would be their technique and approach, a pickpocket is considered _____
vulnerabilities
stolen goods
liabilities
treat
Which of the following best distinguishes machine learning from traditional programming?
Machine learning requires data
Machine learning systems learn patterns from data instead of following explicit rules
Machine learning programs are always faster
Machine learning use algorithms
Which algorithm is an example of supervised learning?
K-means clustering
Principal Component Analysis (PCA)
Linear regression
Apriori algorithm
In deep learning, what is the primary function of an activation function?
To initialize weights
To reduce training time
To introduce non-linearity into the model
To normalize the dataset
What is feature engineering primarily concerned with?
Transforming raw data into meaningful input features
Selecting hardware for computation
Training the model faster
Deploying models into production
Which model architecture is most commonly associated with modern generative AI systems?
Decision Trees
Support Vector Machines
Naive Bayes
Transformers
Which of the following is a real-world application of AI in healthcare?
Manual record keeping
Image-based disease diagnosis
Paper-based scheduling
Handwritten prescriptions
What is a key consideration when deploying AI models in real-world systems?
Model accuracy only
Ethical, security, and scalability concerns
The number of training epochs
The color of the user interface
Which sensor is commonly used for measuring distance in mobile robots?
Gyroscope
Temperature sensor
Ultrasonic sensor
Load cell
What is the primary function of an actuator in a robotic system?
To process data
To sense the environment
To store energy
To convert electrical signals into physical motion
Which programming framework is widely used for robot software development?
TensorFlow
Hadoop
ROS (Robot Operating System)
MATLAB Excel
Which of the following is a common application of robotics in industry?
Automated assembly lines
Automated data entry
Automated handwritten documentation
Automated voice-based translation
Which task is a common application of Natural Language Processing?
Image segmentation
Signal amplification
Hardware acceleration
Sentiment analysis of text
A smartphone uses facial recognition to unlock the device. Which machine learning approach is most commonly used for this real-life application?
Linear regression
Decision trees
Convolutional Neural Networks (CNNs)
K-means clustering
The loss of control, compromise,
unauthorized disclosure, unauthorized
acquisition, or any similar occurrence where:
a person other than an authorized user
accesses or potentially accesses personally
identifiable information; or an authorized
user accesses personally identifiable
information for other than an authorized
purpose.
(a)
(a) is any observable occurrence in a network or system
(a) is an instruction developed to allow or deny access to an object by comparing the validated identity of the subject to an access control list.
(a) is a monitoring example that maintains sign-in sheet maintained by a security guard, or even a log created by an electronic system that manages physical access.
To authenticate a user’s identity, (a) use characteristics unique to the individual seeking access.
What are the two key physical security measures that help maintain overall organizational security, including access control, monitoring of personnel and equipment, and the auditing and logging of physical security events?
logs
Network firewall
Data backup computers
Security Guards
Installation of computers with antivirus software
Why is robot simulation used before deploying a robot program on physical hardware?
To permanently replace physical robots
To increase robot speed
To test and debug programs safely and reduce hardware damage
To eliminate the need for programming
Which ethical concern is most relevant when deploying robots in workplaces alongside human workers?
Worker safety and job displacement
Battery charging time
Robot processing speed
Programming language compatibility
