wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Information Security and Risk Management MCQs

Total questions: 100

Worksheet time: 1hrs 7mins

Name
Class
Date
1.

Which three characteristics form the C.I.A. triad in information security?

a)

Control, Inspection, Accuracy

b)

Confidentiality, Integrity, Availability

c)

Configuration, Identification, Authentication

d)

Communication, Integrity, Authorization

2.

According to the CNSS, information security protects which of the following?

a)

Only the information stored in databases

b)

Only the hardware used to process information

c)

Information and its critical elements, including systems and hardware

d)

Only network devices

3.

Which statement best explains why the C.I.A. triad is considered inadequate today?

a)

It lacks technical controls

b)

Modern information environments require models addressing a broader set of evolving threats

c)

It does not include authentication

d)

It cannot be applied to government systems

4.

What is the primary mission of an information security program?

a)

To eliminate all cyber threats

b)

To ensure information assets remain safe and useful

c)

To maximize system performance

d)

To replace manual business processes

5.

Which of the following best describes “data security”?

a)

Protection of hardware and facilities

b)

Protection of data only when stored

c)

Protection of data at rest, in processing, and in transmission

d)

Protection of network infrastructure only

6.

Why is information security considered primarily a management issue rather than a technical issue?

a)

Most attacks are caused by hardware failures

b)

Security tools automatically enforce policies

c)

Risk management, policy, and enforcement are more critical than technology alone

d)

IT departments are not involved in security

7.

What is the primary goal of risk management in information security?

a)

To eliminate all possible threats

b)

To identify risk, assess its magnitude, and reduce it to an acceptable level

c)

To deploy as many security controls as possible

d)

To ensure maximum system performance

8.

Which term describes the recognition and documentation of risks to information assets?

a)

Risk control

b)

Risk assessment

c)

Risk identification

d)

Risk mitigation

9.

Which three major activities make up the risk management process?

a)

Prevention, detection, response

b)

Identification, assessment, control

c)

Planning, implementation, auditing

d)

Classification, encryption, monitoring

10.

What does risk assessment primarily determine?

a)

The identity of attackers

b)

The value of security software

c)

The likelihood and impact of potential losses

d)

The encryption strength of systems

11.

When does an organization choose the risk acceptance strategy?

a)

When threats cannot be identified

b)

When the cost of protection exceeds the potential loss

c)

When management ignores security risks

d)

When laws require acceptance

12.

Which risk control strategy completely removes an asset from service to eliminate risk?

a)

Mitigation

b)

Acceptance

c)

Transfer

d)

Termination

13.

What is the primary purpose of access control?

a)

Encrypt stored data

b)

Restrict access to authorized users only

c)

Detect malware attacks

d)

Monitor network traffic

14.

Which access control model allows the owner of an object to decide who can access it?

a)

Mandatory Access Control (MAC)

b)

Role-Based Access Control (RBAC)

c)

Discretionary Access Control (DAC)

d)

Attribute-Based Access Control (ABAC)

15.

Which technology is primarily used to separate trusted and untrusted networks?

a)

VPN

b)

Firewall

c)

IDS

d)

Router

16.

Which firewall type filters traffic based on IP addresses and port numbers?

a)

Application-layer firewall

b)

Stateful inspection firewall

c)

Packet-filtering firewall

d)

Circuit-level firewall

17.

Which access control model assigns permissions based on organizational roles?

a)

DAC

b)

MAC

c)

RBAC

d)

TBAC

18.

Which VPN protocol operates at the network (IP) layer?

a)

SSL

b)

IPSec

c)

SSH

d)

HTTPS

19.

Which VPN mode encrypts the entire original IP packet, including its header?

a)

Transport mode

b)

Secure mode

c)

Tunnel mode

d)

Hybrid mode

20.

Which access control model is enforced by a central authority and cannot be modified by users?

a)

DAC

b)

RBAC

c)

MAC

d)

ABAC

21.

Which firewall type examines application-level data payloads?

a)

Packet-filtering firewall

b)

Circuit-level firewall

c)

Application-layer firewall

d)

Screening router

22.

Which term best describes a system that can both detect intrusions and actively prevent them?

a)

Firewall

b)

Intrusion Detection System (IDS)

c)

Intrusion Detection and Prevention System (IDPS)

d)

Virtual Private Network (VPN)

23.

Which of the following is considered the most serious failure of an IDPS?

a)

False positive

b)

Alarm clustering

c)

False negative

d)

Noise

24.

Which detection method compares observed traffic against vendor-supplied models of normal protocol behavior?

a)

Signature-based detection

b)

Anomaly-based detection

c)

Stateful protocol analysis

d)

Log file monitoring

25.

Which term refers to the process of converting a plaintext message into an unreadable form to protect it from unauthorized access?

a)

Cryptanalysis

b)

Encryption

c)

Hashing

d)

Steganography

26.

Which cryptographic method uses the same secret key for both encryption and decryption?

a)

Asymmetric encryption

b)

Public-key encryption

c)

Symmetric encryption

d)

Hash-based encryption

27.

Which cryptographic algorithm became the official U.S. federal standard to replace DES and 3DES?

a)

RSA

b)

AES

c)

SHA-1

d)

Diffie–Hellman

28.

Which term refers to the protection of facilities, equipment, and resources from physical threats such as theft, vandalism, or natural disasters?

a)

Network security

b)

Logical security

c)

Physical security

d)

Operational security

29.

Which physical security control is primarily intended to deter unauthorized access rather than detect it?

a)

Motion detectors

b)

Security guards

c)

Surveillance cameras

d)

Alarm systems

30.

Which concept describes a series of concentric protection zones, each increasing in security closer to the asset?

a)

Defense in depth

b)

Physical layering

c)

Security zoning

d)

Perimeter hardening

31.

Which term refers to a potential danger to an information asset?

a)

Attack

b)

Vulnerability

c)

Threat

d)

Exploit

32.

Which type of attack occurs when an attacker pretends to be a legitimate user or system?

a)

Denial-of-service attack

b)

Spoofing attack

c)

Buffer overflow attack

d)

Brute-force attack

33.

Which attack type specifically exploits poor input validation to overwrite memory and execute malicious code?

a)

SQL injection

b)

Cross-site scripting

c)

Buffer overflow

d)

Replay attack

34.

Which two elements below are explicitly listed as part of “information security” defined by the Committee on National Security Systems (CNSS)?

a)

Data security

b)

Physical security

c)

Network security

d)

Environmental security

35.

Which two threats are explicitly mentioned in the chapter as risks to confidentiality, integrity, and availability?

a)

Unauthorized modification

b)

Natural disasters

c)

Theft

d)

Insider recruitment

36.

Which two statements correctly describe the scope of “security” as defined in the chapter?

a)

Security protects individuals and assets from harm

b)

Security is limited only to protection of information

37.

Which two communities of interest share responsibility for information security?

a)

General management

b)

IT management

c)

External auditors

d)

Customers

38.

Which two are examples of threats to information assets discussed in Chapter 2?

a)

Malware attacks

b)

Social networking

c)

Theft of information

d)

Software licensing

39.

Which two statements correctly describe the difference between threats and attacks?

a)

Threats are always present

b)

Attacks only exist when an action is occurring

c)

Attacks do not cause losses

d)

Threats require exploits to exist

40.

Which two elements are evaluated when calculating risk?

a)

Impact

b)

Likelihood

c)

Encryption strength

d)

User satisfaction

41.

Which two factors influence business risk decisions?

a)

Cost of controls

b)

Benefits of secured systems

c)

Brand color

d)

Office location

42.

Which two activities are part of risk identification?

a)

Asset inventory

b)

Threat prioritization

c)

Firewall configuration

d)

Employee training

43.

Which two plans are considered contingency plans in risk mitigation?

a)

Incident response plan

b)

Disaster recovery plan

c)

Marketing plan

d)

Human resources plan

44.

Which two conditions must be met before selecting risk acceptance as a strategy?

a)

Probability of attack assessed

b)

Cost–benefit analysis completed

c)

System fully encrypted

d)

Users notified

45.

Which two risk control strategies actively reduce risk?

a)

Mitigation

b)

Transfer

c)

Acceptance

d)

Termination

46.

Which two elements are fundamental to access control decisions?

a)

Subject

b)

Object

c)

Encryption key

d)

VPN tunnel

47.

Which two are examples of access control mechanisms?

a)

Access Control Lists (ACLs)

b)

Role assignments

c)

Intrusion detection systems

d)

Data backups

48.

Which two technologies are commonly used to enforce perimeter security?

a)

Firewalls

b)

VPN gateways

c)

File encryption

d)

Hash functions

49.

Which two criteria are typically used by packet-filtering firewalls?

a)

Source IP address

b)

Destination port

50.

Which two benefits are provided by VPN technology?

a)

Confidentiality of data

b)

Secure remote access

c)

Increased transmission speed

d)

Removal of all threats

51.

Which two access control models are considered nondiscretionary?

a)

MAC

b)

RBAC

c)

DAC

d)

ABAC

52.

Which two characteristics describe transport-mode VPNs?

a)

Only the payload is encrypted

b)

Original IP header is visible

c)

Entire packet is encrypted

d)

Requires gateway-to-gateway tunneling

53.

Which two firewall types perform deep packet inspection?

a)

Application-layer firewall

b)

Stateful inspection firewall

c)

Packet-filtering firewall

d)

Static router

54.

Which two elements are required for RBAC to function properly?

a)

Defined roles

b)

Role-permission assignments

c)

Individual encryption keys

d)

Network tunnels

55.

Which two activities are examples of intrusion prevention rather than intrusion detection?

a)

Writing and enforcing enterprise security policies

b)

Logging network packets for later analysis

c)

Installing firewalls and IDPSs

d)

Sending e-mail alerts after an attack

56.

Which TWO capabilities are typical advantages of a host-based IDPS (HIDPS)?

a)

Ability to analyze encrypted traffic

b)

Ability to detect multihost scanning

c)

Monitoring of system configuration files

d)

No performance impact on the host

57.

Which TWO attack-related activities can a Network Behavior Analysis (NBA) IDPS most commonly detect?

a)

Distributed denial-of-service attacks

b)

Unauthorized file modification on a host

c)

Worm propagation

d)

Kernel-level rootkits

58.

Which TWO terms are correctly associated with cryptology?

a)

Cryptography

b)

Cryptanalysis

c)

Steganography only

d)

Network forensics

59.

Which TWO statements correctly describe hash functions?

a)

They generate a fixed-length message digest

b)

They require a secret key for normal operation

c)

They are one-way operations

d)

They produce reversible ciphertext

60.

Which TWO characteristics are advantages of asymmetric (public-key) encryption?

a)

Solves the key distribution problem

b)

Requires only one shared secret key

c)

Uses a public and a private key pair

d)

Is computationally faster than symmetric encryption

61.

Which TWO of the following are examples of natural threats to physical security?

a)

Floods

b)

Earthquakes

c)

Espionage

d)

Theft

62.

Which TWO controls are commonly used to detect unauthorized physical access? Select two.

a)

Closed-circuit television (CCTV)

b)

Biometric authentication

c)

Fences

d)

Lighting

63.

Which TWO physical security measures are most effective for protecting data centers against environmental threats? Select two.

a)

Fire suppression systems

b)

Redundant power supplies

c)

Smart cards

d)

Turnstiles

64.

Which TWO of the following are considered human threats? Select two.

a)

Earthquake

b)

Fire

c)

Espionage

d)

Sabotage

65.

Which TWO attacks primarily target availability of information systems? Select two.

a)

Denial-of-service

b)

Distributed denial-of-service

c)

Phishing

d)

Password guessing

66.

Which TWO attacks are classified as technical attacks rather than social engineering attacks? Select two.

a)

Phishing

b)

Pretexting

c)

Buffer overflow

d)

Malware

67.

The three foundational characteristics of information security are known as the (a)   .

68.

According to CNSS, information security protects information and its (a)   elements.

69.

One major threat category discussed in the chapter includes unintended or unauthorized (a)   of information.

70.

Information that has value to an organization and must be protected is called an (a)   .

71.

An interruption in service from a provider that affects organizational operations is known as (a)   disruption.

72.

Unauthorized duplication or distribution of copyrighted software is known as (a)   .

73.

The process of determining how exposed information assets are to risk is called (a)   .

74.

The application of controls to reduce risk to an acceptable level is known as (a)   .

75.

Risk is calculated using the combination of impact and (a)   .

76.

Risk management decisions are based on balancing security costs and (a)   .

77.

Choosing to do nothing further to protect an asset is called (a)   risk control strategy.

78.

Eliminating risk by removing an information asset from service is known as (a)   .

79.

The process of determining who may access a system resource is called (a)   .

80.

A list that specifies permissions attached to an object is called an (a)   .

81.

Fill the suitable words in the blank: A firewall is primarily used to control (a)   traffic between networks.

82.

Fill the suitable words in the blank: A VPN creates an encrypted (a)   over an untrusted network.

83.

Fill the suitable words in the blank: Firewalls that track the state of active connections are called (a)   firewalls.

84.

Fill the suitable words in the blank: In RBAC, users obtain permissions by being assigned to (a)   .

85.

Fill the suitable words in the blank: MAC systems enforce security labels based on centrally defined (a)   .

86.

Fill the suitable words in the blank: In tunnel mode VPNs, the entire original IP (a)   is encrypted.

87.

Fill the suitable words in the blank: Firewalls that act as intermediaries between clients and servers are known as (a)   firewalls.

88.

Fill the suitable words in the blank: An (a)   occurs when an attacker attempts to gain unauthorized access to an information system or disrupt its normal operations.

89.

Fill the suitable words in the blank: The process of grouping similar IDPS alerts that occur close together in time is called (a)   .

90.

Fill the suitable words in the blank: An IDPS detection method that establishes a baseline of normal activity during a training period is known as (a)   detection.

91.

Fill the suitable words in the blank: The original unencrypted message before encryption is known as (a)   .

92.

Fill the suitable words in the blank: A cryptographic technique that uses a key only once and then discards it is known as the (a)   cipher.

93.

Fill the suitable words in the blank: The strength of a cryptographic algorithm against brute-force attacks is largely determined by the size of its (a)   .

94.

Fill the suitable words in the blank: A (a)   is the outermost boundary used to protect a facility from unauthorized physical access.

95.

Fill the suitable words in the blank: Physical security controls intended to discourage violations before they occur are known as (a)   controls.

96.

Fill the suitable words in the blank: The principle of placing critical assets at the center of multiple layers of protection is known as (a)   .

97.

Fill the suitable words in the blank: A (a)   is a weakness or flaw that can be exploited by a threat.

98.

Fill the suitable words in the blank: An attack that relies on manipulating people rather than technology is known as (a)   engineering.

99.

Fill the suitable words in the blank: An attack that captures authentication data and later reuses it to gain unauthorized access is called a (a)   attack.

100.

Which is the corresponding ciphertext of the plaintext “KHOAHOCXAHOINHANVAN” using Vigenere cipher with the key “HANOI” (use the alphabet including only Latin character from A --> Z)?

a)

LHQNPBJYJABQAOBNXNV

b)

RHWHHJXIOOCUHIUVVU

c)

RHBOPVCKOPVIAVIUVNB

d)

RBBGFSPEUUUGRUHHIGL