wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CPTECH30 COE222 Midterm Exam

Total questions: 65

Worksheet time: 23mins

Name
Class
Date
1.

What is redbook?

a)

An outlined procedure for employees

b)

Hard copy accessible outside the facility

c)

Back up copy for business continuity plan

d)

Document to be distributed to employees

2.

Another term for crisis management

a)

Incident management

b)

Contingency management

c)

Crisis response

d)

Safety management

3.

Which is NOT a common component of comprehensive business plan continuity?

a)

Notification systems

b)

Guidance for management

c)

Immediate response

d)

Contact numbers of employees

4.

What is the key outcome of Business Impact Analysis (BIA)?

a)

Transition to permanent office space

b)

Immediate effect on other areas of work

c)

Importance of customer staff

d)

Identification of functions and dependencies

5.

It refers to restoring the information technology and communication services and systems needed by the organization.

a)

Disaster recovery

b)

Business function

c)

Continuity plan

d)

Business preparation

6.

What is the purpose of the Executive Summary in a Disaster Recovery Plan?

a)

To list department-specific plans

b)

To serve as a checklist for critical team members

c)

To offer a high-level overview of the plan

d)

All of the above

7.

Who must provide support for business continuity planning efforts?

a)

Frontline employees

b)

External consultants

c)

Executive management and an executive sponsor

d)

Middle management

8.

Which of the following components is very likely to be instrumental to any disaster recovery report?

a)

Backups

b)

Firewalls

c)

Routers

d)

Laptops

9.

Why is it necessary to consider not only the server level but also the database and dependencies on other systems in disaster recovery plans for complex systems?

a)

To reduce storage costs

b)

To streamline the disaster recovery process

c)

To comply with legal regulations

d)

To address the intricate dependencies of the systems

10.

What is the next step after detection and analysis in the incident response process?

a)

Finding the appropriate containment strategy

b)

External investigation involving law enforcement

c)

Internal audit of the organization

d)

Identifying attackers and their motives

11.

What is the definition of an object in the context of access controls?

a)

A device with onboard firmware

b)

An entity that responds to a request for service

c)

Anything that initiates a request for service

d)

Something that contains its own access control logic

12.

What is the strategy that integrates people, technology, and operations capabilities to establish variable barriers across multiple layers and missions of an organization?

a)

Layered Defense

b)

Cyberattack Prevention

c)

Multi-Factor Authentication

d)

Single Point of Failure

13.

How does privileged access management implement the principle of least privilege?

a)

By providing access based on seniority

b)

By restricting access to only the most critical information

c)

By granting maximum access to all users

d)

By granting each user access only to the items they need

14.

Which is NOT an example of a logical access control method?

a)

Password

b)

Biometrics on a smartphone

c)

Badge/token readers

d)

Presentation of ID cards

15.

Limiting access to data on the network would be considered which of the following controls?

a)

Physical controls

b)

Administrative controls

c)

Virtualization controls

d)

Logical or technical controls

16.

What would be considered an administrative control in the context of seat belt usage?

a)

Attaching the seat belt to the car

b)

Enforcing seat belt laws

c)

Designing the seat belt for comfort

d)

Testing the seat belt for durability

17.

What alternative control could be used if biometric locks on multiple doors are not necessary and access does not need to be audited?

a)

Installing a permanent wall

b)

Replacing doors with deadbolt locks

c)

Removing doors and securing the area permanently

d)

Implementing biometric scanners on all doors

18.

In what type of environment does role-based access control work well?

a)

Low-staff turnover

b)

Limited access requirements for all personnel

c)

Single personnel with unique access requirements

d)

High-staff turnover and similar access requirements

19.

What term is used to describe the situation where someone inherits expanded permissions that are not appropriate for their role in Role-based Access Control (RBAC)?

a)

Privilege creep

b)

Permissions anomaly

c)

Role deviation

d)

Access overflow

20.

What is the key feature of just-in-time privileged access management?

a)

Role-based subsets of privileges

b)

Unrestricted access

c)

Permanent administrative access

d)

Static privileges

21.

In Mandatory Access Control (MAC), what determines the level of access to certain areas in certain government agencies?

a)

Individual judgment

b)

Owner's discretion

c)

On a request basis

d)

Government policy and security clearance

22.

Who can modify security rules in a system governed by Mandatory Access Control (MAC)?

a)

All subjects within the system

b)

Randomly selected users

c)

Object owners at their discretion

d)

Trusted subjects designated as security administrators

23.

Which of these combinations of physical security controls share a single point of failure?

a)

Dogs and bollards

b)

High-illumination lighting and cameras

c)

Guards and fences

d)

Badge readers and walls

24.

Which of the following is an example of a physical access control?

a)

Firewalls

b)

Encryption algorithms

c)

Motion detectors

d)

Antivirus software

25.

Duncan and Mira work in the data center at Triffid, Inc. There is a policy in place that requires both to be present in the data center at the same time. If one has to leave for any reason, the other must step out, too, until they can both re-enter. What is this policy called?

a)

Blockade

b)

Defense in depth

c)

Two-person control

d)

Dual authentication

26.

Why is Discretionary Access Control (DAC) not considered very scalable?

a)

It is a hardware-intensive approach

b)

It relies on the discretion of individual object owners

c)

It relies on mandatory access controls

d)

It uses advanced encryption techniques

27.

What is the two-person rule in the context of security strategy?

a)

Two people must have the same combination

b)

Two people must have access to the same information

c)

Two people must be in an area together

d)

Two people must perform the same duties

28.

Why is it recommended to disable accounts for a period before deletion when an employee leaves the company?

a)

To preserve the integrity of audit trails or files

b)

To allow the separated employee access to data

c)

So the ex-employee can't steal secrets

d)

To speed up the account deletion process

29.

What is user provisioning in identity management?

a)

Ensuring a user can always control what they want to access

b)

Managing access to resources and information systems

c)

Enabling the option to delete a user's account

d)

Ensuring that users are conducting regular antivirus scans

30.

Which of the following is the responsibility of systems administrators who use privileged accounts?

a)

Managing financial transactions

b)

Handling customer service

c)

Operating systems and applications

d)

Marketing and promotions

31.

What does behavioral biometrics measure?

a)

User actions, such as voiceprints and keystroke dynamics

b)

Physiological attributes

c)

Characteristics like fingerprint and iris scan

d)

Environmental design elements

32.

Which is a physical control that prevents 'piggybacking' or 'tailgating,' when an unauthorized person follows an authorized person into a controlled area?

a)

Wall

b)

Turnstile

c)

Fence

d)

Bollard

33.

Which of the following best distinguishes machine learning from traditional programming?

a)

Machine learning requires data

b)

Machine learning systems learn patterns from data instead of following explicit rules

c)

Machine learning programs are always faster

d)

Traditional programming cannot use algorithms

34.

Which algorithm is an example of supervised learning?

a)

K-means clustering

b)

Principal Component Analysis (PCA)

c)

Linear regression

d)

Apriori algorithm

35.

In deep learning, what is the primary function of an activation function?

a)

To initialize weights

b)

To reduce training time

c)

To introduce non-linearity into the model

d)

To normalize the dataset

36.

What is feature engineering primarily concerned with?

a)

Transforming raw data into meaningful input features

b)

Selecting hardware for computation

c)

Training the model faster

d)

Deploying models into production

37.

Which model architecture is most commonly associated with modern generative AI systems?

a)

Decision Trees

b)

Support Vector Machines

c)

Naive Bayes

d)

Transformers

38.

Which of the following is a real-world application of AI in healthcare?

a)

Manual record keeping

b)

Image-based disease diagnosis

c)

Paper-based scheduling

d)

Handwritten prescriptions

39.

What is a key consideration when deploying AI models in real-world systems?

a)

Model accuracy only

b)

Ethical, security, and scalability concerns

c)

The number of training epochs

d)

The color of the user interface

40.

Which sensor is commonly used for measuring distance in mobile robots?

a)

Gyroscope

b)

Temperature sensor

c)

Ultrasonic sensor

d)

Load cell

41.

What is the primary function of an actuator in a robotic system?

a)

To process data

b)

To sense the environment

c)

To store energy

d)

To convert electrical signals into physical motion

42.

Which programming framework is widely used for robot software development?

a)

TensorFlow

b)

ROS (Robot Operating System)

c)

Hadoop

d)

MATLAB Excel

43.

Which of the following is a common application of robotics in industry?

a)

Automated assembly lines

b)

Automated data entry

c)

Automated handwritten documentation

d)

Automated voice-based translation

44.

Which of the following best describes a security control?

a)

A method for creating user accounts in a system

b)

A safeguard designed to preserve the Confidentiality, Integrity, and Availability of data

c)

A protocol for sending emails securely

d)

A process to speed up network traffic

45.

Which of the following statements correctly distinguishes subjects from objects in access control?

a)

Subjects are passive and objects are active in accessing resources

b)

Subjects and objects are always the same entity in access control

c)

Objects have clearance levels, while subjects store data

d)

Subjects are active and objects are passive in accessing resources

46.

Example of "something you know" authentication factor

a)

Passphrase

b)

Fingerprint

c)

UserID

d)

Iris scan

47.

It means that systems and data are accessible at the time users need them.

a)

Availability

b)

Integrity

c)

Confidentiality

d)

None of the above

48.

As an information security professional, you are expected to uphold _____.

a)

Honorable, honest, just, and responsible within legal conduct

b)

Secrecy and confidentiality

c)

Just enough ethical standards and professional integrity

d)

Produce the fastest results with high impact

49.

Security controls are implemented in risk management to _____.

a)

Mitigate the risk to an acceptable level

b)

Eliminate all vulnerabilities

c)

Ensure that a cyberattack would be impossible

d)

All of the above

50.

In an analogy, if the attack vector would be their technique and approach, a pickpocket is considered _____.

a)

Vulnerabilities

b)

Stolen goods

c)

Liabilities

d)

Treat

51.
  1. Which of the following is very likely to be used in a disaster recovery (DR) effort?

a)

Contact personnel

b)

Data backups

c)

Anti-malware solutions

d)

All of the above

52.

It is based on the security practice that no one person should control an entire high-risk transaction from start to finish.

a)

Separation of duties

b)

mandatory access control (MAC)

c)

Privileged accounts

d)

Role-based access control

53.

It provides each worker privileges based on what role they have in the organization.

a)

Privileged access management

b)

Privileged accounts

c)

Discretionary access control (DAC)

d)

Role-based access control

54.

(a)   systems measure the characteristics of a person such as a fingerprint, iris scan (the colored portion around the outside of the pupil in the eye), retinal scan (the pattern of blood vessels in the back of the eye), palm scan, and venous scans that look for the flow of blood through the veins in the palm.

55.

A (a)   is a record of events that have occurred.

56.

A type of malicious software that locks the computer screen or files, thus preventing or limiting a user from accessing their system and data until money is paid.

a)

Worm

b)

Spyware

c)

Ransomware

d)

None of the above

57.

A (a)   can be defined as any entity that requests access to assets.

58.

(a)   is a device, process, person, user, program, server, client, or other entity that responds to a request for service.

59.

What is the primary function of a sensor in a robotic system

a)

To generate mechanical movement

b)

To process control algorithms

c)

To detect environmental changes

d)

To store program instructions

60.

Why is simulation important in robot programming?

a)

It replaces the need for real robots

b)

It allows testing and debugging in a virtual environment

c)

It increases the robot’s physical strength

d)

It removes the need for programming languages

61.

(a)   is a security strategy that requires a minimum of two people to be in an area together, making it impossible for a person to be in the area alone.

62.

It is the process of transforming raw data into meaningful inputs called features that help machine learning models learn patterns and make accurate predictions

(a)  

63.

Which statement best explains a key limitation of large generative AI models when used in high-stakes decision-making environments (e.g., healthcare or law enforcement)?

a)

They are incapable of learning from unstructured data such as text or images.

b)

They may produce outputs that appear highly confident but are not guaranteed to be factually correct or unbiased.

c)

They cannot be fine-tuned for domain-specific tasks once deployed.

d)

They rely exclusively on real-time internet access to generate responses.

64.

(a)   is the study of robot motion without considering forces.

65.

Robot Programming and Simulations focus on deploying

instructions that allow robots to move, respond to their

environment, and complete tasks accurately.

a)

Yes

b)

No