wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

AAQ IT Hardware & software security

Total questions: 25

Worksheet time: 13mins

Name
Class
Date
1.

Which example best represents a knowledge-based authentication factor?

a)

Smart card with embedded chip

b)

Fingerprint captured by a sensor

c)

Password remembered by the user

d)

Phone used for hardware token codes

2.

Which factor category includes fingerprints, face scans, or iris patterns?

a)

Something you have

b)

Somewhere you are

c)

Something you are

d)

Something you know

3.

A one-time code generated by an authenticator app is primarily which factor?

a)

Something you have

b)

Something you know

c)

Something you are

d)

Somewhere you are

4.

In Discretionary Access Control (DAC), who typically decides object access?

a)

System administrator only

b)

Object owner determines permissions

c)

Central policy engine enforces rules

d)

Role manager assigns privileges

5.

Rule-Based Access Control (RuBAC) decisions are driven by:

a)

Static user role mappings

b)

Physical possession of tokens

c)

Defined policies and conditions

d)

Ad hoc owner preferences

6.

Which scenario best fits RBAC?

a)

Nurse role gets patient-chart view

b)

Token required for VPN access

c)

File owner sets read access

d)

Policy denies after hours login

7.

Which measure helps recover a lost smartphone?

a)

Uninstalling password manager

b)

Removing biometric authentication

c)

GPS-based device tracking service

d)

Disabling all wireless radios

8.

What is the primary purpose of device tracking software?

a)

Encrypt files for data sharing

b)

Block all incoming network traffic

c)

Locate and recover lost devices

d)

Optimize battery health data

9.

In DAC, what is a likely security weakness?

a)

Owner may grant overly broad access

b)

Rigid role definitions everywhere

c)

Tokens always expire after issuance

d)

Policies automatically block risks

10.

In RBAC, what must be managed to keep least privilege?

a)

Device screen brightness levels

b)

Roles and permission assignments

c)

Owner’s mood and preferences

d)

Global GPS location accuracy

11.

Which measure improves recovery odds before loss occurs?

a)

Disable location services everywhere

b)

Use only single-factor passwords

c)

Share login details for backup

d)

Preconfigure tracking and remote wipe

12.

Which access control model simplifies onboarding in large organizations?

a)

DAC with per-file decisions

b)

No model with open permissions

c)

RBAC with role-based permissions

d)

RuBAC with hourly conditions

13.

After enabling tracking, which next step helps recovery?

a)

Contact authorities with live location

b)

Share location publicly with everyone

c)

Immediately post device to social media

d)

Disable SIM and tracking services

14.

Which best explains least privilege under RBAC?

a)

Grant all rights by default

b)

Assign only necessary role permissions

c)

Let owners decide case by case

d)

Allow access based on time alone

15.

Security tokens primarily improve security by:

a)

Storing longer passwords for faster logins

b)

Blocking all network connections by default

c)

Tracking user activity for auditing reports

d)

Requiring possession of a physical device to access

16.

Which example best represents the location factor in authentication?

a)

Matching a facial scan during login

b)

Plugging in a smartcard to a reader

c)

Answering security questions from memory

d)

Verifying sign-in from a usual GPS position

17.

Which model lets the resource owner decide who can read or modify a file, including changing its permissions?

a)

Rule-based access control with strict criteria

b)

Discretionary access control by the owner

c)

Role-based access control with job tiers

d)

Mandatory access control with labels

18.

In a company, access to sensitive financial records is limited to accountants because of their job duties. Which control model is being used?

a)

Rule-based control with user-specific rules

b)

Role-based control tied to responsibilities

c)

Discretionary control by file creators

d)

Time-based control using schedules

19.

Which statement best describes Rule-Based Access Control (RuBAC)?

a)

Access depends on seniority and responsibilities

b)

Owners grant permissions to their own resources

c)

Administrators enforce predefined criteria rules

d)

Labels and clearances determine every access

20.

A lower-level employee tries to open a confidential budget file but is blocked because of their position. What most likely caused the denial?

a)

RBAC restricted access based on role

b)

DAC owner revoked all group permissions

c)

Network segmentation blocked the request

d)

RuBAC criteria did not match their profile

21.

Which statement best describes Trusted Computing in secure environments?

a)

Focuses mainly on physical locks and cable restraints

b)

Depends on third-party apps for all security controls

c)

Relies only on user passwords to block unauthorized access

d)

Uses integrated hardware-software features to reduce threats

22.

A school laptop should lock automatically after inactivity and after several failed logins. Which protection approach applies?

a)

Trusted Computing with centralized audit-only logging

b)

Software updates for the operating system kernel

c)

Hardware-only controls like chassis intrusion switches

d)

Device-Based Protection with timed auto-lock and lock-on failures

23.

What is the primary purpose of a remote wipe when a device cannot be recovered?

a)

Disable Wi‑Fi to save mobile data

b)

Increase GPS accuracy for location

c)

Erase data to prevent unauthorized access

d)

Boost battery life during tracking

24.

A phone is stolen and still connected to cellular and Wi‑Fi networks. Which approach best increases the chance of recovery without exposing data?

a)

Share passwords with the carrier

b)

Use Find the Device to track location

c)

Disable GPS in phone settings

d)

Immediately perform a remote wipe

25.

Which is a commonly cited drawback of Trusted Computing systems?

a)

Guaranteed system uptime for all users

b)

Automatic compatibility with all software

c)

Increased battery life on mobile devices

d)

Potential vendor lock‑in and reduced user control