wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Information Security Worksheet

Total questions: 60

Worksheet time: 30mins

Name
Class
Date
1.

What is information security?

a)

A set of measures to protect information from unauthorized access, modification, and destruction

b)

A process that includes organizing procedures for protecting personal data on the Internet with the participation of third parties

c)

The use of specialized antivirus solutions in a corporate environment to prevent threats

d)

Implementation of software encryption of all data without the possibility of recovery

e)

A mechanism for interaction between government agencies and individuals to identify cyber threats

2.

What elements does the information security triad (CIA) include?

a)

User identification system with subsequent access control based on authority

b)

Confidentiality, integrity, availability

c)

Inventory of all digital media with subsequent audit and archiving

d)

Combination of anonymity and openness of information flows in a hybrid environment

e)

Automated resource allocation by priority and risk levels

3.

What is regulated by legislation in the field of information security?

a)

Features of storing digital information in corporate and government systems

b)

Establishing Internet security procedures taking into account international standards and agreements

c)

Relationships arising in the process of creating, storing, processing and protecting information

d)

Adoption of standards for the development and licensing of software

e)

Organization of network architecture with the possibility of centralized access control

4.

Which legal act governs the protection of personal data in Kazakhstan?

a)

The Constitution of the Republic of Kazakhstan, which ensures the rights of citizens to privacy of correspondence

b)

The Criminal Code with provisions concerning crimes in the field of ICT and personal data

c)

The Law "On Personal Data and Th EIR(Electronic Information Resources) Protection"

d)

The Law "On National Security", which includes strategic approaches to information protection

e)

The Government Resolution regulating the procedure for storing state archives

5.

What is the subject of legal relations in the field of information security?

a)

Government agencies responsible for the development and implementation of regulations

b)

Private companies authorized to process and store customer data

c)

Organizations providing cybersecurity and monitoring services

d)

IT specialists certified to perform information security work

e)

Any individual or legal entity using the information

6.

Which principle underlies the legal regulation of information security?

a)

Priority of individual rights

b)

Transparency of actions and decisions of government bodies and other entities in the digital space

c)

Predominance of technical regulations over legal ones in terms of system protection

d)

Concentration of powers in the hands of government agencies for the purpose of effective management

e)

Creation of conditions for monopolization of access to digital data by telecom operators

7.

What type of liability may arise for the leakage of confidential information?

a)

Application of disciplinary measures within the framework of the internal labor regulations

b)

Administrative penalties, including fines in accordance with the procedure established by law

c)

Criminal liability with imprisonment in the presence of aggravating circumstances

d)

Implementation of all possible mechanisms of influence on the offender

e)

All of the above

8.

What is the object of legal regulation in the field of information security?

a)

Computer systems operating on the basis of local network architecture

b)

Electronic mail as a tool for transmitting messages

c)

Information, resources, technologies and relations associated with th EIR(Electronic Information Resources) use

d)

User authorization mechanisms in distributed information environments

e)

Cyber threat scenarios considered within the framework of operational risks of enterprises

9.

Who is responsible for ensuring information security in the organization?

a)

The head of the IT department, authorized to implement technical protection measures within the scope of his/her competence

b)

The director of the organization, who carries out general management and bears strategic responsibility

c)

Any employee with access to information processing facilities and involved in ensuring security

d)

The designated responsible person or information security department

e)

An outsourcing company providing audit and incident response services

10.

What is an example of cybercrime?

a)

Violating the terms of the license agreement by installing software without notifying the developer

b)

Unauthorized access to information

c)

Using outdated software with potential vulnerabilities

d)

Deleting personal data based on a written request from the subject

e)

Sending advertising materials via e-mail without the recipient's consent

11.

What is the legal regime for restricted access information?

a)

Information subject to free distribution in accordance with the law

b)

Data that is accessible only after obtaining a court permit in a special manner

c)

Information protected by law and access to which is restricted

d)

Electronic documents stored in archival institutions

e)

Materials transmitted via closed communication channels between departments

12.

What information security measures are applied at the legislative level?

a)

Use of antivirus solutions to protect workstations

b)

Use of cryptographic encryption methods with double

c)

Establishment of legal prohibitions and sanctions

d)

Creation of a multi-level password system to restrict access

e)

Implementation of biometric identification technologies for critical operations

13.

In which case is a citizen liable for violating information security legislation?

a)

Only in the presence of malicious intent proven in court

b)

If there are consequences, even if the actions were committed through negligence

c)

Even if there were negligence, if consequences occurred

d)

If he is an employee of the IT department and is authorized to process data

e)

If information about the incident was published in the media

14.

What does criminal law regulate in the context of information security?

a)

Crimes related to illegal access, distribution, and destruction of information

b)

Protection of corporate infrastructure at the level of internal instructions

c)

Features of data storage, including backup and encryption

d)

The procedure for placing commercial advertising on digital platforms

e)

Distribution of licenses and copyrights to electronic resources

15.

What is a legally significant action in an information system?

a)

An electronic action that entails legal consequences, confirmed by identification

b)

A technical operation performed at the system software level without recording

c)

Any change in data occurring within the framework of an automatic processing algorithm

d)

An administrator action recorded in the log within the internal protocol

e)

An electronic action that entails legal consequences

16.

What is an example of a legally significant action in an information communications network?

a)

Checking email messages to obtain information

b)

Sending a private message in a messenger without a digital signature

c)

Watching a video on an open resource without identity verification

d)

Registering for a webinar and then clicking on a link

e)

Electronic filing of a tax return

17.

What is required for an electronic document to be recognized as legally significant?

a)

A color scanned copy with a signature

b)

Confirmation of authenticity by telephone by an authorized person

c)

Sending the document to the recipient's email

d)

Electronic digital signature (EDS)

e)

Publication of the document on the organization's official website

18.

Which law regulates the use of digital signatures in legally significant actions?

a)

The Law on Electronic Digital Signatures

b)

The Law on Communications and Telecommunication Technologies in the Republic of Kazakhstan

c)

The Law on Personal Data and Digital Identifiers

d)

The Law on Legal Liability of Subjects

e)

The Law on Information Resources and Databases

19.

Which element is required to confirm identity in a legally significant action?

a)

Username specified during registration in the system

b)

IP address recorded each time you log in to the system

c)

Password for the Wi-Fi network used for connection

d)

Temporary code sent via SMS or email

e)

Electronic signature or other identification method

20.

What is an infocommunication network?

a)

A set of telecommunications and information systems united for data exchange

b)

A comprehensive solution that ensures the transfer of information using various protocols in a limited environment

c)

Infrastructure intended exclusively for military and closed government channels

d)

A temporary network organized for conducting local operations between devices

e)

A hardware and software system that provides access to certain information resources in a corporate environment

21.

Where can a legally significant action be performed?

a)

Only in government agencies with the mandatory presence of the parties and certification

b)

Online with the participation of witnesses and subsequent written recording of the result

c)

Exclusively through paper document flow with signatures in two copies

d)

Using electronic means of communication and confirmation

e)

In a specially equipped room with the use of audio and video surveillance

22.

Who is responsible for the authenticity of a legally significant action?

a)

An internet service provider that ensures data transmission over encrypted channels

b)

A user who has performed an action and confirmed it with the EIR (Electronic Information Resources) credentials or digital signature

c)

An organization administering the platform and controlling access to information resources

d)

Government agencies authorized to verify all digital documents

e)

External contractors providing information storage and encryption services

23.

Which principle is important for legally significant actions?

a)

Increased interface loading speed and minimization of visual delays in system response

b)

No mandatory authentication when working in simplified access mode

c)

The ability to use anonymous accounts to speed up the submission of requests

d)

Freedom to roll back actions without the need for explanations or registration of changes

e)

Confirmation of identity and the impossibility of retracting the action performed (non-repudiation)

24.

What does the principle of “non-repudiation” mean?

a)

The right of a participant to withdraw from the process after completion of the digital signature and revision of the agreement

b)

The obligation of the system to guarantee the restoration of actions regardless of the EIR (Electronic Information Resources) results

c)

The ability to change the parameters of a document even after its legal execution

d)

The condition under which data can be deleted at the end of the process

e)

The impossibility of retracting a previously completed action in electronic form

25.

Where do legally significant actions most often take place electronically?

a)

Electronic government (e-gov), banking applications and corporate portals

b)

Discussions on forums with registration of participants via email and pseudonyms

c)

Browsing educational platforms with access without registration and verification

d)

Social networks, where actions are saved and can be deleted at will

e)

Online games in which the user interacts with other people in a virtual environment

26.

What can serve as legal evidence of an electronic action?

a)

A screenshot saved by the user on a local device and attached to the application

b)

An SMS notification received upon activation of the action and confirmed manually

c)

A written confirmation from a third party confirming the action performed

d)

An electronic signature and a log of actions automatically recorded in the system

e)

A voice message sent via an encrypted messenger and archived

27.

What technologies ensure the legal validity of online activities?

a)

Using VPN connections in combination with a traffic caching system

b)

Using specialized antivirus software with activity monitoring

c)

Connecting to closed servers with multi-stage authorization

d)

Constant content filtering and automatic blocking of unauthorized actions

e)

Electronic signature, blockchain, and logging of key operations

28.

Electronic information resources are:

a)

Web platforms and pages containing publicly accessible links to other Internet sources

b)

Electronic mailings and newsletters distributed without verification

c)

Electronic documents, databases, digital archives intended for storing and processing information

d)

Encryption systems designed to protect information from remote interference

e)

Cloud storage provided by external providers with a paid subscription

29.

Which of the following is an example of an electronic service?

a)

Obtaining an identity card by appearing in person at a local internal affairs agency

b)

Contacting a notary office with a full package of documents and being physically present

c)

Purchasing goods in a supermarket and then paying in cash

d)

Filling out an application for employment with the submission of a paper resume to the HR department

e)

Paying utility bills through the eGov website using an electronic digital signature

30.

What is the basis for providing services electronically?

a)

Using telephone communications to transmit applications with subsequent manual confirmation

b)

Personal presence at authorized bodies and signing of paper applications

c)

Publication of information in official printed publications with the possibility of feedback

d)

Completing paper forms and submitting them to registration authorities

e)

Electronic information systems and Internet access as a basic infrastructure

31.

What is IS and EIR (ELECTRONIC INFORMATION RESOURCES) protection?

a)

Data archiving and backup

b)

Administration of network devices

c)

Traffic and software control

d)

Access and network monitoring

e)

A set of measures for safety and security

32.

The main goal of protecting the EIR (ELECTRONIC INFORMATION RESOURCES):

a)

Expanding user access

b)

Optimizing the database structure

c)

Improving the system interface

d)

Preventing leaks and hacks

e)

Improving performance

33.

What constitutes unauthorized actions?

a)

Regular node maintenance

b)

Copying or deleting without permission

c)

Rule-based administration

d)

Official login authorization

e)

Setting up permitted access

34.

Who is responsible for protecting the EIR (ELECTRONIC INFORMATION RESOURCES)?

a)

Owners, proprietors, and users

b)

Government agencies only

c)

Information network providers only

d)

System administrators only

e)

System users only

35.

The responsibilities of IS owners are:

a)

Installation of new software as desired

b)

Registration of new users

c)

Prevention of unauthorized access

d)

Development of corporate websites

e)

Upgrading servers as planned

36.

Organizational protective measure is:

a)

Access control to premises

b)

Creating backup copies

c)

Monitoring network attacks

d)

Using cryptographic algorithms

e)

Installing antivirus software

37.

What are technical measures?

a)

Internal operating procedures

b)

Data control and protection systems

c)

Access control regulations

d)

Agreements between owners

e)

Local legal provisions

38.

The legal measure of protection is:

a)

Access control requirements

b)

Use of video surveillance

c)

Event recording system

d)

Legislative and regulatory rules

e)

Enterprise password policy

39.

How is personal data protected?

a)

Transfer to free users

b)

Publication on external resources

c)

Forwarding without restrictions

d)

In accordance with the law and standards

e)

Storage in the public domain

40.

Who is subject to the uniform information security requirements?

a)

Government agencies and IS owners

b)

Only for private organizations

c)

Only for individiuals

d)

Only for foreign companies

e)

Exclusively for educational centers

41.

Blocking the EIR (ELECTRONIC INFORMATION RESOURCES) leads to:

a)

Simplifying the network structure

b)

Improving the quality of network operation

c)

Speeding up the processing of requests

d)

Limiting and denying access

e)

Increasing throughput

42.

The main goal of protection is:

a)

Security, integrity, and confidentiality

b)

Expansion of databases

c)

Simplifying the system interface

d)

Increasing user traffic

e)

Increasing server capacity

43.

Software for state protection is purchased:

a)

With a mandatory import license

b)

From the registry of trusted software

c)

In any store of your choice

d)

Only through foreign companies

e)

Only on open sites

44.

What does "e-government" mean?

a)

Digital network of ministries

b)

Storage of digital resources

c)

Document exchange system

d)

Online interaction of government agencies

e)

State database of electronic acts

45.

Who approves the requirements in the field of information security?

a)

Educational systems committees

b)

State response centers

c)

Akimats and local authorities

d)

Banks and corporate structures

e)

The Government of the Republic of Kazakhstan

46.

Who implements state policy in information security?

a)

Technical Services Center

b)

KZ-CERT response services

c)

Ministry of Digital Development

d)

Domain Zone Registry

e)

Judicial authorities and the prosecutor's office

47.

What does the authorized body develop?

a)

Electronic portal design

b)

School curricula

c)

Information security requirements and methods

d)

Website management recommendations

e)

Backup storage schemes

48.

Who monitors information security compliance in the IS?

a)

Bank financial departments

b)

Judicial and supervisory bodies

c)

Authorized state body

d)

KZ-CERT Response Service

e)

Local executive bodies

49.

Who reports detected information security incidents?

a)

Internet domain registry

b)

Information security operations center

c)

Academic research centers

d)

Judicial authorities and the prosecutor's office

e)

Ministry of Education

50.

Who analyzes threats and makes recommendations?

a)

JSC NIT operator EGOV

b)

Local executive bodies

c)

KZ-CERT Response Service

d)

Central executive agencies

e)

Ministry of Digitalization

51.

Who ensures interaction between information security centers?

a)

National Information Security Coordination Center

b)

Forensic and investigative bodies

c)

Domain Control Center

d)

Ministry of Finance

e)

Information Security Academy

52.

The main task of the National Coordination Center for Information Security?

a)

Management of Internet platforms

b)

Procurement of software

c)

Social digitalization of the population

d)

Judicial processing of incidents

e)

Coordination of monitoring and protection of information security

53.

Who heads the expert council?

a)

Committee of educational institutions

b)

Representative of the banking sector

c)

EGOV technical specialists

d)

NCCIS management

e)

Minister of the authorized body

54.

The role of central authorities?

a)

Compliance with uniform information security rules

b)

Equipping schools with information security equipment

c)

Managing cryptographic nodes

d)

Setting up network routers

e)

Launching state domains

55.

Functions of local executive bodies?

a)

Testing of data encryption

b)

Compliance with uniform information security rules

c)

Organizing public access to the EIR (ELECTRONIC INFORMATION RESOURCES)

d)

Monitoring of server infrastructure

e)

Development of security standards

56.

What is the purpose of creating an information security unit?

a)

Maintenance of network nodes

b)

Installation of technical structure

c)

Server room management

d)

Ensuring security control

e)

Development of ICT systems

57.

What does the information security department do?

a)

Network performance analysis

b)

Workstation maintenance

c)

Site performance assessment

d)

Software license management

e)

Monitoring compliance with information security requirements

58.

The technical documentation of information security consists of?

a)

Five internal modules

b)

Four levels of documents

c)

Three structural groups

d)

One basic block

e)

Two normative sections

59.

What is the first level document of the technical documentation of information security?

a)

Internal Risk Catalog

b)

Work Instructions

c)

Information Security Policy

d)

Inventory List

e)

Accounting Event Log

60.

Which of the following is related to the documentation of information security?

a)

Server visit tables

b)

System testing logs

c)

List of backup channels

d)

Equipment accounting forms

e)

Processing methods and rules