Font size
WorksheetsInformation Security Worksheet
Total questions: 60
Worksheet time: 30mins
What is information security?
A set of measures to protect information from unauthorized access, modification, and destruction
A process that includes organizing procedures for protecting personal data on the Internet with the participation of third parties
The use of specialized antivirus solutions in a corporate environment to prevent threats
Implementation of software encryption of all data without the possibility of recovery
A mechanism for interaction between government agencies and individuals to identify cyber threats
What elements does the information security triad (CIA) include?
User identification system with subsequent access control based on authority
Confidentiality, integrity, availability
Inventory of all digital media with subsequent audit and archiving
Combination of anonymity and openness of information flows in a hybrid environment
Automated resource allocation by priority and risk levels
What is regulated by legislation in the field of information security?
Features of storing digital information in corporate and government systems
Establishing Internet security procedures taking into account international standards and agreements
Relationships arising in the process of creating, storing, processing and protecting information
Adoption of standards for the development and licensing of software
Organization of network architecture with the possibility of centralized access control
Which legal act governs the protection of personal data in Kazakhstan?
The Constitution of the Republic of Kazakhstan, which ensures the rights of citizens to privacy of correspondence
The Criminal Code with provisions concerning crimes in the field of ICT and personal data
The Law "On Personal Data and Th EIR(Electronic Information Resources) Protection"
The Law "On National Security", which includes strategic approaches to information protection
The Government Resolution regulating the procedure for storing state archives
What is the subject of legal relations in the field of information security?
Government agencies responsible for the development and implementation of regulations
Private companies authorized to process and store customer data
Organizations providing cybersecurity and monitoring services
IT specialists certified to perform information security work
Any individual or legal entity using the information
Which principle underlies the legal regulation of information security?
Priority of individual rights
Transparency of actions and decisions of government bodies and other entities in the digital space
Predominance of technical regulations over legal ones in terms of system protection
Concentration of powers in the hands of government agencies for the purpose of effective management
Creation of conditions for monopolization of access to digital data by telecom operators
What type of liability may arise for the leakage of confidential information?
Application of disciplinary measures within the framework of the internal labor regulations
Administrative penalties, including fines in accordance with the procedure established by law
Criminal liability with imprisonment in the presence of aggravating circumstances
Implementation of all possible mechanisms of influence on the offender
All of the above
What is the object of legal regulation in the field of information security?
Computer systems operating on the basis of local network architecture
Electronic mail as a tool for transmitting messages
Information, resources, technologies and relations associated with th EIR(Electronic Information Resources) use
User authorization mechanisms in distributed information environments
Cyber threat scenarios considered within the framework of operational risks of enterprises
Who is responsible for ensuring information security in the organization?
The head of the IT department, authorized to implement technical protection measures within the scope of his/her competence
The director of the organization, who carries out general management and bears strategic responsibility
Any employee with access to information processing facilities and involved in ensuring security
The designated responsible person or information security department
An outsourcing company providing audit and incident response services
What is an example of cybercrime?
Violating the terms of the license agreement by installing software without notifying the developer
Unauthorized access to information
Using outdated software with potential vulnerabilities
Deleting personal data based on a written request from the subject
Sending advertising materials via e-mail without the recipient's consent
What is the legal regime for restricted access information?
Information subject to free distribution in accordance with the law
Data that is accessible only after obtaining a court permit in a special manner
Information protected by law and access to which is restricted
Electronic documents stored in archival institutions
Materials transmitted via closed communication channels between departments
What information security measures are applied at the legislative level?
Use of antivirus solutions to protect workstations
Use of cryptographic encryption methods with double
Establishment of legal prohibitions and sanctions
Creation of a multi-level password system to restrict access
Implementation of biometric identification technologies for critical operations
In which case is a citizen liable for violating information security legislation?
Only in the presence of malicious intent proven in court
If there are consequences, even if the actions were committed through negligence
Even if there were negligence, if consequences occurred
If he is an employee of the IT department and is authorized to process data
If information about the incident was published in the media
What does criminal law regulate in the context of information security?
Crimes related to illegal access, distribution, and destruction of information
Protection of corporate infrastructure at the level of internal instructions
Features of data storage, including backup and encryption
The procedure for placing commercial advertising on digital platforms
Distribution of licenses and copyrights to electronic resources
What is a legally significant action in an information system?
An electronic action that entails legal consequences, confirmed by identification
A technical operation performed at the system software level without recording
Any change in data occurring within the framework of an automatic processing algorithm
An administrator action recorded in the log within the internal protocol
An electronic action that entails legal consequences
What is an example of a legally significant action in an information communications network?
Checking email messages to obtain information
Sending a private message in a messenger without a digital signature
Watching a video on an open resource without identity verification
Registering for a webinar and then clicking on a link
Electronic filing of a tax return
What is required for an electronic document to be recognized as legally significant?
A color scanned copy with a signature
Confirmation of authenticity by telephone by an authorized person
Sending the document to the recipient's email
Electronic digital signature (EDS)
Publication of the document on the organization's official website
Which law regulates the use of digital signatures in legally significant actions?
The Law on Electronic Digital Signatures
The Law on Communications and Telecommunication Technologies in the Republic of Kazakhstan
The Law on Personal Data and Digital Identifiers
The Law on Legal Liability of Subjects
The Law on Information Resources and Databases
Which element is required to confirm identity in a legally significant action?
Username specified during registration in the system
IP address recorded each time you log in to the system
Password for the Wi-Fi network used for connection
Temporary code sent via SMS or email
Electronic signature or other identification method
What is an infocommunication network?
A set of telecommunications and information systems united for data exchange
A comprehensive solution that ensures the transfer of information using various protocols in a limited environment
Infrastructure intended exclusively for military and closed government channels
A temporary network organized for conducting local operations between devices
A hardware and software system that provides access to certain information resources in a corporate environment
Where can a legally significant action be performed?
Only in government agencies with the mandatory presence of the parties and certification
Online with the participation of witnesses and subsequent written recording of the result
Exclusively through paper document flow with signatures in two copies
Using electronic means of communication and confirmation
In a specially equipped room with the use of audio and video surveillance
Who is responsible for the authenticity of a legally significant action?
An internet service provider that ensures data transmission over encrypted channels
A user who has performed an action and confirmed it with the EIR (Electronic Information Resources) credentials or digital signature
An organization administering the platform and controlling access to information resources
Government agencies authorized to verify all digital documents
External contractors providing information storage and encryption services
Which principle is important for legally significant actions?
Increased interface loading speed and minimization of visual delays in system response
No mandatory authentication when working in simplified access mode
The ability to use anonymous accounts to speed up the submission of requests
Freedom to roll back actions without the need for explanations or registration of changes
Confirmation of identity and the impossibility of retracting the action performed (non-repudiation)
What does the principle of “non-repudiation” mean?
The right of a participant to withdraw from the process after completion of the digital signature and revision of the agreement
The obligation of the system to guarantee the restoration of actions regardless of the EIR (Electronic Information Resources) results
The ability to change the parameters of a document even after its legal execution
The condition under which data can be deleted at the end of the process
The impossibility of retracting a previously completed action in electronic form
Where do legally significant actions most often take place electronically?
Electronic government (e-gov), banking applications and corporate portals
Discussions on forums with registration of participants via email and pseudonyms
Browsing educational platforms with access without registration and verification
Social networks, where actions are saved and can be deleted at will
Online games in which the user interacts with other people in a virtual environment
What can serve as legal evidence of an electronic action?
A screenshot saved by the user on a local device and attached to the application
An SMS notification received upon activation of the action and confirmed manually
A written confirmation from a third party confirming the action performed
An electronic signature and a log of actions automatically recorded in the system
A voice message sent via an encrypted messenger and archived
What technologies ensure the legal validity of online activities?
Using VPN connections in combination with a traffic caching system
Using specialized antivirus software with activity monitoring
Connecting to closed servers with multi-stage authorization
Constant content filtering and automatic blocking of unauthorized actions
Electronic signature, blockchain, and logging of key operations
Electronic information resources are:
Web platforms and pages containing publicly accessible links to other Internet sources
Electronic mailings and newsletters distributed without verification
Electronic documents, databases, digital archives intended for storing and processing information
Encryption systems designed to protect information from remote interference
Cloud storage provided by external providers with a paid subscription
Which of the following is an example of an electronic service?
Obtaining an identity card by appearing in person at a local internal affairs agency
Contacting a notary office with a full package of documents and being physically present
Purchasing goods in a supermarket and then paying in cash
Filling out an application for employment with the submission of a paper resume to the HR department
Paying utility bills through the eGov website using an electronic digital signature
What is the basis for providing services electronically?
Using telephone communications to transmit applications with subsequent manual confirmation
Personal presence at authorized bodies and signing of paper applications
Publication of information in official printed publications with the possibility of feedback
Completing paper forms and submitting them to registration authorities
Electronic information systems and Internet access as a basic infrastructure
What is IS and EIR (ELECTRONIC INFORMATION RESOURCES) protection?
Data archiving and backup
Administration of network devices
Traffic and software control
Access and network monitoring
A set of measures for safety and security
The main goal of protecting the EIR (ELECTRONIC INFORMATION RESOURCES):
Expanding user access
Optimizing the database structure
Improving the system interface
Preventing leaks and hacks
Improving performance
What constitutes unauthorized actions?
Regular node maintenance
Copying or deleting without permission
Rule-based administration
Official login authorization
Setting up permitted access
Who is responsible for protecting the EIR (ELECTRONIC INFORMATION RESOURCES)?
Owners, proprietors, and users
Government agencies only
Information network providers only
System administrators only
System users only
The responsibilities of IS owners are:
Installation of new software as desired
Registration of new users
Prevention of unauthorized access
Development of corporate websites
Upgrading servers as planned
Organizational protective measure is:
Access control to premises
Creating backup copies
Monitoring network attacks
Using cryptographic algorithms
Installing antivirus software
What are technical measures?
Internal operating procedures
Data control and protection systems
Access control regulations
Agreements between owners
Local legal provisions
The legal measure of protection is:
Access control requirements
Use of video surveillance
Event recording system
Legislative and regulatory rules
Enterprise password policy
How is personal data protected?
Transfer to free users
Publication on external resources
Forwarding without restrictions
In accordance with the law and standards
Storage in the public domain
Who is subject to the uniform information security requirements?
Government agencies and IS owners
Only for private organizations
Only for individiuals
Only for foreign companies
Exclusively for educational centers
Blocking the EIR (ELECTRONIC INFORMATION RESOURCES) leads to:
Simplifying the network structure
Improving the quality of network operation
Speeding up the processing of requests
Limiting and denying access
Increasing throughput
The main goal of protection is:
Security, integrity, and confidentiality
Expansion of databases
Simplifying the system interface
Increasing user traffic
Increasing server capacity
Software for state protection is purchased:
With a mandatory import license
From the registry of trusted software
In any store of your choice
Only through foreign companies
Only on open sites
What does "e-government" mean?
Digital network of ministries
Storage of digital resources
Document exchange system
Online interaction of government agencies
State database of electronic acts
Who approves the requirements in the field of information security?
Educational systems committees
State response centers
Akimats and local authorities
Banks and corporate structures
The Government of the Republic of Kazakhstan
Who implements state policy in information security?
Technical Services Center
KZ-CERT response services
Ministry of Digital Development
Domain Zone Registry
Judicial authorities and the prosecutor's office
What does the authorized body develop?
Electronic portal design
School curricula
Information security requirements and methods
Website management recommendations
Backup storage schemes
Who monitors information security compliance in the IS?
Bank financial departments
Judicial and supervisory bodies
Authorized state body
KZ-CERT Response Service
Local executive bodies
Who reports detected information security incidents?
Internet domain registry
Information security operations center
Academic research centers
Judicial authorities and the prosecutor's office
Ministry of Education
Who analyzes threats and makes recommendations?
JSC NIT operator EGOV
Local executive bodies
KZ-CERT Response Service
Central executive agencies
Ministry of Digitalization
Who ensures interaction between information security centers?
National Information Security Coordination Center
Forensic and investigative bodies
Domain Control Center
Ministry of Finance
Information Security Academy
The main task of the National Coordination Center for Information Security?
Management of Internet platforms
Procurement of software
Social digitalization of the population
Judicial processing of incidents
Coordination of monitoring and protection of information security
Who heads the expert council?
Committee of educational institutions
Representative of the banking sector
EGOV technical specialists
NCCIS management
Minister of the authorized body
The role of central authorities?
Compliance with uniform information security rules
Equipping schools with information security equipment
Managing cryptographic nodes
Setting up network routers
Launching state domains
Functions of local executive bodies?
Testing of data encryption
Compliance with uniform information security rules
Organizing public access to the EIR (ELECTRONIC INFORMATION RESOURCES)
Monitoring of server infrastructure
Development of security standards
What is the purpose of creating an information security unit?
Maintenance of network nodes
Installation of technical structure
Server room management
Ensuring security control
Development of ICT systems
What does the information security department do?
Network performance analysis
Workstation maintenance
Site performance assessment
Software license management
Monitoring compliance with information security requirements
The technical documentation of information security consists of?
Five internal modules
Four levels of documents
Three structural groups
One basic block
Two normative sections
What is the first level document of the technical documentation of information security?
Internal Risk Catalog
Work Instructions
Information Security Policy
Inventory List
Accounting Event Log
Which of the following is related to the documentation of information security?
Server visit tables
System testing logs
List of backup channels
Equipment accounting forms
Processing methods and rules
