NEW
Font size
WorksheetsInformation Assurance & Security
Total questions: 15
Worksheet time: 7mins
Instructions: Select the best answer for each question. Focus on the technical and legal context of the Philippines. A local government unit’s (LGU) website is defaced by a hacktivist group. Which pillar of the CIA Triad has been primarily violated?
Confidentiality
Integrity
Availability
Authenticity
Instructions: Select the best answer for each question. Focus on the technical and legal context of the Philippines. In the 2023 PhilHealth "Medusa" attack, the encryption of databases prevented employees from processing claims. This is a direct hit on:
Confidentiality
Integrity
Availability
Non-repudiation
Instructions: Select the best answer for each question. Focus on the technical and legal context of the Philippines. What is the mathematical difference between a "Threat" and a "Risk"?
Risk is a weakness; Threat is the person exploiting it.
Risk = Threat × Vulnerability × Asset.
Threats are always external; Risks are always internal.
There is no difference; they are interchangeable.
Instructions: Select the best answer for each question. Focus on the technical and legal context of the Philippines. Under RA 10173 (Data Privacy Act of 2012), how many hours does a company have to notify the National Privacy Commission (NPC) after discovering a sensitive data breach?
24 hours
48 hours
72 hours
7 days
Instructions: Select the best answer for each question. Focus on the technical and legal context of the Philippines. A bank customer receives a fake SMS claiming their account is locked and providing a link to a "verification site." This attack vector is known as:
Vishing
Smishing
Pharming
SQL Injection
Instructions: Select the best answer for each question. Focus on the technical and legal context of the Philippines. Which security control is specifically designed to ensure Integrity by providing a unique fixed-size "fingerprint" of a file?
AES-256 Encryption
RSA Digital Signature
SHA-256 Hashing
Multi-Factor Authentication (MFA)
Instructions: Select the best answer for each question. Focus on the technical and legal context of the Philippines. A student finds a bug in a school portal that allows them to see other students' grades. In security terms, this "bug" is a:
Threat
Attack
Vulnerability
Impact
Instructions: Select the best answer for each question. Focus on the technical and legal context of the Philippines. Which function of the NIST Cybersecurity Framework involves "developing and implementing appropriate activities to identify the occurrence of a cybersecurity event"?
Identify
Protect
Detect
Respond
Instructions: Select the best answer for each question. Focus on the technical and legal context of the Philippines. If a company implements "Defense in Depth," they are:
Using only the strongest firewall available.
Encrypting all data and ignoring other controls.
Using multiple layers of security (e.g., Firewall + MFA + Hashing).
Outsourcing all security to a third-party provider.
Instructions: Select the best answer for each question. Focus on the technical and legal context of the Philippines. A "Denial of Service" (DoS) attack primarily targets which of the following?
Stealing user passwords
Modifying database records
Exhausting system resources to stop legitimate access
Eavesdropping on private conversations
Instructions: Select the best answer for each question. Focus on the technical and legal context of the Philippines. Which Philippine law specifically addresses crimes like "Illegal Access," "System Interference," and "Cyber-squatting"?
RA 10173 (Data Privacy Act)
RA 10175 (Cybercrime Prevention Act)
RA 8792 (E-Commerce Act)
RA 9184 (Government Procurement Act)
Instructions: Select the best answer for each question. Focus on the technical and legal context of the Philippines. What is the primary difference between Symmetric and Asymmetric encryption?
Symmetric is faster; Asymmetric uses two different keys (Public/Private).
Symmetric is only for files; Asymmetric is only for networks.
Symmetric is more secure than Asymmetric.
Asymmetric does not require a key.
Instructions: Select the best answer for each question. Focus on the technical and legal context of the Philippines. In a "Man-in-the-Middle" (MitM) attack, the attacker primarily compromises:
Availability
Confidentiality and Integrity
Physical Security
Only the Hardware
Instructions: Select the best answer for each question. Focus on the technical and legal context of the Philippines. A company requires employees to use a password, a fingerprint scan, and a code sent to their mobile phones. This is an example of:
Single Sign-On (SSO)
Multi-Factor Authentication (MFA)
Role-Based Access Control (RBAC)
Biometric Seeding
Instructions: Select the best answer for each question. Focus on the technical and legal context of the Philippines. Which NIST Framework function is being performed when a company restores data from its off-site backups after a ransomware attack?
Protect
Detect
Respond
Recover
