wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Information Assurance & Security

Total questions: 15

Worksheet time: 7mins

Name
Class
Date
1.

Instructions: Select the best answer for each question. Focus on the technical and legal context of the Philippines. A local government unit’s (LGU) website is defaced by a hacktivist group. Which pillar of the CIA Triad has been primarily violated?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Authenticity

2.

Instructions: Select the best answer for each question. Focus on the technical and legal context of the Philippines. In the 2023 PhilHealth "Medusa" attack, the encryption of databases prevented employees from processing claims. This is a direct hit on:

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Non-repudiation

3.

Instructions: Select the best answer for each question. Focus on the technical and legal context of the Philippines. What is the mathematical difference between a "Threat" and a "Risk"?

a)

Risk is a weakness; Threat is the person exploiting it.

b)

Risk = Threat × Vulnerability × Asset.

c)

Threats are always external; Risks are always internal.

d)

There is no difference; they are interchangeable.

4.

Instructions: Select the best answer for each question. Focus on the technical and legal context of the Philippines. Under RA 10173 (Data Privacy Act of 2012), how many hours does a company have to notify the National Privacy Commission (NPC) after discovering a sensitive data breach?

a)

24 hours

b)

48 hours

c)

72 hours

d)

7 days

5.

Instructions: Select the best answer for each question. Focus on the technical and legal context of the Philippines. A bank customer receives a fake SMS claiming their account is locked and providing a link to a "verification site." This attack vector is known as:

a)

Vishing

b)

Smishing

c)

Pharming

d)

SQL Injection

6.

Instructions: Select the best answer for each question. Focus on the technical and legal context of the Philippines. Which security control is specifically designed to ensure Integrity by providing a unique fixed-size "fingerprint" of a file?

a)

AES-256 Encryption

b)

RSA Digital Signature

c)

SHA-256 Hashing

d)

Multi-Factor Authentication (MFA)

7.

Instructions: Select the best answer for each question. Focus on the technical and legal context of the Philippines. A student finds a bug in a school portal that allows them to see other students' grades. In security terms, this "bug" is a:

a)

Threat

b)

Attack

c)

Vulnerability

d)

Impact

8.

Instructions: Select the best answer for each question. Focus on the technical and legal context of the Philippines. Which function of the NIST Cybersecurity Framework involves "developing and implementing appropriate activities to identify the occurrence of a cybersecurity event"?

a)

Identify

b)

Protect

c)

Detect

d)

Respond

9.

Instructions: Select the best answer for each question. Focus on the technical and legal context of the Philippines. If a company implements "Defense in Depth," they are:

a)

Using only the strongest firewall available.

b)

Encrypting all data and ignoring other controls.

c)

Using multiple layers of security (e.g., Firewall + MFA + Hashing).

d)

Outsourcing all security to a third-party provider.

10.

Instructions: Select the best answer for each question. Focus on the technical and legal context of the Philippines. A "Denial of Service" (DoS) attack primarily targets which of the following?

a)

Stealing user passwords

b)

Modifying database records

c)

Exhausting system resources to stop legitimate access

d)

Eavesdropping on private conversations

11.

Instructions: Select the best answer for each question. Focus on the technical and legal context of the Philippines. Which Philippine law specifically addresses crimes like "Illegal Access," "System Interference," and "Cyber-squatting"?

a)

RA 10173 (Data Privacy Act)

b)

RA 10175 (Cybercrime Prevention Act)

c)

RA 8792 (E-Commerce Act)

d)

RA 9184 (Government Procurement Act)

12.

Instructions: Select the best answer for each question. Focus on the technical and legal context of the Philippines. What is the primary difference between Symmetric and Asymmetric encryption?

a)

Symmetric is faster; Asymmetric uses two different keys (Public/Private).

b)

Symmetric is only for files; Asymmetric is only for networks.

c)

Symmetric is more secure than Asymmetric.

d)

Asymmetric does not require a key.

13.

Instructions: Select the best answer for each question. Focus on the technical and legal context of the Philippines. In a "Man-in-the-Middle" (MitM) attack, the attacker primarily compromises:

a)

Availability

b)

Confidentiality and Integrity

c)

Physical Security

d)

Only the Hardware

14.

Instructions: Select the best answer for each question. Focus on the technical and legal context of the Philippines. A company requires employees to use a password, a fingerprint scan, and a code sent to their mobile phones. This is an example of:

a)

Single Sign-On (SSO)

b)

Multi-Factor Authentication (MFA)

c)

Role-Based Access Control (RBAC)

d)

Biometric Seeding

15.

Instructions: Select the best answer for each question. Focus on the technical and legal context of the Philippines. Which NIST Framework function is being performed when a company restores data from its off-site backups after a ransomware attack?

a)

Protect

b)

Detect

c)

Respond

d)

Recover