Worksheets융합보안 이해 테스트
Total questions: 15
Worksheet time: 8mins
정보 보안의 기본 개념은 무엇인가요?
기밀성, 무결성, 가용성
신뢰성, 접근성, 관리성
보안성, 투명성, 효율성
정확성, 신속성, 지속성
네트워크 보안의 주요 원리는 무엇인가요?
확장성, 유연성, 적시성
기밀성, 무결성, 가용성
속도, 효율성, 안정성
신뢰성, 접근성, 유효성
What are the types of cyber attacks?
Password change request
Network speed degradation
Malware, phishing, denial of service attacks, data breaches, ransomware, zero-day attacks
Spam emails
보안 정책을 수립할 때 고려해야 할 요소는 무엇인가요?
조직의 예산, 직원 수, 경쟁사 분석, 고객 피드백
기술 지원, 마케팅 전략, 제품 개발, 고객 서비스
업무 프로세스, 직원 복지, 사내 문화, 외부 감사
조직의 목표, 법적 요구사항, 위험 평가, 자원, 기술적 환경, 사용자 교육 및 인식, 정책의 시행 및 검토 절차
What are the stages of the risk management process?
Risk exploration, risk management, risk execution, risk recording, risk review
Risk identification, risk analysis, risk assessment, risk response, risk monitoring and review
Risk collection, risk adjustment, risk execution, risk analysis, risk assessment
Risk planning, risk control, risk reporting, risk termination, risk assessment
What are the main components of an information security management system?
Software development, system integration, network design, user support
Legal regulations, audits, risk assessment, data backup
Business continuity planning, external audits, asset management, cloud services
Policies, procedures, technical measures, human resource management, training and awareness programs
What is the definition of ISMS?
Information Security Management System
Information Asset Management System
Information Protection Management Framework
Information Technology Management System
What is the purpose of ISO27001?
Improvement of information technology infrastructure
Establishment and maintenance of Information Security Management System (ISMS)
Establishment of business continuity plans
Preparation of data backup and recovery procedures
What does the CIA triangle of information security mean?
Reliability, Accessibility, Processing Speed
Accuracy, Transparency, Persistence
Security, Efficiency, Promptness
Confidentiality, Integrity, Availability
What is the role of a network firewall?
A network firewall is a device for user authentication.
A network firewall is a device that can slow down internet speed.
A network firewall is a device that enhances network security and blocks unauthorized access.
A network firewall is a device that increases data transmission speed.
What are the characteristics of phishing attacks?
An attack that sends advertisements via email
An attack that distributes malicious software
An attack that hacks the user's computer
An attack that deceives users to steal personal information
What is the importance of security policies?
Security policies contribute to cost reduction.
Security policies increase customer satisfaction.
Security policies are important for protecting information assets and managing risks.
Security policies are unrelated to employee training.
What techniques are used in risk assessment?
Quantitative risk analysis, qualitative risk analysis, FMEA, HAZOP, SWOT analysis
Risk management plan
Cost-benefit analysis
Project schedule management
What is the certification process for the information security management system?
The certification process for the information security management system consists of application submission, document review, and certificate issuance.
The certification process for the information security management system proceeds with document submission, examination, and notification of results.
The certification process for the information security management system is composed of application writing, examination, and certificate issuance.
The certification process for the information security management system consists of application submission, document and on-site examination, certification decision, certificate issuance, and post-management.
What are the requirements of ISO27001?
Requirements for developing an information security training program.
Management measures for information technology assets.
Requirements for establishing and operating an Information Security Management System (ISMS).
Guidelines for establishing an information security policy.
