NEW
Font size
WorksheetsInformation Security Quiz
Total questions: 64
Worksheet time: 32mins
Which pillar ensures information is not disclosed to unauthorized individuals?
Integrity
Confidentiality
Availability
Non-repudiation
A Checksum verifies if a file was corrupted during transmission to protect:
Confidentiality
Authentication
Integrity
Availability
A system with 'Five Nines' (99.999%) availability allows for a maximum annual downtime of:
8.76 hours
5.26 minutes
52.6 minutes
1.00 days
Which concept ensures a person cannot deny performing a digital transaction?
Authentication
Integrity
Non-repudiation
Authorization
'C.I.A.N.A' includes the CIA triad plus which two additional elements?
Accounting & Authorization
Non-repudiation & Authentication
Auditing & Access Control
Privacy & Safety
Which technical method is most closely associated with Confidentiality?
Hashing
Redundancy
Encryption
Digital Signatures
'Information Security' primarily focuses on the protection of:
The systems and hardware
The data and information
The network infrastructure
The physical facilities
Changing a complex password to '123456' for ease of use prioritizes:
Security over Cost
Usability over Security
Performance over Speed
Integrity over Availability
A Digital Signature is created by combining Hashing with:
Symmetric encryption algorithms
Asymmetric private key usage
Redundant checksum verification
Biometric factor identification
A 'Hash Digest' is often referred to as a piece of data's:
Encryption Key
Digital Fingerprint
Access Token
Backup Version
The process of verifying 'Who you are' is known as:
Authorization
Accounting
Authentication
Auditing
Determining that a user can 'Read' but not 'Write' to a file is:
Authentication
Authorization
Accounting
Identification
Tracking user actions to create an audit trail falls under:
Accounting
Authentication
Authorization
Availability
Which of the following is an example of 'Something you have'?
A complex PIN
A hardware token
A retinal pattern
A typing rhythm
What is the core principle of the Zero Trust model?
Trust but verify
Trust only insiders
Trust nothing, verify all
Trust only known VPNs
In Zero Trust, the 'Policy Engine' is located within the:
Data Plane
Control Plane
Management Plane
Physical Plane
'Adaptive Identity' in Zero Trust evaluates access based on:
Static passwords only
Real-time context/risk
Internal IP addresses
Role-based tags only
What is the role of the 'Policy Enforcement Point' (PEP)?
Writing new policies
Executing access decisions
Encrypting static data
Patching vulnerabilities
Using both a password and a fingerprint to log in is:
Single Sign-On (SSO)
Multi-Factor (MFA)
Role-Based (RBAC)
Biometric bypass
In AAA, 'Accounting' is most commonly used for:
Encrypting databases
Auditing and Billing
Granting user rights
Resetting passwords
A Firewall is classified as which category of control?
Managerial
Physical
Technical
Operational
A policy requiring password changes every 90 days is:
Technical Control
Operational Control
Physical Control
Managerial Control
A sign saying 'Area under surveillance' is which type of control?
Preventative
Corrective
Deterrent
Compensating
When legacy systems lack WPA3, using a VPN over WPA2 is a:
Detective Control
Compensating Control
Directive Control
Physical Control
A 'Directive Control' is typically implemented through:
Armed security guards
Policies and manuals
Antivirus software
Biometric scanners
Risk is mathematically defined as the intersection of:
Servers and Hackers
Threats and Vulnerabilities
Assets and Budgets
C.I.A. and A.A.A.
An earthquake that destroys a data center is considered a:
Vulnerability
Threat
Risk
Mitigation
Buying cybersecurity insurance to offset financial loss is:
Risk Mitigation
Risk Avoidance
Risk Acceptance
Risk Transfer
Deciding not to deploy a high-risk service is an example of:
Risk Acceptance
Risk Avoidance
Risk Mitigation
Risk Transfer
What is the goal of a POA&M in a Gap Analysis?
Listing software bugs
Planning to bridge gaps
Auditing daily logs
Purchasing new insurance
What characterizes a 'Script Kiddie'?
Writes custom exploits
Nation-state funded
Uses pre-made tools
Motivated by politics
The primary motivation of 'Organized Crime' groups is:
Social Reputation
Political Ideology
Financial Profit
Personal Revenge
'Hacktivists' usually launch attacks to:
Encrypt files for cash
Promote social change
Conduct deep research
Test system speeds
Which entity is best equipped to carry out an 'APT'?
Script Kiddies
Nation-state Actors
Amateur hackers
New employees
An attack designed to blame another party is known as:
Zero-day attack
False Flag attack
Insider threat
Brute force
'Insider Threats' are dangerous because they have:
Infinite funding
Knowledge and access
AI-driven malware
No traceable IP
'Shadow IT' often occurs because of:
Foreign hack groups
Employee convenience
Operating system bugs
Strict network rules
The 'Stuxnet' worm is an example of an attack by:
Hacktivists
Nation-state Actors
Script Kiddies
Shadow IT users
'Espionage' (Spying) motivations aim to:
Crash remote servers
Gather secret intel
Extort local users
Create public chaos
Shadow IT increases risk primarily because it leads to:
Higher energy costs
Unmanaged vulnerabilities
High user happiness
Extra data backups
'Bollards' are primarily designed to stop:
Fence climbers
Vehicle ramming
Wi-Fi sniffing
Paper theft
How does an 'Access Control Vestibule' (Mantrap) work?
One door opens at a time
Scans with X-ray tech
Identifies from 100m
Uses wooden deadbolts
Which statement correctly identifies Piggybacking?
Sneaking in unknowingly
Entry via user consent
Brute forcing a lock
Cloning an NFC badge
A low 'Crossover Error Rate' (CER) indicates that a system is:
Prone to many errors
Extremely expensive
Accurate and effective
Inefficiently slow
A 'Flipper Zero' can be used to perform which attack?
Dismantling bollards
Access Badge Cloning
Cutting heavy fences
Social engineering
Which sensor uses 'Echo Location' principles?
Infrared sensor
Microwave sensor
Ultrasonic sensor
Pressure sensor
'Shoulder Surfing' refers to the act of:
Stealing trash bags
Observing a user's PIN
Sending fake emails
Picking a door lock
'Vishing' is a form of fraud conducted via:
Standard email
SMS text messages
Voice/Phone calls
Physical letters
Hiding malicious code within image pixels is called:
Vishing
Steganography
Brute Force
Shadow IT
An 'Evil Twin' attack involves:
Physical door locks
Fake Wi-Fi networks
Cloned ID badges
Fake social media
A phishing email targeting the CEO specifically is:
General Phishing
Spear Phishing
Whaling
Vishing
'Pretexting' is best defined as:
Mass email spamming
Fabricated scenarios
Forced physical entry
Port scanning
The psychological trigger 'Scarcity' uses which message?
'I am your manager'
'Only 2 spots remain'
'Hold the door open'
'Join the team today'
A 'Honeypot' is used to:
Block all attacks
Lure/Study attackers
Speed up websites
Store real secrets
'Disinformation' is distinguished from 'Misinformation' by:
Harmful intent
Use of Twitter
Length of message
Technical skill
Which type of attack involves manipulating a user into divulging confidential information?
Phishing
Malware
SQL Injection
Ransomware
What is the primary goal of a Denial of Service (DoS) attack?
Install malware
Disrupt services
Steal data
Gain unauthorized access
Which security measure involves regularly updating software to fix vulnerabilities?
Data Encryption
Access Control
Patch Management
Incident Response
Which of the following is a method to ensure data integrity during transmission?
Encryption
Checksum
Encoding
Compression
What is the primary purpose of a 'Firewall'?
Data storage
User authentication
Network monitoring
Traffic filtering
Which type of malware is designed to replicate itself and spread to other systems?
Trojan
Worm
Spyware
Adware
What does 'Phishing' primarily aim to achieve?
Network monitoring
System repair
Data encryption
Data theft
Which of the following is a common method of 'Social Engineering'?
SQL Injection
Packet Sniffing
Denial of Service
Pretexting
What is the purpose of a 'Security Information and Event Management' (SIEM) system?
Real-time monitoring
Data storage
Software development
Network configuration
