wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Information Security Quiz

Total questions: 64

Worksheet time: 32mins

Name
Class
Date
1.

Which pillar ensures information is not disclosed to unauthorized individuals?

a)

Integrity

b)

Confidentiality

c)

Availability

d)

Non-repudiation

2.

A Checksum verifies if a file was corrupted during transmission to protect:

a)

Confidentiality

b)

Authentication

c)

Integrity

d)

Availability

3.

A system with 'Five Nines' (99.999%) availability allows for a maximum annual downtime of:

a)

8.76 hours

b)

5.26 minutes

c)

52.6 minutes

d)

1.00 days

4.

Which concept ensures a person cannot deny performing a digital transaction?

a)

Authentication

b)

Integrity

c)

Non-repudiation

d)

Authorization

5.

'C.I.A.N.A' includes the CIA triad plus which two additional elements?

a)

Accounting & Authorization

b)

Non-repudiation & Authentication

c)

Auditing & Access Control

d)

Privacy & Safety

6.

Which technical method is most closely associated with Confidentiality?

a)

Hashing

b)

Redundancy

c)

Encryption

d)

Digital Signatures

7.

'Information Security' primarily focuses on the protection of:

a)

The systems and hardware

b)

The data and information

c)

The network infrastructure

d)

The physical facilities

8.

Changing a complex password to '123456' for ease of use prioritizes:

a)

Security over Cost

b)

Usability over Security

c)

Performance over Speed

d)

Integrity over Availability

9.

A Digital Signature is created by combining Hashing with:

a)

Symmetric encryption algorithms

b)

Asymmetric private key usage

c)

Redundant checksum verification

d)

Biometric factor identification

10.

A 'Hash Digest' is often referred to as a piece of data's:

a)

Encryption Key

b)

Digital Fingerprint

c)

Access Token

d)

Backup Version

11.

The process of verifying 'Who you are' is known as:

a)

Authorization

b)

Accounting

c)

Authentication

d)

Auditing

12.

Determining that a user can 'Read' but not 'Write' to a file is:

a)

Authentication

b)

Authorization

c)

Accounting

d)

Identification

13.

Tracking user actions to create an audit trail falls under:

a)

Accounting

b)

Authentication

c)

Authorization

d)

Availability

14.

Which of the following is an example of 'Something you have'?

a)

A complex PIN

b)

A hardware token

c)

A retinal pattern

d)

A typing rhythm

15.

What is the core principle of the Zero Trust model?

a)

Trust but verify

b)

Trust only insiders

c)

Trust nothing, verify all

d)

Trust only known VPNs

16.

In Zero Trust, the 'Policy Engine' is located within the:

a)

Data Plane

b)

Control Plane

c)

Management Plane

d)

Physical Plane

17.

'Adaptive Identity' in Zero Trust evaluates access based on:

a)

Static passwords only

b)

Real-time context/risk

c)

Internal IP addresses

d)

Role-based tags only

18.

What is the role of the 'Policy Enforcement Point' (PEP)?

a)

Writing new policies

b)

Executing access decisions

c)

Encrypting static data

d)

Patching vulnerabilities

19.

Using both a password and a fingerprint to log in is:

a)

Single Sign-On (SSO)

b)

Multi-Factor (MFA)

c)

Role-Based (RBAC)

d)

Biometric bypass

20.

In AAA, 'Accounting' is most commonly used for:

a)

Encrypting databases

b)

Auditing and Billing

c)

Granting user rights

d)

Resetting passwords

21.

A Firewall is classified as which category of control?

a)

Managerial

b)

Physical

c)

Technical

d)

Operational

22.

A policy requiring password changes every 90 days is:

a)

Technical Control

b)

Operational Control

c)

Physical Control

d)

Managerial Control

23.

A sign saying 'Area under surveillance' is which type of control?

a)

Preventative

b)

Corrective

c)

Deterrent

d)

Compensating

24.

When legacy systems lack WPA3, using a VPN over WPA2 is a:

a)

Detective Control

b)

Compensating Control

c)

Directive Control

d)

Physical Control

25.

A 'Directive Control' is typically implemented through:

a)

Armed security guards

b)

Policies and manuals

c)

Antivirus software

d)

Biometric scanners

26.

Risk is mathematically defined as the intersection of:

a)

Servers and Hackers

b)

Threats and Vulnerabilities

c)

Assets and Budgets

d)

C.I.A. and A.A.A.

27.

An earthquake that destroys a data center is considered a:

a)

Vulnerability

b)

Threat

c)

Risk

d)

Mitigation

28.

Buying cybersecurity insurance to offset financial loss is:

a)

Risk Mitigation

b)

Risk Avoidance

c)

Risk Acceptance

d)

Risk Transfer

29.

Deciding not to deploy a high-risk service is an example of:

a)

Risk Acceptance

b)

Risk Avoidance

c)

Risk Mitigation

d)

Risk Transfer

30.

What is the goal of a POA&M in a Gap Analysis?

a)

Listing software bugs

b)

Planning to bridge gaps

c)

Auditing daily logs

d)

Purchasing new insurance

31.

What characterizes a 'Script Kiddie'?

a)

Writes custom exploits

b)

Nation-state funded

c)

Uses pre-made tools

d)

Motivated by politics

32.

The primary motivation of 'Organized Crime' groups is:

a)

Social Reputation

b)

Political Ideology

c)

Financial Profit

d)

Personal Revenge

33.

'Hacktivists' usually launch attacks to:

a)

Encrypt files for cash

b)

Promote social change

c)

Conduct deep research

d)

Test system speeds

34.

Which entity is best equipped to carry out an 'APT'?

a)

Script Kiddies

b)

Nation-state Actors

c)

Amateur hackers

d)

New employees

35.

An attack designed to blame another party is known as:

a)

Zero-day attack

b)

False Flag attack

c)

Insider threat

d)

Brute force

36.

'Insider Threats' are dangerous because they have:

a)

Infinite funding

b)

Knowledge and access

c)

AI-driven malware

d)

No traceable IP

37.

'Shadow IT' often occurs because of:

a)

Foreign hack groups

b)

Employee convenience

c)

Operating system bugs

d)

Strict network rules

38.

The 'Stuxnet' worm is an example of an attack by:

a)

Hacktivists

b)

Nation-state Actors

c)

Script Kiddies

d)

Shadow IT users

39.

'Espionage' (Spying) motivations aim to:

a)

Crash remote servers

b)

Gather secret intel

c)

Extort local users

d)

Create public chaos

40.

Shadow IT increases risk primarily because it leads to:

a)

Higher energy costs

b)

Unmanaged vulnerabilities

c)

High user happiness

d)

Extra data backups

41.

'Bollards' are primarily designed to stop:

a)

Fence climbers

b)

Vehicle ramming

c)

Wi-Fi sniffing

d)

Paper theft

42.

How does an 'Access Control Vestibule' (Mantrap) work?

a)

One door opens at a time

b)

Scans with X-ray tech

c)

Identifies from 100m

d)

Uses wooden deadbolts

43.

Which statement correctly identifies Piggybacking?

a)

Sneaking in unknowingly

b)

Entry via user consent

c)

Brute forcing a lock

d)

Cloning an NFC badge

44.

A low 'Crossover Error Rate' (CER) indicates that a system is:

a)

Prone to many errors

b)

Extremely expensive

c)

Accurate and effective

d)

Inefficiently slow

45.

A 'Flipper Zero' can be used to perform which attack?

a)

Dismantling bollards

b)

Access Badge Cloning

c)

Cutting heavy fences

d)

Social engineering

46.

Which sensor uses 'Echo Location' principles?

a)

Infrared sensor

b)

Microwave sensor

c)

Ultrasonic sensor

d)

Pressure sensor

47.

'Shoulder Surfing' refers to the act of:

a)

Stealing trash bags

b)

Observing a user's PIN

c)

Sending fake emails

d)

Picking a door lock

48.

'Vishing' is a form of fraud conducted via:

a)

Standard email

b)

SMS text messages

c)

Voice/Phone calls

d)

Physical letters

49.

Hiding malicious code within image pixels is called:

a)

Vishing

b)

Steganography

c)

Brute Force

d)

Shadow IT

50.

An 'Evil Twin' attack involves:

a)

Physical door locks

b)

Fake Wi-Fi networks

c)

Cloned ID badges

d)

Fake social media

51.

A phishing email targeting the CEO specifically is:

a)

General Phishing

b)

Spear Phishing

c)

Whaling

d)

Vishing

52.

'Pretexting' is best defined as:

a)

Mass email spamming

b)

Fabricated scenarios

c)

Forced physical entry

d)

Port scanning

53.

The psychological trigger 'Scarcity' uses which message?

a)

'I am your manager'

b)

'Only 2 spots remain'

c)

'Hold the door open'

d)

'Join the team today'

54.

A 'Honeypot' is used to:

a)

Block all attacks

b)

Lure/Study attackers

c)

Speed up websites

d)

Store real secrets

55.

'Disinformation' is distinguished from 'Misinformation' by:

a)

Harmful intent

b)

Use of Twitter

c)

Length of message

d)

Technical skill

56.

Which type of attack involves manipulating a user into divulging confidential information?

a)

Phishing

b)

Malware

c)

SQL Injection

d)

Ransomware

57.

What is the primary goal of a Denial of Service (DoS) attack?

a)

Install malware

b)

Disrupt services

c)

Steal data

d)

Gain unauthorized access

58.

Which security measure involves regularly updating software to fix vulnerabilities?

a)

Data Encryption

b)

Access Control

c)

Patch Management

d)

Incident Response

59.

Which of the following is a method to ensure data integrity during transmission?

a)

Encryption

b)

Checksum

c)

Encoding

d)

Compression

60.

What is the primary purpose of a 'Firewall'?

a)

Data storage

b)

User authentication

c)

Network monitoring

d)

Traffic filtering

61.

Which type of malware is designed to replicate itself and spread to other systems?

a)

Trojan

b)

Worm

c)

Spyware

d)

Adware

62.

What does 'Phishing' primarily aim to achieve?

a)

Network monitoring

b)

System repair

c)

Data encryption

d)

Data theft

63.

Which of the following is a common method of 'Social Engineering'?

a)

SQL Injection

b)

Packet Sniffing

c)

Denial of Service

d)

Pretexting

64.

What is the purpose of a 'Security Information and Event Management' (SIEM) system?

a)

Real-time monitoring

b)

Data storage

c)

Software development

d)

Network configuration