Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

General Security Concepts Part 2

Total questions: 30

Worksheet time: 10mins

Name
Class
Date
1.

Which of the following is an example of a preventive control?

a)

Antivirus logs

b)

Security awareness training

c)

Firewall blocking malicious traffic

d)

Incident investigation reports

2.

Detective controls are designed to?

a)

Prevent security incidents from happening

b)

Recover systems after an attack

c)

Restrict user permissions

d)

Identify and alert on suspicious activity

3.

Which control type enforces policies through people and procedures?

a)

Administrative control

b)

Physical control

c)

Technical control

d)

Technical control

4.

In the CIA triad, what does integrity ensure?

a)

Only authorized users can access the data

b)

Data is encrypted during transmission

c)

Data is accurate, complete, and unaltered

d)

Systems are segmented to limit attacks

5.

A security control that automatically removes malware after detection is:

a)

Preventive

b)

Detective

c)

Physical

d)

Corrective

6.

Which concept ensures users have only the access they need to perform their job?

a)

Least Privilege

b)

Defense in Depth

c)

Micro-Segmentation

d)

Separation of Duties

7.

Which security control is an example of a physical control?

a)

Firewall

b)

Biometric access

c)

Patch management

d)

SIEM monitoring

8.

What is the main purpose of network segmentation?

a)

Encrypt all traffic

b)

Detect unauthorized logins

c)

Limit the spread of attacks within the network

d)

Automate patching processes

9.

Which process ensures changes to systems are reviewed, approved, and documented before implementation?

a)

Incident Response

b)

Patch Management

c)

Change Management

d)

Vulnerability Scanning

10.

Which activity is part of decommissioning a device?

a)

Updating the asset inventory

b)

Installing a new patch

c)

Enabling remote access

d)

Segmenting the network

11.

What is the purpose of configuration enforcement?

a)

To prevent lateral movement of attackers

b)

To ensure devices comply with secure configuration standards

c)

To detect malware

d)

To encrypt data in transit

12.

Which control type directly involves technical tools like firewalls or EDR?

a)

Administrative

b)

Physical

c)

Technical

d)

Corrective

13.

Why is hardening a system important?

a)

It improves network speed

b)

It reduces the system’s attack surface

c)

It ensures users can access all features

d)

It prevents power outages

14.

Which is an example of an administrative control in change management?

a)

Disabling unused ports

b)

Isolating infected devices

c)

Applying a patch to a server

d)

Documenting and approving a configuration change

15.

Multi-factor authentication is primarily an example of which security principle?

a)

Least privilege

b)

Defense in Depth

c)

Segmentation

d)

Encryption

16.

What is the primary purpose of change management in cybersecurity?

a)

To encrypt sensitive data

b)

To patch vulnerabilities automatically

c)

To control and document changes to systems and processes

d)

To segment the network

17.

A security team wants to detect unusual network traffic patterns and potential intrusions. Which type of control are they implementing?

a)

Detective control

b)

Corrective control

c)

Preventive control

d)

Physical control

18.

Which fundamental security principle ensures that users only have the minimum access necessary to perform their job?

a)

Segmentation

b)

Least Privilege

c)

Isolation

d)

Zero Trust

19.

What is the primary goal of change management?

a)

To manage changes with minimal disruption to services

b)

To allow unrestricted system modifications

c)

To implement changes without approval

d)

To create more work for IT staff

20.

What type of change requires the least documentation and approval?

a)

Standard Change

b)

Emergency Change

c)

Major Change

d)

Normal Change

21.

Which tool is commonly used to track and manage changes?

a)

Firewall

b)

IDS

c)

Change Management System (CMS)

d)

VPN

22.

What does a Change Advisory Board (CAB) do?

a)

Designs system architecture

b)

Implements emergency changes

c)

Monitors network traffic

d)

Reviews, assesses, and approves changes

23.

What is the main focus of change evaluation?

a)

Approving changes without risk assessment

b)

Assessing success and lessons learned from a change

c)

Ignoring post-change issues

d)

Implementing changes immediately

24.

A rollback plan is important because:

a)

It provides a way to restore systems if the change fails.

b)

It ensures changes are permanent

c)

It avoids documentation

d)

It delays implementation

25.

Why is communication important in change management?

a)

To avoid documenting changes

b)

To keep stakeholders informed about potential impact and schedule

c)

To bypass approval processes

d)

To delay implementation

26.

Which step ensures that changes do not disrupt business operations after implementation?

a)

Post-Implementation Review

b)

Change Request Submission

c)

Ad-hoc Deployment

d)

Risk Ignoring

27.

Which method reduces risk before implementing a change?

a)

Implementing directly in production

b)

Delaying communication

c)

Testing in a controlled environment

d)

Ignoring dependencies

28.

Which document is crucial for auditing change management processes?

a)

Backup Files Only

b)

Change Logs

c)

Firewall Rules Only

d)

Server Inventory

29.

Risk assessment in change management includes?

a)

Ignoring stakeholder concerns

b)

Immediate deployment

c)

Identifying potential issues and their impact on systems and users

d)

Avoiding documentation

30.

Which of the following is a key metric for evaluating change management effectiveness?

a)

Number of changes implemented without incidents

b)

Number of assets purchased

c)

Server uptime only

d)

Number of employees