wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

CNS001_Q1

Total questions: 20

Worksheet time: 10mins

Name
Class
Date
1.

Which statement best captures the core purpose of security in an IT context?

a)

Protect assets through prevention, detection, and recovery

b)

Ensure systems operate faster under heavy network load

c)

Eliminate all risks by blocking every external connection

d)

Focus mainly on software updates for operating systems

2.

Network security primarily aims to protect which combination of properties for data and networks?

a)

Integrity, confidentiality, and availability

b)

Scalability, usability, and portability

c)

Bandwidth, latency, and throughput

d)

Redundancy, virtualization, and automation

3.

Which example best illustrates the detection aspect of security measures?

a)

Applying access control lists to prevent unauthorized logins

b)

Using monitoring to identify when and by whom assets were altered

c)

Configuring backups to restore lost files quickly

d)

Encrypting data to keep transmitted information unreadable

4.

Which consequence is a likely impact of a network security breach on organizations and society?

a)

Guaranteed protection of intellectual property and user safety

b)

Immediate improvements in e-commerce performance

c)

Lost revenue, privacy threats, and compromised information integrity

d)

Increased public trust and reduced legal exposure

5.

Which term best describes anything of value to an organization, including people, equipment, resources, and data?

a)

Asset

b)

Risk

c)

Threat

d)

Exploit

6.

A weakness in a system or its design that could be leveraged by a threat is called a:

a)

Vulnerability

b)

Mitigation

c)

Functionality

d)

Asset

7.

Which term refers to a potential danger to a company’s assets, data, or network functionality?

a)

Mitigation

b)

Threat

c)

Exploit

d)

Risk

8.

In security, what is a mechanism that takes advantage of a vulnerability?

a)

Exploit

b)

Asset

c)

Policy

d)

Backup

9.

Which option best defines mitigation in network security?

a)

Counter-measure that reduces likelihood or severity

b)

Probability that an event will occur

c)

Inventory of valuable organizational items

d)

Process that increases exposure to attacks

10.

Risk in information security is best described as:

a)

List of organizational hardware resources

b)

Likelihood a threat exploits a vulnerability

c)

Tool used to patch software defects

d)

Confirmed attack with known impact

11.

In the diagram, what does the term attack vector most closely refer to?

a)

A backup process for disaster recovery

b)

A firewall rule that blocks all traffic

c)

A device that stores encryption keys only

d)

A path used to gain unauthorized access

12.

Based on the visuals, which scenario best represents an external threat entering a network?

a)

Admin reboots a core switch at noon

b)

Employee moves laptops between offices

c)

Printer updates drivers overnight

d)

Malware from Internet bypasses firewall

13.

Which internal user action is most likely to directly compromise infrastructure devices?

a)

Requesting Wi‑Fi password resets

b)

Changing desktop wallpaper weekly

c)

Archiving emails to local folders

d)

Installing rogue firmware on a switch

14.

Why can internal threats cause greater damage than external threats?

a)

Outsiders always lack network connectivity

b)

Firewalls fully stop all external attacks

c)

Backups instantly undo insider mistakes

d)

Insiders have direct access and knowledge

15.

Which statement best defines data loss or data exfiltration in an organization?

a)

Data is archived for future regulatory audits

b)

Data is intentionally or unintentionally exposed externally

c)

Data is migrated to a new internal database

d)

Data is compressed to reduce storage costs

16.

Which item is a direct consequence of data loss for a company?

a)

Reduced legal scrutiny and penalties

b)

Immediate increase in customer loyalty

c)

Improved market share and pricing power

d)

Brand damage and loss of reputation

17.

Which example best matches the data loss vector: Unencrypted Devices?

a)

A patched OS prevents exploitation during travel

b)

A stolen laptop reveals files due to no encryption

c)

A VPN timeout logs the user out automatically

d)

A firewall blocks all inbound connections overnight

18.

Sensitive data could be exposed if cloud storage is misconfigured. Which description aligns with this vector?

a)

Excessive on-premises backups consume storage space

b)

Weak cloud security settings allow unauthorized access

c)

Frequent password changes frustrate end users

d)

Single sign-on consolidates authentication events

19.

Which practice mitigates the data loss vector related to hard copy records?

a)

Store paper records in unlocked desk drawers

b)

Email printed pages to the compliance mailbox

c)

Scan and upload files to any public folder

d)

Shred confidential documents when no longer needed

20.

A USB drive with corporate files goes missing after an office move. Which vector and impact pair is most accurate?

a)

Cloud vector; automatic gain of competitive edge

b)

Hard copy vector; improved legal compliance

c)

Email vector; guaranteed loss of all customers

d)

Removable media vector; potential loss of revenue