A hospital must be able to access essential patient records during care. Which security goal is most directly served by ensuring the records remain usable when needed?
1 Foundations of Information Security Online Quiz Questions
Use this free practice quiz with 20 questions to review 1 Foundations of Information Security, test your knowledge, and prepare for your next test or exam.
A security measure can improve one security goal while making another goal harder to achieve.
- A
True
- B
False
Completing a threat model guarantees that every way a system could be attacked or fail has been identified.
- A
True
- B
False
A team is assessing the risk of a security event. What two considerations are commonly used to assess risk?
An administrator gives a service account only the permissions needed for its task, and removes those permissions when they are no longer needed. Which security principle is being applied?
Using complementary safeguards at multiple layers is . Configuring a system to deny unnecessary access initially is .
In the introductory threat-modeling process, after defining scope and assets, teams and then .
A team discovers that a planned activity could expose sensitive customer information. Explain how it could assess and respond to the risk. Describe at least two different risk responses and why ongoing monitoring may still be needed.
A team is beginning a threat model for an online service. Which actions are appropriate parts of the process? Select all that apply.
- A
Identify the system's important information and services.
- B
Assume that the system has no external connections unless an incident proves otherwise.
- C
Examine data flows and trust boundaries.
- D
Consider likelihood and potential impact when prioritizing scenarios.
- E
Treat the first safeguards selected as permanently sufficient.
A manager is deciding how to handle an assessed security risk. Which are recognized risk-response options? Select all that apply.
- A
Add safeguards to reduce the risk.
- B
Stop the activity that creates the risk.
- C
Assume the risk has disappeared without changing anything.
- D
Share or transfer some of the consequences.
- E
Wait for an incident before deciding whether to respond.
- F
Knowingly accept the remaining risk.
A payment process requires one employee to prepare a transaction and a different employee to approve it. Which security principle is most directly reflected in this design?
- A
Separate the task's critical steps so one account cannot complete them all.
- B
Give one account every permission needed to complete the entire process.
- C
Remove all checks so the task can be completed more quickly.
- D
Keep the task's steps undocumented to limit the number of people who understand it.
A safeguard that was appropriate when a system was first deployed may need to be reassessed after the system or its operating conditions change.
- A
True
- B
False
A company stores employee payroll records in a system. Which security goal is most directly served by restricting access so only authorized payroll staff can view those records?
- A
Confidentiality
- B
Integrity
- C
Availability
- D
Risk
A payment record is changed without authorization, causing the amount owed to be incorrect. Which security goal has been directly violated?
- A
Confidentiality
- B
Integrity
- C
Availability
- D
Threat modeling
A ticket-booking service has accurate records and protects customer information, but authorized customers cannot access it during peak booking hours. Which security goal is most directly affected?
- A
Confidentiality
- B
Integrity
- C
Availability
- D
Separation of duties
A public-facing server contains an unpatched software flaw that could allow unauthorized access. What is the flaw in this scenario?
- A
A threat
- B
A vulnerability
- C
An impact
- D
A security goal
A team is choosing between two designs that meet the same requirements. One has fewer unnecessary components and is easier to understand and review. Which security principle best supports choosing that design?
- A
Simplicity and clear boundaries
- B
Availability
- C
Threat identification
- D
Confidentiality
An attacker tries to access a server containing customer records. In this scenario, what is the attacker’s attempt?
- A
A threat
- B
A vulnerability
- C
An impact
- D
A safeguard
A system has a weakness that could be exploited by an attacker or triggered by another harmful event. What is this weakness called? Enter the security term.
In threat modeling, what term names the important information and services identified as things to protect? Enter the plural term.