Free Practice Quiz Question List

1 Foundations of Information Security Online Quiz Questions

Use this free practice quiz with 20 questions to review 1 Foundations of Information Security, test your knowledge, and prepare for your next test or exam.

20 questions
01
Choose one
1 point

A hospital must be able to access essential patient records during care. Which security goal is most directly served by ensuring the records remain usable when needed?

  1. A

    Confidentiality

  2. B

    Availability

  3. C

    Integrity

  4. D

    Separation of duties

02
True or false
1 point

A security measure can improve one security goal while making another goal harder to achieve.

  1. A

    True

  2. B

    False

03
True or false
1 point

Completing a threat model guarantees that every way a system could be attacked or fail has been identified.

  1. A

    True

  2. B

    False

04
Written response
1 point

A team is assessing the risk of a security event. What two considerations are commonly used to assess risk?

05
Written response
1 point

An administrator gives a service account only the permissions needed for its task, and removes those permissions when they are no longer needed. Which security principle is being applied?

06
Fill in the blank
1 point

Using complementary safeguards at multiple layers is . Configuring a system to deny unnecessary access initially is .

07
Fill in the blank
1 point

In the introductory threat-modeling process, after defining scope and assets, teams and then .

08
Open ended
1 point

A team discovers that a planned activity could expose sensitive customer information. Explain how it could assess and respond to the risk. Describe at least two different risk responses and why ongoing monitoring may still be needed.

09
Choose all
1 point

A team is beginning a threat model for an online service. Which actions are appropriate parts of the process? Select all that apply.

  1. A

    Identify the system's important information and services.

  2. B

    Assume that the system has no external connections unless an incident proves otherwise.

  3. C

    Examine data flows and trust boundaries.

  4. D

    Consider likelihood and potential impact when prioritizing scenarios.

  5. E

    Treat the first safeguards selected as permanently sufficient.

10
Choose all
1 point

A manager is deciding how to handle an assessed security risk. Which are recognized risk-response options? Select all that apply.

  1. A

    Add safeguards to reduce the risk.

  2. B

    Stop the activity that creates the risk.

  3. C

    Assume the risk has disappeared without changing anything.

  4. D

    Share or transfer some of the consequences.

  5. E

    Wait for an incident before deciding whether to respond.

  6. F

    Knowingly accept the remaining risk.

11
Choose one
1 point

A payment process requires one employee to prepare a transaction and a different employee to approve it. Which security principle is most directly reflected in this design?

  1. A

    Separate the task's critical steps so one account cannot complete them all.

  2. B

    Give one account every permission needed to complete the entire process.

  3. C

    Remove all checks so the task can be completed more quickly.

  4. D

    Keep the task's steps undocumented to limit the number of people who understand it.

12
True or false
1 point

A safeguard that was appropriate when a system was first deployed may need to be reassessed after the system or its operating conditions change.

  1. A

    True

  2. B

    False

13
Choose one
1 point

A company stores employee payroll records in a system. Which security goal is most directly served by restricting access so only authorized payroll staff can view those records?

  1. A

    Confidentiality

  2. B

    Integrity

  3. C

    Availability

  4. D

    Risk

14
Choose one
1 point

A payment record is changed without authorization, causing the amount owed to be incorrect. Which security goal has been directly violated?

  1. A

    Confidentiality

  2. B

    Integrity

  3. C

    Availability

  4. D

    Threat modeling

15
Choose one
1 point

A ticket-booking service has accurate records and protects customer information, but authorized customers cannot access it during peak booking hours. Which security goal is most directly affected?

  1. A

    Confidentiality

  2. B

    Integrity

  3. C

    Availability

  4. D

    Separation of duties

16
Choose one
1 point

A public-facing server contains an unpatched software flaw that could allow unauthorized access. What is the flaw in this scenario?

  1. A

    A threat

  2. B

    A vulnerability

  3. C

    An impact

  4. D

    A security goal

17
Choose one
1 point

A team is choosing between two designs that meet the same requirements. One has fewer unnecessary components and is easier to understand and review. Which security principle best supports choosing that design?

  1. A

    Simplicity and clear boundaries

  2. B

    Availability

  3. C

    Threat identification

  4. D

    Confidentiality

18
Choose one
1 point

An attacker tries to access a server containing customer records. In this scenario, what is the attacker’s attempt?

  1. A

    A threat

  2. B

    A vulnerability

  3. C

    An impact

  4. D

    A safeguard

19
Written response
1 point

A system has a weakness that could be exploited by an attacker or triggered by another harmful event. What is this weakness called? Enter the security term.

20
Written response
1 point

In threat modeling, what term names the important information and services identified as things to protect? Enter the plural term.