Free Practice Quiz Question List

8 Security in Practice Online Quiz Questions

Use this free practice quiz with 20 questions to review 8 Security in Practice, test your knowledge, and prepare for your next test or exam.

20 questions
01
True or false
1 point

True or false: The qualitative model risk≈likelihood×impact\text{risk} \approx \text{likelihood} \times \text{impact} is intended to provide a precise numerical prediction of harm.

  1. A

    True

  2. B

    False

02
Choose one
1 point

A business cannot eliminate a particular financial risk, but it can arrange insurance to share some potential losses. Which risk response does this illustrate?

  1. A

    Ignore the risk because it has not caused harm yet.

  2. B

    Use insurance or a contract to share some of the consequences.

  3. C

    Accept the risk without review or approval.

  4. D

    Apply safeguards that remove every possible consequence.

03
Written response
1 point

What term describes the risk that remains after safeguards have been applied?

04
Fill in the blank
1 point

A risk arises when a could exploit a and cause harm.

05
True or false
1 point

True or false: Accepting a risk should be an informed decision by someone with appropriate authority, rather than an assumption that an unexamined risk is harmless.

  1. A

    True

  2. B

    False

06
Written response
1 point

According to the material, each account should receive only the access needed for what?

07
Fill in the blank
1 point

To check whether backups can support recovery, a reviewer should seek evidence such as a , not rely only on a written policy.

08
Choose one
1 point

A team has completed a system review. When should it revisit that review?

  1. A

    Only when the system is first built.

  2. B

    Only after a security incident causes confirmed harm.

  3. C

    After significant system changes or incidents, and periodically.

  4. D

    Only when the review's original owner leaves.

09
Choose all
1 point

Select all functions in the NIST Cybersecurity Framework 2.0.

  1. A

    Govern

  2. B

    Identify

  3. C

    Protect

  4. D

    Detect

  5. E

    Respond

  6. F

    Recover

  7. G

    Encrypt

  8. H

    Insure

10
Choose all
1 point

During a practical system review, which actions directly check safeguards or evidence that protections work? Select all that apply.

  1. A

    Review access settings and authentication.

  2. B

    Check whether software updates are applied.

  3. C

    Test whether backups can be restored.

  4. D

    Review logging and incident procedures.

  5. E

    Set the review's scope and purpose.

  6. F

    List the system's devices and applications.

11
Choose one
1 point

An online store discovers that an administrator account uses password-only login. Which single action directly addresses the risk that a stolen password could let an attacker access that account?

  1. A

    Train staff to recognize phishing messages.

  2. B

    Keep an offline copy of important records.

  3. C

    Require multifactor authentication for administrator accounts.

  4. D

    Separate systems according to their roles.

12
Choose one
1 point

An online store is comparing two risks: account takeover, given valuable customer accounts, reused passwords, and an internet-accessible login page; and a temporary outage of a nonessential internal report. Which conclusion best applies risk-based prioritization?

  1. A

    Prioritize account takeover because valuable accounts, reused passwords, and an internet-accessible login create a serious plausible risk.

  2. B

    Prioritize the internal report outage automatically, regardless of its impact or likelihood.

  3. C

    Treat both situations as equal because they involve different kinds of systems.

  4. D

    Ignore account takeover unless an attacker has already succeeded.

13
Open ended
1 point

A company finds that an internet-facing service handling sensitive customer records is running outdated software. Describe how a practical security review should assess and manage this risk, including the potential harm, the threat and weakness, prioritization, a response, verification, and follow-up.

14
Choose one
1 point

A team reviewing an online service inventories its applications, cloud services, vendor connections, backups, and sensitive-data locations. Which system-review step is the team performing?

  1. A

    Set scope and purpose

  2. B

    Map assets and dependencies

  3. C

    Trace likely threat paths

  4. D

    Prioritize and assign action

15
Choose one
1 point

Before reviewing a payment platform, a team identifies the system owner, its users, its important services, and the decisions the review should inform. Which review step does this describe?

  1. A

    Map assets and dependencies

  2. B

    Check safeguards and evidence

  3. C

    Set scope and purpose

  4. D

    Reassess after change

16
Choose one
1 point

A small business wants its security to remain effective even if one safeguard fails. Which plan best applies defense in depth?

  1. A

    Use varied safeguards so one control's failure does not determine the outcome

  2. B

    Use the same safeguard repeatedly so every failure is handled identically

  3. C

    Choose one strong safeguard and remove the others

  4. D

    Apply safeguards only after an incident has caused harm

17
Choose one
1 point

A review finds that a business's administrative application has missed security updates and uses an unnecessarily exposed configuration. Which defense-in-depth layer most directly addresses these issues?

  1. A

    People and policy

  2. B

    Identity and access

  3. C

    Detection and recovery

  4. D

    Devices and applications

18
True or false
1 point

True or false: Using several safeguards guarantees that a system cannot be harmed, so the organization no longer needs to consider whether risks remain.

  1. A

    True

  2. B

    False

19
Written response
1 point

During a system review, a team traces how a phishing message could lead to account compromise and harm. What two-word term names this route from a possible event toward harm?

20
Written response
1 point

A company decides not to launch a feature because it does not want to undertake the risky activity at all. Which single-word risk response describes this decision?