EMT Practice Test

1. Question Content...


Question List

Question1: What is an example of a non-human threat to the physical environment?

Question2: Midwest Insurance controls access to its offices with a passkey system. What kind of security measure is this?

Question3: What is the purpose for an organization to have an information security policy?

Question4: What is the goal of an organization's security policy?

Question5: What is accomplished if reports are assigned the appropriate grading?

Question6: Within a company several employees work mostly outside the perimeter of the company. These employees have laptops on which the necessary (confidential) information is stored.
Which technical security measure protects the information from unwanted disclosure in case the employee loses the laptop?

Question7: You are the first to arrive at work in the morning and notice that the CD ROM on which you saved contracts yesterday has disappeared. You were the last to leave yesterday. When should you report this information security incident?

Question8: Which of these is not malicious software?

Question9: What is the purpose of a Disaster Recovery Plan (DRP)?

Question10: You work in the office of a large company. You receive a call from a person claiming to be from the Helpdesk. He asks you for your password. What kind of threat is this?

Question11: Some security measures are optional. Other security measures must always be implemented.
Which measure(s) must always be implemented?

Question12: The consultants at Smith Consultants Inc. work on laptops that are protected by asymmetrical cryptography. To keep the management of the keys cheap, all consultants use the same key pair.
What is the company's risk if they operate in this manner?

Question13: Your company is concerned about the effect of global warming on sea levels and asks you to make preparations that prevents downtime of the billing process.
What will you create?

Question14: Logging in to a computer system is an access-granting process consisting of three steps: identification, authentication and authorization. What occurs during the first step of this process: identification?

Question15: What is the best way to comply with legislation and regulations for personal data protection?

Question16: In the organization where you work, information of a very sensitive nature is processed.
Management is legally obliged to implement the highest-level security measures. What is this kind of risk strategy called?

Question17: The company Midwest Insurance has taken many measures to protect its information. It uses an Information Security Management System, the input and output of data in applications is validated, confidential documents are sent in encrypted form and staff use tokens to access information systems.
Which of these is not a technical measure?

Question18: What are the two main types of damage, resulting from incidents?

Question19: There are three types of "human threats".
The threat that a user accidentally deletes a document belongs to which category?

Question20: The act of taking organizational security measures is inextricably linked with all other measures that have to be taken. What is the name of the system that guarantees the coherence of information security in the organization?

Question21: You are the owner of the courier company SpeeDelivery. On the basis of your risk analysis you have decided to take a number of measures. You have daily backups made of the server, keep the server room locked and install an intrusion alarm system and a sprinkler system. Which of these measures is a detective measure?

Question22: What physical security measure is necessary to control access to company information?

Question23: You have an office that designs corporate logos. You have been working on a draft for a large client. Just as you are going to press the <save> button, the screen goes blank. The hard disk is damaged and cannot be repaired. You find an early version of the design in your mail folder and you reproduce the draft for the customer. What is such a measure called?

Question24: Which legislation makes it easier to deal with offences perpetrated through advanced information technology?

Question25: We can acquire and supply information in various ways. The value of the information depends on whether it is reliable. What are the reliability aspects of information?

Question26: Susan sends an email to Paul. Who determines the meaning and the value of information in this email?

Question27: Two friends want to exchange a confidential document by e-mail. They decide to use cryptography to protect the confidentiality of the document. To be able to encrypt alid decrypt the document they first exchange the key that is both used for encryption and decryption by phone.
What type of encryption system is used by the two friends?

Question28: Who is authorized to change the classification of a document?

Question29: An employee in the administrative department of Smiths Consultants Inc. finds out that the expiry date of a contract with one of the clients is earlier than the start date. What type of measure could prevent this error?

Question30: Which type of malware is a program which, in addition to the function that it appears to perform, purposely conducts secondary activities?

Question31: To which category of security measures does a smoke alarm belong?

Question32: There is a network printer in the hallway of the company where you work. Many employees don't pick up their printouts immediately and leave them in the printer. What are the consequences of this to the reliability of the information?

Question33: What is not a criteria in the review process where it is determined whether segregation of duties is applicable for an employee?

Question34: What is the purpose of authentication?

Question35: You read in the newspapers that the ex-employee of a large company systematically deleted files out of revenge on his manager. Recovering these files caused great losses in time and money.
What is this kind of threat called?

Question36: Someone sends an e-mail. The sender wants the recipient to be able to verify who wrote and sent the email.
What does the sender attach to the email?

Question37: You are the owner of the SpeeDelivery courier service. Last year you had a firewall installed. You now discover that no maintenance has been performed since the installation. What is the biggest risk because of this?

Question38: After a thorough risk analysis and the identification of appropriate security controls, the management team decides that for one specific threat the impact should be covered by insurance.
Which kind of risk treatment control is described here?

Question39: What is the objective of classifying information?

Question40: Which approach does/did the United States take with regard to privacy legislation?

Question41: Which one of the threats listed below can occur as a result of the absence of a physical measure?

Question42: You own a small company in a remote industrial area. Lately, the alarm regularly goes off in the middle of the night. It takes quite a bit of time to respond to it and it seems to be a false alarm every time. You decide to set up a hidden camera. What is such a measure called?

Question43: What is the relationship between data and information?

Question44: An employee detects abnormal behavior of her desktop computer.
After reporting to the system administrator and a first investigation, the system administrators decide to get some help from the Computer emergency response Team (CERT).
Which type of escalation is described above?

Question45: Which regulation is only applicable for United States public companies (e.g. listed on the New York Stock Exchange)?

Question46: An Incident Management process has several purposes.
Which is not a purpose of the Incident Management process?

Question47: A Dutch company requests to be listed on the American Stock Exchange. Which legislation within the scope of information security is relevant in this case?

Question48: You apply for a position in another company and get the job. Along with your contract, you are asked to sign a code of conduct. What is a code of conduct?

Question49: You work for a large organization. You notice that you have access to confidential information that you should not be able to access in your position. You report this security incident to the helpdesk. The incident cycle is initiated. What are the stages of the security incident cycle?

Question50: What do employees need to know to report a security incident?

Question51: Why is compliance important for the reliability of the information?

Question52: A hacker gains access to a webserver and deletes a file on the server containing credit card numbers.
Which of the Confidentiality, Integrity, Availability (CIA) principles of the credit card file are violated?

Question53: Which measure assures that valuable information is not left out available for the taking?

Question54: Your organization has an office with space for twenty five (25) workstations. These workstations are all fully equipped and in use. Due to a reorganization ten (10) extra workstations are added, five (5) of which are used for a call center 24 hours per day. Five (5) workstations must always be available.
What physical security measures must be taken in order to ensure this?

Question55: You are the owner of a growing company, SpeeDelivery, which provides courier services. You decide that it is time to draw up a risk analysis for your information system. This includes an inventory of the threats and risks. What is the relation between a threat, risk and risk analysis?

Question56: Peter works at the company Midwest Insurance. His manager, Linda, asks him to send the terms and conditions for a life insurance policy to Rachel, a client. Who determines the value of the information in the insurance terms and conditions document?

Question57: What is the definition of the Annual Loss Expectancy?

Question58: You own a store, and money keeps disappearing from the cash register. You want to put an end to this by means of a detective measure.
What is an example of a detective measure?

Question59: Two friends want to exchange a confidential document. It is important that eavesdroppers cannot see this information. Furthermore the receiver should be able to validate the sender and that the information is not altered during transport. Both friends have a public/private key combination.
Which key is used, prior to transmission, to ensure the authenticity of the document?

Question60: Which legislation regulates the storage and destruction of archive documents?

Question61: Your organization has an office with space for 25 workstations. These workstations are all fully equipped and in use. Due to a reorganization 10 extra workstations are added, 5 of which are used for a call centre
24 hours per day. Five workstations must always be available. What physical security measures must be taken in order to ensure this?

Question62: A Dutch company is processing information from Dutch civilians; this implies applicability of some Dutch regulations regarding the privacy of these civilians. The company is mandated to implement security measures.
Which measure helps the company best in proving compliance with applicable regulations?

Question63: Midwest Insurance controls access to its offices with a passkey system. We call this a preventive measure.
What are some other measures?

Question64: A company moves into a new building. A few weeks after the move, a visitor appears unannounced in the office of the director. An investigation shows that visitors passes grant the same access as the passes of the companys staff. Which kind of security measure could have prevented this?

Question65: My user profile specifies which network drives I can read and write to. What is the name of the type of logical access management wherein my access and rights are determined centrally?

Question66: Some threats are caused directly by people, others have a natural cause. What is an example of an intentional human threat?

Question67: What is the physical equivalent of the logical information security measure Intrusion Detection System (IDS)?

Question68: There are three types of human threats: Intentional human threats, Unintentional human threats and a third human threat.
What is the third type of human threat?

Question69: In most organizations, access to the computer or the network is granted only after the user has entered a correct username and password. This process consists of 3 steps: identification, authentication and authorization. What is the purpose of the second step, authentication?

Question70: You have a small office in an industrial areA. You would like to analyze the risks your company faces. The office is in a pretty remote location; therefore, the possibility of arson is not entirely out of the question.
What is the relationship between the threat of fire and the risk of fire?

Question71: What is a risk analysis used for?

Question72: What is an example of a security incident?

Question73: What action is an unintentional human threat?

Question74: When we are at our desk, we want the information system and the necessary information to be available.
We want to be able to work with the computer and access the network and our files.
What is the correct definition of availability?

Question75: What is 'a potential cause of an unwanted incident, which may result in harm to a system or organization' called?

Question76: Why is sensitive information graded?

Question77: You work for a flexible employer who doesn't mind if you work from home or on the road. You regularly take copies of documents with you on a USB memory stick that is not secure. What are the consequences for the reliability of the information if you leave your USB memory stick behind on the train?

Question78: A well executed risk analysis provides a great deal of useful information. A risk analysis has four main objectives. What is not one of the four main objectives of a risk analysis?

Question79: What is the most common risk strategy besides Risk bearing and Risk neutral?

Question80: The incident cycle has four stages. Which stage follows the Threat stage?

Question81: Of which concept is 'measures taken to safeguard an information system from attacks' the definition?

Question82: Under which condition is an employer permitted to check if Internet and email services in the workplace are being used for private purposes?

Question83: You have just started working at a large organization. You have been asked to sign a code of conduct as well as a contract. What does the organization wish to achieve with this?

Question84: What is a repressive measure in the case of a fire?

Question85: A marketing employee accidentally e-mails a spreadsheet with all the company¡¯s clients, their personal and commercial data, to the wrong email address.
Who determines the value of the information in the spreadsheet?

Question86: The term 'big data' is commonly used. However data itself has less (or no) value for an organization.
Which process adds value to the data and turns data into 'information'?

Question87: At Midwest Insurance, all information is classified. What is the goal of this classification of information?

Question88: Lightning strikes the data center and the power surge destroys several servers. What type of threat is this?

Question89: What is a human threat to the reliability of the information on your company website?

Question90: You work for a large organization. You notice that you have access to confidential information that you should not be able to access in your position. You report this security incident to the helpdesk. The incident cycle is initiated.
Which stage of the incident cycle follows the incident stage?

Question91: What is the best description of a risk analysis?

Question92: Why is air-conditioning placed in the server room?

Question93: Three characteristics determine the reliability of information. Which characteristics are these?

Question94: What is the most important reason for applying segregation of duties?

Question95: Which threat can materialize as a result of the absence of physical security?

Question96: What is an example of a good physical security measure?

Question97: Which type of malware builds a network of contaminated computers?

Question98: Physical security must protect a company for anyone to easily access the company assets. This is illustrated by thinking in terms of series of protection rings.
Which protection ring deals with the asset that is to be protected?

Question99: What is not a category for security measures?

Question100: What is the greatest risk for an organization if no information security policy has been defined?

Question101: You are a consultant and are regularly hired by the Ministry of Defense to perform analyses.
Since the assignments are irregular, you outsource the administration of your business to temporary workers. You don't want the temporary workers to have access to your reports. Which reliability aspect of the information in your reports must you protect?

Question102: An airline company employee notices that she has access to one of the company's applications that she has not used before. Is this an information security incident?

Question103: Midwest Insurance grades the monthly report of all claimed losses per insured as confidential.
What is accomplished if all other reports from this insurance office are also assigned the appropriate grading?

Question104: You work in the IT department of a medium-sized company. Confidential information has got into the wrong hands several times. This has hurt the image of the company. You have been asked to propose organizational security measures for laptops at your company. What is the first step that you should take?

Question105: What is the relationship between data and information?

Question106: What sort of security does a Public Key Infrastructure (PKI) offer?

Question107: You are the owner of the courier company SpeeDelivery. You have carried out a risk analysis and now want to determine your risk strategy. You decide to take measures for the large risks but not for the small risks. What is this risk strategy called?

Question108: The Information Security Manager (ISM) at Smith Consultants Inc. introduces the following measures to assure information security:
- The security requirements for the network are specified.
- A test environment is set up for the purpose of testing reports coming from the database.
- The various employee functions are assigned corresponding access rights.
- RFID access passes are introduced for the building.
Which one of these measures is not a technical measure?

Question109: You are the owner of SpeeDelivery courier service. Because of your companys growth you have to think about information security. You know that you have to start creating a policy. Why is it so important to have an information security policy as a starting point?

Question110: A couple of years ago you started your company which has now grown from 1 to 20 employees.
Your company's information is worth more and more and gone are the days when you could keep it all in hand yourself. You are aware that you have to take measures, but what should they be?
You hire a consultant who advises you to start with a qualitative risk analysis. What is a qualitative risk analysis?

Question111: Which type of malware is a program that collects information of the computer user and sends it to another party?

Question112: During a risk analysis a system administrator mentions that due to the lack of communication between Human recourses management (HRM) and system administrators, employees can still access the company server from home even if they are no longer employed by the company.
Which characteristic of a risk is missing here?

Question113: Which is a legislative or regulatory act related to information security that can be imposed upon all organizations?