EMT Practice Test

1. Question Content...


Question List

Question1: What is an example of a human threat?

Question2: How are data and information related?

Question3: Access Control System, CCTV and security guards are form of:

Question4: Who is responsible for Initial asset allocation to the user/custodian of the assets?

Question5: Which of the following is a preventive security measure?

Question6: Please match the roles to the following descriptions:

Question7: In regard to generating an audit finding, select the words that best complete the following sentence.
To complete the sentence with the best word(s), click on the blank section you want to complete so that it Is highlighted in red, and then click on the applicable text from the options below. Alternatively, you may drag and drop the option to the appropriate blank section.

Question8: There is a scheduled fire drill in your facility. What should you do?

Question9: Which of the following does a lack of adequate security controls represent?

Question10: What is the standard definition of ISMS?

Question11: Below is Purpose of "Integrity", which is one of the Basic Components of Information Security

Question12: Which of the following is not a type of Information Security attack?

Question13: Four types of Data Classification (Choose two)

Question14: Who are allowed to access highly confidential files?

Question15: Integrity of data means

Question16: In which order is an Information Security Management System set up?

Question17: Cabling Security is associated with Power, telecommunication and network cabling carrying information are protected from interception and damage.

Question18: You are an experienced ISMS audit team leader, talking to an Auditor in training who has been assigned to your audit team. You want to ensure that they understand the importance of the Check stage of the Plan-Do-Check-Act cycle in respect of the operation of the information security management system.
You do this by asking him to select the words that best complete the sentence:
To complete the sentence with the best word(s), click on the blank section you want to complete so that it is highlighted in red, and then click on the applicable text from the options below. Alternatively, you may drag and drop the option to the appropriate blank section.

Question19: Who is authorized to change the classification of a document?

Question20: A member of staff denies sending a particular message.
Which reliability aspect of information is in danger here?

Question21: What would be the reference for you to know who should have access to data/document?

Question22: Which two of the following statements are true?

Question23: What is the difference between a restricted and confidential document?

Question24: An employee caught with offense of abusing the internet, such as P2P file sharing or video/audio streaming, will not receive a warning for committing such act but will directly receive an IR.

Question25: Which two of the following are examples of audit methods that 'do' involve human interaction?

Question26: What type of measure involves the stopping of possible consequences of security incidents?

Question27: An administration office is going to determine the dangers to which it is exposed.
What do we call a possible event that can have a disruptive effect on the reliability of information?

Question28: Which of the following is a possible event that can have a disruptive effect on the reliability of information?

Question29: Which department maintain's contacts with law enforcement authorities, regulatory bodies, information service providers and telecommunications service providers depending on the service required.

Question30: A couple of years ago you started your company which has now grown from 1 to 20 employees. Your company's information is worth more and more and gone are the days when you could keep control yourself. You are aware that you have to take measures, but what should they be? You hire a consultant who advises you to start with a qualitative risk analysis.
What is a qualitative risk analysis?

Question31: The following are purposes of Information Security, except:

Question32: What controls can you do to protect sensitive data in your computer when you go out for lunch?

Question33: What is a definition of compliance?

Question34: CEO sends a mail giving his views on the status of the company and the company's future strategy and the CEO's vision and the employee's part in it. The mail should be classified as

Question35: The computer room is protected by a pass reader. Only the System Management department has a pass.
What type of security measure is this?

Question36: A hacker gains access to a web server and reads the credit card numbers stored on that server. Which security principle is violated?

Question37: A decent visitor is roaming around without visitor's ID. As an employee you should do the following, except:

Question38: You are an experienced ISMS audit team leader providing instruction to an auditor in training. They are unclear in their understanding of risk processes and ask you to provide them with an example of each of the processes detailed below.
Match each of the descriptions provided to one of the following risk management processes.
To complete the table click on the blank section you want to complete so that it is highlighted in red, and then click on the applicable text from the options below. Alternatively, you may drag and drop each option to the appropriate blank section.

Question39: What is social engineering?

Question40: Often, people do not pick up their prints from a shared printer. How can this affect the confidentiality of information?

Question41: An employee caught with offense of abusing the internet, such as P2P file sharing or video/audio streaming, will not receive a warning for committing such act but will directly receive an IR.

Question42: What type of legislation requires a proper controlled purchase process?

Question43: __________ is a software used or created by hackers to disrupt computer operation, gather sensitive information, or gain access to private computer systems.

Question44: Select the words that best complete the sentence:
To complete the sentence with the word(s) click on the blank section you want to complete so that it is highlighted in red, and then click on the application text from the options below. Alternatively, you may drag and drop the option to the appropriate blank section.

Question45: You work in the office of a large company. You receive a call from a person claiming to be from the Helpdesk. He asks you for your password.
What kind of threat is this?

Question46: Select a word from the following options that best completes the sentence:
To complete the sentence with the word(s) click on the blank section you want to complete so that it is highlighted in red, and then click on the application text from the options below. Alternatively, you may drag and drop the option to the appropriate blank section.

Question47: What type of system ensures a coherent Information Security organisation?

Question48: After completing Stage 1 and in preparation for a Stage 2 initial certification audit, the auditee informs the audit team leader that they wish to extend the audit scope to include two additional sites that have recently been acquired by the organisation.
Considering this information, what action would you expect the audit team leader to take?

Question49: You see a blue color sticker on certain physical assets. What does this signify?

Question50: What is the worst possible action that an employee may receive for sharing his or her password or access with others?

Question51: In what part of the process to grant access to a system does the user present a token?

Question52: A scenario wherein the city or location where the building(s) reside is / are not accessible.

Question53: What is the security management term for establishing whether someone's identity is correct?