Security Final Prep Exam (Latest Update
2026/2027) Questions and Verified
Answers | 100% Correct | Grade A.
1. Which of the following best describes the primary goal of
information security?
A. Eliminate all technology risks
B. Increase internet speed
C. Protect the confidentiality, integrity, and availability of information
D. Prevent employees from accessing company systems
Rationale: The primary objective of information security is preserving
the Confidentiality, Integrity, and Availability (CIA) triad. Confidentiality
prevents unauthorized disclosure, integrity ensures information remains
accurate and unaltered, and availability ensures authorized users can
access information when needed. Organizations build security programs
around these three foundational principles.
2. Which component of the CIA triad ensures data is accessible when
authorized users need it?
A. Confidentiality
B. Authentication
,C. Availability
D. Nonrepudiation
Rationale: Availability focuses on ensuring systems, applications, and
data remain operational and accessible despite failures, cyberattacks, or
disasters. Techniques such as redundancy, backups, load balancing, and
disaster recovery planning improve availability.
3. Which security principle prevents unauthorized disclosure of
sensitive information?
A. Confidentiality
B. Availability
C. Accountability
D. Redundancy
Rationale: Confidentiality limits information access to authorized
individuals. Encryption, access controls, data classification, and
authentication mechanisms all contribute to maintaining confidentiality.
4. Which document defines management's expectations regarding
acceptable security behavior?
A. Standard
B. Guideline
C. Security policy
D. Procedure
Rationale: A security policy establishes management's high-level
expectations and direction regarding security. Standards provide
,mandatory technical requirements, procedures explain implementation
steps, and guidelines offer recommended practices.
5. Which risk management activity occurs first?
A. Risk treatment
B. Risk identification
C. Risk monitoring
D. Risk acceptance
Rationale: Organizations must first identify assets, threats,
vulnerabilities, and risks before they can analyze or treat them. Without
identification, meaningful risk management cannot occur.
6. What is a vulnerability?
A. Someone attempting to exploit a weakness
B. The financial impact of a breach
C. A weakness that could be exploited
D. A security policy violation
Rationale: A vulnerability is any weakness in hardware, software,
procedures, or personnel that could allow a threat to compromise a
system. Vulnerabilities become dangerous when paired with active
threats.
7. Which of the following is an example of a threat?
, A. Weak password policy
B. Ransomware attack
C. Missing software patch
D. Misconfigured firewall
Rationale: A threat is any circumstance capable of exploiting a
vulnerability. Ransomware represents an active threat, while weak
passwords and missing patches are vulnerabilities.
8. Which risk treatment option involves implementing controls to
reduce the likelihood or impact of a risk?
A. Avoidance
B. Acceptance
C. Mitigation
D. Transfer
Rationale: Risk mitigation reduces either the probability or
consequences of a risk through administrative, technical, or physical
controls. Examples include implementing firewalls, security awareness
training, and multifactor authentication.
9. Which risk treatment strategy involves purchasing cyber
insurance?
A. Acceptance
B. Transfer
C. Avoidance
D. Mitigation