solution New 2025/2026
In a corporate office, employees are required to use their access cards to enter different sections
Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il`
of the building. What type of control is being implemented in this scenario?
Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il`
Detective control Il`
Preventive control Il`
Physical control Il`
Corrective control Il`
Physical control Il`
- The use of access cards to enter different sections of the building is an example of physical
Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il`
control, as it restricts and controls physical access to specific areas.
Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il`
Detective controls Il`
Help to identify and respond to security incidents after they have occurred.
Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il`
- ex. security cameras
Il` Il` Il`
Preventive controls Il`
Aim to stop security incidents before they occur.
Il` Il` Il` Il` Il` Il` Il`
Corrective controls Il`
Implemented in response to identified security incidents. Il` Il` Il` Il` Il` Il`
A financial institution implements encryption for all sensitive data transmitted between its
Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il`
branches to ensure confidentiality. What type of control is being applied here?
Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il`
Technical control Il`
Administrative control Il`
Physical control Il`
Operational control Il`
Technical control Il`
- Encryption is a technical control that involves the use of technology to protect sensitive data
Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il`
during transmission, ensuring its confidentiality.
Il` Il` Il` Il` Il`
Administrative controls Il`
involve policies, procedures, and training to shape behavior. Il` Il` Il` Il` Il` Il` Il`
,Physical controls Il`
Restrict access to physical areas and assets.
Il` Il` Il` Il` Il` Il`
Operational control Il`
Focus on day-to-day processes and procedures to ensure the security of information systems.
Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il`
A company encrypts sensitive customer data to prevent unauthorized access. What security
Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il`
principle does this primarily address?
Il` Il` Il` Il` Il`
Confidentiality
Integrity
Availability
Accountability
Confidentiality
- Encrypting sensitive customer data helps maintain confidentiality by protecting it from
Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il`
unauthorized access.
Il` Il`
Integrity
Ensures that data remains accurate and unaltered.
Il` Il` Il` Il` Il` Il`
Availability
Focuses on ensuring that resources are accessible when needed.
Il` Il` Il` Il` Il` Il` Il` Il`
Accountability
Is about tracking actions and identifying responsible parties.
Il` Il` Il` Il` Il` Il` Il`
AD
A system administrator implements regular backups to ensure that critical data can be restored in
Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il`
the event of a hardware failure. Which security principle does this align with?
Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il`
Confidentiality
Integrity
Availability
Non-repudiation
Availability
- Regular backups contribute to the ability of critical data by ensuring it can be stores in case of a
Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il`
hardware failure or data loss.
Il` Il` Il` Il` Il`
,Confidentiality
Is about preventing unauthorized access to sensitive information.
Il` Il` Il` Il` Il` Il` Il`
Non-repudiation
Focuses on ensuring that a party cannot deny its actions.
Il` Il` Il` Il` Il` Il` Il` Il` Il`
A security mechanism is implemented to verify that data remains unchanged during transmission
Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il`
over a network. Which security principle is being emphasized?
Il` Il` Il` Il` Il` Il` Il` Il` Il`
Confidentiality
Integrity
Availability
Authentication
Integrity
- Verifying data integrity ensures that it remains unchanged during transmission, guarding against
Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il`
unauthorized alterations.
Il` Il`
In a network environment, what AAA component is responsible for tracking the activities of users
Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il`
and monitoring resource usage?
Il` Il` Il` Il`
Authentication
Authorization
Accounting
Auditing
Accounting
- Involves tracking user activities and resource usage for the purpose of billing, auditing, and
Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il`
security monitoring.
Il` Il`
Auditing
Involves the analysis of logs and records to ensure compliance and detect security incidents.
Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il`
Authorization
Determines the user's access rights and permissions after successful authentication.
Il` Il` Il` Il` Il` Il` Il` Il` Il`
Authentication
Involves verifying the identity of a user. Il` Il` Il` Il` Il` Il`
, In a multi-factor authentication system, which of the following is an example of something you
Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il`
know?
Il`
Fingerprint scan Il`
One-time password Il`
Smart card Il`
Retina scan Il`
One-time password Il`
- Something you know refers to knowledge-based factors, such as a password or PIN, and a one-
Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il`
time password is an example of this. Il` Il` Il` Il` Il` Il`
Something you are Il` Il`
A biometric factor
Il` Il`
- ex. fingerprint scan, retina scan
Il` Il` Il` Il` Il`
AD
Something you have Il` Il`
A possession-based factor
Il` Il`
- ex. smart card
Il` Il` Il`
What is a common outcome of a gap analysis process in the context of cybersecurity?
Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il`
A) Development of a risk management plan
Il` Il` Il` Il` Il` Il`
B) Implementation of compensating controls
Il` Il` Il` Il`
C) Creation of a security policy
Il` Il` Il` Il` Il`
D) Establishment of a remediation plan
Il` Il` Il` Il` Il`
Establishment of a remediation plan Il` Il` Il` Il`
- A common outcome of gap analysis is the identification of security gaps and the development of
Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il`
a remediation plan to address these gaps.
Il` Il` Il` Il` Il` Il` Il`
Incorrect Answers Explanation: Il` Il`
A) While gap analysis contributes to risk assessment, developing a risk management plan is a
Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il`
broader process.
Il` Il`
B) Compensating controls may be part of the remediation plan but are not the primary outcome
Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il`
of a gap analysis.
Il` Il` Il` Il`
C) A security policy may be reviewed during gap analysis, but creating one is not a direct outcome.
Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il` Il`