Exam 2026 | Trusted Questions & Answers
1. List the five factors of authentication as described in information security.
Something You Know, Something You Do, Something You Own,
Something You Are, and Somewhere You Are.
Something You Know, Something You Use, Something You Have,
Something You Are, and Somewhere You Are.
Something You Know, Something You Do, Something You Have,
Something You Are, and Somewhere You Are.
Something You Know, Something You Trust, Something You Have,
Something You Are, and Somewhere You Go.
2. In a scenario where a company experiences a data breach despite having
security measures in place, which aspect of layered security controls could
be evaluated for improvement?
The effectiveness of the multiple security layers in detecting and
responding to the breach.
The company's employee training programs on security awareness.
The cost of implementing security measures.
The speed of the internet connection used by the company.
3. What is the purpose of antivirus software?
Prevent unauthorized access to sensitive data
Monitor credit reports for suspicious activity
Remove viruses and malware from a computer system
Encrypt files on a computer system
,4. Describe the significance of geo-location authentication in enhancing
security measures.
'Where You Are' is irrelevant to security and focuses solely on user
identity.
'Where You Are' enhances security by ensuring that actions, such as
changing a PIN, can only be performed in specific physical
locations.
'Where You Are' is a type of biometric authentication.
'Where You Are' is a method for creating strong passwords.
5. What is unauthorized access?
Activity to access data and cyber systems without permission
Getting into systems with permission
Stealing keys
Getting into computer systems to access sensitive data
6. Describe how administrative controls contribute to an organization's
information security framework.
Administrative controls focus solely on technical measures to protect
data.
Administrative controls are not necessary for small organizations.
Administrative controls are only relevant for physical security
measures.
Administrative controls establish policies and procedures that guide
security practices within the organization.
,7. Describe the significance of possession/control in ensuring data security.
Possession/control is about the network security measures in place.
Possession/control refers to the software used to encrypt data.
Possession/control is crucial as it ensures that only authorized
individuals have physical access to the data storage media.
Possession/control is irrelevant to data security.
8. Describe the implications of unauthorized access in information security.
Unauthorized access is a minor issue that does not affect data security.
Unauthorized access only affects the availability of information.
Unauthorized access ensures data integrity and enhances security.
Unauthorized access can lead to data breaches and compromise
the confidentiality and integrity of information.
9. Describe the role of firewalls in network perimeter security.
Firewalls provide physical security for network hardware.
Firewalls act as a barrier between trusted and untrusted networks,
controlling incoming and outgoing traffic based on predetermined
security rules.
Firewalls encrypt data to protect it from unauthorized access.
Firewalls are used to monitor user activity on the network.
10. What is Two-Factor Authentication?
Involves three distinct stages to confirm your identity.
Requires physical and digital proof to confirm your identity.
, Relies on a single piece of information to verify your identity.
Uses two different methods to verify your identity.
11. What is the primary purpose of security incident response procedures?
To document incidents for legal purposes
To prevent incidents from occurring
To respond to incidents in a way that minimizes loss and disruption
To train staff in security practices
12. What are the three key aspects of information systems that security attacks
aim to compromise?
Authentication, Authorization, Accounting
Confidentiality, Integrity, Availability
Prevention, Detection, Response
Data, Network, Application
13. What is the definition of availability in the CIA triad?
Availability refers to the protection of information from unauthorized
access.
Availability ensures that information and resources are accessible
to authorized users when needed.
Availability involves maintaining the accuracy and reliability of data.
Availability is the process of identifying and mitigating risks.
14. Describe the significance of each phase in the incident response cycle.
The phases are irrelevant as incidents can be handled in any order.