Security
Chapter 1 Assessment Study Guide
2026/2027 | Cybersecurity Fundamentals
| Practice Questions and Answers
Description: This comprehensive study guide contains 200 multiple-choice questions
(MCQs) covering Chapter 1 of Fundamentals of Information Systems Security. Topics
include the CIA Triad, security frameworks, risk management, threat actors, attack types,
cryptography basics, access control, and security policies.
Keywords: Information Systems Security, CIA Triad, Risk Management, Threats,
Vulnerabilities, Access Control, Cryptography, Security Policies, Compliance, Incident
Response.
1. What does the CIA Triad stand for in information security?
A) Confidentiality, Integrity, Availability ✅
B) Control, Intelligence, Authentication
C) Confidentiality, Identity, Authorization
D) Compliance, Integrity, Auditing
2. Which principle ensures data is not disclosed to unauthorized individuals?
A) Integrity
B) Confidentiality ✅
C) Availability
D) Non-repudiation
,3. Which principle ensures data remains accurate and unaltered?
A) Confidentiality
B) Availability
C) Integrity ✅
D) Authentication
4. Which principle ensures authorized users can access resources when needed?
A) Confidentiality
B) Integrity
C) Availability ✅
D) Privacy
5. What is a vulnerability?
A) A weakness that can be exploited ✅
B) A potential cause of harm
C) An implemented control
D) A security policy
6. What is a threat?
A) A weakness in a system
B) Any potential danger to an asset ✅
C) A security control
D) A compliance requirement
7. What is risk in information security?
A) The likelihood and impact of a threat exploiting a vulnerability ✅
B) The cost of security tools
C) The number of users in a system
D) The speed of data transmission
8. What is the primary goal of information security?
A) To eliminate all risks
B) To protect information assets ✅
,C) To increase network speed
D) To reduce hardware costs
9. Which of the following is a physical control?
A) Encryption
B) Firewall
C) Locked doors ✅
D) Password policy
10. Which of the following is a technical control?
A) Security guards
B) Encryption ✅
C) Background checks
D) Security awareness training
11. Which of the following is an administrative control?
A) Firewalls
B) Security policies ✅
C) Biometric locks
D) Intrusion detection systems
12. What is the purpose of a security policy?
A) To define rules and guidelines for protecting assets ✅
B) To increase network bandwidth
C) To replace technical controls
D) To eliminate the need for training
13. What is risk management?
A) The process of identifying, assessing, and mitigating risks ✅
B) The process of installing antivirus software
C) The process of hiring security guards
D) The process of encrypting all data
, 14. What is risk avoidance?
A) Accepting the risk
B) Eliminating the activity that causes the risk ✅
C) Transferring the risk to a third party
D) Reducing the risk through controls
15. What is risk transfer?
A) Accepting the risk
B) Eliminating the risk
C) Shifting the risk to another party (e.g., insurance) ✅
D) Ignoring the risk
16. What is risk acceptance?
A) Acknowledging the risk and taking no action ✅
B) Eliminating the risk
C) Transferring the risk
D) Mitigating the risk
17. What is risk mitigation?
A) Accepting the risk
B) Reducing the risk through controls ✅
C) Transferring the risk
D) Avoiding the risk
18. What is a threat actor?
A) A security control
B) An individual or group that poses a threat ✅
C) A vulnerability
D) A policy
19. Which type of threat actor is motivated by financial gain?
A) Hacktivist
B) Cybercriminal ✅