PRACTICE PRACTICE SCRIPT 2026
QUESTIONS WITH SOLUTIONS GRADED A+
⩥ What is PII? Answer: Personally Identifiable Information (PII)
Any data about an individual that could be used to identify them.
⩥ What is Protected health Information (PHI)? Answer: Information
regarding the health status, the provision of healthcare or payment for
healthcare (As defined in the health Insurance Portability Act).
⩥ What is the definition of Classified or Sensitive Information? Answer:
Information that requires protection against unauthorised disclosure and
is marked to indicate classification level.
⩥ What is the definition of a breach? Answer: A data breach is a security
violation, in which sensitive, protected or confidential data is copied,
transmitted, viewed, stolen, altered or used by an individual
unauthorized to do so.
⩥ What is an Incident? Answer: An event that actually or potentially
jeopardizes the confidentiality, integrity or availability of an information
system.
,⩥ What is an Intrusion? Answer: A security event, or combination of
events, that constitutes a deliberate security incident in which an intruder
gains, or attempts to gain, access to a system
⩥ What is a threat? Answer: Any circumstance or event with the
potential to adversely impact organizational operations (including
mission, functions, image or reputation)
⩥ What is vulnerability? Answer: Weakness in an information system,
system security procedures, internal controls or implementation that
could be exploited by a threat source.
⩥ What is a zero Day? Answer: A previously unknown system
vulnerability with the potential of exploitation without risk of detection
or prevention because it does not, in general, fit recognized patterns,
signatures or methods.
⩥ What are the components commonly found in an Incident response
plan? Answer: ● Preparation
● Detection and Analysis
● Containment, Eradication and Recovery
● Post-Incident Activity
⩥ What is the ISC² definition of Authorization? Answer: The right or a
permission that is granted to a system entity to access a system resource.
, ⩥ What is the ISC² definition of Authentication? Answer: The control
process that compares one or more factors of identification to validate
that the identity claimed by a user or entity is known to the system.
⩥ What is the ISC² definition of Integrity? Answer: The property that
data has not been altered in an unauthorised manner.
⩥ What is the ISC² definition of Confidentiality? Answer: The
characteristic of data or information when it is not made available or
disclosed to unauthorised persons or processes.
⩥ What is the ISC² definition of Privacy? Answer: The right of an
individual to control the distribution of information about themselves.
⩥ What is the ISC² definition of Availability? Answer: Ensuring timely
and reliable access to and use of information by authorised users.
⩥ What is the ISC² definition of non-repudiation? Answer: The inability
to deny taking an action, such as sending an email.
⩥ What is the ISC² definition of Mitigation? Answer: Taking action to
prevent or reduce the impact of an event.