CS – D430 ITAS 2110 Fundamentals of
Information Security
Comprehensive Objective Assessment (Qns &
Ans)
2025
Multiple Choice
1.
Which of the following best describes the concept of the "least
privilege" principle in access control?
A) Granting users unlimited access
B) Granting users only the access required to perform their duties
C) Allowing users to share access credentials
D) Privileging superusers over regular users
©2025
,ANS: B
Rationale: The least privilege principle restricts access rights to
the minimum necessary for users to perform their functions.
2.
Which security control is specifically designed to detect
unauthorized access attempts?
A) Firewall
B) Intrusion Detection System (IDS)
C) RAID Array
D) Virtual Private Network (VPN)
ANS: B
Rationale: IDS tools monitor and alert on suspicious activity,
detecting unauthorized access attempts.
3.
In Public Key Infrastructure (PKI), what is the primary
responsibility of the Certificate Authority (CA)?
A) Encrypting data in transit
B) Issuing and managing digital certificates
C) Managing firewall rules
©2025
,D) Implementing physical security
ANS: B
Rationale: The CA is responsible for issuing, renewing, and
revoking digital certificates.
4.
Which form of attack specifically targets users by tricking them
into providing sensitive information via deceptive
communications?
A) Backdoor attack
B) DDoS attack
C) Phishing attack
D) Brute-force attack
ANS: C
Rationale: Phishing attacks deceive users through fraudulent
messages to steal sensitive data.
5.
What mechanism ensures non-repudiation in digital
communications?
©2025
, A) Encryption only
B) Firewalls
C) Digital signatures
D) Salted hashes
ANS: C
Rationale: Digital signatures provide proof of origin and integrity,
ensuring non-repudiation.
6.
Which model describes mandatory access control based on
classification labels for users and data?
A) Discretionary Access Control (DAC)
B) Role-Based Access Control (RBAC)
C) Attribute-Based Access Control (ABAC)
D) Bell-LaPadula Model
ANS: D
Rationale: The Bell-LaPadula model enforces mandatory access
control using classification levels.
©2025
Information Security
Comprehensive Objective Assessment (Qns &
Ans)
2025
Multiple Choice
1.
Which of the following best describes the concept of the "least
privilege" principle in access control?
A) Granting users unlimited access
B) Granting users only the access required to perform their duties
C) Allowing users to share access credentials
D) Privileging superusers over regular users
©2025
,ANS: B
Rationale: The least privilege principle restricts access rights to
the minimum necessary for users to perform their functions.
2.
Which security control is specifically designed to detect
unauthorized access attempts?
A) Firewall
B) Intrusion Detection System (IDS)
C) RAID Array
D) Virtual Private Network (VPN)
ANS: B
Rationale: IDS tools monitor and alert on suspicious activity,
detecting unauthorized access attempts.
3.
In Public Key Infrastructure (PKI), what is the primary
responsibility of the Certificate Authority (CA)?
A) Encrypting data in transit
B) Issuing and managing digital certificates
C) Managing firewall rules
©2025
,D) Implementing physical security
ANS: B
Rationale: The CA is responsible for issuing, renewing, and
revoking digital certificates.
4.
Which form of attack specifically targets users by tricking them
into providing sensitive information via deceptive
communications?
A) Backdoor attack
B) DDoS attack
C) Phishing attack
D) Brute-force attack
ANS: C
Rationale: Phishing attacks deceive users through fraudulent
messages to steal sensitive data.
5.
What mechanism ensures non-repudiation in digital
communications?
©2025
, A) Encryption only
B) Firewalls
C) Digital signatures
D) Salted hashes
ANS: C
Rationale: Digital signatures provide proof of origin and integrity,
ensuring non-repudiation.
6.
Which model describes mandatory access control based on
classification labels for users and data?
A) Discretionary Access Control (DAC)
B) Role-Based Access Control (RBAC)
C) Attribute-Based Access Control (ABAC)
D) Bell-LaPadula Model
ANS: D
Rationale: The Bell-LaPadula model enforces mandatory access
control using classification levels.
©2025