0% found this document useful (0 votes)
16 views18 pages

History of Information Security MCQs

The document consists of a series of multiple-choice questions covering various aspects of information security, including its history, key concepts, the C.I.A. triad, the CNSS security model, components of information systems, implementation approaches, software assurance principles, roles and responsibilities, and scenario-based questions. It aims to assess knowledge on the evolution of computer security, fundamental definitions, security models, and the roles of individuals in information security management. The questions are structured to test understanding of both theoretical concepts and practical applications in the field of information security.

Uploaded by

i221617
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
16 views18 pages

History of Information Security MCQs

The document consists of a series of multiple-choice questions covering various aspects of information security, including its history, key concepts, the C.I.A. triad, the CNSS security model, components of information systems, implementation approaches, software assurance principles, roles and responsibilities, and scenario-based questions. It aims to assess knowledge on the evolution of computer security, fundamental definitions, security models, and the roles of individuals in information security management. The questions are structured to test understanding of both theoretical concepts and practical applications in the field of information security.

Uploaded by

i221617
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Part 1: 100 Multiple Choice Questions (MCQs)

Section: History of Information Security

1. The concept of computer security is generally recognized to have begun with which
event?
A) The invention of the Internet
B) The creation of the first virus
C) The need to break German code (Enigma) during WWII
D) The release of Windows 95
2. Which report, published in 1970 (declassified in 1979), is considered the paper that
started the study of computer security?
A) The ARPANET Program Plan
B) RAND Report R-609
C) The NIST Handbook
D) The Pentagon Papers
3. In the early years of computing (Cold War era), security was primarily composed of:
A) Antivirus software and firewalls
B) Physical security and document classification
C) Biometric scanning and cloud encryption
D) Network intrusion detection
4. Who is credited with being the founder of the Internet (ARPANET)?
A) Robert Metcalfe
B) Dennis Ritchie
C) Dr. Larry Roberts
D) Ken Thompson
5. Which operating system was the first to integrate security into its core functions
using a time-sharing approach?
A) UNIX
B) MULTICS
C) DOS
D) Linux
6. In 1973, who identified fundamental problems with ARPANET security, such as the
lack of user identification?
A) Robert M. Metcalfe
B) Willis Ware
C) John McCumber
D) Charlie Moody
7. The "black hats" and "white hats" terminology became popular at which conference
first held in 1993?
A) BlackHat Briefings
B) RSA Conference
C) DEFCON
D) COMSEC
8. Which legislation was passed in the mid-1980s to define computer security
responsibilities?
A) The USA PATRIOT Act
B) The Computer Fraud and Abuse Act of 1986
C) The Sarbanes-Oxley Act
D) The Freedom of Information Act
9. Early UNIX implementations were:
A) Highly secure with complex passwords
B) Primarily for text processing and lacked strong security
C) Based on the McCumber Cube
D) Only available to the military
10. What major event in 2001 significantly changed legislation regarding computer
security and law enforcement?
A) The dot-com bubble burst
B) The release of Windows XP
C) The September 11 terrorist attacks
D) The Y2K bug

Section: Key Concepts & Definitions

1. Which term describes a potential weakness in an asset or its defensive control


system?
A) Threat
B) Vulnerability
C) Exploit
D) Risk
2. An intentional or unintentional act that can damage or compromise information is
called a(n):
A) Asset
B) Attack
C) Risk
D) Subject
3. A technique used to compromise a system (which can be a verb or a noun) is known
as a(n):
A) Exploit
B) Vulnerability
C) Object
D) Control
4. In the context of an attack, if a hacker uses a compromised computer to attack a third
system, the compromised computer is acting as the:
A) Object of the attack
B) Subject of the attack
C) Threat agent
D) Controller
5. Which term refers to the probability of an unwanted occurrence, such as an adverse
event or loss?
A) Threat
B) Vulnerability
C) Risk
D) Exposure
6. A specific instance or component of a threat (e.g., a specific hacker or a lightning
strike) is called a:
A) Threat Source
B) Threat Agent
C) Vulnerability
D) Countermeasure
7. What is the difference between a "Direct Attack" and an "Indirect Attack"?
A) Direct attacks are physical; indirect are digital.
B) Direct attacks originate from the threat itself; indirect originate from a compromised
system.
C) Direct attacks are accidental; indirect are intentional.
D) There is no difference.
8. A "Botnet" is an example of what type of attack structure?
A) Direct attack
B) Physical attack
C) Indirect attack
D) Passive attack
9. "Protection Profile" or "Security Posture" refers to:
A) The physical stance a guard takes.
B) The entire set of controls and safeguards implemented by an organization.
C) The antivirus software version.
D) The legal documents signed by employees.
10. When a vulnerability is known to an attacker, a condition of ___ exists.
A) Safety
B) Exposure
C) Control
D) Assurance

Section: The C.I.A. Triad & Characteristics of Information

1. The C.I.A. triad stands for:


A) Control, Integrity, Authorization
B) Confidentiality, Intelligence, Access
C) Confidentiality, Integrity, Availability
D) Cyber, Information, Assurance
2. Which characteristic ensures that information is free from mistakes or errors and has
the value expected?
A) Utility
B) Accuracy
C) Possession
D) Availability
3. If a file has been modified by a virus, which characteristic of the information has
been compromised?
A) Confidentiality
B) Availability
C) Integrity
D) Utility
4. Which attribute describes information that is genuine or original rather than a
fabrication?
A) Accuracy
B) Authenticity
C) Possession
D) Utility
5. "Personally Identifiable Information" (PII) is most closely linked to which C.I.A.
attribute?
A) Confidentiality
B) Integrity
C) Availability
D) Utility
6. Which quality ensures that data is accessible and correctly formatted for use without
interference?
A) Accuracy
B) Integrity
C) Availability
D) Possession
7. "Utility" of information means:
A) The data is encrypted.
B) The data is owned by the correct person.
C) The data has value for a purpose or end.
D) The data is free of errors.
8. If a hacker encrypts a company's data and demands a ransom (Ransomware), which
primary characteristic is violated because the owner has lost control?
A) Accuracy
B) Possession
C) Authenticity
D) Utility
9. File hashing is a key method for ensuring which information characteristic?
A) Confidentiality
B) Availability
C) Integrity
D) Utility
10. E-mail spoofing (sending an email with a modified sender field) primarily attacks:
A) Availability
B) Authenticity
C) Utility
D) Possession

Section: The CNSS Security Model

1. The McCumber Cube, created in 1991, has how many dimensions?


A) 2
B) 3
C) 4
D) 6
2. Which of the following is NOT one of the three dimensions of the McCumber Cube?
A) Information Characteristics (Confidentiality, Integrity, Availability)
B) Information States (Storage, Processing, Transmission)
C) Security Measures (Policy, Education, Technology)
D) Threat Vectors (Internal, External, Environmental)
3. The McCumber Cube allows for how many intersection points (cells)?
A) 9
B) 18
C) 27
D) 36
4. CNSS stands for:
A) Center for National Security Standards
B) Committee on National Security Systems
C) Computer Network Security Services
D) Central Network Safety System

Section: Components of an Information System

1. Which component of an Information System is often considered the "weakest link" in


security?
A) Hardware
B) Software
C) People
D) Networks
2. An Information System (IS) consists of Software, Hardware, Data, People,
Procedures, and:
A) Networks
B) Buildings
C) Electricity
D) Managers
3. According to the text, which component is the most difficult to secure and carries the
lifeblood of information?
A) Hardware
B) Software
C) Networks
D) Procedures
4. "Physical Security" is most directly applied to which IS component?
A) Procedures
B) Hardware
C) Data
D) Software
5. Written instructions for accomplishing a specific task are called:
A) Policies
B) Procedures
C) Protocols
D) Standards
6. Information was originally defined as:
A) Data with meaning
B) Raw facts
C) Electronic signals
D) Binary code

Section: Implementation Approaches

1. Which approach to information security implementation begins as a grassroots effort


by system administrators?
A) Top-down approach
B) Bottom-up approach
C) Side-channel approach
D) Agile approach
2. Why does the Bottom-up approach often fail?
A) It lacks technical expertise.
B) It is too expensive.
C) It lacks participant support and organizational staying power.
D) It focuses too much on policy.
3. Which approach is initiated by upper management and has a higher probability of
success?
A) Top-down approach
B) Bottom-up approach
C) Grassroots approach
D) Technical approach
4. Who is typically the "champion" in a Top-down approach?
A) A system administrator
B) An external consultant
C) A high-level executive (e.g., CIO or VP-IT)
D) The data user
5. JAD stands for:
A) Joint Application Development
B) Java Application Design
C) Justified Access Defense
D) Joint Admin Department

Section: Systems Development Life Cycle (SDLC)

1. The first phase of the traditional Waterfall SDLC is:


A) Analysis
B) Physical Design
C) Investigation
D) Implementation
2. During which SDLC phase is a preliminary cost-benefit analysis conducted?
A) Investigation
B) Analysis
C) Logical Design
D) Maintenance
3. In which phase do analysts determine "what" the new system is expected to do
(assessments of current systems)?
A) Investigation
B) Analysis
C) Physical Design
D) Implementation
4. The "Logical Design" phase creates a blueprint that is:
A) Dependent on specific hardware vendors
B) Implementation independent
C) Focused on physical wiring
D) The final step before disposal
5. The make-or-buy decision (develop in-house or purchase) happens during which
phase?
A) Logical Design
B) Physical Design
C) Investigation
D) Maintenance
6. Which phase of the SDLC is generally the longest and most expensive?
A) Investigation
B) Implementation
C) Maintenance and Change
D) Analysis
7. Software Assurance (SA) attempts to:
A) Add security after the software is deployed.
B) Build security into the development life cycle.
C) Ensure software is free.
D) Replace the SDLC entirely.
8. In the NIST approach to SDLC, the "Disposal" phase ensures:
A) Hardware is thrown in the trash.
B) Information is preserved, moved, or sanitized (destroyed) securely.
C) Contracts are renewed.
D) New software is installed.
9. The "waterfall model" is characterized by:
A) Simultaneous execution of all phases.
B) Each phase flowing from the information gained in the previous phase.
C) Skipping the design phase to save time.
D) Ignoring feedback loops.
10. DevOps focuses on integrating:
A) Development and Sales
B) Operations and Human Resources
C) Development and Operations
D) Management and Janitorial staff

Section: Software Assurance & Principles

1. The "Economy of mechanism" principle suggests:


A) Buying the cheapest software.
B) Keeping the design as simple and small as possible.
C) Using the most complex encryption available.
D) Automating all security.
2. "Fail-safe defaults" means:
A) Access decisions should be based on permission rather than exclusion.
B) Systems should crash safely.
C) Users should have administrative rights by default.
D) Passwords should never expire.
3. "Complete mediation" requires that:
A) Two keys are used to unlock a mechanism.
B) Every access to every object must be checked for authority.
C) Designs should not be secret.
D) Users should have the least privilege necessary.
4. Which principle states that designs should not be secret, but depend on possession
of keys/passwords?
A) Open design
B) Psychological acceptability
C) Separation of privilege
D) Least common mechanism
5. "Least privilege" means:
A) Users operate with the minimum privileges necessary to do their job.
B) Users have no privileges.
C) Users have all privileges to ensure efficiency.
D) Privilege is granted based on seniority.
6. Microsoft's approach to secure software development is called:
A) MS-Secure
B) Security Development Lifecycle (SDL)
C) Windows Defender Protocol
D) Active Defense
7. According to Saltzer and Schroeder (1975), "Psychological acceptability" means:
A) Security should be invisible.
B) The human interface should be designed for ease of use.
C) Users must pass a psychological exam.
D) Security controls should be frightening to deter attackers.

Section: Roles and Responsibilities

1. The executive responsible for advising the CEO on strategic information planning is
the:
A) CISO
B) CIO
C) CFO
D) COO
2. The CISO (Chief Information Security Officer) typically reports to the:
A) CEO
B) CIO
C) Head of Physical Security
D) Human Resources Director
3. Who is responsible for the security and use of a particular set of information?
A) Data Custodian
B) Data Owner
C) Data User
D) System Administrator
4. Who is responsible for the storage, maintenance, and protection of information (e.g.,
backups)?
A) Data Custodian
B) Data Owner
C) Data User
D) CEO
5. Data Users are:
A) Only external customers.
B) Only hackers.
C) Everyone in the organization who interacts with information.
D) Only the IT department.
6. Which group of professionals focuses more on transaction response time and ease
of use?
A) Information Security Management
B) Information Technology (IT) Management
C) Legal Department
D) Physical Security Team
7. "Communities of Interest" in an organization typically include General Management,
IT Management, and:
A) Information Security Management
B) The Sales Team
C) The Stockholders
D) The Cleaning Staff

Section: Scenario-Based & Conceptual (Higher Difficulty)

1. Scenario: Amy receives an email with an attachment titled "Funniest joke". She
opens it, and her computer freezes. This is an example of:
A) A brute force attack
B) A direct attack
C) Malware execution via a Trojan/Worm approach
D) A hardware failure
2. If a bank teller accidentally inputs $100 instead of $1000, which information
characteristic is compromised?
A) Confidentiality
B) Accuracy
C) Availability
D) Possession
3. Scenario: A hacker steals a backup tape of encrypted customer data. They have the
tape, but cannot read the data. Which characteristic is breached?
A) Confidentiality
B) Possession
C) Integrity
D) Authenticity
4. Why is Information Security considered both an Art and a Science?
A) It requires drawing diagrams (Art) and coding (Science).
B) It involves rigorous technology (Science) and user interpretation/implementation (Art).
C) It is neither; it is purely social science.
D) Because hackers use artistic fonts.
5. "Security as a Social Science" emphasizes:
A) The behavior of people interacting with systems.
B) The physics of electricity.
C) The mathematics of encryption.
D) The artistic design of websites.
6. Balancing Information Security and Access means:
A) Maximum security, zero access.
B) Maximum access, zero security.
C) Allowing reasonable access while protecting against threats.
D) Giving security professionals total control over business operations.
7. If a system is C-2 level certified (TCSEC) but is disconnected from all networks to
achieve it, this illustrates:
A) Perfect security for a modern business.
B) The trade-off between security and utility/access.
C) The failure of Microsoft Windows.
D) The importance of physical security.
8. In the Amy/SLS scenario, what was the primary failure that led to the incident?
A) The firewall failed.
B) Amy lacked preparation/awareness regarding email attachments.
C) The phone lines were cut.
D) Bob's computer was too old.
9. What is the relationship between Data Owners and Data Custodians?
A) Custodians tell Owners what to do.
B) Owners specify who gets access; Custodians implement the technical controls.
C) They are the same person.
D) Owners are external; Custodians are internal.
10. If a politician uses Census data to plan a campaign, but a private citizen finds the
same data overwhelming, this illustrates the concept of:
A) Integrity
B) Utility
C) Secrecy
D) Encryption
11. What implies that "Information Security cannot be absolute"?
A) We don't have enough money.
B) It is a process, not a goal; perfect security usually means no access.
C) Hackers are smarter than defenders.
D) Computers are inherently broken.
12. Which of the following is an example of an "Indirect Attack"?
A) A hacker typing commands directly into a server.
B) A lightning strike burning down a server room.
C) A DDoS attack launched from a compromised "Botnet" of zombie computers.
D) Stealing a laptop from an airport.
13. The "Check bits" and "Redundancy bits" in data transmission are used to ensure:
A) Confidentiality
B) Integrity
C) Possession
D) Privacy
14. Which statement best describes the "Waterfall" model's limitation?
A) It is too fast.
B) It is not secure.
C) It assumes a linear flow and can be difficult to adjust once a phase is passed.
D) It requires no documentation.
15. DevOps and SecOps are examples of:
A) Old-fashioned security.
B) Agile/Accelerated development models merging skills.
C) Government regulations.
D) Hardware components.
16. The Georgia Secretary of State breach (2015) mentioned in the text was caused by:
A) A Russian hacker.
B) An employee failing to follow policies (sent data to 12 orgs).
C) A software bug in Windows.
D) A physical theft of a hard drive.
17. The GE Money/Iron Mountain incident involved the loss of:
A) A laptop.
B) A backup magnetic tape.
C) An encryption key.
D) The CEO's password.
18. The "McCumber Cube" is used to:
A) Solve cryptographic puzzles.
B) Represent the architectural approach to security (3x3x3).
C) Test physical strength of hardware.
D) Calculate risk cost.
19. What is "C.O.T.S." software?
A) Commercial Off-The-Shelf.
B) Computer Operated Technical Security.
C) Code Of The System.
D) Central Operating Tech Stack.
20. Who authored the seminal paper "The Protection of Information in Computer
Systems" (1975)?
A) Gates and Jobs.
B) Saltzer and Schroeder.
C) Ritchie and Thompson.
D) Bisbey and Hollingworth.
21. A "Champion" in the project team context is:
A) The person who wins the coding contest.
B) A senior executive who promotes and funds the project.
C) The lead developer.
D) The external auditor.
22. "Separation of Privilege" is best described as:
A) Keeping managers away from employees.
B) Requiring two keys (or people) to unlock a mechanism rather than one.
C) Giving everyone their own office.
D) Using different passwords for email and banking.
23. The intersection of "Technology," "Integrity," and "Storage" is a cell in which model?
A) The OSI Model
B) The McCumber Cube
C) The Waterfall Model
D) The C.I.A. Triad
24. When an organization assigns a "Data Custodian," they are typically:
A) The CEO.
B) IT/Systems Administrators implementing the protection.
C) The customer.
D) The legal team.
25. If a user is "spoofed" by an email, they have fallen victim to a failure of:
A) Hardware.
B) Authenticity verification.
C) Network cabling.
D) Power supply.
26. The "Security Systems Development Life Cycle" (SecSDLC) differs from standard
SDLC by:
A) Using different phases entirely.
B) Ensuring security is addressed at every phase of the standard SDLC.
C) Being shorter.
D) Only involving the CISO.
27. In the "Investigation" phase of SDLC, the most important output is:
A) The final code.
B) The scope, objectives, and preliminary cost-benefit analysis.
C) The user manual.
D) The disposal plan.
28. Why is "People" considered a distinct component of IS?
A) Because they are expensive.
B) Because they can be manipulated (Social Engineering) and are prone to error.
C) Because they are biological assets.
D) They are not considered a component; only tech is.
29. "Kanban" and "Scrum" are associated with which development methodology?
A) Waterfall
B) Agile
C) Bottom-up
D) RAND
30. If a company initiates a security program because the CEO orders it, this is:
A) Bottom-up.
B) Top-down.
C) Horizontal.
D) Circular.
31. Ultimately, information security exists to:
A) Stop all computer usage.
B) Support the goals and mission of the organization.
C) Make the IT department famous.
D) Use the most expensive technology available.

MCQ Answer Key


1. C | 2. B | 3. B | 4. C | 5. B
2. A | 7. C | 8. B | 9. B | 10. C
3. B | 12. B | 13. A | 14. B | 15. C
4. B | 17. B | 18. C | 19. B | 20. B
5. C | 22. B | 23. C | 24. B | 25. A
6. C | 27. C | 28. B | 29. C | 30. B
7. B | 32. D | 33. C | 34. B | 35. C
8. A | 37. B | 38. B | 39. B | 40. A
9. B | 42. C | 43. A | 44. C | 45. A
10. C | 47. A | 48. B | 49. B | 50. B
11. C | 52. B | 53. B | 54. B | 55. C
12. B | 57. A | 58. B | 59. A | 60. A
13. B | 62. B | 63. B | 64. B | 65. B
14. A | 67. C | 68. B | 69. A | 70. C
15. B | 72. B | 73. B | 74. A | 75. C
16. B | 77. B | 78. B | 79. B | 80. B
17. C | 82. B | 83. C | 84. B | 85. B
18. B | 87. B | 88. A | 89. B | 90. B
19. B | 92. B | 93. B | 94. B | 95. B
20. B | 97. B | 98. B | 99. B | 100. B

Part 2: 20 Short Questions


Definitions

1. Define "Information Security" according to the CNSS.


The protection of information and its critical elements, including the systems and hardware
that use, store, and transmit the information.
2. What is the C.I.A. Triad?
The industry standard for computer security based on three characteristics: Confidentiality,
Integrity, and Availability.
3. Define "Exploit" in the context of information security.
A technique used to compromise a system. It can be a verb (the act of using it) or a noun
(the software tool/script used).
4. What is a "Threat Agent"?
The specific instance or component of a threat (e.g., a specific hacker, a lightning strike, or
a specific virus).
5. Define "Software Assurance" (SA).
A methodological approach to software development that seeks to build security into the
development life cycle rather than adding it later.

Conceptual Questions

1. Explain the difference between a "Direct Attack" and an "Indirect Attack."


A direct attack originates from the threat itself (e.g., a hacker typing code). An indirect attack
originates from a compromised system or resource (e.g., a botnet) under the control of the
threat.
2. Why is the "Top-down approach" preferred over the "Bottom-up approach" in
implementing security?
Top-down has upper-management support, funding, clear planning, and the ability to
influence organizational culture. Bottom-up often fails due to lack of authority and funding.
3. Explain the concept of "People as the weakest link."
Even with perfect technology, human error (social engineering susceptibility, losing
passwords, clicking malicious links) can bypass technical controls.
4. How does "Possession" differ from "Confidentiality"?
Confidentiality means only authorized people can read the data. Possession means holding
the data. You can breach possession (steal an encrypted hard drive) without breaching
confidentiality (if you can't decrypt it).
5. What is the significance of RAND Report R-609?
It was the first widely recognized document to identify the role of management and policy in
security, expanding the scope beyond just physical hardware security.

Diagram/Model Based

1. Describe the three dimensions of the McCumber Cube.


(1) Information Characteristics (C.I.A.), (2) Information States (Storage, Processing,
Transmission), and (3) Security Measures (Policy, Education, Technology).
2. In the "Subject vs. Object" of attack concept, can a computer be both? Explain.
Yes. A computer is the Object when it is being attacked. Once compromised, it becomes
the Subject if it is used to attack other systems (e.g., in a botnet).
3. List the six components of an Information System.
Hardware, Software, Data, People, Procedures, Networks.
4. List the phases of the traditional Waterfall SDLC.
Investigation, Analysis, Logical Design, Physical Design, Implementation, Maintenance &
Change.
5. What are the three "Communities of Interest" in Information Security?
InfoSec Management/Professionals, IT Management/Professionals, and Organizational
(General) Management/Professionals.

Scenario Based

1. Scenario: An employee throws a document containing credit card numbers into a


trash can without shredding it. Which C.I.A. attribute is primarily at risk and why?
Confidentiality. Unauthorized individuals ("dumpster divers") could access sensitive
information they are not authorized to see.
2. Scenario: A data entry clerk accidentally deletes a critical customer file. Is this an
attack? Explain.
Yes, it is an unintentional attack that affects Availability (and potentially Integrity/Accuracy).
3. Scenario: The CIO decides that "Availability" is more important than "Confidentiality"
for a public website. Is this valid?
Yes. Security is about balance. A public website needs to be available to everyone; high
confidentiality controls (like complex logins) would hinder its purpose (Utility).
4. Scenario: SLS Company (from the text) suffered a malware attack. If Amy had
recognized the "Funniest joke" email as suspicious, which "Control" would have
been effective?
Education, Training, and Awareness (People/Procedure control). Technology (Antivirus) is
one layer, but user awareness is critical.
5. Scenario: A developer is rushing to finish an app and hard-codes a password into the
script. Which Software Assurance principle did they violate?
Open Design (designs shouldn't rely on secrets like hidden passwords) or potentially Least
Privilege (if that password grants root access).

You might also like