An employee reports seeing someone in a restricted area who isn’t wearing a badge. What is the appropriate response?
A company wants to prevent unauthorized individuals from entering restricted areas by following employees through doors. Which control is most effective?
To reduce the risk of shoulder surfing in open offices, what workstation security measure should be used?
A company’s workstation security policy requires employees to clear their desks of paper documents before leaving. What is this policy called?
Which practice directly prevents an adversary from installing malware via a USB flash drive?
An organization installs fencing and security lighting around its building. What type of control is this?
An employee finds a USB drive labeled “Executive Salaries” in the parking lot and plugs it into their computer.
Which security awareness topic was most relevant to preventing this incident?
During a storm, a company’s servers shut down abruptly and lose unsaved data. What device could have prevented this?
Which of the following is an example of mitigating a moderate physical risk?
An employee notices their coworker’s laptop is left unattended and unlocked at a shared workspace. According to workstation policy, what should have been done?
Which combination of controls best protects sensitive data from an event like a hurricane?
An attacker clones an employee’s access card to enter the data center after hours. Which physical control could best detect this unauthorized access?
A company disables USB ports on all computers and installs card readers on lab entrances. What is the main purpose of these measures?
After several phishing reports, a company decides to take action. Which of the following would be an appropriate control to put in place?
A company that handles sensitive financial records conducts a security audit and finds that several workstations located near exterior windows are visible from the sidewalk outside the building. Which 2 controls would offer the best mitigation?
An employee receives an email that looks like it’s from the IT department asking them to “verify” their login information.
Which part of security awareness training is designed to prevent this?
After several reports of employees holding doors open for strangers, the company installs turnstiles that allow entry to only one person at a time.
Which attack is this designed to prevent?
A company worries that its windows are too close to the ground and are accessible on foot. Which control would best mitigate this observed risk?
Which cybersecurity principle do access card reader logs assist with?
A company experiences multiple incidents of food spilling onto keyboards, damaging computers.
Which workstation policy could mitigate this?