Question 1
Which type of security control acts during an incident to identify or record that the incident is happening?
Correct Answer:
Detective
Explanation:
Detective security controls identify and record events as they occur. They monitor the environment and generate alerts or logs when something suspicious happens, so an incident can be detected in real time and evidence can be collected. Examples include intrusion detection systems, security information and event management (SIEM), access logs, and continuous monitoring. Deterrent controls aim to discourage attacks before they happen and do not provide real-time identification. Directive controls are policies and procedures that guide how people should behave, rather than actively detecting incidents. Compensating controls provide an alternative safeguard when the primary control isn’t feasible, but they’re not defined primarily by their ability to detect incidents.
Question 2
A group account is a collection of user accounts used to grant the same level of access to multiple users. What is this concept called?
Correct Answer:
Group Account
Explanation:
The idea being tested is using a shared container to grant the same access to many people. A group account acts as a single identity that represents a set of user accounts; when permissions are given to that group account, every member of the group inherits those rights. This makes administration simpler because you manage access at the group level rather than configuring permissions for each individual user, and you can add or remove members to adjust who has the access. Other terms point to different ideas: permissions are the actual rights granted, not the container that holds multiple users; discretionary access control is a model where owners decide who can access resources; and RBAC is a system that assigns permissions to roles which are then assigned to users. The concept described—a single account representing multiple users to provide the same access—is best described as a group account.
Question 3
What process determines what rights and privileges an entity has?
Correct Answer:
Authorization
Explanation:
Authorization determines what rights and privileges an entity has. It happens after authentication, when the system applies policies to decide what a user or process is allowed to do with resources. In practice, once identity is verified, the system checks roles, attributes, or rules (such as ACLs or RBAC) to grant or deny specific actions like read, write, or execute. This separation matters: authentication verifies who you are, identification is the claimed identity, and accounting logs what you did. For example, after logging in (authentication), a user’s role is consulted to determine if they can access a file or perform a change (authorization).
Question 4
Which port is commonly used by the Remote Desktop Protocol?
Correct Answer:
3389
Explanation:
Remote Desktop Protocol relies on a dedicated TCP port by default, which is the one most commonly associated with and expected for RDP connections. That default port is what makes it the best answer here, because knowing this port helps you configure firewalls and access controls around RDP. The other ports correspond to different services you might see on a network—SSH for secure remote login, HTTP for web traffic, and HTTPS for secure web traffic—so they’re not the standard port used by RDP. While you can reconfigure RDP to listen on another port, using the default port is the common, recognized choice, and it’s important to secure it properly (for example, by restricting exposure to the internet and using VPN or a gateway).
Question 5
Which term denotes a token that represents the ownership factor in a multifactor authentication scheme, generated by a hardware device?
Correct Answer:
Hard authentication token
Explanation:
Ownership as a factor in multifactor authentication means you must prove you possess something physical. A hardware device that generates a code or cryptographic response on demand is a hard authentication token—the classic physical token used to demonstrate you have the device. This token is produced by the device itself and changes over time or per event, which is exactly what shows possession of the hardware. Biometric authentication isn’t an ownership factor but a “something you are” factor. Smart cards are hardware credentials and can serve as possession devices, but the term that emphasizes the generated token from the hardware device is hard authentication token. A security key is a hardware credential as well, but the phrasing here centers on the token generated by the device, which aligns with the hard token concept.
Question 1
Exam overview

About this Exam

Prepare with the Information Security Principles and Frameworks Practice Test practice quiz. This question bank includes 10 questions covering term, security, incident, access, and entity. Use it to review important concepts, identify knowledge gaps, and build confidence for the related exam, course, or assessment.

More details

Additional Information

Information Security Principles and Frameworks Practice Test

This practice set contains 10 questions from the matching question bank and focuses on term, security, incident, access, and entity. Work through each question carefully, review the provided solutions, and revisit topics that need more study before your next attempt.

This is an independent study resource intended for practice and review; it is not an official examination or an endorsement by any organization named in the title.

Quiz information

Frequently Asked Questions

The complete question count is available after full access is unlocked.
No fixed duration is currently configured for this quiz.
Question explanations are included where they are available in the quiz content, helping you review the reasoning after answering.
Yes. You can retake the practice test again as you continue studying during your available access period.
After your access is confirmed, you can continue into the complete practice exam from this quiz flow.
Unless explicitly stated otherwise, this page provides independent practice material for study and exam preparation and is not the official examination itself.
Keep studying

Related Questions