ISR考试
Information Security Awareness Quiz
1. 基本信息:
姓名(中文):
汇丰工号:
2. What kind of information are not allowed to be sent to one's personal e-mail box not in business need?
1. Public
2. Internal
3. Restricted
4. Highly Restricted
A. 1,2,3 & 4
B. 2,3 & 4
C. 3 & 4
D. 4 Only
3. Which of the following behavious are regarded as tailgating? (Select all that apply)
A. An unknown person wearing visitor card following you to go through the security glass door.
B. A known colleague left HID card at home and wearing visitor card following you to go through the security glass door.
C. The cleaner in custom suit following you to go through the security glass door.
D. Your registered visitor following you to go through the security glass door.
4. Which of the following behaviours are regarded as a breach of relevant policies? (Select all that apply)
A. Sending HSBC training materials to personal e-mail box to study at home without approval
B. Sending one's own payroll/pension details provided by HR to his/her personal e-mail box.
C. Sending HSBC releases to personal email box.
D. Sending Work-in-progress PPT to personal email box to continue working to complete the ppt at home during weekend.
E. Receiving email from TradeUnion(TU) for the weekend company activity logistic arrangement. Take photo on screen/monitor by mobile phone to remember the information.
5. Which of the below suggestion is NOT recommended to use for password? (Select all that apply)
A. All in Numeric characters
B. Including Sequential Characters, e.g. abs, 456
C. Including Repeating Characters, e.g. yyy, 999
D. Including Keyboard order, e.g. qwer, !@#$
E. Include the same sequence of characters as the value of the user’s login property.
F. Equal to the previous used passwords.
G. Password in length of 5
6. Passwords can be leaked in the way of (Select all that apply)
A. The owner may tell it to another person
B. The owner may write it down and not guard the note
C. An attacker could ‘shoulder surf’ i.e. closely watch the user entering the password
D. The owner may enter it in an electronic system that is not secure, such as an internet café where a key stroke logger is set to capture all key strokes
E. If a password is transmitted or stored in clear text, an attacker may be able to ‘sniff’ the transmission or get it from the place it is stored.
7. Which of the following instances are considered as Physical Security breach (misconducts)? (Select all that apply)
A. Photography on the processing floor
B. Bring unauthorized items in the premises
C. Using someone else card to access the premises / tailgating
D. None of one
8. Peter communicates with his clients using his smartphone messaging apps such as WhatsApp and WeChat. This is considered an information security risk because:
A. Smartphone or mobile messaging apps are not Bank-approved tools for communications
B. The phone could get lost or hacked
C. The data is stored in a third-party server and you never know whether it is secure and who has access to your messages
D. All of the above
9. Jane the Project manager has stored records of the project plan, user requirement, system design details on her personal smartphone. She has also used her phone to photograph the daily KANBAN so that she can refer to them whenever she needs. Even though she doesn't intend to send the information to anyone, it is an information security risk because:
A. The phone could get lost
B. Any security loophole could become a window for criminals to lay their hands on customer information
C. The phone could get hacked
D. All of the above
10. Information Security Risk (ISR) occurs when information held by the company, wherever it resides and in whatever format it is stored, is:
A. Lost
B. Stolen
C. Manipulated
D. All of the above
11. It is the responsibility of all employees and service providers to build the strongest line of defence against information security risk.
A. TRUE
B. FALSE
C. Not sure
D. Patially True
12. You could put your accurate Job-Title, Department name, Work email account, on Linkin or Wechat.
A. True
B. False
C. Not sure
D. Patially True
13. What kinds of information are not allowed to be sent to external e-mail box in business need without encryption?
1. Public
2. Internal
3. Restricted
4. Highly Restricted
A. 1,2,3 & 4
B. 2,3 & 4
C. 3 & 4
D. 4 Only
14. Which of the follow action are regarded as a misconduct?(Select all that apply)
A. pply external visitor access for a friend of yours whom would like to apply a job in HSBC and would like to see the working environment in advance
B. Take photo in office for a friend of yours whom would like to apply a job in HSBC and would like to see the working environment in advance
C. Share your bad experience in using the office facilities to a friend of yours whom would like to apply a job in HSBC
D. Print an Internal job description which is not published on Recruitment Website, to to a friend of yours whom would like to apply a job in HSBC
15. The way we could properly validate if the unknown caller is a real colleague. (Select all that apply)
A. Search the Name and Email account provided by the caller in Group directory
B. The caller would able to provide the correct department name and line manager's name as you known.
C. The caller could ping you on Internal instant communication tool. e.g.Sametime/Jabber
D. The caller could send you an email via company domain email account.
16. Which actions are helping you to keep your personal and business information safe? (Select all that apply)
A. Protect yourself from identity theft by destroying any personal information criminals could use
B. Password protect your personal email account and any WiFi facility to avoid unauthorised usage
C. Ensure you are comfortable with what family members are revealing on social networking sites and what they are using them for
D. Manage who can access information on your personal computer by using a facility to restrict visitors
E. Use a shredder to dispose of confidential papers.
F. Put personal details onto social networking sites including date of birth, address, telephone number
G. State that you work for HSBC or supply details of your office/branch location
17. Items that are NOT required to be visibly labelled include: (Select all that apply)
A. Documents that are released to external parties (e.g. marketing materials, business cards, press releases, contracts, etc).
B. System-generated outputs (e.g. reports or files) unless edited within the end user environment.
C. Customer correspondence e.g. Paper letters to the customer.
D. Documents generated from an external source.
E. Internal training material
18. Use of Private Equipment for company Work, which of the following are Prohibited behaviours? (Select all that apply)
A. Plug in the personal USB wireless mouse
B. Use company provided PC/Laptop USB port to charge your mobile phone
C. Audio or video recording of meetings, presentations or conversations on mobile phones
D. All employees are responsible for immediately reporting any breach/suspected breach of information to line management.
19. Which of the following description is Ture? (Select all that apply)
A. A leakage of just a small piece of Restricted information won't do harm to the company.
B. To share fake news of the company is NOT regarded as breaching ISR policy.
C. Customer information is more important than Employee information needs to be protected.
D. All employees are responsible for immediately reporting any breach/suspected breach of information to line management.
20. What is the impact to the company caused by Information Leakage? (Select all that apply)
A. Direct financial impacts
B. Customer Detriment
C. Reputational impacts
D. Regulatory Censure
21. Which of the following items are belong to "HIGHLY RESTRICTED" infomration? (Select all that apply)
A. Answers to memorable questions
B. Admin user ID & Password
C. Employee payroll records
D. Staff reductions (Internal announced)
E. Intellectual property
22. Which of the following are the types of Social Engineering attack? (Select all that apply)
A. Phishing
B. SMShing
C. Vishing
D. Baiting
E. Tailgating
F. Dumpster Diving
23. What types of file in the follow extension could be downloaded to the company provided PC/Laptop from Internet?
A. .MP3
B. . AVI
C. .TXT
D. .COM
E. .JAR
F. .PPTX
G. .DOCX
H. .WAV
24. It's already late at Friday night, but David is still not finish his work on a project PPT which contains RESTRICTED information. The PPT need to be submitted on Monday Morning. David could consider to: (Select all that apply)
A. Come back to Office on Weekend to continue working.
B. Save the draft PPT in the company provided laptop local Drive folder, the 'C:/TEMP/', and bring the laptop to home to continue working.
C. Save the draft PPT in the company provided laptop local Drive folder, the 'C:/USERS/[userID]/Desktop/', and bring the laptop to home to continue working.
D. Bring the laptop to home to continue working via Remote working VPN
E. Send the draft PPT to personal email box, to work at home on personal PC, and send to company email box upon completion.
关闭
更多问卷
复制此问卷