Skip to content

NSE_1 NSE 1 - Information Security Awareness Practice Questions

Prepare for NSE_1 with more than an answer.

140 questions in the full set12 sample questionsUpdated Mar 12, 2026
Passing score
Pass all module quizzes
Level
Fundamentals
Valid for
2 years
  1. 1

    A hospital administrator is reviewing data security policies. They identify a database containing patient names, medical history, and social security numbers. Under data classification standards, what is the specific term for this type of data?

    Show answer details

    Correct answer: C

    Protected Health Information (PHI) specifically refers to health data that is linked to an individual's identity. While it contains PII, the medical context makes PHI the most specific and accurate classification.

  2. 2

    Which state of data is most vulnerable to interception by a Man-in-the-Middle (MitM) attack if not properly secured?

    Show answer details

    Correct answer: C

    Data in Transit (moving between devices or networks) is the target of Man-in-the-Middle attacks where attackers intercept the communication. Encryption (like HTTPS/VPN) is required to protect it.

  3. 3

    Select TWO effective methods for protecting 'Data at Rest' on a laptop. (Select TWO)

    Show answer details

    Correct answer: B, D

    Full Disk Encryption ensures that if the physical drive is stolen, the data cannot be read without the decryption key.

    Physical security prevents unauthorized physical access to the storage media, which is a primary defense for data at rest.

  4. 4

    A Chief Information Security Officer (CISO) is classifying threat actors attacking the organization's financial infrastructure. The attackers are highly sophisticated, well-funded, use custom-developed zero-day exploits, and appear to be motivated by long-term espionage rather than immediate financial gain. Which category of threat actor does this profile best match?

    Show answer details

    Correct answer: D

    Nation-State actors (or State-Sponsored attackers) are characterized by high sophistication, substantial funding, and long-term goals such as espionage or political influence. They often develop custom zero-day exploits (Advanced Persistent Threats) unlike other groups.

  5. 5

    Which of the following motivations is primarily associated with 'Hacktivist' groups?

    Show answer details

    Correct answer: B

    Hacktivists are motivated by political, social, or ideological causes. They attack targets to promote a message, protest actions, or bring attention to a cause, rather than for direct financial gain.

  6. 6

    Review the diagram below depicting the sophistication versus resources of various threat actors. Which actor type best fits the description of 'Group C'—individuals with low technical skill who rely primarily on pre-written tools downloaded from the internet?

    quadrantChart title Threat Actor Landscape x-axis Low Resources --> High Resources y-axis Low Sophistication --> High Sophistication quadrant-1 Nation States quadrant-2 Organized Crime quadrant-3 Group C quadrant-4 Insiders "APT Groups": [0.9, 0.9] "Cyber Criminals": [0.7, 0.6] "Group C": [0.1, 0.1] "Hacktivists": [0.4, 0.5]
    Show answer details

    Correct answer: D

    Script Kiddies are characterized by low technical sophistication and resources. They rely on existing scripts and tools created by others to launch attacks, often for thrill or attention, rather than developing their own exploits.

Create an account to continue.