wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Netrust Freshers Battery Exam

Total questions: 40

Worksheet time: 21mins

Name
Class
Date
1.

What best describes a strong Multi-factor Authenticator?

a)

Something You Are, You Know, You Are Right About

b)

Something You Are, You Know, You Have

c)

Something You Are, You Know, You Have Not

d)

Something You Are, You Know, You Only Knew

e)

All of the above

2.

Choose the best statement for Privileged Account.

a)

A privileged account is a user account that has more executive privileges than other executive officers.

b)

A privileged account is a user account that has more privileges than ordinary users.

c)

A privileged account is a user account that has more privileges than executive officers.

d)

A privileged account is a user account that has executive privileges than ordinary users.

3.

True or False: Passwords are vulnerable to brute force regardless of the number of characters.

a)

True

b)

False

c)

Maybe

4.

Which of the following is NOT a threat to identity.

a)

Identity Digital Twin

b)

Identity Theft

c)

Identity Fraud

5.

What eKYC feature employs strong counter-measure against deepfakes?

a)

Liveness Detection

b)

Passive Detection

c)

Passive Liveness

d)

Liveness Feature

6.

True or False: One-Time-Passwords are considered as part of Multi-factor Authentication strategy

a)

TRUE

b)

FALSE

7.

True or False: Identity and Access Management is only for employees.

a)

TRUE

b)

FALSE

8.

Select all that apply: Which are vulnerable to brute force attack?

a)

Passwords

b)

PIN

c)

OTP

9.

Select the best answer: A type of attack that sends a deceptive emails to fool specific category of people within the organization specially the high-ranking individuals.

a)

Business Email Compromise

b)

Phishing

c)

Spear Phishing

d)

Whaling

10.

Based on the image on the right what is it MOST susceptible to when it comes to data security?

a)

Theft

b)

Brute Force

c)

Password Guessing

11.

Select the best answer based on this RISK statement about Information Security: Where the content of the information is changed so that it is no longer accurate or complete.

a)

Integrity

b)

Confidentiality

c)

Availability

12.

Select the best answer based on this statement about information security: When the information needed is made available when needed.

a)

Confidentiality

b)

Integrity

c)

Availability

13.

Select the best answer based on this RISK statement about information securtiy: where one or more person gain unauthorized access to information.

a)

Confidentiality

b)

Integrity

c)

Availability

14.

True or False: An SSL/TLS handshake is a negotiation between two parties on a network – such as a browser and web server – to establish the details of their connection.

a)

TRUE

b)

FALSE

15.

True or False: The difference between a digital signature and a digital certificate is that the certificate binds the digital signature to the object, while the digital signature must ensure that the data or information remains secure from the moment it is sent.

a)

TRUE

b)

FALSE

16.

Fill in the blanks: Hashing is a ______ function that scrambles plain text to produce a unique message digest.

a)

Forward

b)

Two-way

c)

Backward

d)

One-way

17.

True or False: Hashing is can be virtually reversed.

a)

TRUE

b)

FALSE

18.

Which verifies the user application/ request for a digital certificate within a PKI?

a)

Registration authority

b)

Revocation authority

c)

User authority

d)

Primary authority

19.

Bob encrypts and sends a message for Alice using PKI system. What method does Alice use to decrypt the message when she receives it?

a)

Alice's Private Key

b)

Alice's Public Key

c)

Bob's Private Key

d)

Bob's Public Key

20.

Fill in the blanks: ______ algorithms are faster and are suited for bulk encryption.

a)

Symmetric

b)

Assymetric

21.

Which is NOT part of application security practice to eliminate vulnerabilities?

a)

DevSecOps

b)

Mobile and Web VAPT

c)

Use of Static Application and Security Testing

d)

Github Integration

22.

Fill in the blanks: _______  is the practice of integrating security continuously throughout the software and/or application development lifecycle.

a)

DevSecOps

b)

SecOps

c)

DevOps

23.

True or False: The attack surface is the number of all possible points, or attack vectors, where an unauthorized user can access a system and extract data.

a)

True

b)

False

24.

Fill in the blanks: In the context of Application Security, Mobile phones and APIs are considered ______.

a)

Device Vectors

b)

Attack Vectors

c)

Hacking Vectors

25.

True or False: SAST stands for Static Application Security Testing.

a)

TRUE

b)

FALSE

26.

Fill in the blanks: If S in SAST stands for Static, then D in DAST stands for ______.

a)

Disclosed

b)

Distributed

c)

Dynamic

d)

Decrypted

27.

Fill in the blanks: ______ is a security tool or control that helps protect web applications by filtering and monitoring HTTP traffic between a web application and the Internet.

a)

Web Application Firewall

b)

Application Firewall

c)

Application Control

d)

Reverse Proxy

28.

True or False: A Web Application Firewall (WAF) operates through a set of rules often called policies.

a)

TRUE

b)

FALSE

29.

True or False: During a DDoS attack, rate limiting can be quickly implemented by modifying Web Application Firewall (WAF) policies.

a)

TRUE

b)

FALSE

30.

Fill in the blanks: ______ only admits traffic that has been pre-approved.

a)

Allow List

b)

Block List

c)

Deny List

31.

Which is the right answer: An Endpoint Security Control that covers some more advanced capabilities like detecting and investigating security incidents, and ability to remediate endpoints to pre-infection state.

a)

Endpoint Detention and Respond (EDR)

b)

Endpoint Detection and Response (EDR)

c)

Endpoint Detention and Response (EDR)

d)

Endpoint Detection and Respond (EDR)

32.

Fill in the blanks: ______ ______ is the framework that gives us insight how attacker sees the organization.

a)

Mitre Att&ck

b)

CIS Control

c)

NIST

d)

ISO 27001

33.

In the context of Attack Surface Monitoring: Company Social Media Pages also considered part of the __________.

a)

Cloud Assets

b)

Attack Page

c)

Unsupervised Assets

d)

Attack Surface

34.

Fill in the blanks: ______ is the practice of proactively searching for cyber threats that are lurking undetected in a network.

a)

Cyber Hunting

b)

Vulnerability Scanning

c)

Threat hunting

d)

Network Hunting

35.

Which tool is essential in a Security Operations Center (SOC) for it to aggregate data and detect threats in an organization?

a)

EDR

b)

CCTV

c)

Antivirus

d)

SIEM

36.

Which of the following can detect behavior based threats in an endpoint?

a)

Antivirus

b)

EDR

c)

IPS

d)

Application Firewall

37.

True or False: Mean time to detect (MTTD) is one of the main key performance indicators in incident management.

a)

TRUE

b)

FALSE

38.

True or False: In the context of Cyber Incident: Mean Time to Respond (MTTR, sometimes written as Mean Time to Response) is the average time required to return a system to operational condition after receiving notification of a failure or cyberattack.

a)

TRUE

b)

FALSE

39.

Fill in the blanks: A ______ is a facility that houses an information security team responsible for monitoring and analyzing an organization's security posture on an ongoing basis

a)

Security Operations Center

b)

Security Detection Center

c)

Security Response Center

d)

Security Operating Center

40.

Fill in the blanks: ______ is a technology that can identify and stop evasive network threats that couldn't be easily blocked using known attack patterns or signatures. 

a)

Network Detection and Response (NDR)

b)

Network Prevention and Response (NPR)

c)

Network Intrustion and Response (NIR)