wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Module 3 - Security Architecture

Total questions: 25

Worksheet time: 13mins

Name
Class
Date
1.
An organization is building a new backup data center with cost-benefit as the primary requirement and RTO and RPO values around two days. Which of the following types of sites is the best for this scenario?
a)
Real-time recovery
b)
Hot
c)
Cold
d)
Warm
2.
A systems administrator is looking for a low-cost application-hosting solution that is cloud-based. Which of the following meets these requirements?
a)
Serverless framework
b)
Type 1 hypervisor
c)
SD-WAN
d)
SDN
3.
A company is concerned about weather events causing damage to the server room and downtime. Which of the following should the company consider?
a)
Clustering servers
b)
Geographic dispersion
c)
Load balancers
d)
Off-site backups
4.
An enterprise is trying to limit outbound DNS traffic originating from its internal network. Outbound DNS requests will only be allowed from one device with the IP address 10.50.10.25. Which of the following firewall ACLs will accomplish this goal?
a)
Access list outbound permit 0.0.0.0/0 0.0.0.0/0 port 53 Access list outbound deny 10.50.10.25/32 0.0.0.0/0 port 53
b)
Access list outbound permit 0.0.0.0/0 10.50.10.25/32 port 53 Access list outbound deny 0.0.0.0/0 0.0.0.0/0 port 53
c)
Access list outbound permit 0.0.0.0/0 0.0.0.0/0 port 53 Access list outbound deny 0.0.0.0/0 10.50.10.25/32 port 53
d)
Access list outbound permit 10.50.10.25/32 0.0.0.0/0 port 53 Access list outbound deny 0.0.0.0/0 0.0.0.0/0 port 53
5.
A company prevented direct access from the database administrators' workstations to the network segment that contains database servers. Which of the following should a database administrator use to access the database servers?
a)
Jump server
b)
RADIUS
c)
HSM
d)
Load balancer
6.
An engineer needs to find a solution that creates an added layer of security by preventing unauthorized access to internal company resources. Which of the following would be the best solution?
a)
RDP server
b)
Jump server
c)
Proxy server
d)
Hypervisor
7.
A company needs to provide administrative access to internal resources while minimizing the traffic allowed through the security boundary. Which of the following methods is most secure?
a)
Implementing a bastion host
b)
Deploying a perimeter network
c)
Installing a WAF
d)
Utilizing single sign-on
8.
A hacker gained access to a system via a phishing attempt that was a direct result of a user clicking a suspicious link. The link laterally deployed ransomware, which laid dormant for multiple weeks, across the network. Which of the following would have mitigated the spread?
a)
IPS
b)
IDS
c)
WAF
d)
UAT
9.
Which of the following roles, according to the shared responsibility model, is responsible for securing the company's database in an IaaS model for a cloud environment?
a)
Client
b)
Third-party vendor
c)
Cloud provider
d)
DBA
10.
A company is developing a business continuity strategy and needs to determine how many staff members would be required to sustain the business in the case of a disruption. Which of the following best describes this step?
a)
Capacity planning
b)
Redundancy
c)
Geographic dispersion
d)
Tablet exercise
11.
A company's legal department drafted sensitive documents in a SaaS application and wants to ensure the documents cannot be accessed by individuals in high-risk countries. Which of the following is the most effective way to limit this access?
a)
Data masking
b)
Encryption
c)
Geolocation policy
d)
Data sovereignty regulation
12.
A security consultant needs secure, remote access to a client environment. Which of the following should the security consultant most likely use to gain access?
a)
EAP
b)
DHCP
c)
IPSec
d)
NAT
13.
A security analyst scans a company's public network and discovers a host is running a remote desktop that can be used to access the production network. Which of the following changes should the security analyst recommend?
a)
Changing the remote desktop port to a non-standard number
b)
Setting up a VPN and placing the jump server inside the firewall
c)
Using a proxy for web connections from the remote desktop server
d)
Connecting the remote server to the domain and increasing the password length
14.
Security controls in a data center are being reviewed to ensure data is properly protected and that human life considerations are included. Which of the following best describes how the controls should be set up?
a)
Remote access points should fail closed.
b)
Logging controls should fail open.
c)
Safety controls should fail open.
d)
Logical security controls should fail closed
15.
An organization is struggling with scaling issues on its VPN concentrator and internet circuit due to remote work. The organization is looking for a software solution that will allow it to reduce traffic on the VPN and internet circuit, while still providing encrypted tunnel access to the data center and monitoring of remote employee internet traffic. Which of the following will help achieve these objectives?
a)
Deploying a SASE solution to remote employees
b)
Building a load-balanced VPN solution with redundant internet
c)
Purchasing a low-cost SD-WAN solution for VPN traffic
d)
Using a cloud provider to create additional VPN concentrators
16.
A business received a small grant to migrate its infrastructure to an off-premises solution. Which of the following should be considered first?
a)
Security of cloud providers
b)
Cost of implementation
c)
Ability of engineers
d)
Security of architecture
17.
A company is planning a disaster recovery site and needs to ensure that a single natural disaster would not result in the complete loss of regulated backup data. Which of the following should the company consider?
a)
Geographic dispersion
b)
Platform diversity
c)
Hot site
d)
Load balancing
18.
A security administrator is deploying a DLP solution to prevent the exfiltration of sensitive customer data. Which of the following should the administrator do first?
a)
Block access to cloud storage websites
b)
Create a rule to block outgoing email attachments
c)
Apply classifications to the data
d)
Remove all user permissions from shares on the file server
19.
Which of the following should a systems administrator use to ensure an easy deployment of resources within the cloud provider?
a)
Software as a service
b)
Infrastructure as code
c)
Internet of Things
d)
Software-defined networking
20.
An enterprise has been experiencing attacks focused on exploiting vulnerabilities in older browser versions with well-known exploits. Which of the following security solutions should be configured to best provide the ability to monitor and block these known signature-based attacks?
a)
ACL
b)
DLP
c)
IDS
d)
IPS
21.
An organization is leveraging a VPN between its headquarters and a branch location. Which of the following is the VPN protecting?
a)
Data in use
b)
Data in transit
c)
Geographic restrictions
d)
Data sovereignty
22.
A small business uses kiosks on the sales floor to display product information for customers. A security team discovers the kiosks use end-of-life operating systems. Which of the following is the security team most likely to document as a security implication of the current architecture?
a)
Patch availability
b)
Product software compatibility
c)
Ease of recovery
d)
Cost of replacement
23.
Employees in the research and development business unit receive extensive training to ensure they understand how to best protect company data. Which of the following is the type of data these employees are most likely to use in day-to-day work activities?
a)
Encrypted
b)
Intellectual property
c)
Critical
d)
Data in transit
24.
Which of the following must be considered when designing a high-availability network? (Choose two).
a)
Ease of recovery
b)
Ability to patch
c)
Physical isolation
d)
Responsiveness
e)
Attack surface
25.
A company is developing a critical system for the government and storing project information on a fileshare. Which of the following describes how this data will most likely be classified? (Select two).
a)
Private
b)
Confidential
c)
Public
d)
Restricted
e)
Urgent