Font size
WorksheetsIAS 2 FINAL EXAMINATION
Total questions: 85
Worksheet time: 45mins
What does the principle of "least privilege" imply?
A. Users should have access to all resources
B. Users should have the minimum access necessary to perform their job functions
C. Security should be implemented through hidden mechanisms
D. Security should be based on the user's rank
What is a security policy?
A. A set of guidelines for aesthetic design
B. A document outlining the rules and procedures for protecting assets
C. A software tool for managing security
D. A list of all users and their permissions
In the context of security design, what does CIA stand for?
A. Confidentiality, Integrity, Availability
B. Central Intelligence Agency
C. Confidentiality, Information, Authentication
D. Control, Integrity, Access
What is the purpose of a demilitarized zone (DMZ) in network security?
A. To store backup data
B. To host internal company resources
C. To provide an additional layer of security for external-facing services
D. To monitor employee activities
What is a firewall?
A. A physical barrier to prevent unauthorized entry
B. A system designed to prevent unauthorized access to or from a private network
C. A software for managing user credentials
D. An encryption technique
Which of the following best describes a "honeypot"?
A. A security mechanism that records all network traffic
B. A system designed to attract and trap potential attackers
C. A database of known security threats
D. A method for securing wireless networks
What does the term "asymmetric cryptography" refer to?
A. Cryptography using the same key for encryption and decryption
B. Cryptography using different keys for encryption and decryption
C. Cryptography without any keys
D. Cryptography using hash functions
What is the purpose of a hash function in cryptography?
A. To encrypt data
B. To compress data
C. To generate a unique fixed-size output from variable-size input data
D. To create encryption keys
What does the term "public key" refer to in asymmetric cryptography?
A. A key used only for decryption
B. A key that is kept secret and never shared
C. A key that is shared publicly and used for encryption
D. A key used for both encryption and decryption
What is the primary goal of physical security?
A. To prevent unauthorized access to physical resources
B. To encrypt sensitive data
C. To monitor network traffic
D. To backup data regularly
What does a CCTV system primarily help with?
A. Data encryption
B. Physical surveillance
C. Network security
D. Software updates
Which type of physical security measure involves controlling access to the premises using key cards or biometric scanners?
A. Surveillance
B. Perimeter security
C. Access control
D. Environmental design
What is a mantrap used for in physical security?
What is the primary purpose of having security lighting around a facility?
A. To enhance aesthetic appeal
B. To prevent unauthorized physical access
C. To reduce energy costs
D. To facilitate data recovery
Which type of attack does encryption primarily protect against?
Denial of Service (DoS) attacks
Man-in-the-Middle (MitM) attacks
Phishing attacks
Unauthorized access to data
Which cryptographic algorithm is commonly used for digital signatures?
AES
Blowfish
RSA
MD5
A digital certificate binds a public key with the identity of the certificate holder.
True
False
A Virtual Private Network (VPN) provides a secure connection over a public network.
True
False
Multi-factor authentication (MFA) enhances security by requiring multiple forms of verification.
True
False
Physical security is less important than cyber security in protecting information assets.
True
False
Security by design involves incorporating security measures at the earliest stages of system development.
True
False
What is the primary goal of security architecture and design?
To create aesthetically pleasing systems
To ensure systems are scalable
To protect information assets
To reduce costs
AES (Advanced Encryption Standard) is an example of an asymmetric encryption algorithm.
True
False
Security architecture should be considered only after the system is fully developed.
True
False
What is the primary purpose of cryptography?
To speed up data transmission
To protect information by transforming it into an unreadable format
To reduce the size of data files
To increase the storage capacity of databases
Role-Based Access Control (RBAC) assigns permissions to users based on their roles within an organization.
True
False
Biometrics, such as fingerprint and retina scans, are considered reliable methods for physical access control.
True
False
Which of the following is an example of a cryptographic hash function?
SHA-256
Triple DES
AES
RSA
Environmental hazards, such as fire and floods, should be considered in a physical security plan.
True
False
In symmetric key cryptography, the same key is used for both encryption and decryption.
True
False
Which of the following algorithms is an example of symmetric key cryptography?
RSA
DES
ECC
DSA
Which model is commonly used for mandatory access control?
Bell-LaPadula model
Clark-Wilson model
Biba model
Brewer-Nash model
A physical security policy should include procedures for both normal operations and emergency situations.
True
False
Which of the following is an example of a physical security control?
Firewall
Antivirus software
Security guard
Encryption
Which of the following is a principle of security architecture?
Security through obscurity
Defense in depth
Single layer of defense
Unlimited access
Which of the following is NOT a type of network topology?
A. Star
B. Ring
C. Square
D. Mesh
What does the term 'port scanning' refer to?
A. Scanning physical ports on a device
B. Scanning network ports to find open services
C. Scanning data packets for malware
D. Scanning user accounts
Which protocol is used to resolve IP addresses to MAC addresses?
A. ARP
B. DNS
C. DHCP
D. HTTP
Which of the following protocols is used for secure file transfer?
A. FTP
B. TFTP
C. SFTP
D. SNMP
Which protocol is commonly used for secure web communication?
A. HTTP
B. FTP
C. SSH
D. HTTPS
What does the term 'DDoS' stand for?
A. Distributed Denial of Service
B. Data Distribution over System
C. Direct Data Over System
D. Digital Data Over Security
What is a man-in-the-middle attack?
A. An attack where an unauthorized person intercepts and possibly alters the communication between two parties
B. An attack that targets database vulnerabilities
C. An attack that uses brute force to guess passwords
D. An attack that installs malware on a system
Which of the following describes a VPN concentrator?
A. A device that provides network access
B. A device that allows multiple VPN connections from remote users
C. A type of firewall
D. A device for managing databases
Which of the following protocols is used for sending email?
A. HTTP
B. SMTP
C. FTP
D. SNMP
Which network device is used to forward data packets between computer networks?
A. Router
B. Switch
C. Hub
D. Modem
Which of the following best describes a Virtual Private Network (VPN)?
A. A private network that uses public networks to connect remote sites and users
B. A tool for managing databases
C. A method of encrypting data
D. A type of firewall
What is the function of an Intrusion Detection System (IDS)?
A. To encrypt data
B. To detect unauthorized access or attacks on a network
C. To backup data
D. To manage user accounts
Which of the following best describes a packet sniffer?
A. A tool used to encrypt data
B. A tool used to capture and analyze network traffic
C. A type of firewall
D. A tool for managing databases
What does the acronym 'IP' stand for in networking?
A. Internet Protocol
B. Internal Processing
C. International Protocol
D. Information Processing
What does the term 'phishing' refer to in network security?
A. A method of encrypting data
B. A type of firewall
C. A form of social engineering attack where attackers deceive users into revealing personal information
D. A network protocol
What is the primary purpose of the Secure Shell (SSH) protocol?
A. To provide secure access to a remote computer
B. To send emails
C. To transfer files
D. To manage databases
Which of the following is a key feature of the Transport Layer Security (TLS) protocol?
A. Data encryption
B. Data compression
C. Data backup
D. Data redundancy
What is the purpose of two-factor authentication (2FA) in network security?
A. To encrypt data
B. To require two different forms of identification to access a system
C. To backup data
D. To manage user accounts
What is the primary purpose of a firewall in network security?
A. To store data
B. To enforce security policies by monitoring and controlling incoming and outgoing network traffic
C. To manage user accounts
D. To increase system speed
Which of the following is an example of a Denial of Service (DoS) attack?
A. Encrypting user data
B. Overloading a server with excessive requests to make it unavailable
C. Intercepting communications between two parties
D. Installing malware on a system
Which of the following best describes a VLAN (Virtual Local Area Network)?
A. A physical network device
B. A method of creating logically separate networks within a single physical network
C. A type of firewall
D. A method of encrypting data
What is the purpose of a 'honeypot' in network security?
A. To store honey
B. To detect, deflect, or study attempts to gain unauthorized access to information systems
C. To encrypt data
D. To backup data
What is the primary function of a proxy server?
A. To backup data
B. To act as an intermediary between a client and a server to provide increased security, privacy, and anonymity
C. To manage user accounts
D. To encrypt data
Which of the following is an example of a secure email protocol?
A. HTTP
B. IMAP
C. POP3
D. SMTPS
What is the primary function of the Domain Name System (DNS)?
A. To encrypt data
B. To translate domain names into IP addresses
C. To manage user accounts
D. To provide internet access
What is the purpose of Multi-Factor Authentication (MFA)?
A. To use multiple passwords for a single account
B. To require multiple forms of verification to increase security
C. To allow access from multiple devices
D. To manage multiple user accounts
What is the principle of least privilege?
A. Users have the maximum level of access
B. Users have no access rights
C. Users have the minimal level of access necessary to perform their job functions
D. Users have temporary access rights
Which of the following best describes Role-Based Access Control (RBAC)?
A. Access is based on the user's role within an organization
B. Access is determined by the user's location
C. Access is based on the user's hardware
D. Access is randomly assigned
What is a common use of a directory service in IAM?
A. To store and manage user identities and access privileges
B. To encrypt user data
C. To monitor network traffic
D. To backup data
What does the term 'authentication' refer to in IAM?
A. The process of monitoring user activities
B. The process of verifying the identity of a user
C. The process of encrypting data
D. The process of backing up data
Which of the following best describes 'authorization'?
A. The process of verifying user identity
B. The process of granting or denying access to resources
C. The process of encrypting user data
D. The process of monitoring network traffic
What is an Identity Provider (IdP) in federated identity management?
A. A service that authenticates and verifies user identities
B. A service that stores encrypted data
C. A service that monitors network traffic
D. A service that performs backups
What is a common risk associated with poor IAM practices?
A. Increased system performance
B. Unauthorized access to sensitive information
C. Reduced need for backups
D. Improved user experience
What is the purpose of provisioning in IAM?
A. To encrypt data
B. To create and manage user accounts and access rights
C. To monitor network traffic
D. To perform backups
What is the primary benefit of using Role-Based Access Control (RBAC)?
A. Simplifies the management of user permissions by assigning permissions to roles instead of individual users
B. Increases the number of required passwords
C. Reduces the need for encryption
D. Enhances data backup processes
What is the main function of an Identity Governance and Administration (IGA) system?
A. To encrypt data
B. To ensure compliance with policies and regulations regarding identity and access management
C. To manage network traffic
D. To perform system backups
Which protocol is commonly used for federated identity management?
FTP
SAML
SMTP
HTTP
Which of the following is NOT a component of IAM?
Authentication
Authorization
Accounting
Encryption
Which of the following is NOT a common authentication method?
Password
Biometric scan
CAPTCHA
Data compression
What does Single Sign-On (SSO) enable users to do?
Access multiple applications with one set of login credentials
Encrypt data with a single key
Backup data to a single location
Access one application with multiple sets of login credentials
Which of the following is an example of a directory service protocol?
LDAP
HTTP
FTP
SMTP
What is the purpose of an Access Control List (ACL)?
To list all users in a system
To specify which users or system processes are granted access to objects
To encrypt data
To monitor network traffic
Which type of access control is based on predefined rules and policies set by an organization?
Discretionary Access Control (DAC)
Mandatory Access Control (MAC)
Role-Based Access Control (RBAC)
Attribute-Based Access Control (ABAC)
Which of the following best describes 'Identity as a Service' (IDaaS)?
A cloud-based service for managing digital identities
A service for backing up data
A service for encrypting data
A network monitoring service
Which of the following is an example of a 'something you have' factor in MFA?
Password
Security token
Fingerprint
PIN
Which IAM framework includes standards such as OAuth, OpenID Connect, and SAML?
COBIT
ITIL
NIST
Federated Identity Management
Which of the following is an example of a 'something you know' factor in MFA?
Fingerprint
Password
Security token
Mobile phone
What is the primary goal of Identity and Access Management (IAM)?
To enhance user experience
To ensure that the right individuals have access to the right resources at the right times for the right reasons
To manage network traffic
To back up data
What is the main advantage of using Single Sign-On (SSO)?
Reduced administrative costs and improved user experience by requiring users to remember only one set of credentials
Increased complexity of user management
Enhanced data encryption
Increased network traffic
What does the term 'biometric authentication' refer to?
Using biological traits, such as fingerprints or facial recognition, to verify identity
Using passwords to verify identity
Using security questions to verify identity
Using hardware tokens to verify identity
