Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Module 3 Quiz – Network Security

Total questions: 29

Worksheet time: 15mins

Name
Class
Date
1.

1. The IT department is reporting that a company web server is receiving an abnormally high number of web page requests from different locations simultaneously. Which type of security attack is occurring?

a)

spyware

b)
  • phishing

c)

DDoS

d)
  • social engineering

e)
  • adware

2.

2. What causes a buffer overflow?

a)
  • downloading and installing too many software updates at one time

b)

attempting to write more data to a memory location than that location can hold

c)
  • sending too much information to two or more interfaces of the same device, thereby causing dropped packets

d)
  • sending repeated connections such as Telnet to a particular device, thus denying other data sources

e)
  • launching a security countermeasure to mitigate a Trojan horse

3.

3. Which objective of secure communications is achieved by encrypting data?

a)
  • authentication

b)

confidentiality

c)
  • integrity

d)
  • availability

4.

4. What type of malware has the primary objective of spreading across the network?

a)
  • virus

b)
  • botnet

c)
  • Trojan horse

d)
  • worm

5.

5. Which algorithm can ensure data confidentiality?

a)
  • MD5

b)
  • PKI

c)
  • AES

d)
  • RSA

6.

6. What three items are components of the CIA triad? (Choose three.)

a)

scalibility

b)

access

c)

confidentiality

d)

integrity

e)

availability

7.

7. Which cyber attack involves a coordinated attack from a botnet of zombie computers?

a)
  • address spoofing

b)
  • ICMP redirect

c)
  • DDoS

d)
  • MITM

8.

8. What specialized network device is responsible for enforcing access control policies between networks?

a)

firewall

b)

switch

c)

IDS

d)

bridge

9.

9. To which category of security attacks does man-in-the-middle belong?

a)
  • DoS

b)

access

c)
  • reconnaissance

d)
  • social engineering

10.

10. What is the role of an IPS?

a)
  • to detect patterns of malicious traffic by the use of signature files

b)
  • to enforce access control policies based on packet content

c)
  • to filter traffic based on defined rules and connection context

d)
  • to filter traffic based on Layer 7 information

11.

11. Which type of DNS attack involves the cybercriminal compromising a parent domain and creating multiple subdomains to be used during the attacks?

a)
  • tunneling

b)
  • cache poisoning

c)
  • amplification and reflection

d)
  • shadowing

12.

12. Which two types of hackers are typically classified as grey hat hackers? (Choose two.)

a)
  • script kiddies

b)
  • cyber criminals

c)
  • vulnerability brokers

d)
  • state-sponsored hackers

e)
  • hacktivists

13.

13. What is a significant characteristic of virus malware?

a)
  • Virus malware is only distributed over the Internet.

b)
  • Once installed on a host system, a virus will automatically propagate itself to other systems.

c)
  • A virus can execute independently of the host system.

d)
  • A virus is triggered by an event on the host system.

14.

14. A cleaner attempts to enter a computer lab but is denied entry by the receptionist because there is no scheduled cleaning for that day. What type of attack was just prevented?

a)
  • phishing

b)
  • shoulder surfing

c)
  • war driving

d)
  • social engineering

e)
  • Trojan

15.

15. Which network security statement is true?

a)
  • All threats come from external networks.

b)
  • Internal threats are always accidental.

c)
  • Internal threats are always intentional.

d)
  • Internal threats can cause greater damage than external threats.

16.

16. What commonly motivates cybercriminals to attack networks as compared to hacktivists or statesponsored hackers?

a)
  • Fame seeking

b)
  • Financial gain

c)
  • Political reasons

d)
  • Status among peers

17.

17. Which type of hacker is motivated by protesting political and social issues?

a)
  • Cybercriminal

b)
  • Hacktivist

c)
  • Script kiddie

d)
  • Vulnerability broker

18.

18. What is Trojan horse malware?

a)
  • It is malware that can only be distributed over the internet.

b)
  • It is software that appears useful but includes malicious code.

c)

It is software that causes annoying computer problems

d)
  • It is the most easily detected form of malware.

19.

19. A user receives a call from someone in IT services, asking her to confirm her username and password for auditing purposes. Which security threat does this represent?

a)
  • Anonymous keylogging

b)
  • DDoS

c)
  • Social engineering

d)
  • Spam

20.

20. What is a ping sweep?

a)
  • A DNS query and response protocol

b)
  • A network scanning technique that involves identifying active IP addresses

c)
  • A type of packet capturing software

d)
  • A TCP and UDP port scanner to detect open services

21.

21. How are zombies used in security attacks?

a)
  • Zombies are infected machines that carry out a DDoS attack.

b)
  • Zombies are maliciously formed code segments used to replace legitimate applications.

c)
  • Zombies probe a group of machines for open ports to learn which services are running.

d)
  • Zombies target specific individuals to gain corporate or personal information.

22.

22. What is used to decrypt data that has been encrypted using an asymmetric encryption algorithm public key?

a)
  • A different public key

b)
  • A digital certificate

c)
  • A private key

d)
  • DH

23.

23. What are the SHA hash generating algorithms used for?

a)
  • Authentication

b)
  • Confidentiality

c)
  • Integrity

d)
  • Nonrepudiation

24.

24. Which of the following is true of an IPS?

a)
  • It can stop malicious packets.

b)
  • It has no impact on latency.

c)
  • It is deployed in offline mode.

d)
  • It is primarily focused on identifying possible incidents.

25.

25. What is the term used to describe unethical criminals who compromise computer and network security for personal gain or for malicious reasons?

a)
  • Black hat hackers

b)
  • Hacktivists

c)
  • Script kiddies

d)
  • Vulnerability broker

26.

26. What is the term used to describe a potential danger to a company’s assets, data, or network functionality?

a)
  • Asymmetric encryption algorithm

b)
  • Exploit

c)
  • Threat

d)
  • Vulnerability

27.

27. What term is used to describe a guarantee that a message is not a forgery and does actually come from the person who is supposed to have sent it?

a)
  • Data nonrepudiation

b)
  • Exploit

c)
  • Mitigation

d)
  • Origin authentication

28.

28. What term is used to describe a mechanism that takes advantage of a vulnerability?

a)
  • Asymmetric encryption algorithm

b)
  • Exploit

c)
  • Threat

d)
  • Vulnerability

29.

29. Which of the following guarantees that the sender cannot repudiate, or refute, the validity of a message sent?

a)
  • Data nonrepudiation

b)
  • Exploit

c)
  • Mitigation

d)
  • Origin authentication