wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

INF2781 - Day 9

Total questions: 55

Worksheet time: 1hrs 12mins

Name
Class
Date
1.

What is the main advantage of using a security group in cloud architecture compared to traditional firewall rules?

a)

Simplified configuration

b)

Remote control of firewall rules

c)

Reduces the risk of accidental exposure

d)

More efficient packet filtering

2.

Which of the following is NOT a function of a NIDS (Network Intrusion Detection System)?

a)

Monitoring inbound packets

b)

Encrypting network traffic

c)

Alerting administrators of potential attacks

d)

Blocking suspicious IP addresses

3.

In traditional network architecture, which layer is primarily responsible for protecting the internal network from external threats?

a)

Load balancer

b)

Virtual Private Network (VPN)

c)

Perimeter layer

d)

DMZ (DeMilitarized Zone)

4.

What is a key reason corporations are moving away from perimeter-based network security?

a)

Difficulty in managing firewall rules

b)

Vulnerability due to compromised authentication credentials

c)

Increased cost of maintenance

d)

ncompatibility with cloud-based services

5.

Which of the following best practices helps minimize the risk of network attacks in a cloud environment?

a)

Opening all ports on a server

b)

Running multiple network services on a single server

c)

Using a reverse proxy

d)

Allowing unrestricted direct access to databases

6.

What is the purpose of a DMZ in network architecture?

a)

To provide a secure zone for external users to access internal servers

b)

To encrypt data traffic within the network

c)

To expose external-facing services to an untrusted network

d)

To manage load balancing across the network

7.

How does a firewall in a cloud environment differ from a traditional firewall?

a)

It does not block traffic

b)

It operates based on physical hardware

c)

It uses security groups instead of physical devices

d)

It is less efficient in filtering traffic

8.

What is the role of PEP (Policy Enforcement Points) in traditional network security?

a)

Acts as an interface for managing virtual servers

b)

Serves as the gatekeeper for network traffic

c)

Encrypts communication between servers

d)

Provides a user interface for configuring firewalls

9.

Which of the following could result in full access to all servers within a network segment in traditional architectures?

a)

Misconfigured VPN

b)

Weak passwords

c)

Compromise of an individual server

d)

Poorly implemented load balancing

10.

What is a major benefit of using multiple layers of security (multilayered defense) in a network architecture?

a)

It simplifies network design

b)

It eliminates the need for encryption

c)

It allows audit of the end-to-end communication

d)

It ensures data is only encrypted once

11.

True/False: Implementing NIDS on each server in a cloud network introduces a single point of failure.

(a)  

12.

True/False: Security groups in cloud environments can be managed remotely, reducing the risk of configuration errors.

(a)  

13.

True/False: A reverse proxy can make an infrastructure more vulnerable to attacks.

(a)  

14.

True/False: Using multiple network services on a single server is considered a best practice for network security.

(a)  

15.

True/False: Perimeter security involves the use of both NIDS and firewalls to monitor and control traffic.

(a)  

16.

True/False: A DMZ acts as a buffer zone between an internal network and external networks, exposing certain services.

(a)  

17.

True/False: A firewall’s primary function is to encrypt data sent between different segments of a network.

(a)  

18.

True/False: If one server is compromised in a traditional network, it can lead to full access across all servers in the same segment.

(a)  

19.

True/False: Security in cloud networks does not require the use of traditional firewalls.

(a)  

20.

True/False: Opening only necessary ports on a server is an example of a network security best practice.

(a)  

21.

A company’s internal network was compromised after an attacker gained access through a stolen authentication credential. Describe how implementing multilayered security could have mitigated this situation

4 lines
22.

During a high-traffic period, a company’s servers experienced a Denial-of-Service (DoS) attack that disrupted services. Explain how NIDS could have helped to detect and mitigate this attack.

4 lines
23.

A company uses traditional perimeter security with a DMZ but plans to migrate to a cloud-based environment. What changes should they consider to maintain or enhance their network security?

4 lines
24.

An organization’s web application is hosted in a DMZ, but they want to allow internal employees to connect directly to the application servers. What are the potential security risks, and how can they be mitigated?

4 lines
25.

A new firewall rule accidentally exposed a company’s internal servers to the internet. Describe a best practice that could prevent such accidental exposures in the future.

4 lines
26.

An attacker managed to bypass the external firewall and reached the internal network. What measures can be taken to ensure further layers of security prevent complete access?

4 lines
27.

A company wants to use cloud services but is concerned about the security of sensitive data. How can they use security groups to protect their data in the cloud?

4 lines
28.

Explain a situation where using a reverse proxy could enhance the security of a web-based application.

4 lines
29.

A company experienced data loss after a security incident. What data protection measures should they implement to avoid this in the future?

4 lines
30.

During a security audit, it was found that several servers were running services on non-standard ports. What could be the implications of this, and how should it be addressed?

4 lines
31.

In cloud networking, a _ acts as a virtual firewall, filtering traffic based on specified rules.

(a)  

32.

A _ zone allows external services to be exposed without compromising the internal network.

(a)  

33.

_ intrusion detection systems are used to monitor inbound and outbound traffic across a network.

(a)  

34.

A _ is a server that acts as an intermediary for requests from clients seeking resources from other servers.

(a)  

35.

Traditional network security often focuses on protecting the _ layer.

(a)  

36.

A _ is responsible for inspecting and allowing or denying traffic entering or leaving the network.

(a)  

37.

The purpose of a _ is to monitor for and alert administrators of suspicious patterns.

(a)  

38.

Security groups do not provide privileged access unless _ are defined.

(a)  

39.

An attack that attempts to overwhelm a network or service is known as a _ attack.

(a)  

40.

You see a boat filled with people. It has not sunk, but when you look again you don’t see a single person on the boat. Why?

4 lines
41.

I have keys but open no locks. I have space but no room. You can enter but you can't go outside. What am I?

4 lines
42.

What can travel around the world while staying in a corner?

4 lines
43.

If two's company and three's a crowd, what are four and five?

4 lines
44.

What is a common challenge faced when implementing zero trust security models?

a)

High initial setup costs

b)

Complexity in user authentication

c)

Incompatibility with legacy systems

d)

Difficulty in monitoring user activity

45.

Which technology is often used to enhance security in cloud environments by isolating workloads?

a)

Virtualization

b)

Load balancing

c)

Content Delivery Network (CDN)

d)

Network Address Translation (NAT)

46.

What is the primary function of a Web Application Firewall (WAF)?

a)

To filter and monitor HTTP traffic

b)

To encrypt data in transit

c)

To manage user access controls

d)

To provide a backup for data storage

47.

What is a significant drawback of relying solely on perimeter security in modern networks?

a)

Increased latency in network traffic

b)

Inability to detect insider threats

c)

Higher costs for hardware upgrades

d)

Complexity in managing multiple firewalls

48.

Which of the following is a key feature of a Security Information and Event Management (SIEM) system?

a)

Real-time analysis of security alerts

b)

Physical security of data centers

c)

Automated backup of data

d)

Network load balancing capabilities

49.

What is the primary purpose of implementing multi-factor authentication (MFA) in network security?

a)

To simplify user login processes

b)

To enhance security by requiring multiple forms of verification

c)

To reduce the number of passwords users need to remember

d)

To allow access from any device without restrictions

50.

What is the primary advantage of using encryption in data transmission?

a)

It increases data transfer speed

b)

It ensures data integrity

c)

It prevents unauthorized access

d)

It simplifies data management

51.

Which of the following is a common method for securing APIs?

a)

Using API keys

b)

Implementing load balancing

c)

Disabling logging

d)

Opening all endpoints

52.

What is a significant benefit of using a Virtual Private Network (VPN) in network security?

a)

It allows unrestricted access to all websites

b)

It encrypts internet traffic

c)

It improves internet speed

d)

It eliminates the need for firewalls

53.

What is the main advantage of using a Virtual Private Network (VPN) in network security?

a)

It allows unrestricted access to all network resources

b)

It encrypts data transmitted over the internet

c)

It simplifies network configuration

d)

It eliminates the need for firewalls

54.

How does a Distributed Denial of Service (DDoS) attack impact network security?

a)

It enhances network performance

b)

It overwhelms the network with excessive traffic

c)

It secures the network from unauthorized access

d)

It provides a backup for data storage

55.

What is the purpose of using intrusion prevention systems (IPS) in network security?

a)

To monitor network traffic for suspicious activity

b)

To automatically block potential threats

c)

To manage user access controls

d)

To provide a user interface for configuring firewalls