wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Network Security Baselines

Total questions: 14

Worksheet time: 12mins

Name
Class
Date
1.

Which of the following is a primary reason for establishing network security baselines in an organization?

a)

To prevent zero-day attacks by using predefined signatures

b)

To define a minimum standard of security configurations across devices

c)

To enable seamless network integration with third-party vendors

d)

To ensure all network components use identical encryption methods

2.

How does the Security Content Automation Protocol (SCAP) contribute to network security baseline compliance?

a)

By detecting and removing malware from network endpoints

b)

By enabling automated monitoring and comparison against defined baselines

c)

By providing real-time analysis of network traffic patterns

d)

By enforcing access control policies based on user roles

3.

Which network configuration change can reduce the likelihood of unauthorized access to router management interfaces?

a)

Enabling SNMPv1 for remote monitoring

b)

Using HTTPS and disabling HTTP on management interfaces

c)

Configuring default SNMP community strings

d)

Disabling SSH access to the router

4.

What is the purpose of using a secure baseline configuration for all organizational assets?

a)

To establish consistent security controls and mitigate common vulnerabilities

b)

To increase network traffic speed and prevent latency

c)

To reduce encryption overhead on network resources

d)

To enable quick data recovery in case of a breach

5.

Which protocol should be avoided when configuring secure remote access to network devices, due to its lack of encryption?

a)

HTTPS

b)

SNMPv3

c)

Telnet

d)

SSH

6.

What key information does a heat map provide to network administrators in the context of wireless network management?

a)

List of connected device

b)

Signal strength, interference levels, and channel usage

c)

IP address allocation across wireless access points

d)

Data transfer rates per access point

7.

Which wireless security standard is no longer considered secure and is not recommended for use?

a)

WPA2

b)

WPA3

c)

WEP

d)

WPA2-Personal

8.

How does WPA3 improve upon WPA2 in terms of preventing offline password attacks?

a)

By using a single shared password for all connected devices

b)

By replacing PSK authentication with Simultaneous Authentication of Equals (SAE)

c)

By requiring complex passphrases for network connections

d)

By implementing RADIUS authentication by default

9.

Network Access Control (NAC) can enforce compliance by using which of the following approaches?

a)

Agent-based and agentless monitoring of device status and compliance

b)

Dynamic IP routing to isolate non-compliant devices

c)

Encryption enforcement on all client devices

d)

Static routing based on user credentials

10.

In a network environment, what key function does a RADIUS server provide?

a)

Packet filtering and forwarding

b)

Authentication, Authorization, and Accounting for network access

c)

IP address assignment for connected clients

d)

Intrusion prevention through signature-based detection

11.

What advantage does Network Access Control (NAC) provide through dynamic VLAN assignment?

a)

Efficient bandwidth allocation across network segments

b)

Restricts device connectivity based on compliance and user roles

c)

Directs all external traffic to a secure VLAN

d)

Provides load balancing for network traffic

12.

In WPA3, which feature ensures that traffic is encrypted even on open networks?

a)

SAE (Simultaneous Authentication of Equals)

b)

Enhanced Open

c)

RADIUS authentication

d)

WPA2 compatibility mode

13.

Which tool is specifically used for assessing compliance with CIS Benchmarks?

a)

CIS-CAT Pro

b)

Wireshark

c)

OpenVAS

d)

Nessus

14.

What does Simultaneous Authentication of Equals (SAE) in WPA3-Personal mode mitigate that WPA2-PSK is vulnerable to?

a)

Offline dictionary and brute force attacks

b)

Man-in-the-middle attacks on encrypted data

c)

Unauthorized device connections via SSID spoofing

d)

Cross-site scripting attacks on network credentials