WorksheetsNetwork Security Quiz
Total questions: 16
Worksheet time: 16mins
Which of the following best describes an Intrusion Prevention System (IPS)?
It only monitors network traffic and alerts administrators of potential threats.
It automatically takes action to prevent threats after detecting them.
It blocks network access based on specific port numbers.
It encrypts data being transmitted over the network.
Access Control Lists (ACLs) are commonly implemented to:
Encrypt network traffic between devices
Log all network traffic on a device
Control traffic based on IP addresses, ports, and protocols
Perform URL filtering on outgoing network traffic
Which principle in firewall configuration ensures that unspecified traffic is automatically blocked?
Principle of Least Privilege
Explicit Allow
Implicit Deny
Role-Based Access Control
What is a screened subnet, and how does it enhance network security?
A segment isolated by two firewalls to separate public-facing servers from internal systems
A VLAN that restricts access to sensitive data
A subnet that provides secure encryption for traffic
A method for load balancing internal traffic
Which is a main advantage of using Network-Based Intrusion Prevention Systems (NIPS) over Host-Based Intrusion Prevention Systems (HIPS)?
They can detect and prevent local system changes.
They analyze all network traffic for suspicious activity.
They provide more detailed reports on host-specific threats.
They are more effective at preventing local file modifications.
Behavior-based detection in an IDS typically relies on:
Matching packets against known attack signatures
Establishing a baseline of normal activity and detecting deviations
Monitoring for specific IP addresses
Filtering web traffic by URL
Which detection method is more likely to generate false positives due to variations in network traffic?
Signature-based detection
Anomaly-based detection
Protocol filtering
Port scanning
What is one potential downside to decrypting HTTPS traffic for web filtering?
It enhances network performance.
It allows for better content filtering.
It could raise privacy concerns.
It prevents all malware infections.
Which web filtering method involves installing software on individual devices to enforce compliance?
Centralized filtering
Proxy-based filtering
Reputation-based filtering
Agent-based filtering
How does a centralized proxy server contribute to security?
It prevents all unauthorized external traffic from reaching the network.
It encrypts data between internal users and the Internet.
It controls and monitors web requests based on predefined rules.
It blocks access to internal files and servers.
What advantage does a dual firewall setup provide in a screened subnet?
Improved encryption of data within the subnet
Separate control of inbound and outbound traffic
Reduces latency in public-facing services
Provides content filtering on both firewalls
Which IDS detection method is particularly effective for detecting zero-day attacks?
Signature-based
Behavior-based
Protocol-based
ACL-based
In firewall configuration, what is the purpose of using an explicit 'deny all' rule at the end?
To permit specific traffic to pass
To ensure any unpermitted traffic is blocked
To increase network speed
To prioritize certain protocols
Which system would be the best choice to monitor changes in system files and detect insider threats?
NIDS
HIDS
NIPS
Centralized Web Filtering
What is a key benefit of web filtering in a corporate environment?
It ensures all traffic is encrypted.
It improves system patching efficiency.
It prevents access to malicious or inappropriate websites.
It monitors internal file changes.
What distinguishes a screened subnet from other subnets in network architecture?
It allows unrestricted access to internal systems.
It separates public servers from sensitive internal networks.
It hosts only non-critical services.
It uses a single firewall for all traffic control.
