wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Authentication/Access Control/Enterprise Architecture

Total questions: 50

Worksheet time: 25mins

Name
Class
Date
1.

Which of the following is the term for the process of validating a subject's identity?

a)

Authorization

b)

Authentication

c)

Auditing

d)

Identification

2.

An employee traveling in Europe for vacation submitted a ticket as they could not access their work email. Which policy does the company use?

a)

Multi-factor authentication

b)

Password age

c)

Password management

d)

Location-based authentication

3.

A contractor only works for a company from 9 a.m. to 12 p.m. What kind of restriction could the company set up on the contractor's account to prevent using it outside that range?

a)

Password restrictions

b)

Mandatory access control

c)

Location-based restrictions

d)

Time-based restrictions

4.

A cyber engineer conducts a multi-factor authentication (MFA) assessment of an organization's authentication security. What MFA philosophy uses knowledge factors and includes passphrases to gain access to systems?

a)

Something you have

b)

Somewhere you are

c)

Something you know

d)

Something you are

5.

What type of password is maryhadalittlelamb?

a)

Composition

b)

Static

c)

Passphrase

d)

Cognitive

6.

You assign access permissions so that users can only access the resources required to accomplish their specific work tasks. Which security principle are you complying with?

a)

Principle of least privilege

b)

Job rotation

c)

Need to know

d)

Cross-training

7.

In which form of access control environment is access controlled by rules rather than identity?

a)

Mandatory access control (MAC)

b)

Discretionary access control (DAC)

c)

Access control list (ACL)

d)

Most client-server environments

8.

What is the primary function of Active Directory as a centralized database in a network?

a)

It provides internet access to all computers in the network.

b)

It serves as a backup system for all files in the network.

c)

It stores and organizes all user accounts and security information.

d)

It manages the power supply to all computers in the network.

9.

You are teaching new users about security and passwords. Which of the following is the BEST example of a secure password?

a)

JoHnSmITh

b)

Stiles_2031

c)

8181952

d)

T1a73gZ9!

10.

The IT department of a corporation evaluates its security mechanisms to identify areas lacking sufficient protection. Which of the following techniques should the IT department employ?

a)

Authorization models

b)

Zero trust

c)

Gap analysis

d)

Non-repudiation

11.

Which access control model is based on assigning attributes to objects and using Boolean logic to grant access based on the attributes of the subject?

a)

Rule-based access control

b)

Attribute-based access control (ABAC)

c)

Role-based access control (RBAC)

d)

Mandatory access control (MAC)

12.

An IT department is using a technique to assess the differences in performance between their systems, looking to see if the systems meet the established requirements. Which of the following terms BEST describes the technique the IT department is using?

a)

Authorization models

b)

Non-repudiation

c)

Gap analysis

d)

Zero trust

13.

You have implemented an access control method that only allows users who are managers to access specific data. Which type of access control model is being used?

a)

Discretionary access control (DAC)

b)

Mandatory access control (MAC)

c)

Discretionary access control list (DACL)

d)

Role-based access control (RBAC)

14.

You have configured a security device in your network to fail-closed. Which of the following will happen when an attack occurs?

a)

The device will block access or enter the most secure state available when it fails.

b)

The device will act on behalf of a client when accessing resources over the internet when it fails.

c)

The device will distribute network traffic across multiple servers when it fails.

d)

The device will preserve network or host access when it fails.

15.

Which technology is primarily used by smart cards to store digital signatures, cryptography keys, and identification codes?

a)

Hashing algorithms

b)

Public Key Infrastructure (PKI)

c)

Blockchain technology

d)

Secure Sockets Layer (SSL)

e)

Advanced Encryption Standard (AES)

16.

What is the process of controlling access to resources such as computers, files, or printers called?

a)

Conditional access

b)

Authorization

c)

Mandatory access control

d)

Authentication

17.

Which of the following principles is implemented in a mandatory access control model to determine object access by classification level?

a)

Clearance

b)

Ownership

c)

Need to know

d)

Principle of least privilege

e)

Separation of duties

18.

Which of the following is the MOST common form of authentication?

a)

Fingerprint

b)

Photo ID

c)

Password

d)

Digital certificate on a smart card

19.

When sending confidential data over a network, a company wants to ensure both parties involved cannot deny the validity of the transmitted data. Which security principle should they prioritize?

a)

Non-repudiation

b)

Authentication, authorization, and accounting (AAA)

c)

Zero trust

d)

Adaptive identity

20.

Which of the following identifies the type of access that is allowed or denied for an object?

a)

User rights

b)

SACL

c)

Permissions

d)

DACL

21.

Which of the following authentication methods specifically allows users to access multiple systems, applications, or websites using only a single set of credentials?

a)

Attestation

b)

Directory services

c)

Federation

d)

Single sign-on (SSO)

22.

After a breach, an organization implements new multi-factor authentication (MFA) protocols. What MFA philosophy incorporates using a smart card or key fob to support authentication?

a)

Something you are

b)

Something you know

c)

Somewhere you are

d)

Something you have

23.

An organization implements a new network infrastructure and plans to use an intrusion prevention system (IPS) for security. The IT manager wants to ensure that the IPS will continue to let traffic flow if it fails. Which failure mode should the IT manager configure the IPS?

a)

Fail-closed

b)

Active

c)

Passive

d)

Fail-open

24.

What principle of an organization's information security system ensures that only authorized individuals can access sensitive data, the data remains unaltered during storage and transfer, and the data is always accessible when needed?

a)

CIA triad

b)

Authenticating people

c)

Two-factor authentication

d)

Access control list

25.

An employee at a company frequently recycles old passwords when prompted for a password change. What feature of a password policy can prevent this?

a)

Password complexity

b)

Password history

c)

Password length

d)

Password age

26.

You have hired ten new temporary employees to be with the company for three months. How can you make sure that these users can only log on during regular business hours?

a)

Configure day/time restrictions in user accounts.

b)

Configure account policies in Group Policy.

c)

Configure account lockout in Group Policy.

d)

Configure account expiration in user accounts.

27.

One of your company's accountants submitted a ticket stating they could not access a particular section of the accounting software. Why might the accountant not have access to every part of the accounting software?

a)

Licensing

b)

Least privilege

c)

DAC

d)

MAC

28.

After finding a corporate phone unattended in a local mall, an organization decides to enhance its multi-factor authentication (MFA) procedures. What MFA philosophy applies a location-based factor for authentication?

a)

Something you know

b)

Something you are

c)

Something you have

d)

Somewhere you are

29.

Which form of access control is based on job descriptions?

a)

Discretionary access control (DAC)

b)

Role-based access control (RBAC)

c)

Mandatory access control (MAC)

d)

Attribute-based access control (ABAC)

30.

In the context of the NIST Cybersecurity Framework, which function involves identifying, analyzing, containing, and eradicating threats to systems and data security?

a)

Identify

b)

Protect

c)

Recover

d)

Respond

31.

Which of the following statements about honeyfiles are true? (Select two.)

a)

Honeyfiles are designed to provide real data to the attacker.

b)

Honeyfiles are named in a way that makes them attractive to hackers, enticing them to open or execute them.

c)

Honeyfiles are used to block all types of malicious traffic.

d)

Honeyfiles can only be created by system administrators.

e)

Honeyfiles work with network intrusion detection systems (NIDs) and can help prevent false positives.

32.

An IT team at a global pharmaceutical company has decided to implement a virtual private network (VPN) for remote employees to securely access internal company resources from home. Which of the following is a primary reason for this decision?

a)

VPNs are designed for managing devices on IP networks.

b)

VPNs provide secure command-line access and file transfer.

c)

VPNs provide a direct connection to a single machine.

d)

VPNs encrypt and encapsulate all traffic to create a secure tunnel.

33.

Jessica needs to set up a firewall to protect her internal network from the internet. Which of the following would be the BEST type of firewall for her to use?

a)

Stateful

b)

Hardware

c)

Tunneling

d)

Software

34.

You are deploying a brand new router. After you change the factory default settings, what should you do next?

a)

Update the firmware.

b)

Configure anti-spoofing rules.

c)

Secure the configuration file.

d)

Configure SSH to access the router configuration.

35.

In a rapidly evolving IT environment, a cloud service provider offers various services to businesses, enabling them to store and process data securely. To enhance security, the provider regularly updates its systems and software. Despite these efforts, a security researcher discovers a previously unknown vulnerability in one of the cloud-specific applications, leaving customer data exposed to potential threats. In this scenario, which vulnerability is the security researcher likely to have found in the cloud-specific application?

a)

Zero-day vulnerability

b)

Network misconfiguration

c)

SQL injection vulnerability

d)

Cross-site scripting (XSS) vulnerability

36.

Which of the following applies the appropriate policies in order to provide a device with the access it's defined to receive?

a)

Authentication

b)

Identity Services Engine

c)

Authorization

d)

Zero-trust security

37.

Which of the following is the BEST device to deploy to protect your private network from a public untrusted network?

a)

Hub

b)

Router

c)

Gateway

d)

Firewall

38.

A financial institution is processing transactions and wishes to improve its security posture. The institution divides its network into different sections to minimize risk while actively updating or retrieving transaction data. What method does the financial institution intend to use?

a)

Segmentation

b)

Virtual private network (VPN)

c)

Network address translation (NAT)

d)

Firewalling

39.

An attacker was able to gain unauthorized access to a mobile phone and install a Trojan horse so that he or she could bypass security controls and reconnect later. Which type of attack is this an example of?

a)

Privilege escalation

b)

Replay

c)

Backdoor

d)

Social engineering

40.

You are a cybersecurity specialist for a financial institution that is planning to enhance its network security. The institution has decided to adopt a defense in depth strategy. Which of the following approaches would BEST align with a defense in-depth strategy?

a)

Implementing a complex array of different security technologies without considering their interaction or potential redundancies.

b)

Implementing a single, robust firewall at the network perimeter and relying on this for all network security.

c)

Implementing a single security measure, such as encryption, across all data and network traffic.

d)

Implementing multiple security measures at different network layers, including firewalls, intrusion detection systems, and regular patch management.

41.

You are a network architect for a rapidly growing startup. The startup is planning to expand its operations and is considering a major upgrade to its network architecture. Which of the following factors should be your primary consideration when designing the new network architecture?

a)

Maximizing compute resources and responsiveness, regardless of cost.

b)

Balancing costs, compute and responsiveness, scalability, availability, and resilience.

c)

Minimizing initial capital outlay by choosing the cheapest available hardware and software options.

d)

Prioritizing scalability and ease of deployment over all other considerations.

42.

Which of the following describes how access control lists can be used to improve network security?

a)

An access control list filters traffic based on the frame header, such as source or destination MAC address.

b)

An access control list looks for patterns of traffic between multiple packets and takes action to stop detected attacks.

c)

An access control list filters traffic based on the IP header information, such as source or destination IP address, protocol, or socket number.

d)

An access control list identifies traffic that must use authentication or encryption.

43.

Which of the following BEST describes zero-trust security?

a)

All devices are trusted.

b)

Only devices that pass authorization are trusted.

c)

Only devices that pass authentication are trusted.

d)

Only devices that pass both authentication and authorization are trusted.

44.

Which of the following should be configured on the router to filter traffic at the router level?

a)

Access control list

b)

Telnet

c)

Anti-spoofing rules

d)

SSH

45.

In an effort to increase the security of your organization, programmers have been informed they can no longer bypass security during development. Which vulnerability are you attempting to prevent?

a)

Privilege escalation

b)

Social engineering

c)

Backdoor

d)

Replay

46.

Which VPN tunnel style routes only certain types of traffic?

a)

Split

b)

Site-to-site

c)

Full

d)

Host-to-host

47.

A VPN is primarily used for which of the following purposes?

a)

Support secured communications over an untrusted network

b)

Support the distribution of public web documents

c)

Allow remote systems to save on long-distance charges

d)

Allow the use of network-attached printers

48.

Which VPN implementation uses routers on the edge of each site?

a)

Remote access VPN

b)

Host-to-host VPN

c)

Site-to-site VPN

d)

Always-on VPN

49.

Which of the following defines all the prerequisites a device must meet in order to access a network?

a)

Authorization

b)

Authentication

c)

Zero-trust security

d)

Identity Services Engine (ISE)

50.

Which of the following NAC agent types would be used for IoT devices?

a)

Permanent

b)

Zero-trust

c)

Dissolvable

d)

Agentless