Font size
WorksheetsNetwork Security Quiz
Total questions: 45
Worksheet time: 24mins
A company transmits sensitive customer information across its network. Which of the following technologies should it use to protect data in motion?
AES encryption
TLS or IPsec
Full disk encryption
Access control lists
Which of the following methods would best protect a database stored on a server from unauthorized access?
Encrypting the database with AES
Using a firewall to block unauthorized users
Implementing a VPN for remote access
Using TLS encryption
Which entity is responsible for digitally signing and issuing certificates to verify the authenticity of websites and users?
Firewall
Certificate Authority (CA)
Intrusion Prevention System (IPS)
File Integrity Checker
A company assigns employees to specific job roles and grants access permissions accordingly. This is an example of:
Mandatory Access Control (MAC)
Multi-Factor Authentication (MFA)
Discretionary Access Control (DAC)
Role-Based Access Control (RBAC)
Which of the following best describes the Principle of Least Privilege (PoLP)?
Users should have administrator access to all systems
Users should be granted only the minimum permissions necessary to perform their job functions
All users must be assigned to a single security group
Users should have full access to their department's data
A company wants to ensure that employees can only access their work applications while connected to the corporate VPN. Which method would enforce this?
Digital Certificate Signing
Network Access Control (NAC)
File Integrity Monitoring
Role-Based Access Control
Which of the following best describes the security strategy for SCADA networks?
Complete isolation from external networks
Full integration with public internet
Allowing remote access for all employees
Using strong passwords only
What is the primary reason for segmenting IIoT devices from other networks?
To increase device efficiency
To ensure real-time communication remains uninterrupted
To allow external users access to IIoT devices
To improve wireless connectivity
Why is network segmentation critical for SCADA and ICS systems?
To ensure restricted access to industrial control systems
To increase download speeds
To allow remote access from any device
To enhance corporate email security
What is the main reason Operational Technology (OT) networks are segmented from traditional IT networks?
To allow faster internet browsing
To prevent cyberattacks from disrupting critical infrastructure
To enable employees to connect personal devices
To reduce firewall costs
An organization wants to allow users to authenticate across multiple web applications using a single set of credentials. Which protocol is best suited for this?
TACACS+
RADIUS
SAML
LDAP
A person without a security badge closely follows an employee through a secured door without using their own access card. The employee does not challenge them. What type of attack does this scenario demonstrate?
Tailgating
Piggybacking
Dumpster Diving
Shoulder Surfing
Which of the following is responsible for verifying that a user is who they claim to be in the AAA framework?
Authentication
Identification
Authorization
Accounting
After a user has successfully logged into a corporate network, they are only allowed to access specific files. Which AAA function does this represent?
Authentication
Authorization
Accounting
Identification
An IT administrator needs to track login attempts, including failed logins. Which component of AAA is responsible for this?
Authentication
Authorization
Accounting
Identification
Which of the following authentication protocols is commonly used in VPNs and 802.1X authentication?
TACACS+
Kerberos
RADIUS
SAML
A company uses a directory service that allows employees to log in with their network credentials and access shared resources. Which protocol is likely being used?
RADIUS
LDAP
TACACS+
OAuth
Your server experiences an attack where multiple requests exhaust the server's ability to establish new connections. What type of attack does this describe?
SYN Flood Attack
Phishing Attack
SQL Injection
Session Hijacking
An attacker uses a botnet to generate large volumes of traffic towards a target, causing the server to exhaust all available bandwidth. Which defense mechanism could help mitigate this attack?
Implementing CAPTCHA verification
Using a Content Delivery Network (CDN)
Enabling strong password policies
Conducting regular software updates
You notice unusual traffic between VLANs without an authorized router. Which attack might this indicate?
Double Tagging
Keylogging
DDoS Attack
Packet Sniffing
Your switch uses the default native VLAN ID 1. An attacker uses double tagging to access another VLAN. What configuration change can mitigate this risk?
Increase the native VLAN ID to a higher number
Set the native VLAN ID to a non-default value
Disable VLAN tagging
Allow all VLANs on the trunk port
An attacker sends numerous frames with random source MAC addresses to a switch. What attack method is being used?
MAC Flooding
Phishing
Man-in-the-Middle
Double Tagging
A network administrator wants to prevent a MAC flooding attack. Which security measure should they implement?
Enable port security
Allow all MAC addresses by default
Increase the size of the MAC address table
Disable switch learning mode
Scenario: A device with a MAC address not present in the switch's MAC address table sends data. What action does the switch take?
Broadcasts the frame to all ports
Drops the frame
Sends the frame to a random port
Sends the frame only to the default gateway
A user tries to visit a legitimate website but is redirected to a phishing site that looks identical. What kind of attack might have occurred?
Brute Force Attack
DNS Spoofing
IP Address Blocking
Password Spraying
A device with IP 192.168.1.9 wants to connect to the router 192.168.1.1, but an attacker intercepts the traffic. What type of attack is this scenario describing?
ARP Spoofing
SQL Injection
Social Engineering
Phishing
An attacker uses a spoofed DNS response to redirect a victim to a fake banking site. What is the goal of this attack?
To capture the victim’s banking credentials
To increase network bandwidth
To improve DNS resolution times
To provide a secure connection
The organization deploys Multi-Factor Authentication (MFA) for all network access. How does this help prevent spoofing attacks?
By requiring more than just a password, it mitigates the risk if a spoofing attack compromises credentials.
It allows faster access to the network.
It improves email delivery speeds.
It automatically encrypts all network traffic.
An unauthorized access point is detected during a routine network scan. What should the IT team do first?
Increase the network bandwidth
Physically disconnect the rogue access point
Ignore the device if it has low signal strength
Automatically connect all devices to it
An attacker uses session hijacking to gain control of a user's active session. Which broader category of attacks does this belong to?
On-Path Attacks
Malware Attacks
Phishing Attacks
Physical Attacks
Which of the following is a key difference between a standard and an extended ACL?
Standard ACLs filter by protocol type, while extended ACLs do not.
Extended ACLs can filter by source and destination IPs, ports, and protocols, while standard ACLs filter by source IP only.
Standard ACLs are more granular than extended ACLs.
Extended ACLs only work on routers, not firewalls.
Which security technique involves categorizing websites to allow or block access?
URL Filtering
Port Forwarding
MAC Address Filtering
Load Balancing
What is the purpose of a screened subnet (DMZ) in network security?
To allow unrestricted access to the internal network
To provide a secure area for public-facing services without exposing the internal network
To store sensitive company data
To isolate network devices from each other
You are setting up a new router for your home office. Which of the following is a best practice?
Keep the default password for easy access
Change the default credentials to a strong, unique password
Share the default credentials with everyone on the network
Disable all security features
Which practice helps reduce the attack surface on a networked device?
Keeping all ports open for flexibility
Closing unused ports and services
Using the same password for all devices
Avoiding security updates
What is the primary difference between a virus and a worm?
A virus requires human intervention to spread, while a worm spreads automatically.
A worm requires human intervention to spread, while a virus spreads automatically.
Both viruses and worms require human intervention to spread.
Neither viruses nor worms can replicate themselves.
An attacker uses a rootkit to gain administrative control of a system. What makes this malware difficult to detect?
It is not installed on the operating system.
It hides itself within system files and processes.
It only displays advertisements.
It does not affect system performance.
A person dressed as a delivery driver asks an employee to hold the door open as they bring in packages. The employee does not verify their identity. What security risk does this scenario illustrate?
Dumpster Diving
Phishing
Piggybacking
Shoulder Surfing
You are working on confidential information in a public space. What is a good security practice?
Use a privacy screen on your laptop
Share your screen with those nearby
Leave your laptop unattended
Connect to any open Wi-Fi network
A technician is assigned to harden a laptop for a medical practice. Which of the following should be used to protect PII in the event of hardware theft?
Hard drive encryption
Disable bluetooth
Password expiration
Host based firewall
Match the Following Networking Terms
Defense-in-Depth
Combining multiple security layers
NAC Controls
Manage who & what connects to the netwrk
Reflective Attack
Redirects traffic from legitimate server
On Path Attack
Intercepts & alters communication
Amplified Attack
Exploit response with high volume data
A switch is configured to only allow DHCP responses from a legitimate server. What feature is being used?
DHCP Snooping
Port Mirroring
VLAN Tagging
Load Balancing
A network administrator implements encryption for all communications using HTTPS and TLS. How does this help prevent on-path attacks?
It makes data unreadable to attackers even if intercepted.
It increases internet speed.
It blocks all external connections.
It disables unauthorized DHCP servers automatically.
You need to allow SSH access on port 22 to a server from any source. Which ACL rule would achieve this?
permit tcp any any eq 80
permit tcp any any eq 22
permit tcp any any eq 21
permit udp any any eq 22
An administrator wants to block all ICMP (ping) traffic on a firewall. Which rule should be implemented?
permit icmp any any
deny icmp any any
deny tcp any any eq 443
allow icmp any any
