wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Zero Trust Management

Total questions: 15

Worksheet time: 8mins

Name
Class
Date
1.

Zero trust model says.......

a)
  1. a) Keep a trust on your own actions

b)

b) Keep trust on your own tools

c)

c) Have no trust on anything, just evaluate and confirm

d)

d) None of the above

2.

In a zero trust architecture, which of the following is a key principle?

a)

d) None of the above

b)

c) Trust all internal users

c)

b) Assume breach and verify

d)

  1. a) Trust but verify

3.

What is the primary goal of implementing a zero trust security model?

a)

d) To reduce costs

b)

c) To increase user trust

c)

b) To enhance data protection and minimize risk

d)

  1. a) To simplify network management

4.

Which technology is commonly associated with zero trust security?

a)

d) Antivirus software

b)

c) Firewalls

c)

b) Multi-factor authentication

d)

  1. a) VPNs

5.

What is a significant benefit of adopting a zero trust security approach?

a)

  1. a) Reduced need for security training

b)

b) Simplified compliance with regulations

c)

c) Enhanced visibility and control over user access

d)

d) Increased operational costs

6.

Which of the following best describes the concept of 'least privilege' in a zero trust model?

a)

b) Allowing users to access resources based on their role

b)

d) Granting all users full access to resources

c)

  1. a) Trusting users based on their location

d)

c) Providing users with the minimum level of access necessary

7.

In the context of zero trust, what does the term 'micro-segmentation' refer to?

a)

b) A technique to simplify network architecture

b)

c) Dividing a network into smaller, isolated segments for better security

c)

  1. a) A strategy to enhance user experience

d)

d) A method to increase network speed

8.

Which of the following is a common challenge when implementing a zero trust security model?

a)

d) Reduced need for monitoring

b)

c) Simplified access controls

c)

b) Higher user satisfaction

d)

a) Increased complexity in network management

9.

What role does continuous monitoring play in a zero trust architecture?

a)

c) It only focuses on external threats

b)

b) It helps in identifying and responding to threats in real-time

c)

a) It is optional and not necessary

d)

d) It is primarily for compliance purposes

10.

Which of the following technologies is often used to enforce policies in a zero trust environment?

a)

c) Identity and Access Management (IAM) solutions

b)

b) Traditional firewalls

c)

a) Data Loss Prevention (DLP) tools

d)

d) Basic antivirus software

11.

Cybersecurity professionals may have access to sensitive data. What one factor should they understand to help them make informed ethical decisions in relation to this data?

a)
  • a) Partnerships with third parties

b)
  • b) Laws governing the data

c)
  • c) A potential bonus

d)
  • d) Cloud provider agreements

12.

What is the primary goal of IT security governance?

a)
  • a) To provide oversight to ensure that risks are adequately mitigated

b)
  • b) To define a set of controls that an organisation should implement

c)
  • c) To make decisions to mitigate risk

d)
  • d) To provide a set of policies and procedures to manage sensitive data

13.

What is a fundamental principle of the zero trust security model regarding user access?

a)

a) Grant access based on user location

b)

b) Trust users until they prove otherwise

c)

d) Allow unrestricted access to internal users

d)

c) Verify every user and device before granting access

14.

Which of the following best describes the role of encryption in a zero trust architecture?

a)

d) It is primarily used for compliance purposes

b)

c) It only secures data on local devices

c)

b) It protects data at rest and in transit

d)

a) It is optional and not necessary

15.

In a zero trust environment, what is the significance of user behavior analytics?

a)

a) It helps in identifying potential insider threats

b)

b) It is used to simplify user access

c)

d) It only focuses on external attacks

d)

c) It has no relevance in security