NEW
Font size
WorksheetsSecurity Fundamental
Total questions: 25
Worksheet time: 18mins
What is the purpose of a Non-Disclosure Agreement (NDA) during onboarding?
To issue security tokens
To provision user accounts
To protect sensitive company information
To assign default privileges
Which principle states that users should only be given permissions necessary to perform their job?
Separation of duties
Mandatory vacations
Least privilege
Role-based access
Which account is a key target for attackers and often disabled after system installation?
Guest account
Service account
Standard user account
Administrator/root account
Why are shared accounts discouraged in a secure environment?
They are more expensive to maintain
They break the principle of non-repudiation
They offer better collaboration
They improve password rotation
What is a major risk associated with generic device accounts?
Network congestion
They automatically log out users
Default passwords may not be changed
Incompatibility with MFA
Which account type typically has limited privileges and cannot change system configuration?
Standard user
Guest user
Service account
Superuser
What is the purpose of job rotation policies?
To enforce working hours
To reduce dependency on one employee and distribute knowledge
To increase salaries
To simplify account provisioning
What access control model is based on roles instead of individual user permissions?
Discretionary Access Control (DAC)
Role-Based Access Control (RBAC)
Mandatory Access Control (MAC)
Rule-Based Access Control
What protocol is commonly used for federated identity and supports XML assertions?
SAML
TLS
OAuth
LDAP
What type of training might simulate phishing emails to test employee awareness?
Clean desk audits
CBT
Phishing campaigns
Bring your own device training
What policy prevents users from reusing old passwords?
Minimum password length
Password history and reuse policy
Complexity policy
Account lockout policy
What kind of control is enforced through access based on subject, object, and environment attributes?
Attribute-Based Access Control (ABAC)
Discretionary Access Control (DAC)
Role-Based Access Control (RBAC)
Mandatory Access Control (MAC)
What type of identity is managed by an external provider and used across multiple services?
Guest identity
Shared account
Federated identity
Role-based user
What ensures that an account cannot be used even if credentials are correct, unless re-enabled manually?
Account lockout
Geolocation fencing
Password reset
Account disablement
What is a common issue with overdependence on perimeter security in network design?
It improves internal segmentation
t prevents man-in-the-middle attacks
It leaves internal systems unprotected
It increases password complexity
What type of topology isolates systems with similar security requirements?
Mesh
Star
Zone-based
Tree
What should be avoided in DMZ configurations for security reasons?
Use of VLANs
Allowing direct communications through the DMZ
Use of proxies
Using minimal services on bastion hosts
What type of device is typically placed in a DMZ to interface with the internet?
Proxy server
Bastion host
Authentication server
Endpoint firewall
What issue does MAC flooding cause on a switch?
Disables STP
Forces the switch into broadcast mode
Overloads firewall policies
Enables SSL stripping
What protocol is used to map IP addresses to MAC addresses?
ICMP
DNS
ARP
STP
What is the purpose of the Spanning Tree Protocol (STP)?
Prevent ARP poisoning
Prevent IP spoofing
Prevent network loops
Prevent MAC flooding
Which feature disables ports if STP traffic is detected on access ports?
DHCP snooping
MAC filtering
Portfast
BPDU guard
What wireless security protocol introduced Simultaneous Authentication of Equals (SAE)?
WPA
WPA2
WPA3
WEP
What is the benefit of using VLANs in a network design?
Faster internet speeds
Increased signal range
Segmentation of broadcast domains
Simplified IP addressing
What does the zero trust model emphasize in network security?
Open access to internal resources
Reliance on perimeter defense
Trust but verify policy
Continuous authentication and microsegmentation
