NEW
Font size
WorksheetsCybersecurity and IT Infrastructure Quiz
Total questions: 20
Worksheet time: 10mins
Your company is migrating to a Platform as a Service (PaaS) model to reduce infrastructure overhead. Which of the following accurately describes a key difference in security responsibilities between PaaS and Infrastructure as a Service (IaaS)?
In PaaS, the provider secures applications and OS; in IaaS, the customer secures both.
In IaaS, the customer secures hardware and apps; in PaaS, the provider secures everything.
In both models, the customer is responsible for the entire stack.
In PaaS, the customer secures the infrastructure; in IaaS, the provider manages security.
A network engineer is choosing between traditional infrastructure and SDN. Which of the following best highlights a security advantage of SDN?
SDN lacks segmentation, making it less secure than traditional networking.
Traditional networks are more secure due to static configurations.
SDN enables centralized control and real-time policy enforcement.
Both models offer the same level of security.
Your team is deciding between containerization and virtualization. Which option provides stronger hardware-level isolation?
Containerization, due to app-level segregation
Virtualization, via hypervisor-based separation
Both are equally secure
Containerization, because each app runs in a VM
Which of the following is a primary concern when deploying IoT devices in an enterprise environment?
Better scalability than traditional systems
Advanced encryption makes them more secure
Easier patch management
Limited security features make them more vulnerable
A company is implementing a solution to ensure uptime during server failure. What is the main difference between load balancing and clustering?
Load balancing spreads traffic; clustering ensures failover with grouped servers.
Clustering spreads traffic; load balancing enables failover.
They’re interchangeable terms.
Clustering requires geo-dispersed nodes; load balancing replicates data.
A company hires an external auditor to validate compliance with government regulations. What type of audit is being conducted?
Internal Audit
Self-Assessment
Regulatory Examination
Technical Assessment
An employee receives an email requesting login credentials. They’re unsure if it’s legitimate. What should they do?
Click the link and verify credentials
Forward it to a coworker
Report it to IT/security
Reply to the sender for confirmation
Your organization wants to prevent threats from spreading laterally in the network. Which technique helps isolate sensitive areas?
Encryption
Segmentation
Access Control List
Application Allow List
To reduce attack surface and run only necessary software, which technique should be applied?
Least Privilege
Decommissioning
Hardening Techniques
Monitoring
An organization uses logs to track user activity on the database. What part of the AAA model does this represent?
Authentication
Authorization
Accounting
Attestation
Your company adopts a multi-cloud approach to reduce dependency on a single vendor. What is the main benefit of this strategy?
Simplifies management by centralizing data backups
Improves resilience and leverages strengths of multiple providers
Reduces complexity by consolidating services under one cloud
Centralizes monitoring, increasing network performance
A security consultant is hired to simulate an attack and assess weaknesses. Their first step is gathering information without engaging the target systems. What is this phase called?
Exploitation
Enumeration
Reconnaissance
Vulnerability scanning
An organization implements a policy ensuring users can only access the resources required for their job functions. What principle is being enforced?
Segmentation
Least Privilege
Zero Trust
Authentication
Your IT department disables unused ports and protocols and restricts software installations. What mitigation technique is being applied?
Isolation
Application Allow List
Hardening
Configuration Enforcement
An organization lacks the ability to implement multi-factor authentication. Instead, they enforce strict password policies and monitoring. What type of control is this?
Preventive
Compensating
Directive
Corrective
A user logs into the company VPN with valid credentials. What AAA function is this?
Authorization
Authentication
Accounting
Identification
A company rolls out a program that includes simulated phishing attacks, training sessions, and regular reminders about social engineering. What is this an example of?
Threat Intelligence Sharing
Incident Response
Security Awareness Program Execution
Risk Mitigation Testing
Your company retires old hardware, ensuring all data is wiped and the devices are securely disposed of. What security practice does this represent?
Segmentation
Decommissioning
Patching
Auditing
A company rolls out a formal policy requiring all employees to complete annual security training. What type of control is this?
Preventive
Corrective
Directive
Technical
Which of the following best describes a security challenge of Real-Time Operating Systems (RTOS) in industrial environments?
RTOS have strong built-in firewalls
RTOS are updated frequently, minimizing risks
RTOS often lack modern security features due to limited resources
RTOS only run in isolated test labs and pose no real-world risk
