wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Cybersecurity and IT Infrastructure Quiz

Total questions: 20

Worksheet time: 10mins

Name
Class
Date
1.

Your company is migrating to a Platform as a Service (PaaS) model to reduce infrastructure overhead. Which of the following accurately describes a key difference in security responsibilities between PaaS and Infrastructure as a Service (IaaS)?

a)

In PaaS, the provider secures applications and OS; in IaaS, the customer secures both.

b)

In IaaS, the customer secures hardware and apps; in PaaS, the provider secures everything.

c)

In both models, the customer is responsible for the entire stack.

d)

In PaaS, the customer secures the infrastructure; in IaaS, the provider manages security.

2.

A network engineer is choosing between traditional infrastructure and SDN. Which of the following best highlights a security advantage of SDN?

a)

SDN lacks segmentation, making it less secure than traditional networking.

b)

Traditional networks are more secure due to static configurations.

c)

SDN enables centralized control and real-time policy enforcement.

d)

Both models offer the same level of security.

3.

Your team is deciding between containerization and virtualization. Which option provides stronger hardware-level isolation?

a)

Containerization, due to app-level segregation

b)

Virtualization, via hypervisor-based separation

c)

Both are equally secure

d)

Containerization, because each app runs in a VM

4.

Which of the following is a primary concern when deploying IoT devices in an enterprise environment?

a)

Better scalability than traditional systems

b)

Advanced encryption makes them more secure

c)

Easier patch management

d)

Limited security features make them more vulnerable

5.

A company is implementing a solution to ensure uptime during server failure. What is the main difference between load balancing and clustering?

a)

Load balancing spreads traffic; clustering ensures failover with grouped servers.

b)

Clustering spreads traffic; load balancing enables failover.

c)

They’re interchangeable terms.

d)

Clustering requires geo-dispersed nodes; load balancing replicates data.

6.

A company hires an external auditor to validate compliance with government regulations. What type of audit is being conducted?

a)

Internal Audit

b)

Self-Assessment

c)

Regulatory Examination

d)

Technical Assessment

7.

An employee receives an email requesting login credentials. They’re unsure if it’s legitimate. What should they do?

a)

Click the link and verify credentials

b)

Forward it to a coworker

c)

Report it to IT/security

d)

Reply to the sender for confirmation

8.

Your organization wants to prevent threats from spreading laterally in the network. Which technique helps isolate sensitive areas?

a)

Encryption

b)

Segmentation

c)

Access Control List

d)

Application Allow List

9.

To reduce attack surface and run only necessary software, which technique should be applied?

a)

Least Privilege

b)

Decommissioning

c)

Hardening Techniques

d)

Monitoring

10.

An organization uses logs to track user activity on the database. What part of the AAA model does this represent?

a)

Authentication

b)

Authorization

c)

Accounting

d)

Attestation

11.

Your company adopts a multi-cloud approach to reduce dependency on a single vendor. What is the main benefit of this strategy?

a)

Simplifies management by centralizing data backups

b)

Improves resilience and leverages strengths of multiple providers

c)

Reduces complexity by consolidating services under one cloud

d)

Centralizes monitoring, increasing network performance

12.

A security consultant is hired to simulate an attack and assess weaknesses. Their first step is gathering information without engaging the target systems. What is this phase called?

a)

Exploitation

b)

Enumeration

c)

Reconnaissance

d)

Vulnerability scanning

13.

An organization implements a policy ensuring users can only access the resources required for their job functions. What principle is being enforced?

a)

Segmentation

b)

Least Privilege

c)

Zero Trust

d)

Authentication

14.

Your IT department disables unused ports and protocols and restricts software installations. What mitigation technique is being applied?

a)

Isolation

b)

Application Allow List

c)

Hardening

d)

Configuration Enforcement

15.

An organization lacks the ability to implement multi-factor authentication. Instead, they enforce strict password policies and monitoring. What type of control is this?

a)

Preventive

b)

Compensating

c)

Directive

d)

Corrective

16.

A user logs into the company VPN with valid credentials. What AAA function is this?

a)

Authorization

b)

Authentication

c)

Accounting

d)

Identification

17.

A company rolls out a program that includes simulated phishing attacks, training sessions, and regular reminders about social engineering. What is this an example of?

a)

Threat Intelligence Sharing

b)

Incident Response

c)

Security Awareness Program Execution

d)

Risk Mitigation Testing

18.

Your company retires old hardware, ensuring all data is wiped and the devices are securely disposed of. What security practice does this represent?

a)

Segmentation

b)

Decommissioning

c)

Patching

d)

Auditing

19.

A company rolls out a formal policy requiring all employees to complete annual security training. What type of control is this?

a)

Preventive

b)

Corrective

c)

Directive

d)

Technical

20.

Which of the following best describes a security challenge of Real-Time Operating Systems (RTOS) in industrial environments?

a)

RTOS have strong built-in firewalls

b)

RTOS are updated frequently, minimizing risks

c)

RTOS often lack modern security features due to limited resources

d)

RTOS only run in isolated test labs and pose no real-world risk