wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

4.3 & 4.4 Application Security Quiz

Total questions: 20

Worksheet time: 10mins

Name
Class
Date
1.

What is the main function of a bug bounty program?

a)

Reward researchers for finding vulnerabilities

b)

Monitor for stolen data

c)

Simulate attacks to find flaws

d)

Provide paid threat intelligence

2.

Why is it important to prioritize vulnerabilities during analysis?

a)

To focus on critical vulnerabilities first

b)

To avoid false positives/negatives

c)

To assign unique IDs to each flaw

d)

To monitor for stolen data

3.

Which of the following best describes "exposure factor"?

a)

The percentage of asset value lost if exploited

b)

The name of the vulnerability

c)

The process of applying vendor updates

d)

The method of isolating vulnerable systems

4.

What is one of the key steps in reporting after addressing a security issue?

a)

Document findings, actions taken, and lessons learned

b)

Ignore the incident

c)

Only inform end users

d)

Delete all related logs

5.

Which of the following is NOT a typical computing resource monitored for security purposes?

a)

CPU, memory, disk, uptime

b)

Errors, crashes, performance

c)

Network traffic, device status

d)

User interface design

6.

Which key monitoring activity involves collecting logs from all systems in one place?

a)

Log aggregation

b)

Verification

c)

Audit

d)

Application monitoring

7.

If an organization wants to use reports for risk assessments and audits, which process are they engaging in?

a)

Reporting

b)

Verification

c)

Log aggregation

d)

Application monitoring

8.

If a security system needs to summarize activity for analysis, which function is being performed?

a)

Reporting

b)

Scanning

c)

Alert tuning

d)

Quarantine

9.

What is the main role of SIEM in a security environment?

a)

Central log analysis

b)

Isolate infected devices

c)

Reduce false positives

d)

Detect and remove malware

10.

What is the purpose of archiving in security operations?

a)

Store logs for compliance and forensics

b)

Notify when thresholds are exceeded

c)

Reduce false positives

d)

Isolate infected devices

11.

Which tool aggregates logs and creates alerts?

a)

SIEM

b)

NetFlow

c)

Vulnerability scanner

d)

SNMP trap

12.

IDS didn’t detect an attack. What should be updated to detect it next time?

a)

Signatures

b)

Trends

c)

Honeypot

d)

Reputation

13.

Which of the following is NOT a key monitoring tool mentioned in the summary checklist?

a)

SIEM

b)

DLP

c)

IDS

d)

Firewall

14.

What is a compensating control in cybersecurity?

a)

A primary security measure

b)

An alternative security measure when the primary isn't feasible

c)

A method for scoring vulnerabilities

d)

A type of firewall log

15.

If you want to investigate the source IP of a port scan, what should you check?

a)

CVSS reports

b)

Firewall logs

c)

DLP alerts

d)

SIEM dashboards

16.

How does the Common Vulnerability Scoring System (CVSS) assist organizations?

a)

By assigning unique IDs to vulnerabilities

b)

By rating the severity of vulnerabilities

c)

By preventing data loss

d)

By detecting network intrusions

17.

Why might an organization use a compensating control?

a)

To replace a failed firewall

b)

When the primary security measure isn't feasible

c)

To score vulnerabilities

d)

To detect intrusions

18.

What is the primary purpose of the Security Content Automation Protocol (SCAP)?

a)

To automate security content and vulnerability management

b)

To provide internet access to users

c)

To encrypt sensitive data

d)

To monitor network traffic

19.

What does the acronym ALE stand for in risk management?

a)

Annualized Loss Expectancy

b)

Automated Log Encryption

c)

Advanced Learning Environment

d)

Application Layer Encryption

20.

If a company wants to measure how often a specific risk is expected to occur in a year, which metric should they use?

a)

Annualized Rate of Occurrence (ARO)

b)

Single Loss Expectancy (SLE)

c)

Recovery Time Objective (RTO)

d)

Security Content Automation Protocol (SCAP)