Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

4.5 Identity and Access Management Quiz

Total questions: 20

Worksheet time: 10mins

Name
Class
Date
1.

Which of the following is the primary purpose of Identity and Access Management (IAM)?

a)

To ensure the right people have the right access to the right resources at the right time

b)

To monitor network traffic for performance issues

c)

To create backup copies of data

d)

To manage software updates on devices

2.

Which of the following is an example of enforcing system-level policies in IAM?

a)

Using a web filter to block malicious websites

b)

Using Group Policy or SELinux

c)

Blocking unauthorized traffic with a firewall

d)

Using signatures to identify attacks

3.

Which of the following best describes the role of a firewall in IAM?

a)

Detects and prevents intrusions using signatures

b)

Blocks unauthorized traffic by enforcing access rules

c)

Enforces system-level policies like SELinux

d)

Blocks malicious websites using a centralized proxy

4.

If you are asked to select the best access control or authentication method for a scenario, which exam tip should you remember?

a)

Always choose the most expensive solution

b)

Select the method that best fits the scenario requirements

c)

Choose the method with the most features

d)

Select the method that is easiest to implement

5.

What is the primary purpose of DNS filtering in cybersecurity?

a)

Block access to known malicious domains

b)

Encrypt email messages

c)

Detect unauthorized file changes

d)

Monitor user behavior

6.

Which set of technologies is used to prevent email spoofing and phishing?

a)

SPF, DKIM, DMARC

b)

TLS, IPSec

c)

Tripwire, Wazuh

d)

UEBA tools

7.

What is the main function of file integrity monitoring tools like Tripwire and Wazuh?

a)

Detect unauthorized changes to critical files

b)

Block phishing emails

c)

Encrypt network traffic

d)

Analyze user behavior

8.

What does NAC ensure before allowing a device to connect to a network?

a)

Devices meet security standards

b)

Emails are encrypted

c)

Files are not altered

d)

User behavior is normal

9.

Which tools are examples of advanced threat detection solutions?

a)

CrowdStrike, Microsoft Defender

b)

TLS, IPSec

c)

SPF, DKIM

d)

UEBA tools

10.

A company wants to prevent phishing and malware by blocking access to certain domains. Which security control should they implement?

a)

DNS filtering

b)

File integrity monitoring

c)

DLP

d)

EDR/XDR

11.

Which term refers to verifying a user's identity before issuing credentials?

a)

Federation

b)

De-provisioning

c)

Identity proofing

d)

Permission assignments

12.

A company wants to allow users to log in once and access multiple systems without re-entering credentials. Which solution should they implement?

a)

Federation

b)

Single Sign-On (SSO)

c)

De-provisioning

d)

Permission assignments

13.

The principle of least privilege in permission assignments is important for security because it:

a)

Allows users to choose their own permissions

b)

Grants only the permissions needed for a user’s role, reducing the risk of misuse or accidental damage

c)

Grants all users administrative rights to ensure flexibility

d)

Disables accounts for terminated users

14.

What is the main principle of the "least privilege" access control model?

a)

Users can access any system at any time

b)

Users get only what they need

c)

Access is based on location

d)

Access is based on firewall rules

15.

Which of the following is an example of a biometric factor used in multifactor authentication (MFA)?

a)

Password

b)

Smart card

c)

Fingerprint

d)

Location

16.

Which of the following is NOT a factor used in multifactor authentication (MFA)?

a)

Something you know

b)

Something you have

c)

Something you want

d)

Something you are

17.

Which access control model grants access based on attributes such as user, device, or location?

a)

Role-based (RBAC)

b)

Rule-based

c)

Attribute-based (ABAC)

d)

Least privilege

18.

Which of the following is an example of a security key used for authentication?

a)

YubiKey

b)

Password

c)

Fingerprint

d)

Smart card

19.

If a system uses firewall rules to determine access, which access control model is being used?

a)

Rule-based

b)

Role-based (RBAC)

c)

Attribute-based (ABAC)

d)

Time-of-day restrictions

20.

Which of the following statements best describes Identity and Access Management (IAM)?

a)

A tool for encrypting emails

b)

A process for managing user identities and their access to resources

c)

A type of firewall

d)

A method for detecting network intrusions