NEW
Font size
WorksheetsIoT and Security Concepts Quiz
Total questions: 27
Worksheet time: 14mins
Which characteristic of IoT devices most increases the overall attack surface of a network?
They use only wired connections
They are typically isolated from the internet
They often have weak default security settings
They cannot be remotely managed
A company deploys smart lighting and HVAC systems in its office building. Soon after, unauthorized temperature changes are noticed. Which security strategy BEST prevents this issue?
Using only consumer-grade IoT devices
Connecting building systems directly to the production LAN
Creating isolated network segments for building automation devices
Allowing all traffic to pass through by default
Antion works for a water treatment facility and needs to ensure that pumps and sensors located miles away are operating correctly at all times. Which industrial system is primarily responsible for real-time monitoring and control of this remote equipment?
IDS
SCADA
SIEM
NAS
A manufacturing plant connects its ICS network to the corporate IT network for easier monitoring. Soon after, attackers exploit vulnerabilities to access critical systems. Which action would BEST reduce this risk?
Allow ICS devices full access to the internet
Isolate management traffic and monitor cross-network links
Disable all access controls
Replace Ethernet with coaxial cabling
Damian is setting up a smart home system with various IoT devices, such as smart thermostats and security sensors. He notices that standard networking solutions (like traditional Wi-Fi or Ethernet) are not always effective for these devices. Why might this be the case?
IoT devices never use IP addressing
IoT devices require extremely high bandwidth
IoT devices may have unique connectivity requirements
IoT devices only operate offline
A company installs multiple consumer-grade IoT devices in its network. Within weeks, unusual outbound traffic is detected. What is the MOST likely reason?
Devices are over-patched
Default admin interfaces were left unsecured
Devices were placed in a DMZ
The network had too many VLANs
Which mitigation strategy BEST addresses the increased attack surface created by adding IoT devices to a network?
Disable all encryption
Conduct regular audits and segmentation
Allow all inbound traffic
Share admin accounts across devices
Which access control model allows the OWNER of a resource to determine who can access it?
Role-Based Access Control (RBAC)
Mandatory Access Control (MAC)
Discretionary Access Control (DAC)
Attribute-Based Access Control (ABAC)
A company assigns permissions based on employees’ job titles such as 'HR,' 'Manager,' or 'Technician.' Which access control model is being used?
DAC
RBAC
MAC
ABAC
An IT administrator can create new user accounts, reset passwords, and modify group memberships. To prevent this account from being abused, the security team implements a system that controls, monitors, and audits privileged accounts. Which term BEST describes this system?
Separation of duties
PAM
Least privilege
NAC
Which principle ensures a user only has the minimum permissions required to complete their job tasks?
PAM
Least Privilege
Separation of Duties
Defense in Depth
An employee in accounting can approve vendor payments. Another employee is responsible for entering vendor invoices. This setup prevents one individual from both entering AND approving transactions. Which security concept does this represent?
Defense in depth
Privileged account
Separation of duties
RBAC
Which layer of the Defense in Depth model includes VLANs and IDS/IPS systems?
Perimeter
Internal Network
Host
Application
A network administrator notices unauthorized devices connecting to office switch ports. To prevent this, they implement 802.1X and configure MAC filtering. Which security goal are they addressing?
Firewall configuration
Port Security
Content filtering
Application hardening
Which element of the CIA triad ensures that information is only accessible to authorized users?
Availability
Integrity
Confidentiality
Accountability
A company wants to assess how a DDoS attack would affect its mission-critical functions. Which risk management process should they use?
Technical audit
Business Impact Analysis (BIA)
Separation of duties
GDPR Compliance
Which type of security audit focuses on verifying adherence to laws and regulations such as GDPR or PCI DSS?
Risk-based audit
Technical audit
Compliance audit
Vulnerability assessment
A security team scans a server to compare its configuration to the company’s baseline and identify missing patches. What process are they performing?
Deception technologies
Vulnerability assessment
Data encryption
Access control
Which regulatory framework focuses on protecting personal data and giving individuals data rights in the European Union?
PCI DSS
GDPR
SOX
HIPAA
What is the primary purpose of encryption?
Improve system availability
Prevent data deletion
Ensure data confidentiality
Monitor user access
Which cryptographic method is commonly used for password storage and data integrity verification?
Symmetric encryption
Asymmetric encryption
Cryptographic hashing
Tokenization
An attacker exploits a vulnerability that developers were not aware of and had no patch for. What type of vulnerability is this?
Misconfiguration
Zero-day
Legacy exploit
Insider threat
Which state of data is MOST associated with TLS or HTTPS protection?
Data at rest
Data in transit
Data in use
Data archived
A security team deploys fake servers that appear vulnerable to attract attackers and analyze their techniques. What technology is being used?
ACLs
IDS
Honeypots
Firewalls
Imagine Andrew and David have set up a small office network. What is the primary function of a firewall they installed to protect their network?
To increase internet speed.
To serve as a physical barrier against network intrusion.
To monitor and control incoming and outgoing network traffic based on predetermined security rules.
To detect and remove viruses and other malware.
What does AUP stand for?
Autherised User Policy
Acceptable Usage Policy
Anonymous User Policy
Average Usage Policy
What is a limitation of a firewall in an IT network?
It can protect against all types of cyber threats
It cannot prevent insider attacks
It ensures complete data encryption
It eliminates the need for other security measures
