wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

IoT and Security Concepts Quiz

Total questions: 27

Worksheet time: 14mins

Name
Class
Date
1.

Which characteristic of IoT devices most increases the overall attack surface of a network?

a)

They use only wired connections

b)

They are typically isolated from the internet

c)

They often have weak default security settings

d)

They cannot be remotely managed

2.

A company deploys smart lighting and HVAC systems in its office building. Soon after, unauthorized temperature changes are noticed. Which security strategy BEST prevents this issue?

a)

Using only consumer-grade IoT devices

b)

Connecting building systems directly to the production LAN

c)

Creating isolated network segments for building automation devices

d)

Allowing all traffic to pass through by default

3.

Antion works for a water treatment facility and needs to ensure that pumps and sensors located miles away are operating correctly at all times. Which industrial system is primarily responsible for real-time monitoring and control of this remote equipment?

a)

IDS

b)

SCADA

c)

SIEM

d)

NAS

4.

A manufacturing plant connects its ICS network to the corporate IT network for easier monitoring. Soon after, attackers exploit vulnerabilities to access critical systems. Which action would BEST reduce this risk?

a)

Allow ICS devices full access to the internet

b)

Isolate management traffic and monitor cross-network links

c)

Disable all access controls

d)

Replace Ethernet with coaxial cabling

5.

Damian is setting up a smart home system with various IoT devices, such as smart thermostats and security sensors. He notices that standard networking solutions (like traditional Wi-Fi or Ethernet) are not always effective for these devices. Why might this be the case?

a)

IoT devices never use IP addressing

b)

IoT devices require extremely high bandwidth

c)

IoT devices may have unique connectivity requirements

d)

IoT devices only operate offline

6.

A company installs multiple consumer-grade IoT devices in its network. Within weeks, unusual outbound traffic is detected. What is the MOST likely reason?

a)

Devices are over-patched

b)

Default admin interfaces were left unsecured

c)

Devices were placed in a DMZ

d)

The network had too many VLANs

7.

Which mitigation strategy BEST addresses the increased attack surface created by adding IoT devices to a network?

a)

Disable all encryption

b)

Conduct regular audits and segmentation

c)

Allow all inbound traffic

d)

Share admin accounts across devices

8.

Which access control model allows the OWNER of a resource to determine who can access it?

a)

Role-Based Access Control (RBAC)

b)

Mandatory Access Control (MAC)

c)

Discretionary Access Control (DAC)

d)

Attribute-Based Access Control (ABAC)

9.

A company assigns permissions based on employees’ job titles such as 'HR,' 'Manager,' or 'Technician.' Which access control model is being used?

a)

DAC

b)

RBAC

c)

MAC

d)

ABAC

10.

An IT administrator can create new user accounts, reset passwords, and modify group memberships. To prevent this account from being abused, the security team implements a system that controls, monitors, and audits privileged accounts. Which term BEST describes this system?

a)

Separation of duties

b)

PAM

c)

Least privilege

d)

NAC

11.

Which principle ensures a user only has the minimum permissions required to complete their job tasks?

a)

PAM

b)

Least Privilege

c)

Separation of Duties

d)

Defense in Depth

12.

An employee in accounting can approve vendor payments. Another employee is responsible for entering vendor invoices. This setup prevents one individual from both entering AND approving transactions. Which security concept does this represent?

a)

Defense in depth

b)

Privileged account

c)

Separation of duties

d)

RBAC

13.

Which layer of the Defense in Depth model includes VLANs and IDS/IPS systems?

a)

Perimeter

b)

Internal Network

c)

Host

d)

Application

14.

A network administrator notices unauthorized devices connecting to office switch ports. To prevent this, they implement 802.1X and configure MAC filtering. Which security goal are they addressing?

a)

Firewall configuration

b)

Port Security

c)

Content filtering

d)

Application hardening

15.

Which element of the CIA triad ensures that information is only accessible to authorized users?

a)

Availability

b)

Integrity

c)

Confidentiality

d)

Accountability

16.

A company wants to assess how a DDoS attack would affect its mission-critical functions. Which risk management process should they use?

a)

Technical audit

b)

Business Impact Analysis (BIA)

c)

Separation of duties

d)

GDPR Compliance

17.

Which type of security audit focuses on verifying adherence to laws and regulations such as GDPR or PCI DSS?

a)

Risk-based audit

b)

Technical audit

c)

Compliance audit

d)

Vulnerability assessment

18.

A security team scans a server to compare its configuration to the company’s baseline and identify missing patches. What process are they performing?

a)

Deception technologies

b)

Vulnerability assessment

c)

Data encryption

d)

Access control

19.

Which regulatory framework focuses on protecting personal data and giving individuals data rights in the European Union?

a)

PCI DSS

b)

GDPR

c)

SOX

d)

HIPAA

20.

What is the primary purpose of encryption?

a)

Improve system availability

b)

Prevent data deletion

c)

Ensure data confidentiality

d)

Monitor user access

21.

Which cryptographic method is commonly used for password storage and data integrity verification?

a)

Symmetric encryption

b)

Asymmetric encryption

c)

Cryptographic hashing

d)

Tokenization

22.

An attacker exploits a vulnerability that developers were not aware of and had no patch for. What type of vulnerability is this?

a)

Misconfiguration

b)

Zero-day

c)

Legacy exploit

d)

Insider threat

23.

Which state of data is MOST associated with TLS or HTTPS protection?

a)

Data at rest

b)

Data in transit

c)

Data in use

d)

Data archived

24.

A security team deploys fake servers that appear vulnerable to attract attackers and analyze their techniques. What technology is being used?

a)

ACLs

b)

IDS

c)

Honeypots

d)

Firewalls

25.

Imagine Andrew and David have set up a small office network. What is the primary function of a firewall they installed to protect their network?

a)

To increase internet speed.

b)

To serve as a physical barrier against network intrusion.

c)

To monitor and control incoming and outgoing network traffic based on predetermined security rules.

d)

To detect and remove viruses and other malware.

26.

What does AUP stand for?

a)

Autherised User Policy

b)

Acceptable Usage Policy

c)

Anonymous User Policy

d)

Average Usage Policy

27.

What is a limitation of a firewall in an IT network?

a)

It can protect against all types of cyber threats

b)

It cannot prevent insider attacks

c)

It ensures complete data encryption

d)

It eliminates the need for other security measures