Font size
WorksheetsNetwork Security 1 mod SIB-23-1
Total questions: 90
Worksheet time: 50mins
Which layer of the TCP/IP model is responsible for addressing and routing packets?
Application Layer
Transport Layer
Internet Layer
Network Access Layer
Session Layer
Which OSI layer does a Packet Filtering Firewall operate at?
Layer 7 – Application
Layer 3 – Network
Layer 4 – Transport
Layer 2 – Data Link
Layer 1 – Physical
What is the main advantage of a Stateful Inspection Firewall?
Very high speed with no resource usage
Works only at the Application Layer
Tracks active connections and prevents spoofed packets
Does not keep any connection records
Only filters traffic by IP address
Which access control model grants permissions based on a user's position in an organization?
Mandatory Access Control (MAC)
Discretionary Access Control (DAC)
Role-Based Access Control (RBAC)
Time-Based Access Control
Location-Based Access Control
What does encryption do?
It deletes data permanently
It converts ciphertext into plain text
It converts plain text into unreadable form
It makes data public for everyone
It compresses the size of data
Which encryption method uses two different keys?
Symmetric encryption
Substitution cipher
Hashing
Asymmetric encryption
Caesar Cipher
What is the main use of a hash function?
Encrypting and decrypting data
Compressing files
Storing and verifying passwords or file integrity
Hiding encryption keys
Translating data into another language
Which of the following best describes the main goal of network security?
To make data transmission faster
To preserve the confidentiality, integrity, and availability of data
To block all internet access
To collect user information for analysis
To increase Wi-Fi range
What does the “C” in the CIA triad stand for?
Connection
Confidentiality
Control
Configuration
Cryptography
Which of the following is an example of maintaining Integrity in a network?
Using HTTPS to encrypt traffic
Making regular data backups
Applying digital signatures and checksums
Limiting Wi-Fi access with a password
Blocking unknown IP addresses
What is an example of a threat actor?
Firewall
Antivirus software
Malware operator or insider
Security update
Network cable
Which term describes a weakness that an attacker can exploit?
Asset
Threat
Vulnerability
Control
Risk
What does WPA3 primarily protect in the CIA triad?
Availability
Integrity
Confidentiality
Authentication
Risk
Which control helps protect against DoS/DDoS attacks?
Strong passwords
WPA3 encryption
Rate limiting and redundancy
Using HTTPS
File hashing
What is the primary function of an Intrusion Detection System (IDS)?
To detect suspicious activity and generate alerts
To automatically block all incoming traffic
To encrypt network traffic
To replace the firewall
To manage user authentication
Which detection method relies on comparing network traffic against a database of known attack patterns?
Signature-based
Anomaly-based
Heuristic-based
Behavior-based
Policy-based detection
How does an IPS typically affect network traffic?
It is placed inline and may slightly slow down traffic
It has no impact on traffic speed
It encrypts all traffic, causing significant delay
It only monitors traffic out-of-band
It analyzes traffic after it reaches the destination
Which of the following is a key advantage of Snort?
It is a powerful, open-source IDS/IPS
It is a proprietary, expensive system
It does not require any configuration.
It can only function as a packet sniffer
It is available only for Windows systems
What is a major disadvantage of an anomaly-based IDS?
A higher rate of false positives
Inability to detect new attacks
It requires no training period
It only works with encrypted traffic
It consumes almost no system resources
Which definition best describes malware?
Software that helps users organize their files efficiently
Software that causes random pop-ups but does not damage data
Software intentionally created to damage systems, steal data, or disrupt networks in various harmful ways
A temporary tool used for testing system vulnerabilities
An application that protects devices from online threats
What does a computer worm do?
It hides within image files and activates only when opened
It copies documents and sends them to hackers over email
It replicates itself and spreads across computer networks automatically, consuming bandwidth and slowing systems.
It monitors user behavior to collect login information
It updates operating systems without user permission
What makes a Trojan different from a virus?
It can infect files only after being connected to the internet.
It spreads automatically through local networks
It disguises itself as legitimate software but secretly performs malicious actions once installed on the victim’s system.
It replaces operating system files with fake ones.
It is only found on mobile devices and tablets
What does ransomware do?
It shows ads and pop-ups to generate income for the attacker.
It modifies hardware settings to cause overheating
It encrypts important files on a victim’s device and demands payment, often in cryptocurrency, to restore access
It records everything typed on the keyboard
It changes system settings to hide unwanted programs
What is a Zero-day attack?
A cyberattack that lasts less than twenty-four hours
A type of attack that targets antivirus databases before they update
An exploitation of an undiscovered vulnerability that developers and security vendors have not yet patched or identified
A planned attack that occurs on the day software is released
A network test performed by ethical hackers
Which of the following statements best describes the function of a firewall?
Scans the system for viruses
Filters incoming and outgoing network traffic according to defined rules
Encrypts data during transmission over the network
Stores data backups
Controls antivirus signature updates
What does the TLS
Used for data compression before transmission
Provides routing of IP packets
Provides encryption and authentication of data during transmission.
Analyzes network traffic for malicious activity
Manages the distribution of IP addresses among network devices
What does a computer virus do?
Encrypts files and demands ransom
Spreads automatically through the network
Attaches itself to legitimate programs and infects other files
Monitors user activity and sends data to hackers
Displays advertisements on the screen
Which of the following is an example of ransomware?
Conficker
Pegasus
ILOVEYOU
WannaCry
Stuxnet
What is authentication?
Encrypting files
Verifying user identity
Creating user accounts
Blocking websites
Managing passwords
Which method uses fingerprints or face?
Password-based
Token-based
Biometric
Smart card
Email code
What does Access Control do?
Monitors traffic
Grants or denies access
Repairs system errors
Updates software
Encrypts files
Which control is used in military systems?
RBAC
DAC
MAC
UAC
PAC
Main advantage of MFA?
Cheaper
Easier
More secure
Uses one password
Works offline only
How many layers does the TCP/IP model have?
3
4
5
6
7
Which protocol is used for secure remote access to a server?
FTP
HTTP
SMTP
SSH
SNMP
Which protocol provides encryption and authentication for websites?
HTTP
FTP
HTTPS
ARP
POP3
Which protocol operates at the Transport Layer of the TCP/IP model?
IP
ICMP
TCP
DNS
HTTP
What is the main function of the TLS protocol?
Data compression
Routing optimization
Encrypting and protecting transmitted data
File transfer
Network discovery
Which OSI layer does a Packet Filtering Firewall operate on?
Layer 2
Layer 3(Network)
Layer 4
Layer 7
Layer 1
Which firewall type keeps track of active connections in a “state table”?
Packet Filtering Firewall
Stateful Inspection Firewall
Application Firewall
Hardware Firewall
Software Firewall
What is an example of a Hardware Firewall?
Windows Firewall
Linux iptables
FortiGate
Proxy firewall
SSH
What is one disadvantage of an Application Firewall?
Cannot filter packets
Low CPU usage
Needs frequent updates and maintenance
Cannot inspect content
Only works on Layer 3
Which of the following actions can a firewall perform?
Play videos
Block unauthorized access
Install software
Delete files
Print documents
What is a firewall?
A program to speed up the internet
A system that controls network traffic based on security rules
An antivirus for a computer
A backup program
A system for storing logs
Which type of firewall works at the Application Layer (Layer 7) and can inspect the content of data?
Packet Filtering Firewall
Stateful Inspection Firewall
Application Firewall
Hardware Firewall
Software Firewall
What is an advantage of a stateful firewall compared to a simple packet filter?
Low CPU usage
Instant filtering without checking connection states
Tracks connection state and prevents spoofed packets
Ignores IPs and ports
Works only at the application level
What does a modern Next Generation Firewall (NGFW) do?
Only filters packets by IP
Provides packet filtering, application control, IDS/IPS, and deep packet inspection
Is only a software firewall
Ignores all HTTPS connections
Allows all users full network access
Which layer of the TCP/IP model is responsible for addressing and routing packets?
Application Layer
Transport Layer
Internet Layer
Network Access Layer
Session Layer
Which protocol is used for secure remote login and command execution?
HTTP
FTP
SSH
Telnet
DNS
What does HTTPS add compared to regular HTTP?
Uses UDP instead of TCP
Adds encryption through TLS
Transfers data faster
Works without ports
Sends data in plain text
Which protocol is the successor of SSL and provides encryption T and authentication?
TLS
SSH
TCP
HTTP
ICMP
Name the CIA triad:
Confidentiality, Integrity, Availability
Casualty, Integrity, Eventuality
Confidentiality, Identification, Authentication
Compliance, Integrity, Accessibility
Communication, Information, Analysis
What is Network Security?
Practices and technologies that preserve the confidentiality, integrity, and availability (CIA) of data in transit and networked systems
Methods used only to speed up data transmission across networks
Methods used only to speed up data transmission across networks
Physical measures to protect network cables and hardware from theft
Techniques for improving website design and user experience
Which of the following best defines a vulnerability?
A valuable data or service that must be protected
A weakness an attacker can exploit to cause harm
Any unauthorized entity that attempts to access the network
The impact caused by an incident on system availability
A technology that prevents eavesdropping on open Wi-Fi
Which element of the CIA triad is primarily supported by backups and redundancy?
Confidentiality
Integrity
Availability
Authentication
Accountability
What is the main goal of cryptography?
To delete confidential information
To protect and ensure the integrity of information
To slow down data transmission
To compress files efficiently
To detect computer viruses
What is encryption?
The process of verifying user identity
The process of converting ciphertext into plain text
The process of converting plain text into unreadable ciphertext
The process of compressing large files
The process of deleting sensitive data
What is the main weakness of symmetric encryption?
It uses complex algorithms
It requires too much memory
It is too slow for large data
The key distribution problem
It cannot encrypt numbers
In asymmetric encryption, which key is used to decrypt data?I
Secret key
Public key
Random key
Private key
Shared session key
Which of the following algorithms is an example of symmetric encryption?
RSA
AES
SHA-256
MD5
Diffie–Hellman
What is a key feature of a hash function?
It can be easily reversed
It uses a private and public key
It produces a fixed-size output and cannot be reversed
It slows down encryption
It requires symmetric algorithms
What do digital signatures ensure?
Confidentiality only
Data compression
File deletion protection
Authenticity and integrity of a message
Fast encryption speed
Which of the following best describes symmetric encryption?
Uses a pair of public and private keys
Uses one key for both encryption and decryption
Does not require any key
Is slower but more secure
Is only used for digital signatures
Which algorithm is an example of asymmetric encryption?
AES
DES
Blowfish
RSA
SHA-1
Which of the following is not a use of hash functions?
Password storage
File integrity verification
Digital signatures
Data encryption
Blockchain verification
What happens when Alice encrypts a message using Bob’s public key in RSA?
Everyone can decrypt it
Only Alice can decrypt it
Only Bob can decrypt it
The message becomes a hash
It automatically verifies the sender
Which of the following best describes a signature-based IDS?
Detects attacks by comparing network traffic to known patterns of malicious activity
Uses machine learning to detect previously unknown attacks
Blocks all incoming traffic by default
Relies on system administrators to manually identify every intrusion
Detects only internal network misconfigurations
What is the main advantage of an anomaly-based IDS compared to a signature-based IDS?
It uses fewer system resources
It detects zero-day attacks by recognizing abnormal behavior
It requires no initial configuration
It never produces false positives
It only analyzes encrypted traffic
Which of the following devices is primarily used to filter and control network traffic based on security rules?
Router
Switch
Firewall
Modem
Hub
What is the main purpose of a VPN (Virtual Private Network)?
To increase internet speed
To provide secure communication over public networks
To host web applications
To detect malware
To store encrypted passwords
What are the key characteristics of an Anomaly-Based IDS?
It requires frequent signature updates to be effective
It can detect zero-day attacks
It has a very low false positive rate
It learns a baseline of normal network behavior
It is ineffective against any new threats
Which of the following threats are used for hidden user surveillance?
Spyware
Trojan
Worm
Rootkit
Ransomware
Select two correct statements about IDS/IPS systems:
IDS can block suspicious traffic
IPS can not only detect but also prevent an attack
IDS/IPS analyze network packets and system logs.
IDS operates only at the application layer.
IPS is used exclusively for data encryption
About RBAC
Permissions are linked to roles
Users get random access
It simplifies administration
Used only by hackers
Roles are based on hardware
Which of the following protocols provide secure communication over the Internet?
HTTPS
SSH
FTP
Telnet
DES
Which of the following are functions of a stateful firewall?
Track connection state
Block all HTTP traffic
Prevent spoofed packets
Filter local files
Develop web pages
Which of the following statements about Snort are true?
Snort is primarily a firewall application
Snort can function as both IDS and IPS
Snort uses rule-based signatures to detect threats
Snort is a commercial-only tool with no open-source version
Snort cannot perform packet logging
Which two protocols are commonly used to secure web communications?
HTTP
FTP
HTTPS
TLS
SMTP
Which of the following are examples of authentication factors?
Password
Username
Fingerprint
Email address
IP address
Which two measures help prevent unauthorized access to a corporate network?
Using strong passwords
Disabling all firewalls
Applying access control lists (ACLs)
Allowing open Wi-Fi networks
Sharing admin credentials
Which of the following statements are true about the SSH protocol?
It is used for secure remote login and management.
It operates on port 22
It uses TLS for encryption
It transfers data in plain text.
It supports key-based authentication without a password
Which of the following measures are effective against malware?
Regularly updating antivirus software
Using firewalls
Downloading files from any source.
Implementing IDS/IPS systems
Ignoring security updates
Which of the following types belong to malware?
Viruses
Worms
Trojans
Browsers
Ransomware
Which of the following are the main functions of a firewall?
Traffic filtering by IP and port
Web development
Access control for trusted users
Sending emails automatically
Protection against attacks and malware
Which functions are provided by secure protocols (HTTPS, SSH, TLS)?
Encryption
Data compression
Authentication
Zero-latency transmission
Data integrity
Which of the following are examples of common network threats?
Eavesdropping/sniffing
Spoofing
DDoS (Denial of Service)
Data compression
VPN tunneling
Which of the following statements about cryptographic tools are correct?
Symmetric encryption is faster than asymmetric
Asymmetric encryption solves the key distribution problem
Hash functions can be reversed easily
Digital signatures prove message authenticity
Hash functions use two keys
Which of the following are true about Suricata?
It supports multi-threading for high performance
It cannot read Snort rule sets
It performs protocol identification and file extraction
It is developed and maintained by Cisco Systems
It includes native support for JSON output and EVE logging
Which of the following are common types of network attacks?
Phishing
DDoS
SQL Injection
DHCP configuration
Subnetting
Which security practices help protect network infrastructure?
Regular software updates
Disabling unnecessary network services
Using intrusion detection and prevention systems (IDS/IPS)
Allowing default passwords
Ignoring access logs
