wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Network Security 1 mod SIB-23-1

Total questions: 90

Worksheet time: 50mins

Name
Class
Date
1.

Which layer of the TCP/IP model is responsible for addressing and routing packets?

a)

  Application Layer

b)

  Transport Layer

c)

Internet Layer

d)

Network Access Layer

e)

  Session Layer

2.

Which OSI layer does a Packet Filtering Firewall operate at?

a)

Layer 7 – Application

b)

Layer 3 – Network

c)

Layer 4 – Transport

d)

  Layer 2 – Data Link

e)

Layer 1 – Physical

3.

What is the main advantage of a Stateful Inspection Firewall?

a)

   Very high speed with no resource usage

b)

    Works only at the Application Layer

c)

Tracks active connections and prevents spoofed packets

d)

Does not keep any connection records

e)

Only filters traffic by IP address

4.

Which access control model grants permissions based on a user's position in an organization?

a)

Mandatory Access Control (MAC)

b)

Discretionary Access Control (DAC)

c)

Role-Based Access Control (RBAC)

d)

Time-Based Access Control

e)

Location-Based Access Control

5.

What does encryption do?

a)

It deletes data permanently

b)

It converts ciphertext into plain text

c)

It converts plain text into unreadable form

d)

It makes data public for everyone

e)

It compresses the size of data

6.

Which encryption method uses two different keys?

a)

Symmetric encryption

b)

Substitution cipher

c)

Hashing

d)

Asymmetric encryption

e)

Caesar Cipher

7.

What is the main use of a hash function?

a)

Encrypting and decrypting data

b)

Compressing files

c)

Storing and verifying passwords or file integrity

d)

Hiding encryption keys

e)

Translating data into another language

8.

Which of the following best describes the main goal of network security?

a)

To make data transmission faster

b)

To preserve the confidentiality, integrity, and availability of data

c)

To block all internet access

d)

To collect user information for analysis

e)

To increase Wi-Fi range

9.

What does the “C” in the CIA triad stand for?

a)

Connection

b)

Confidentiality

c)

Control

d)

Configuration

e)

Cryptography

10.

Which of the following is an example of maintaining Integrity in a network?

a)

Using HTTPS to encrypt traffic

b)

Making regular data backups

c)

Applying digital signatures and checksums

d)

Limiting Wi-Fi access with a password

e)

Blocking unknown IP addresses

11.

What is an example of a threat actor?

a)

Firewall

b)

Antivirus software

c)

Malware operator or insider

d)

Security update

e)

Network cable

12.

Which term describes a weakness that an attacker can exploit?

a)

Asset

b)

Threat

c)

Vulnerability

d)

Control

e)

Risk

13.

What does WPA3 primarily protect in the CIA triad?

a)

Availability

b)

Integrity

c)

Confidentiality

d)

Authentication

e)

Risk

14.

Which control helps protect against DoS/DDoS attacks?

a)

Strong passwords

b)

WPA3 encryption

c)

Rate limiting and redundancy

d)

Using HTTPS

e)

File hashing

15.

What is the primary function of an Intrusion Detection System (IDS)?

a)

To detect suspicious activity and generate alerts

b)

To automatically block all incoming traffic

c)

To encrypt network traffic

d)

To replace the firewall

e)

  To manage user authentication

16.

Which detection method relies on comparing network traffic against a database of known attack patterns?

a)

Signature-based

b)

Anomaly-based

c)

Heuristic-based

d)

Behavior-based

e)

  Policy-based detection

17.

How does an IPS typically affect network traffic?

a)

It is placed inline and may slightly slow down traffic

b)

It has no impact on traffic speed

c)

It encrypts all traffic, causing significant delay

d)

It only monitors traffic out-of-band

e)

It analyzes traffic after it reaches the destination

18.

Which of the following is a key advantage of Snort?

a)

It is a powerful, open-source IDS/IPS

b)

It is a proprietary, expensive system

c)

It does not require any configuration.

d)

It can only function as a packet sniffer

e)

It is available only for Windows systems

19.

What is a major disadvantage of an anomaly-based IDS?

a)

A higher rate of false positives

b)

Inability to detect new attacks

c)

It requires no training period

d)

It only works with encrypted traffic

e)

It consumes almost no system resources

20.

Which definition best describes malware?

a)

Software that helps users organize their files efficiently

b)

Software that causes random pop-ups but does not damage data

c)

Software intentionally created to damage systems, steal data, or disrupt networks in various harmful ways

d)

A temporary tool used for testing system vulnerabilities

e)

An application that protects devices from online threats

21.

What does a computer worm do?

a)

It hides within image files and activates only when opened

b)

It copies documents and sends them to hackers over email

c)

It replicates itself and spreads across computer networks automatically, consuming bandwidth and slowing systems.

d)

It monitors user behavior to collect login information

e)

It updates operating systems without user permission

22.

What makes a Trojan different from a virus?

a)

It can infect files only after being connected to the internet.

b)

It spreads automatically through local networks

c)

It disguises itself as legitimate software but secretly performs malicious actions once installed on the victim’s system.

d)

It replaces operating system files with fake ones.

e)

It is only found on mobile devices and tablets

23.

What does ransomware do?

a)

   It shows ads and pop-ups to generate income for the attacker.

b)

It modifies hardware settings to cause overheating

c)

It encrypts important files on a victim’s device and demands payment, often in cryptocurrency, to restore access

d)

It records everything typed on the keyboard

e)

It changes system settings to hide unwanted programs

24.

What is a Zero-day attack?

a)

A cyberattack that lasts less than twenty-four hours

b)

A type of attack that targets antivirus databases before they update

c)

An exploitation of an undiscovered vulnerability that developers and security vendors have not yet patched or identified

d)

A planned attack that occurs on the day software is released

e)

A network test performed by ethical hackers

25.

Which of the following statements best describes the function of a firewall?

a)

Scans the system for viruses

b)

Filters incoming and outgoing network traffic according to defined rules

c)

Encrypts data during transmission over the network

d)

Stores data backups

e)

Controls antivirus signature updates

26.

What does the TLS

a)

Used for data compression before transmission

b)

Provides routing of IP packets

c)

Provides encryption and authentication of data during transmission.

d)

Analyzes network traffic for malicious activity

e)

Manages the distribution of IP addresses among network devices

27.

What does a computer virus do?

a)

Encrypts files and demands ransom

b)

Spreads automatically through the network

c)

Attaches itself to legitimate programs and infects other files

d)

Monitors user activity and sends data to hackers

e)

Displays advertisements on the screen

28.

Which of the following is an example of ransomware?

a)

Conficker

b)

Pegasus

c)

ILOVEYOU

d)

WannaCry

e)

Stuxnet

29.

What is authentication?

a)

Encrypting files

b)

Verifying user identity

c)

Creating user accounts

d)

Blocking websites

e)

Managing passwords

30.

Which method uses fingerprints or face?

a)

Password-based

b)

Token-based

c)

Biometric

d)

Smart card

e)

Email code

31.

What does Access Control do?

a)

Monitors traffic

b)

Grants or denies access

c)

Repairs system errors

d)

Updates software

e)

Encrypts files

32.

Which control is used in military systems?

a)

RBAC

b)

DAC

c)

MAC

d)

UAC

e)

PAC

33.

Main advantage of MFA?

a)

Cheaper

b)

Easier

c)

More secure

d)

Uses one password

e)

Works offline only

34.

How many layers does the TCP/IP model have?

a)

3

b)

4

c)

5

d)

6

e)

7

35.

Which protocol is used for secure remote access to a server?

a)

FTP

b)

HTTP

c)

SMTP

d)

SSH

e)

SNMP

36.

Which protocol provides encryption and authentication for websites?

a)

HTTP

b)

FTP

c)

HTTPS

d)

ARP

e)

POP3

37.

Which protocol operates at the Transport Layer of the TCP/IP model?

a)

IP

b)

ICMP

c)

TCP

d)

DNS

e)

HTTP

38.

What is the main function of the TLS protocol?

a)

Data compression

b)

Routing optimization

c)

Encrypting and protecting transmitted data

d)

File transfer

e)

Network discovery

39.

Which OSI layer does a Packet Filtering Firewall operate on?

a)

Layer 2

b)

Layer 3(Network)

c)

Layer 4

d)

Layer 7

e)

Layer 1

40.

Which firewall type keeps track of active connections in a “state table”?

a)

Packet Filtering Firewall

b)

Stateful Inspection Firewall

c)

Application Firewall

d)

Hardware Firewall

e)

Software Firewall

41.

What is an example of a Hardware Firewall?

a)

Windows Firewall

b)

Linux iptables

c)

FortiGate

d)

Proxy firewall

e)

SSH

42.

What is one disadvantage of an Application Firewall?

a)

Cannot filter packets

b)

Low CPU usage

c)

Needs frequent updates and maintenance

d)

Cannot inspect content

e)

Only works on Layer 3

43.

Which of the following actions can a firewall perform?

a)

Play videos

b)

Block unauthorized access

c)

Install software

d)

Delete files

e)

Print documents

44.

What is a firewall?

a)

A program to speed up the internet

b)

A system that controls network traffic based on security rules

c)

An antivirus for a computer

d)

A backup program

e)

A system for storing logs

45.

Which type of firewall works at the Application Layer (Layer 7) and can inspect the content of data?

a)

Packet Filtering Firewall

b)

Stateful Inspection Firewall

c)

Application Firewall

d)

Hardware Firewall

e)

Software Firewall

46.

What is an advantage of a stateful firewall compared to a simple packet filter?

a)

Low CPU usage

b)

Instant filtering without checking connection states

c)

Tracks connection state and prevents spoofed packets

d)

Ignores IPs and ports

e)

Works only at the application level

47.

What does a modern Next Generation Firewall (NGFW) do?

a)

Only filters packets by IP

b)

Provides packet filtering, application control, IDS/IPS, and deep packet inspection

c)

Is only a software firewall

d)

Ignores all HTTPS connections

e)

Allows all users full network access

48.

Which layer of the TCP/IP model is responsible for addressing and routing packets?

a)

Application Layer

b)

Transport Layer

c)

Internet Layer

d)

Network Access Layer

e)

Session Layer

49.

Which protocol is used for secure remote login and command execution?

a)

HTTP

b)

FTP

c)

SSH

d)

Telnet

e)

DNS

50.

What does HTTPS add compared to regular HTTP?

a)

Uses UDP instead of TCP

b)

Adds encryption through TLS

c)

Transfers data faster

d)

Works without ports

e)

Sends data in plain text

51.

Which protocol is the successor of SSL and provides encryption T and authentication?

a)

TLS

b)

SSH

c)

TCP

d)

HTTP

e)

ICMP

52.

Name the CIA triad:

a)

Confidentiality, Integrity, Availability

b)

Casualty, Integrity, Eventuality

c)

Confidentiality, Identification, Authentication

d)

Compliance, Integrity, Accessibility

e)

Communication, Information, Analysis

53.

What is Network Security?

a)

Practices and technologies that preserve the confidentiality, integrity, and availability (CIA) of data in transit and networked systems

b)

Methods used only to speed up data transmission across networks

c)

Methods used only to speed up data transmission across networks

d)

   Physical measures to protect network cables and hardware from theft

e)

Techniques for improving website design and user experience

54.

Which of the following best defines a vulnerability?

a)

  A valuable data or service that must be protected

b)

A weakness an attacker can exploit to cause harm

c)

  Any unauthorized entity that attempts to access the network

d)

  The impact caused by an incident on system availability

e)

   A technology that prevents eavesdropping on open Wi-Fi

55.

Which element of the CIA triad is primarily supported by backups and redundancy?

a)

    Confidentiality

b)

  Integrity

c)

Availability

d)

Authentication

e)

Accountability

56.

What is the main goal of cryptography?

a)

To delete confidential information

b)

To protect and ensure the integrity of information

c)

To slow down data transmission

d)

To compress files efficiently

e)

To detect computer viruses

57.

What is encryption?

a)

The process of verifying user identity

b)

The process of converting ciphertext into plain text

c)

The process of converting plain text into unreadable ciphertext

d)

The process of compressing large files

e)

The process of deleting sensitive data

58.

What is the main weakness of symmetric encryption?

a)

It uses complex algorithms

b)

It requires too much memory

c)

It is too slow for large data

d)

The key distribution problem

e)

It cannot encrypt numbers

59.

In asymmetric encryption, which key is used to decrypt data?I

a)

Secret key

b)

Public key

c)

Random key

d)

Private key

e)

Shared session key

60.

Which of the following algorithms is an example of symmetric encryption?

a)

RSA

b)

AES

c)

SHA-256

d)

MD5

e)

Diffie–Hellman

61.

What is a key feature of a hash function?

a)

It can be easily reversed

b)

It uses a private and public key

c)

It produces a fixed-size output and cannot be reversed

d)

It slows down encryption

e)

It requires symmetric algorithms

62.

What do digital signatures ensure?

a)

Confidentiality only

b)

Data compression

c)

File deletion protection

d)

Authenticity and integrity of a message

e)

Fast encryption speed

63.

Which of the following best describes symmetric encryption?

a)

Uses a pair of public and private keys

b)

Uses one key for both encryption and decryption

c)

Does not require any key

d)

Is slower but more secure

e)

Is only used for digital signatures

64.

Which algorithm is an example of asymmetric encryption?

a)

AES

b)

DES

c)

Blowfish

d)

RSA

e)

SHA-1

65.

Which of the following is not a use of hash functions?

a)

Password storage

b)

File integrity verification

c)

Digital signatures

d)

Data encryption

e)

Blockchain verification

66.

What happens when Alice encrypts a message using Bob’s public key in RSA?

a)

Everyone can decrypt it

b)

Only Alice can decrypt it

c)

Only Bob can decrypt it

d)

The message becomes a hash

e)

It automatically verifies the sender

67.

Which of the following best describes a signature-based IDS?

a)

Detects attacks by comparing network traffic to known patterns of malicious activity

b)

Uses machine learning to detect previously unknown attacks

c)

Blocks all incoming traffic by default

d)

Relies on system administrators to manually identify every intrusion

e)

Detects only internal network misconfigurations

68.

What is the main advantage of an anomaly-based IDS compared to a signature-based IDS?

a)

It uses fewer system resources

b)

It detects zero-day attacks by recognizing abnormal behavior

c)

It requires no initial configuration

d)

It never produces false positives

e)

It only analyzes encrypted traffic

69.

Which of the following devices is primarily used to filter and control network traffic based on security rules?

a)

Router

b)

Switch

c)

Firewall

d)

Modem

e)

Hub

70.

What is the main purpose of a VPN (Virtual Private Network)?

a)

To increase internet speed

b)

To provide secure communication over public networks

c)

To host web applications

d)

To detect malware

e)

To store encrypted passwords

71.

What are the key characteristics of an Anomaly-Based IDS?

a)

It requires frequent signature updates to be effective

b)

It can detect zero-day attacks

c)

It has a very low false positive rate

d)

It learns a baseline of normal network behavior

e)

It is ineffective against any new threats

72.

Which of the following threats are used for hidden user surveillance?

a)

Spyware

b)

   Trojan

c)

   Worm

d)

Rootkit

e)

  Ransomware

73.

Select two correct statements about IDS/IPS systems:

a)

IDS can block suspicious traffic

b)

IPS can not only detect but also prevent an attack

c)

IDS/IPS analyze network packets and system logs.

d)

IDS operates only at the application layer.

e)

IPS is used exclusively for data encryption

74.

About RBAC

a)

Permissions are linked to roles

b)

Users get random access

c)

It simplifies administration

d)

Used only by hackers

e)

Roles are based on hardware

75.

Which of the following protocols provide secure communication over the Internet?

a)

HTTPS

b)

SSH

c)

FTP

d)

Telnet

e)

DES

76.

Which of the following are functions of a stateful firewall?

a)

Track connection state

b)

Block all HTTP traffic

c)

Prevent spoofed packets

d)

Filter local files

e)

Develop web pages

77.

Which of the following statements about Snort are true?

a)

Snort is primarily a firewall application

b)

Snort can function as both IDS and IPS

c)

Snort uses rule-based signatures to detect threats

d)

Snort is a commercial-only tool with no open-source version

e)

Snort cannot perform packet logging

78.

Which two protocols are commonly used to secure web communications?

a)

HTTP

b)

FTP

c)

HTTPS

d)

TLS

e)

SMTP

79.

Which of the following are examples of authentication factors?

a)

Password

b)

Username

c)

Fingerprint

d)

Email address

e)

IP address

80.

Which two measures help prevent unauthorized access to a corporate network?

a)

Using strong passwords

b)

Disabling all firewalls

c)

Applying access control lists (ACLs)

d)

Allowing open Wi-Fi networks

e)

Sharing admin credentials

81.

Which of the following statements are true about the SSH protocol?

a)

It is used for secure remote login and management.

b)

It operates on port 22

c)

It uses TLS for encryption

d)

It transfers data in plain text.

e)

It supports key-based authentication without a password

82.

Which of the following measures are effective against malware?

a)

Regularly updating antivirus software

b)

Using firewalls

c)

Downloading files from any source.

d)

Implementing IDS/IPS systems

e)

Ignoring security updates

83.

Which of the following types belong to malware?

a)

Viruses

b)

Worms

c)

Trojans

d)

Browsers

e)

Ransomware

84.

Which of the following are the main functions of a firewall?

a)

Traffic filtering by IP and port

b)

Web development

c)

Access control for trusted users

d)

Sending emails automatically

e)

Protection against attacks and malware

85.

Which functions are provided by secure protocols (HTTPS, SSH, TLS)?

a)

Encryption

b)

Data compression

c)

Authentication

d)

Zero-latency transmission

e)

Data integrity

86.

Which of the following are examples of common network threats?

a)

Eavesdropping/sniffing

b)

Spoofing

c)

DDoS (Denial of Service)

d)

    Data compression

e)

VPN tunneling

87.

Which of the following statements about cryptographic tools are correct?

a)

Symmetric encryption is faster than asymmetric

b)

Asymmetric encryption solves the key distribution problem

c)

Hash functions can be reversed easily

d)

Digital signatures prove message authenticity

e)

Hash functions use two keys

88.

Which of the following are true about Suricata?

a)

It supports multi-threading for high performance

b)

It cannot read Snort rule sets

c)

It performs protocol identification and file extraction

d)

It is developed and maintained by Cisco Systems

e)

It includes native support for JSON output and EVE logging

89.

Which of the following are common types of network attacks?

a)

Phishing

b)

DDoS

c)

SQL Injection

d)

DHCP configuration

e)

Subnetting

90.

Which security practices help protect network infrastructure?

a)

Regular software updates

b)

Disabling unnecessary network services

c)

Using intrusion detection and prevention systems (IDS/IPS)

d)

Allowing default passwords

e)

Ignoring access logs