wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Network and Cloud Security Quiz

Total questions: 20

Worksheet time: 10mins

Name
Class
Date
1.

Which solution BEST meets the goal of separating database servers from public-facing web servers to reduce the risk of lateral movement in case of a breach?

a)

VLAN segmentation with ACLs between zones

b)

NAT overload on the web servers

c)

Installing additional antivirus on all hosts

d)

Using only Layer 2 switches

2.

What control should be implemented to restrict physical port access to authorized devices when rogue devices are connecting to office Ethernet ports?

a)

802.1X authentication with RADIUS

b)

SSL inspection

c)

Network address translation (NAT)

d)

Content filtering

3.

What network design principle is exemplified by a classified system that must never be connected to the internet, with updates delivered via encrypted USB drives?

a)

VLAN trunking

b)

Air-gapped isolation

c)

VPN tunneling

d)

Jump-server routing

4.

Which concept does the setup demonstrate where a firewall sits at the internet border, an IDS is placed inside the internal LAN, and endpoint antivirus software runs on each workstation?

a)

Single-point control

b)

Defense in depth

c)

MAC filtering

d)

Fail-open architecture

5.

Which type of control is being used when a network tap sends mirrored traffic to an IDS without interrupting live network flow?

a)

Inline active control

b)

Passive out-of-band control

c)

Fail-close control

d)

Active endpoint control

6.

What type of security device is being used when a rule is configured to block all incoming TCP port 23 traffic from the internet?

a)

Intrusion detection system

b)

Firewall

c)

Load balancer

d)

Proxy server

7.

Which solution should be deployed to not only detect attacks but also automatically block malicious traffic in real time?

a)

IDS

b)

IPS

c)

SIEM

d)

Proxy

8.

What type of device should be implemented to combine a firewall, intrusion prevention, anti-malware, and content filtering into a single platform?

a)

IDS

b)

Load balancer

c)

Unified Threat Management (UTM) appliance

d)

Reverse proxy

9.

Which feature provides resilience when a cloud service provider distributes web requests evenly across several backend servers and automatically removes a node from the pool when it fails a health check?

a)

Source IP filtering

b)

Heartbeat and health checks

c)

SSL offloading

d)

Weighted DNS routing

10.

What principle is being used when an administrator manages a remote server farm using a separate network and a jump server for access, even when the production network is down?

a)

Air-gapping

b)

Out-of-band management

c)

Port security

d)

VPN segmentation

11.

Which deployment model does it represent when a startup chooses to host its customer-facing app in a cloud environment shared with other organizations to minimize costs?

a)

Private cloud

b)

Community cloud

c)

Public cloud

d)

Hybrid cloud

12.

What’s the biggest security challenge with a setup where a healthcare company processes patient data in its on-premises private cloud but uses a public cloud for web hosting, and the systems exchange sensitive data?

a)

Cost management

b)

User training

c)

Data transfer and encryption between environments

d)

Network latency

13.

Who is responsible for managing physical access to a cloud data center in an IaaS environment?

a)

The customer organization

b)

The cloud service provider

c)

A third-party contractor

d)

The system administrator

14.

Who owns the task of configuring database encryption and user access permissions for a hosted cloud app according to the responsibility matrix?

a)

Cloud provider

b)

Customer organization

c)

Security auditor

d)

Data center manager

15.

What resiliency concept is being used when an enterprise deploys its virtual machines across multiple cloud zones within the same region to reduce downtime during localized outages?

a)

Geo-redundant storage (GRS)

b)

Local replication

c)

High availability across zones

d)

Cloud bursting

16.

What technology is being used when a DevOps team deploys microservices in lightweight, isolated environments that share the same host OS kernel?

a)

Virtual machines

b)

Application virtualization

c)

Containerization

d)

Emulation

17.

Which risk does the scenario best illustrate when a manufacturer connects hundreds of low-cost IoT sensors to monitor factory operations, and the devices start transmitting abnormal data to unknown IP addresses?

a)

Insufficient memory capacity

b)

Weak or missing security controls in IoT devices

c)

Poor network segmentation

d)

Misconfigured VPNs

18.

Which term best describes devices like smart infusion pumps and heart monitors that run real-time operating systems for critical timing?

a)

SCADA

b)

Embedded systems

c)

Hypervisors

d)

Bastion hosts

19.

Which concept is being implemented when a corporate network authenticates all devices and users—internal or external—before granting access?

a)

Defense in depth

b)

Least privilege

c)

Zero Trust

d)

Network Access Control

20.

What architectural concept addresses the change when an organization realizes its traditional firewall-based perimeter no longer provides full protection after adopting remote work and cloud apps?

a)

Deperimeterization

b)

Edge computing

c)

Virtual private cloud

d)

Federated identity