NEW
Font size
WorksheetsCybersecurity and IT Concepts Quiz
Total questions: 27
Worksheet time: 13mins
A cybersecurity analyst notices that their organization’s endpoint security solution is collecting data from servers, workstations, and network traffic. The system is capable of correlating information across multiple environments to detect advanced threats. Which solution is most likely in use?
Endpoint Detection and Response (EDR)
Extended Detection and Response (XDR)
Host-Based Intrusion Prevention System (HIPS)
Security Information and Event Management (SIEM)
A system administrator configures user accounts so each employee only has the rights required to perform their job functions. Which endpoint configuration concept is being implemented?
Role-Based Access Control (RBAC)
Principle of Least Privilege
File System Encryption
Configuration Enforcement
A manufacturing plant uses several PLCs (Programmable Logic Controllers) connected to a SCADA network. To protect these systems, the security team implements strict network segmentation and unidirectional gateways to control data flow. What is the main goal of using unidirectional gateways?
To reduce latency between network segments
To prevent sensitive data from leaving the control network
To increase redundancy for network resilience
To enable two-way synchronization between devices
An organization allows employees to use personal smartphones for work, but requires installation of a management app that enforces encryption and security policies. Which deployment model is this?
COBO – Corporate-Owned, Business-Only
COPE – Corporate-Owned, Personally-Enabled
BYOD – Bring Your Own Device
CYOD – Choose Your Own Device
A mobile administrator enables password locks on all company iPhones. The administrator explains that this automatically triggers “Data Protection” encryption for apps that use the feature. What type of security measure is being implemented?
Secure boot
Full Device Encryption
Hardware Root of Trust
File-level Access Control
An IT technician disables unused USB ports, removes unnecessary software, and applies full-disk encryption to company laptops. Which security goal do these actions best support?
Network availability
Endpoint hardening
Cloud security
Identity federation
A security analyst detects a Wi-Fi network named “CompanyGuest-FreeWiFi” broadcasting near headquarters. Employees report slow connections and redirected logins. Which threat is most likely occurring?
DNS spoofing
Evil Twin attack
VLAN hopping
Bluejacking
A system administrator is configuring HTTPS for a company website. During a vulnerability scan, the tool reports that the web server supports TLS 1.0 and SSL 3.0. Which action should the administrator take to secure the site?
Enable only TLS 1.2 or newer and disable older protocols
Add self-signed SSL certificates to the site
Configure the web server to use RC4 cipher suites
Move the site behind a reverse proxy
A company’s mail server has been flagged for sending spam. The security analyst finds that the organization has no SPF or DKIM records in DNS. Which of the following should be implemented to prevent this issue in the future?
Create DNS TXT records defining authorized senders
Configure NAT on the mail gateway
Implement POP3 and IMAP encryption
Add static routing to the DNS zone
An organization wants to ensure that sensitive emails are encrypted and digitally signed so recipients can verify their authenticity. Which technology should the administrator deploy?
S/MIME
SPF
DKIM
DMARC
A security engineer is tasked with securing the company’s internal DNS from being used for data exfiltration and spoofing attacks. Which of the following solutions provides validation of DNS responses?
DNS filtering
DNSSEC
DHCP snooping
Content filtering
A developer rushes to meet a software release deadline and skips thorough input validation. Shortly after release, attackers exploit the application by injecting SQL commands into input fields. Which secure coding practice could have prevented this attack?
Error handling
Code signing
Input validation
Data obfuscation
An organization experiences an increase in phishing and Business Email Compromise (BEC) attempts. The CISO decides to implement a centralized control point that filters emails, scans attachments, and sanitizes links before delivery. Which security tool is being deployed?
Web Application Firewall
Email Gateway
DLP Server
SIEM
A company currently uses FTP for file transfers, but management wants to protect data confidentiality without changing the overall workflow. Which protocol should replace FTP?
TFTP
SFTP
Telnet
POP3
A security analyst is the first to respond after a user reports unusual network activity. The analyst collects evidence, isolates the affected system, and notifies management. At which stage of the incident response process is the analyst currently operating?
Preparation
Containment
Eradication
Lessons Learned
During a forensic investigation, a technician creates a bit-by-bit copy of a hard drive and calculates a hash value for the original and the copy. What is the purpose of hashing in this scenario?
To anonymize data for privacy compliance
To ensure evidence integrity during analysis
To speed up the imaging process
To compress the copied data
A SOC team receives a flood of alerts from the organization’s SIEM. After analysis, they discover most alerts are false positives caused by normal network behavior. Which of the following should the team do to improve detection accuracy?
Disable the SIEM temporarily
Redirect all alerts to management
Tune correlation rules and refine alert thresholds
Increase sensitivity to capture all possible events
An analyst investigating a ransomware attack uses Windows Event Logs, IDS alerts, and NetFlow data to trace the attacker’s movement within the network. Which concept is being demonstrated here?
Data normalization
Evidence preservation
Data correlation
Chain of custody
A company receives a court order to preserve digital evidence related to a data breach. The security team is instructed not to modify, overwrite, or delete any related data. Which principle is being applied?
Due process
Legal hold
Evidence tampering
Public disclosure
A SOC analyst discovers an unusual PowerShell process running from memory on several workstations. The malware uses legitimate Windows tools to execute malicious code and maintain persistence via registry entries. Which type of malware is this most likely describing?
Rootkit
Fileless malware
Logic bomb
Trojan horse
An attacker gains access to a Windows domain controller and extracts Kerberos tickets to authenticate to other systems without knowing user passwords. Which type of attack has occurred?
Pass the hash (PtH)
Credential replay
Pass the ticket (PtT)
Dictionary attack
A security engineer notices that multiple compromised systems across the internet are sending massive amounts of SYN requests to the organization’s web server, causing resource exhaustion. Which attack is being observed?
Reflected DDoS
SYN flood
Amplified NTP attack
Brute force attack
A company’s wireless intrusion detection system reports an SSID that matches the corporate Wi-Fi name but originates from a different MAC address. Employees who connect report credential theft. Which type of attack is this?
Rogue access point
Evil twin attack
Jamming attack
Replay attack
What is spyware??
When your kids use your phone
James Bond's movie
Software that collects data from computer
a cyber criminal
Why is it important to change the default password on devices such as wireless access points and routers?
To prevent the device from malfunctioning
To ensure the device runs faster
To prevent unauthorized access to the network
To comply with manufacturer warranties
___________ is the European Union (EU) standard for handling data that affects companies doing business in the EU.
HIPPA
GDPR (General Data Protection Regulation)
EUDRS
PCI-DSS
