Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Security Operations - 4.1 & 4.2

Total questions: 75

Worksheet time: 1hrs 15mins

Name
Class
Date
1.

1. Secure Baseline Implementation

After deploying new Windows workstations, the SOC notes that some users have local admin privileges.
What baseline control was likely missed?

a)

A. Patch management

b)

B. Least privilege configuration

c)

C. Encryption enforcement

d)

D. Application whitelisting

2.

2. Baseline Maintenance

A server’s configuration drifts from the secure baseline over time due to manual updates.
What’s the best solution?

a)

A. Increase patch frequency

b)

B. Disable updates

c)

C. Use configuration management tools (e.g., Ansible, SCCM)

d)

D. Reimage the server weekly

3.

3. Router Hardening

A network engineer enables SSH and disables Telnet on routers.
What principle is being applied?

a)

A. Access control

b)

B. Protocol hardening

c)

C. Network segmentation

d)

D. Default denial

4.

4. Switch Hardening

An attacker connects to an unused switch port and gains network access.
What control prevents this?

a)

A. VLAN tagging

b)

B. Port security / MAC address limiting

c)

C. Flood guards

d)

D. QoS configuration

5.

5. Server Hardening

A web server hosts only HTTPS but still allows TLS 1.0. What should be done?

a)

A. Install more certificates

b)

B. Enable HTTP/2

c)

C. Disable weak cryptographic protocols

d)

D. Add more firewall rules

6.

6. Cloud Infrastructure Hardening

A cloud administrator leaves S3 buckets public by default.
Which control prevents this exposure?

a)

A. Password complexity policy

b)

B. Access control list (ACL) review and default deny

c)

C. MFA enforcement

d)

D. Role-based training

7.

7. ICS/SCADA Security

A plant’s SCADA systems cannot be patched often due to uptime requirements.
What’s the best compensating control?

a)

A. Network segmentation and strict access control

b)

B. Annual reimaging

c)

C. Full internet connectivity

d)

D. Backup-only protection

8.

8. IoT Device Hardening

IoT cameras in a building all use the default admin password.
What’s the best fix?

a)

A. Limit network bandwidth

b)

B. Change default credentials and update firmware

c)

C. Use stronger Wi-Fi

d)

D. Enable MAC filtering

9.

9. Mobile Device Hardening

An employee’s phone is jailbroken.
What MDM policy should apply?

a)

A. Enable roaming

b)

B. Block access to corporate apps

c)

C. Force strong password

d)

D. Allow personal hotspot

10.

10. RTOS Security

A vendor’s medical device runs an RTOS and cannot support antivirus.
What’s the best mitigation?

a)

A. Install antivirus anyway

b)

B. Implement strong network segmentation and monitoring

c)

C. Apply host-based firewalls

d)

D. Use TLS only

11.

11. Establishing Secure Baselines

Which tool best automates establishing a Windows baseline?

a)

A. Wireshark

b)

B. Group Policy Objects (GPOs)

c)

C. Ping

d)

D. Nmap

12.

12. Wireless Site Survey

During a new office setup, overlapping wireless channels cause poor performance.
What should have been done first?

a)

A. Use WPA3

b)

B. Perform a wireless site survey

c)

C. Set static IPs

d)

D. Enable SSID hiding

13.

13. Heat Maps

The IT team uses a heat map showing signal strength across the building.
What is this map used for?

a)

A. Incident response

b)

B. Placement and coverage optimization

c)

C. Bandwidth management

d)

D. Guest network design

14.

14. MDM Enforcement

If employees ignore password policies on their mobile devices, what can MDM enforce?

a)

A. Nothing

b)

B. Only notifications

c)

C. Policy-based password compliance and remote wipe

d)

D. VPN creation

15.

15. BYOD Challenge

Which risk is highest in a BYOD deployment?

a)

A. Data center downtime

b)

B. Mixing personal and corporate data

c)

C. VPN misconfiguration

d)

D. Weak firewall

16.

16. COPE Model

Which best describes Corporate-Owned, Personally Enabled (COPE)?

a)

A. Employees bring their own phones

b)

B. Company provides devices that can be used personally

c)

C. Employees lease devices

d)

D. Shared mobile pool

17.

17. CYOD Deployment

In a CYOD program, what’s a major security benefit?

a)

A. Employees pick any device

b)

B. Devices remain preapproved and manageable by IT

c)

C. Devices are unmanaged

d)

D. Users install their own MDM

18.

18. Wireless Security Setting

Which wireless security feature provides forward secrecy and resistance to offline dictionary attacks?

a)

A. WPA2-PSK

b)

B. WPA3-SAE (Simultaneous Authentication of Equals)

c)

C. WEP

d)

D. EAP-TLS

19.

19. AAA Integration

Why would a company integrate wireless authentication with RADIUS?

a)

A. Simplify passwords

b)

B. Centralize AAA (Authentication, Authorization, Accounting)

c)

C. Reduce encryption

d)

D. Enable guest access

20.

20. Cryptographic Protocol Choice

Which protocol provides the best security for wireless communication?

a)

A. TKIP

b)

B. WEP

c)

C. AES-CCMP

d)

D. MD5

21.

21. Authentication Protocol

EAP-TLS provides which advantage?

a)

A. Passwordless authentication using certificates

b)

B. Simple username/password login

c)

C. Shared key encryption

d)

D. MAC filtering

22.

22. Application Security

During testing, an app fails when given unexpected input. What control prevents this?

a)

A. Encryption

b)

B. Input validation

c)

C. Authentication

d)

D. Obfuscation

23.

23. Secure Cookies

Why mark a cookie as “Secure” and “HttpOnly”?

a)

A. Increases speed

b)

B. Prevents interception and XSS attacks

c)

C. Allows caching

d)

D. Enables SSO

24.

24. Static Code Analysis

A developer runs automated scanning before compiling. What is this process?

a)

A. Dynamic analysis

b)

B. Static code analysis

c)

C. Fuzz testing

d)

D. Runtime debugging

25.

25. Code Signing

Why is code signing important?

a)

A. Improves performance

b)

B. Ensures code integrity and authenticity

c)

C. Prevents zero-days

d)

D. Enables debugging

26.

26. Sandboxing

Developers test an unverified app in isolation. Which technique is used?

a)

A. Patch testing

b)

B. Sandboxing

c)

C. Logging

d)

D. Virtual patching

27.

27. Monitoring

Which tool best identifies anomalies in baseline system behavior?

a)

A. SIEM with behavioral analytics

b)

B. IDS signatures only

c)

C. Log rotation

d)

D. Task scheduler

28.

28. Secure Baseline Verification

After a Windows update, the baseline checksum file no longer matches.
What should be done?

a)

A. Revalidate and update the baseline after integrity verification

b)

B. Ignore differences

c)

C. Restore old hash

d)

D. Delete baseline

29.

29. Mobile Connection Methods

Which mobile connection method introduces the most risk in public spaces?

a)

A. Cellular

b)

B. Open Wi-Fi

c)

C. VPN

d)

D. NFC

30.

30. Bluetooth Security

Which setting prevents automatic Bluetooth connections to unknown devices?

a)

A. Discoverable mode

b)

B. Pairing approval or “ask before connecting”

c)

C. Bluejacking

d)

D. Beaconing

31.

31. Cloud Monitoring

Which approach ensures compliance across multiple cloud environments?

a)

A. Host-only monitoring

b)

B. Cloud Security Posture Management (CSPM)

c)

C. Local logging

d)

D. Antivirus scanning

32.

32. Secure Baseline Deployment

How can organizations deploy secure baselines efficiently across multiple VMs?

a)

A. Use golden images

b)

B. Manual setup

c)

C. Ad hoc patching

d)

D. Random provisioning

33.

33. Workstation Hardening

Which control reduces attack surface on endpoints?

a)

A. Disable antivirus

b)

B. Application whitelisting

c)

C. Enable guest accounts

d)

D. Install more apps

34.

34. Server Patch Prioritization

A zero-day affects a critical server. What should admins do?

a)

A. Wait for baseline update

b)

B. Apply vendor mitigation or isolate the system immediately

c)

C. Ignore

d)

D. Reboot

35.

35. Embedded System Security

Smart vending machines use outdated firmware.
Best step?

a)

A. Replace hardware

b)

B. Apply vendor patches or restrict network access

c)

C. Disable TLS

d)

D. Use weaker encryption

36.

36. Monitoring Wireless

Rogue access points appear in the office. Which tool detects this?

a)

A. Ping

b)

B. Wireless intrusion detection system (WIDS)

c)

C. Firewall

d)

D. DNS filter

37.

37. Mobile Data Separation

How does an MDM enforce separation between work and personal data?

a)

A. Containerization

b)

B. Rooting

c)

C. Jailbreaking

d)

D. VPN tunneling

38.

38. IoT Monitoring

What’s the best way to monitor IoT traffic for anomalies?

a)

A. Network segmentation with flow analysis (NetFlow)

b)

B. Install endpoint AV

c)

C. Cloud-only scanning

d)

D. Block all traffic

39.

39. Application Security Failure

An application exposes stack traces to users during crashes.
Which control is missing?

a)

A. Input validation

b)

B. Error handling / exception management

c)

C. Logging

d)

D. Authentication

40.

40. Secure Monitoring

Why use log normalization in SIEM systems?

a)

A. Standardizes diverse log formats for correlation

b)

B. Deletes duplicates

c)

C. Speeds up storage

d)

D. Encrypts data

41.

41. Sandboxing in Email

Email attachments are detonated in a virtual machine before delivery.
What is this technique?

a)

A. Whitelisting

b)

B. Attachment sandboxing

c)

C. Firewall filtering

d)

D. Signature matching

42.

42. Baseline Drift Detection

A file server’s registry differs from the baseline but has no recorded updates.
What’s the likely cause?

a)

A. Patch installation

b)

B. Unauthorized configuration change

c)

C. Baseline error

d)

D. Scheduled maintenance

43.

43. Secure Wireless Deployment

To prevent unauthorized AP installations, what control helps?

a)

A. WPA3 only

b)

B. Network Access Control (NAC)

c)

C. EAP-TLS

d)

D. VLAN segmentation

44.

44. Mobile App Vetting

Before allowing a new app on work devices, what’s the best security step?

a)

A. Allow installation

b)

B. Perform app reputation and permissions review

c)

C. Test network speed

d)

D. Ignore privacy policy

45.

45. Cloud Hardening

Cloud admin discovers exposed management ports on virtual machines.
Best action?

a)

A. Patch the OS

b)

B. Restrict access using security groups/firewall rules

c)

C. Add users

d)

D. Reboot VMs

46.

46. Monitoring Alerts

Analysts are overwhelmed by too many alerts.
What’s the best improvement?

a)

A. Tune SIEM correlation rules and thresholds

b)

B. Disable alerts

c)

C. Ignore low-severity events

d)

D. Use longer logs

47.

47. Application Security Testing

A developer executes fuzzing against a running web app.
What is this?

a)

A. Static testing

b)

B. Dynamic application testing

c)

C. Code review

d)

D. Input sanitization

48.

48. Router Monitoring

SNMPv2 is in use to monitor routers. What’s the risk?

a)

A. High encryption

b)

B. Unencrypted community strings (cleartext)

c)

C. Performance degradation

d)

D. VLAN mismatch

49.

49. Server Baseline Compliance

Which tool automatically checks servers against CIS benchmarks?

a)

A. Wireshark

b)

B. SCAP compliance scanner

c)

C. IDS

d)

D. Packet sniffer

50.

50. Continuous Hardening

How can organizations ensure hardening remains consistent after new deployments?

a)

A. Manual audits

b)

B. Automated compliance scanning and CI/CD integration

c)

C. Random testing

d)

D. Quarterly reboots

51.

51. Procurement Oversight

A department orders new IoT sensors directly from a vendor without involving security review.
What’s the main risk?

a)

A. Delayed delivery

b)

B. Higher price

c)

C. Introduction of unvetted or insecure hardware

d)

D. Network congestion

52.

52. Software Acquisition

A company purchases new CRM software without verifying its license type.
What’s a potential security implication?

a)

A. Excessive logging

b)

B. Use of pirated or unlicensed software lacking patches

c)

C. Vendor lock-in

d)

D. Slower installation

53.

53. Procurement Process

Why should the security team participate in procurement?

a)

A. To negotiate pricing

b)

B. To reduce the vendor list

c)

C. To ensure vendors meet security and compliance requirements

d)

D. To speed up delivery

54.

54. Hardware Ownership

Laptops are assigned to employees but not documented.
What risk does this create?

a)

A. Device overheating

b)

B. Lack of accountability and tracking

c)

C. Network throttling

d)

D. Double billing

55.

55. Asset Classification

A project stores PII in the same shared folder as public data.
Which classification control failed?

a)

A. Availability

b)

B. Data segregation by sensitivity level

c)

C. Encryption

d)

D. Backup

56.

56. Ownership Assignment

Why is assigning data ownership critical?

a)

A. Reduces legal liability

b)

B. Clarifies who is responsible for protection and access control

c)

C. Allows more users

d)

D. Simplifies backups

57.

57. Asset Accounting

During an audit, 12 missing laptops aren’t found in inventory.
What’s the most likely process failure?

a)

A. Improper logging

b)

B. Poor asset accounting and tracking

c)

C. Overclassification

d)

D. Incorrect labeling

58.

58. Asset Enumeration

A vulnerability scanner detects unknown systems on the network.
What does this indicate?

a)

A. Rogue DHCP server

b)

B. Untracked or unauthorized assets

c)

C. Network segmentation

d)

D. Misconfigured firewall

59.

59. Monitoring and Tracking

What tool best supports hardware asset tracking?

a)

A. IDS

b)

B. CMDB

c)

C. Firewall

d)

D. Proxy

60.

60. Data Classification

What’s the primary purpose of data classification?

a)

A. To reduce redundancy

b)

B. To determine security controls and handling procedures

c)

C. To minimize storage

d)

D. To simplify encryption

61.

61. Software Inventory

A license compliance audit finds multiple unapproved applications installed by users.
What’s the likely cause?

a)

A. Network latency

b)

B. Lack of software whitelisting or inventory control

c)

C. Weak password policy

d)

D. Cloud misconfiguration

62.

62. Asset Enumeration Techniques

What network security risk comes from poor asset enumeration?

a)

A. Low bandwidth

b)

B. Unmonitored devices that attackers can exploit

c)

C. User lockouts

d)

D. Duplicate IPs

63.

63. Acquisition Policy

Why should all asset purchases go through a single procurement channel?

a)

A. Simplifies payments

b)

B. Ensures uniform security evaluation and recordkeeping

c)

C. Minimizes network usage

d)

D. Increases storage

64.

64. Disposal Phase

Old hard drives are donated without wiping. What control failed?

a)

A. Network segmentation

b)

B. Encryption

c)

C. Data sanitization before disposal

d)

D. Physical access control

65.

65. Sanitization Method

Which sanitization method is most appropriate for SSDs?

a)

A. Low-level formatting

b)

B. Cryptographic erasure

c)

C. File deletion

d)

D. Zero-fill overwriting

66.

66. Destruction Verification

Why should destruction of storage media be certified?

a)

A. Tax purposes

b)

B. To prove compliance with legal or regulatory data retention standards

c)

C. For shipping insurance

d)

D. To reuse devices

67.

67. Decommissioning Systems

Before decommissioning an old server, what should be done first?

a)

A. Turn it off

b)

B. Sanitize or migrate all stored data

c)

C. Reinstall OS

d)

D. Disable network

68.

68. Data Retention

Why is a data retention policy important?

a)

A. Reduces backups

b)

B. Ensures legal, regulatory, and business obligations are met

c)

C. Avoids encryption

d)

D. Saves storage costs

69.

69. Improper Retention

Old customer data kept past regulatory deadlines increases which risk?

a)

A. Availability

b)

B. Legal and privacy non-compliance

c)

C. Data corruption

d)

D. Backup failure

70.

70. Certification Process

Which phase ensures that decommissioned hardware meets destruction standards?

a)

A. Monitoring

b)

B. Procurement

c)

C. Disposal certification

d)

D. Inventory enumeration

71.

71. Software Asset Expiration

Expired licenses on security tools pose what threat?

a)

A. Increased cost

b)

B. Loss of updates and vulnerability exposure

c)

C. Bandwidth reduction

d)

D. Duplicate logs

72.

72. Asset Lifecycle Security

What’s the best practice at each phase of the asset lifecycle?

a)

A. Document only at disposal

b)

B. Apply security controls from acquisition to destruction

c)

C. Encrypt only at use

d)

D. Ignore monitoring

73.

73. Hardware Enumeration

Which method best validates the physical presence of assets?

a)

A. SNMP polling

b)

B. Physical inventory audit

c)

C. Network scan

d)

D. SIEM alert

74.

74. Software Monitoring

To prevent shadow IT, admins deploy a tool that reports all executables on systems.
What’s this practice?

a)

A. Software asset inventory and monitoring

b)

B. Network mapping

c)

C. Code review

d)

D. Patch scanning

75.

75. Data Ownership Conflict

Two departments share one database, both claiming ownership.
What’s the risk?

a)

A. Redundant backups

b)

B. Unclear accountability for security controls

c)

C. Extra encryption

d)

D. Better redundancy