wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Intro Cyber Exam 5 (Modules 9-11)

Total questions: 68

Worksheet time: 34mins

Name
Class
Date
1.

What is the main goal of storing encryption keys securely?

a)

To ensure easy access for all users

b)

To facilitate key revocation

c)

To prevent unauthorized access

d)

To increase the key's strength

2.

What is an implicit deny in firewall configuration?

a)

A rule that explicitly allows all traffic

b)

A default behavior to block traffic that does not match any rule

c)

A temporary rule that denies access during peak hours

d)

A rule that only denies traffic from specific countries

3.

What is Personally Identifiable Information (PII)?

a)

Any data that can be publicly accessed

b)

Data that can identify, contact, or locate an individual

c)

Information related to a company's financial status

d)

Data that is encrypted and stored securely

4.

What makes smart devices vulnerable to standard attacks?

a)

Their inability to connect to the Internet

b)

The use of proprietary operating systems

c)

Their compute, storage, and network functions

d)

The lack of integrated peripherals

5.

What is a zero-day vulnerability?

a)

A vulnerability patched within a day of its discovery

b)

A vulnerability that exists for zero days

c)

A vulnerability exploited before the developer can patch it

d)

A vulnerability that cannot be patched

6.

A cyber security technician responds to a department experiencing degraded network bandwidth, and customers call the department saying they cannot visit the company website. What is likely causing the issue?

a)

On-path attack

b)

DNS Poisoning

c)

Malware

d)

Distributed DoS (DDoS)

7.

What is the primary purpose of deploying a firewall in a network environment?

a)

To increase the network speed

b)

To filter traffic entering or leaving a network segment

c)

To serve as a primary storage device

d)

To manage user access to the internet

8.

What is a recommended step to secure IoT devices in a corporate environment?

a)

Limiting device functionality

b)

Assigning device configuration to appropriate organizational roles

c)

Using default device configurations

d)

Encouraging employees to manage their own devices

9.

What can mitigate the risks posed by IoT devices in remote working scenarios?

a)

Decreasing the number of devices connected to the home network

b)

Regular audits and employee security awareness training

c)

Using older, more familiar technology

d)

Avoiding the use of Wi-Fi networks

10.

What is a key difference between the perimeter security model and defense in depth?

a)

The perimeter security model uses multiple layers of security, while defense in depth relies on a single layer.

b)

The perimeter security model focuses on internal threats, while defense in depth focuses on external threats.

c)

The perimeter security model relies on trusting internal connections once they're inside the perimeter, while defense in depth does not.

d)

The perimeter security model is a modern approach, while defense in depth is outdated.

11.

What should be done to secure SNMP traffic?

a)

Disable SNMP entirely.

b)

Use the original versions of SNMP.

c)

Configure SNMPv3 or use IPSec for encryption.

d)

Limit SNMP traffic to internal networks.

12.

What is the primary goal of most adversaries when launching network attacks?

a)

To improve network security

b)

To steal information from the network

c)

To provide free services to users

d)

To enhance network performance

13.

What might a firewall be incorrectly doing if an application fails to function correctly?

a)

Allowing all TCP and UDP ports

b)

Blocking TCP or UDP ports that should be open

c)

Increasing bandwidth for all applications

d)

Decrypting all incoming traffic

14.

Which security device is typically used to enforce rules between network zones?

a)

Switch

b)

Router

c)

Firewall

d)

Access Point

15.

How is a user's biometric data used in a biometric lock system?

a)

It is sent to a remote server for storage.

b)

It is recorded and stored on an authentication server.

c)

It is stored on the user's badge.

d)

It is deleted immediately after each use for privacy reasons.

16.

What does MAC filtering on a switch allow an administrator to do?

a)

Limit the bandwidth usage per MAC address.

b)

Define which MAC addresses are permitted to connect to a particular port.

c)

Assign specific IP addresses to MAC addresses.

d)

Monitor the amount of data transmitted by each MAC address.

17.

What is a badge reader used for in building security?

a)

To detect motion at entry points

b)

To authenticate users quickly at access points

c)

To record the time employees leave the building

d)

To provide lighting at entry points

18.

What is MAC spoofing?

a)

Changing the MAC address of a network interface to any arbitrary value

b)

Physically altering the network interface to change its MAC address

c)

Using malware to reveal the MAC address of a device

d)

Intercepting MAC addresses during data transmission

19.

What is a forward proxy primarily used for?

a)

Inbound traffic management

b)

Outbound traffic management

c)

Data encryption only

d)

Data storage

20.

What does "defense in depth" refer to in network security design?

a)

A single, impenetrable layer of security at the network's edge

b)

Placing security controls throughout the network

c)

Focusing solely on physical security measures

d)

Ignoring internal threats and focusing on external attacks

21.

What is the primary goal of implementing security policies within an organization?

a)

To increase the organization's revenue

b)

To ensure compliance with legal requirements

c)

To mitigate risks associated with network systems

d)

To eliminate all risks facing the organization

22.

What is malware?

a)

A type of computer hardware that performs poorly

b)

Software designed to protect computer networks

c)

Software that performs malicious actions

d)

A beneficial software tool that enhances system performance

23.

What is the primary difference between ARP spoofing and ARP poisoning?

a)

ARP spoofing is a passive attack while ARP poisoning is an active attack.

b)

ARP spoofing involves broadcasting fake ARP messages, while ARP poisoning refers to the state of the ARP cache.

c)

ARP poisoning is used to secure network communications, whereas ARP spoofing is a malicious activity.

d)

ARP spoofing and ARP poisoning are terms for the same process, with no difference between them.

24.

What is the purpose of spoofing attacks?

a)

To improve the security of DNS services

b)

To disguise the attacker's identity

c)

To enhance the performance of ARP services

d)

To provide legitimate services to users

25.

Which of the following servers should be placed in a perimeter network?

a)

Database servers containing sensitive information

b)

Web servers providing public access services

c)

File servers used exclusively by internal employees

d)

Internal email servers for employee communication

26.

A network administrator is tasked with securing a company's network infrastructure against ARP cache poisoning attacks. The network consists of several switches and hosts, with IPv4 being the primary protocol used. The administrator decides to implement a security feature on the switches to mitigate these types of attacks.

a)

VLAN tagging

b)

Dynamic ARP Inspection (DAI)

c)

BPDU Guard

d)

DHCP snooping

27.

What is the function of a content filtering firewall or proxy?

a)

To increase bandwidth

b)

To serve as a backup data center

c)

To restrict access

d)

To provide a VPN service

28.

What does enabling Root Guard on ports not used as trunk lines accomplish?

a)

It allows for faster convergence of the spanning tree.

b)

It prevents unauthorized changes to the root bridge selection.

c)

It encrypts BPDU packets for secure transmission.

d)

It increases the number of allowable VLANs on a port.

29.

Due to an increase in foot traffic from outside groups throughout the building, the organization asks their security office to employ equipment that will allow visual monitoring across the organization. What equipment would best be suited to manage this request?

a)

Circuit

b)

Cameras

c)

Motion Detection

d)

Asset Tag

30.

What does DHCP snooping help to prevent?

a)

The operation of rogue DHCP servers

b)

The switch from assigning IP addresses

c)

The encryption of DHCP traffic

d)

The use of static IP addresses on the network

31.

Which factor determines the type of credential a subject can use for authentication?

a)

Authorization model

b)

Accounting system

c)

Authentication factor

d)

Identification process

32.

What is DNS spoofing?

a)

Manipulating cached DNS records

b)

Using false DNS requests or replies

c)

Attacking the physical infrastructure of DNS servers

d)

Infecting DNS servers with malware

33.

Why are longer and more complex passwords more secure against brute force attacks?

a)

They are easier to remember.

b)

They take less time to crack.

c)

They increase the amount of time the attack takes to run.

d)

They are less likely to be stored in password files.

34.

What does the principle of least privilege entail in the context of PAM?

a)

Granting users unlimited rights to perform their job

b)

Granting users only the rights necessary to perform their job

c)

Allowing users to determine their access rights

d)

Providing all users with administrative privileges

35.

Which of the following examples BEST describes shoulder surfing?

a)

Guessing someone's password because it is so common or simple

b)

Finding someone's password in the trash can and using it to access their account

c)

Giving someone you trust your username and account password

d)

Someone nearby watching you enter your password on your computer and recording it

36.

What can the most serious vulnerabilities allow an attacker to do?

a)

Increase system performance

b)

Execute arbitrary code on the system

c)

Improve application security

d)

Encrypt system files for data protection

37.

What is the purpose of a choke point in a screened subnet configuration?

a)

To provide a direct connection to the Internet

b)

To facilitate better access control and easier monitoring

c)

To eliminate the need for internal firewalls

d)

To allow unrestricted access between the perimeter network and the LAN

38.

What is the role of the screening firewall in a screened subnet?

a)

To connect directly to the LAN

b)

To filter communications between hosts in the perimeter and the LAN

c)

To restrict traffic on the external/public interface

d)

To provide unrestricted access to the Internet

39.

What framework does Windows use to provide Single Sign-On (SSO) authentication?

a)

OAuth

b)

LDAP

c)

Kerberos

d)

SAML

40.

What does the Ticket Granting Ticket (TGT) provide in the Kerberos authentication process?

a)

Immediate access to all network resources

b)

A token that grants access to a target application server

c)

Authentication for user logon requests

d)

The ability to request Service Tickets from the TGS

41.

What tool can be used to discover whether false records have been inserted into a DNS server's cache?

a)

Ping

b)

Traceroute

c)

nslookup or dig

d)

Netstat

42.

What are Potentially Unwanted Programs (PUPs)/Potentially Unwanted Applications (PUAs)?

a)

Software that is always malicious and installed without the user's consent

b)

Software installed alongside a package selected by the user

c)

Programs that enhance computer security without the user's knowledge

d)

Applications that cannot be uninstalled by the user

43.

What does "availability" in the CIA Triad refer to?

a)

The data is stored and transferred as intended and that any modification is authorized.

b)

Information and resources are accessible to those authorized when needed.

c)

Information is protected from unauthorized access except to those with the proper permissions.

d)

The system is protected against unauthorized access, attacks, and disclosure.

44.

What is meant by "data at rest"?

a)

Data being transmitted over a network

b)

Data stored on a persistent storage media

c)

Data present in volatile memory

d)

Data being actively processed by a computer

45.

What is the primary purpose of the Spanning Tree Protocol (STP) in a network?

a)

To encrypt traffic between switches

b)

To increase network bandwidth

c)

To prevent switching loops

d)

To facilitate VLAN hopping attacks

46.

What is an on-path attack?

a)

A type of physical attack where the attacker physically intercepts a data transmission.

b)

A type of spoofing attack where a threat actor intercepts communications between two hosts.

c)

A cyber-attack that exclusively targets the path of data storage devices.

d)

An attack where the threat actor creates a new path in a network to reroute data.

47.

What does the term "attack surface" refer to?

a)

The physical area of a network

b)

The total number of users in a system

c)

The range of potential vulnerabilities exploitable by attackers

d)

The graphical interface of security software

48.

How does RBAC differ from using security groups for assigning permissions?

a)

RBAC assigns permissions directly to users, while security groups do not.

b)

RBAC is discretionary, while security groups are nondiscretionary.

c)

RBAC focuses on job roles, while security groups are about user identity.

d)

Security groups encrypt data, while RBAC does not.

49.

What distinguishes an external threat actor from an internal threat actor?

a)

The type of malware they use

b)

Whether they have authorized access to the system

c)

The geographical location of the actor

d)

The sophistication of the attack

50.

What is the role of a Certificate Authority (CA) in PKI?

a)

To distribute private keys to users

b)

To guarantee the validity of digital certificates

c)

To encrypt messages with public keys

d)

To generate symmetric session keys

51.

What does "integrity" in the context of the CIA Triad mean?

a)

The data is stored and transferred as intended and that any modification is authorized.

b)

Information is accessible to those authorized to view or modify it.

c)

Certain information should only be known to certain people.

d)

The system is protected against unauthorized access and attacks.

52.

What is a DHCP starvation attack?

a)

An attack that floods the network with excessive data

b)

An attack that exhausts a DHCP server's address pool

c)

An attack that encrypts all DHCP traffic

d)

An attack that physically damages the DHCP server

53.

Which of the following combinations represents two-factor authentication?

a)

Password and a smart card

b)

Two different passwords

c)

Password and a user's favorite color

d)

Password and the time of login

54.

What can be a source of internal threats?

a)

Hackers from another country

b)

Employees within the organization

c)

Malware found on the Internet

d)

Phishing emails from unknown senders

55.

What is VLAN hopping?

a)

A method to increase the speed of VLAN traffic

b)

An attack designed to send traffic to a VLAN other than the one the host system is in

c)

A technique to reduce network congestion

d)

A security feature of 802.1Q to enhance VLAN compatibility

56.

Which of the following can be a use case for the mirror port in port mirroring?

a)

Connecting another switch

b)

Acting as a monitoring point

c)

Serving as an additional port for network clients

d)

Providing power over Ethernet (PoE) to devices

57.

What is the purpose of the HOSTS file in DNS resolution?

a)

To store the user's browsing history

b)

To act as a backup for DNS servers

c)

To map domain names to IP addresses

d)

To log DNS query errors

58.

What can an organization use geofencing for?

a)

To increase the speed of their internet connection

b)

To monitor the productivity of their employees

c)

To control the use of camera functions on devices

d)

To improve the accuracy of their GPS systems

59.

In the context of IEEE 802.1X, what is the role of a switch configured as a RADIUS client?

a)

To distribute IP addresses

b)

To forward authentication data

c)

To encrypt network traffic

d)

To manage network storage

60.

What is the primary purpose of prevention-type physical controls like electronic locks?

a)

To monitor and record access attempts

b)

To stop an intruder from gaining unauthorized access

c)

To alert security personnel of an unauthorized access attempt

d)

To provide a backup power source for electronic devices

61.

What is one of the key benefits of using a honeypot or honeynet in cybersecurity?

a)

Completely eliminating cyber threats

b)

Providing an early warning of attacks

c)

Increasing the encryption strength

d)

Reducing the need for other security measures

62.

Which of the following network security zones is subject to strict hardening and configuration management policies, and where hosts, user accounts, and traffic are continually monitored to ensure compliance with security policies?

a)

Guest

b)

Public server network

c)

Private client network

d)

Private server administrative networks

63.

Which of the following can be considered a rogue device?

a)

An officially sanctioned DHCP server

b)

A wireless access point installed without IT approval

c)

A firewall configured by the network security team

d)

A company-issued laptop with up-to-date security software

64.

What is a Distributed Reflection DoS (DRDoS) attack?

a)

An attack that improves server reflection capabilities

b)

A type of attack where the victim's IP address is spoofed

c)

A method to reduce network bandwidth consumption

d)

An attack that directly targets the attacker's network

65.

What is the APIPA range used for?

a)

Global internet routing

b)

Private IP addressing when DHCP is unavailable

c)

Static IP addressing

d)

Network address translation (NAT)

66.

What is the difficulty in implementing security controls?

a)

They are always too complex to implement.

b)

They can be expensive.

c)

They are not supported by IT service frameworks.

d)

They only address low-level risks.

67.

What does "protect mode" do when a switch port enters a violation state?

a)

It disables the port and sends alerts.

b)

It drops frames from the invalid source address but keeps the interface open.

c)

It encrypts traffic from the invalid source address.

d)

It reroutes traffic from the invalid source address to a quarantine VLAN.

68.

What is a key pair in public key cryptography?

a)

Two identical keys used for encryption and decryption

b)

A set of two keys, one for signing and one for verification

c)

A set of two keys, one public and one private, used together

d)

Two public keys used interchangeably