wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Week 6: Network Resilience and Security

Total questions: 89

Worksheet time: 45mins

Name
Class
Date
1.

An organisation wants to minimise downtime to a few seconds when its main data centre fails. Which recovery site type best meets this requirement?

a)

Warm site

b)

Cold site

c)

Cloud site

d)

Hot site

e)

Portable site

2.

An analyst is reviewing failures of network switches that cannot be repaired once they fail. Which reliability metric applies?

a)

MTBF

b)

MTTR

c)

RTO

d)

MTTF

e)

RPO

3.

A company plans to replicate data every 4 hours. This frequency directly impacts which metric?

a)

MTTR

b)

RPO

c)

MTD

d)

RTO

e)

MTBF

4.

An attacker sends unsolicited ARP replies to impersonate the gateway. What attack is this?

a)

DNS poisoning

b)

VLAN hopping

c)

ARP spoofing

d)

DoS flooding

e)

Rogue DHCP

5.

A network engineer deploys multiple fibre connections between two servers to guarantee connectivity in case one fails. Which concept is this?

a)

Trunking

b)

Load balancing

c)

Multipathing

d)

Port mirroring

e)

Loop protection

6.

A web application receives traffic through a device that decides how to distribute client requests across multiple servers. Which device is being used?

a)

Router

b)

Firewall

c)

Load balancer

d)

Proxy server

e)

Switch

7.

A company defines that after an outage, the service must be restored within 3 hours. Which metric is this?

a)

MTBF

b)

MTTR

c)

RPO

d)

MTD

e)

RTO

8.

A cybercriminal uses multiple compromised systems to overwhelm a victim’s bandwidth. This describes a:

a)

Rogue AP

b)

DDoS attack

c)

VLAN hopping

d)

Spoofing error

e)

Port scan

9.

A technician bundles four Ethernet cables into a single logical link for higher bandwidth and redundancy. Which protocol supports this?

a)

HSRP

b)

CARP

c)

LACP

d)

VRRP

e)

STP

10.

A company wants its backup generator to automatically take over when power fails. What must still be present?

a)

Load balancer

b)

Firewall

c)

UPS

d)

DHCP server

e)

Solar panel

11.

A malicious actor intercepts traffic between two endpoints without detection. Which attack is this?

a)

Evil twin

b)

DNS poisoning

c)

MitM

d)

DDoS

e)

Ransomware

12.

A user reports a fake Wi-Fi network named similar to the legitimate one. What attack is this?

a)

Rogue DHCP

b)

Evil twin

c)

MitM

d)

ARP spoof

e)

VLAN hopping

13.

A device caches configuration settings in battery-backed memory to protect against sudden loss. This feature is known as:

a)

RPO

b)

UPS runtime

c)

Battery-backed cache

d)

Flash mirroring

e)

Warm failover

14.

A server cluster where all nodes actively process traffic simultaneously is known as:

a)

Active-active

b)

Passive-passive

c)

Backup-only

d)

Failover-only

e)

VRRP cluster

15.

A network admin restricts each switchport to a single MAC address to prevent rogue devices. What technique is used?

a)

DHCP Snooping

b)

Port Security

c)

DAI

d)

PVLAN

e)

802.11X

16.

A threat actor modifies the HOSTS file on a victim’s device so specific domain names resolve incorrectly. This is a:

a)

DNS server poisoning

b)

Client-side DNS poisoning

c)

Rogue gateway

d)

Cache amplification

e)

Port redirection attack

17.

A business wants side-to-side separation of devices within one VLAN. Which technology enables this?

a)

Trunking

b)

PVLAN

c)

STP

d)

SNMPv3

e)

LAG

18.

Password hashes stored insecurely are at risk of which attack?

a)

VLAN hopping

b)

Botnet injection

c)

Hash cracking

d)

ARP poisoning

e)

Ransom payment redirection

19.

A company wants to ensure that a default gateway is always reachable without reconfiguring hosts. What protocol supports this?

a)

STP

b)

HSRP

c)

RIP

d)

OSPF

e)

PPPoE

20.

A system admin reviews the total operational hours of a device divided by the number of failures. This metric is:

a)

MTTR

b)

RPO

c)

MTBF

d)

RTO

e)

MTD

21.

An attacker sets up a DHCP server that gives victims a malicious default gateway. What attack is this?

a)

Rogue DHCP

b)

ARP poisoning

c)

HSRP spoofing

d)

DNS tunnelling

e)

VLAN hopping

22.

A company plans to restore full operations after an outage, including administrative tasks. The total time includes RTO plus WRT. What is the name of this combined period?

a)

MTTR

b)

MTD

c)

MTBF

d)

RPO

e)

RTF

23.

Which site requires the longest time to restore operations after a disaster?

a)

Warm site

b)

Hot site

c)

Cloud site

d)

Cold site

e)

Hybrid site

24.

An admin configures a trunk to use a unique native VLAN to reduce risk. This follows best practice for preventing:

a)

Ransomware

b)

VLAN hopping

c)

DNS spoofing

d)

Rogue APs

e)

DDoS

25.

An organisation deploys a system where a backup router uses a priority system to take over if the active router fails. Which protocol describes this?

a)

CARP

b)

VRRP

c)

LACP

d)

HSRP

e)

GLBP

26.

A system has a high MTTR. What does this typically indicate?

a)

Failures are frequent

b)

Repairs take longer

c)

The RPO is strict

d)

Ransomware risk is high

e)

Backups are not configured

27.

A company wants to prevent devices from using unauthorized wireless networks. Which measure helps?

a)

ARP refresh

b)

Geofencing

c)

LACP

d)

RAID

e)

SNMP alerts

28.

A botnet controller sends commands to infected hosts. The network that manages this is known as:

a)

Shadow VLAN

b)

Split tunnel

c)

C2 network

d)

MitM

e)

ARP domain

29.

A system must never lose more than 30 minutes of data if a failure occurs. Which metric sets this?

a)

RTO

b)

MTTR

c)

RPO

d)

WRT

e)

MTD

30.

A firewall applies rules from top to bottom and blocks anything not explicitly allowed. This is known as:

a)

Explicit permit

b)

First-hop redundancy

c)

Implicit deny

d)

Route policing

e)

NAT exclusion

31.

A device that filters and stabilises power while allowing remote power monitoring is called a:

a)

Generator

b)

PDU

c)

Patch panel

d)

UPS

e)

Inverter

32.

A technician detects an employee plugging an unauthorized laptop into a free switchport. Which defence applies?

a)

MTBF tracking

b)

Port security

c)

DNSSEC

d)

HSRP

e)

Multipathing

33.

Multiple ISPs with physically separate entry points to a building are used to ensure:

a)

Cache prevention

b)

Physical path diversity

c)

VLAN convergence

d)

Native VLAN isolation

e)

Ransomware mitigation

34.

A firewall admin configures INPUT, OUTPUT, and FORWARD chains. Which tool is being used?

a)

SNMPv3

b)

iptables

c)

OpenVPN

d)

NetFlow

e)

Syslog

35.

Malware that encrypts files and demands payment is known as:

a)

Trojan

b)

Rootkit

c)

Worm

d)

Ransomware

e)

RAT

36.

An organisation defines that a service can be unavailable for up to 8 hours without severe impact. Which concept is this?

a)

MTD

b)

RTO

c)

RPO

d)

MTBF

e)

Hot standby

37.

An attacker uses double tagging to access a VLAN they shouldn’t. What attack is this?

a)

DNS spoofing

b)

Rogue DHCP

c)

VLAN hopping

d)

ARP broadcast

e)

SMURF reflection

38.

Which power problem describes a prolonged reduction in voltage?

a)

Surge

b)

Blackout

c)

Brownout

d)

Spike

e)

Ripple

39.

A technician needs a backup of a device’s running configuration for rollback. This is a:

a)

Bare metal backup

b)

State backup

c)

Config file backup

d)

Cluster snapshot

e)

Disk image

40.

A wireless admin wants to isolate connected clients so they cannot communicate with one another. This is called:

a)

Client isolation

b)

HSRP isolation

c)

VLAN shifting

d)

Beacon limiting

e)

PVLAN routing

41.

If a component is repairable, which metric tracks average repair time?

a)

MTBF

b)

MTTR

c)

MTD

d)

RPO

e)

WRT

42.

When an attacker sends large numbers of DNS queries using a spoofed source IP, this is:

a)

Evil twin

b)

DNS amplification

c)

Rogue AP

d)

ARP flooding

e)

Port scanning

43.

A network admin implements control plane rate-limiting to protect the router CPU. This is:

a)

PVLAN

b)

Control plane policing

c)

Firewall bypass

d)

VLAN pruning

e)

MTTR reduction

44.

Which fire suppression system uses water to extinguish fires?

a)

Halon

b)

CO2

c)

Sprinkler system

d)

Inergen

e)

Dry aerosol

45.

A user sees a fake login pop-up mimicking a real OS window. What malware does this?

a)

RAT

b)

Crypto-malware

c)

Botnet

46.

A network's uptime is measured over a year and expressed as a percentage. This identifies its:

a)

MTBF

b)

High availability

c)

WRT

d)

MTD

e)

MTTR

47.

A malicious person follows an employee through a secured door without authentication. This is:

a)

Shoulder surfing

b)

Piggybacking

c)

VLAN hopping

d)

Rogue DHCP

e)

DNS poisoning

48.

A warm site typically takes how long to activate?

a)

Seconds

b)

Minutes

c)

Hours

d)

Days

e)

Weeks

49.

A cluster that shares one external address between nodes uses what?

a)

Static NAT

b)

Virtual IP

c)

LACP

d)

VRRP

e)

PVLAN

50.

Users are disconnected from Wi‑Fi suddenly due to a targeted attack. What caused this?

a)

Rogue DHCP

b)

Deauthentication attack

c)

Evil twin

d)

VLAN hopping

e)

C2 command

51.

A company wants systems to remain online even if individual servers fail. Which technology supports this?

a)

DNSSEC

b)

Clustering

c)

ARP caching

d)

NAT

e)

RAID 0 only

52.

Attackers try every possible password until one works. This is:

a)

Dictionary attack

b)

Hash poisoning

c)

Brute force

d)

Rainbow flooding

e)

Credential masking

53.

A generator must always be paired with which component?

a)

PVLAN

b)

Load balancer

c)

UPS

d)

DDoS filter

e)

Battery cache

54.

An organisation deploys a web portal that forces users to accept terms before connecting wirelessly. This is:

a)

EAP

b)

Captive portal

c)

PSK

d)

ARP request

e)

Rogue login

55.

A power event where voltage spikes momentarily is called a:

a)

Brownout

b)

Surge

c)

Blackout

d)

Drain

e)

Ripple

56.

A backup method capturing the whole system state including applications and OS is:

a)

Config‑only

b)

Bare metal

c)

Clustered copy

d)

Hot spare

e)

Differential sync

57.

An attacker spoofs a trusted DNS record on a server. This is:

a)

VLAN injection

b)

Rogue gateway

c)

Server‑side DNS poisoning

d)

Evil twin

e)

Load balancing attack

58.

A technician assigns unused switchports to a black hole VLAN. This is an example of:

a)

Attack amplification

b)

Endpoint security

c)

Rogue DHCP prevention

d)

HSRP tuning

e)

PVLAN tunnelling

59.

A laptop overheats in a poorly ventilated room. Which infrastructure support system helps prevent this?

a)

UPS

b)

HVAC

c)

C2 network

d)

LACP

e)

MTBF tracking

60.

Malware that hides itself deeply inside the OS to avoid detection is a:

a)

Worm

b)

Rootkit

c)

Trojan

d)

Botnet

e)

PUP

61.

Switching between multiple active uplinks to improve performance best describes:

a)

RAID 5

b)

LAG

c)

HSRP

d)

PVLAN

e)

VRRP

62.

A technician enforcing strong password length is performing:

a)

VLAN provisioning

b)

Device hardening

c)

MitM prevention

d)

Native VLAN change

e)

DNS caching

63.

In a failover scenario, the time taken to restore normal application operation plus cleanup is:

a)

RPO

b)

WRT

c)

MTTR

d)

MTBF

e)

MTD

64.

An employee viewing another’s PIN over their shoulder is an example of:

a)

Spoofing

b)

Shoulder surfing

c)

Piggybacking

d)

VLAN intrusion

e)

ARP manipulation

65.

A malicious AP installed in the building by an attacker is called:

a)

Rogue AP

b)

Evil twin

c)

Fake DHCP

d)

DNS hijacker

e)

HSRP mirror

66.

A user gets redirected to a fake website although the URL is correct. What attack is likely?

a)

VLAN hopping

b)

DNS poisoning

c)

RAID desync

d)

UPS failure

e)

EAP misconfiguration

67.

Devices with identical MAC addresses on a switch indicate which attack?

a)

Rogue DHCP

b)

MAC spoofing

c)

DDoS

d)

PVLAN

e)

Hot standby

68.

Tools that check vendor updates for embedded IoT devices support:

a)

VLAN tagging

b)

Patch management

c)

Flow control

d)

Multipathing

e)

Power conditioning

69.

When a device loses power for a short period due to grid failure, it experienced a:

a)

Spike

b)

Surge

c)

Brownout

d)

Blackout

e)

Ripple

70.

A hacker uses social engineering via email to trick employees. This is:

a)

Tailgating

b)

Phishing

c)

Botnet seeding

d)

ARP flooding

e)

VLAN injection

71.

An attacker overwhelms a firewall’s state table with SYN packets. This is a form of:

a)

DoS

b)

Evil twin

c)

IPv6 RA guard

d)

Keylogging

e)

MTTR reduction

72.

A network backup that records multiple versions of a configuration allows:

a)

ARP isolation

b)

Version rollback

c)

Rate limiting

d)

PVLAN mapping

e)

Multipath pruning

73.

An admin uses ND Inspection to protect against rogue IPv6 devices. This protects which protocol layer?

a)

Application

b)

IPv6 Neighbor Discovery

c)

ARP

d)

DNSSEC

e)

DHCPv4

74.

To prevent wireless coverage leakage outside a building, an admin adjusts:

a)

VLAN ID

b)

Power levels

c)

STP timers

d)

LACP

e)

MTBF

75.

A node in a cluster that only becomes active during failure is:

a)

Active-active

b)

Active-passive

c)

Fully redundant

d)

Multipath node

e)

Virtual gateway

76.

A system’s operational hours divided by its number of failures measures:

a)

MTTR

b)

MTBF

c)

RTO

d)

MTD

e)

MTDS

77.

A pop-up program that appears legitimate but installs malware is a:

a)

RAT

b)

Trojan

c)

Botnet

d)

DAI

e)

Rogue DHCP

78.

Which wireless security technique isolates guest devices from internal networks?

a)

WPA3

b)

Guest network isolation

c)

ND inspection

d)

VLAN hopping

e)

Hot spare

79.

A device that replaces grid power for long periods is:

a)

PDU

b)

Generator

c)

UPS

d)

Rectifier

e)

Inverter

80.

A malicious actor using a fake MAC address is performing:

a)

MTD

b)

MAC spoofing

c)

Rogue DHCP

d)

DNS tunnelling

e)

ARP restriction

81.

A switch feature that validates ARP packets against DHCP snooping tables is:

a)

Port security

b)

DAI

c)

VRRP

d)

PSK

e)

LACP

82.

The complete loss of power describes a:

a)

Spike

b)

Brownout

c)

Blackout

d)

Surge

e)

Ripple

83.

A configuration where multiple nodes process traffic and share a virtual address describes:

a)

LACP

b)

Active-active cluster

c)

PVLAN

d)

DNSSEC

e)

WAN failover

84.

When an OS forces the user to accept automatic updates for security patches, this is part of:

a)

Multipathing

b)

Patch management

c)

VLAN provisioning

d)

Link aggregation

e)

RTO calculation

85.

Allowing only authorised MAC addresses to use a wireless network is:

a)

Evil twin protection

b)

MAC filtering

c)

Rogue AP

d)

PVLAN

e)

DHCP snooping

86.

A company requires that hosts keep the same IP address for their gateway even during failover. Which technology supports this?

a)

DNSSEC

b)

Virtual IP

c)

LACP

d)

RPO

e)

MTD

87.

A company restricts access to IoT devices to a separate monitoring network. This is:

a)

ARP suppression

b)

Traffic isolation

c)

LAG

d)

RTO alignment

e)

Cold site

88.

A malicious actor broadcasting many gratuitous ARP replies is attempting:

a)

ARP spoofing

b)

RA guard

c)

DHCP starvation

d)

VLAN juggling

e)

VRRP takeover

89.

A sudden increase in voltage that lasts only milliseconds describes a:

a)

Surge

b)

Spike

c)

Brownout

d)

Blackout

e)

Overdraw