WorksheetsAccess Control and Security Quiz
Total questions: 30
Worksheet time: 30mins
Which of the following is NOT one of the primary purposes of Access Controls?
Define permissions for digital and physical resources
Ensure only authorized entities can access specific resources
Eliminate the need for Multi-Factor Authentication (MFA)
Track and monitor user activity rigorously
The process of verifying a user's claimed identity, often using passwords or biometrics, is known as:
Identification
Authorization
Authentication
Accountability
Granting specific permissions based on a user's verified role is referred to as:
Identification
Authorization
Authentication
Accountability
Which type of access control involves logging and auditing access events for traceability and compliance?
Identification
Authorization
Authentication
Accountability
Traditional locks, security guards, and biometric scanners for entry are examples of which type of access control?
Logical Controls
Physical Controls
Network Controls
Software Controls
Which of the following is an example of a Logical Access Control?
CCTV and alarm systems
Badges and biometric scanners
Traditional locks
Access Control Lists (ACLs) and role-based access
Enforcing the principles of 'least privilege' and 'need-to-know' is a key part of minimizing access risks within which type of control?
Physical Controls
Logical Controls
Identification Controls
Accountability Controls
The combination of policies, programs, and technologies used to enforce security measures is a definition of combining which element of access control?
Permissions
Authorization
Monitoring
Technologies
Restricting data center access to only authorized personnel using biometric scans is a specific example of:
Logical Access Control
Accountability
Physical Access Control
Authorization by default
Multi-Factor Authentication (MFA) is specifically listed as a component of which kind of access control?
Physical Controls
Biometric Controls
Logical Controls
Traditional Controls
What is the core function of a firewall?
To create encrypted tunnels over public networks
To manage user and system permissions
To act as a critical barrier, controlling traffic between trusted and untrusted networks
To log and audit access events
A firewall's primary security action is to:
Enforce security policies to permit or deny data flow
Encrypt data at rest and in transit
Provide single sign-on capabilities
Automatically update all system software
A firewall that inspects only IP headers for source and destination, offering fast but basic security, is known as a:
Stateful Inspection firewall
Proxy Firewall
Next-Gen Firewall (NGFW)
Packet Filtering firewall
Which type of firewall tracks the state of active connections, offering improved security over basic filters?
Packet Filtering firewall
Stateful Inspection firewall
Proxy Firewall
Personal Firewall
Proxy Firewalls are primarily characterized by their ability to:
Intercept and filter application-level traffic, providing deep inspection
Block traffic based solely on IP addresses
Focus only on outbound traffic
Track connection states at the network layer
Next-Gen Firewalls (NGFW) combine deep packet inspection with which of the following advanced features?
Basic IP filtering
Traditional locks
Application awareness and intrusion prevention
Only Geo-location filtering
Firewall types are available as both software-based and which other form?
Cloud-only virtual machines
Network-based hardware appliances
Satellite communication devices
Biometric scanners
What is a crucial part of firewall maintenance?
Never changing the rules to ensure stability
Regular rule configuration updates and diligent log reviews
Allowing all traffic by default
Disabling the Intrusion Detection/Prevention System (IDPS)
The practice of segmenting network zones to limit lateral movement in case of a breach is a key aspect of firewall:
Configuration
Inspection
Segmentation
Maintenance
Geo-location Filtering is an advanced firewall feature that blocks traffic based on:
Packet size
Application protocol
Specific geographic regions
Connection state
What is the main security benefit provided by a Virtual Private Network (VPN)?
It scans files for malware.
It acts as a perimeter filter for all network traffic.
It creates secure, encrypted tunnels over public networks, protecting data confidentiality and integrity.
It enforces least privilege access control.
VPNs are described as essential for employees needing to:
Encrypt their stored hard drives.
Access internal resources securely from outside the corporate network (Remote Access)
Inspect encrypted traffic for malicious content.
Block traffic from specific geographic regions.
A VPN used to connect two separate office locations securely over public infrastructure is known as a:
Remote Access VPN
Personal VPN
Site-to-Site VPN
Software VPN
VPNs are often integrated with which other security technology to provide an additional layer of network security and policy enforcement?
Badges
Traditional Locks
CCTV Systems
Firewalls
In the layered security model, which of the three technologies is positioned to secure data in transit over untrusted networks?
Access Controls
Firewalls
VPNs
CCTV Systems
Which layer of the security approach is primarily responsible for monitoring and filtering network traffic at the perimeter?
VPNs
Firewalls
Access Controls
Physical Controls
The most fundamental layer of defense, positioned to restrict who can enter and what they can do with resources, is:
VPNs
Firewalls
Access Controls
Geo-location Filtering
What concept does the combination of Access Controls, Firewalls, and VPNs exemplify?
Single Point of Failure
Defense-in-Depth (Layered Security Approach)
Least Privilege Access
Simple Security Model
The purpose of a VPN tunnel is to protect data during transmission by ensuring:
Only network segmentation is applied.
Confidentiality and Integrity
Physical security of the data center.
Authentication is only done once.
Which of the following is listed as a challenge associated with firewalls?
They always solve all security problems automatically.
Maintenance complexity and the inherent risk of misconfiguration
They are never integrated with other systems.
They do not support rule configuration updates.
