Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Access Control and Security Quiz

Total questions: 30

Worksheet time: 30mins

Name
Class
Date
1.

Which of the following is NOT one of the primary purposes of Access Controls?

a)

Define permissions for digital and physical resources

b)

Ensure only authorized entities can access specific resources

c)

Eliminate the need for Multi-Factor Authentication (MFA)

d)

Track and monitor user activity rigorously

2.

The process of verifying a user's claimed identity, often using passwords or biometrics, is known as:

a)

Identification

b)

Authorization

c)

Authentication

d)

Accountability

3.

Granting specific permissions based on a user's verified role is referred to as:

a)

Identification

b)

Authorization

c)

Authentication

d)

Accountability

4.

Which type of access control involves logging and auditing access events for traceability and compliance?

a)

Identification

b)

Authorization

c)

Authentication

d)

Accountability

5.

Traditional locks, security guards, and biometric scanners for entry are examples of which type of access control?

a)

Logical Controls

b)

Physical Controls

c)

Network Controls

d)

Software Controls

6.

Which of the following is an example of a Logical Access Control?

a)

CCTV and alarm systems

b)

Badges and biometric scanners

c)

Traditional locks

d)

Access Control Lists (ACLs) and role-based access

7.

Enforcing the principles of 'least privilege' and 'need-to-know' is a key part of minimizing access risks within which type of control?

a)

Physical Controls

b)

Logical Controls

c)

Identification Controls

d)

Accountability Controls

8.

The combination of policies, programs, and technologies used to enforce security measures is a definition of combining which element of access control?

a)

Permissions

b)

Authorization

c)

Monitoring

d)

Technologies

9.

Restricting data center access to only authorized personnel using biometric scans is a specific example of:

a)

Logical Access Control

b)

Accountability

c)

Physical Access Control

d)

Authorization by default

10.

Multi-Factor Authentication (MFA) is specifically listed as a component of which kind of access control?

a)

Physical Controls

b)

Biometric Controls

c)

Logical Controls

d)

Traditional Controls

11.

What is the core function of a firewall?

a)

To create encrypted tunnels over public networks

b)

To manage user and system permissions

c)

To act as a critical barrier, controlling traffic between trusted and untrusted networks

d)

To log and audit access events

12.

A firewall's primary security action is to:

a)

Enforce security policies to permit or deny data flow

b)

Encrypt data at rest and in transit

c)

Provide single sign-on capabilities

d)

Automatically update all system software

13.

A firewall that inspects only IP headers for source and destination, offering fast but basic security, is known as a:

a)

Stateful Inspection firewall

b)

Proxy Firewall

c)

Next-Gen Firewall (NGFW)

d)

Packet Filtering firewall

14.

Which type of firewall tracks the state of active connections, offering improved security over basic filters?

a)

Packet Filtering firewall

b)

Stateful Inspection firewall

c)

Proxy Firewall

d)

Personal Firewall

15.

Proxy Firewalls are primarily characterized by their ability to:

a)

Intercept and filter application-level traffic, providing deep inspection

b)

Block traffic based solely on IP addresses

c)

Focus only on outbound traffic

d)

Track connection states at the network layer

16.

Next-Gen Firewalls (NGFW) combine deep packet inspection with which of the following advanced features?

a)

Basic IP filtering

b)

Traditional locks

c)

Application awareness and intrusion prevention

d)

Only Geo-location filtering

17.

Firewall types are available as both software-based and which other form?

a)

Cloud-only virtual machines

b)

Network-based hardware appliances

c)

Satellite communication devices

d)

Biometric scanners

18.

What is a crucial part of firewall maintenance?

a)

Never changing the rules to ensure stability

b)

Regular rule configuration updates and diligent log reviews

c)

Allowing all traffic by default

d)

Disabling the Intrusion Detection/Prevention System (IDPS)

19.

The practice of segmenting network zones to limit lateral movement in case of a breach is a key aspect of firewall:

a)

Configuration

b)

Inspection

c)

Segmentation

d)

Maintenance

20.

Geo-location Filtering is an advanced firewall feature that blocks traffic based on:

a)

Packet size

b)

Application protocol

c)

Specific geographic regions

d)

Connection state

21.

What is the main security benefit provided by a Virtual Private Network (VPN)?

a)

It scans files for malware.

b)

It acts as a perimeter filter for all network traffic.

c)

It creates secure, encrypted tunnels over public networks, protecting data confidentiality and integrity.

d)

It enforces least privilege access control.

22.

VPNs are described as essential for employees needing to:

a)

Encrypt their stored hard drives.

b)

Access internal resources securely from outside the corporate network (Remote Access)

c)

Inspect encrypted traffic for malicious content.

d)

Block traffic from specific geographic regions.

23.

A VPN used to connect two separate office locations securely over public infrastructure is known as a:

a)

Remote Access VPN

b)

Personal VPN

c)

Site-to-Site VPN

d)

Software VPN

24.

VPNs are often integrated with which other security technology to provide an additional layer of network security and policy enforcement?

a)

Badges

b)

Traditional Locks

c)

CCTV Systems

d)

Firewalls

25.

In the layered security model, which of the three technologies is positioned to secure data in transit over untrusted networks?

a)

Access Controls

b)

Firewalls

c)

VPNs

d)

CCTV Systems

26.

Which layer of the security approach is primarily responsible for monitoring and filtering network traffic at the perimeter?

a)

VPNs

b)

Firewalls

c)

Access Controls

d)

Physical Controls

27.

The most fundamental layer of defense, positioned to restrict who can enter and what they can do with resources, is:

a)

VPNs

b)

Firewalls

c)

Access Controls

d)

Geo-location Filtering

28.

What concept does the combination of Access Controls, Firewalls, and VPNs exemplify?

a)

Single Point of Failure

b)

Defense-in-Depth (Layered Security Approach)

c)

Least Privilege Access

d)

Simple Security Model

29.

The purpose of a VPN tunnel is to protect data during transmission by ensuring:

a)

Only network segmentation is applied.

b)

Confidentiality and Integrity

c)

Physical security of the data center.

d)

Authentication is only done once.

30.

Which of the following is listed as a challenge associated with firewalls?

a)

They always solve all security problems automatically.

b)

Maintenance complexity and the inherent risk of misconfiguration

c)

They are never integrated with other systems.

d)

They do not support rule configuration updates.