WorksheetsCYF MCQ Part 2
Total questions: 139
Worksheet time: 1hrs 10mins
Why is high availability critical for the finance industry?
For customer satisfaction only
Continuous trading, compliance, and customer trust
Only for software updates
It is not critical
Which of the following is a threat to availability?
Unauthorized database access
DoS attacks
Natural disasters like hurricanes
All of the above
Categorizing the impact of a threat helps organizations to:
Increase complexity
Reduce employee workload
Determine the dollar impact of a threat
Avoid redundancy
Asset identification includes which of the following?
Hardware, software, network devices, firmware, libraries
Only software applications
Only operating systems
Only user accounts
Which of the following is the correct order for asset classification?
Identify assets → Assign owner → Determine criteria → Implement schema
Assign owner → Determine criteria → Identify assets → Implement schema
Determine criteria → Implement schema → Assign owner → Identify assets
Implement schema → Identify assets → Assign owner → Determine criteria
Asset standardization helps to:
Increase maintenance cost
Reduce complexity, increase security, and improve maintenance
Increase number of software applications used
Eliminate risk entirely
Quantitative risk analysis involves:
Using opinions and scenarios
Assigning numeric values to risk, such as dollars or percentages
Ignoring asset value
None of the above
Qualitative risk analysis is:
Numeric calculation of losses
Subjective evaluation of likelihood and impact
Always more accurate than quantitative
Only applicable to physical assets
Which of the following is NOT a risk mitigation strategy?
Accept
Reduce
Avoid
Ignore
Defense in depth aims to:
Use a single strong defense
Layer multiple security measures to minimize risk
Avoid using redundancy
Transfer all risks to a third party
Which principle ensures that if one security layer fails, others still protect the system?
Obscurity
Simplicity
Diversity
Limiting
Obscuring information in security means:
Making system details hard to detect by attackers
Using strong passwords only
Eliminating redundancy
Increasing system complexity
Simplicity in security solutions is important because:
Complexity always guarantees security
Complex systems are easy to manage
Simple internal design reduces misconfiguration risk
Simplicity prevents attacks entirely
A single point of failure is:
A backup component
A critical element whose failure halts operations
A type of RAID configuration
A non-critical process
N+1 redundancy ensures:
Only N components are used with no backup
N components plus one backup can take over if one fails
Fault tolerance is ignored
Network loops are created
RAID provides:
Only backup power
Data redundancy and improved performance
User authentication
Firewall protection
Spanning Tree Protocol (STP) prevents:
Loops in networks with redundant paths
Data mirroring
Risk analysis failures
Unauthorized access
Which of the following is a benefit of system resiliency?
Maintains data availability during attacks
Rapid recovery from failures
Router Redundancy: What is considered a single point of failure in a network?
A redundant switch
A router serving as the only default gateway
Multiple load-balanced servers
Multiple network paths
Router Redundancy: First-hop redundancy provides:
Backup power supply
Alternate routing paths at the first-hop router
Firewall protection
End-user device security
Router Redundancy: Which of the following is not a router redundancy protocol?
HSRP
VRRP
GLBP
OSPF
Router Redundancy: In HSRP, the standby router’s main function is:
Forward packets actively
Block redundant paths
Monitor the active router and take over if it fails
Assign IP addresses
Location Redundancy: Synchronous replication requires:
Low bandwidth and high latency
Real-time updates and low latency
Periodic updates
Only a single site
Location Redundancy: Which replication method is most bandwidth-efficient?
Synchronous
Asynchronous
Point-in-time
Real-time
Resiliency: Resiliency in networking is best described as:
Adding multiple firewalls
Maintaining network operation despite failures
Using only one network path
Backing up data once a month
Resiliency: What is the difference between redundancy and resiliency?
Redundancy prevents attacks; resiliency detects them
Redundancy adds backups; resiliency ensures continued operation
Redundancy is cheaper than resiliency
Resiliency is hardware only
Resiliency: Application resilience ensures:
Applications always run on a single server
Applications function even if one component fails
Users can bypass security controls
Only data backups are available
Resiliency: Cisco IOS resilient configuration protects routers by:
Using multiple IP addresses
Maintaining secure copies of the IOS image and running configuration
Encrypting all packets
Blocking unauthorized users
Incident Response: What is the primary role of a CSIRT?
Manage incident response and maintain the response plan
Install antivirus software
Audit annual budgets
Design hardware chipsets
Which is not a stage of incident handling?
Detection & analysis
Containment, eradication & recovery
Post-incident follow-up
Network configuration
Post-incident follow-up is important to:
Increase network speed
Prevent recurrence and improve monitoring
Reduce server memory usage
Upgrade software
NAC ensures that:
Only authorized and compliant devices access the network
All devices can connect
Routers are always online
Firewalls are disabled
Which is a common NAC compliance check?
Firewall logs
Virus updates
VLAN configuration
Physical cable labelling
How does an IPS differ from an IDS?
IPS only monitors traffic; IDS blocks it
IPS operates inline and blocks malicious traffic; IDS monitors passively
IDS detects viruses; IPS detects malware
IDS replaces firewalls; IPS replaces routers
Operating an IDS in promiscuous mode means:
It blocks unauthorized traffic
It monitors a copy of traffic without affecting flow
It changes the source IP of packets
It forwards all traffic to the Internet
Which is not a detection method used by IPS?
Signature-based
Profile-based
Protocol analysis-based
Encryption-based
NetFlow provides:
Firewall rules
Packet flow statistics through a router or switch
Encryption of network traffic
User authentication
IPFIX is based on which NetFlow version?
Version 5
Version 7
Version 9
Version 10
Indicators of a cyberattack include:
User login success
Account lockouts
Printer activity
Power outages
Advanced threat intelligence helps organizations:
Encrypt all data automatically
Detect attacks earlier and respond faster
Eliminate all vulnerabilities
Replace firewalls
Which is a human-caused disaster?
Earthquake
Hurricane
Sabotage
Tsunami
Difference between a DRP and a business continuity plan:
DRP restores systems after disaster; business continuity ensures operations continue
DRP replaces servers; business continuity replaces users
DRP encrypts data; business continuity backs up files
DRP and business continuity are the same
Which is not a disaster recovery control type?
Preventive
Detective
Corrective
Predictive
Why restore mission-critical systems first?
To minimize downtime and maintain essential operations
To reduce electricity costs
To test new software
To upgrade all hardware
A network is only as strong as:
Its firewall
Its antivirus software
Its weakest link
Its bandwidth
Endpoint security includes which of the following?
Workstations only
Servers only
LAN devices, servers, and end systems
Only IP phones
Device hardening involves:
Installing any software
Securing administrative access, maintaining passwords, and implementing secure communications
Using default configurations
Ignoring patches
Which is the first stage of the Kill Chain?
Exploitation
Delivery
Reconnaissance
Installation
Command and Control in the Kill Chain refers to:
Gaining remote access and controlling the target
Creating a malicious payload
Gathering information
Installing software
Which stage involves sending the exploit to the target?
Delivery
Installation
Weaponization
Action
Hardening an OS includes:
Installing unnecessary programs
Removing unnecessary services and applying security patches
Leaving default passwords
Ignoring updates
MBSA (Microsoft Baseline Security Analyzer) is used to:
Scan malware only
Assess missing updates and security misconfigurations
Encrypt files
Backup data
Security patches:
Introduce new vulnerabilities
Fix vulnerabilities and prevent exploits
Only affect hardware
Are optional for security
Spyware protection scans for:
Viruses
Keyloggers
Spam emails
Browser history
True or False: Running multiple antimalware programs simultaneously is recommended.
True
False
Rogue antivirus software usually:
Removes malware
Warns of fake infections and installs malware
Updates patches
Secures VPN connections
A patch differs from a service pack in that:
Patch fixes specific vulnerabilities, service pack combines multiple updates
Patch is optional, service pack is mandatory
Patch encrypts data
Patch clones hard drives
Which is NOT a benefit of automated patch management?
Centralized reporting
Users cannot disable updates
Users manually select updates
Force updates on schedule
A host-based firewall:
Runs on a network switch
Filters traffic to and from the local host
Encrypts email
Tracks GPS
HIDS (Host Intrusion Detection System) can monitor:
Only traffic reaching the host
Entire network traffic
VPN tunnels
Wireless devices only
VPNs are used to:
Encrypt traffic over public networks
Install patches
Backup files
Scan malware
VPN clients:
Encrypt data before sending over the Internet
Monitor host-based activity
Block phishing websites
Run only on mobile phones
Wireless Security: WEP is:
Strong and secure
Obsolete and vulnerable
Mandatory for WPA2
A firewall protocol
Wireless Security: WPA2 uses:
TKIP only
AES encryption
WEP encryption
VPN tunneling
Wireless Security: Mutual authentication prevents:
Malware installation
Rogue access points
OS misconfiguration
Data backup failure
File Access Control: Principle of Least Privilege means:
Give users full access
Limit users to only necessary resources
Deny all access
Ignore permissions
File Access Control: Denying a user permission to a network share:
Can be overridden
Always overrides other permissions
Does nothing
Deletes files
File Access Control: Moving a file to a different volume:
Keeps original permissions
Inherits new permissions
Encrypts the file
Deletes the file
File Encryption: EFS (Encrypting File System) in Windows:
Encrypts entire drives only
Encrypts files/folders for a specific user
Is hardware only
Backups data
File Encryption: BitLocker requires:
Antivirus software
TPM enabled in BIOS
VPN connection
Disk cloning
System and Data Backups: Data backups should:
Be performed regularly and stored offsite
Be ignored
Only include software
Be public
System and Data Backups: Two key considerations for backups are:
Speed and size
Frequency and security
Encryption and WEP
VPN and HIDS
Content Screening and Blocking: Content filtering types include:
Browser-based
Router-based
Cloud-based
All of the above
Disk Cloning and Deep Freeze: Disk cloning is used to:
Encrypt files
Restore a system to a pre-configured state
Block malicious sites
Track GPS
Disk Cloning and Deep Freeze: Deep Freeze:
Protects the system after a restart
Offers real-time protection
Encrypts files
Is a firewall
Physical Security: Cipher locks:
Can restrict access by time
Record door usage
Are programmable
All of the above
Logout Timers: Idle timeout and screen lock prevent:
Data backup errors
Unauthorized access when a user leaves a workstation
Rogue access points
Antivirus failure
GPS Tracking: Tracking a device without consent is:
Legal
Illegal
Recommended
Required
GPS Tracking: Legal GPS tracking examples include:
Locating vehicles or pets with consent
Hacking phones
Unauthorized surveillance
Rogue access points
What is the purpose of Remote Desktop in Windows?
To install Windows updates automatically
To view and control a computer from a remote location
To back up files to the cloud
To monitor network traffic
Which TCP port does Remote Desktop use by default?
22
23
3389
80
Which Windows tool allows a technician to assist a user while the user watches the repair in real-time?
Remote Desktop
Remote Assistance
Task Manager
Device Manager
Which protocol transmits login credentials in plaintext?
Telnet
SSH
SCP
HTTPS
Which protocol encrypts login credentials and data for secure remote management?
Telnet
HTTP
SSH
FTP
What port does SSH use?
22
23
3389
80
What is the purpose of SCP?
To scan for open ports
To monitor system logs
To securely transfer files between remote systems
To manage Active Directory
Why should an administrator disable unused switch ports?
To increase bandwidth
To prevent unauthorized access
To reduce power consumption
To improve routing efficiency
Removing unnecessary services on devices:
Reduces network speed
Improves security
Increases network traffic
Has no effect
Why are privileged accounts a target for cyber criminals?
They are used to store public data
They have elevated access to systems and devices
They have default passwords
They are rarely monitored
Which of the following is a best practice for privileged accounts?
Use shared passwords indefinitely
Grant all users full access
Enforce least privilege and rotate passwords regularly
Disable logging for administrative sessions
Where are account policies automatically applied in a Windows domain?
Local Security Policy
Group Policy on Windows Server
Task Scheduler
Windows Firewall
How often must a user change their password if the policy requires a 90-day rotation?
Every 30 days
Every 60 days
Every 90 days
Every 120 days
What happens if a user enters the wrong password too many times according to account lockout policy?
Account is deleted
Account locks for a configured duration
Password resets automatically
User is granted guest access
What is the purpose of audit logs?
To monitor hardware temperature
To track security events and user activity
To manage power supply
To encrypt passwords
Which of the following is a type of system log?
DHCP log
Operating System log
VLAN log
MAC address log
Which of the following are types of power loss events?
Spike and surge
Fault and blackout
Sag and brownout
Inrush and overload
What device allows a graceful shutdown during power failure?
Firewall
UPS (Uninterruptible Power Supply)
Router
Switch
Why are HVAC systems important in IT facilities?
They provide internet access
They control temperature, humidity, airflow, and air filtering
They manage network protocols
They encrypt sensitive data
One security risk of smart HVAC systems is:
Overheating servers
Unauthorized access by contractors
Power spikes
Packet loss
What is the purpose of hardware monitoring in server farms?
To increase network speed
To monitor CPU, memory, disk, fan, power, and network status
To manage VLANs
To configure firewalls
What is the main difference between a NOC and SOC?
NOC monitors cybersecurity; SOC monitors network performance
NOC monitors network performance; SOC monitors cybersecurity incidents
NOC is physical; SOC is cloud-based
NOC handles hardware; SOC handles software
What is a Red Team exercise?
A firewall configuration process
A simulated cyberattack to test defenses
A DHCP server check
VLAN segmentation
What is port security on a switch used for?
To increase bandwidth
To restrict access to authorized MAC addresses
To encrypt traffic
To assign IP addresses
What is the primary function of VLANs?
To increase network speed
To segment networks logically and protect sensitive data
To assign IP addresses
To filter traffic by protocol
Name one threat to firewalls.
VLAN attacks
Theft, hacking, or attacks on ACLs
DHCP failure
IP address exhaustion
Why change default passwords on network devices?
To improve network speed
To prevent unauthorized access
To reduce electricity consumption
To enable VLANs
Which wireless standard provides the strongest encryption?
WEP
WPA
IEEE 802.11i / WPA2
Open system authentication
Which authentication method allows any device to connect to a wireless network?
WEP
Open system authentication
WPA2
TKIP
True or False: WEP is secure because its encryption key changes for every packet.
True
False
What tool can check for open ports on a device?
Firewall
Port scanner
VLAN
DHCP server
Which protocol automatically assigns IP addresses to devices?
DNS
DHCP
NTP
RIP
Which protocol translates domain names to IP addresses?
DHCP
NTP
DNS
RIP
Why is NTP important for network security?
Encrypts DNS traffic
Synchronizes clocks for logs, digital certificates, and event tracking
Limits network hops
Assigns IP addresses
How many hops does RIP allow at maximum?
10
12
15
20
What does the CIA triad in cybersecurity stand for?
Control, Information, Access
Confidentiality, Integrity, Availability
Cybersecurity, Infrastructure, Access
Confidentiality, Intelligence, Access
Why has increased connectivity led to higher cybersecurity risks?
Devices are cheaper
Users work from home
More devices interconnected increases exposure to theft, fraud, and abuse
Organizations have more servers
Which of the following is NOT a cybersecurity specialist role?
Penetration tester
Security analyst
Network security professional
Graphic designer
Why is understanding cyber law and ethics important for cybersecurity specialists?
To develop software
To guide ethical decisions and ensure compliance
To manage databases
To prevent hardware failures
Why are users often considered the weakest link in cybersecurity?
They have administrative access
Poor user practices can undermine technical controls
They know the network architecture
They always follow policies
Which of the following is a common user-related threat?
Firewall misconfiguration
Data theft
Router vulnerability
Network congestion
Which is a countermeasure to manage user threats?
Enable remote desktop
Security awareness training
Disable antivirus
Increase bandwidth
Which of the following is considered a device in the Device Domain?
Router only
Desktop, laptop, tablet, smartphone
Firewall only
Cloud storage only
A common threat to devices is:
Employee turnover
Malware infection via unauthorized downloads
Compliance violation
Poor website design
Which is a way to protect devices?
Enable screen lockout and passwords
Use outdated software
Share admin credentials
Disable antivirus
What is the LAN Domain?
A collection of cloud services
A network of interconnected devices within an organization
A type of software
A security protocol
Which is a threat to LAN?
Employee training
Network OS vulnerabilities
Disaster recovery plan
Business continuity plan
Which is a countermeasure for LAN threats?
Encrypt wireless networks
Install unauthorized apps
Disable firewalls
Share passwords
What defines the Private Cloud Domain?
Servers accessible to the public
Private servers accessible only to organization members
Cloud services hosted externally
Public Wi-Fi networks
Which is a threat to the Private Cloud?
Unauthorized access
Open-source software
Screen lockout
Antivirus scanning
Which countermeasure helps manage Private Cloud threats?
Intrusion detection and prevention systems (IDS/IPS)
Leaving ports open
Sharing credentials
Disabling monitoring
Which is NOT a cloud service model?
SaaS
PaaS
IaaS
NAS
Which is a threat to the public cloud?
Account hijacking
Antivirus scanning
Password rotation
Hardware updates
Which countermeasure helps secure the public cloud?
Multifactor authentication
Sharing access credentials
Physical Facilities Domain: Which is a threat to physical facilities?
Unauthorized access
Firewall misconfiguration
Malware infection
Software patching
Physical Facilities Domain: Which is a countermeasure for physical facilities?
CCTV and access control
Open network access
Public Wi-Fi sharing
Ignoring visitors
Application Domain: A common threat to applications is:
Unauthorized access to critical systems
Password expiration
Security awareness training
Data backups
Application Domain: Which is a measure to manage application threats?
Software testing before launch
Leaving servers unpatched
Sharing admin credentials
Disabling logging
Miscellaneous: Why is monitoring user behavior important?
To detect abnormal or risky activity
To save electricity
To improve graphics
To share passwords
Miscellaneous: Why is patching and updating software essential?
It fixes vulnerabilities and reduces exploitation risk
It slows down the system
It reduces network speed
It increases storage usage
