WorksheetsCybersecurity & Information Technology Fundamentals Exam
Total questions: 201
Worksheet time: 2hrs 41mins
Why is explicit written permission required before using Nmap on a target system?
To increase scan accuracy
To ensure OS detection works
To avoid legal violations and unauthorized access
To reduce scan time
Which term describes reconnaissance that directly interacts with the target system?
Passive reconnaissance
Active reconnaissance
Shadow reconnaissance
Closed reconnaissance
Which is an example of passive reconnaissance?
Using WHOIS and DNS records
Running NSE scripts
Performing an Nmap SYN scan
Brute-forcing SSH
What is the primary purpose of a Rules of Engagement (RoE) document?
To hide the tester’s identity
To define scope, permission, and testing limits
To provide target passwords
To reduce scan time
Which CIA principle is most likely affected when aggressive scans disrupt services?
Authentication
Availability
Integrity
Confidentiality
Why should testers start with non-aggressive scans on production systems?
To bypass firewalls
To speed up scanning
To reduce the risk of crashing or interrupting services
To avoid incomplete results
Why should NSE scripts be tested in a lab before production use?
They always require root access
To increase OS detection accuracy
Some scripts may disrupt or crash services
They do not work on production systems
How does a vulnerability scan differ from a penetration test?
Vulnerability scans never produce false positives
Pen tests are automated
Pen tests demonstrate real impact; scanners primarily identify weaknesses
Vulnerability scans show real exploitation chains
What is a limitation of vulnerability scanners?
They replace penetration tests entirely
They never require configuration
They may generate false positives or false negatives
They cannot scan open ports
What describes a black-box penetration test?
Tester must avoid exploitation
Tester is given full internal knowledge
Tester has minimal knowledge and simulates an external attacker
Tester only performs vulnerability scans
In MITRE ATT&CK, identifying running services and host information falls under:
Credential Access
Persistence
Discovery
Impact
If default credentials are found during a pentest, the tester should:
Publish them online
Always exploit fully
Ignore them
Use them only if allowed in the RoE
Ethical reporting requires:
Hiding details to avoid responsibility
Providing complete findings privately to the client
Selling findings for profit
Sharing results publicly
Why include a rollback plan in the RoE?
To avoid documenting findings
To enable fast escalation
To increase scan performance
To restore systems if scanning causes service issues
What is the risk of scanning external systems without permission?
Legal penalties under computer misuse laws
Improved OS fingerprinting
Faster learning
Higher accuracy
Why adjust timing/rate limits when scanning sensitive networks?
To reduce risk of overwhelming production systems
To bypass encryption
To avoid IDS detection
To increase scan power
Which technique is least detectable?
Passive OSINT
SYN scan (-sS)
Full connect scan (-sT)
NSE script scan
If a client forbids service disruption but requests deep exploitation testing, what should the tester do?
Continue without notifying
Renegotiate scope
Fully exploit anyway
Cancel the report
Responsible disclosure during a contract means:
Selling vulnerabilities to third parties
Hiding critical vulnerabilities
Posting the exploit online immediately
Reporting findings privately and professionally to the client
Which is a passive source of target information?
UDP scan
SSH enumeration scripts
Job postings and publicly available DNS data
SMB brute force
Why keep detailed logs during testing?
To confuse incident responders
To enable repeat attacks
To increase scan speed
To provide evidence of permission and methodology
Which statement best distinguishes a vulnerability scan from a penetration test?
Pen tests avoid tools and only use manual steps
Scans exploit systems to prove impact and persistence
Pen tests only list missing patches without context
Scans identify weaknesses with automation and breadth
In a black-box penetration test, what information is typically provided to the tester at the start?
Partial source code and test accounts provisioned
Full network diagrams and admin credentials
Only high-level scope and targets defined
Detailed asset inventory and internal topology
Which MITRE ATT&CK tactic best matches credential dumping?
Credential Access tactic in ATT&CK matrix
Persistence tactic for maintaining footholds
Reconnaissance tactic for external scanning
Discovery tactic for host enumeration
Why might a penetration test uncover issues that a vulnerability scan missed?
Testers chain findings creatively with validation
Scanners always output perfectly accurate results
Testers skip exploitation to reduce effort
Scanners perform deep manual verification steps
During an engagement, you detect clear signs of ongoing malicious activity on a client system. What is the most appropriate immediate action?
Notify the client following the rules of engagement
Ignore and proceed to preserve test timeline
Attempt to attack the adversary to stop activity
Post an urgent warning on social media platforms
A routine scan unexpectedly degrades a production service. What should be your first response?
Disconnect and leave without any coordination
Notify the client per the communication plan
Hide the event to avoid delaying the schedule
Restart the scan to finish quickly for reporting
Before publishing a pentest case study, what is required to remain ethical and professional?
List all credentials used during exploitation
Disclose public IP addresses used in testing
Release the full exploit code for transparency
Obtain client permission and anonymize details
Cybersecurity is also called:
Ethical Coding and Scripting
Cloud Engineering and Architecture
InfoSec, IA, or System Security
Data Science, ML, or Analytics
The main purpose of cybersecurity is to ensure:
Automation, AI, Robotics
User experience only
Speed, cost, efficiency
Confidentiality, Integrity, Availability
Which of the following is NOT a cyber threat?
Malware
Phishing
Debugging
SQL Injection
Phishing mainly targets:
IoT devices primarily
Users via deception
Servers using protocols
Cloud providers only
A DDoS attack is most similar to:
A thief breaking a lock
Too many cars clogging a road
A virus infecting a file
Someone stealing passwords
Ransomware works by:
Exploiting SQL vulnerabilities directly
Spying on emails silently
Encrypting files and demanding payment
Flooding the network with traffic
Which attack inserts malicious code into databases?
MITM
DDoS
SQL Injection
Zero-day exploit
An attacker secretly reading messages between two people is:
SQL Injection
Man-in-the-Middle
Insider threat
DoS
What makes Zero-day exploits dangerous?
They are insider-only threats
They affect only old systems
No patch exists yet
They are predictable
Network Security protects against:
Unauthorized access to networks
Data encryption only
Malware in applications
Employee errors primarily
Which tool belongs to Network Security?
Word Processor
Text Editor
Photoshop
VPN
A safe approach to scanning production environments is to:
Start with aggressive full-range scans
Begin with limited, slow scans and monitor impact
Disable monitoring tools entirely
Only use UDP flooding always
Why is documenting scope and exclusions in a Rules of Engagement critical?
It lets testers do anything outside scope
It protects both sides by defining boundaries and risks
It is only useful for billing purposes
It makes tests less effective by preventing exploitation
Which cyber threat primarily relies on social engineering to steal credentials?
Ransomware encrypting user files
Phishing through deceptive messages
DDoS exhausting bandwidth resources
SQL Injection altering database queries
During a Man-in-the-Middle attack, the attacker can:
Encrypt files for ransom
Modify messages between parties
Overload servers with traffic
Exploit unknown vulnerabilities
A primary defense against SQL Injection is to:
Use parameterized queries
Increase network bandwidth
Rely on antivirus scans
Disable user authentication
Using fake apps to steal user data is an example of failing:
Endpoint Security
Application Security
Network Security
IoT Security
Which best protects laptops and smartphones?
SQL Injection filters
DDoS mitigation
Endpoint Security tools
Firewalls only
IoT Security mainly addresses:
Servers in data centers
Firewalls
Connected smart devices
Software coding bugs
Which is part of Operational Security (OpSec)?
Employee training & access control
VPN installation
Mobile device encryption
DDoS filtering
Cloud Security deals with:
Insider misuse only
AWS, Azure, GCP
MS Word
SQL Injection
Which of these showed the early need for digital protection?
Creeper virus & Reaper antivirus
WannaCry ransomware
Zeus Trojan
Stuxnet worm
Today, hackers exploit mostly:
Strong passwords
Weak passwords & outdated systems
Firewalls
Up-to-date software
A company suffers data breach → loses trust & money. This is:
Availability issue
Malware installation
Business consequence
Integrity risk only
For individuals, the top cyber-attack consequences include:
Identity theft & fraud
High CSAT
Free software
Increased storage
Which tool tracks insider misuse patterns?
VPN
UEBA
Antivirus
Load Balancer
SIEM platforms are for:
Detecting phishing emails
Collecting & analyzing security logs
Encrypting files only
Password generation
VPN is mainly used for:
Replacing firewalls
Managing insider threats
Encrypted internet traffic
Faster internet
Best practice for passwords:
Short, simple password
Use one password everywhere
Share with IT staff
Strong & unique, use password manager
Which is NOT a safety step?
2FA
Software updates
Clicking unknown links
Awareness training
Cybersecurity challenges include:
Declining internet use
Decreasing reliance on digital data
Sophisticated evolving attacks
Static threats
Confidentiality ensures:
Only authorized users access data
Data is always accurate
Systems always available
Files backed up
Which example shows confidentiality?
Counting apples to check box size
End-to-end encrypted WhatsApp chat
Firewall load balancer
Cloud backup server
Outdated DES encryption threatens:
Redundancy
Integrity
Availability
Confidentiality
Insider emailing trade secrets = breach of:
Disaster recovery
Integrity
Confidentiality
Availability
In Windows, what is the main purpose of Active Directory (AD)?
To manage printers and scanners
To centralize user and device management across a network
To store files across different drives
To back up system files automatically
Which Windows tool is used to manage Group Policy Objects (GPOs)?
taskmgr.exe
regedit.exe
gpedit.msc
msconfig
What is the function of the “Administrators” group in Windows?
Full control over system settings and configurations
Perform basic user tasks
Limited access to files and folders
Access shared drives only
The “Users” group in Windows has:
Access to system registry files
Permission to modify GPOs
Limited permissions; cannot install software
The same privileges as Administrators
The “Guests” group is typically used for:
Permanent user accounts
Network administration
Installing new software
Temporary or one-time access
In an organization, what does a “Group” represent in Windows?
A single administrator
A shared drive
A type of application
A collection of user accounts
In the analogy, if Users = Employees, then Groups = ?
Passwords
Devices
Buildings
Departments
Which default group can back up and restore files without full system access?
Power Users
Network Configuration Operators
Backup Operators
Administrators
Which command lists local groups in PowerShell?
netstat
ipconfig
net users
net localgroup
What is the purpose of GPOs (Group Policy Objects)?
To configure network cabling
To enforce policies for users and computers
To manage IP addressing
To create new user accounts
Which of the following is not a default Windows group?
Administrators
Guests
Power Users
Network Engineers
Active Directory accounts usually follow what format?
name.domain@work
admin.root@network
company@user.net
user@company.local
A user is able to log in to any office computer using one account. This is possible because of:
Local Users and Groups
Active Directory domain integration
Manual user replication
Remote Desktop access
What is the purpose of “Network Configuration Operators”?
To change network settings without being admin
To configure and test applications
To manage Active Directory users
To create new domains
In Windows, where can you view all local groups?
Device Manager
Control Panel → Network Settings
Computer Management → Local Users and Groups → Groups
Services.msc
The function of a GPO includes all except:
Modifying DNS records
Setting startup/shutdown scripts
Restricting software installation
Enforcing password policies
In an organization, IT changes Vera’s department. Her access automatically updates because:
She has a static IP
Local policy overrides AD
AD updates her group membership
Her GPO is disabled
Which group allows a user to connect remotely to a PC?
Remote Desktop Users
Administrators
Backup Operators
Users
“Everyone” group in Windows includes:
Only local users
Guest accounts only
All users with network access
Only administrators
What is the relationship between Users, Groups, and Permissions?
Users belong to permissions; groups manage files
Users belong to groups; groups are assigned permissions
Permissions control users directly without groups
Which tool allows centralized management of password policies in Windows?
GPO
Firewall
Device Manager
Event Viewer
Why is Active Directory important in security?
It increases internet speed
It blocks internet access
It enforces consistent access control and identity management
It prevents hardware failure
In the AD analogy, who acts as the “security guard at the gate”?
The system firewall
The domain controller
The AD service itself
The DNS server
What would happen if GPOs were misconfigured?
Users could lose access or gain excessive permissions
DNS records would update faster
Network speed would increase
IP conflicts would disappear
What does the “Power Users” group signify?
A group for network management only
A group limited to guest access
A group with full admin rights
Outdated group with privileges between Users and Administrators
Which of the following tasks can a Backup Operator perform?
Change registry entries
Restore files even without permission
Edit GPOs
Add users to AD
Vera’s password policy requires complexity rules and 90-day expiration. This is enforced via:
Registry tweaks only
Local security policy only
User account properties
GPO settings
Vera’s office uses the address 192.168.10.5 for her laptop. When she tries to access a public website, her router translates this private address to 41.210.55.12 before sending it out. What process is responsible for this translation?
DNS Resolution
NAT
DHCP
ARP
Kofi is configuring a small home Wi‑Fi network. He wants all devices to share one internet connection using a single public IP. Which feature allows this?
Subnetting
NAT
DHCP
DNS
A network administrator notices that internal computers have addresses like 172.20.15.7 and 172.18.4.5. Which class of private IPs are these computers using?
Class C
Class B
Class A
Class D
An IT department needs to assign 50 IPs to a subnet. Which CIDR notation would best fit their need with minimal waste?
/28
/25
/26
/27
Vera observes the IP address 2001:0db8::1 on her smart thermostat. What can she conclude about the protocol being used?
It’s IPv4 using NAT
It’s a public IPv4 address
It’s IPv6 using hexadecimal format
It’s IPv4 in binary form
A network device shows the address 192.168.1.10 with subnet mask 255.255.255.0. How many usable hosts can exist in this subnet?
254
253
256
255
Your ISP assigns you a public IP 41.210.55.12. Which of the following statements is TRUE about this address?
It’s only used within your local network
It’s assigned by your router
It’s globally routable and visible on the internet
It belongs to a private address space
During network troubleshooting, Emmanuel sees an IP 10.0.5.25. Which environment is most likely using it?
A web hosting service
A multinational company network
A DNS server farm
A small home router
A system administrator notices that devices with private IPs like 192.168.0.100 are communicating online without having public IPs. Which mechanism makes this possible?
Subnetting
NAT
DNS
IPv6 Tunneling
A company uses 192.168.10.0/24 and needs to allocate IPs to three departments: HR (10 hosts), IT (50 hosts), and Finance (20 hosts). According to VLSM, which subnet mask will IT use?
/26
/25
/28
/27
Fatima converts the IP 192.168.1.1 into binary and gets 11000000.10101000.00000001.00000001. How many bits in total are represented?
8
32
64
16
You are given 192.168.1.0/27. What is the maximum number of usable IP addresses in this subnet?
62
32
30
16
Christabel configures an IPv4 network and runs out of available IPs. She decides to upgrade to IPv6. What key advantage will she gain?
Lower latency
Better broadcast control
Virtually unlimited address space
Simpler addressing format
Nabil notices his office PCs have IPs like 192.168.0.5 and 192.168.0.50, but both access the internet using the same public IP. Which concept explains this?
Subnetting
DNS
CIDR
NAT
A router receives a packet from 192.168.1.100 destined for 142.250.190.78 (Google). Before forwarding, it changes the source IP to 41.210.55.12. What must it record in its NAT table?
Only public IP
Private IP and corresponding public IP with ports
Only DNS entry
Destination and source MAC address
Vera is tasked with converting an IPv4 address like 182.168.1.2 into binary. How many total bits will the binary form contain?
24
16
32
8
An IPv6 address supports 2^128 possible combinations. Which analogy best represents this scale?
A small village directory
A mega city with infinite houses
A city with fixed postcodes
A limited street with a few houses
Kobby configures the subnet 192.168.10.0/28 for HR. How many usable host addresses are available in this subnet?
32
30
16
14
To handle a large number of devices, IPv6 primarily relies on which feature instead of IPv4’s NAT?
Port forwarding
Expanded address space
CIDR only
DNS caching
A network engineer creates the subnet 192.168.1.0/26 for a branch office. How many total IP addresses (including network and broadcast) are in this subnet?
64
62
32
128
What is the primary purpose of Nmap?
To assign IP addresses
To encrypt communications
To scan networks and discover open ports
To manage users
Who created Nmap?
Vint Cerf
Fyodor (Gordon Lyon)
Linus Torvalds
Tim Berners-Lee
Which of the following is a common use of Nmap?
Editing videos
Managing DNS zones
Network discovery and auditing
Creating websites
Which protocol uses a three-way handshake?
ICMP
TCP
UDP
ARP
UDP is best described as:
Connection-oriented and reliable
Connectionless and faster
Slow and guaranteed
Secure and encrypted
How many total ports exist per transport protocol?
65,536
1024
4096
256
What command performs a default Nmap scan?
nmap target
nmap -sU target
nmap -A target
nmap --script target
What does the port state “open” mean in Nmap?
No service is listening
The port is blocked by a firewall
The application is actively accepting connections
Nmap cannot reach the host
Which Nmap flag is used for OS detection?
-A
-p
-O
-V
Which Nmap option displays help information?
-T
-h
-H
-v
What does “-A” enable in Nmap?
Aggressive scan with OS and version detection
Access restriction
Auto script update
Anonymous scan mode
The command nmap -sV is used for:
Version detection of services
Vulnerability scanning
OS detection
Port blocking
What does the -p flag specify in Nmap?
Packet capture
Ports to scan
Proxy list
Permissions
Which of the following Nmap states means “firewall interference”?
Unfiltered
Filtered
Closed
Open
What is the purpose of NSE scripts?
Speed up DNS resolution
Block suspicious ports
Encrypt scan traffic
Automate vulnerability checks and scanning tasks
Which command brute-forces DNS subdomains?
nmap -sS -p 80
nmap -O
nmap --script=dns-brute
Which port does DNS typically use?
53
80
22
443
Which protocol does DHCP use to assign IPs dynamically?
FTP
HTTP
TCP/IP
UDP
How many steps are in the DHCP handshake (DORA)?
3
2
5
4
What does DNS translate?
MAC addresses into URLs
Usernames into passwords
Domain names into IP addresses
IP addresses into MACs
What does the Nmap timing option “-T5” do?
Disables aggressive mode
Enables passive scanning
Slows the scan
Speeds up the scan but may be noisy
What does “open|filtered” indicate in Nmap results?
Port is closed
Nmap failed completely
Firewall blocks traffic, uncertain state
The port is open
Why are UDP scans harder to interpret?
UDP encrypts packets
UDP doesn’t respond when ports are closed
Nmap doesn’t support UDP
They require root privileges
What risk does a “DNS Spoofing” attack create?
It changes router passwords
It scans DNS ports
It redirects users to fake sites
It blocks UDP traffic
Which command performs a DNS UDP scan on Google’s server?
nmap --script vulnrs.nse
nmap -A -p 80 8.8.8.8
nmap -sU -p 53 8.8.8.8
nmap -sS -p 53 8.8.8.8
In DHCP, what does the “Offer” message represent?
The client asking for IP
The server suggesting an IP lease
The final confirmation
The client rejection
Which DNS attack uses small queries to produce large responses for DDoS?
DNS Poisoning
DNS Amplification
DNS Spoofing
DNS Tunneling
What is the correct order of the DHCP DORA process?
Discover → Offer → Request → Acknowledge
Discover → Acknowledge → Offer → Request
Request → Offer → Discover → Acknowledge
Offer → Request → Discover → Acknowledge
Which tool command shows DNS open on both TCP and UDP?
nmap -O 8.8.8.8
nmap -A -T5
nmap -sS -p 443 8.8.8.8
nmap -sV -p 53 8.8.8.8
DHCP lease refers to:
Manual configuration of IP
Temporary IP assignment for a duration
Permanent IP assignment
A financial firm segments its network into VLANs: one for HR, one for Finance, and one for Guest Wi‑Fi. However, a misconfigured switch trunk allows traffic from the Guest VLAN to pass into Finance VLAN for 3 minutes before being blocked. No data was stolen, but traffic flowed where it should not. What was primarily violated?
Proper network segmentation
DNS configuration
Physical security
Encryption standards
A company uses Wi‑Fi protected with WPA2. An attacker performs a Man‑in‑the‑Middle attack by setting up an identical SSID with stronger signal strength, causing users to connect unknowingly. The attacker captures login credentials before sending traffic to the real router. Which network weakness enabled this attack?
Lack of certificate‑based authentication
Limited VLAN support
Incorrect subnet mask
Router not supporting IPv6
A streaming service experiences sudden service failure. Logs show millions of requests from multiple distributed IP sources, overwhelming the server. The internal network remains intact and data is untouched, but legitimate users cannot access the service. Which attack type is occurring?
DNS Spoofing
DDoS
Man‑in‑the‑Middle
ARP Poisoning
A security analyst notices packet traces where the source and destination IP addresses remain unchanged, but packet payloads are subtly altered. This results in incorrect data being displayed to the receiving device without users realizing it. Which attack is most likely?
Port Scanning
MITM Data Injection
DDoS Flooding
Rogue DHCP Assignment
A network admin uses traceroute to examine packet paths to a remote server. The results show unexpected hops passing through a foreign country’s network infrastructure. No service outage occurs. What is the likely issue?
DHCP lease expiration
Border gateway protocol (BGP) routing manipulation
VLAN mis‑tagging
Wi‑Fi interference
An enterprise router is configured to allow remote management for IT staff. An attacker discovers the port is open over the internet and brute‑forces login credentials. No firewall rules blocked access. Which oversight enabled the attack?
Misconfigured DNS caching
Improper firewall access control
Wrong subnet mask
Duplicate IP address conflict
During an investigation, analysts find that internal traffic between employees’ computers was not segmented, allowing lateral movement after one machine was compromised. Only one employee fell for phishing, yet the attacker spread to 12 systems. Which network control was missing?
DNS recursion
IPv6 tunneling support
VLAN separation
Static routing
A business uses a public Wi‑Fi network at a café to access corporate servers through HTTP instead of HTTPS. An attacker eavesdrops and copies login session cookies. Why was the attack successful?
DNS records were outdated
Switch did not support spanning tree
Data was not encrypted in transit
Traffic was routed through fiber optic cables
A server remains online but begins responding extremely slowly. Packet captures show frequent retransmissions, dropped packets, and congestion across multiple hops. The organization’s internal network is operating normally. Where is the problem most likely located?
Local subnet addressing
External routing path congestion
An employee connects an unauthorized wireless access point to the company switch port to “extend Wi‑Fi.” Unknown devices begin connecting through it, bypassing corporate authentication. What type of device has been introduced?
VLAN Trunk Bridge
Fiber Media Converter
DNS Forwarder
Rogue Access Point
What is the primary purpose of using Wireshark in network analysis?
To configure network devices
To monitor system performance
To capture and analyze network packets
To create network diagrams
Which protocol can be analyzed using Wireshark to troubleshoot web traffic?
HTTP
All of the above
SMTP
FTP
In Wireshark, what does the term 'filter' refer to?
A feature for exporting captured data
A method to enhance packet capture speed
A tool for editing packet data
A way to limit displayed packets based on criteria
What is the primary purpose of using Nmap in network security?
To perform network mapping and discovery
To encrypt data transmissions
To exploit vulnerabilities
To monitor user activity
Which Nmap option is used to perform a version detection scan?
-O
-sV
-sS
-A
What does the Nmap command 'nmap -sP 192.168.1.0/24' accomplish?
Runs a full TCP connect scan
Detects the operating system of devices
Scans for open ports on a single host
Performs a ping scan on the specified subnet
What is the primary function of Cisco Packet Tracer?
Network simulation and visualization
Data encryption
Malware detection
Web hosting
Which of the following devices can be simulated using Cisco Packet Tracer?
Firewalls only
Only switches
Only routers
Routers and switches
In Cisco Packet Tracer, what feature allows users to visualize network traffic?
Simulation mode
Real-time mode
Design mode
Debug mode
What is the primary purpose of Cisco Packet Tracer?
Malware analysis
Network simulation and visualization
Data encryption
Web development
Which feature allows users to create and save network topologies in Cisco Packet Tracer?
Simulation mode
Workspace
Device manager
Packet capture
In Cisco Packet Tracer, which device is used to connect multiple networks?
Hub
Access Point
Router
Switch
What is the primary function of Cisco Packet Tracer?
Data encryption
Cloud storage management
Network simulation and visualization
Web development
Which of the following devices can be simulated using Cisco Packet Tracer?
Only firewalls
Only IoT devices
Only servers
Routers and switches
In Cisco Packet Tracer, how can you test network connectivity?
By using the ping command
By changing the device color
By adding more devices
By increasing bandwidth
What is the primary function of Wireshark?
To encrypt network traffic
To analyze and capture network packets
To manage network devices
To create firewalls
Which protocol can Wireshark capture and analyze?
All of the above
TCP
FTP
HTTP
What feature of Wireshark allows users to filter captured packets?
Export options
Packet coloring
Statistics overview
Display filters
What is the primary goal of a penetration test?
To identify vulnerabilities in a system
To create software documentation
To increase system performance
To improve user experience
Which of the following is a common method used in social engineering attacks?
SQL Injection
Phishing emails
Network scanning
Malware distribution
What does the term 'zero-day vulnerability' refer to?
A vulnerability that is fixed on the same day it is discovered
A vulnerability that is exploited before a patch is available
A vulnerability that has been publicly disclosed
A vulnerability that affects only outdated software
What is the primary function of Cisco Packet Tracer?
Web development
Data encryption
Database management
Network simulation and visualization
Which of the following devices can be simulated using Cisco Packet Tracer?
Firewalls only
Only switches
Only routers
Routers and switches
How can users share their Cisco Packet Tracer projects?
By exporting to PDF only
By uploading to social media
By sharing .pkt files
By printing directly from the application
What protocol does Wireshark primarily use to capture network traffic?
All of the above
UDP
TCP
HTTP
Which feature in Wireshark allows you to filter packets based on specific criteria?
Coloring Rules
Packet Analysis
Capture Filters
Display Filters
What is the purpose of the 'Follow TCP Stream' feature in Wireshark?
To view all packets in a capture
To reconstruct the data flow of a TCP connection
To analyze packet loss
To filter out non-TCP packets
Which of the following is NOT a component of the CIA triad?
Integrity
Availability
Confidentiality
Authentication
What does the 'Integrity' aspect of the CIA triad primarily ensure?
Data is accessible when needed
Data is accurate and unaltered
Data is kept secret from unauthorized users
Data is encrypted during transmission
In the context of the CIA triad, which of the following best describes 'Availability'?
Ensuring data can be accessed when required
Ensuring data is not lost
Maintaining data accuracy over time
Preventing unauthorized access to data
What is the primary benefit of running Kali Linux in a virtual machine?
It eliminates the need for a host operating system
It allows for easier updates
It provides a secure environment for testing
It requires less hardware resources
Which virtualization software is commonly used to run Kali Linux?
Notepad
VMware
Microsoft Word
Adobe Photoshop
What is a common use case for Kali Linux running in a virtual machine?
Web browsing
Gaming
Penetration testing and security assessments
Office productivity
What is the primary benefit of using a ticketing system in customer support?
To track and manage customer inquiries efficiently
To reduce the number of employees needed
To automate marketing campaigns
To eliminate the need for customer feedback
Which feature is essential for a ticketing system to enhance team collaboration?
Automated email responses
Customizable ticket categories
Real-time chat functionality
Integration with social media
How can a ticketing system improve response times for customer issues?
By limiting the number of tickets submitted
By prioritizing tickets based on urgency and impact
By providing a single point of contact for all inquiries
By allowing customers to resolve issues independently
What is the primary purpose of using Cisco Packet Tracer?
To simulate and visualize network configurations
To perform real-time network attacks
To monitor network traffic in real-time
To manage physical network devices
Which feature of Cisco Packet Tracer allows users to create complex network topologies?
Network visualization
Multi-user collaboration
Simulation mode
Device configuration
How can users test their networking skills using Cisco Packet Tracer?
By participating in online competitions
By creating and completing custom labs
By accessing real-world network devices
By reading documentation only
What is the consequence of failing to secure sensitive data?
Increased customer trust
Legal repercussions and fines
Improved system performance
Enhanced user experience
Which of the following is a common method for preventing phishing attacks?
Using outdated software
Using multi-factor authentication
Disabling firewalls
Ignoring suspicious emails
What is the main goal of a penetration test?
To exploit vulnerabilities for personal gain
To identify and fix security weaknesses
To disrupt business operations
To sell vulnerabilities to competitors
What is the primary goal of a firewall?
To monitor network traffic
To block unauthorized access
To encrypt data transmissions
To improve network speed
Which of the following is a common method of social engineering?
Network scanning
Malware installation
Phishing emails
SQL Injection
What does the term 'zero-day vulnerability' refer to?
A vulnerability that has been publicly disclosed
A vulnerability that is exploited before a patch is available
A vulnerability that is fixed on the same day it is discovered
A vulnerability that affects only outdated software
What is a primary benefit of using virtual machines in a development environment?
Reduced software compatibility
Increased hardware costs
Limited resource allocation
Isolation of applications
Which hypervisor type runs directly on the host's hardware?
Container Hypervisor
Cloud Hypervisor
Type 2 Hypervisor
Type 1 Hypervisor
What is a common use case for virtual machines in enterprise environments?
Running legacy applications
Creating physical servers
Storing large databases
Enhancing network speed
What does SLA stand for in the context of service agreements?
Service Level Agreement
Systematic Log Analysis
Service Level Assessment
Standardized License Agreement
Which of the following is typically included in an SLA?
Company financial statements
Employee personal information
Performance metrics
Marketing strategies
What is a common consequence of failing to meet SLA requirements?
Increased customer satisfaction
Improved employee morale
Financial penalties
Enhanced service features
