wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

T5 - System Assessment and Testing

Total questions: 87

Worksheet time: 1hrs 27mins

Name
Class
Date
1.

What is the primary goal of a vulnerability management program?

a)

Block all inbound internet traffic

b)

Identify, prioritize, and remediate weaknesses on an ongoing basis

c)

Replace all legacy systems with cloud systems

d)

Encrypt every file on the network

2.

Which factor MOST directly influences how often an organization should run vulnerability scans?

a)

Employee dress code

b)

Risk appetite

c)

Building occupancy

d)

Vendor warranty length

3.

Regulatory requirements such as PCI DSS or FISMA MOSTLY affect which aspect of scanning?

a)

Choice of operating system

b)

Scan frequency and evidence requirements

c)

Screen resolution of scan consoles

d)

Number of technicians hired

4.

In a credentialed scan, the scanner:

a)

Uses only ICMP to identify hosts

b)

Logs in to systems with supplied accounts to gather deeper configuration data

c)

Only scans from outside the firewall

d)

Cannot see patch levels

5.

What is an intrusive plug-in in the context of vulnerability scanning?

a)

A browser extension that blocks pop-ups

b)

A scan check that may disrupt service or crash a system

c)

A plug-in that only checks for informational issues

d)

An add-on that encrypts scan traffic

6.

Which statement best describes a discovery scan?

a)

It verifies that specific vulnerabilities have been fixed

b)

It scans only web applications

c)

It maps out assets and open ports to see what is present

d)

It checks compliance documentation

7.

A validation scan is primarily used to:

a)

Identify all unknown assets

b)

Confirm that previously identified vulnerabilities have been remediated

c)

Measure wireless signal strength

d)

Identify phishing emails

8.

What does an internal scan perspective typically show?

a)

What an attacker on the internet can see

b)

Only wireless access points

c)

What an attacker or insider with internal network access could see

d)

Only web applications

9.

In the SCAP family, CVE primarily provides:

a)

Standard device names

b)

Standard configuration templates

c)

Standard vulnerability identifiers

d)

Standard encryption protocols

10.

Which of the following assigns IDs to publicly known vulnerabilities?

a)

Standard encryption algorithms

b)

Common Vulnerability Scoring System (CVSS)

c)

Common Vulnerabilities and Exposures (CVE)

d)

Vulnerability assessment tools

11.

What is the primary use of the Common Vulnerability Scoring System (CVSS)?

a)

Assign IP addresses

b)

Score vulnerability severity numerically

c)

Configure firewalls

d)

Encrypt scan data

12.

Which BEST describes static application testing?

a)

Running the app and injecting inputs

b)

Analyzing source or compiled code without executing it

c)

Fuzzing web forms

d)

Intercepting network traffic only

13.

Dynamic application testing primarily focuses on:

a)

Reviewing design documents

b)

Evaluating the application while it is running

c)

Scoring vulnerabilities with CVSS

d)

Reviewing backup logs

14.

Which approach combines elements of static and dynamic testing and often involves agents or instrumentation in the runtime environment?

a)

Interactive application security testing (IAST)

b)

Packet sniffing

c)

Port scanning

d)

Sandboxing

15.

Nikto and Arachni are examples of which type of tool?

a)

Endpoint encryption clients

b)

Web application vulnerability scanners

c)

SIEM platforms

d)

Patch management tools

16.

A false positive in vulnerability scanning is:

a)

A real vulnerability reported with low severity

b)

A reported issue that does not actually exist

c)

A vulnerability that is invisible to the scanner

d)

A vulnerability with a CVSS of 0

17.

A false negative is best described as:

a)

A vulnerability the scanner correctly reports as low risk

b)

A harmless issue reported as critical

c)

A real vulnerability that the scan fails to detect

d)

Any vulnerability with unknown impact

18.

When a scan report lists severity/risk ratings, what does “severity” communicate?

a)

Number of users affected

b)

Likely impact if the vulnerability is exploited

c)

Cost of the scanner license

d)

Age of the system

19.

Rules of engagement (ROE) for a penetration test should primarily define:

a)

Employee vacation schedules

b)

Scope, methods, time windows, and data-handling expectations

c)

Annual salary for testers

d)

Hardware warranty conditions

20.

In a security audit, "evidence" usually refers to:

a)

Marketing materials

b)

Documentation or artifacts that prove a control is designed and operating effectively

c)

User complaints

d)

Security awareness posters

21.

An executive summary in a test report is primarily written for:

a)

Tier-1 technicians

b)

System administrators only

c)

Senior leadership and non-technical stakeholders

d)

The scanner vendor

22.

In the test → findings → remediation → retest lifecycle, what is the main purpose of the retest step?

a)

Increase the number of findings

b)

Confirm that remediation was effective

c)

Reduce scanner license cost

d)

Reset all severity ratings to low

23.

An asset inventory used with vulnerability management should primarily help you:

a)

Track cafeteria food orders

b)

Identify which systems exist and how critical they are

c)

Disable all wireless networks

d)

Select wallpaper images

24.

Why is it important to update scanner software and plug-ins regularly?

a)

To change the color of the UI

b)

To add new vulnerability checks and fix scanner vulnerabilities

c)

To reduce the scanner's memory usage

d)

To improve the scanner's user interface design

25.

Which description best fits a security assessment compared to testing?

a)

It only reviews financial data

b)

It focuses on evaluating controls and risk posture more broadly, not just running tools

c)

It never uses technical tools

d)

It is always anonymous

26.

Which factor is LEAST likely to be used when assigning a risk rating to a vulnerability?

a)

Exploitability

b)

Business impact

c)

Asset criticality

d)

Favorite color of the system admin

27.

A K-12 district has low risk appetite and must meet PCI DSS requirements for its lunch payment system. Which scanning decision is MOST appropriate?

a)

Run scans once every three years

b)

Run regular automated scans and additional scans after significant changes

c)

Never run scans; rely only on firewalls

d)

Run scans only on teacher laptops

28.

During a scan of the grade-reporting server, an intrusive plug-in causes the application to crash during school hours. Which step should have prevented this?

a)

Running only discovery scans

b)

Reviewing ROE and scheduling intrusive checks in approved maintenance windows

c)

Setting CVSS to 10 for all vulnerabilities

d)

Scanning only desktops

29.

Your team needs to verify that a critical patch for an SSL vulnerability actually applied across all SIS servers. Which testing approach is MOST appropriate?

a)

Non-credentialed external discovery scan

b)

Credentialed validation scan targeting the SSL configuration

c)

Password spraying attack

d)

Wireless site survey

30.

A Nessus report flags an old SMB vulnerability on a fully patched file server. The sysadmin believes it’s a false positive. What should they do FIRST?

a)

Delete the report

b)

Disable all SMB plug-ins

c)

Check the server’s patch level and configuration manually against the finding description

d)

Mark all SMB findings as accepted risk

31.

A school’s web server later gets compromised by an RDP exploit that was not in the last scan report. What does this MOST likely illustrate?

a)

False positive

b)

False negative

c)

Low severity issue

d)

Proper remediation

32.

An external scan shows the district’s VPN gateway has only a few exposed services. An internal scan of the same device reveals many more open ports. What is the BEST explanation?

a)

Misconfigured DHCP

b)

Different perspectives due to firewalls and segmentation

c)

Scanner malfunction

d)

Rogue wireless access points

33.

Internal scans show almost no findings on student devices, but random spot checks reveal outdated systems. Which control is MOST likely hiding issues from the scanner?

a)

Network segmentation blocking scan traffic to some VLANs

b)

Overly aggressive password policy

c)

High-speed switches

d)

New laptops

34.

The district just acquired a separate building and network from another organization. You want a quick, non-disruptive view of what’s there. Which scan is MOST appropriate initially?

a)

Credentialed validation scan

b)

Non-credentialed discovery scan from inside that network

c)

Full intrusive pen test immediately

d)

Web application scan only

35.

A developer asks which testing method would identify input validation issues by sending crafted requests to a running web app. Which answer is MOST accurate?

a)

Static testing

b)

Dynamic application testing

c)

Backup testing

d)

Tape rotation testing

36.

A security consultant wants real-time insight into how the app behaves while processing specific requests, using instrumentation inside the running code. Which technique are they describing?

a)

IAST

b)

Packet capture

c)

Password cracking

d)

Log rotation

37.

The district’s public website keeps failing a PCI external scan due to outdated SSL ciphers. Which control is MOST effective for identifying and detailing this issue?

a)

Nikto or Arachni web app scan against the site

b)

Password policy review

c)

Wireless heat map

d)

Physical access audit

38.

A principal reads an executive summary that says, “High-risk vulnerabilities exist on student information systems,” and panics about imminent data loss. What was MOST likely missing from the summary?

a)

Technical jargon and plugin IDs

b)

Clear risk context, timelines, and remediation plan

c)

The scanner vendor’s logo

d)

Color graphics

39.

During a compliance audit, the auditor asks for evidence that monthly scans are being performed. Which item BEST meets this request?

a)

A verbal statement from the sysadmin

b)

A screenshot of the scan schedule and sample reports with dates

c)

A list of technician names

d)

The scanner license invoice

40.

A scan identifies 2 critical vulnerabilities on the gradebook server and 80 medium issues on lab PCs. The team fixes only the easy medium issues first. Which risk management mistake are they MOST likely making?

a)

Ignoring change management

b)

Prioritizing quantity of fixes over impact

c)

Overusing encryption

d)

Running too many validation scans

41.

Your team performs scans, generates findings, and starts remediation tickets but never schedules retests. Months later, you discover several “fixed” items still vulnerable. What part of the lifecycle failed?

a)

Assessment

b)

Reporting

c)

Verification/validation

d)

Identification

42.

A penetration test of the district network proceeds without defined ROE, and the tester accidentally causes an outage during state testing. Which control would have MOST reduced this risk?

a)

Enforcing multi-factor authentication

b)

A signed, detailed rules-of-engagement document approved by leadership

c)

Longer passwords

d)

Automatic updates on student laptops

43.

Scanner plug-ins haven’t been updated in over a year. A major RCE vulnerability disclosed last month is not flagged in scans. Which conclusion is MOST accurate?

a)

The vulnerability doesn’t affect schools

b)

The scanner likely lacks signatures for the new CVE due to outdated feeds

c)

The network is fully patched

d)

The firewall blocked the exploit permanently

44.

A security engineer wants to automatically correlate vulnerabilities across multiple tools using standard identifiers. Which SCAP component would be MOST helpful?

a)

CPE

b)

CVE and CVSS references

c)

WPA3

d)

SNMP

45.

The district chooses to use both a commercial scanner and OpenVAS for network scans. What security principle are they MOST directly applying?

a)

Obfuscation

b)

Defense in depth and tool diversity

c)

Mandatory access control

d)

Single point of failure

46.

A junior tech disables entire families of plug-ins “to make scans faster,” without documenting what was changed. What is the MOST significant security risk?

a)

Larger reports

b)

Increase in false positives

c)

Important vulnerability checks may never run, leading to missed issues

d)

Loss of internet access

47.

Asset criticality has been defined as: - Gradebook servers: critical - Library kiosks: low - Cafeteria menu site: medium Which remediation order BEST reflects this information after a scan?

a)

Cafeteria → Kiosks → Gradebook

b)

Gradebook → Cafeteria → Kiosks

c)

Kiosks → Cafeteria → Gradebook

d)

All at once, no prioritization

48.

The network team deploys agents on key servers to send configuration data back to the vulnerability management platform. This MOST closely describes:

a)

Non-credentialed scanning

b)

Agent-based vulnerability assessment

c)

Static application testing

d)

Wireless intrusion detection

49.

In your project, you diagrammed Plan → Test/Assess → Analyze → Report → Remediate → Retest → Monitor. A real incident shows that testing and reporting occurred, but remediation tickets were never created. Which stage failed?

a)

Plan

b)

Analyze

c)

Remediate

d)

Monitor

50.

A consultant reviews policies, interviews staff, and verifies that required controls are in place without actively exploiting anything. Which activity are they MOST likely performing?

a)

Penetration test

b)

Security audit/assessment

c)

Vulnerability scan

d)

Social media review

51.

A pen test uncovers a vulnerable club web server run by a student group. Who MOST needs a non-technical explanation of risk and remediation steps?

a)

Tier-1 tech only

b)

Director of Technology only

c)

Building administrator responsible for the club and student safety

d)

Internet service provider

52.

A scan finds: - 2 critical vulnerabilities on SIS servers - 10 high on payroll - 60 medium on lab PCs Which remediation strategy is BEST?

a)

Fix all medium issues first to reduce report length

b)

Focus on SIS and payroll critical/high findings first, then address mediums by asset criticality

c)

Defer all fixes until summer break

d)

Fix lab PCs only because they are numerous

53.

Your team is deciding policy for intrusive plug-ins on production systems. Which policy is BEST?

a)

Disable all intrusive plug-ins permanently

b)

Run intrusive plug-ins only in approved windows with ROE and change control

c)

Run intrusive plug-ins continuously for maximum coverage

d)

Only run intrusive plug-ins on student devices

54.

Which is the BEST reason to choose credentialed scans in the district environment?

a)

They always run faster than non-credentialed scans

b)

They require no configuration

c)

They provide deeper insight into patch levels and configurations, reducing false positives

d)

They eliminate the need for audits

55.

The security team is designing a scanner maintenance process. Which plan is BEST?

a)

Update plug-ins once per year and rely on firewalls

b)

Enable automatic daily plug-in updates and verify manually on a set schedule

c)

Never update plug-ins to keep results consistent

d)

Only update after a breach

56.

Management complains about “too many false positives.” Which action is the BEST long-term response?

a)

Disable families of checks to reduce noise

b)

Tune scan templates and create a documented process for validating and recording true/false positives

c)

Run fewer scans

d)

Lower all severity ratings by one level

57.

The school board will review security in the next meeting. Which report is MOST appropriate for them?

a)

Raw Nessus CSV report

b)

Detailed technical report with plugin IDs

c)

Executive summary describing top risks, trends, and remediation status

d)

Syslog extract from the firewall

58.

You need to store scan results and audit evidence. Which practice is BEST?

a)

Save everything to a public shared drive

b)

Store reports in a restricted repository with access controls and regular backups

c)

E-mail reports to everyone in the district

d)

Print and stack them on your desk

59.

The district wants a comprehensive assessment approach for externally accessible systems. Which combination is BEST?

a)

Network vulnerability scans only

b)

Network scans plus web application testing on public-facing sites

c)

Physical security walkthrough only

d)

Password policy review only

60.

After patching a critical SSL bug, what is the BEST retest strategy?

a)

Assume success and move on

b)

Wait six months and scan again

c)

Run a focused validation scan on affected systems and document results

d)

Disable all SSL ciphers

61.

A vendor-supplied student portal fails a pentest due to several high SQL injection issues. Which response is BEST?

a)

Ignore the findings because the vendor is responsible

b)

Immediately disconnect or restrict access, open a ticket with the vendor including technical details, and track remediation

c)

Change the logo and hope the vendor fixes it later

d)

Only inform students

62.

You are designing a scan schedule considering risk appetite, regulatory, business, and technical constraints. Which plan is MOST appropriate for critical servers?

a)

Monthly scans, plus additional scans after major changes

b)

Scans only after incidents

c)

Annual scans only

d)

Continuous intrusive scans 24/7

63.

A colleague asks whether using SCAP standards is worth the effort. Which justification is BEST?

a)

They make reports look nicer.

b)

They standardize IDs and scores so multiple tools and teams can speak the same vulnerability language.

c)

They eliminate the need for patching.

d)

They make scans invisible to attackers.

64.

Before running an external pentest, which communication plan is BEST?

a)

Tell no one to keep it realistic

b)

Notify only students

c)

Have ROE signed by leadership, inform help desk and NOC of windows and symptoms to expect

d)

Announce all test details publicly on the website

65.

When creating remediation tickets, which field from scan reports is MOST critical to include for tracking and correlation?

a)

Scanner UI theme

b)

Vulnerability ID (e.g., CVE/Plugin ID)

c)

Scanner serial number

d)

Technician’s favorite snack

66.

You are writing SOPs for Tier-1 techs on handling suspected false positives/negatives. Which instruction is MOST important?

a)

If you’re unsure, delete the finding.

b)

Validate configuration against the description, document your steps, and escalate if you cannot conclusively verify.

c)

Change the score to medium.

d)

Disable that plug-in.

67.

Which of the following BEST represents a mature assessment and testing program in a K-12 district?

a)

One annual scan with no follow-up

b)

Regular scanning, documented ROE for tests, risk-based prioritization, retesting, and reporting

c)

Random scans with no documentation

d)

Testing only when vulnerabilities are reported

68.

A mature program is characterized by which of the following?

a)

Executive reporting

b)

Continuous, documented, and risk-driven processes

c)

Only relying on vendor marketing claims

d)

Only performing ad-hoc testing after breaches

69.

How should you respond to a suggestion of running a surprise, after-hours pentest on production systems without leadership approval?

a)

Approve it; realism is more important than policy

b)

Approve only if they promise to be careful

c)

Reject it; testing without ROE and approvals exposes the district to legal and operational risk

d)

Ignore the suggestion

70.

To satisfy an external compliance requirement, the district must demonstrate both internal and external vulnerability management. Which approach is BEST?

a)

Internal scans only

b)

External scans only

c)

Regular internal scans plus quarterly external scans from an approved vendor

d)

Rely only on antivirus

71.

What is the BEST rebuttal to the claim, “As long as we run monthly scans, we’re automatically compliant with all frameworks”?

a)

True, scans are all that matter.

b)

Compliance usually requires broader controls, documentation, and sometimes specific scan types and evidence, not just a schedule.

c)

We only need daily scans.

d)

Compliance doesn’t care about scanning.

72.

A manager proposes: “We should only fix critical vulnerabilities and ignore medium and low issues forever.” Which evaluation is MOST accurate?

a)

Good idea; it saves time

b)

Acceptable as long as we document it

c)

It is a poor approach; all vulnerabilities should be addressed based on risk

d)

Only critical vulnerabilities matter

73.

You review two pentest ROE drafts: - Draft A: Lists scope, time windows, data-handling rules, and escalation paths. - Draft B: Says “Do whatever you need to; don’t tell anyone.” Which is BEST and why?

a)

Draft A, because it controls risk and sets expectations

b)

Draft B, because it is more realistic

c)

Both are equal

d)

Neither; ROE is unnecessary

74.

Raw scan results containing internal IPs, hostnames, and exploits are placed on an unsecured shared drive accessible to all staff. What is the BEST assessment?

a)

Acceptable; transparency is good

b)

Risky; scan data is sensitive and could help attackers or curious insiders

c)

Required for compliance

d)

Harmless because it’s not real data

75.

You must choose a scanning approach for: - 3 high-value servers (SIS, payroll, HR) - 200 student lab PCs Which plan is BEST?

a)

Same minimal template, monthly, for all devices

b)

More frequent, deeper credentialed scans for high-value servers; periodic broader scans for labs

c)

Scan only lab PCs

d)

Scan only servers

76.

An external firm reviews whether controls are designed and operating effectively against a standard, while another team regularly runs scanners and pen tests. Which mapping is MOST accurate?

a)

Firm = vulnerability testing, internal team = audit

b)

Firm = audit, internal team = vulnerability testing

c)

Firm = compliance testing, internal team = audit

d)

Firm = penetration testing, internal team = compliance testing

77.

You’re revising the “Security Assessment & Testing — Overview for Northrop Techs” guide. Which change would MOST improve its usefulness for Tier-1 technicians?

a)

Remove the lifecycle diagram to save space

b)

Add a section that shows example scan findings and how Tier-1 should create tickets with severity, asset, and evidence attached

c)

Replace all text with marketing slogans

d)

Aim the entire guide only at the school board

78.

A security team wants to use real student data in a test environment to evaluate SQL injection defenses. Which step is MOST important before using the data?

a)

Ensure the testing server uses the same database engine

b)

Mask or anonymize all sensitive student information

c)

Copy production logs to improve analyst accuracy

d)

Export the data in CSV instead of SQL format

79.

During a penetration test, the tester asks for a copy of the SIS (student information system) database to test query manipulation. What is the MOST appropriate response?

a)

Provide read-only access to the real database

b)

Give the tester a sanitized dataset containing no real student data

c)

Deny the request and cancel the test

d)

Provide full access if the tester signs the ROE

80.

A technician uploads a vulnerability scan report containing IPs, OS versions, and open ports to a shared Google Drive accessible by teachers. What is the PRIMARY security concern?

a)

Teachers may delete the report

b)

CSV formatting may break

c)

Sensitive infrastructure data is exposed to unauthorized users

d)

Severity values may not sort correctly

81.

A school district assigns data classifications to all items. What classification is MOST appropriate for vulnerability scan results?

a)

Public

b)

Internal

c)

Sensitive

d)

Public-with-restrictions

82.

Why is auditor independence critical during a security audit?

a)

It ensures the audit finishes more quickly

b)

It guarantees high-severity findings

c)

It prevents conflicts of interest and improves objectivity

d)

It allows auditors to modify production systems

83.

A system administrator who manages backups is assigned to audit the district’s backup controls. What is the MAIN problem?

a)

They may choose the wrong tools

b)

They cannot objectively audit a control they operate

c)

They are too familiar with the system

d)

They may not have enough time

84.

A district wants more objective audits. Which option BEST increases independence?

a)

Have the help desk manager audit every system

b)

Allow network engineers to audit their own firewall rules

c)

Hire an external auditor for annual control validation

d)

Ask the database admin to audit patch compliance

85.

During an audit, a technician says, “Just trust me—the server is patched.” What should the auditor request instead?

a)

A written statement from the technician

b)

Verbal confirmation from another staff member

c)

A screenshot or log file showing patch status

d)

A network diagram

86.

In a K–12 district, who must ultimately approve penetration testing Rules of Engagement (ROE)?

a)

Any Tier-1 technician

b)

The building principal

c)

The Director of Technology or CIO

d)

The athletic director

87.

A vendor offers a free pen test on the district’s SIS. A tech supervisor signs the ROE without informing leadership. What is the MOST serious concern?

a)

The test may slow down Chromebooks

b)

The ROE may violate FERPA or district data-handling rules

c)

The pen test will find too many issues

d)

The vendor may use a nonstandard tool