wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

module 8 - cognate 3

Total questions: 77

Worksheet time: 39mins

Name
Class
Date
1.

Which core security principle is maintained through redundancy, DDoS protection, and disaster recovery?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Non-repudiation

2.

Confidentiality, a core security principle, is primarily ensured using which two methods?

a)

Cryptographic hashing and digital signatures

b)

Encryption and access controls

c)

Redundancy and DDoS protection

d)

Threat modeling and risk assessment

3.

Integrity is ensured via which of the following?

a)

Multi-Factor Authentication (MFA)

b)

Hardware Security Modules (HSM)

c)

Cryptographic hashing and digital signatures

d)

Cloud Access Security Brokers (CASB)

4.

Network Security in the Digital Era is described as foundational to all network operations and digital transformation, and it extends beyond traditional networks to which areas?

a)

Cloud, IoT, and mobile

b)

Mainframe, on-premise, and legacy systems

c)

WAN, LAN, and SAN

d)

Zero Trust Network Access (ZTNA) and SASE

5.

Which of the following is an example of a sophisticated threat mentioned in the document?

a)

Ransomware

b)

Cloud Workloads

c)

TLS 1.3

d)

Businesss impact analysis

6.

Vulnerability weaknesses caused by human error, social engineering, or malicious insiders fall under which vulnerability category?

a)

Technical

b)

Human

c)

Configuration

d)

Physical

7.

What is described as an emerging threat vector caused by improper cloud service settings?

a)

Supply Chain Compromises

b)

API Security Weaknesses

c)

Cloud Misconfigurations

d)

Advanced Persistent Threats (APTs)

8.

What contemporary threat involves stealthy, continuous computer hacking processes?

a)

Ransomware

b)

Business Email Compromise (BEC)

c)

Advanced Persistent Threats (APTs)

d)

Microservices

9.

An attack targeting third-party vendors and software dependencies is known as a(n):

a)

Business Email Compromise (BEC)

b)

Supply Chain Compromise

c)

Technical Flaw

d)

Nation-state attack

10.

Malicious software that encrypts data and demands payment for restoration is defined as:

a)

Advanced Persistent Threat (APT)

b)

Ransomware

c)

Cloud Misconfiguration

d)

Social Engineering

11.

Which security model requires verification for every access request, regardless of its source?

a)

DevSecOps

b)

Zero Trust Architecture

c)

Cloud Security Posture Management (CSPM)

d)

Secure Access Service Edge (SASE)

12.

Integrating security practices into the DevOps pipeline for continuous security is the definition of:

a)

Cloud Workloads

b)

Zero Trust Architecture

c)

DevSecOps

d)

Security Orchestration & Response (SOAR)

13.

What is an automated tool used for detecting and remediating cloud misconfigurations?

a)

SIEM

b)

Cloud Security Posture Management (CSPM)

c)

Multi-Factor Authentication (MFA)

d)

Hardware Security Module (HSM)

14.

What cloud-native architecture combines network and security services?

a)

ZTNA

b)

CASB

c)

Secure Access Service Edge (SASE)

d)

EDR

15.

What control within Identity & Access Management (IAM) is specifically used for controlling and monitoring privileged account access?

a)
  • Multi-Factor Authentication (MFA)

b)
  • Privileged Access Management (PAM)

c)
  • TLS 1.3

d)
  • Cloud Access Security Brokers (CASB)

16.

What is the latest protocol mentioned for securing internet communications?

a)

SSL 3.0

b)

TLS 1.2

c)

TLS 1.3

d)

HTTPS

17.

Physical devices that securely manage digital keys are known as:

a)

Cloud Workloads

b)

Hardware Security Modules (HSM)

c)

Microservices

d)

Endpoint Detection & Response (EDR)

18.

Cloud Access Security Brokers (CASB) function as security policy enforcement points between which two parties?

a)

Internal network and the firewall

b)

Cloud users and providers

c)

EDR and SIEM

d)

ZTNA and SASE

19.

Providing secure remote access based on user identity and context is the goal of:

a)

Privileged Access Management (PAM)

b)

Multi-Factor Authentication (MFA)

c)

Zero Trust Network Access (ZTNA)

d)

Hardware Security Module (HSM)

20.

What tool continuously monitors and responds to threats on endpoints?

a)

SIEM (Security Information & Event Management)

b)

EDR (Endpoint Detection & Response)

c)

SOAR (Security Orchestration & Response)

d)

CASB (Cloud Access Security Brokers)

21.

The continuous process of identifying and remediating security weaknesses is referred to as:

a)

Business Impact Analysis

b)

Quantum-Readiness

c)

Vulnerability Management

d)

Threat Prioritization

22.

What systematic approach uses models like STRIDE and DREAD to identify and prioritize potential threats?

a)

Risk Assessment

b)

Business Impact Analysis

c)

Threat Modeling

d)

Security Orchestration & Response (SOAR)

23.

What are independently deployable services that make up modern applications?

a)

Cloud Workloads

b)

Microservices

c)

Critical Assets

d)

Hardware Security Modules

24.

Real-time analysis of security alerts is performed by which security operation tool?

a)

XDR (Extended Detection & Response)

b)

SOAR (Security Orchestration & Response)

c)

SIEM (Security Information & Event Management)

d)

EDR (Endpoint Detection & Response)

25.

What platform provides cross-layer detection and response?

a)

SIEM (Security Information & Event Management)

b)

XDR (Extended Detection & Response)

c)

SOAR (Security Orchestration & Response)

d)

CASB (Cloud Access Security Brokers)

26.

What tool is designed for automating security operations and response workflows?

a)

EDR (Endpoint Detection & Response)

b)

SIEM (Security Information & Event Management)

c)

SOAR (Security Orchestration & Response)

d)

CSPM (Cloud Security Posture Management)

27.

The process of understanding the financial and operational consequences of security incidents is called:

a)

Risk Assessment

b)

Business Impact Analysis

c)

Threat Prioritization

d)

Threat Modeling

28.

Focusing resources on the most likely and damaging attack scenarios is known as:

a)

Risk Assessment

b)

Business Impact Analysis

c)

Threat Prioritization

d)

Quantum-Readiness

29.

What emerging requirement is defined as a formal record containing details and relationships of software components?

a)

AI Security Governance

b)

Software Bill of Materials (SBOM)

c)

Quantum-Readiness

d)

Critical Assets

30.

Preparing for future quantum computing threats to current encryption is categorized as:

a)

Vulnerability Management

b)

AI Security Governance

c)

Quantum-Readiness

d)

DevSecOps

31.

1. Statement 1: Network Security in the Digital Era is foundational to all digital transformation. Statement 2: Integrity is primarily ensured by redundancy and disaster recovery.

a)

statement 1 is true, statement 2 is false

b)

statement 1 is false, statement 2 is true

c)

both statements are true

d)

both statements are false

32.

Statement 1: The CIA Triad stands for Confidentiality, Integrity, and Availability. Statement 2: Confidentiality is protected via encryption, access controls, and data classification.

a)

A. statement 1 is true, statement 2 is false

b)

B. statement 1 is false, statement 2 is true

c)

C. both statements are true

d)

D. both statements are false

33.

Statement 1: Availability ensures systems and data are accessible when needed. Statement 2: Integrity prevents unauthorized modification of data using digital signatures.

a)

statement 1 is true, statement 2 is false

b)

statement 1 is false, statement 2 is true

c)

both statements are true

d)

both statements are false

34.

Statement 1: Network security extends only to traditional on-premise networks. Statement 2: Sophisticated threats include Nation-state attacks and Ransomware.

a)

statement 1 is true, statement 2 is false

b)

statement 1 is false, statement 2 is true

c)

both statements are true

d)

both statements are false

35.

Statement 1: Technical Flaws are security weaknesses caused by human error or malicious insiders. Statement 2: Supply Chain Compromises are attacks targeting third-party vendors and software dependencies.

a)

statement 1 is true, statement 2 is false

b)

statement 1 is false, statement 2 is true

c)

both statements are true

d)

both statements are false

36.

Cloud Misconfigurations are security gaps caused by improper cloud service settings. API Security Weaknesses are a type of human vulnerability.

a)

statement 1 is true, statement 2 is false

b)

statement 1 is false, statement 2 is true

c)

both statements are true

d)

both statements are false

37.

Ransomware is malicious software that demands payment for data restoration. Business Email Compromise (BEC) targets systems through exploiting technical flaws.

a)

statement 1 is true, statement 2 is false

b)

statement 1 is false, statement 2 is true

c)

both statements are true

d)

both statements are false

38.

8. Statement 1: Advanced Persistent Threats (APTs) are defined as stealthy, continuous computer hacking processes. Statement 2: Critical Assets include Cloud Workloads and Microservices.

a)

A. statement 1 is true, statement 2 is false

b)

B. statement 1 is false, statement 2 is true

c)

C. both statements are true

d)

D. both statements are false

39.

Zero Trust Architecture requires verification for every access request, regardless of source. Zero Trust Network Access (ZTNA) is a non-identity-centric approach to remote access security.

a)

statement 1 is true, statement 2 is false

b)

statement 1 is false, statement 2 is true

c)

both statements are true

d)

both statements are false

40.

Statement 1: DevSecOps focuses on integrating security practices into the DevOps pipeline. Statement 2: Cloud Security Posture Management (CSPM) is used to manually detect cloud misconfigurations.

a)

statement 1 is true, statement 2 is false

b)

statement 1 is false, statement 2 is true

c)

both statements are true

d)

both statements are false

41.

Statement 1: Threat Modeling is a systematic approach to identify and prioritize potential threats. Statement 2: SASE is a cloud-native architecture that combines network and security services.

a)

statement 1 is true, statement 2 is false

b)

statement 1 is false, statement 2 is true

c)

both statements are true

d)

both statements are false

42.

Statement 1: Multi-Factor Authentication (MFA) requires only one verification method for access. Statement 2: Privileged Access Management (PAM) controls and monitors privileged account access.

a)

statement 1 is true, statement 2 is false

b)

statement 1 is false, statement 2 is true

c)

both statements are true

d)

both statements are false

43.

TLS 1.3 is the latest protocol mentioned for securing internet communications. Hardware Security Modules (HSM) are physical devices that securely manage digital keys.

a)

statement 1 is true, statement 2 is false

b)

statement 1 is false, statement 2 is true

c)

both statements are true

d)

both statements are false

44.

Cloud Access Security Brokers (CASB) enforce security policy between cloud users and providers. CASB is categorized under Endpoint Protection controls.

a)

statement 1 is true, statement 2 is false

b)

statement 1 is false, statement 2 is true

c)

both statements are true

d)

both statements are false

45.

Statement 1: Endpoint Detection & Response (EDR) tools continuously monitor and respond to endpoint threats. Statement 2: EDR is considered a Network Security control.

a)

statement 1 is true, statement 2 is false

b)

statement 1 is false, statement 2 is true

c)

both statements are true

d)

both statements are false

46.

Statement 1: ZTNA (Zero Trust Network Access) is an identity-centric approach to remote access security. Statement 2: SASE (Secure Access Service Edge) is a security model used for DevSecOps.

a)

statement 1 is true, statement 2 is false

b)

statement 1 is false, statement 2 is true

c)

both statements are true

d)

both statements are false

47.

SIEM provides real-time analysis of security alerts. XDR is a tool used for automating security operations and response workflows.

a)

statement 1 is true, statement 2 is false

b)

statement 1 is false, statement 2 is true

c)

both statements are true

d)

both statements are false

48.

Statement 1: XDR (Extended Detection & Response) is a cross-layer detection and response platform. Statement 2: SIEM is an acronym for Security Information & Event Management.

a)

statement 1 is true, statement 2 is false

b)

statement 1 is false, statement 2 is true

c)

both statements are true

d)

both statements are false

49.

Statement 1: SOAR stands for Security Orchestration & Response. Statement 2: SOAR is used to manually respond to security incidents.

a)

statement 1 is true, statement 2 is false

b)

statement 1 is false, statement 2 is true

c)

both statements are true

d)

both statements are false

50.

Risk Assessment is the process of identifying, analyzing, and evaluating security risks. Threat Prioritization focuses resources on the least likely attack scenarios.

a)

statement 1 is true, statement 2 is false

b)

statement 1 is false, statement 2 is true

c)

both statements are true

d)

both statements are false

51.

Statement 1: Business Impact Analysis determines the technical cause of a security incident.
Statement 2: Risk Management in the Modern Context includes Business Impact Analysis.

a)
  • statement 1 is true, statement 2 is false

b)

statement 1 is false, statement 2 is true

c)
  • both statements are true

d)
  • both statements are false

52.

Vulnerability Management is a continuous process of identifying and remediating security weaknesses. "MFA Everywhere" is listed as a Must-Implement Control.

a)

statement 1 is true, statement 2 is false

b)

statement 1 is false, statement 2 is true

c)

both statements are true

d)

both statements are false

53.

AI Security Governance is an emerging requirement that manages risks associated with AI systems. Quantum-Readiness prepares for the threat of quantum computing to current encryption.

a)

statement 1 is true, statement 2 is false

b)

statement 1 is false, statement 2 is true

c)

both statements are true

d)

both statements are false

54.

24. Statement 1: A Software Bill of Materials (SBOM) is an emerging requirement. Statement 2: An SBOM is a formal record of hardware components.

a)

statement 1 is true, statement 2 is false

b)

statement 1 is false, statement 2 is true

c)

both statements are true

d)

both statements are false

55.

The STRIDE and DREAD methodologies are used in Threat Modeling. Microservices are defined as virtual machines running in cloud environments.

a)

statement 1 is true, statement 2 is false

b)

statement 1 is false, statement 2 is true

c)

both statements are true

d)

both statements are false

56.

26. Statement 1: ZTNA is an evolution of traditional VPNs for remote access. Statement 2: CASB and CSPM are both classified under Cloud Security controls.

a)

statement 1 is true, statement 2 is false

b)

statement 1 is false, statement 2 is true

c)

both statements are true

d)

both statements are false

57.

27. Statement 1: The purpose of cryptographic hashing is to ensure data confidentiality. Statement 2: Digital signatures are a method of ensuring data integrity.

a)

statement 1 is true, statement 2 is false

b)

statement 1 is false, statement 2 is true

c)

both statements are true

d)

both statements are false

58.

28. Statement 1: Ransomware and Supply Chain Compromises are both specific examples of sophisticated threats. Statement 2: Protecting against sophisticated threats is a goal of modern network security.

a)

statement 1 is true, statement 2 is false

b)

statement 1 is false, statement 2 is true

c)

both statements are true

d)

both statements are false

59.

29. Statement 1: Privileged Access Management (PAM) is a type of Security Monitoring tool. Statement 2: MFA Everywhere is an essential security practice.

a)

statement 1 is true, statement 2 is false

b)

statement 1 is false, statement 2 is true

c)

both statements are true

d)

both statements are false

60.

SOAR helps automate security response workflows. Threat Prioritization is a process within Security Assessment & Planning.

a)
  • statement 1 is true, statement 2 is false

b)
  • statement 1 is false, statement 2 is true

c)
  •  both statements are true

d)
  • both statements are false

61.

What does the acronym CIA stand for in the context of Core Security Principles?

a)
  • Cryptography, Intelligence, Authorization

b)

Confidentiality, Integrity, Availability

c)

Cloud, IoT, Authentication

d)

Classification, Identity, Access

62.

The systematic approach to identifying and prioritizing potential threats includes methodologies like STRIDE and DREAD. What process are they associated with?

a)

Security Operations and Response (SOAR)

b)

Digital Forensics and Evidence Acquisition (DFEA)

c)

Threat Modeling

d)

Business Impact Analysis (BIA)

63.

What does the acronym ZTNA stand for?

a)

Zero Tolerance Network Access

b)

Zone Trust Network Administration

c)

Zero Trust Network Access

d)

Zonal Threat and Network Assessment

64.

What does SASE represent in the context of network and security services?

a)

Security Analysis and Service Engine

b)

Simple Authentication and Secure Encryption

c)

Secure Access Service Edge

d)

Software Application Security Evaluation

65.

DevSecOps describes the integration of security practices into the DevOps pipeline. What does the "Ops" in DevSecOps refer to?

a)

Outsourced Processing Solutions

b)

Operations

c)

Optimized Protocols and Standards

d)

Organizational Policy Structure

66.

What does CSPM stand for, which uses automated tools for detecting and remediating cloud misconfigurations?

a)

Critical Security Policy Management

b)

Cloud System Performance Metrics

c)

Compliance and Security Program Monitoring

d)

Cloud Security Posture Management

67.

APTs are defined as stealthy, continuous computer hacking processes. What does APT stand for?

a)

Automated Phishing Threats

b)

Active Protocol Tactics

c)

Advanced Persistent Threats

d)

Application Penetration Testing

68.

What does MFA require for access, making it a critical control?

a)

Managed Firewall Access

b)

Multiple verification methods

c)

Mandatory File Auditing

d)

Minimum Firewall Allocation

69.

PAM is used for controlling and monitoring privileged account access. What does PAM stand for?

a)

Public Access Management

b)

Perimeter Access Monitoring

c)

Policy and Audit Mechanism

d)

Privileged Access Management

70.

In encryption and data protection, what does HSM stand for, referring to physical devices that manage digital keys securely?

a)

Highly Secured Methodology

b)

Hardware Security Modules

c)

Host System Monitoring

d)

Hybrid Security Model

71.

SIEM provides real-time analysis of security alerts. What does SIEM stand for?

a)

System Integration and Event Management

b)

Security Information & Event Management

c)

Secure Identity and Endpoint Management

d)

Software Image and Execution Metrics

72.

XDR is a cross-layer detection and response platform. What does XDR stand for?

a)

External Data Replication

b)

Extended Detection & Response

c)

eXtended Data Retrieval

d)

Executive Decision Reporting

73.

What process does SOAR automate, using it to accelerate security response workflows?Software Operations and Analysis Reporting

a)

Software Operations and Analysis Reporting

b)

Security Orchestration & Response

c)

Service Optimization and Risk assessment

d)

System Ownership and Account Reconciliation

74.

EDR tools continuously monitor and respond to endpoint threats. What does EDR stand for?

a)

Encrypted Data Retrieval

b)

Enterprise Device Registry

c)

Endpoint Detection & Response

d)

Event Data Reporting

75.

CASBs act as security policy enforcement points between cloud users and providers. What does CASB stand for?

a)

Cloud Application Security Benchmarks

b)

Centralized Access Security Buffer

c)

Cloud Access Security Brokers

d)

Content and Asset Security Blueprint

76.

What does SBOM stand for, which is a formal record containing details and relationships of software components?

a)
  • Standard Business Operating Model

b)

Security Baseline and Operation Metrics

c)
  • System Build and Operation Management

d)

Software Bill of Materials

77.

What is the definition of BEC?

a)

Basic Encryption Code

b)
  • Business Email Compromise

c)

Binary Exchange Communication

d)

Breach Event Control