wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

palo 2

Total questions: 55

Worksheet time: 28mins

Name
Class
Date
1.

What is the decimal equivalent of 1110?

a)

10

b)

12

c)

14

d)

16

2.

What is the binary equivalent of 250?

a)

1111 1100

b)

1111 1010

c)

1111 1001

d)

1111 1000

3.

Identify the broadcast address from the following.

a)

214.19.21.255/14

b)

192.168.12.127/25

c)

192.168.0.255/16

d)

10.24.36.48/28

4.

Which address class is within the range of 192 to 223?

a)

Class A

b)

Class B

c)

Class C

d)

Class D

5.

An IPv6 address is structured with how many bits?

a)

128

b)

64

c)

256

d)

32

6.

What is another term for a logical address?

a)

IP Address

b)

Physical Address

c)

MAC Address

d)

Burned-In Address

7.

Which subnetwork is 192.168.25.50/28 on?

a)

192.168.25.64

b)

192.168.0.0

c)

192.168.25.48

d)

192.168.25.0

8.

Which area network separates the control and management processes from the underlying networking hardware, making them available as software that can be easily configured and deployed?

a)

LAN

b)

WAN

c)

SD-WAN

d)

CAN

9.

Which DNS record type specifies authoritative information about a DNS zone such as a primary name server, email address of the domain administrator, and domain serial number?

a)

PTR - Pointer:

b)

SOA - Start for Authority:

c)

PTR - Pointer:

d)

CNAME

10.

Which IoT technology is backed by ultra-low latency, massive connectivity and scalability for IoT devices, more efficient use of licensed spectrum, and network slicing for application traffic prioritization?

a)

2G

b)

3G

c)

4G

d)

5G

11.

The network device that is essentially an intelligent hub and uses physical addresses to forward data packets to devices on a network is known as:

a)

Switch

b)

Router

c)

Repeater

d)

Modem

12.

Which layer of the hierarchical networking model is responsible for high-speed routing and switching? Routers and switches at this layer are designed for high-speed packet routing and forwarding.

a)

Access

b)

Core

c)

Distribution

d)

Internet

13.

Which type of extranet will allow businesses within an industry to share information or integrate shared business processes?

a)

Value Add Network - VAN

b)

Campus Area Network - CAN

c)

Metropolitan Area Network - MAN

d)

Storage Area Network - SAN

14.

Which task is typically not included in server and system administration duties?

a)

Account provisioning and de-provisioning

b)

Managing account permissions

c)

Installing and maintaining server software

d)

Maintaining and optimizing network devices

15.

Which application identification technique determines whether the initially detected application protocol is the "real one" or if it is being used as a tunnel to hide the actual application - for example, Tor might run inside HTTPS.

a)

Application protocol detection and decryption

b)

Application protocol decoding

c)

Application signatures

d)

Heuristics

16.

Which Content-ID filtering capability controls the transfer of sensitive data patterns such as credit card and social security numbers in application content and attachments?

a)

File blocking by type

b)

Data filtering

c)

File transfer function control

d)

File filtering by size

17.

Which Linux command gives you extensive help on how to use a command?

a)

help

b)

more

c)

man

d)

guide

18.

Which subscription service complements App-ID by enabling you to configure the next-generation firewall to identify and control access to websites and to protect your organization from websites hosting malware and phishing pages.

a)

URL Filtering

b)

Wildfire

c)

Threat Prevention

19.

On the NGFW, which type of User-ID technique can be configured to probe Microsoft Windows servers for active network sessions of a user?

a)

Client Probing

b)

Server Probing

c)

Internet Probing

d)

Connection Probing

20.

Characteristics of unified threat management (UTM) include all of the following except:

a)

Combines security functions such as firewalls, intrusion detection systems (IDS), anti-malware, and data loss prevention (DLP) in a single appliance.

b)

Enabling all of the security functions in a UTM device can have a significant performance impact.

c)

UTM fully integrates all of the security functions installed on the device.

d)

UTM can be a convenient solution for small networks.

21.

Characteristics of application firewalls include all of the following except:

a)

Proxies traffic rather than permitting direct communication between hosts

b)

Can be used to implement strong user authentication

c)

Masks the internal network from untrusted networks

d)

Is extremely fast and has no impact on network performance

22.

Which VPN technology is currently considered the preferred method for securely connecting a remote endpoint device back to an enterprise network?

a)

Point-to-point Tunneling protocol - PPTP

b)

Secure Socket Layer - SSL

c)

Secure Socket tunneling protocol - SSTP

d)

Internet Protocol Security - IPSEC

23.

At which Data Link sublayer does the physical address reside?

a)

Media Access Control - MAC

b)

Logical Link Control - LLC

c)

Data Access Control - DAC

d)

Network Access Control - NAC

24.

HTTPS interacts with which OSI layer?

a)

Application

b)

Physical

c)

Data Link

d)

Session

25.

Which OSI layer handles flow control, data segmentation, and reliability?

a)

Application

b)

Physical

c)

Transport

d)

Data Link

26.

At which OSI layer does the PDU contain sequence and acknowledgement numbers?

a)

Application

b)

4

c)

Data Link

d)

6

27.

Which OSI layer determines the route a packet takes from sender to receiver?

a)

7

b)

1

c)

3

d)

4

28.

Which OSI layer is responsible for setting up, maintaining, and ending ongoing information exchanges across a network?

a)

6

b)

3

c)

2

d)

5

29.

Which layer of the OSI model does Project 802 divide into two sublayers?

a)

Physical

b)

Data Link

c)

Network

d)

Session

30.

Which term refers to stripping header information as a PDU is passed from one layer to a higher layer?

a)

De-encapsulation

b)

Encapsulation

c)

Packetization

d)

PDU stripping

31.

Which of the following problems can occur at the Physical layer of the OSI Model?

a)

NIC driver problems

b)

Incorrect IP addresses

c)

Signal errors caused by noise

32.

In the Kipling Model of Zero Trust which allows security solutions to track where accessed data resides?

a)

What

b)

How

c)

Who

d)

Where

33.

Which control point in a Zero-Trust Model scans all content for malicious activity and data theft?

a)

Access

b)

Transaction

c)

Device/Workload

d)

Identity

34.

In the Kipling Model of Zero Trust which asks for the asserted identity of the user or entity that attempts resource access?

a)

How

b)

What

c)

Who

d)

When

35.

Zero Trust is intended to remedy the deficiencies of perimeter-centric strategies.

a)

True

b)

False

36.

In the Kipling Model of Zero Trust which entifies the application used to access protected data?

a)

What

b)

When

c)

How

d)

Where

37.

Select True or False - Zero Trust eliminates Implicit Trust

a)

True

b)

False

38.

Which Microsoft Zero Trust Guiding Principle minimizes blast radius and segment access?

a)

Trust and Verify

b)

Least Privileged Access

c)

Assume Breach

d)

Verify Explicitly

39.

The following are limitations of Zero Trust Network Access 1:

a)

Doesn't protect data

b)

Secures all apps

c)

Adheres to the principles of Least Privileged Access

40.

Which of the following is an appropriate explanation of the functions of Zero Trust?

a)

CART Model

b)

Cooper Test

c)

Kipling Method

d)

Keynesian Theory

41.

Which of the following statements is the best way to describe Zero Trust?

a)

Zero Trust endpoint applications are automatically verified

b)

Zero Trust eliminates the need for user authentication

c)

Never Trust - Always Verify

d)

Always Trust - Always Verify

42.

An effective SASE solution needs to service the following requirements - Select the best answer.

a)

All of the answers

b)

Diversity - Carrier Agnostic

c)

Scalability

d)

Mobility

43.

Select the phrase below that best fills in the blank in the following sentence - A successful SASE deployment employs a __________ approach, as it services a company's need to provide application resources for a hybrid work demand.

a)

cloud first

b)

mobile

c)

proprietary

d)

restricted

44.

The term SASE stands for:

a)

Secure Access Services Edge

b)

Standards Authentication Services Enforcement

c)

Services Authentication Services Edge

d)

Secure Access Standards Enforcement

45.

Which of the following is NOT one of the 10 Tenets of an Effective SASE Solution?

a)

Agility

b)

Monitoring and Reporting

c)

Cost Reduction

d)

Complexity

46.

Which of the following is NOT one of the Ten Benefits of SASE?

a)

Website Enrollments

b)

Authentication Capabilities

c)

Default Routes

d)

Service Connections

47.

Which Prisma Access Architecture Layer provides SD-WAN, VPN, ZTNA, and QoS capabilities?

a)

Management

b)

Network-as-a-service

c)

Security-as-a-service

d)

Public Cloud

48.

Which SASE tenet is able to accurately detect devices for full visibility and enforce policies to ensure security across the network, eliminating the need for additional IoT security solutions?

a)

Autonomous Digital Experience Monitoring - ADEM

b)

Internet of Things - IoT

c)

Zero Trust Network Access - ZTNA

d)

Cloud Access Security Broker - CASB

49.

Which SASE tenet provides segment-wise insights across the entire service delivery path, allowing real and synthetic traffic analysis that enables organizations to proactively drive remediation of digital experience problems?

a)

Autonomous Digital Experience Monitoring - ADEM

b)

Internet of Things - IoT

c)

Zero Trust Network Access - ZTNA

d)

Cloud Access Security Broker - CASB

50.

Which SASE tenet should enable complete visibility and control over all traffic, regardless of where a user may be located, to ensure the secure use of cloud-based apps and other web services?

a)

Zero Trust Network Access - ZTNA

b)

Secure Web Gateway - SWG

c)

Autonomous Digital Experience Monitoring - ADEM

d)

Cloud Access Security Broker - CASB

51.

Which tenet is a core component of SASE, creating a single platform for administrators to manage security controls for all application types?

a)

Cloud Access Security Broker - CASB

b)

Zero Trust Network Access - ZTNA

c)

Data Loss Prevention - DLP

d)

Software Defined - Wide Area Network - SD-WAN

52.

Which of the following terms describes the process of making and using codes to secure the transmission of information?

a)

Steganography

b)

Cryptography

c)

Algorithm

d)

Cryptanalysis

53.

PKI systems are based on public-key cryptosystems and include digital certificates and certificate authorities.

a)

True

b)

False

54.

Which of the following is considered to be the strongest symmetric encryption cryptosystem?

a)

Data Encryption Standard (DES)

b)

Triple DES (3DES)

c)

Advanced Encryption Standard (AES)

d)

RSA Algorithm

55.

Packet-Filtering Firewalls operate at Layer 3 (network layer) of the Open Systems Interconnection (OSI) model.

a)

True

b)

False