Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Semester 1 Exam Review: Unit 3 Securing Networks

Total questions: 15

Worksheet time: 8mins

Name
Class
Date
1.

An attacker intercepts and alters data as it travels between a client and a server. Which attack is occurring?

a)

On-path (Man-in-the-Middle)

b)

MAC flooding

c)

Injection

d)

DNS poisoning

2.

Network logs show repeated, unsolicited ARP replies mapping the gateway IP to a new MAC address. What attack does this indicate?

a)

MAC flooding

b)

ARP poisoning

c)

Evil twin

d)

DNS poisoning

3.

An attacker performs a MAC flooding attack to force a switch into a hub-like state, broadcasting traffic. What is the attacker's PRIMARY goal?

a)

Denial of service

b)

Traffic interception

c)

Credential theft

d)

Lateral movement

4.

An attacker compromises one workstation and then uses it to access additional systems across the internal network. This behavior is known as:

a)

Injection

b)

Lateral movement

c)

On-path attack

d)

MAC flooding

5.

Which control MOST directly limits lateral movement after a device is compromised?

a)

Network segmentation

b)

Signature-based detection

c)

Strong encryption

d)

Log aggregation

6.

Which segmentation technique isolates public-facing servers from the internal network?

a)

VLANs

b)

Subnetting

c)

Screened subnet (DMZ)

d)

Firewall rule logging

7.

A rogue wireless access point mimics a legitimate SSID to trick users into connecting. Which attack is this?

a)

DNS poisoning

b)

Evil twin

c)

MAC flooding

d)

ARP poisoning

8.

Which wireless defense MOST directly reduces the risk of an evil twin attack?

a)

Disabling beacon frames

b)

Controlling signal strength

c)

Network authentication (802.1X)

d)

Strong encryption (WPA3)

9.

A firewall evaluates packets only based on source, destination, and port, without tracking sessions. This firewall is BEST described as:

a)

Next-generation

b)

Stateful

c)

Application-layer

d)

Stateless

10.

A firewall rule set denies TCP port 443 traffic from 10.0.0.0/8 before allowing HTTPS traffic from all sources. Which change would allow HTTPS access?

a)

Move the deny rule below the allow rule

b)

Replace the firewall with an IDS

c)

Enable stateful inspection

d)

Remove ICMP rules

11.

Which tool collects logs from many sources and allows analysts to correlate events across the network?

a)

NIPS

b)

NIDS

c)

SIEM

d)

Firewall

12.

Which detection method compares current behavior to a baseline to identify unusual activity?

a)

Signature-based

b)

Hybrid

c)

Rule-based

d)

Anomaly-based

13.

Duplicate ARP replies appearing in network logs are MOST likely an indicator of:

a)

MAC flooding

b)

ARP poisoning

c)

Injection

d)

Evil twin

14.

Why does unsanitized user input increase the risk of injection attacks?

a)

It allows attackers to intercept traffic

b)

It allows attackers to add unintended commands

c)

It exposes MAC addresses

d)

It weakens encryption

15.

How does defense in depth reduce the impact of a successful network breach?

a)

It prevents all attacks

b)

It replaces the need for detection tools

c)

It ensures only one control can fail

d)

It limits attacker movement and damage