wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

ndc+ca

Total questions: 40

Worksheet time: 20mins

Name
Class
Date
1.

Which firewall inspects traffic only based on IP addresses and ports?

a)

Stateful firewall

b)

Packet filtering firewall

c)

Application firewall

d)

Circuit gateway

2.

Which control is intended to discourage violations rather than detect them?

a)

Preventive

b)

Detective

c)

Deterrent

d)

Corrective

3.

Which iptables table is responsible for Network Address Translation?

a)

FILTER

b)

RAW

c)

MANGLE

d)

NAT

4.

Which term describes an attack that goes undetected by an IDS?

a)

False positive

b)

False negative

c)

True positive

d)

True negative

5.

Which document lists risks, controls, and treatment decisions?

a)

Audit charter

b)

Risk register

c)

ISMS policy

d)

SoA

6.

Which port is used by Secure Shell (SSH)?

a)

21

b)

22

c)

23

d)

25

7.

Which phase of audit formally communicates findings to management?

a)

Planning

b)

Assessment

c)

Reporting

d)

Follow-up

8.

Which IDS type runs directly on the monitored host?

a)

Network-based

b)

Signature-based

c)

Host-based

d)

Anomaly-based

9.

NAT is MOST effective in reducing exposure of:

a)

Encryption keys

b)

Internal IP structure

c)

Firewall rules

d)

Routing tables

10.

Which command-line utility captures live network packets?

a)

Snort

b)

tcpdump

c)

Netcat

d)

Nikto

11.

A firewall validates packets using session information stored dynamically. This firewall is:

a)

Packet filtering

b)

Circuit-level

c)

Stateful

d)

Proxy

12.

Audit logs exist but are never reviewed. Which control weakness exists?

a)

Preventive

b)

Detective

c)

Corrective

d)

Administrative

13.

Which iptables chain handles packets generated by the local system?

a)

INPUT

b)

FORWARD

c)

PREROUTING

d)

OUTPUT

14.

Cyber insurance taken to cover ransomware loss is an example of:

a)

Risk mitigation

b)

Risk avoidance

c)

Risk acceptance

d)

Risk transfer

15.

An IDS generates alerts whenever legitimate traffic spikes during business hours. The issue is most likely:

a)

False negatives

b)

Weak firewall

c)

Poor baseline

d)

Signature mismatch

16.

Which IDS detection technique relies on deviation from normal behavior?

a)

Signature

b)

Rule-based

c)

Anomaly

d)

Heuristic

17.

A DMZ is BEST described as:

a)

Trusted internal zone

b)

Untrusted external zone

c)

Isolated buffer network

d)

Encrypted tunnel

18.

Which audit evidence carries the HIGHEST reliability?

a)

User confirmation

b)

Management assertion

c)

System-generated logs

d)

Policy documentation

19.

Which Snort component formats alerts and logs?

a)

Sniffer

b)

Preprocessor

c)

Detection engine

d)

Output module

20.

Firewall rules that allow only required services reflect which principle?

a)

Defense in depth

b)

Least privilege

c)

Due care

d)

Separation of duties

21.

An IPS differs from IDS mainly because IPS:

a)

Detects attacks faster

b)

Works only on signatures

c)

Blocks traffic automatically

d)

Stores logs centrally

22.

Which audit phase focuses on testing controls?

a)

Planning

b)

Assessment

c)

Reporting

d)

Closure

23.

Which firewall generation introduced application-layer inspection?

a)

First

b)

Second

c)

Third

d)

Fourth

24.

Multiple IDS alerts for normal activity indicate poor:

a)

Network design

b)

IDS tuning

c)

Encryption

d)

Firewall placement

25.

Which iptables target drops packets silently?

a)

ACCEPT

b)

LOG

c)

DROP

d)

REJECT

26.

Selecting 60 systems from 3000 during audit introduces:

a)

Inherent risk

b)

Control risk

c)

Sampling risk

d)

Detection risk

27.

Which control provides traceability of user actions?

a)

Authentication

b)

Authorization

c)

Logging

d)

Encryption

28.

Which IDS placement cannot block traffic?

a)

Inline

b)

Passive

c)

Proxy-based

d)

Gateway-based

29.

Traffic flooding using compromised machines worldwide is known as:

a)

DoS

b)

Reflection attack

c)

DDoS

d)

Spoofing

30.

IDS effectiveness in anomaly detection depends MOST on:

a)

Signature updates

b)

Hardware speed

c)

Baseline accuracy

d)

Packet size

31.

Developers have write access to production systems. What is the PRIMARY audit concern?

a)

Confidentiality

b)

Availability

c)

Lack of segregation of duties

d)

Weak firewall

32.

An IDS misses a genuine attack because traffic is encrypted. This is a:

a)

False positive

b)

False negative

c)

True positive

d)

True negative

33.

Firewall rules placed incorrectly cause later rules to never execute. This issue is called:

a)

Rule chaining

b)

Rule shadowing

c)

Rule escalation

d)

Rule bypass

34.

Auditor recommends separating dev, test, and production environments. This protects:

a)

Availability

b)

Confidentiality

c)

Integrity

d)

Authentication

35.

Organization knowingly accepts flood risk due to business location. This is:

a)

Risk mitigation

b)

Risk avoidance

c)

Risk transfer

d)

Risk acceptance

36.

Which control ensures recovery after ransomware attack?

a)

IDS

b)

Antivirus

c)

Backup and restore

d)

Firewall

37.

Anomaly-based IDS generates excessive alerts. What should be corrected FIRST?

a)

Signature database

b)

Baseline definition

c)

Firewall rules

d)

Packet filtering

38.

Which iptables chain processes packets routed through the system?

a)

INPUT

b)

OUTPUT

c)

FORWARD

d)

POSTROUTING

39.

Which audit risk exists regardless of control effectiveness?

a)

Control risk

b)

Detection risk

c)

Inherent risk

d)

Sampling risk

40.

Auditor verifies antivirus on a subset of endpoints due to time constraints. Method used is:

a)

Compliance testing

b)

Continuous auditing

c)

Audit sampling

d)

Risk assessment