WorksheetsInformation Security Quiz
Total questions: 30
Worksheet time: 15mins
Which of the following best defines Information Security?
Protecting only network devices
Protecting information from unauthorized access, use, disclosure, disruption, modification, or destruction
Installing antivirus software
Encrypting all data
Which component represents a potential cause of an unwanted incident?
Vulnerability
Threat
Risk
Asset
Risk is best described as:
Threat × Asset
Vulnerability × Asset
Threat × Vulnerability × Impact
Exposure × Countermeasure
Which QoS parameter directly affects real-time applications like VoIP?
Throughput
Latency
Packet size
TTL
OpenVAS is primarily used for:
Intrusion prevention
Packet sniffing
Vulnerability assessment
Firewall configuration
A DMZ is used to:
Completely isolate internal users
Host public services with controlled access
Replace a firewall
Encrypt network traffic
Which firewall implementation method places the firewall on a separate dedicated system?
Dual-homed host
Screened subnet
Bastion host
Proxy firewall
Packet-filtering firewalls mainly operate at which OSI layers?
Application
Session
Network and Transport
Presentation
Which firewall maintains connection state information?
Packet filtering firewall
Proxy firewall
Stateful inspection firewall
Screened host firewall
In iptables, which chain handles packets destined for the local system?
FORWARD
OUTPUT
INPUT
PREROUTING
Default policy in iptables is applied when:
A packet matches a rule
No rule matches a packet
Kernel modules fail
Firewall restarts
Which iptables table is used for NAT operations?
filter
mangle
nat
raw
The iptables target DROP means:
Reject packet with ICMP
Log packet only
Silently discard packet
Forward packet
Xtables-addons are mainly used for:
GUI management
Advanced matching features
Logging only
VPN tunneling
Geo-IP blocking is implemented using:
iptables filter table
DNS server
Xtables-addons
Squid ACLs
Wireshark display filters differ from capture filters because:
They reduce disk usage
They filter packets after capture
They drop packets
They block traffic
Fail2ban primarily works by:
Blocking MAC addresses
Modifying firewall rules dynamically
Capturing packets
Encrypting logs
A reverse proxy primarily:
Protects clients
Protects backend servers
Encrypts VPN traffic
Acts as IDS
UTM devices combine:
Routing and switching
Firewall, IDS/IPS, VPN
IDS and SIEM only
Load balancing only
Which VPN type relies on IPsec?
Trusted VPN
Secure VPN
SSL VPN
MPLS VPN
IPsec Tunnel mode is mainly used for:
Host-to-host communication
Site-to-site VPN
Application security
Split tunneling
Split tunneling allows:
All traffic through VPN
Only VPN traffic encrypted
Selective routing of traffic
No encryption
IDS differs from IPS because IDS:
Blocks traffic automatically
Detects and alerts only
Works inline
Drops packets
Snort is classified as:
HIDS
SIEM
NIDS
Firewall
OSSEC primarily functions as:
NIDS
IPS
HIDS
UTM
Defence-in-depth emphasizes:
Single strong firewall
Multiple layered security controls
IDS only
Encryption only
Threat hunting focuses on:
Known signatures
Reactive alerts
Proactive anomaly detection
Firewall tuning
A three-tier architecture separates:
User, kernel, hardware
Presentation, application, database
LAN, MAN, WAN
IDS, IPS, SIEM
SIEM primarily performs:
Packet inspection
Log correlation and event triggering
Firewall enforcement
Vulnerability scanning
IDS bypass techniques generally exploit:
Weak encryption
Log rotation
Evasion and fragmentation techniques
Hardware failure
