wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Day 6 - Leadership

Total questions: 26

Worksheet time: 13mins

Name
Class
Date
1.

Which architecture best supports micro-segmentation in enterprise networks?

a)

Flat network core

b)

End-user device VLANs

c)

Legacy protocol design

d)

Network segmentation with policy

2.

How does defense-in-depth reduce breach impact?

a)

Removes human error

b)

Reduces alert fatigue

c)

Provides layered controls

d)

Eliminates false positives

3.

What is the primary benefit of TLS inspection for egress traffic?

a)

Reducing storage needs

b)

Better encryption strength

c)

Faster routing decisions

d)

Identifying hidden threats

4.

Why are cloud security groups commonly used?

a)

They prevent outages globally

b)

They define security policy

c)

They lower cost per VM

d)

They increase performance

5.

Which architecture aligns with Zero Trust principles?

a)

Load balancing stickiness

b)

Network zoning with policy

c)

NAT-only perimeter

d)

VPN tunneling only

6.

Why should an organization standardize IAM roles across accounts?

a)

For access control clarity

b)

For UI consistency only

c)

For DNS resolution speed

d)

For password sharing ease

7.

What risk increases when security tools are misconfigured?

a)

Slower CPUs only

b)

Missed attack chains

c)

Patch delays only

d)

Misconfigured detections

8.

Which component validates server identity during HTTPS sessions?

a)

IDS signatures

b)

TLS certificates

c)

SSL inspection box

d)

Firewalls with NAT

9.

How does Zero Trust handle internal application access?

a)

Removes perimeter entirely

b)

Enforces continuous verification

c)

Blocks all traffic by default

d)

Eliminates IAM dependencies

10.

Why is understanding asset inventory critical for SOC operations?

a)

Different vendors supported

b)

Different OS versions

c)

Different threat models

d)

Different cabling types

11.

What architecture decision most affects broadcast domain size?

a)

IP addressing scheme

b)

Time synchronization

c)

VLAN sizing strategy

d)

MTU settings only

12.

Why is process automation valuable in a SOC?

a)

Improves compliance forms

b)

Speeds containment steps

c)

Cuts costs without tradeoffs

d)

Reduces staff entirely

13.

What is the main advantage of a consolidated SIEM dashboard?

a)

Faster, consistent triage

b)

Better reports aesthetics

c)

Easier audits only

d)

Fewer alerts overall

14.

Which metric better reflects response efficiency than tool count?

a)

Number of tools used

b)

Mean Time to Respond

c)

Number of analysts hired

d)

Ticket volume per hour

15.

How does automation in SOAR typically impact triage?

a)

Eliminates analyst review

b)

Reduces repetitive tasks

c)

Increases alert numbers

d)

Prevents breaches always

16.

Why should security run tabletop exercises regularly?

a)

Tools expire frequently

b)

Threats evolve continuously

c)

Staff turnover solely

d)

Compliance only goals

17.

Which process best reduces false positives over time?

a)

Tuning detections iteratively

b)

Hiring staff immediately

c)

More logging everywhere

d)

Adding more tools quickly

18.

What does a post-incident review primarily drive?

a)

Visibility metrics only

b)

Speed and consistency gains

c)

Compliance checklists only

d)

Network design changes

19.

How does ticket prioritization improve SOC throughput?

a)

Improves metric vanity

b)

Reduces worklog length

c)

Focuses on critical alerts

d)

Simplifies reports only

20.

What process failure most commonly leads to data exfiltration persistence?

a)

DNS issues generally

b)

Poor escalation paths

c)

Weak encryption choices

d)

Network latency spikes

21.

What is a key benefit of implementing network segmentation in a Zero Trust model?

a)

Limits lateral movement

b)

Reduces need for encryption

c)

Increases broadcast traffic

d)

Removes authentication requirements

22.

Which security control helps verify user identity before granting access to sensitive resources?

a)

Multi-factor authentication

b)

Network address translation

c)

VLAN trunking

d)

Load balancing

23.

How does regular vulnerability scanning support SOC operations?

a)

Detects misconfigurations and weaknesses

b)

Improves network speed

c)

Reduces staff workload entirely

d)

Identifies outdated hardware

24.

Which approach best limits unauthorized lateral movement within a network?

a)

Using default credentials

b)

Increasing bandwidth

c)

Implementing network segmentation

d)

Disabling all encryption

25.

What is the main purpose of continuous monitoring in a SOC environment?

a)

To automate password resets

b)

To detect threats in real time

c)

To increase ticket volume

d)

To reduce hardware costs

26.

Which security measure most effectively verifies user identity during remote access?

a)

Static IP assignment

b)

Multi-factor authentication

c)

Disabling firewalls

d)

Increasing VLAN count