Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

C13-ITNS-02002 Security Fundamentals 1

Total questions: 35

Worksheet time: 21mins

Name
Class
Date
1.

Which control or technology helps confirm that information has not been altered without permission?

a)

File versioning

b)

Data mirroring

c)

Network segmentation

d)

Cryptographic digital signatures

2.

What is the best way to protect against social engineering?

a)

Stronger encryption

b)

Employee awareness

c)

Stronger authentication

d)

Risk mitigation

3.

What is the main objective of applying the principle of least privilege?

a)

Grant users only the access needed for their role

b)

Reduce system maintenance

c)

Completely prevent cyberattacks

d)

Improve user convenience

4.

Which of the following terms indicates that information is to be read only by those people for whom it is intended?

a)

accounting

b)

availability

c)

integrity

d)

confidentiality

5.

Which scenario best reflects proper separation of duties within an organization?

a)

Authorization and execution are handled by various individuals

b)

Security rules are enforced by an IDS

c)

A single IT admin manages every service

d)

One employee handles all financial tasks

6.

What technology is not used to implement confidentiality?

a)

auditing

b)

access controls

c)

authentication

d)

encryption

7.

How do vulnerabilities and threats interact in a security context?

a)

Threats remove vulnerabilities

b)

Vulnerabilities only occur in networks

c)

Threats take advantage of existing weaknesses

d)

Vulnerabilities are a type of threat

8.

How do vulnerabilities and threats interact in a security context?

a)

Vulnerabilities are a type of threat

b)

Threats remove vulnerabilities

c)

Threats take advantage of existing weaknesses

d)

Vulnerabilities only occur in networks

9.

The primary reason for performing vulnerability assessments is to:

a)

Detect weaknesses that attackers could exploit

b)

Identify known hacker groups

c)

Estimate system downtime

d)

Guarantee complete system security

10.

Which solution is most effective for controlling physical entry into a restricted building?

a)

Host-based firewall

b)

Secure file permissions

c)

VPN gateway

d)

Electronic Badge Access System

11.

What social engineering technique sends you to a fake, but realistic-looking, website to verify your account information?

a)

Spoofing

b)

Smurfing

c)

Man-In-The-Middle

d)

Phishing

12.

Which option represents a biometric authentication factor?

a)

One-time PIN

b)

Account password

c)

Fingerprint scan

d)

Smart card

13.

RBAC is primarily implemented to:

a)

Track suspicious activity

b)

Block unauthorized network traffic

c)

Assign access rights based on organizational roles

d)

Secure data using cryptography

14.

What type of attack floods a network with packets preventing legitimate users from accessing resources?

a)

SQL injection

b)

Man in the Middle

c)

DoS

d)

DNS Poisoning

15.

Why is it considered best practice to disable or remove default accounts on systems?

a)

They reduce compatibility with updates

b)

They complicate logging processes

c)

They consume unnecessary resources

d)

Attackers frequently target them

16.

What is the safest action to take before using a USB drive on a company computer?

a)

Rename all files

b)

Temporarily disable antivirus

c)

Upload contents to cloud storage

d)

Scan the device for malicious software

17.

What security measure uses layer 2 addresses to specify which systems can connect to the WLAN?

a)

Wired Equivalency Privacy

b)

Service Set Identifiers

c)

Mac filtering

d)

Wi-Fi Protected Access

18.

What is the fundamental purpose of encryption technologies?

a)

Detect malware activity

b)

Improve data transmission reliability

c)

Protect information from unauthorized access

d)

Increase processing efficiency

19.

Before entering confidential information online, a user should first:

a)

Disable cookies

b)

Close all other browser tabs

c)

Switch to private browsing mode

d)

Confirm the site uses HTTPS

20.

After a person has been authenticated, they are given access to a system and resources. This is known as:

a)

authorization

b)

Logging

c)

accounting

d)

authentication

21.

Which technology is used to secure communication between a web browser and a server?

a)

TLS

b)

Telnet

c)

DNS

d)

SNMP

22.

Which are methods by which a person can authenticate by?

a)

What they know

b)

What he/she is

c)

What virtues they carry

d)

What they possess

23.

What security improvement is gained by using SSH instead of Telnet for remote access?

a)

Lower bandwidth usage

b)

Encrypted data transmission

c)

Easier user authentication

d)

Automatic system updates

24.

Which best describes Social engineering?

a)

A way to encrypt data in transit

b)

A method to prevent software vulnerabilities

c)

A firewall filtering packets at the network edge

d)

A technique exploits a person's trust to gain unauthorized access

25.

Why do wireless networks generally pose a higher security risk than wired networks?

a)

Signals can be intercepted by nearby devices

b)

They lack authentication mechanisms

c)

They cannot support firewalls

d)

They use legacy protocols

26.

Which of the following would be considered a strong password?

a)

Malachi1

b)

grEEn@Duck1e

c)

NESCSTUDENT

d)

GlH7%x

27.

Which wireless security method is most suitable for enterprises requiring centralized authentication?

a)

802.1X with centralized authentication

b)

Standalone certificate login

c)

Unsecured open network

d)

Shared wireless password

28.

Which of the following is considered the first line of defence when designing a network?

a)

Physical security

b)

Encryption

c)

Availability

d)

Firewalls

29.

Which wireless security protocol is considered obsolete and insecure?

a)

WPA2

b)

WEP

c)

WPA3

d)

TKIP

30.

What do you call the scope that hacker can use to break into a system?

a)

defense in depth

b)

attack surface

c)

principle of least privilege

d)

risk mitigation

31.

A cybercriminal creates a fake Wi-Fi hotspot to steal user credentials. This attack is called:

a)

Signal jamming

b)

Packet injection

c)

Rogue wireless deployment

d)

Evil twin attack

32.

Which of the following is not a response when dealing with a risk?

a)

patching

b)

transfer

c)

mitigation

d)

avoidance

33.

What is the main goal of cryptographic key lifecycle management?

a)

Replace outdated encryption tools

b)

Store user credentials

c)

Improve algorithm strength

d)

Protect keys from creation through disposal

34.

Which of the following makes sure that data is not changed when it not supposed to be?

a)

confidentiality

b)

availability

c)

integrity

d)

accounting

35.

Which behaviour best supports a Zero Trust security approach?

a)

Continuously verifying identity and access

b)

Automatically trusting internal users

c)

Allowing long-term access after login

d)

Disabling internal security monitoring