WorksheetsC13-ITNS-02002 Security Fundamentals 1
Total questions: 35
Worksheet time: 21mins
Which control or technology helps confirm that information has not been altered without permission?
File versioning
Data mirroring
Network segmentation
Cryptographic digital signatures
What is the best way to protect against social engineering?
Stronger encryption
Employee awareness
Stronger authentication
Risk mitigation
What is the main objective of applying the principle of least privilege?
Grant users only the access needed for their role
Reduce system maintenance
Completely prevent cyberattacks
Improve user convenience
Which of the following terms indicates that information is to be read only by those people for whom it is intended?
accounting
availability
integrity
confidentiality
Which scenario best reflects proper separation of duties within an organization?
Authorization and execution are handled by various individuals
Security rules are enforced by an IDS
A single IT admin manages every service
One employee handles all financial tasks
What technology is not used to implement confidentiality?
auditing
access controls
authentication
encryption
How do vulnerabilities and threats interact in a security context?
Threats remove vulnerabilities
Vulnerabilities only occur in networks
Threats take advantage of existing weaknesses
Vulnerabilities are a type of threat
How do vulnerabilities and threats interact in a security context?
Vulnerabilities are a type of threat
Threats remove vulnerabilities
Threats take advantage of existing weaknesses
Vulnerabilities only occur in networks
The primary reason for performing vulnerability assessments is to:
Detect weaknesses that attackers could exploit
Identify known hacker groups
Estimate system downtime
Guarantee complete system security
Which solution is most effective for controlling physical entry into a restricted building?
Host-based firewall
Secure file permissions
VPN gateway
Electronic Badge Access System
What social engineering technique sends you to a fake, but realistic-looking, website to verify your account information?
Spoofing
Smurfing
Man-In-The-Middle
Phishing
Which option represents a biometric authentication factor?
One-time PIN
Account password
Fingerprint scan
Smart card
RBAC is primarily implemented to:
Track suspicious activity
Block unauthorized network traffic
Assign access rights based on organizational roles
Secure data using cryptography
What type of attack floods a network with packets preventing legitimate users from accessing resources?
SQL injection
Man in the Middle
DoS
DNS Poisoning
Why is it considered best practice to disable or remove default accounts on systems?
They reduce compatibility with updates
They complicate logging processes
They consume unnecessary resources
Attackers frequently target them
What is the safest action to take before using a USB drive on a company computer?
Rename all files
Temporarily disable antivirus
Upload contents to cloud storage
Scan the device for malicious software
What security measure uses layer 2 addresses to specify which systems can connect to the WLAN?
Wired Equivalency Privacy
Service Set Identifiers
Mac filtering
Wi-Fi Protected Access
What is the fundamental purpose of encryption technologies?
Detect malware activity
Improve data transmission reliability
Protect information from unauthorized access
Increase processing efficiency
Before entering confidential information online, a user should first:
Disable cookies
Close all other browser tabs
Switch to private browsing mode
Confirm the site uses HTTPS
After a person has been authenticated, they are given access to a system and resources. This is known as:
authorization
Logging
accounting
authentication
Which technology is used to secure communication between a web browser and a server?
TLS
Telnet
DNS
SNMP
Which are methods by which a person can authenticate by?
What they know
What he/she is
What virtues they carry
What they possess
What security improvement is gained by using SSH instead of Telnet for remote access?
Lower bandwidth usage
Encrypted data transmission
Easier user authentication
Automatic system updates
Which best describes Social engineering?
A way to encrypt data in transit
A method to prevent software vulnerabilities
A firewall filtering packets at the network edge
A technique exploits a person's trust to gain unauthorized access
Why do wireless networks generally pose a higher security risk than wired networks?
Signals can be intercepted by nearby devices
They lack authentication mechanisms
They cannot support firewalls
They use legacy protocols
Which of the following would be considered a strong password?
Malachi1
grEEn@Duck1e
NESCSTUDENT
GlH7%x
Which wireless security method is most suitable for enterprises requiring centralized authentication?
802.1X with centralized authentication
Standalone certificate login
Unsecured open network
Shared wireless password
Which of the following is considered the first line of defence when designing a network?
Physical security
Encryption
Availability
Firewalls
Which wireless security protocol is considered obsolete and insecure?
WPA2
WEP
WPA3
TKIP
What do you call the scope that hacker can use to break into a system?
defense in depth
attack surface
principle of least privilege
risk mitigation
A cybercriminal creates a fake Wi-Fi hotspot to steal user credentials. This attack is called:
Signal jamming
Packet injection
Rogue wireless deployment
Evil twin attack
Which of the following is not a response when dealing with a risk?
patching
transfer
mitigation
avoidance
What is the main goal of cryptographic key lifecycle management?
Replace outdated encryption tools
Store user credentials
Improve algorithm strength
Protect keys from creation through disposal
Which of the following makes sure that data is not changed when it not supposed to be?
confidentiality
availability
integrity
accounting
Which behaviour best supports a Zero Trust security approach?
Continuously verifying identity and access
Automatically trusting internal users
Allowing long-term access after login
Disabling internal security monitoring
