wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Threats & Preventative Measures (I01-I04)

Total questions: 138

Worksheet time: 1hrs 27mins

Name
Class
Date
1.

A small firm uses admin/admin on a router and has no password policy. What is the most effective first step to reduce risk, while planning for layered controls?

Time limit: 1 minute

a)

Install an enterprise password manager

b)

Enable MFA for all accounts immediately

c)

Deploy SIEM to monitor failed logins

d)

Implement a 15+ character password policy

2.

You are designing access for staff and visitors who share one subnet with guest Wi‑Fi. Which strategic change best isolates traffic while keeping manageability?

Time limit: 1 minute

a)

Segment using VLANs with ACLs between segments

b)

Create separate physical networks for each group

c)

Install antivirus on all endpoints

d)

Increase password complexity requirements

3.

A school has OneDrive-only backups and no offsite copy. Which plan most directly meets the 3-2-1 backup principle?

Time Limit: 1 minute

a)

Two cloud copies and weekly local copy

b)

Three copies, two different media, one offsite

c)

One cloud copy and daily local snapshots

d)

One local copy and one offsite tape

4.

Login attempts show unlimited retries without rate limiting. What policy choice creates both deterrence and monitoring value? Time limit: 1 minute

a)

Disable guest Wi‑Fi during work hours

b)

Require BitLocker on laptops

c)

Increase password expiration frequency

d)

Lockout after five failures with SIEM alerts

5.

A nonprofit with limited technical skill wants to strengthen authentication quickly. Which layered approach balances cost and impact?

Time Limit: 1 minute

a)

Password manager without policy changes

b)

Password policy plus MFA for all users

c)

MFA only for IT administrators

d)

Firewall ACLs between existing VLANs

6.

BYOD devices must not access internal finance systems on the same switch. Which plan uses realistic controls to enforce this?

Time limit: 1 minute

a)

Use SIEM to watch BYOD connections

b)

Apply VLAN separation and firewall rules

c)

Enable antivirus on finance PCs

d)

Raise password length to 20 characters

7.

Ransomware risk analysis shows manual backups on a single external drive. Which step most improves business continuity?

You have 1 minute to answer this question.

a)

Adopt account lockout on all services

b)

Increase password complexity to 18 characters

c)

Upgrade to premium antivirus software

d)

Switch to immutable or air‑gapped backups

8.

A helpdesk receives tickets about default credentials found on IoT cameras. Which trigger word signals a needed solution area for these devices?

Time limit: 1 minute

a)

Password strength

b)

Network separation

c)

Disaster recovery

d)

Endpoint protection

9.

You must reduce lateral movement between staff PCs and visitor devices. What planning choice sets the foundation before adding firewall policies?

Time limit for this question: 1 minute

a)

Create SIEM correlation rules

b)

Implement VLAN tagging (802.1Q)

c)

Deploy application whitelisting

d)

Enable Windows Defender

10.

A team disables antivirus due to budget constraints and old equipment. What low‑cost measure restores baseline protection?

Time limit for this question: 1 minute.

a)

Apply BitLocker on portable laptops

b)

Implement EDR across all endpoints

c)

Install Microsoft Defender (built‑in)

d)

Use account lockout after failed logins

11.

A laptop with sensitive data is often used offsite. You have 1 minute to answer: Which measure directly protects data at rest if the device is lost?

a)

Place the laptop on a separate VLAN

b)

Install SIEM agent on the laptop

c)

Increase password length to 20 characters

d)

Enable BitLocker full‑disk encryption

12.

While drafting policy, you need a tertiary measure for weak passwords beyond policy and MFA. Which option fits as an additional safeguard?

Time Limit: 1 minute

a)

Firewall ACLs between VLANs

b)

Password manager adoption

c)

BitLocker full‑disk encryption

d)

SIEM alerts for failed logins

13.

A startup wants to implement segmentation but lacks deep networking skills. Which statement best represents realistic difficulty and cost?

Time limit: 1 minute

a)

Easy and free with built‑in policies

b)

Medium difficulty, no hardware cost

c)

Hard and requires networking knowledge

d)

Very hard and requires custom software

14.

During an audit, you see repeated failed logins. Which combined action improves both security and incident visibility?

Time limit for this question is now 1 minute.

a)

Increase password length only

b)

Move finance systems to a new VLAN only

c)

Enable account lockout with SIEM alerts

d)

Install antivirus on all servers

15.

Leadership asks for a concise MFA benefit when paired with strong passwords. Which impact should you emphasize?

Time Limit: 1 minute

a)

Eliminates the need for backups entirely

b)

Stops all phishing attempts completely

c)

Prevents network segmentation requirements

d)

Reduces risk from stolen credentials

16.

You must write requirements for backups after a ransomware incident. Which wording most clearly indicates the needed strategy?

Time limit: 1 minute

a)

Single cloud backup copy only

b)

Automated 3‑2‑1 with offsite media

c)

Manual nightly local copy

d)

Weekly snapshot on the same disk

17.

An organization with guest Wi‑Fi wants to prevent guests from reaching admin interfaces. Which design sequence is most robust?

Time limit for this question: 1 minute.

a)

BitLocker first, then EDR rollout

b)

VLAN separation, then firewall ACLs

c)

Password policy, then SIEM alerts

d)

Account lockout, then antivirus

18.

A security plan mandates lockout after five failed attempts. You now have 1 minute to answer. What complementary control adds detection for brute force campaigns?

a)

Deploy VLANs across all departments

b)

Increase password expiration frequency

c)

Enable SIEM alerts on repeated failures

d)

Implement BitLocker on endpoints

19.

You are prioritizing internal controls for a small business with limited budget. Which layered set best addresses common internal threats quickly?

Time limit: 1 minute

a)

Backups only using 3‑2‑1

b)

Antivirus alone on all devices

c)

Password policy and MFA together

d)

VLANs only across all networks

20.

A company stores sensitive files on laptops used by sales staff who travel frequently. Which mitigation best protects those files if a laptop is stolen?

Time limit: 1 minute

a)

Full‑disk encryption with BitLocker enabled

b)

Per‑file passwords set by users

c)

Local firewall with strict outbound rules

d)

Hidden folders and renamed file extensions

21.

You must recommend an open‑source alternative to BitLocker for encrypting data at rest on Windows. Which choice aligns with that requirement?

Time limit: 1 minute

a)

Windows EFS for selected directories

b)

WinZip with strong archive passwords

c)

VeraCrypt implementing file‑level encryption

d)

TLS certificates installed on devices

22.

An organization issues USB drives to staff for offline backups. What is the most appropriate control to reduce data‑at‑rest theft from lost USBs?

Time limit: 1 minute

a)

Disabling USB ports on all desktops

b)

Weekly antivirus scans on the drives

c)

Labeling drives with owner names

d)

Hardware‑encrypted USB drives with PIN

23.

A small IT team suspects intrusions go unnoticed because logs are scattered and never reviewed. Which solution creates centralized detection with alerting?

You have 1 minute to answer this question.

a)

Remove guest Wi‑Fi to reduce noise

b)

Increase password complexity policy

c)

Deploy a SIEM platform for log analysis

d)

Add more admin accounts for faster response

24.

Finance must keep an audit trail of access to payment systems. Which principle most directly limits insider abuse while preserving accountability?

Time Limit: 1 minute

a)

Least privilege with role‑based access

b)

Daily password rotation for all users

c)

Shared admin credentials for efficiency

d)

Unlimited access with post‑incident audits

25.

A startup runs all services on one server without redundancy. Which term best describes the risk and its primary mitigation?

Time Limit: 1 minute

a)

Vendor lock‑in; use open standards

b)

Cold site recovery; schedule backups

c)

Network congestion; increase bandwidth

d)

Single point of failure; add failover

26.

A branch office relies on a single ISP link for critical operations. Which practical step improves availability during outages?

Time limit for this question: 1 minute

a)

Block all social media to save bandwidth

b)

Switch all devices to static IP addresses

c)

Raise firewall default logging level

d)

Install a 4G router for backup connectivity

27.

During a power cut, the file server shut down abruptly and corrupted a database. Which control best prevents this impact?

Time limit for this question: 1 minute

a)

Deploy an uninterruptible power supply

b)

Replace spinning disks with SSDs

c)

Disable automatic OS updates

d)

Increase antivirus scan frequency

28.

Security needs detection coverage without large license fees. Which stack fits an open‑source SIEM approach?

Time limit: 1 minute

a)

Splunk Enterprise with premium apps

b)

Graylog with Wazuh for alerts

c)

Commercial IDS appliance only

d)

Microsoft Sentinel with Azure AD

29.

To strengthen network‑level intrusion discovery, which tools align with free network IDS capability?

Time limit: 1 minute

a)

Remote desktop gateway service

b)

FTP server for log archiving

c)

NTP servers for time sync

d)

Snort or Suricata as sensors

30.

An employee threatens to leak data during a dispute. Which combination best reduces risk of malicious insider exfiltration?

Time limit: 1 minute

a)

DLP monitoring with least privilege

b)

Allow personal email for large files

c)

Open file shares with faster access

d)

Disable SIEM to improve performance

31.

A team frequently makes mistakes in complex manual deployments. What strategic change reduces error rates while preserving oversight?

Time Limit: 1 minute

a)

Process automation with change approval

b)

Longer passwords for all staff

c)

More shared admin accounts

d)

Quarterly social events for morale

32.

Visitors connect phones and laptops to office Wi‑Fi, occasionally spreading malware. Which control enforces device checks before access?

Time limit for this question: 1 minute

a)

Open SSID bridged to internal VLAN

b)

RDP access for all guests

c)

Default allow rules on core switch

d)

Network Access Control with captive portal

33.

Guest devices should be isolated from internal systems yet still browse the web. What network design supports this?

Time Limit: 1 minute

a)

Separate guest VLAN with limited access

b)

Single flat network with DHCP

c)

Air‑gapped internal Wi‑Fi only

d)

Proxy all traffic through admin LAN

34.

Before allowing BYOD laptops onto Wi‑Fi, the company wants assurance they have basic protections. Which control fits this need?

Time Limit: 1 minute

a)

Force WPA2‑PSK for all internal users

b)

Mandatory local admin rights enabled

c)

Disable Windows Defender updates

d)

Device posture check for antivirus status

35.

Email staff often click suspicious links. What program most effectively builds resilience against phishing?

Time limit for this question: 1 minute

a)

Using only plaintext email formatting

b)

Blocking all external emails entirely

c)

Weekly password changes enforced globally

d)

Security awareness training with simulations

36.

Endpoint security needs continuous monitoring and response to modern threats. Which capability directly provides this?

Time limit: 1 minute

a)

Standalone antivirus with no telemetry

b)

Static firewall rules without updates

c)

Periodic manual log reviews monthly

d)

Endpoint Detection and Response agents

37.

For data at rest on Windows Pro devices, which built‑in feature enables disk encryption integrated with TPM?

Time limit: 1 minute

a)

BitLocker full‑disk encryption

b)

Windows Hello biometrics only

c)

Group Policy password policies

d)

SMB signing on file shares

38.

Security wants better detection fidelity by correlating events across devices and networks in near‑real time. Which platform type fulfills this?

Time limit: 1 minute

a)

Load balancer distributing traffic

b)

Backup software running nightly

c)

DNS server with caching enabled

d)

SIEM collecting and analyzing logs

39.

A company aims to survive a core router failure without major downtime. Which design principle guides a robust solution?

Time limit: 1 minute

a)

Default deny for outbound traffic

b)

Strict VLAN segmentation only

c)

Redundancy with automatic failover

d)

Manual reboot procedures documented

40.

A contractor plugs an unknown USB drive into a workstation. Which control best prevents data exfiltration while still allowing file receipt in a highly regulated lab?

Time Limit: 1 minute

a)

Antivirus scans on USB insertion for malware

b)

Manual user checks of files after copy

c)

USB data diodes enabling one-way data transfer

d)

Group Policy allowing any USB mass storage

41.

An office has valuable equipment in a remote, unsupervised area with no locks or cameras. Which layered plan most effectively reduces unauthorized physical access?

Time Limit: 1 minute

a)

Deploy CCTV with NVR, then burglar alarm, then locks

b)

Hide equipment and use visitor sign-in sheets only

c)

Install biometric locks only on the main door

d)

Add keypad locks and remove all windows

42.

A school uses guest Wi‑Fi with WPA or WEP and a default SSID/password. Which strategic upgrade best strengthens authentication and isolation for staff devices?

a)

Change SSID name and rotate password weekly

b)

Adopt WPA3‑Enterprise with 802.1X RADIUS

c)

Create a single VLAN for all wireless clients

d)

Enable hidden SSID with MAC filtering

43.

Students frequently install personal apps on BYOD laptops connected to campus resources. Which approach best enforces least privilege and approved software use?

Time limit: 1 minute

a)

Grant local admin rights for easier installs

b)

Block all internet access from BYOD devices

c)

Use AppLocker or equivalent whitelist with PAM

d)

Rely on an honor code for responsible installs

44.

Staff rely on personal Dropbox and Gmail for work file sharing. Which plan balances usability and data governance?

Time limit: 1 minute

a)

Permit any cloud app if users encrypt files

b)

Ban all cloud services and allow USB transfers

c)

Use DLP only without any user guidance

d)

Publish an approved SaaS list and enforce via CASB

45.

Phishing emails bypass basic filters. Which sequenced measures reduce successful credential theft and fraud?

Time Limit: 1 minute

a)

Install CCTV to monitor email usage visually

b)

Enable guest VLAN isolation only

c)

Run simulations, deploy an email gateway, enable DMARC/SPF/DKIM

d)

Rely on hidden SSID and MAC filtering

46.

A company wants to allow guests on Wi‑Fi without risking internal systems. What is the most effective network segmentation strategy?

Time Limit: 1 minute

a)

Isolate guest network on a separate VLAN

b)

Use one SSID for guests and staff together

c)

Allow guests with strong password rotation

d)

Hide the guest SSID from scans

47.

Which statement best captures the Principle of Least Privilege in managing admin rights on endpoints?

Time Limit: 1 minute

a)

Disable all privileges including basic functions

b)

Grant rights temporarily and keep them afterward

c)

Assign minimal rights needed for tasks via PAM

d)

Users should have full control for productivity

48.

A lab needs to whitelist only approved software while maintaining an inventory. What paired controls achieve this?

Time Limit: 1 minute

a)

AppLocker policies plus application approval process

b)

Group Policy to allow any app installation

c)

Hidden SSID combined with MAC address filtering

d)

CCTV monitoring combined with biometric locks

49.

An organization must detect and block unapproved cloud uploads from campus networks. Which monitoring choice is most appropriate?

a)

Visitor management logs at reception

b)

RADIUS authentication on Wi‑Fi only

c)

Network monitoring integrated with CASB enforcement

d)

Antivirus scheduled scans on endpoints

50.

Which prioritized sequence best reflects a defense-in-depth approach to USB malware risk?

Time limit: 1 minute

a)

Encrypt all USB drives without whitelisting

b)

Run AV scans only and disable whitelisting

c)

Whitelist allowed USB storage, then AV scans, then consider data diodes

d)

Permit any USB devices to improve flexibility

51.

A school plans CCTV with an NVR retaining 30 days of footage. You have 1 minute to answer: Which reasoning best justifies this over alarms alone?

a)

Alarms stop all insider threats without recordings

b)

CCTV eliminates the need for locks entirely

c)

Alarms are always cheaper than cameras and better

d)

CCTV provides visual evidence and deterrence for investigations

52.

For WPA3‑Enterprise authentication, what backend service is typically required to validate user credentials?

Time Limit: 1 minute

a)

NVR video retention server

b)

802.1X RADIUS authentication server

c)

DMARC DNS text records

d)

CASB proxy for SaaS apps

53.

A team wants to prevent shadow IT while enabling needed tools. Which plan demonstrates strategic governance?

Time limit: 1 minute

a)

Ban all SaaS and require local file shares

b)

Use MAC filtering to block unknown devices

c)

Allow any app but monitor with antivirus only

d)

Acceptable Use Policy with an approved tools list, CASB enforcement, and DLP

54.

Which control best mitigates unauthorized application installations on Windows endpoints?

Time limit: 1 minute

a)

Visitor sign‑in with badges

b)

AppLocker rule set with software inventory

c)

Biometric door locks at the lab

d)

Hidden SSID and guest VLAN

55.

Why is relying on MAC filtering and hidden SSIDs insufficient for Wi‑Fi security in a school?

Time limit: 1 minute

a)

They require expensive licenses only

b)

They replace the need for RADIUS servers

c)

They do not provide strong authentication or encryption

d)

They prevent all guest access completely

56.

A policy states: remove local admin rights, then whitelist apps, then approve new tools via catalog. What threat is this strategy primarily addressing?

Time Limit: 1 minute

a)

Phishing through email attachments

b)

Physical access by visitors after hours

c)

Unauthorized software installation and misuse

d)

Weak Wi‑Fi encryption and SSIDs

57.

Which measure complements burglar alarms to strengthen physical security for sensitive areas?

Time limit: 1 minute

a)

Group Policy allowing all USB devices

b)

DMARC records for email authentication

c)

Guest VLAN isolation on Wi‑Fi

d)

CCTV with NVR plus biometric or keypad locks

58.

A district wants to reduce phishing success while quantifying training outcomes. Which method provides actionable feedback?

Time limit: 1 minute

a)

Random password changes every month

b)

Security awareness training with phishing simulations

c)

Blocking all external emails permanently

d)

Moving staff to guest Wi‑Fi networks

59.

A school uses legacy servers with updates disabled. Plan a layered mitigation that balances cost and effort while reducing exploit risk over six months.

Time limit: 1 minute

a)

Run full Nessus weekly, ignore Windows Update

b)

Enable auto updates, then quarterly WSUS rollout

c)

Migrate to new hardware without patching plan

d)

Disable services and postpone updates indefinitely

60.

An SME has no SIEM and incidents are discovered late. Which plan best improves forensic readiness while controlling cost?

You have 1 minute to answer this question.

a)

Disable application logs, rely on antivirus alerts only

b)

Keep local logs, increase disk space, review annually

c)

Enable Windows logs, centralize to Graylog, 90‑day retention

d)

Deploy premium SIEM, skip log forwarding, short retention

61.

Users all have local admin rights. Which staged approach reduces risk while maintaining productivity for developers?

Time limit: 1 minute

a)

Create standard accounts, separate admin, add JIT elevation

b)

Remove all admin rights, deny elevation permanently

c)

Move developers to PAWs, no process changes

d)

Keep admin rights, add password complexity only

62.

Your patch budget is nearly zero. Which practical sequence strengthens security fastest?

Time limit: 1 minute

a)

Turn on automatic Windows Update, schedule WSUS later

b)

Buy EDR first, delay operating system updates

c)

Implement vulnerability scans, ignore patch results

d)

Replace legacy apps, keep current patch state

63.

A hospital worries about ransomware. Design a defense that remains effective if endpoints are encrypted.

Time limit: 1 minute

a)

Offline backups using 3‑2‑1 plus tested restores

b)

Full‑disk encryption of all endpoints only

c)

Email filtering alone for suspicious attachments

d)

Real‑time AV signatures without backup strategy

64.

You must justify purchasing Nessus Professional. Which outcome makes it a secondary control after enabling auto update?

Time Limit: 1 minute

a)

Replace Graylog as centralized log collector

b)

Block brute force attempts at the firewall

c)

Provide offline backup storage automation

d)

Identify missing patches and misconfigs regularly

65.

A company has external RDP exposed and weak passwords. Propose an order of controls to reduce account takeover risk.

You have 1 minute to answer this question.

a)

Permit guest accounts, monitor failed logins

b)

Deploy EDR, ignore authentication hardening

c)

Increase password length, leave RDP open to internet

d)

Enable MFA, set lockout policy, restrict to VPN/IP whitelist

66.

Executives ask for a minimal‑cost logging plan that still supports incident triage within 90 days. You have 1 minute to answer this question. What do you recommend?

a)

Forward Windows Event logs to Graylog with 90‑day retention

b)

Use a cloud SIEM without retention or parsing

c)

Store logs locally and delete weekly to save space

d)

Collect only security logs, ignore system/application

67.

Your org has shadow IT: unsanctioned cloud apps. Which control aligns visibility and policy enforcement across SaaS use?

Time Limit: 1 minute

a)

Mandate weekly password changes

b)

Rely on endpoint AV signatures only

c)

Block all internet traffic by default

d)

Deploy a CASB for discovery and control

68.

A university must choose between WSUS and Intune for centralized patching. Which reasoning supports either option?

Time limit: 1 minute

a)

Both provide centralized Windows patch orchestration

b)

Only WSUS can patch endpoints off campus

c)

Intune replaces backups for ransomware

d)

Neither supports scheduling update windows

69.

Security wants least privilege but admins resist. What argument best supports JIT elevation?

You have 1 minute to answer this question.

a)

Eliminates need for service accounts everywhere

b)

Grants permanent admin access for convenience

c)

Provides time‑bound admin rights reducing standing risk

d)

Replaces MFA across all privileged operations

70.

You analyze a brute force pattern: five failed logins per user in bursts. Which policy change most directly limits success if the account is locked out for 1 minute after 5 failed attempts?

a)

Account lockout after 5 attempts for 1 minute

b)

Disable password complexity requirements

c)

Allow unlimited attempts to improve usability

d)

Rotate usernames monthly without lockout

71.

During ransomware containment, email gateways begin flagging suspicious attachments. How should this be positioned in the defense?

Time limit for this question: 1 minute.

a)

Tertiary filter behind backups and EDR behavior

b)

Primary control replacing offline backups

c)

Sole measure making endpoints immune

d)

Quaternary control removing need for MFA

72.

Budgeting for ransomware defenses, which cost‑effective combo delivers resilience and detection?

Time limit: 1 minute

a)

Password rotation every 30 days without backups

b)

Offline backups plus EDR with behavioral detection

c)

Premium SIEM only with monthly reviews

d)

IP whitelisting alone for all services

73.

A team proposes PAWs for admins. What strategic benefit justifies them beyond standard accounts and JIT?

Time limit for this question: 1 minute

a)

Reduce exposure by isolating privileged operations

b)

Replace CASB for SaaS access control

c)

Offer faster internet browsing for admins

d)

Eliminate need for patching privileged hosts

74.

Logs exist but are never reviewed. You have 1 minute to answer this question: Which change increases detection speed without major spend?

a)

Forward to centralized SIEM and create basic alerts

b)

Disable system logs to reduce noise

c)

Only review after incidents are public

d)

Keep logs local and archive quarterly

75.

A small business wonders if EDR can replace backups for ransomware. What is the sound plan?

a)

Disable backups, enable Windows Defender CFA

b)

Rely on AV signatures, avoid behavior rules

c)

Adopt EDR only, skip backups entirely

d)

Use EDR as secondary, keep offline 3‑2‑1 backups

76.

After enabling MFA, lockouts rise. Which tuning maintains protection while reducing disruptions?

Time limit for this question: 1 minute.

a)

Disable lockout policy to reduce helpdesk

b)

Whitelist all internet IPs to allow access

c)

Remove MFA, trust passwords again

d)

Keep MFA, adjust lockout thresholds and IP whitelist

77.

To address unpatched systems where updates were disabled, which governance step sustains progress long term?

Time limit: 1 minute

a)

Ignore legacy systems until replacement

b)

Rely on ad‑hoc manual updates by users

c)

Disable auto updates to avoid reboots

d)

Define update schedules and compliance reporting

78.

Which set maps internal threats to matching mitigations for a quick‑win roadmap?

Time limit: 1 minute

a)

Unpatched→hardware refresh; No logging→annual review; Excess privilege→passwords

b)

Unpatched→email filters; No logging→local storage; Excess privilege→guest admin

c)

Unpatched→EDR only; No logging→disable logs; Excess privilege→keep admin

d)

Unpatched→auto updates; No logging→central SIEM; Excess privilege→JIT

79.

An organization sees a rise in phishing emails despite running simulations. You have 1 minute to answer: Which strategic change most directly reduces successful spoofing of your domain when mail is forwarded by partners?

a)

Enable basic spam filters on user inboxes

b)

Publish SPF records without DMARC policy alignment

c)

Implement DMARC with DKIM signing and monitoring

d)

Rely on employee reporting via a shared mailbox

80.

You’re planning controls for credential stuffing against a public login portal. Given limited developer time, which layered plan balances quick impact and longer-term resilience?

You have 1 minute to answer this question.

a)

Implement input validation on usernames, then add WAF rules

b)

Add MFA for all external accounts, then enable breached password checks

c)

Deploy rate limiting only for failed logins

d)

Roll out CAPTCHA everywhere, then remove password complexity

81.

A charity uses an email gateway but still suffers phishing. What sequencing best raises protection while controlling cost and complexity?

Time limit: 1 minute

a)

Replace gateway with user training courses

b)

Buy advanced sandboxing before training users

c)

Disable gateway, rely on fail2ban for SMTP

d)

Keep gateway, add DMARC with DKIM, continue simulations

82.

During a DDoS attack on an e‑commerce site, what immediate, evidence‑based action most likely restores availability with minimal internal changes?

You have 1 minute to answer this question.

a)

Rewrite backend database queries for efficiency

b)

Enable strict CSP headers on all pages

c)

Route traffic through a CDN with DDoS protection like Cloudflare

d)

Switch hosting provider mid‑attack

83.

Your team must mitigate SQL injection in custom forms. With limited budget but strong developer skills, what plan addresses root cause and auditability?

Time limit: 1 minute

a)

Encode output and trust client‑side validation

b)

Block risky IPs via WAF only, no code changes

c)

Use parameterized queries throughout, then schedule a pen‑test

d)

Sanitize input using ad‑hoc string replacement

84.

A forum suffers Cross‑Site Scripting via comment fields. Which two‑step approach most directly prevents execution and reduces future exposure?

Time limit for this question: 1 minute.

a)

Validate user names only, then rate limit posts

b)

Strip all text containing angle brackets, then add WAF

c)

Escape output on render, then enforce a restrictive CSP

d)

Whitelist allowed HTML and disable JavaScript globally

85.

You’re tasked to justify spending on Cloudflare Pro for a critical booking site. What evidence‑based rationale best supports the purchase?

Time limit: 1 minute

a)

It eliminates SQL injection risks without code changes

b)

It replaces the need for MFA on staff accounts

c)

It provides traffic scrubbing and stronger DDoS mitigation features

d)

It blocks all malware from user devices

86.

A business has no MFA and reuses passwords across services. Which control sequence most effectively reduces account takeover from credential stuffing?

Time limit: 1 minute

a)

Deploy CSP headers, then enforce output encoding

b)

Implement MFA on all external accounts, then add breached password detection

c)

Enable CAPTCHA first, then consider MFA next year

d)

Increase password length policy, then remove lockouts

87.

Email spoofing bypasses basic filters. You have 1 minute to answer: What configuration change provides domain‑level enforcement against unauthenticated senders?

a)

Disable DKIM to reduce complexity

b)

Set DMARC policy to reject with aligned DKIM

c)

Publish a permissive SPF include for all clouds

d)

Move mail to on‑prem servers with fail2ban only

88.

A login endpoint suffers bot traffic causing lockouts. Which plan balances usability and defense with measurable thresholds?

Time limit for this question is 1 minute.

a)

Block all traffic from foreign countries

b)

Require password changes weekly for all users

c)

Apply rate limiting to a small max attempts per IP, plus CAPTCHA on spikes

d)

Allow unlimited attempts to avoid support tickets

89.

Security wants to rely only on WAF to stop SQL injection. What is the strongest counter‑argument grounded in risk and maintainability?

Time limit: 1 minute

a)

Pen‑testing removes the need for development fixes

b)

Parameterized queries address the vulnerability at code level

c)

WAF is free and perfect at blocking attacks

d)

Client‑side validation is sufficient for trusted users

90.

A social app needs to support user‑generated content safely. You have 1 minute to answer: Which combined measures reduce XSS without breaking features?

a)

Encode database inputs, skip output encoding

b)

Escape dynamic content on output and enforce CSP headers

c)

Disable all forms and comments globally

d)

Use client‑side filters only for script tags

91.

Your incident plan must include post‑phishing resilience. Which metric‑driven approach improves outcomes over time?

Time limit for this question: 1 minute

a)

Stop simulations to avoid user fatigue

b)

Run regular phishing simulations tied to training and measure click rates

c)

Block all external emails by default

d)

Forward suspicious emails to IT without user training

92.

For a legacy site under DDoS, DNS change is acceptable but code changes are not. What step aligns with constraints and offers defense in depth?

Time limit: 1 minute

a)

Deploy parameterized queries everywhere

b)

Add DMARC to outbound email

c)

Rewrite application to use web sockets

d)

Implement Cloudflare free tier, then consider Pro for advanced mitigation

93.

Developers propose input validation lists to stop SQL injection. What refinement makes the plan robust against bypass techniques?

You have 1 minute to answer this question.

a)

Trust blacklists of dangerous characters

b)

Use server‑side parameterized statements with bound variables

c)

Encode output instead of validating inputs

d)

Allow client‑side JavaScript validation only

94.

Which coordinated actions most reduce XSS risk while maintaining developer velocity on a comments feature?

Time limit: 1 minute

a)

Enable CSP report‑only without other changes

b)

Escape HTML/JavaScript on render and sanitize inputs server‑side

c)

Strip all user content including emojis and links

d)

Rely solely on WAF signatures for script detection

95.

A company wants to minimize email attack surface quickly with low complexity. Which prioritized set is most appropriate?

Time limit: 1 minute

a)

Rely on employee vigilance only, remove simulations

b)

Replace gateway with on‑prem SMTP, disable DKIM

c)

Enable DMARC and DKIM, keep existing gateway, continue awareness training

d)

Use CSP headers on newsletters to block phishing

96.

Which plan best integrates WAF into broader application security for injection and XSS risks?

Time limit: 1 minute

a)

Use WAF alone for all protection layers

b)

Treat WAF as tertiary defense after code fixes and validation

c)

Disable parameterized queries to avoid duplication

d)

Run WAF only during business hours to save cost

97.

You’re evaluating costs for mitigating SQL injection across a portfolio. Which option reflects realistic investment and capability needs?

Time limit for this question: 1 minute

a)

Parameterized queries plus scheduled pen‑tests, requiring developer skill

b)

Only output encoding, no developer involvement

c)

CAPTCHA and rate limiting on login pages

d)

Zero‑cost fixes by interns over a weekend

98.

A critical service must resist automated login abuse and maintain user experience. Which strategy balances defense and friction using evidence?

You have 1 minute to answer this question.

a)

Force MFA on every page view

b)

Use CSP to restrict scripts at login

c)

Combine MFA for external accounts, breached password detection, and IP‑based rate limits

d)

Block sign‑ins from unfamiliar browsers entirely

99.

A company forces browsers to use HTTPS and refuses HTTP fallback. Which measure best ensures this behavior on the web?

Time limit: 1 minute

a)

DNSSEC zone signing policy

b)

HSTS header enforcing HTTPS

c)

VPN split-tunneling config

d)

TLS session resumption headers only

100.

Remote employees often use public Wi‑Fi at cafes. Which strategic pairing mitigates man‑in‑the‑middle risk when full certificate pinning is not feasible?

Time Limit: 1 minute

a)

Local firewall and IDS only

b)

Password rotation weekly

c)

VPN for all remote access

d)

Endpoint AV plus ad‑blocker

101.

A mobile app needs to prevent rogue certificates during TLS connections. What approach most directly addresses this?

Time limit: 1 minute

a)

DNSSEC validating resolvers

b)

Certificate pinning in the app

c)

HSTS with preload lists

d)

Registry lock at registrar

102.

Which ordered plan best reduces MITM risk for a small firm, considering effort and impact?

Time limit: 1 minute

a)

Buy WAF first, block ads, rotate passwords

b)

Turn on IDS, enforce MFA, change domains

c)

Enable HSTS, deploy VPN, educate staff

d)

Enable DNSSEC, add SBOM, patch monthly

103.

To lower supply chain risk from third‑party software, which policy is most effective at the point of acquisition?

Time limit for this question: 1 minute.

a)

Disable HTTPS to speed downloads

b)

Avoid code signing verification

c)

Use public Wi‑Fi for quick access

d)

Download only from official vendors

104.

Security wants visibility into dependencies inside delivered software packages. Which artifact supports this?

Time limit: 1 minute

a)

Browser ad‑block rules

b)

VPN connection profile

c)

DNSSEC DS record set

d)

Software Bill of Materials list

105.

Which strategic sequence strengthens vendor assurance for outsourced IT services?

Time limit: 1 minute

a)

Run EDR first, then patch monthly

b)

Use vendor risk questionnaires

c)

Enable ad‑blockers enterprise‑wide

d)

Change registrar at quarter end

106.

Your organization suspects a zero‑day in a web app but cannot patch immediately. Which control buys time by filtering exploit traffic?

Time limit: 1 minute

a)

Registry lock with MFA

b)

Certificate pinning feature

c)

DNSSEC on all zones

d)

Virtual patching via WAF/IPS

107.

To prepare for urgent zero‑day fixes, what proactive subscription is most useful for rapid response?

a)

Browser ad network feeds

b)

Public Wi‑Fi hotspot alerts

c)

General tech newsletters

d)

Vendor security bulletins

108.

Endpoint protection should stop common exploit techniques before patching occurs. Which capability aligns with this?

Time limit for this question: 1 minute

a)

Basic antivirus only

b)

EDR with exploit protection

c)

DNSSEC resolvers

d)

Ad‑blocker on browsers

109.

You need to validate DNS answers cryptographically to prevent spoofing. What mechanism provides this?

Time limit: 1 minute

a)

Certificate pinning policy

b)

HSTS preload lists

c)

DNSSEC with validation

d)

VPN client configuration

110.

A domain keeps getting unauthorized nameserver changes. What registrar‑level control reduces this?

You have 1 minute to answer this question.

a)

Use virtual patching WAF

b)

Enable browser ad‑blocker

c)

Registry lock on the domain

d)

Turn off HTTPS headers

111.

Which detection step helps discover unexpected DNS zone edits promptly?

Time limit for this question: 1 minute

a)

SBOM periodic review

b)

Monthly password changes

c)

DNS monitoring alerts

d)

Ad‑blocking on endpoints

112.

To protect registrar accounts from takeover, what access control is most appropriate?

Time limit for this question: 1 minute

a)

VPN split tunnel only

b)

HSTS with strict mode

c)

MFA on registrar account

d)

EDR network containment

113.

Employees see malicious ads delivering drive‑by scripts. What immediate workstation control reduces risk?

Time limit: 1 minute

a)

Enable SBOM publishing

b)

Registry lock at registrar

c)

Disable HTTPS on sites

d)

Browser ad‑block extension

114.

A school wants network‑level ad blocking without managing every browser. Which solution fits?

Time Limit: 1 minute

a)

Vendor questionnaires

b)

DNS‑based ad blocking

c)

Local HSTS policies

d)

Certificate pinning per app

115.

During a critical zero‑day, what planned environment helps safely test updates before deployment?

Time Limit: 1 minute

a)

Air‑gapped testing setup

b)

Open registrar account

c)

Public Wi‑Fi staging

d)

Live production trial

116.

Which pair correctly matches threat and primary countermeasure?

Time limit: 1 minute

a)

DNS hijacking—enable DNSSEC

b)

MITM—enable registry lock

c)

Supply chain—use ad‑blocker

d)

Zero‑day—disable TLS

117.

A startup must balance cost and effort securing remote access. Which statement reflects realistic planning?

Time limit: 1 minute

a)

Set up VPN server costs £0–500

b)

DNSSEC costs £500 monthly

c)

Ad‑blocking requires new ISP

d)

SBOM requires new hardware

118.

Which strategic combination exemplifies defense‑in‑depth against zero‑day web exploits?

Time limit: 1 minute

a)

Pin certificates everywhere, ignore patches

b)

Enable DNSSEC, registry lock, ad‑block only

c)

Disable HTTPS, use public Wi‑Fi, trust ads

d)

Patch fast, deploy EDR, add WAF rules

119.

A mid-size firm wants to cut drive-by malware from industry news sites without blocking all browsing. Which preventative stack best reduces risk while keeping usability?

Time Limit: 1 minute

a)

Primary web filtering plus browser isolation layered

b)

Adding banner warnings to all external emails

c)

Only disabling JavaScript on all external sites

d)

Relying on auto-update of browsers alone

120.

Finance receives an urgent wire request appearing from the CEO. You now have 1 minute to respond. Which immediate action most effectively prevents Business Email Compromise loss?

a)

Execute transfer within policy time window

b)

Verify via dual-approval with out-of-band call

c)

Forward email to IT for later DMARC check

d)

Reply asking the sender to confirm by email

121.

Your security plan must address predictable user behavior at industry-specific portals. Which evidence-backed control combination strengthens resilience?

Time limit for this question: 1 minute

a)

Deploy IDS and threat intel feeds together

b)

Train users to avoid all external websites

c)

Disable all browser extensions organization-wide

d)

Mandate VPN for all browsing sessions

122.

Budget allows £0–2,000 per year for commercial threat intelligence. Which planning choice best uses this budget to reduce watering-hole risk?

Time limit: 1 minute

a)

Hire marketing to rewrite external banners

b)

Purchase new laptops with faster CPUs

c)

Subscribe to threat feeds updating blocklists

d)

Buy DLP software and restrict sales data

123.

To protect large payments, which policy redesign offers both low cost and high impact?

Time Limit: 1 minute

a)

Enable DMARC quarantine without training

b)

Implement mandatory browser isolation for finance

c)

Deploy endpoint DLP across all departments

d)

Dual-approval with voice verification on transfers

124.

An email spoofs a trusted partner domain. Which control directly rejects spoofed messages at the gateway?

Time limit: 1 minute

a)

Access controls limiting finance inboxes

b)

User training on suspicious senders

c)

Threat intelligence domain blocklists

d)

DMARC enforcement policy on inbound mail

125.

Compliance wants a measurable way to harden browsers against watering-hole sites. Which plan is most defensible?

Time limit: 1 minute

a)

Disable JavaScript only for untrusted domains

b)

Block all downloads organization-wide

c)

Force TOR for external web access

d)

Remove Chrome and use legacy IE

126.

Executives demand quick browsing with minimal phishing exposure. Which layered approach balances speed and safety?

Time limit: 1 minute

a)

Remote browser isolation plus web filtering

b)

Company-wide email banners only

c)

Quarterly awareness training alone

d)

Upgrade Wi-Fi with stronger encryption

127.

Sales data must be protected from competitor espionage. Which access design most limits exposure while preserving operations?

Time limit: 1 minute

a)

Only sales team sees customer lists

b)

Everyone in company views CRM exports

c)

Marketing shares full lists with partners

d)

Finance team owns all prospect records

128.

A startup lacks formal agreements with contractors handling proprietary designs. Which step offers the strongest immediate legal protection?

a)

Block social media on office Wi‑Fi

b)

Purchase IDS for internal network

c)

Enable DMARC reject for outbound mail

d)

Implement Non-Disclosure Agreements with contractors

129.

Which control specifically aims to prevent data exfiltration to competitors from endpoints?

Time limit for this question: 1 minute

a)

Email banners on external messages

b)

Threat intelligence blocklist updates

c)

Dual-approval for large wire payments

d)

DLP software deployment organization-wide

130.

A firm wants to reduce the implementation difficulty of BEC protections while maintaining effectiveness. Which plan fits?

Time limit: 1 minute

a)

Deploy enterprise DLP across departments

b)

Replace email with internal chat only

c)

Mandate browser isolation for all users

d)

Adopt dual-approval and DMARC gradually

131.

Security proposes remote browser rendering for risky sites. Which outcome does this most directly achieve?

a)

Eliminates need for web filtering policies

b)

Guarantees zero phishing emails are received

c)

Isolates web content away from endpoints

d)

Encrypts all network traffic end-to-end

132.

During incident planning, which evidence supports choosing IDS for watering-hole mitigation?

Time limit: 1 minute

a)

Automatically rewrites all third-party JavaScript

b)

Blocks every external site by default

c)

Replaces the need for patch management

d)

Detects suspicious traffic patterns to known threats

133.

To verify a high-risk payment instruction, which method provides independent confirmation and auditability?

Time limit: 1 minute

a)

Out-of-band call to a known contact number

b)

Reply to the requesting email for confirmation

c)

Send a text message to the sender’s number

d)

Approve based on email signature graphics

134.

Which combination most effectively counters competitor data theft with balanced cost and difficulty?

Time limit: 1 minute

a)

NDAs plus access controls on customer data

b)

Only deploy DLP to block all uploads

c)

Train staff quarterly without agreements

d)

Encrypt Wi‑Fi and rotate passwords weekly

135.

A company updates browsers automatically but still gets infected via compromised industry portals. Which added control best addresses the gap?

Time limit for this question: 1 minute

a)

Introduce web filtering to block known malicious sites

b)

Remove auto-update to test patches manually

c)

Force all traffic through email gateways only

d)

Disable internal DNS resolution entirely

136.

Leadership asks for a practical first step against BEC with minimal spend. Which action should be prioritized?

Time limit: 1 minute

a)

Deploy full browser isolation to finance

b)

Implement process change for dual-approval

c)

Launch a custom phishing simulation program

d)

Purchase advanced DLP software suite

137.

The security team must flag external emails for caution. Which measure complements authentication checks to aid users?

a)

Banner warnings on messages from outside

b)

Mandatory VPN for sending all emails

c)

Blocking emails with attachments only

d)

Auto-forwarding external mail to quarantine

138.

When designing a layered defense for watering-hole attacks, which sequence reflects sensible prioritization?

a)

Intel feeds then disable all browsing then IDS

b)

User training then block all JavaScript globally

c)

Web filtering then browser isolation then intel feeds

d)

Auto-updates alone then rely on email banners