Question 1 of 15 Technology Essentials
Which layer of the TCP IP model is responsible for routing packets between networks?
A The internet layer B The application layer C The link layer D The session layer
Question 2 of 15 Technology Essentials
What does DNS primarily do?
A Encrypt all web traffic B Store user passwords C Filter spam email D Resolve human readable names to IP addresses
Question 3 of 15 Technology Essentials
A command line tool shows active network connections and listening ports on a host. Which utility fits?
A ping B traceroute C netstat D nslookup
Question 4 of 15 Technology Essentials
Why is understanding a system baseline important for an operations analyst?
A Because it sets the marketing plan B Because deviations from normal behavior help detect potential incidents C Because it chooses the hardware color D Because baselines never change
Question 5 of 15 Cybersecurity Principles and Risk
The principle of least privilege reduces risk by doing what?
A Giving all users administrator rights B Granting only the access needed for a role C Removing all authentication D Sharing accounts among staff
Question 6 of 15 Cybersecurity Principles and Risk
Risk is commonly expressed as a function of which two factors?
A Cost and color B Speed and size C Age and brand D Likelihood and impact
Question 7 of 15 Cybersecurity Principles and Risk
Defense in depth improves security by doing what?
A Relying on a single strong control B Removing redundant controls C Trusting the perimeter alone D Layering multiple controls so one failure does not expose everything
Question 8 of 15 Adversarial Tactics Techniques and Procedures
An attacker sends a crafted email to trick a user into revealing credentials. Which technique is this?
A Denial of service B Phishing C SQL injection D Port scanning
Question 9 of 15 Adversarial Tactics Techniques and Procedures
An adversary who has gained access moves from one system to others inside the network. What is this called?
A Initial access B Exfiltration C Lateral movement D Reconnaissance
Question 10 of 15 Incident Detection and Response
What is the first phase of a typical incident response process?
A Preparation B Eradication C Recovery D Lessons learned
Question 11 of 15 Incident Detection and Response
A SIEM correlates logs from many sources primarily to do what?
A Detect suspicious patterns and generate alerts for analysts B Replace all firewalls C Store marketing data D Encrypt user files
Question 12 of 15 Incident Detection and Response
During incident response, why is containment performed before eradication?
A To stop the incident from spreading while the threat is removed B To delete evidence quickly C To skip the investigation D To notify the public first
Question 13 of 15 Incident Detection and Response
What is the value of preserving forensic evidence during an incident?
A It slows the response for no reason B It supports investigation, root cause analysis, and possible legal action C It is only for marketing D It prevents future backups
Question 14 of 15 Securing Assets
Hardening a server by disabling unused services and ports achieves what?
A Increasing the number of vulnerabilities B Making the server public by default C Reducing the attack surface exposed to adversaries D Removing all logging
Question 15 of 15 Securing Assets
Why should security patches be applied in a timely, tested manner?
A To slow systems down deliberately B To use more storage C To close known vulnerabilities while avoiding unplanned outages D To change the interface theme