Cybersecurity-Fundamentals Sample Questions & Answers
Securing assets, including classification, controls and identity and access management, carries the most weight, ahead of core information security and network concepts, the threat landscape of attack vectors and vulnerabilities, and incident response and continuity.
Launch the full Cybersecurity-Fundamentals simulator →Showing 10 of 20 free samples.
- Question 1Beginner
Securing Assets · Encryption Technologies
True or False: In a symmetric encryption system, the key used for encryption is different from the key used for decryption.
Show answer & explanation
Correct answer: B
This statement is false. The defining characteristic of symmetric encryption (also known as secret-key or shared-key encryption) is that the same key is used for both the encryption and decryption processes. Asymmetric encryption, in contrast, uses a key pair consisting of a public key for encryption and a different, private key for decryption.
- Question 2Advanced
Securing Assets · Network Architecture Security
Company Background:
Global Logistics Inc. (GLI) is a large shipping and logistics company that operates a complex network of warehouses, distribution centers, and transportation fleets. The company relies heavily on its Industrial Control Systems (ICS) and Supervisory Control and Data Acquisition (SCADA) systems to manage automated sorting machinery, climate control in sensitive storage areas, and fleet tracking. Historically, the ICS/SCADA network was completely air-gapped from the corporate IT network.Current Situation:
To improve efficiency and enable predictive maintenance, GLI's management has approved a project to connect the ICS/SCADA network to the corporate IT network. This will allow data from the operational technology (OT) environment to be analyzed by business intelligence platforms in the IT environment. The CISO is concerned because the ICS/SCADA systems are legacy devices, many running on old, unpatched operating systems that cannot be easily upgraded. The OT engineers are resistant to any changes that could introduce latency or cause downtime.Requirements & Constraints:
- Prevent unauthorized traffic from the IT network from reaching the critical ICS/SCADA devices.
- Allow specific, approved data flows from the OT network to a data historian server in the IT network.
- Ensure that security controls do not interfere with the real-time operational requirements of the OT environment.
- The solution must be implemented without replacing the legacy ICS/SCADA equipment.
Which of the following architectural approaches BEST meets GLI's security and operational requirements?
graph TD subgraph IT_Network [Corporate IT Network] BI[BI Platform] Users[Corporate Users] end subgraph OT_Network [ICS/SCADA Network] PLC[PLCs] HMI[HMIs] Sensors[Sensors] end IT_Network -- "????" -- OT_NetworkShow answer & explanation
Correct answer: B
This is the best approach based on industry best practices like the Purdue Model for ICS security. A DMZ creates a buffer zone that strictly controls communication between the IT and OT networks. Placing a data historian in the DMZ allows OT systems to send data to a single, controlled point without allowing direct access from the IT network into the OT environment. A proxy adds another layer of security by terminating connections and inspecting traffic, preventing direct protocol communication. This architecture meets all requirements: it prevents unauthorized access, allows specific data flows, and minimizes impact on the real-time OT network.
- Question 3Intermediate
Security Operations and Response · Security Monitoring and Analysis
A SOC analyst is reviewing logs from a Security Information and Event Management (SIEM) system and notices a large number of failed login attempts for a single administrator account, originating from multiple international IP addresses within a five-minute window. This is immediately followed by a single successful login from a new, previously unseen international IP address. Which type of attack has MOST likely occurred?
Show answer & explanation
Correct answer: D
The pattern described—many failed login attempts against a single account from various sources, culminating in a success—is a classic indicator of a distributed brute-force attack. Attackers use a botnet or multiple compromised machines to try a large number of passwords against one username, eventually guessing the correct one. Password spraying involves trying one or a few common passwords against many different usernames, which would present a different log pattern.
- Question 4BeginnerSelect 3
Securing Assets · Security Controls
Which of the following are considered administrative security controls? (Select THREE).
Show answer & explanation
Correct answers: B, C, E
Security awareness training is an administrative control that aims to influence user behavior and enforce security policies through education.
An acceptable use policy is a document (a policy) that governs how employees can use company assets, making it a classic administrative control.
Conducting background checks is a procedural control (an administrative control) designed to mitigate risks associated with personnel.
- Question 5Intermediate
Securing Assets · Application Security
A software development team uses a CI/CD pipeline to automate builds, testing, and deployments. A security engineer wants to integrate security scanning into this pipeline to identify vulnerabilities early in the development lifecycle. This practice is a core component of which methodology?
Show answer & explanation
Correct answer: C
DevSecOps is a methodology that integrates security practices within the DevOps process. A key principle of DevSecOps is 'shifting left,' which means incorporating security considerations and automated testing (like SAST and DAST scans) as early as possible in the development lifecycle, often directly within the CI/CD pipeline. This contrasts with traditional models where security testing is a separate phase at the end of development.
- Question 6Beginner
Information Security Fundamentals · Security Principles
An organization is concerned about insider threats. A security architect has been asked to implement a control that requires two different employees to approve any high-risk transaction, such as a wire transfer over $100,000. What is the name of this security principle?
Show answer & explanation
Correct answer: B
Separation of Duties is a security principle that prevents a single individual from having control over all aspects of a critical task. By requiring two different employees to approve a high-risk transaction, the organization ensures that no single person can execute the action fraudulently without collusion. This is a key control for preventing fraud and errors.
- Question 7Intermediate
Threat Landscape · Threat Modeling
What is the primary purpose of conducting a threat modeling exercise during the design phase of a new application?
Show answer & explanation
Correct answer: C
The primary purpose of threat modeling is proactive risk identification. By systematically analyzing the application's design, data flows, and trust boundaries (e.g., using a methodology like STRIDE), the team can identify potential security flaws at the architectural level. This allows them to design and build in countermeasures from the beginning, which is far more effective and less costly than finding and fixing vulnerabilities after the application has been built.
- Question 8Beginner
Information Security Fundamentals · CIA Triad
A hospital needs to ensure that patient data, classified as Protected Health Information (PHI), is secured according to regulatory requirements. A security administrator is configuring full-disk encryption on laptops used by medical staff. What specific aspect of the CIA triad does this control primarily address?
pie title CIA Triad Focus "Confidentiality" : 70 "Integrity" : 15 "Availability" : 15Show answer & explanation
Correct answer: A
Encryption is a primary control for ensuring confidentiality. By encrypting the data on the laptop's hard drive, the organization ensures that if the laptop is lost or stolen, the data remains unreadable to unauthorized individuals. This directly prevents the unauthorized disclosure of sensitive PHI, which is the core of confidentiality.
- Question 9Intermediate
Threat Landscape · Vulnerability Management
True or False: A zero-day vulnerability is a software flaw that has been publicly disclosed but for which no official patch or update has been released by the vendor.
Show answer & explanation
Correct answer: A
This statement is true. A zero-day vulnerability refers to a security flaw that is known to attackers (and possibly the public) before the software vendor has released a patch to fix it. This creates a critical window of opportunity for attackers to exploit the vulnerability, as there are 'zero days' of protection available for users.
- Question 10Advanced
Securing Assets · Cloud Security Best Practices
Company Background:
FinSecure, a rapidly growing fintech startup, provides a mobile banking application to its customers. The company prides itself on innovation and rapid feature deployment, following a DevOps model. The entire infrastructure is hosted in a public cloud environment. The application handles sensitive financial data, including transaction histories and personally identifiable information (PII).Current Situation:
An external audit revealed several security concerns. The development team has been storing database credentials and API keys as plain text variables within their source code repositories. The audit also noted that the company has no formal process for managing user access to its cloud infrastructure, with several developers having broad administrative permissions. Finally, there is no centralized system for monitoring and responding to security events, making it difficult to detect breaches.Requirements & Constraints:
- Eliminate the practice of storing secrets in source code.
- Implement the principle of least privilege for cloud infrastructure access.
- Establish a capability for centralized logging and security event monitoring.
- The solutions must be cloud-native and integrate well with their existing CI/CD pipeline.
Which combination of security controls would be MOST effective in addressing all of the audit findings for FinSecure?
Show answer & explanation
Correct answer: A
This option comprehensively addresses all three audit findings with appropriate, modern solutions. A secrets management tool directly solves the problem of hardcoded credentials. Implementing RBAC via the cloud provider's IAM service is the standard way to enforce the principle of least privilege. Deploying a SIEM provides the necessary centralized logging and monitoring capabilities. These tools are designed to work in cloud environments and integrate with CI/CD pipelines.
Ready for the real thing?
The full Cybersecurity-Fundamentals simulator has every exam-style question, timed mode, and instant scoring.