Cybersecurity-Apprentice Sample Questions & Answers
Free Cybersecurity Apprentice practice questions with worked answers and explanations. See how the ExamJungle simulator prepares you — then jump into the full test.
Launch the full Cybersecurity-Apprentice simulator →Showing 10 of 20 free samples.
- Question 1Beginner
Network Security · Explain the function of a VPN
A remote employee reports being unable to access internal company resources. A network administrator determines the employee needs a secure, encrypted connection over the public internet to the corporate network. Which technology is specifically designed for this purpose?
Show answer & explanation
Correct answer: D
A Virtual Private Network (VPN) creates a secure, encrypted tunnel over a public network like the internet. This allows remote users to securely connect to a private corporate network as if they were physically present, protecting the confidentiality and integrity of the data in transit.
- Question 2Intermediate
Network Security · Explain the function of data loss prevention (DLP)
An organization wants to prevent sensitive data, such as credit card numbers and social security numbers, from being exfiltrated from their network via email or web uploads. Which security technology is specifically designed to inspect outbound traffic for such content and block it based on policy?
Show answer & explanation
Correct answer: C
Data Loss Prevention (DLP) systems are designed to detect and prevent data breaches and data exfiltration. They use mechanisms like deep packet inspection and content analysis to identify sensitive data patterns (like credit card numbers) within network traffic and enforce policies to block or alert on unauthorized transmission.
- Question 3Intermediate
Cybersecurity · Identify and describe the stages of the cyber attack lifecycle
A security team is analyzing an attack that successfully compromised a web server. The investigation revealed the following sequence of events: 1) The attacker identified open ports on the server. 2) The attacker used a known software flaw to gain access. 3) The attacker installed a persistent backdoor. 4) The attacker began exfiltrating data. In which stage of the cyber attack lifecycle did the attacker use the known software flaw?
Show answer & explanation
Correct answer: C
The Exploitation stage is where the attacker actively triggers a vulnerability to gain unauthorized access or execute code. Using a known software flaw to gain initial access is the definitive action of this stage. Reconnaissance (Step 1) preceded it, and Installation (Step 3) followed it.
- Question 4Beginner
Endpoint Security · Differentiate between single-factor authentication and multi-factor authentication
What is the key difference between single-factor authentication (SFA) and multi-factor authentication (MFA)?
Show answer & explanation
Correct answer: B
The core principle of MFA is the use of multiple, independent categories of credentials. The main categories are: something you know (password, PIN), something you have (token, phone), and something you are (biometrics). SFA relies on only one of these categories (typically a password), whereas true MFA requires proof from at least two.
- Question 5Advanced
Cloud Security · Explain the function of continuous integration and continuous delivery / deployment (CI/CD)
A DevOps team is adopting a CI/CD pipeline to automate application deployment to the cloud. What is the primary security benefit of integrating security checks into this pipeline (a practice known as DevSecOps)?
Show answer & explanation
Correct answer: C
The core concept of DevSecOps, or 'shifting left,' is to integrate automated security testing and validation early in the CI/CD pipeline. Finding and fixing vulnerabilities during development is significantly cheaper and less risky than discovering them in production. This approach makes security a shared responsibility and builds it into the development process, rather than treating it as a final gate before release.
- Question 6Intermediate
Security Operations · Explain security orchestration, automation, and response (SOAR) and security information and event management (SIEM)
A Security Operations Center (SOC) manager wants to improve the team's efficiency by automatically enriching alerts with threat intelligence, creating incident tickets, and executing initial containment actions without manual intervention. Which technology is best suited for these tasks?
Show answer & explanation
Correct answer: C
Security Orchestration, Automation, and Response (SOAR) platforms are specifically designed to automate and orchestrate security workflows. While a SIEM is excellent for collecting, correlating, and generating alerts from log data, a SOAR platform takes the output from the SIEM (and other tools) and executes predefined playbooks to handle repetitive tasks, thereby improving response times and freeing up analysts for more complex investigations.
- Question 7Beginner
Cybersecurity · Explain the purpose of a DMZ
A network is designed with a separate, isolated segment to host public-facing servers like web and email servers. This segment is positioned between the internal private network and the untrusted public internet. What is this isolated network segment called?
Show answer & explanation
Correct answer: C
A Demilitarized Zone (DMZ) is a perimeter network that protects an organization's internal local-area network (LAN) from untrusted traffic. By placing public-facing services in the DMZ, an organization can provide an additional layer of security; if a server in the DMZ is compromised, the attacker does not have direct access to the internal network.
- Question 8Beginner
Network Fundamentals · Identify and describe devices that operate in Layer 1 through Layer 4 of the OSI model
Which device operates primarily at Layer 3 of the OSI model to forward packets between different networks based on their destination IP address?
Show answer & explanation
Correct answer: C
A router is the quintessential Layer 3 device. Its primary function is to make routing decisions, reading the destination IP address of incoming packets and forwarding them to the appropriate next hop on a different network. Switches operate at Layer 2 (using MAC addresses), and hubs operate at Layer 1 (simply repeating signals).
- Question 9Beginner
Network Fundamentals · Explain the function of NAT, DNS, and DHCP
What is the primary function of the Domain Name System (DNS) in a TCP/IP network?
Show answer & explanation
Correct answer: B
DNS serves as the 'phonebook of the internet.' Its core function is to resolve (translate) human-friendly domain names (e.g., www.paloaltonetworks.com) into the numerical IP addresses (e.g., 199.167.52.13) that computers use to communicate with each other. Automatic IP address assignment is the function of DHCP.
- Question 10Advanced
Endpoint Security · Explain the objectives of endpoint security and network security
A hospital is deploying numerous medical IoT devices, such as infusion pumps and patient monitors, on its network. From a security perspective, what is a primary objective when distinguishing between endpoint security for these IoT devices and traditional network security?
Show answer & explanation
Correct answer: C
This highlights the core difference. Medical IoT devices often run specialized, closed-source operating systems where traditional endpoint security agents (like antivirus) cannot be installed. Therefore, endpoint security objectives shift to hardening what is possible (e.g., configuration) and relying heavily on network security to compensate. Network security's objective is to use segmentation (e.g., placing IoT devices in a specific VLAN) and strict firewall policies to isolate these devices and limit their communication to only what is necessary, preventing them from being used as a pivot point in an attack.
Ready for the real thing?
The full Cybersecurity-Apprentice simulator has every exam-style question, timed mode, and instant scoring.