1. Which control best supports confidentiality for a shared document? Restrict access to approved users only. Make the link public. Disable all logging. Remove the file owner.
2. Which control best supports integrity for an important file? Use permissions, version history, approvals, and change records. Allow anyone to edit anonymously. Delete all backups. Disable authentication.
3. Which control best supports availability? Tested backups, monitoring, redundancy, and recovery planning. One unverified copy. No owner. No update process.
4. Which statement best describes risk? The possibility that a threat may use a vulnerability and cause harm to an asset. A guaranteed attack. A password policy. A device name.
5. What is a control? A safeguard used to prevent, detect, respond to, or recover from risk. A confirmed attacker. A public website. A user profile.
6. Which example shows defense in depth? Unique passwords, MFA, login alerts, least privilege, and recovery review used together. One shared password. One security tool with no monitoring. No backup plan.
7. Who should provide authorization for a cybersecurity activity? The responsible owner or an approved authority. Any student. Any internet user. The first person who finds the system.
8. Which action is outside scope? Interacting with a real public system when only a fictional sandbox was approved. Reviewing the provided fictional logs. Using the approved read-only dashboard. Writing a defensive report from the lab evidence.
9. Why are stop conditions important? They pause activity when unexpected risk, real data, instability, or unclear permission appears. They allow the learner to continue without approval. They remove privacy requirements. They replace documentation.
10. Which evidence-handling practice is strongest? Preserve originals, document timestamps, restrict access, and work from approved copies. Edit the original evidence. Delete timestamps. Share the evidence publicly.
11. What is privacy minimization? Collecting, viewing, storing, and sharing only what the task requires. Collecting every available detail. Publishing all information. Disabling access controls.
12. What is an IP address used for? Helping devices send data to the correct network destination. Storing passwords. Classifying documents. Creating recovery codes.
13. Which statement about DNS is correct? It helps map domain names to network addresses. It guarantees website trustworthiness. It encrypts every file. It replaces MFA.
14. Which evidence best helps review a network connection? Source, destination, service, protocol, time, volume, and expected purpose. Only the alert color. Only the device wallpaper. Only the user's opinion.
15. Why are ports useful? They help identify the application or service involved in communication. They create user accounts. They store backups. They replace routers.
16. Which statement about HTTPS is correct? It can protect the connection even when the website itself is deceptive. It guarantees the website owner is honest. It guarantees every download is safe. It makes URL review unnecessary.
17. Which URL detail is most important during look-alike review? The actual registered domain and spelling. The logo size. The page background. The number of images.
18. What should a user do when a page requests unexpected browser permissions? Deny or pause, verify the need, and use the official service through a trusted route. Approve everything automatically. Disable browser protections. Enter credentials first.
19. Which response to an unfamiliar cloud destination is strongest? Compare it with approved changes, application ownership, domain, service, and device group. Assume it is malicious immediately. Ignore it permanently. Block it without authority.
20. What is a digital identity? The accounts, identifiers, credentials, devices, profiles, and activity connected to a person or organization. Only a profile picture. Only a password. Only a device name.
21. Which passphrase practice is strongest? Use a long, unique passphrase for each important account. Reuse one short password everywhere. Share the passphrase with friends. Store it in a public document.
22. Which MFA response is safest? Deny an unexpected approval request and review the account through the official service. Approve every request. Share the code with the sender. Disable MFA permanently.
23. Why should recovery codes be protected? They may allow account access when the usual authentication method is unavailable. They are harmless public information. They replace every password. They should be posted online.
24. Which access-review decision is strongest? Remove permissions that are no longer required and document the change. Keep every old permission. Grant more access just in case. Use one shared administrator account.
25. What should happen to a former contractor account? Disable or suspend it through the approved offboarding process. Leave it active forever. Share it with another person. Delete all related logs first.
26. Which privacy setting is strongest for personal profile details? Limit visibility to the smallest appropriate audience. Make all details public. Share exact location history. Publish recovery information.
27. What is the safest response to an app permission that is no longer needed? Remove the permission and verify the app still works as required. Keep every permission forever. Grant additional access. Share the account password.
28. Which backup plan is strongest? Separate protected copies, clear ownership, regular testing, and documented recovery goals. One copy on the same device. No owner. No restore testing.
29. What is phishing triage? A structured review of message risk, evidence, priority, and next action. Opening every attachment. Replying to unknown senders. Deleting every urgent email.
30. Which sender indicator is most useful? The full sending address and domain. Only the display name. Only the profile image. Only the signature.
31. Which request is a strong phishing warning sign? An urgent demand for passwords, MFA codes, payment, or immediate sign-in. A scheduled class reminder. A normal calendar invitation from a verified source. A message with no request.
32. What should a user do with a suspicious password-reset message? Avoid the link and access the official account page directly. Click the link immediately. Reply with the old password. Forward the message widely.
33. Why should the original suspicious message be preserved? It may contain headers, timestamps, sender details, URLs, and other evidence. It makes the link safe. It proves the sender is malicious. It removes the need for reporting.
34. What is malware? Software designed to disrupt, damage, spy on, steal from, or gain unauthorized access. A secure browser setting. A backup schedule. A password manager.
35. Which endpoint action is safest for a suspicious file? Do not open or run it; preserve evidence and follow the approved playbook. Execute it again. Upload it publicly. Send it to classmates.
36. What does an endpoint process chain show? The sequence of programs, files, or actions connected to an event. Only the device name. Only the alert severity. Only the user's role.
37. Which endpoint case deserves higher priority? A privileged account, suspicious download, blocked script, and unusual network activity on the same device. A harmless wallpaper change. A resolved printer message. A normal approved update.
38. Why is a blocked script not enough to close a case? Related account, email, network, or recovery evidence may remain unresolved. Blocked events are always harmless. Logs are unnecessary. Users should run the script again.
39. Which network event should be correlated with an endpoint alert? Outbound attempts from the same device during the same time window. An unrelated printer status message. A normal login from another user. A scheduled class event.
40. What is escalation? Moving a case to a more specialized or authorized responder when risk or uncertainty requires it. Deleting the case. Sharing evidence publicly. Ignoring the alert.
41. Which incident timeline is strongest? An ordered record of relevant events, evidence, actions, owners, and decisions. A list with no timestamps. A guess about what happened. Only the final alert.
42. What should be documented in a case? Evidence, facts, uncertainty, decisions, owners, actions, limitations, and next steps. Only the alert title. Only the final score. Only the user's opinion.
43. Which portfolio artifact is strongest? A safely recreated report with a clear skill claim, evidence, reflection, and revision. A screenshot with private data. A title with no explanation. An exaggerated expert claim.
44. Which reflection statement is strongest? I initially confused HTTPS with website trust, then revised my diagram to separate secure transport from domain legitimacy. I learned a lot. Everything was easy. I am now an expert.
45. What should happen before sharing a screenshot in a portfolio? Redact or recreate sensitive names, emails, tickets, credentials, and internal details. Publish it immediately. Add more private data. Remove all explanation.
46. Which beginner skill claim is most credible? I can review fictional web evidence by checking the domain, HTTPS status, warning messages, and user request. I can secure every organization. I know all of cybersecurity. I never need supervision.
47. What is a knowledge gap? A concept, process, or decision area that still needs review or practice. A completed lesson. A correct answer. A certificate.
48. Which evidence should lower a learner's confidence rating? Repeated missed questions and weak explanations in the same domain. One correctly explained practice set. A revised artifact. A strong checklist.
49. What is the best use of a practice-test score? Identify weak domains, review explanations, and build a targeted study plan. Treat it as the only measure of ability. Ignore missed questions. Memorize answer letters.
50. What should happen before the Beginner Final Test? Review repeated errors, explain weak concepts, complete targeted practice, and confirm readiness. Skip all missed topics. Use only confidence feelings. Avoid reviewing explanations.