Quiz 1 — 2026/2027 Curriculum
Total Questions: 25 | Time Recommended: 45 minutes
Questions 1–10: Foundational Recall & Terminology
Q1: Which layer of the OSI model is primarily responsible for end-to-end encryption and
session management?
plain
A) Transport Layer
B) Session Layer
C) Presentation Layer
D) Application Layer
Answer: B
Explanation: The Session Layer (Layer 5) manages sessions between applications, while
the Transport Layer (Layer 4) handles end-to-end delivery. Encryption typically occurs at
multiple layers, but session management is the Session Layer's core function. Security
professionals must understand layer boundaries to implement controls effectively.
Q2: In the TCP/IP model, which layer combines the functions of the OSI model's Session,
Presentation, and Application layers?
plain
A) Internet Layer
B) Transport Layer
C) Application Layer
D) Network Access Layer
,Answer: C
Explanation: The TCP/IP Application Layer is a broader construct that encompasses OSI
Layers 5–7. This consolidation means application-layer security controls in TCP/IP
environments must address session management, data formatting, and user interface
security simultaneously.
Q3: Which protocol operates on port 53 and is frequently targeted for cache poisoning
attacks?
plain
A) HTTP
B) FTP
C) DNS
D) SNMP
Answer: C
Explanation: DNS (Domain Name System) operates on UDP/TCP port 53. DNS cache
poisoning exploits the trust relationship between recursive resolvers and authoritative
servers, redirecting users to malicious sites. DNSSEC mitigates this by adding
cryptographic authentication to DNS responses.
Q4: Which encryption algorithm is an asymmetric cipher commonly used for key
exchange and digital signatures?
plain
A) AES-256
B) RSA
C) 3DES
D) Blowfish
Answer: B
Explanation: RSA is an asymmetric algorithm using public-private key pairs, making it
ideal for secure key exchange and digital signatures. AES-256, 3DES, and Blowfish are all
symmetric algorithms that use a single shared key for encryption and decryption.
, Q5: What is the primary security purpose of a hashing algorithm like SHA-256?
plain
A) Confidentiality of data at rest
B) Data integrity verification
C) Non-repudiation of sender identity
D) Session key generation
Answer: B
Explanation: Hashing algorithms produce a fixed-length digest that acts as a digital
fingerprint. Any alteration to the input data produces a completely different hash,
enabling integrity verification. Hashing does not provide confidentiality (that's
encryption) or non-repudiation (that requires digital signatures).
Q6: In the CIA Triad, which principle ensures that authorized users can access
information and resources when needed?
plain
A) Confidentiality
B) Integrity
C) Availability
D) Non-repudiation
Answer: C
Explanation: Availability ensures systems and data are accessible to authorized users
upon demand. DDoS attacks, hardware failures, and ransomware directly threaten
availability. While non-repudiation is important, it is not part of the core CIA Triad.
Q7: Which component of AAA is responsible for verifying that a user is who they claim
to be?
plain
A) Authorization
B) Authentication
C) Accounting
D) Auditing
Answer: B