IS 5403 CYBERSECURITY WEEK 5 QUIZZES |
QUESTIONS & CORRECT ANSWERS | 2026
UPDATED | 100% CORRECT | TRINE UNIVERSITY
147 Questions with Answers and Detailed Rationales
100 PERCENT GUARANTEED PASS
INSTANT DOWNLOAD ANSWERS INCLUDED
IMPORTANCE OF THIS DOCUMENT
This comprehensive examination preparation guide has been meticulously developed to help you succeed in the
IS 5403 CYBERSECURITY WEEK 5 QUIZZES | QUESTIONS & CORRECT ANSWERS | 2026 UPDATED |
100% CORRECT | TRINE UNIVERSITY. It contains 147 carefully selected questions that reflect the most current
exam content and testing strategies. Each question is accompanied by a correct answer and a detailed rationale
that explains the underlying pathophysiology, pharmacology, or clinical reasoning.
Self-Assessment – Test your knowledge and Exam Preparation – Familiarize yourself with the
identify areas requiring further question format and content
study areas
Concept Reinforcement – Deepen your Confidence Building – Develop test-taking
understanding through strategies and reduce
evidence-based exam anxiety
rationales
Time Management – Practice answering
questions under simulated
exam conditions
Review Summary 147 Questions
Foundations - Application - IS 5403 Cybersecurity WEEK 5 Quizzes & Correct 2026 Updated 100 Correct
Trine University Cybersecurity WEEK 5 Applied Cryptography Access Control AND Secure Network Defense
Undergraduate Upper-level / Graduate IS 5403 Cybersecurity Trine University
All answers with rationales
,Table of Contents
Content Area Questions Key Topics
Security Governance RISK 1-25 Security, Access, Control, Directly, Analyst
Management AND
Compliance
Security Architecture AND 26-50 Security, Access, Directly, Control, Model
Design
Network Security AND 51-75 Security, Analyst, Incident, Response, Addresses
Perimeter Defense
Access Control AND Identity 76-100 Security, Principle, Access, Cannot, Wants
Management
Cryptography AND 101-125 Wants, Access, Control, Principle, Without
Cryptographic Protocols
Threats Vulnerabilities AND 126-147 Directly, Access, Control, Attacker, Company
Attack Vectors
TOTAL 147 All questions include answers and detailed rationales
,Section A - Security Governance RISK Management AND
Compliance
Q1.
An administrator configures a firewall rule that permits inbound TCP/443 from any source
to the public web server, then denies all other inbound traffic. Which security principle
does this rule most directly implement?
A. Implicit deny with explicit allow B. Defense in depth through layered
(default-deny posture) encryption
C. Least privilege applied to user accounts D. Non-repudiation via centralized logging
Correct: A - Implicit deny with explicit allow (default-deny posture)
Rationale:A default-deny firewall posture allows only explicitly permitted traffic and drops
everything else, which is the definition of implicit deny with explicit allow. Least privilege
concerns user permissions, defense in depth involves multiple overlapping controls, and
non-repudiation concerns proof of action-none describe the firewall rule logic.
Why the other answers are wrong:
B. Layered encryption is a confidentiality control, not a traffic-filtering logic rule.
C. Least privilege is an access-control principle for identities, not firewall rule construction.
D. Non-repudiation is achieved through signatures and audit logs, not inbound port filtering.
Reference: NIST SP 800-41 Rev. 1, Guidelines on Firewalls and Firewall Policy, Sec. 2.2.
Q2.
A user logs in with a password plus a code from a hardware token. Which authentication
model does this represent, and what is its primary security benefit?
A. Single-factor authentication; reduces B. Multi-factor authentication; a stolen
help-desk cost password alone is insufficient
C. Federated identity; eliminates the need D. Role-based access control; enforces
for local passwords least privilege
Correct: B - Multi-factor authentication; a stolen password alone is insufficient
Rationale:Combining something you know (password) with something you have (hardware
token) satisfies two distinct authentication factors, so compromise of one factor is insufficient.
Federated identity and RBAC are authorization/identity architectures, not factor combinations.
Why the other answers are wrong:
A. Using two different factor types is by definition multi-factor, not single-factor.
C. Federation concerns trust between identity domains, not the number of factors used locally.
D. RBAC governs authorization (what you can do), not the authentication factors presented.
Page 3
, Section A - Security Governance RISK Management AND Compliance
Reference: NIST SP 800-63B, Digital Identity Guidelines - Authentication and Lifecycle Management, Sec. 4.
Q3.
During a TLS inspection, a browser warns that the server's certificate is valid but issued
by an untrusted root. Which PKI component is most likely misconfigured?
A. The server's cipher suite negotiation B. The certificate trust chain (missing or
order unknown root CA)
C. The session key length used for D. The OCSP stapling response timeout
symmetric encryption
Correct: B - The certificate trust chain (missing or unknown root CA)
Rationale:A warning about an untrusted issuer indicates the client cannot build a chain to a
trusted root CA in its trust store-a trust-chain problem. Cipher suites, key lengths, and OCSP
timeouts do not produce 'untrusted root' errors when the leaf certificate itself is valid.
Why the other answers are wrong:
A. Cipher suite order affects algorithm selection, not certificate trust validation.
C. Key length affects cryptographic strength, not trust anchoring.
D. OCSP stapling affects revocation checking, not root trust establishment.
Reference: RFC 5280, Internet X.509 Public Key Infrastructure Certificate and CRL Profile, Sec. 6.
Q4.
A company assigns permissions based on job function (e.g., 'Accountant', 'HR Specialist')
rather than to individual users. Which access control model is being applied?
A. Discretionary access control (DAC) B. Mandatory access control (MAC)
C. Role-based access control (RBAC) D. Attribute-based access control (ABAC)
Correct: C - Role-based access control (RBAC)
Rationale:RBAC assigns permissions to roles, and users inherit permissions through role
membership, which matches the described job-function model. DAC lets owners set
permissions, MAC relies on labels/clearances, and ABAC evaluates dynamic attributes rather
than static roles.
Why the other answers are wrong:
A. DAC is owner-controlled discretionary permission, not role-based job-function grouping.
B. MAC uses mandatory labels and clearances enforced by the system, not job roles.
D. ABAC evaluates multiple attributes (time, location, device) rather than a single role
assignment.
Reference: NIST RBAC Standard, INCITS 359-2012; Sandhu et al., IEEE Computer, 1996.
Page 4
QUESTIONS & CORRECT ANSWERS | 2026
UPDATED | 100% CORRECT | TRINE UNIVERSITY
147 Questions with Answers and Detailed Rationales
100 PERCENT GUARANTEED PASS
INSTANT DOWNLOAD ANSWERS INCLUDED
IMPORTANCE OF THIS DOCUMENT
This comprehensive examination preparation guide has been meticulously developed to help you succeed in the
IS 5403 CYBERSECURITY WEEK 5 QUIZZES | QUESTIONS & CORRECT ANSWERS | 2026 UPDATED |
100% CORRECT | TRINE UNIVERSITY. It contains 147 carefully selected questions that reflect the most current
exam content and testing strategies. Each question is accompanied by a correct answer and a detailed rationale
that explains the underlying pathophysiology, pharmacology, or clinical reasoning.
Self-Assessment – Test your knowledge and Exam Preparation – Familiarize yourself with the
identify areas requiring further question format and content
study areas
Concept Reinforcement – Deepen your Confidence Building – Develop test-taking
understanding through strategies and reduce
evidence-based exam anxiety
rationales
Time Management – Practice answering
questions under simulated
exam conditions
Review Summary 147 Questions
Foundations - Application - IS 5403 Cybersecurity WEEK 5 Quizzes & Correct 2026 Updated 100 Correct
Trine University Cybersecurity WEEK 5 Applied Cryptography Access Control AND Secure Network Defense
Undergraduate Upper-level / Graduate IS 5403 Cybersecurity Trine University
All answers with rationales
,Table of Contents
Content Area Questions Key Topics
Security Governance RISK 1-25 Security, Access, Control, Directly, Analyst
Management AND
Compliance
Security Architecture AND 26-50 Security, Access, Directly, Control, Model
Design
Network Security AND 51-75 Security, Analyst, Incident, Response, Addresses
Perimeter Defense
Access Control AND Identity 76-100 Security, Principle, Access, Cannot, Wants
Management
Cryptography AND 101-125 Wants, Access, Control, Principle, Without
Cryptographic Protocols
Threats Vulnerabilities AND 126-147 Directly, Access, Control, Attacker, Company
Attack Vectors
TOTAL 147 All questions include answers and detailed rationales
,Section A - Security Governance RISK Management AND
Compliance
Q1.
An administrator configures a firewall rule that permits inbound TCP/443 from any source
to the public web server, then denies all other inbound traffic. Which security principle
does this rule most directly implement?
A. Implicit deny with explicit allow B. Defense in depth through layered
(default-deny posture) encryption
C. Least privilege applied to user accounts D. Non-repudiation via centralized logging
Correct: A - Implicit deny with explicit allow (default-deny posture)
Rationale:A default-deny firewall posture allows only explicitly permitted traffic and drops
everything else, which is the definition of implicit deny with explicit allow. Least privilege
concerns user permissions, defense in depth involves multiple overlapping controls, and
non-repudiation concerns proof of action-none describe the firewall rule logic.
Why the other answers are wrong:
B. Layered encryption is a confidentiality control, not a traffic-filtering logic rule.
C. Least privilege is an access-control principle for identities, not firewall rule construction.
D. Non-repudiation is achieved through signatures and audit logs, not inbound port filtering.
Reference: NIST SP 800-41 Rev. 1, Guidelines on Firewalls and Firewall Policy, Sec. 2.2.
Q2.
A user logs in with a password plus a code from a hardware token. Which authentication
model does this represent, and what is its primary security benefit?
A. Single-factor authentication; reduces B. Multi-factor authentication; a stolen
help-desk cost password alone is insufficient
C. Federated identity; eliminates the need D. Role-based access control; enforces
for local passwords least privilege
Correct: B - Multi-factor authentication; a stolen password alone is insufficient
Rationale:Combining something you know (password) with something you have (hardware
token) satisfies two distinct authentication factors, so compromise of one factor is insufficient.
Federated identity and RBAC are authorization/identity architectures, not factor combinations.
Why the other answers are wrong:
A. Using two different factor types is by definition multi-factor, not single-factor.
C. Federation concerns trust between identity domains, not the number of factors used locally.
D. RBAC governs authorization (what you can do), not the authentication factors presented.
Page 3
, Section A - Security Governance RISK Management AND Compliance
Reference: NIST SP 800-63B, Digital Identity Guidelines - Authentication and Lifecycle Management, Sec. 4.
Q3.
During a TLS inspection, a browser warns that the server's certificate is valid but issued
by an untrusted root. Which PKI component is most likely misconfigured?
A. The server's cipher suite negotiation B. The certificate trust chain (missing or
order unknown root CA)
C. The session key length used for D. The OCSP stapling response timeout
symmetric encryption
Correct: B - The certificate trust chain (missing or unknown root CA)
Rationale:A warning about an untrusted issuer indicates the client cannot build a chain to a
trusted root CA in its trust store-a trust-chain problem. Cipher suites, key lengths, and OCSP
timeouts do not produce 'untrusted root' errors when the leaf certificate itself is valid.
Why the other answers are wrong:
A. Cipher suite order affects algorithm selection, not certificate trust validation.
C. Key length affects cryptographic strength, not trust anchoring.
D. OCSP stapling affects revocation checking, not root trust establishment.
Reference: RFC 5280, Internet X.509 Public Key Infrastructure Certificate and CRL Profile, Sec. 6.
Q4.
A company assigns permissions based on job function (e.g., 'Accountant', 'HR Specialist')
rather than to individual users. Which access control model is being applied?
A. Discretionary access control (DAC) B. Mandatory access control (MAC)
C. Role-based access control (RBAC) D. Attribute-based access control (ABAC)
Correct: C - Role-based access control (RBAC)
Rationale:RBAC assigns permissions to roles, and users inherit permissions through role
membership, which matches the described job-function model. DAC lets owners set
permissions, MAC relies on labels/clearances, and ABAC evaluates dynamic attributes rather
than static roles.
Why the other answers are wrong:
A. DAC is owner-controlled discretionary permission, not role-based job-function grouping.
B. MAC uses mandatory labels and clearances enforced by the system, not job roles.
D. ABAC evaluates multiple attributes (time, location, device) rather than a single role
assignment.
Reference: NIST RBAC Standard, INCITS 359-2012; Sandhu et al., IEEE Computer, 1996.
Page 4