IS 5403 CYBERSECURITY WEEK 6 QUIZZES |
QUESTIONS & CORRECT ANSWERS | 2026
UPDATED | 100% CORRECT | TRINE UNIVERSITY
150 Questions with Answers and Detailed Rationales
100 PERCENT GUARANTEED PASS
INSTANT DOWNLOAD ANSWERS INCLUDED
IMPORTANCE OF THIS DOCUMENT
This comprehensive examination preparation guide has been meticulously developed to help you succeed in the
IS 5403 CYBERSECURITY WEEK 6 QUIZZES | QUESTIONS & CORRECT ANSWERS | 2026 UPDATED |
100% CORRECT | TRINE UNIVERSITY. It contains 150 carefully selected questions that reflect the most current
exam content and testing strategies. Each question is accompanied by a correct answer and a detailed rationale
that explains the underlying pathophysiology, pharmacology, or clinical reasoning.
Self-Assessment – Test your knowledge and Exam Preparation – Familiarize yourself with the
identify areas requiring further question format and content
study areas
Concept Reinforcement – Deepen your Confidence Building – Develop test-taking
understanding through strategies and reduce
evidence-based exam anxiety
rationales
Time Management – Practice answering
questions under simulated
exam conditions
Review Summary 150 Questions
Foundations - Application - IS 5403 Cybersecurity WEEK 6 Quizzes & Correct 2026 Updated 100 Correct
Trine University Cybersecurity WEEK 6 Malware Network Attacks AND Defensive Controls
Undergraduate/graduate IS 5403 Cybersecurity Trine University
All answers with rationales
,Table of Contents
Content Area Questions Key Topics
Security Governance AND 1-25 Directly, Attack, Control, Network, Describes
Policy
RISK Management AND 26-50 Access, Security, Control, Organization, Directly
Assessment
Security Architecture AND 51-75 Certificate, Security, Cryptographic, Directly, Digital
Design
Access Control AND Identity 76-100 Control, Security, Wants, Access, Addresses
Management
Cryptography AND 101-125 Security, Wants, Authentication, Certificate, Directly
Encryption
Network Security AND 126-150 Security, Access, Control, Network, Analyst
Perimeter Defense
TOTAL 150 All questions include answers and detailed rationales
,Section A - Security Governance AND Policy
Q1.
A user receives an email attachment that, when opened, encrypts all files and demands
payment. The file also copies itself to network shares. Which malware classification best
describes this?
A. Trojan horse B. Worm
C. Ransomware D. Rootkit
Correct: C - Ransomware
Rationale:Ransomware encrypts files and demands payment; self-propagation to network
shares indicates worm-like behavior, but the primary payload is ransomware. A Trojan relies
on user execution but does not typically self-replicate. A worm spreads automatically but does
not encrypt files. A rootkit hides presence but does not encrypt.
Why the other answers are wrong:
A. A Trojan disguises itself as legitimate software but does not inherently encrypt files or
self-propagate.
B. A worm self-propagates but does not encrypt files for ransom.
D. A rootkit conceals other malware but does not directly encrypt files or demand payment.
Reference: Stallings, W. (2023). Computer Security: Principles and Practice, 5th Ed., Ch. 6
Q2.
Which TCP/IP layer is most directly targeted by a SYN flood attack?
A. Application layer B. Transport layer
C. Network layer D. Data link layer
Correct: B - Transport layer
Rationale:SYN floods exploit the TCP three-way handshake at the transport layer by sending
many SYN packets without completing the handshake. Application-layer attacks target
HTTP/DNS, network-layer attacks target IP, and data-link attacks target MAC/ARP.
Why the other answers are wrong:
A. Application-layer attacks target protocols like HTTP, not the TCP handshake.
C. Network-layer attacks target IP routing, not TCP connection state.
D. Data-link attacks target MAC addresses or ARP, not TCP SYN packets.
Reference: NIST SP 800-61 Rev. 2, Computer Security Incident Handling Guide
Page 3
, Section A - Security Governance AND Policy
Q3.
In symmetric encryption, which key distribution challenge is addressed by using a key
encapsulation mechanism (KEM) in TLS 1.3?
A. Ensuring forward secrecy B. Authenticating the server
C. Securely exchanging the symmetric D. Preventing replay attacks
session key
Correct: C - Securely exchanging the symmetric session key
Rationale:TLS 1.3 uses KEM (e.g., ephemeral Diffie-Hellman) to securely establish a shared
symmetric key without transmitting it directly. Forward secrecy is a property, not the primary
challenge addressed. Server authentication uses certificates. Replay protection uses nonces.
Why the other answers are wrong:
A. Forward secrecy is a benefit of ephemeral keys, not the key distribution challenge itself.
B. Server authentication is handled by digital certificates, not KEM.
D. Replay attacks are mitigated by sequence numbers and nonces, not KEM.
Reference: RFC 8446, The Transport Layer Security (TLS) Protocol Version 1.3
Q4.
Which authentication factor is most resistant to phishing attacks?
A. Password B. SMS-based one-time code
C. FIDO2 security key D. Security questions
Correct: C - FIDO2 security key
Rationale:FIDO2 security keys use public-key cryptography bound to the origin, preventing
phishing by design. Passwords, SMS codes, and security questions can be captured via
phishing or social engineering.
Why the other answers are wrong:
A. Passwords can be stolen through phishing pages.
B. SMS codes can be intercepted or relayed in real time by attackers.
D. Security questions are often guessable or obtainable via social media.
Reference: NIST SP 800-63B, Digital Identity Guidelines
Q5.
A company wants to detect unauthorized changes to critical system files. Which security
control is most appropriate?
A. File integrity monitoring (FIM) B. Intrusion prevention system (IPS)
Page 4
QUESTIONS & CORRECT ANSWERS | 2026
UPDATED | 100% CORRECT | TRINE UNIVERSITY
150 Questions with Answers and Detailed Rationales
100 PERCENT GUARANTEED PASS
INSTANT DOWNLOAD ANSWERS INCLUDED
IMPORTANCE OF THIS DOCUMENT
This comprehensive examination preparation guide has been meticulously developed to help you succeed in the
IS 5403 CYBERSECURITY WEEK 6 QUIZZES | QUESTIONS & CORRECT ANSWERS | 2026 UPDATED |
100% CORRECT | TRINE UNIVERSITY. It contains 150 carefully selected questions that reflect the most current
exam content and testing strategies. Each question is accompanied by a correct answer and a detailed rationale
that explains the underlying pathophysiology, pharmacology, or clinical reasoning.
Self-Assessment – Test your knowledge and Exam Preparation – Familiarize yourself with the
identify areas requiring further question format and content
study areas
Concept Reinforcement – Deepen your Confidence Building – Develop test-taking
understanding through strategies and reduce
evidence-based exam anxiety
rationales
Time Management – Practice answering
questions under simulated
exam conditions
Review Summary 150 Questions
Foundations - Application - IS 5403 Cybersecurity WEEK 6 Quizzes & Correct 2026 Updated 100 Correct
Trine University Cybersecurity WEEK 6 Malware Network Attacks AND Defensive Controls
Undergraduate/graduate IS 5403 Cybersecurity Trine University
All answers with rationales
,Table of Contents
Content Area Questions Key Topics
Security Governance AND 1-25 Directly, Attack, Control, Network, Describes
Policy
RISK Management AND 26-50 Access, Security, Control, Organization, Directly
Assessment
Security Architecture AND 51-75 Certificate, Security, Cryptographic, Directly, Digital
Design
Access Control AND Identity 76-100 Control, Security, Wants, Access, Addresses
Management
Cryptography AND 101-125 Security, Wants, Authentication, Certificate, Directly
Encryption
Network Security AND 126-150 Security, Access, Control, Network, Analyst
Perimeter Defense
TOTAL 150 All questions include answers and detailed rationales
,Section A - Security Governance AND Policy
Q1.
A user receives an email attachment that, when opened, encrypts all files and demands
payment. The file also copies itself to network shares. Which malware classification best
describes this?
A. Trojan horse B. Worm
C. Ransomware D. Rootkit
Correct: C - Ransomware
Rationale:Ransomware encrypts files and demands payment; self-propagation to network
shares indicates worm-like behavior, but the primary payload is ransomware. A Trojan relies
on user execution but does not typically self-replicate. A worm spreads automatically but does
not encrypt files. A rootkit hides presence but does not encrypt.
Why the other answers are wrong:
A. A Trojan disguises itself as legitimate software but does not inherently encrypt files or
self-propagate.
B. A worm self-propagates but does not encrypt files for ransom.
D. A rootkit conceals other malware but does not directly encrypt files or demand payment.
Reference: Stallings, W. (2023). Computer Security: Principles and Practice, 5th Ed., Ch. 6
Q2.
Which TCP/IP layer is most directly targeted by a SYN flood attack?
A. Application layer B. Transport layer
C. Network layer D. Data link layer
Correct: B - Transport layer
Rationale:SYN floods exploit the TCP three-way handshake at the transport layer by sending
many SYN packets without completing the handshake. Application-layer attacks target
HTTP/DNS, network-layer attacks target IP, and data-link attacks target MAC/ARP.
Why the other answers are wrong:
A. Application-layer attacks target protocols like HTTP, not the TCP handshake.
C. Network-layer attacks target IP routing, not TCP connection state.
D. Data-link attacks target MAC addresses or ARP, not TCP SYN packets.
Reference: NIST SP 800-61 Rev. 2, Computer Security Incident Handling Guide
Page 3
, Section A - Security Governance AND Policy
Q3.
In symmetric encryption, which key distribution challenge is addressed by using a key
encapsulation mechanism (KEM) in TLS 1.3?
A. Ensuring forward secrecy B. Authenticating the server
C. Securely exchanging the symmetric D. Preventing replay attacks
session key
Correct: C - Securely exchanging the symmetric session key
Rationale:TLS 1.3 uses KEM (e.g., ephemeral Diffie-Hellman) to securely establish a shared
symmetric key without transmitting it directly. Forward secrecy is a property, not the primary
challenge addressed. Server authentication uses certificates. Replay protection uses nonces.
Why the other answers are wrong:
A. Forward secrecy is a benefit of ephemeral keys, not the key distribution challenge itself.
B. Server authentication is handled by digital certificates, not KEM.
D. Replay attacks are mitigated by sequence numbers and nonces, not KEM.
Reference: RFC 8446, The Transport Layer Security (TLS) Protocol Version 1.3
Q4.
Which authentication factor is most resistant to phishing attacks?
A. Password B. SMS-based one-time code
C. FIDO2 security key D. Security questions
Correct: C - FIDO2 security key
Rationale:FIDO2 security keys use public-key cryptography bound to the origin, preventing
phishing by design. Passwords, SMS codes, and security questions can be captured via
phishing or social engineering.
Why the other answers are wrong:
A. Passwords can be stolen through phishing pages.
B. SMS codes can be intercepted or relayed in real time by attackers.
D. Security questions are often guessable or obtainable via social media.
Reference: NIST SP 800-63B, Digital Identity Guidelines
Q5.
A company wants to detect unauthorized changes to critical system files. Which security
control is most appropriate?
A. File integrity monitoring (FIM) B. Intrusion prevention system (IPS)
Page 4