Michigan IT Security Specialist Exam
Practice Questions And Correct Answers
(Verified Answers) Plus Rationale 2026
Q&A| Instant Download Pdf
1. Which of the following is the primary goal of information security?
A. Maintain high throughput
B. Protect confidentiality, integrity, and availability
C. Reduce hardware costs
D. Increase market share
The CIA triad — confidentiality, integrity, and availability —
represents the foundational objectives in information security.
2. What does encryption primarily provide?
A. Faster data access
B. Data confidentiality
C. Easier data indexing
D. System performance optimization
Encryption transforms data into unreadable form to ensure secrecy
and prevent unauthorized access.
3. A firewall operates primarily at which layer of the OSI model?
A. Presentation
B. Session
C. Network
D. Application
Most firewalls examine and control traffic at the network layer,
enforcing rules on IP addresses and ports.
4. Which of the following is a symmetric encryption algorithm?
A. RSA
B. ECC
C. AES
, D. DSA
AES uses the same key for encryption and decryption, characteristic
of symmetric cryptography.
5. What type of attack attempts to overwhelm a service with massive
traffic?
A. Phishing
B. Denial of Service (DoS)
C. SQL Injection
D. Keylogging
A DoS attack floods a system with traffic, making it unavailable to
legitimate users.
6. Which security principle dictates that users should have only the
access necessary to perform their jobs?
A. Least Tolerance
B. Full Privilege
C. Least Privilege
D. Maximum Exposure
Least privilege restricts users to the minimal access needed to reduce
risk.
7. What does multi-factor authentication (MFA) combine?
A. Username and password only
B. Password and IP address
C. Two or more authentication factors
D. Hardware inventory and software licenses
MFA requires multiple distinct authentication types such as
something you know and something you have.
8. A zero-day vulnerability refers to:
A. A patch released on the same day
B. A virus that deletes files
C. An unknown flaw exploited before a fix exists
D. A scheduled backup error
Zero-day indicates a previously unknown security flaw actively
exploited before remediation is available.
9. What type of malware disguises itself as legitimate software?
A. Worm
, B. Rootkit
C. Ransomware
D. Trojan horse
Trojan malware appears benign but contains harmful payloads.
10. Which protocol is used for secure web traffic?
A. HTTP
B. FTP
C. Telnet
D. HTTPS
HTTPS encrypts web traffic using TLS/SSL to protect data in transit.
11. What is the purpose of a DMZ in network architecture?
A. Increase internal traffic
B. Eliminate firewalls
C. Remove IDS sensors
D. Isolate public-facing systems
A Demilitarized Zone separates external-facing services from internal
networks to reduce exposure.
12. Which device detects unauthorized activity and alerts security
personnel?
A. Router
B. Firewall
C. Intrusion Detection System (IDS)
D. Load Balancer
IDS monitors traffic patterns and logs potential security events.
13. Social engineering attacks primarily exploit:
A. Hardware defects
B. Software bugs
C. Human psychology
D. Physical security controls
Social engineering preys on human trust to bypass security.
14. Strong passwords should include:
A. Only letters
B. Only numbers
C. Only special characters
Practice Questions And Correct Answers
(Verified Answers) Plus Rationale 2026
Q&A| Instant Download Pdf
1. Which of the following is the primary goal of information security?
A. Maintain high throughput
B. Protect confidentiality, integrity, and availability
C. Reduce hardware costs
D. Increase market share
The CIA triad — confidentiality, integrity, and availability —
represents the foundational objectives in information security.
2. What does encryption primarily provide?
A. Faster data access
B. Data confidentiality
C. Easier data indexing
D. System performance optimization
Encryption transforms data into unreadable form to ensure secrecy
and prevent unauthorized access.
3. A firewall operates primarily at which layer of the OSI model?
A. Presentation
B. Session
C. Network
D. Application
Most firewalls examine and control traffic at the network layer,
enforcing rules on IP addresses and ports.
4. Which of the following is a symmetric encryption algorithm?
A. RSA
B. ECC
C. AES
, D. DSA
AES uses the same key for encryption and decryption, characteristic
of symmetric cryptography.
5. What type of attack attempts to overwhelm a service with massive
traffic?
A. Phishing
B. Denial of Service (DoS)
C. SQL Injection
D. Keylogging
A DoS attack floods a system with traffic, making it unavailable to
legitimate users.
6. Which security principle dictates that users should have only the
access necessary to perform their jobs?
A. Least Tolerance
B. Full Privilege
C. Least Privilege
D. Maximum Exposure
Least privilege restricts users to the minimal access needed to reduce
risk.
7. What does multi-factor authentication (MFA) combine?
A. Username and password only
B. Password and IP address
C. Two or more authentication factors
D. Hardware inventory and software licenses
MFA requires multiple distinct authentication types such as
something you know and something you have.
8. A zero-day vulnerability refers to:
A. A patch released on the same day
B. A virus that deletes files
C. An unknown flaw exploited before a fix exists
D. A scheduled backup error
Zero-day indicates a previously unknown security flaw actively
exploited before remediation is available.
9. What type of malware disguises itself as legitimate software?
A. Worm
, B. Rootkit
C. Ransomware
D. Trojan horse
Trojan malware appears benign but contains harmful payloads.
10. Which protocol is used for secure web traffic?
A. HTTP
B. FTP
C. Telnet
D. HTTPS
HTTPS encrypts web traffic using TLS/SSL to protect data in transit.
11. What is the purpose of a DMZ in network architecture?
A. Increase internal traffic
B. Eliminate firewalls
C. Remove IDS sensors
D. Isolate public-facing systems
A Demilitarized Zone separates external-facing services from internal
networks to reduce exposure.
12. Which device detects unauthorized activity and alerts security
personnel?
A. Router
B. Firewall
C. Intrusion Detection System (IDS)
D. Load Balancer
IDS monitors traffic patterns and logs potential security events.
13. Social engineering attacks primarily exploit:
A. Hardware defects
B. Software bugs
C. Human psychology
D. Physical security controls
Social engineering preys on human trust to bypass security.
14. Strong passwords should include:
A. Only letters
B. Only numbers
C. Only special characters