SEC-450 Firewalls and Network Security
Weekly Quizzes Weeks 1–7 | Complete
Multiple-Choice Question Bank | 100%
Correct | 2026 GRADED A+ |INSTANT
DOWNLOAD
Question 1
Are there any reasons not to take an extreme view of security if that view
errs on the side of caution?
A. No, there is no reason not to take such an extreme view
B. Yes, that can lead to wasting on threats that are not likely
C. Yes, if you're going to err, assume there are few if any realistic threats
D. Yes, that can require that you increase your security skills in order to
implement more rigorous defenses
Answer: B — Taking an extreme view can lead to wasting resources on
threats that are unlikely to materialize .
Question 2
Which of the following best describes the principle of least privilege?
A. Develop a patch only after the exploit has been discovered and
publicized
B. Allow the user to access items only during their normal scheduled work
hours
C. Allow the user to have access to only the items on their payment plan
D. Allow the user access to only what is essential for their job
responsibilities
,Answer: D — Users should only have permissions necessary for their
specific job functions .
Question 3
Which of the following best describes the concept of risk?
A. The unsecured content on a network that may be used to gain access to
the network
B. The surface that is exposed when a network is live that hackers can use
for access
C. The likelihood that a threat will take advantage of vulnerability on the
network
D. The solution that incorporates the best solution for a particular network
Answer: C — Risk is the probability that a threat will exploit a vulnerability .
Question 4
What is the first stage or step in the hacking process?
A. Penetration
B. Reconnaissance
C. Scanning
D. Enumeration
Answer: B — Reconnaissance is the initial information-gathering phase .
Question 5
Which attack uses nontechnical means to achieve results?
A. Man-in-the-middle
B. SQL injection
C. Replay
,D. Social engineering
Answer: D — Social engineering exploits human psychology rather than
technical vulnerabilities .
Question 6
Which of the following best describes the concept of nonrepudiation?
A. It ensures that malicious code is not rampant on a corporate network
B. It is proof of a user's identity prior to granting access to a secured area
C. It prevents a user from being able to deny having performed an action
D. It controls what users are allowed to do and not allowed to do
Answer: C — Nonrepudiation provides proof that a user performed a
specific action .
Question 7
What type of threat are there no current defenses?
A. Unauthorized software
B. Malicious code
C. Zero-day
D. Hardware failure
Answer: C — Zero-day exploits target unknown vulnerabilities with no
existing patch .
Question 8
Most exploits are based on the existence of which of the following?
A. Bandwidth speed
B. Filtering protocols
C. Human beings
, D. System anomalies
Answer: C — Human error and behavior are the most common exploit
vectors .
Question 9
Which form of an attack captures authentication packets to retransmit them
later?
A. Replay
B. Hijacking
C. Insertion
D. Interruption
Answer: A — Replay attacks capture and retransmit valid data
transmissions .
Question 10
Which form of attack submits excessive amounts of data to a target to
cause arbitrary code execution?
A. Fragmentation
B. Buffer overflow
C. DoS
D. Spoofing
Answer: B — Buffer overflow attacks overwhelm memory buffers to
execute malicious code .
Question 11
Which attack is based on the impersonation of a legitimate host?
A. DoS
Weekly Quizzes Weeks 1–7 | Complete
Multiple-Choice Question Bank | 100%
Correct | 2026 GRADED A+ |INSTANT
DOWNLOAD
Question 1
Are there any reasons not to take an extreme view of security if that view
errs on the side of caution?
A. No, there is no reason not to take such an extreme view
B. Yes, that can lead to wasting on threats that are not likely
C. Yes, if you're going to err, assume there are few if any realistic threats
D. Yes, that can require that you increase your security skills in order to
implement more rigorous defenses
Answer: B — Taking an extreme view can lead to wasting resources on
threats that are unlikely to materialize .
Question 2
Which of the following best describes the principle of least privilege?
A. Develop a patch only after the exploit has been discovered and
publicized
B. Allow the user to access items only during their normal scheduled work
hours
C. Allow the user to have access to only the items on their payment plan
D. Allow the user access to only what is essential for their job
responsibilities
,Answer: D — Users should only have permissions necessary for their
specific job functions .
Question 3
Which of the following best describes the concept of risk?
A. The unsecured content on a network that may be used to gain access to
the network
B. The surface that is exposed when a network is live that hackers can use
for access
C. The likelihood that a threat will take advantage of vulnerability on the
network
D. The solution that incorporates the best solution for a particular network
Answer: C — Risk is the probability that a threat will exploit a vulnerability .
Question 4
What is the first stage or step in the hacking process?
A. Penetration
B. Reconnaissance
C. Scanning
D. Enumeration
Answer: B — Reconnaissance is the initial information-gathering phase .
Question 5
Which attack uses nontechnical means to achieve results?
A. Man-in-the-middle
B. SQL injection
C. Replay
,D. Social engineering
Answer: D — Social engineering exploits human psychology rather than
technical vulnerabilities .
Question 6
Which of the following best describes the concept of nonrepudiation?
A. It ensures that malicious code is not rampant on a corporate network
B. It is proof of a user's identity prior to granting access to a secured area
C. It prevents a user from being able to deny having performed an action
D. It controls what users are allowed to do and not allowed to do
Answer: C — Nonrepudiation provides proof that a user performed a
specific action .
Question 7
What type of threat are there no current defenses?
A. Unauthorized software
B. Malicious code
C. Zero-day
D. Hardware failure
Answer: C — Zero-day exploits target unknown vulnerabilities with no
existing patch .
Question 8
Most exploits are based on the existence of which of the following?
A. Bandwidth speed
B. Filtering protocols
C. Human beings
, D. System anomalies
Answer: C — Human error and behavior are the most common exploit
vectors .
Question 9
Which form of an attack captures authentication packets to retransmit them
later?
A. Replay
B. Hijacking
C. Insertion
D. Interruption
Answer: A — Replay attacks capture and retransmit valid data
transmissions .
Question 10
Which form of attack submits excessive amounts of data to a target to
cause arbitrary code execution?
A. Fragmentation
B. Buffer overflow
C. DoS
D. Spoofing
Answer: B — Buffer overflow attacks overwhelm memory buffers to
execute malicious code .
Question 11
Which attack is based on the impersonation of a legitimate host?
A. DoS