Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 76 pages
Exam (elaborations)

IS 5403 Cybersecurity Week 5 Quizzes Questions & Correct Answers 2026 Updated 100% Correc

Document preview thumbnail
Preview 4 out of 76 pages

This document contains Week 5 quiz questions and correct answers for IS 5403 Cybersecurity. It is presented as an updated 2026 version for students reviewing course material. The listing focuses on quiz-style questions and answers tied to the Week 5 cybersecurity topic within the IS 5403 course.

Content preview

IS 5403 CYBERSECURITY WEEK 5 QUIZZES
QUESTIONS & CORRECT ANSWERS 2026
UPDATED 100% CORRECT TRINE UNIVERSITY
148 QUESTIONS

TABLE OF CONTENTS

# TOPIC

1 Analyze hybrid network architectures and justify segmentation, zero-trust, and monitoring controls against
advanced threats

2 Evaluate cryptographic primitives and protocols for confidentiality, integrity, and authentication trade-offs
in real deployments

3 Design IAM, incident response, and risk-treatment decisions that satisfy regulatory and
business-continuity constraints

4 Interpret quantitative risk, forensic, and log evidence to recommend defensible mitigations

5 IS 5403 Cybersecurity Week 5 Quizzes Questions & Correct Answers 2026 Updated 100% Correct Trine
University

6 Foundations of Cybersecurity - Network Defense, Applied Cryptography, IAM, Incident Response, Risk &
Compliance

7 Applied Cybersecurity - Network Defense, Applied Cryptography, IAM, Incident Response, Risk &
Compliance

8 Advanced Cybersecurity - Network Defense, Applied Cryptography, IAM, Incident Response, Risk &
Compliance

9 Cybersecurity - Network Defense, Applied Cryptography, IAM, Incident Response, Risk & Compliance
Review


ABSTRACT




Page 1

,This study document brings together 148 carefully worded exam questions drawn from IS 5403
Cybersecurity Week 5 Quizzes Questions & Correct Answers 2026 Updated 100% Correct Trine
University, with the strongest emphasis placed on Analyze hybrid network architectures and justify
segmentation, zero-trust, and monitoring controls against advanced threats, Evaluate
cryptographic primitives and protocols for confidentiality, integrity, and authentication trade-offs in
real deployments, Design IAM, incident response and and risk-treatment decisions that satisfy
regulatory and business-continuity constraints. Every item follows the wording style and level of
reasoning you meet in the real paper, and each one is paired with a clear rationale so the correct
choice is never a guess. Work through the set at your own pace, mark the questions that slow you
down, then come back to them until the reasoning feels automatic. Learners who revise this way
walk into the exam room recognising the pattern behind the questions instead of meeting them for
the first time. Keep going - steady, honest practice is what turns a difficult paper into a comfortable
pass.




Q1 ANALYZE HYBRID NETWORK ARCHITECTURES AND JUSTIFY SEGMENTATION,
ZERO-TRUST, AND MONITORING CONTROLS AGAINST ADVANCED THREATS
A hospital must expose an infusion-pump management API to a third-party
vendor. Which control set best enforces least privilege at the API layer while
preserving availability during a pump-firmware emergency?
A. Mutual TLS with short-lived client certificates, per-endpoint scopes, and a break-glass role
that is time-boxed and fully audited CORRECT

B. Static API keys rotated quarterly, IP allowlisting, and a shared service account with read/write
access

C. OAuth 2.0 implicit flow with long-lived bearer tokens and CORS wildcard to simplify vendor
onboarding

D. Network ACLs restricting vendor source ranges, plus basic authentication over TLS with a
single admin credential

RATIONALE: A combines strong workload identity (mTLS + short-lived certs), fine-grained
authorization (scopes), and an auditable emergency path, which satisfies least privilege and
availability. B and D use shared/static credentials that violate non-repudiation and least privilege;
C's implicit flow and long-lived tokens are deprecated and unsafe for machine-to-machine
access.




Page 2

,Q2 ANALYZE HYBRID NETWORK ARCHITECTURES AND JUSTIFY SEGMENTATION,
ZERO-TRUST, AND MONITORING CONTROLS AGAINST ADVANCED THREATS
A SOC observes repeated 200 OK responses from an internal API to requests
containing encoded SQL metacharacters, but no database errors. Which
interpretation is most defensible?
A. The WAF is blocking the payloads and the 200s are benign retries

B. The application may be vulnerable to blind SQL injection and responses should be correlated
with DB query latency and outbound DNS CORRECT

C. The 200 status proves parameterized queries are in use and the alerts are false positives

D. The traffic is encrypted, so payload inspection is impossible and the alerts should be closed

RATIONALE: Blind SQLi often returns normal HTTP status while leaking data through timing or
out-of-band channels, so latency and DNS correlation are the correct next evidence. A assumes
WAF efficacy without proof; C mistakes a status code for proof of safe coding; D is false because
TLS termination at the WAF/load balancer permits inspection.




Q3 ANALYZE HYBRID NETWORK ARCHITECTURES AND JUSTIFY SEGMENTATION,
ZERO-TRUST, AND MONITORING CONTROLS AGAINST ADVANCED THREATS
An organization stores 10 million records. A breach of 2% of records is estimated
to cost $180 per record in notification, credit monitoring, and legal fees. What is
the single-loss expectancy (SLE) for this scenario?
A. $36,000,000

B. $3,600,000 CORRECT

C. $360,000

D. $180,000,000

RATIONALE: SLE = asset value at risk × exposure factor = (10,000,000 × $180) × 0.02 = $1.8B ×
0.02 = $3,600,000. A omits the exposure factor, C misplaces a decimal, and D applies the
per-record cost to all records without the 2% factor.




Page 3

, Q4 ANALYZE HYBRID NETWORK ARCHITECTURES AND JUSTIFY SEGMENTATION,
ZERO-TRUST, AND MONITORING CONTROLS AGAINST ADVANCED THREATS
Which statement correctly distinguishes the security properties provided by
AES-GCM versus RSA-OAEP in a hybrid encryption scheme?
A. AES-GCM provides confidentiality and integrity for bulk data; RSA-OAEP securely transports
the symmetric key but provides no bulk-data integrity CORRECT

B. AES-GCM provides key transport; RSA-OAEP provides authenticated bulk encryption

C. Both provide digital signatures; AES-GCM is simply faster for large messages

D. AES-GCM is asymmetric and RSA-OAEP is symmetric, so they are interchangeable for key
wrapping

RATIONALE: In hybrid encryption, AES-GCM is the AEAD bulk cipher (confidentiality +
integrity/authenticity), while RSA-OAEP is used to encrypt the symmetric key and does not itself
authenticate the message payload. B reverses roles, C confuses encryption with signatures, and
D misstates the symmetric/asymmetric classification.




Q5 ANALYZE HYBRID NETWORK ARCHITECTURES AND JUSTIFY SEGMENTATION,
ZERO-TRUST, AND MONITORING CONTROLS AGAINST ADVANCED THREATS
A zero-trust program replaces VPN with per-application access. Which metric best
demonstrates the program is reducing lateral-movement risk rather than merely
shifting access?
A. Number of VPN sessions replaced by identity-aware proxy sessions

B. Mean time to detect east-west traffic anomalies and the count of successful peer-to-peer
authentications between workloads CORRECT

C. Percentage of employees enrolled in phishing-resistant MFA

D. Total blocked inbound connections at the perimeter firewall

RATIONALE: Lateral-movement risk is evidenced by east-west visibility and
workload-to-workload authentication behavior, which B measures directly. A counts migration
activity, C measures credential hygiene, and D reflects north-south perimeter filtering-none prove
reduced internal reachability.




Page 4

Document information

Uploaded on
September 18, 2026
Number of pages
76
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$28.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
PremiumExamBank
4.8
(1060)
Sold
466
Followers
74
Items
7109
Last sold
1 day ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions