• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 4 out of 75 pages
Exam (elaborations)

IS 5403 Cybersecurity Week 3 Quizzes | Questions & Correct Answers | 2026 Updated | 100% Correct | Trine University | A+ Guide

Document preview thumbnail
Preview 4 out of 75 pages

IS 5403 Cybersecurity Week 3 Quizzes | Questions & Correct Answers | 2026 Updated | 100% Correct | Trine University | A+ Guide

Content preview

IS 5403 CYBERSECURITY WEEK 3 QUIZZES |
QUESTIONS & CORRECT ANSWERS | 2026
UPDATED | 100% CORRECT | TRINE UNIVERSITY
147 Questions with Answers and Detailed Rationales


100 PERCENT GUARANTEED PASS


INSTANT DOWNLOAD ANSWERS INCLUDED



IMPORTANCE OF THIS DOCUMENT
This comprehensive examination preparation guide has been meticulously developed to help you succeed in the
IS 5403 CYBERSECURITY WEEK 3 QUIZZES | QUESTIONS & CORRECT ANSWERS | 2026 UPDATED |
100% CORRECT | TRINE UNIVERSITY. It contains 147 carefully selected questions that reflect the most current
exam content and testing strategies. Each question is accompanied by a correct answer and a detailed rationale
that explains the underlying pathophysiology, pharmacology, or clinical reasoning.

Self-Assessment – Test your knowledge and Exam Preparation – Familiarize yourself with the
identify areas requiring further question format and content
study areas

Concept Reinforcement – Deepen your Confidence Building – Develop test-taking
understanding through strategies and reduce
evidence-based exam anxiety
rationales
Time Management – Practice answering
questions under simulated
exam conditions




Review Summary 147 Questions


Foundations - Application - IS 5403 Cybersecurity WEEK 3 Quizzes & Correct 2026 Updated 100 Correct
Trine University Cybersecurity Undergraduate YEAR 3
All answers with rationales

,Table of Contents

Content Area Questions Key Topics

Introduction TO 1-25 Security, Directly, Access, Control, Network
Cybersecurity AND Security
Mindset

Threat Actors Attack Vectors 26-50 Analyst, Security, Password, Company, Access
AND Social Engineering

Cryptography Fundamentals 51-75 Security, Access, Control, Primary, Directly
AND Encryption

Authentication Authorization 76-100 Access, University, Control, Security, Organization
AND Access Control

Network Security AND 101-125 Security, Control, Attack, Firewall, Describes
Perimeter Defense

Security Policies RISK 126-147 Security, Access, Analyst, Stored, Control
Management AND
Compliance

TOTAL 147 All questions include answers and detailed rationales

,Section A - Introduction TO Cybersecurity AND Security
Mindset

Q1.
A security team implements AES-256 in Galois/Counter Mode (GCM) for encrypting
database records. Which property does GCM provide that CBC mode does not inherently
offer?


A. Confidentiality only B. Integrity and authenticity

C. Key exchange D. Non-repudiation
Correct: B - Integrity and authenticity


Rationale:GCM is an authenticated encryption mode that provides both confidentiality and
integrity/authenticity via a universal hash, while CBC only provides confidentiality and requires
a separate MAC for integrity.
Why the other answers are wrong:
A. CBC also provides confidentiality, so this is not unique to GCM.
C. Key exchange is handled by protocols like Diffie-Hellman, not by the block cipher mode.
D. Non-repudiation requires digital signatures, not symmetric encryption modes.
Reference: Stallings, W. (2023). Cryptography and Network Security, 8th Ed., Ch. 6


Q2.
In a Role-Based Access Control (RBAC) system, a user is assigned to the 'HR Specialist'
role. Which principle does this assignment directly support?


A. Least privilege B. Separation of duties

C. Mandatory access control D. Discretionary access control
Correct: A - Least privilege


Rationale:RBAC assigns permissions based on roles, which enforces least privilege by giving
users only the access needed for their role. Separation of duties is a related but distinct
concept involving conflict of interest constraints.
Why the other answers are wrong:
B. Separation of duties focuses on preventing fraud by dividing tasks, not on role assignment
itself.
C. Mandatory access control uses labels and clearances, not roles.
D. Discretionary access control lets owners set permissions, not centralized role assignment.
Reference: NIST SP 800-53 Rev. 5, AC-2, AC-3




Page 3

, Section A - Introduction TO Cybersecurity AND Security Mindset


Q3.
A company's web server is configured to allow only HTTPS traffic on port 443. Which
security principle does this configuration best illustrate?


A. Defense in depth B. Attack surface reduction

C. Zero trust D. Security through obscurity
Correct: B - Attack surface reduction


Rationale:Limiting open ports reduces the attack surface by disabling unnecessary services.
Defense in depth involves multiple layers, zero trust assumes no implicit trust, and security
through obscurity relies on secrecy of design.
Why the other answers are wrong:
A. Defense in depth would include multiple controls, not just port filtering.
C. Zero trust focuses on continuous verification, not just port configuration.
D. Security through obscurity is hiding information, not reducing exposed services.
Reference: OWASP Top 10 (2021), A05: Security Misconfiguration


Q4.
During a risk assessment, a team calculates the Annualized Loss Expectancy (ALE) for a
threat. Which formula correctly represents ALE?


A. ALE = Single Loss Expectancy (SLE) × B. ALE = SLE + ARO
Annualized Rate of Occurrence (ARO)

C. ALE = SLE / ARO D. ALE = ARO / SLE
Correct: A - ALE = Single Loss Expectancy (SLE) × Annualized Rate of Occurrence (ARO)


Rationale:ALE is computed by multiplying the monetary loss from a single event (SLE) by the
expected frequency of the event per year (ARO). This quantifies annual risk exposure.
Why the other answers are wrong:
B. Addition does not account for frequency of occurrence.
C. Division would yield a per-occurrence metric, not annualized.
D. Inverting the ratio would produce a meaningless value.
Reference: NIST SP 800-30 Rev. 1, Risk Assessment Guide


Q5.
Which of the following best describes the primary function of a demilitarized zone (DMZ)
in network architecture?


A. To provide a secure area for internal B. To isolate public-facing services from the
databases internal network




Page 4

Document information

Uploaded on
September 25, 2026
Number of pages
75
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$27.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
ProfReginaBank
4.7
(3)
Sold
21
Followers
2
Items
1735
Last sold
1 day ago




Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions