IS 5403 CYBERSECURITY WEEK 3 QUIZZES |
QUESTIONS & CORRECT ANSWERS | 2026
UPDATED | 100% CORRECT | TRINE UNIVERSITY
147 Questions with Answers and Detailed Rationales
100 PERCENT GUARANTEED PASS
INSTANT DOWNLOAD ANSWERS INCLUDED
IMPORTANCE OF THIS DOCUMENT
This comprehensive examination preparation guide has been meticulously developed to help you succeed in the
IS 5403 CYBERSECURITY WEEK 3 QUIZZES | QUESTIONS & CORRECT ANSWERS | 2026 UPDATED |
100% CORRECT | TRINE UNIVERSITY. It contains 147 carefully selected questions that reflect the most current
exam content and testing strategies. Each question is accompanied by a correct answer and a detailed rationale
that explains the underlying pathophysiology, pharmacology, or clinical reasoning.
Self-Assessment – Test your knowledge and Exam Preparation – Familiarize yourself with the
identify areas requiring further question format and content
study areas
Concept Reinforcement – Deepen your Confidence Building – Develop test-taking
understanding through strategies and reduce
evidence-based exam anxiety
rationales
Time Management – Practice answering
questions under simulated
exam conditions
Review Summary 147 Questions
Foundations - Application - IS 5403 Cybersecurity WEEK 3 Quizzes & Correct 2026 Updated 100 Correct
Trine University Cybersecurity Undergraduate YEAR 3
All answers with rationales
,Table of Contents
Content Area Questions Key Topics
Introduction TO 1-25 Security, Directly, Access, Control, Network
Cybersecurity AND Security
Mindset
Threat Actors Attack Vectors 26-50 Analyst, Security, Password, Company, Access
AND Social Engineering
Cryptography Fundamentals 51-75 Security, Access, Control, Primary, Directly
AND Encryption
Authentication Authorization 76-100 Access, University, Control, Security, Organization
AND Access Control
Network Security AND 101-125 Security, Control, Attack, Firewall, Describes
Perimeter Defense
Security Policies RISK 126-147 Security, Access, Analyst, Stored, Control
Management AND
Compliance
TOTAL 147 All questions include answers and detailed rationales
,Section A - Introduction TO Cybersecurity AND Security
Mindset
Q1.
A security team implements AES-256 in Galois/Counter Mode (GCM) for encrypting
database records. Which property does GCM provide that CBC mode does not inherently
offer?
A. Confidentiality only B. Integrity and authenticity
C. Key exchange D. Non-repudiation
Correct: B - Integrity and authenticity
Rationale:GCM is an authenticated encryption mode that provides both confidentiality and
integrity/authenticity via a universal hash, while CBC only provides confidentiality and requires
a separate MAC for integrity.
Why the other answers are wrong:
A. CBC also provides confidentiality, so this is not unique to GCM.
C. Key exchange is handled by protocols like Diffie-Hellman, not by the block cipher mode.
D. Non-repudiation requires digital signatures, not symmetric encryption modes.
Reference: Stallings, W. (2023). Cryptography and Network Security, 8th Ed., Ch. 6
Q2.
In a Role-Based Access Control (RBAC) system, a user is assigned to the 'HR Specialist'
role. Which principle does this assignment directly support?
A. Least privilege B. Separation of duties
C. Mandatory access control D. Discretionary access control
Correct: A - Least privilege
Rationale:RBAC assigns permissions based on roles, which enforces least privilege by giving
users only the access needed for their role. Separation of duties is a related but distinct
concept involving conflict of interest constraints.
Why the other answers are wrong:
B. Separation of duties focuses on preventing fraud by dividing tasks, not on role assignment
itself.
C. Mandatory access control uses labels and clearances, not roles.
D. Discretionary access control lets owners set permissions, not centralized role assignment.
Reference: NIST SP 800-53 Rev. 5, AC-2, AC-3
Page 3
, Section A - Introduction TO Cybersecurity AND Security Mindset
Q3.
A company's web server is configured to allow only HTTPS traffic on port 443. Which
security principle does this configuration best illustrate?
A. Defense in depth B. Attack surface reduction
C. Zero trust D. Security through obscurity
Correct: B - Attack surface reduction
Rationale:Limiting open ports reduces the attack surface by disabling unnecessary services.
Defense in depth involves multiple layers, zero trust assumes no implicit trust, and security
through obscurity relies on secrecy of design.
Why the other answers are wrong:
A. Defense in depth would include multiple controls, not just port filtering.
C. Zero trust focuses on continuous verification, not just port configuration.
D. Security through obscurity is hiding information, not reducing exposed services.
Reference: OWASP Top 10 (2021), A05: Security Misconfiguration
Q4.
During a risk assessment, a team calculates the Annualized Loss Expectancy (ALE) for a
threat. Which formula correctly represents ALE?
A. ALE = Single Loss Expectancy (SLE) × B. ALE = SLE + ARO
Annualized Rate of Occurrence (ARO)
C. ALE = SLE / ARO D. ALE = ARO / SLE
Correct: A - ALE = Single Loss Expectancy (SLE) × Annualized Rate of Occurrence (ARO)
Rationale:ALE is computed by multiplying the monetary loss from a single event (SLE) by the
expected frequency of the event per year (ARO). This quantifies annual risk exposure.
Why the other answers are wrong:
B. Addition does not account for frequency of occurrence.
C. Division would yield a per-occurrence metric, not annualized.
D. Inverting the ratio would produce a meaningless value.
Reference: NIST SP 800-30 Rev. 1, Risk Assessment Guide
Q5.
Which of the following best describes the primary function of a demilitarized zone (DMZ)
in network architecture?
A. To provide a secure area for internal B. To isolate public-facing services from the
databases internal network
Page 4
QUESTIONS & CORRECT ANSWERS | 2026
UPDATED | 100% CORRECT | TRINE UNIVERSITY
147 Questions with Answers and Detailed Rationales
100 PERCENT GUARANTEED PASS
INSTANT DOWNLOAD ANSWERS INCLUDED
IMPORTANCE OF THIS DOCUMENT
This comprehensive examination preparation guide has been meticulously developed to help you succeed in the
IS 5403 CYBERSECURITY WEEK 3 QUIZZES | QUESTIONS & CORRECT ANSWERS | 2026 UPDATED |
100% CORRECT | TRINE UNIVERSITY. It contains 147 carefully selected questions that reflect the most current
exam content and testing strategies. Each question is accompanied by a correct answer and a detailed rationale
that explains the underlying pathophysiology, pharmacology, or clinical reasoning.
Self-Assessment – Test your knowledge and Exam Preparation – Familiarize yourself with the
identify areas requiring further question format and content
study areas
Concept Reinforcement – Deepen your Confidence Building – Develop test-taking
understanding through strategies and reduce
evidence-based exam anxiety
rationales
Time Management – Practice answering
questions under simulated
exam conditions
Review Summary 147 Questions
Foundations - Application - IS 5403 Cybersecurity WEEK 3 Quizzes & Correct 2026 Updated 100 Correct
Trine University Cybersecurity Undergraduate YEAR 3
All answers with rationales
,Table of Contents
Content Area Questions Key Topics
Introduction TO 1-25 Security, Directly, Access, Control, Network
Cybersecurity AND Security
Mindset
Threat Actors Attack Vectors 26-50 Analyst, Security, Password, Company, Access
AND Social Engineering
Cryptography Fundamentals 51-75 Security, Access, Control, Primary, Directly
AND Encryption
Authentication Authorization 76-100 Access, University, Control, Security, Organization
AND Access Control
Network Security AND 101-125 Security, Control, Attack, Firewall, Describes
Perimeter Defense
Security Policies RISK 126-147 Security, Access, Analyst, Stored, Control
Management AND
Compliance
TOTAL 147 All questions include answers and detailed rationales
,Section A - Introduction TO Cybersecurity AND Security
Mindset
Q1.
A security team implements AES-256 in Galois/Counter Mode (GCM) for encrypting
database records. Which property does GCM provide that CBC mode does not inherently
offer?
A. Confidentiality only B. Integrity and authenticity
C. Key exchange D. Non-repudiation
Correct: B - Integrity and authenticity
Rationale:GCM is an authenticated encryption mode that provides both confidentiality and
integrity/authenticity via a universal hash, while CBC only provides confidentiality and requires
a separate MAC for integrity.
Why the other answers are wrong:
A. CBC also provides confidentiality, so this is not unique to GCM.
C. Key exchange is handled by protocols like Diffie-Hellman, not by the block cipher mode.
D. Non-repudiation requires digital signatures, not symmetric encryption modes.
Reference: Stallings, W. (2023). Cryptography and Network Security, 8th Ed., Ch. 6
Q2.
In a Role-Based Access Control (RBAC) system, a user is assigned to the 'HR Specialist'
role. Which principle does this assignment directly support?
A. Least privilege B. Separation of duties
C. Mandatory access control D. Discretionary access control
Correct: A - Least privilege
Rationale:RBAC assigns permissions based on roles, which enforces least privilege by giving
users only the access needed for their role. Separation of duties is a related but distinct
concept involving conflict of interest constraints.
Why the other answers are wrong:
B. Separation of duties focuses on preventing fraud by dividing tasks, not on role assignment
itself.
C. Mandatory access control uses labels and clearances, not roles.
D. Discretionary access control lets owners set permissions, not centralized role assignment.
Reference: NIST SP 800-53 Rev. 5, AC-2, AC-3
Page 3
, Section A - Introduction TO Cybersecurity AND Security Mindset
Q3.
A company's web server is configured to allow only HTTPS traffic on port 443. Which
security principle does this configuration best illustrate?
A. Defense in depth B. Attack surface reduction
C. Zero trust D. Security through obscurity
Correct: B - Attack surface reduction
Rationale:Limiting open ports reduces the attack surface by disabling unnecessary services.
Defense in depth involves multiple layers, zero trust assumes no implicit trust, and security
through obscurity relies on secrecy of design.
Why the other answers are wrong:
A. Defense in depth would include multiple controls, not just port filtering.
C. Zero trust focuses on continuous verification, not just port configuration.
D. Security through obscurity is hiding information, not reducing exposed services.
Reference: OWASP Top 10 (2021), A05: Security Misconfiguration
Q4.
During a risk assessment, a team calculates the Annualized Loss Expectancy (ALE) for a
threat. Which formula correctly represents ALE?
A. ALE = Single Loss Expectancy (SLE) × B. ALE = SLE + ARO
Annualized Rate of Occurrence (ARO)
C. ALE = SLE / ARO D. ALE = ARO / SLE
Correct: A - ALE = Single Loss Expectancy (SLE) × Annualized Rate of Occurrence (ARO)
Rationale:ALE is computed by multiplying the monetary loss from a single event (SLE) by the
expected frequency of the event per year (ARO). This quantifies annual risk exposure.
Why the other answers are wrong:
B. Addition does not account for frequency of occurrence.
C. Division would yield a per-occurrence metric, not annualized.
D. Inverting the ratio would produce a meaningless value.
Reference: NIST SP 800-30 Rev. 1, Risk Assessment Guide
Q5.
Which of the following best describes the primary function of a demilitarized zone (DMZ)
in network architecture?
A. To provide a secure area for internal B. To isolate public-facing services from the
databases internal network
Page 4