IS 5403 CYBERSECURITY WEEK 7 QUIZZES |
QUESTIONS & CORRECT ANSWERS | 2026
UPDATED | 100% CORRECT | TRINE UNIVERSITY
149 Questions with Answers and Detailed Rationales
100 PERCENT GUARANTEED PASS
INSTANT DOWNLOAD ANSWERS INCLUDED
IMPORTANCE OF THIS DOCUMENT
This comprehensive examination preparation guide has been meticulously developed to help you succeed in the
IS 5403 CYBERSECURITY WEEK 7 QUIZZES | QUESTIONS & CORRECT ANSWERS | 2026 UPDATED |
100% CORRECT | TRINE UNIVERSITY. It contains 149 carefully selected questions that reflect the most current
exam content and testing strategies. Each question is accompanied by a correct answer and a detailed rationale
that explains the underlying pathophysiology, pharmacology, or clinical reasoning.
Self-Assessment – Test your knowledge and Exam Preparation – Familiarize yourself with the
identify areas requiring further question format and content
study areas
Concept Reinforcement – Deepen your Confidence Building – Develop test-taking
understanding through strategies and reduce
evidence-based exam anxiety
rationales
Time Management – Practice answering
questions under simulated
exam conditions
Review Summary 149 Questions
Foundations - Application - IS 5403 Cybersecurity WEEK 7 Quizzes & Correct 2026 Updated 100 Correct
Trine University Cybersecurity Undergraduate YEAR 3/4 Information Systems Security
All answers with rationales
,Table of Contents
Content Area Questions Key Topics
Security Governance AND 1-25 Security, Access, Control, Application, Directly
Policy
RISK Management AND 26-50 Organization, Control, Directly, Attack, Security
Assessment
Security Architecture AND 51-75 Without, Security, Directly, Network, Analyst
Design
Network Security AND 76-100 Directly, Organization, Analyst, Phase, Wants
Defense
Access Control AND Identity 101-125 Directly, Wants, Control, Without, Analyst
Management
Cryptography AND 126-149 Security, Current, Attack, Incident, Reflects
Encryption
TOTAL 149 All questions include answers and detailed rationales
,Section A - Security Governance AND Policy
Q1.
During the containment phase of an incident response, which action best balances
evidence preservation and threat neutralization for a compromised server?
A. Immediately power off the server to stop B. Disconnect the network cable and
malware execution. capture a memory image before shutdown.
C. Run antivirus scan and delete infected D. Reimage the server from a known good
files. backup.
Correct: B - Disconnect the network cable and capture a memory image before shutdown.
Rationale:Capturing volatile memory before shutdown preserves critical evidence like running
processes and encryption keys, while disconnecting the network contains the threat.
Powering off or reimaging destroys volatile data, and antivirus may alter evidence.
Why the other answers are wrong:
A. Powering off loses volatile memory evidence and may trigger anti-forensic mechanisms.
C. Antivirus scanning modifies file metadata and may not capture memory-resident threats.
D. Reimaging destroys all evidence and prevents root cause analysis.
Reference: NIST SP 800-61 Rev. 2, Computer Security Incident Handling Guide, Section 3.2.5
Q2.
A security team implements a PKI using ECDSA with P-256. Which property is most
critical to ensure the integrity of issued certificates?
A. Certificate revocation list (CRL) is B. The CA's private key is stored in a
updated hourly. hardware security module (HSM).
C. Certificates use SHA-1 for hashing. D. The CA issues certificates with a 10-year
validity period.
Correct: B - The CA's private key is stored in a hardware security module (HSM).
Rationale:The CA's private key must be protected to prevent unauthorized certificate
issuance; an HSM provides tamper-resistant key storage. SHA-1 is deprecated, long validity
increases risk, and CRL frequency alone does not ensure integrity.
Why the other answers are wrong:
A. CRL updates affect revocation, not the integrity of certificate issuance.
C. SHA-1 is cryptographically broken and unsuitable for certificate hashing.
D. Long validity periods increase exposure if keys are compromised.
Reference: NIST SP 800-57 Part 1 Rev. 5, Recommendation for Key Management, Section 5.3
Page 3
, Section A - Security Governance AND Policy
Q3.
In a role-based access control (RBAC) system, which principle is violated if a user is
assigned to multiple roles that collectively grant excessive privileges?
A. Least privilege B. Separation of duties
C. Need to know D. Defense in depth
Correct: A - Least privilege
Rationale:Least privilege requires users have only the minimum access necessary. Multiple
roles can accumulate permissions beyond what is needed, violating least privilege.
Separation of duties and need to know are related but not directly violated by role
accumulation.
Why the other answers are wrong:
B. Separation of duties concerns dividing tasks to prevent fraud, not role accumulation.
C. Need to know is about data access based on job function, not role assignment.
D. Defense in depth is about layered controls, not privilege assignment.
Reference: NIST RBAC Model, Sandhu et al., IEEE Computer, 1996; updated in NIST SP 800-53 Rev. 5,
AC-6
Q4.
Which network security control is most effective against ARP spoofing on a local area
network?
A. Enabling DHCP snooping B. Implementing dynamic ARP inspection
(DAI)
C. Using WPA3 encryption D. Deploying a stateful firewall
Correct: B - Implementing dynamic ARP inspection (DAI)
Rationale:Dynamic ARP inspection validates ARP packets against a trusted DHCP snooping
binding database, preventing ARP spoofing. DHCP snooping alone builds the database but
does not inspect ARP. WPA3 and firewalls do not address Layer 2 ARP attacks.
Why the other answers are wrong:
A. DHCP snooping helps build the binding table but does not block ARP spoofing by itself.
C. WPA3 secures wireless frames, not wired ARP traffic.
D. Stateful firewalls operate at Layer 3/4 and typically do not inspect ARP.
Reference: Cisco Press, LAN Switch Security, Chapter 5: Dynamic ARP Inspection
Q5.
When conducting a quantitative risk assessment, which formula correctly represents
annualized loss expectancy (ALE)?
Page 4
QUESTIONS & CORRECT ANSWERS | 2026
UPDATED | 100% CORRECT | TRINE UNIVERSITY
149 Questions with Answers and Detailed Rationales
100 PERCENT GUARANTEED PASS
INSTANT DOWNLOAD ANSWERS INCLUDED
IMPORTANCE OF THIS DOCUMENT
This comprehensive examination preparation guide has been meticulously developed to help you succeed in the
IS 5403 CYBERSECURITY WEEK 7 QUIZZES | QUESTIONS & CORRECT ANSWERS | 2026 UPDATED |
100% CORRECT | TRINE UNIVERSITY. It contains 149 carefully selected questions that reflect the most current
exam content and testing strategies. Each question is accompanied by a correct answer and a detailed rationale
that explains the underlying pathophysiology, pharmacology, or clinical reasoning.
Self-Assessment – Test your knowledge and Exam Preparation – Familiarize yourself with the
identify areas requiring further question format and content
study areas
Concept Reinforcement – Deepen your Confidence Building – Develop test-taking
understanding through strategies and reduce
evidence-based exam anxiety
rationales
Time Management – Practice answering
questions under simulated
exam conditions
Review Summary 149 Questions
Foundations - Application - IS 5403 Cybersecurity WEEK 7 Quizzes & Correct 2026 Updated 100 Correct
Trine University Cybersecurity Undergraduate YEAR 3/4 Information Systems Security
All answers with rationales
,Table of Contents
Content Area Questions Key Topics
Security Governance AND 1-25 Security, Access, Control, Application, Directly
Policy
RISK Management AND 26-50 Organization, Control, Directly, Attack, Security
Assessment
Security Architecture AND 51-75 Without, Security, Directly, Network, Analyst
Design
Network Security AND 76-100 Directly, Organization, Analyst, Phase, Wants
Defense
Access Control AND Identity 101-125 Directly, Wants, Control, Without, Analyst
Management
Cryptography AND 126-149 Security, Current, Attack, Incident, Reflects
Encryption
TOTAL 149 All questions include answers and detailed rationales
,Section A - Security Governance AND Policy
Q1.
During the containment phase of an incident response, which action best balances
evidence preservation and threat neutralization for a compromised server?
A. Immediately power off the server to stop B. Disconnect the network cable and
malware execution. capture a memory image before shutdown.
C. Run antivirus scan and delete infected D. Reimage the server from a known good
files. backup.
Correct: B - Disconnect the network cable and capture a memory image before shutdown.
Rationale:Capturing volatile memory before shutdown preserves critical evidence like running
processes and encryption keys, while disconnecting the network contains the threat.
Powering off or reimaging destroys volatile data, and antivirus may alter evidence.
Why the other answers are wrong:
A. Powering off loses volatile memory evidence and may trigger anti-forensic mechanisms.
C. Antivirus scanning modifies file metadata and may not capture memory-resident threats.
D. Reimaging destroys all evidence and prevents root cause analysis.
Reference: NIST SP 800-61 Rev. 2, Computer Security Incident Handling Guide, Section 3.2.5
Q2.
A security team implements a PKI using ECDSA with P-256. Which property is most
critical to ensure the integrity of issued certificates?
A. Certificate revocation list (CRL) is B. The CA's private key is stored in a
updated hourly. hardware security module (HSM).
C. Certificates use SHA-1 for hashing. D. The CA issues certificates with a 10-year
validity period.
Correct: B - The CA's private key is stored in a hardware security module (HSM).
Rationale:The CA's private key must be protected to prevent unauthorized certificate
issuance; an HSM provides tamper-resistant key storage. SHA-1 is deprecated, long validity
increases risk, and CRL frequency alone does not ensure integrity.
Why the other answers are wrong:
A. CRL updates affect revocation, not the integrity of certificate issuance.
C. SHA-1 is cryptographically broken and unsuitable for certificate hashing.
D. Long validity periods increase exposure if keys are compromised.
Reference: NIST SP 800-57 Part 1 Rev. 5, Recommendation for Key Management, Section 5.3
Page 3
, Section A - Security Governance AND Policy
Q3.
In a role-based access control (RBAC) system, which principle is violated if a user is
assigned to multiple roles that collectively grant excessive privileges?
A. Least privilege B. Separation of duties
C. Need to know D. Defense in depth
Correct: A - Least privilege
Rationale:Least privilege requires users have only the minimum access necessary. Multiple
roles can accumulate permissions beyond what is needed, violating least privilege.
Separation of duties and need to know are related but not directly violated by role
accumulation.
Why the other answers are wrong:
B. Separation of duties concerns dividing tasks to prevent fraud, not role accumulation.
C. Need to know is about data access based on job function, not role assignment.
D. Defense in depth is about layered controls, not privilege assignment.
Reference: NIST RBAC Model, Sandhu et al., IEEE Computer, 1996; updated in NIST SP 800-53 Rev. 5,
AC-6
Q4.
Which network security control is most effective against ARP spoofing on a local area
network?
A. Enabling DHCP snooping B. Implementing dynamic ARP inspection
(DAI)
C. Using WPA3 encryption D. Deploying a stateful firewall
Correct: B - Implementing dynamic ARP inspection (DAI)
Rationale:Dynamic ARP inspection validates ARP packets against a trusted DHCP snooping
binding database, preventing ARP spoofing. DHCP snooping alone builds the database but
does not inspect ARP. WPA3 and firewalls do not address Layer 2 ARP attacks.
Why the other answers are wrong:
A. DHCP snooping helps build the binding table but does not block ARP spoofing by itself.
C. WPA3 secures wireless frames, not wired ARP traffic.
D. Stateful firewalls operate at Layer 3/4 and typically do not inspect ARP.
Reference: Cisco Press, LAN Switch Security, Chapter 5: Dynamic ARP Inspection
Q5.
When conducting a quantitative risk assessment, which formula correctly represents
annualized loss expectancy (ALE)?
Page 4