D488 ITAS 6291
Cybersecurity Architecture &
Engineering
Final Assessment (Qns & Ans)
2025
General Instructions
1. Read All Questions Carefully: Make sure you understand each question.
2. Time Management: You have a specific amount of time to complete the exam.
Keep an eye on the clock and pace yourself.
3. Allowed Materials: Only use materials that are explicitly allowed. Unauthorized
materials can lead to disqualification.
4. ANS Format: Follow the required format for your ANS. For example, multiple-
choice questions might need you to select the best ANS, while essay questions
require detailed responses.
5. Academic Integrity: Adhere to the university's honor code. Any form of cheating or
plagiarism is strictly prohibited.
6. Technical Requirements: Ensure your computer and internet connection are
stable. For online exams, you might need a webcam and microphone for proctoring
purposes.
7. Submission: Submit your ANS before the time expires. Late submissions might
not be accepted.
©2024/2025
,1. What is the purpose of a Security Information and Event
Management (SIEM) system?
- A) Data storage
- B) Threat detection and response
- C) Network performance monitoring
- D) User authentication
- Correct ANS: B) Threat detection and response
- Rationale: A SIEM system combines security information
management (SIM) and security event management (SEM) to
provide real-time analysis of security alerts generated by network
hardware and applications.
2. Which framework is commonly used to manage cybersecurity
risk?
- A) COBIT
- B) NIST Cybersecurity Framework
- C) ITIL
- D) TOGAF
- Correct ANS: B) NIST Cybersecurity Framework
©2024/2025
, - Rationale: The NIST Cybersecurity Framework provides
guidelines for managing cybersecurity risks and is widely adopted
across different industries.
3. In the context of network architecture, which of the following
components is an example of a defensive layer?
- A) Firewall
- B) Load Balancer
- C) Switch
- D) Router
- Correct ANS: A) Firewall
- Rationale: A firewall serves as a protective barrier that
filters incoming and outgoing traffic based on predetermined
security rules.
4. Which of the following is an example of a security control
type?
- A) Administrative
- B) Operational
- C) Technical
- D) All of the above
- Correct ANS: D) All of the above
©2024/2025
, - Rationale: Security controls can be categorized as
administrative, operational, and technical, and all play a role in a
comprehensive security strategy.
5. What technique can be used to achieve data encryption?
- A) Hashing
- B) Salting
- C) Symmetric key encryption
- D) All of the above
- Correct ANS: C) Symmetric key encryption
- Rationale: Symmetric key encryption uses the same key for
both encryption and decryption processes to secure data.
### Fill-in-the-Blank Questions
6. The process of converting plaintext into ciphertext is known
as __________.
- Correct ANS: Encryption
- Rationale: Encryption is the method used to transform
readable data into a format that cannot be easily understood
without a key.
©2024/2025
Cybersecurity Architecture &
Engineering
Final Assessment (Qns & Ans)
2025
General Instructions
1. Read All Questions Carefully: Make sure you understand each question.
2. Time Management: You have a specific amount of time to complete the exam.
Keep an eye on the clock and pace yourself.
3. Allowed Materials: Only use materials that are explicitly allowed. Unauthorized
materials can lead to disqualification.
4. ANS Format: Follow the required format for your ANS. For example, multiple-
choice questions might need you to select the best ANS, while essay questions
require detailed responses.
5. Academic Integrity: Adhere to the university's honor code. Any form of cheating or
plagiarism is strictly prohibited.
6. Technical Requirements: Ensure your computer and internet connection are
stable. For online exams, you might need a webcam and microphone for proctoring
purposes.
7. Submission: Submit your ANS before the time expires. Late submissions might
not be accepted.
©2024/2025
,1. What is the purpose of a Security Information and Event
Management (SIEM) system?
- A) Data storage
- B) Threat detection and response
- C) Network performance monitoring
- D) User authentication
- Correct ANS: B) Threat detection and response
- Rationale: A SIEM system combines security information
management (SIM) and security event management (SEM) to
provide real-time analysis of security alerts generated by network
hardware and applications.
2. Which framework is commonly used to manage cybersecurity
risk?
- A) COBIT
- B) NIST Cybersecurity Framework
- C) ITIL
- D) TOGAF
- Correct ANS: B) NIST Cybersecurity Framework
©2024/2025
, - Rationale: The NIST Cybersecurity Framework provides
guidelines for managing cybersecurity risks and is widely adopted
across different industries.
3. In the context of network architecture, which of the following
components is an example of a defensive layer?
- A) Firewall
- B) Load Balancer
- C) Switch
- D) Router
- Correct ANS: A) Firewall
- Rationale: A firewall serves as a protective barrier that
filters incoming and outgoing traffic based on predetermined
security rules.
4. Which of the following is an example of a security control
type?
- A) Administrative
- B) Operational
- C) Technical
- D) All of the above
- Correct ANS: D) All of the above
©2024/2025
, - Rationale: Security controls can be categorized as
administrative, operational, and technical, and all play a role in a
comprehensive security strategy.
5. What technique can be used to achieve data encryption?
- A) Hashing
- B) Salting
- C) Symmetric key encryption
- D) All of the above
- Correct ANS: C) Symmetric key encryption
- Rationale: Symmetric key encryption uses the same key for
both encryption and decryption processes to secure data.
### Fill-in-the-Blank Questions
6. The process of converting plaintext into ciphertext is known
as __________.
- Correct ANS: Encryption
- Rationale: Encryption is the method used to transform
readable data into a format that cannot be easily understood
without a key.
©2024/2025