Michigan IT Security Specialist Exam
Questions and Correct Answers (Verified
Answers) Plus Rationales 2026 Q&A |
Instant Download Pdf
1. Which of the following best describes the principle of least
privilege?
A) Giving users access to all system resources
B) Restricting user access to only what is necessary for their role
C) Allowing users to change system security settings
D) Sharing passwords to improve efficiency
B) Restricting user access to only what is necessary for their role
This principle limits access rights to the minimum necessary, reducing
the potential for accidental or malicious misuse.
2. What is a common characteristic of a phishing attack?
A) Use of encrypted connections
B) Attempts to steal sensitive information via deceptive emails
C) Physical break-ins to access servers
D) Installing updates automatically
B) Attempts to steal sensitive information via deceptive emails
Phishing exploits human trust by mimicking legitimate communication
to collect credentials or sensitive data.
, 3. Which security model focuses on confidentiality by enforcing
strict access controls?
A) Bell-LaPadula
B) Biba
C) Clark-Wilson
D) Brewer-Nash
A) Bell-LaPadula
The Bell-LaPadula model emphasizes data confidentiality and
prohibits information flow from higher to lower security levels.
4. What is the primary purpose of a firewall?
A) Encrypt all internal traffic
B) Block unauthorized network access while permitting legitimate
communications
C) Store backup data
D) Monitor employee productivity
B) Block unauthorized network access while permitting legitimate
communications
Firewalls act as a barrier between trusted and untrusted networks,
filtering traffic based on rules.
5. Which of the following is a symmetric encryption algorithm?
A) RSA
B) AES
C) ECC
D) DSA
B) AES
AES (Advanced Encryption Standard) uses the same key for encryption
and decryption, which characterizes symmetric cryptography.
, 6. Which protocol is commonly used for secure remote logins?
A) Telnet
B) SSH
C) FTP
D) HTTP
B) SSH
SSH (Secure Shell) provides encrypted communication for secure
remote access, unlike Telnet, which transmits data in plaintext.
7. What does multi-factor authentication (MFA) require?
A) Username and password only
B) At least two forms of verification from independent categories
C) Biometric verification only
D) VPN access
B) At least two forms of verification from independent categories
MFA combines something you know (password), something you have
(token), and/or something you are (biometrics) for stronger security.
8. Which attack involves overwhelming a system to make it
unavailable to legitimate users?
A) SQL Injection
B) Denial of Service (DoS)
C) Cross-Site Scripting (XSS)
D) Man-in-the-Middle
B) Denial of Service (DoS)
DoS attacks flood a system with traffic, causing service disruption and
preventing legitimate access.
9. What is the main purpose of an intrusion detection system (IDS)?
A) Automatically block all network traffic
B) Detect and alert on potential security breaches
, C) Encrypt data at rest
D) Monitor employee emails
B) Detect and alert on potential security breaches
IDS tools monitor networks or systems for suspicious activities and
provide alerts without necessarily blocking traffic.
10. Which of the following describes ransomware?
A) Software that records keystrokes
B) Malicious software that encrypts files and demands payment
C) Malware that monitors network traffic silently
D) A virus that deletes files randomly
B) Malicious software that encrypts files and demands payment
Ransomware restricts access to files or systems until a ransom is paid,
often via cryptocurrency.
11. What is the purpose of a digital certificate?
A) To prevent network attacks
B) To validate the identity of a website or entity and establish
secure communication
C) To encrypt local files
D) To install software updates
B) To validate the identity of a website or entity and establish secure
communication
Digital certificates, issued by a trusted Certificate Authority (CA),
confirm identities and enable encrypted sessions.
12. Which of the following best describes a zero-day
vulnerability?
A) A vulnerability known for more than one year
B) A vulnerability exploited before a patch is available
Questions and Correct Answers (Verified
Answers) Plus Rationales 2026 Q&A |
Instant Download Pdf
1. Which of the following best describes the principle of least
privilege?
A) Giving users access to all system resources
B) Restricting user access to only what is necessary for their role
C) Allowing users to change system security settings
D) Sharing passwords to improve efficiency
B) Restricting user access to only what is necessary for their role
This principle limits access rights to the minimum necessary, reducing
the potential for accidental or malicious misuse.
2. What is a common characteristic of a phishing attack?
A) Use of encrypted connections
B) Attempts to steal sensitive information via deceptive emails
C) Physical break-ins to access servers
D) Installing updates automatically
B) Attempts to steal sensitive information via deceptive emails
Phishing exploits human trust by mimicking legitimate communication
to collect credentials or sensitive data.
, 3. Which security model focuses on confidentiality by enforcing
strict access controls?
A) Bell-LaPadula
B) Biba
C) Clark-Wilson
D) Brewer-Nash
A) Bell-LaPadula
The Bell-LaPadula model emphasizes data confidentiality and
prohibits information flow from higher to lower security levels.
4. What is the primary purpose of a firewall?
A) Encrypt all internal traffic
B) Block unauthorized network access while permitting legitimate
communications
C) Store backup data
D) Monitor employee productivity
B) Block unauthorized network access while permitting legitimate
communications
Firewalls act as a barrier between trusted and untrusted networks,
filtering traffic based on rules.
5. Which of the following is a symmetric encryption algorithm?
A) RSA
B) AES
C) ECC
D) DSA
B) AES
AES (Advanced Encryption Standard) uses the same key for encryption
and decryption, which characterizes symmetric cryptography.
, 6. Which protocol is commonly used for secure remote logins?
A) Telnet
B) SSH
C) FTP
D) HTTP
B) SSH
SSH (Secure Shell) provides encrypted communication for secure
remote access, unlike Telnet, which transmits data in plaintext.
7. What does multi-factor authentication (MFA) require?
A) Username and password only
B) At least two forms of verification from independent categories
C) Biometric verification only
D) VPN access
B) At least two forms of verification from independent categories
MFA combines something you know (password), something you have
(token), and/or something you are (biometrics) for stronger security.
8. Which attack involves overwhelming a system to make it
unavailable to legitimate users?
A) SQL Injection
B) Denial of Service (DoS)
C) Cross-Site Scripting (XSS)
D) Man-in-the-Middle
B) Denial of Service (DoS)
DoS attacks flood a system with traffic, causing service disruption and
preventing legitimate access.
9. What is the main purpose of an intrusion detection system (IDS)?
A) Automatically block all network traffic
B) Detect and alert on potential security breaches
, C) Encrypt data at rest
D) Monitor employee emails
B) Detect and alert on potential security breaches
IDS tools monitor networks or systems for suspicious activities and
provide alerts without necessarily blocking traffic.
10. Which of the following describes ransomware?
A) Software that records keystrokes
B) Malicious software that encrypts files and demands payment
C) Malware that monitors network traffic silently
D) A virus that deletes files randomly
B) Malicious software that encrypts files and demands payment
Ransomware restricts access to files or systems until a ransom is paid,
often via cryptocurrency.
11. What is the purpose of a digital certificate?
A) To prevent network attacks
B) To validate the identity of a website or entity and establish
secure communication
C) To encrypt local files
D) To install software updates
B) To validate the identity of a website or entity and establish secure
communication
Digital certificates, issued by a trusted Certificate Authority (CA),
confirm identities and enable encrypted sessions.
12. Which of the following best describes a zero-day
vulnerability?
A) A vulnerability known for more than one year
B) A vulnerability exploited before a patch is available