ITS153L FINAL EXAM QUESTIONS AND CORRECT
ANSWERS 2026/27 UPDATED 100% CORRECT -
MAPÚA INSTITUTE OF TECHNOLOGY.
148 QUESTIONS
TABLE OF CONTENTS
# TOPIC
1 Analyze and troubleshoot complex network architectures using layered protocol models and modern
diagnostic tools
2 Design and evaluate security controls that mitigate advanced persistent threats across endpoints,
networks, and cloud services
3 Apply cryptographic principles and access-control models to protect data at rest, in transit, and in use
4 ITS153L Final Exam Questions and Correct Answers 2026
5 27 Updated 100% Correct
6 Mapúa Institute of Technology.
7 Foundations of Network Technology, Systems Administration, and Cybersecurity
8 Applied Network Technology, Systems Administration, and Cybersecurity
9 Advanced Network Technology, Systems Administration, and Cybersecurity
10 Network Technology, Systems Administration, and Cybersecurity Review
ABSTRACT
This study document brings together 148 carefully worded exam questions drawn from ITS153L
Final Exam Questions and Correct Answers 2026/27 Updated 100% Correct - Mapúa Institute of
Technology., with the strongest emphasis placed on Analyze and troubleshoot complex network
architectures using layered protocol models and modern diagnostic tools, Design and evaluate
security controls that mitigate advanced persistent threats across endpoints, networks, and cloud
services, Apply cryptographic principles and access-control models to protect data at rest, in transit
and and in use. Every item follows the wording style and level of reasoning you meet in the real
paper, and each one is paired with a clear rationale so the correct choice is never a guess. Work
through the set at your own pace, mark the questions that slow you down, then come back to them
until the reasoning feels automatic. Learners who revise this way walk into the exam room
recognising the pattern behind the questions instead of meeting them for the first time. Keep going
- steady, honest practice is what turns a difficult paper into a comfortable pass.
Page 1
,Q1 ANALYZE AND TROUBLESHOOT COMPLEX NETWORK ARCHITECTURES USING
LAYERED PROTOCOL MODELS AND MODERN DIAGNOSTIC TOOLS
A network engineer observes that TCP throughput between two data centers
collapses after a route change increases RTT from 20 ms to 120 ms while the
receiver window remains 64 KB. Which factor most directly explains the
throughput reduction?
A. Increased packet loss triggering multiplicative decrease
B. Bandwidth-delay product exceeding the congestion window CORRECT
C. Nagle's algorithm coalescing small segments
D. Delayed ACK interaction with slow start
RATIONALE: Throughput is bounded by window size divided by RTT; a 64 KB window over 120
ms caps throughput near 4.3 Mbps regardless of available bandwidth. Packet loss and
Nagle/delayed-ACK interactions are secondary here, and the question specifies a route change
without indicating loss.
Q2 ANALYZE AND TROUBLESHOOT COMPLEX NETWORK ARCHITECTURES USING
LAYERED PROTOCOL MODELS AND MODERN DIAGNOSTIC TOOLS
In a zero-trust architecture, a policy engine continuously evaluates device posture,
user identity, and session context. Which principle is most critical to prevent
lateral movement after an endpoint compromise?
A. Implicit trust based on network location
B. Micro-segmentation with least-privilege access CORRECT
C. Static VLAN assignment for all user devices
D. Perimeter firewall rules allowing internal any-any
RATIONALE: Zero-trust rejects implicit trust; micro-segmentation limits east-west traffic so a
compromised host cannot reach unrelated resources. The other options describe legacy
perimeter or static models that enable lateral movement.
Page 2
,Q3 ANALYZE AND TROUBLESHOOT COMPLEX NETWORK ARCHITECTURES USING
LAYERED PROTOCOL MODELS AND MODERN DIAGNOSTIC TOOLS
An organization must store encrypted backups in a public cloud while ensuring
that a compromised cloud provider cannot decrypt them, yet authorized
on-premises systems can restore without manual key entry. Which design best
satisfies these requirements?
A. Provider-managed encryption at rest with customer-supplied bucket policies
B. Client-side envelope encryption using a customer-managed KMS key with automated key
rotation CORRECT
C. TLS in transit plus server-side AES-256 with provider-held keys
D. Database-native transparent data encryption with provider key escrow
RATIONALE: Client-side envelope encryption ensures plaintext and data keys never reach the
provider in usable form, while a customer-managed KMS supports automated restore workflows.
Options A, C, and D leave key control with the provider, violating the stated threat model.
Q4 ANALYZE AND TROUBLESHOOT COMPLEX NETWORK ARCHITECTURES USING
LAYERED PROTOCOL MODELS AND MODERN DIAGNOSTIC TOOLS
A web application reflects user input into HTML without encoding. Which
mitigation most effectively prevents exploitation while preserving legitimate
functionality?
A. Input length restriction to 255 characters
B. Output encoding contextual to the HTML insertion point CORRECT
C. Blocklisting common script tags
D. Client-side JavaScript validation only
RATIONALE: Context-aware output encoding neutralizes dangerous characters at the point of
interpretation, which is the definitive fix for reflected XSS. Length limits, blocklists, and client-side
checks are bypassable and do not address the root cause.
Page 3
, Q5 ANALYZE AND TROUBLESHOOT COMPLEX NETWORK ARCHITECTURES USING
LAYERED PROTOCOL MODELS AND MODERN DIAGNOSTIC TOOLS
A company uses a SIEM that ingests NetFlow, DNS logs, and endpoint telemetry.
Which analytic approach best detects a low-and-slow data exfiltration that evades
volume thresholds?
A. Static signature matching on known malware hashes
B. Baseline deviation analysis on destination diversity and periodic beaconing CORRECT
C. Alerting on any outbound transfer exceeding 1 GB
D. Daily manual review of firewall deny logs
RATIONALE: Low-and-slow exfiltration hides in normal volumes but often shows anomalous
destination diversity or regular beacon intervals, which behavioral baselining can surface. Hash
signatures, volume thresholds, and manual review are ineffective against this pattern.
Q6 ANALYZE AND TROUBLESHOOT COMPLEX NETWORK ARCHITECTURES USING
LAYERED PROTOCOL MODELS AND MODERN DIAGNOSTIC TOOLS
Which scenario most accurately illustrates the difference between authentication
and authorization in a federated identity system?
A. A user proves identity via SAML assertion, then the SP grants access based on role attributes
CORRECT
B. A user enters a password, then the IdP hashes it for storage
C. A user connects via VPN, then the firewall permits all internal traffic
D. A user receives a session cookie, then the browser caches it
RATIONALE: Authentication establishes who the user is (SAML assertion); authorization
determines what they may do (role-based access). The other options describe credential
handling, network admission, or session persistence, not the authn/authz distinction.
Page 4
ANSWERS 2026/27 UPDATED 100% CORRECT -
MAPÚA INSTITUTE OF TECHNOLOGY.
148 QUESTIONS
TABLE OF CONTENTS
# TOPIC
1 Analyze and troubleshoot complex network architectures using layered protocol models and modern
diagnostic tools
2 Design and evaluate security controls that mitigate advanced persistent threats across endpoints,
networks, and cloud services
3 Apply cryptographic principles and access-control models to protect data at rest, in transit, and in use
4 ITS153L Final Exam Questions and Correct Answers 2026
5 27 Updated 100% Correct
6 Mapúa Institute of Technology.
7 Foundations of Network Technology, Systems Administration, and Cybersecurity
8 Applied Network Technology, Systems Administration, and Cybersecurity
9 Advanced Network Technology, Systems Administration, and Cybersecurity
10 Network Technology, Systems Administration, and Cybersecurity Review
ABSTRACT
This study document brings together 148 carefully worded exam questions drawn from ITS153L
Final Exam Questions and Correct Answers 2026/27 Updated 100% Correct - Mapúa Institute of
Technology., with the strongest emphasis placed on Analyze and troubleshoot complex network
architectures using layered protocol models and modern diagnostic tools, Design and evaluate
security controls that mitigate advanced persistent threats across endpoints, networks, and cloud
services, Apply cryptographic principles and access-control models to protect data at rest, in transit
and and in use. Every item follows the wording style and level of reasoning you meet in the real
paper, and each one is paired with a clear rationale so the correct choice is never a guess. Work
through the set at your own pace, mark the questions that slow you down, then come back to them
until the reasoning feels automatic. Learners who revise this way walk into the exam room
recognising the pattern behind the questions instead of meeting them for the first time. Keep going
- steady, honest practice is what turns a difficult paper into a comfortable pass.
Page 1
,Q1 ANALYZE AND TROUBLESHOOT COMPLEX NETWORK ARCHITECTURES USING
LAYERED PROTOCOL MODELS AND MODERN DIAGNOSTIC TOOLS
A network engineer observes that TCP throughput between two data centers
collapses after a route change increases RTT from 20 ms to 120 ms while the
receiver window remains 64 KB. Which factor most directly explains the
throughput reduction?
A. Increased packet loss triggering multiplicative decrease
B. Bandwidth-delay product exceeding the congestion window CORRECT
C. Nagle's algorithm coalescing small segments
D. Delayed ACK interaction with slow start
RATIONALE: Throughput is bounded by window size divided by RTT; a 64 KB window over 120
ms caps throughput near 4.3 Mbps regardless of available bandwidth. Packet loss and
Nagle/delayed-ACK interactions are secondary here, and the question specifies a route change
without indicating loss.
Q2 ANALYZE AND TROUBLESHOOT COMPLEX NETWORK ARCHITECTURES USING
LAYERED PROTOCOL MODELS AND MODERN DIAGNOSTIC TOOLS
In a zero-trust architecture, a policy engine continuously evaluates device posture,
user identity, and session context. Which principle is most critical to prevent
lateral movement after an endpoint compromise?
A. Implicit trust based on network location
B. Micro-segmentation with least-privilege access CORRECT
C. Static VLAN assignment for all user devices
D. Perimeter firewall rules allowing internal any-any
RATIONALE: Zero-trust rejects implicit trust; micro-segmentation limits east-west traffic so a
compromised host cannot reach unrelated resources. The other options describe legacy
perimeter or static models that enable lateral movement.
Page 2
,Q3 ANALYZE AND TROUBLESHOOT COMPLEX NETWORK ARCHITECTURES USING
LAYERED PROTOCOL MODELS AND MODERN DIAGNOSTIC TOOLS
An organization must store encrypted backups in a public cloud while ensuring
that a compromised cloud provider cannot decrypt them, yet authorized
on-premises systems can restore without manual key entry. Which design best
satisfies these requirements?
A. Provider-managed encryption at rest with customer-supplied bucket policies
B. Client-side envelope encryption using a customer-managed KMS key with automated key
rotation CORRECT
C. TLS in transit plus server-side AES-256 with provider-held keys
D. Database-native transparent data encryption with provider key escrow
RATIONALE: Client-side envelope encryption ensures plaintext and data keys never reach the
provider in usable form, while a customer-managed KMS supports automated restore workflows.
Options A, C, and D leave key control with the provider, violating the stated threat model.
Q4 ANALYZE AND TROUBLESHOOT COMPLEX NETWORK ARCHITECTURES USING
LAYERED PROTOCOL MODELS AND MODERN DIAGNOSTIC TOOLS
A web application reflects user input into HTML without encoding. Which
mitigation most effectively prevents exploitation while preserving legitimate
functionality?
A. Input length restriction to 255 characters
B. Output encoding contextual to the HTML insertion point CORRECT
C. Blocklisting common script tags
D. Client-side JavaScript validation only
RATIONALE: Context-aware output encoding neutralizes dangerous characters at the point of
interpretation, which is the definitive fix for reflected XSS. Length limits, blocklists, and client-side
checks are bypassable and do not address the root cause.
Page 3
, Q5 ANALYZE AND TROUBLESHOOT COMPLEX NETWORK ARCHITECTURES USING
LAYERED PROTOCOL MODELS AND MODERN DIAGNOSTIC TOOLS
A company uses a SIEM that ingests NetFlow, DNS logs, and endpoint telemetry.
Which analytic approach best detects a low-and-slow data exfiltration that evades
volume thresholds?
A. Static signature matching on known malware hashes
B. Baseline deviation analysis on destination diversity and periodic beaconing CORRECT
C. Alerting on any outbound transfer exceeding 1 GB
D. Daily manual review of firewall deny logs
RATIONALE: Low-and-slow exfiltration hides in normal volumes but often shows anomalous
destination diversity or regular beacon intervals, which behavioral baselining can surface. Hash
signatures, volume thresholds, and manual review are ineffective against this pattern.
Q6 ANALYZE AND TROUBLESHOOT COMPLEX NETWORK ARCHITECTURES USING
LAYERED PROTOCOL MODELS AND MODERN DIAGNOSTIC TOOLS
Which scenario most accurately illustrates the difference between authentication
and authorization in a federated identity system?
A. A user proves identity via SAML assertion, then the SP grants access based on role attributes
CORRECT
B. A user enters a password, then the IdP hashes it for storage
C. A user connects via VPN, then the firewall permits all internal traffic
D. A user receives a session cookie, then the browser caches it
RATIONALE: Authentication establishes who the user is (SAML assertion); authorization
determines what they may do (role-based access). The other options describe credential
handling, network admission, or session persistence, not the authn/authz distinction.
Page 4