🔒 Cybersecurity Study Guide — 23 Question Type Variants

Each of the 23 original questions is presented with multiple variant phrasings — different ways the same concept can be tested. Master the concept, not just the wording.

Table of Contents

Question Type 1: IAAA Acronym

Original: What does the acronym IAAA stand for in information security?
📖 Source: 5_0_Introduction.txt, 5_1_Intro_to_IAAA.txt — "IAAA stands for Identity, Authentication, Authorization, and Auditing/Accounting… It is the foundational framework for access management."
Variant A — Multiple Choice (Reworded)
The access management framework that begins with claiming an identity and ends with logging actions is known by which acronym?
Reveal Answer
Correct Answer: B) IAAA

IAAA = Identity, Authentication, Authorization, Auditing/Accounting. CIA is the Confidentiality-Integrity-Availability triad. AAA is a subset (Authentication, Authorization, Accounting). DAC is Discretionary Access Control.

Variant B — Fill in the Blank
In the IAAA framework, the four stages in order are: ________, ________, ________, and ________.
Reveal Answer
Identity, Authentication, Authorization, Auditing/Accounting

The order matters: you must first claim who you are, prove it, receive permissions, then have actions logged.

Variant C — Scenario-Based
A new employee enters their username (step 1), provides their password and fingerprint (step 2), is granted access to HR files (step 3), and all file access is recorded in a log (step 4). Which IAAA component does each step represent?
Reveal Answer
Step 1 = Identity, Step 2 = Authentication, Step 3 = Authorization, Step 4 = Auditing

This is a real-world walkthrough of the entire IAAA pipeline.

Variant D — True/False
True or False: The IAAA framework includes "Integrity" as one of its four components.
Reveal Answer
False

Integrity belongs to the CIA triad, not IAAA. The four As in IAAA are Identity, Authentication, Authorization, and Auditing/Accounting.

Variant E — Ordering / Sequencing
Place the following IAAA steps in their correct sequence: Authorization, Auditing, Authentication, Identity.
Reveal Answer
1. Identity → 2. Authentication → 3. Authorization → 4. Auditing

You cannot authenticate without first identifying; you cannot authorize without first authenticating; and auditing records the results of all prior steps.

Question Type 2: Identity Examples

Original: Which of the following is a primary example of an Identity?
📖 Source: 5_2_Identity.txt — "Identity is a claim… examples include username, email address, employee ID number. It is the public component—not a secret."
Variant A — Negative Selection
Which of the following is NOT an example of an identity?
Reveal Answer
Correct Answer: C) Fingerprint

A fingerprint is a Type 3 authentication factor (something you are), not an identity claim. Identities are public claims like usernames, email addresses, and employee IDs.

Variant B — Scenario-Based
When Sarah logs into her company portal, she first types "sarah.jones@company.com" into the login form. Which component of IAAA is she performing?
Reveal Answer
Correct Answer: C) Identification

Entering her email address is claiming her identity. Authentication comes next when she provides her password/MFA token.

Variant C — True/False
True or False: A password is considered an Identity because it uniquely identifies a user.
Reveal Answer
False

A password is an authentication factor (Type 1 — something you know). Identity is the public claim (username, email). Passwords are secret and used to prove that identity, not state it.

Variant D — Select All That Apply
Select ALL that are valid examples of an Identity: (a) Username, (b) Smart Card, (c) Employee Badge Number, (d) Email Address, (e) PIN Code
Reveal Answer
Correct: (a) Username, (c) Employee Badge Number, (d) Email Address

Smart Cards are "something you have" (authentication). PIN Codes are "something you know" (authentication). The remaining three are public identity claims.

Variant E — Conceptual / Short Answer
Explain why an identity must be unique within a system and give two examples of identities.
Reveal Answer
An identity must be unique so the system can distinguish one user from another for proper authentication, authorization, and auditing. Examples: email address, username, employee ID.

Question Type 3: Authentication Factor Types

Original: Match the Authentication Factor "Type" with the correct example.
📖 Source: 5_3_Authentication.txt — "Type 1 = Something you know (password, PIN), Type 2 = Something you have (smart card, OTP token), Type 3 = Something you are (biometrics — fingerprint, iris), Type 4 = Somewhere you are (geolocation technology)."
Variant A — Multiple Choice
A retinal scan is an example of which authentication factor type?
Reveal Answer
Correct Answer: C) Type 3 — Something you are

Retinal scans and all biometrics are Type 3 factors because they rely on your unique physical characteristics.

Variant B — Categorization
Categorize each into Type 1, 2, or 3: (a) Security Question, (b) RSA Token, (c) Voice Recognition, (d) Passphrase, (e) Smart Card, (f) Palm Vein Scan
Reveal Answer
Type 1 (Know): (a) Security Question, (d) Passphrase
Type 2 (Have): (b) RSA Token, (e) Smart Card
Type 3 (Are): (c) Voice Recognition, (f) Palm Vein Scan
Variant C — Scenario-Based
An employee swipes their company-issued smart card at a door reader. Which authentication factor type is being used?
Reveal Answer
Type 2 — Something you have

A smart card is a physical token the user possesses.

Variant D — True/False
True or False: A One-Time Password (OTP) sent to a user's phone is a Type 1 authentication factor because the user must "know" the code.
Reveal Answer
False

An OTP is Type 2 (something you have) because it depends on possession of the device receiving the code, not on memorized knowledge. The code itself is ephemeral and device-bound.

Variant E — Fill in the Blank
The four authentication factor types are: Type 1 = Something you ________, Type 2 = Something you ________, Type 3 = Something you ________, Type 4 = Somewhere you ________.
Reveal Answer
Know, Have, Are, Are (Geolocation)
Variant F — Type 4 Geolocation (Lecture 5.3)
A corporate VPN only allows login attempts from IP addresses originating within the United States. If an employee travels to another country, they are blocked. Which authentication factor type is this an example of?
Reveal Answer
Correct Answer: D) Type 4 — Somewhere you are

Type 4 authentication uses geolocation technology (GPS, IP geolocation) to verify a user's physical location as a factor. Per Lecture 5.3, this is the fourth valid authentication type.

Variant G — True/False (Type 4)
True or False: According to the lecture material, there are only three types of authentication factors.
Reveal Answer
False

Lecture 5.3 defines four types: Type 1 (Something you know), Type 2 (Something you have), Type 3 (Something you are), and Type 4 (Somewhere you are — Geolocation Technology).

Question Type 4: MFA vs. Single-Factor Authentication

Original: True or False: A username/password followed by a PIN is MFA.
📖 Source: 5_3_Authentication.txt — "Multi-Factor Authentication requires two or more different types of factors. Using two passwords is NOT MFA — both are Type 1."
Variant A — Multiple Choice
Which of the following scenarios is a valid example of Multi-Factor Authentication (MFA)?
Reveal Answer
Correct Answer: C) Password + Fingerprint Scan

Only option C combines two different factor types: Type 1 (password — know) + Type 3 (fingerprint — are). All other options combine two Type 1 factors.

Variant B — Scenario-Based
A bank requires customers to enter their PIN and then insert a physical chip card. Is this MFA? Explain why or why not.
Reveal Answer
Yes, this IS MFA.

A PIN is Type 1 (something you know) and a chip card is Type 2 (something you have). Two different factor types = MFA.

Variant C — True/False (Reworded)
True or False: Entering a password and then answering "What is your mother's maiden name?" constitutes Multi-Factor Authentication.
Reveal Answer
False

Both a password and a security question are Type 1 (something you know). MFA requires at LEAST two different types.

Variant D — Short Answer
What is the minimum requirement for a system to claim it uses Multi-Factor Authentication? Give an example combination.
Reveal Answer
The system must require at least two different types of authentication factors. Example: Password (Type 1) + OTP from a mobile app (Type 2).
Variant E — Select All That Apply
Which of the following are valid MFA combinations? (Select all)
(a) Password + OTP Token
(b) Iris Scan + Fingerprint
(c) Smart Card + Retinal Scan
(d) PIN + Password
(e) Passphrase + Smart Card + Fingerprint
Reveal Answer
Valid MFA: (a), (c), (e)

(a) Type 1 + Type 2 ✓ | (b) Type 3 + Type 3 ✗ (same type) | (c) Type 2 + Type 3 ✓ | (d) Type 1 + Type 1 ✗ | (e) Type 1 + Type 2 + Type 3 ✓ (three-factor)

Question Type 5: Role-Based Access Control (RBAC)

Original: Which method assigns permissions based on a user's role or job function?
📖 Source: 5_4_Authorization.txt — "RBAC assigns permissions to roles, not individuals. Users are placed in roles like 'HR Manager' or 'IT Admin'. When they change jobs, they simply move to a new role."
Variant A — Scenario-Based
A hospital assigns "Nurse", "Doctor", and "Admin" roles. Each role has specific system permissions. When Dr. Smith transfers departments, her permissions automatically update to match the new department's "Doctor" role. Which access control model is being used?
Reveal Answer
Correct Answer: C) RBAC

RBAC assigns permissions to roles. Moving a user to a different role automatically updates their permissions without individually editing access rights.

Variant B — Compare & Contrast
How does Role-Based Access Control (RBAC) differ from an Access Control List (ACL)?
Reveal Answer
RBAC assigns permissions to named roles (job functions), and users inherit permissions by being assigned to a role. An ACL is attached to a specific object (file, resource) and lists which users/groups can access that object and what operations they can perform. RBAC scales better in large organizations.
Variant C — True/False
True or False: In RBAC, individual users are directly assigned permissions to specific files and resources.
Reveal Answer
False

In RBAC, permissions are assigned to roles, not individual users. Users are then assigned to roles, inheriting the permissions associated with that role.

Variant D — Multiple Choice (Different Angle)
A firewall that blocks all traffic after 6:00 PM regardless of the user is an example of which type of access control?
Reveal Answer
Correct Answer: B) Rule-Based Access Control

Rule-based applies global conditions (time-of-day, IP range, etc.) uniformly. RBAC is specifically about job roles/functions. This is a common distractor pairing on exams.

Variant E — Fill in the Blank
In ________ access control, permissions follow the principle: "What does this job need access to?" rather than "What does this individual user need?"
Reveal Answer
Role-Based (RBAC)
Variant F — MAC vs. DAC (Lecture 5.4)
In which access control model does the system administrator (not the data owner) set all access permissions based on security labels and clearance levels?
Reveal Answer
Correct Answer: B) Mandatory Access Control (MAC)

In MAC, access decisions are made by the system based on security labels (e.g., Top Secret, Secret, Confidential) — not by the individual data owner. In DAC, the owner of the resource decides who gets access.

Variant G — ACL vs. Capability List (Lecture 5.4)
An Access Control Matrix can be decomposed in two ways. Which method is described as "column-based, organized by object" and which is "row-based, organized by subject"?
Reveal Answer
Column-based (by object) = Access Control List (ACL). Row-based (by subject) = Capability List.

Per Lecture 5.4: An ACL lists all subjects that can access a given object. A Capability List lists all objects a given subject can access. Both are derived from the Access Control Matrix to solve the sparse table problem.

Variant H — True/False (DAC)
True or False: In Discretionary Access Control (DAC), the owner of a file can grant or revoke access to other users at their own discretion.
Reveal Answer
True

DAC allows the data owner to control access. This is flexible but less secure than MAC because users may grant access carelessly. Most consumer operating systems (Windows, macOS) use DAC by default.

Question Type 6: Access Control Matrix (Sparse Table)

Original: True or False: An access control matrix is inefficient for large systems because of its sparse table.
📖 Source: 5_4_Authorization.txt — "An access control matrix maps every subject to every object… In large organizations this creates a 'sparse table' with many empty cells."
Variant A — Multiple Choice
What is the main scalability problem with an Access Control Matrix?
Reveal Answer
Correct Answer: B)

As user and resource counts grow, the matrix becomes enormous with most cells empty (no access), making it wasteful and hard to manage.

Variant B — Scenario-Based
A company with 10,000 employees and 50,000 files attempts to manage access using a table where each row is a user and each column is a file. Most employees only access about 20 files. What problem will this approach cause?
Reveal Answer
The table would have 500 million cells (10,000 × 50,000), but only about 200,000 would contain actual permissions. Over 99.9% of the cells would be empty—a classic sparse table problem that wastes memory and is nearly impossible to administer.
Variant C — Short Answer
Name two alternatives to an Access Control Matrix that solve the sparse table problem.
Reveal Answer
1) Access Control Lists (ACLs) — attach permission lists to individual objects. 2) Role-Based Access Control (RBAC) — assign permissions to roles rather than enumerating every user-object pair.
Variant D — True/False (Reworded)
True or False: An Access Control Matrix is the most efficient authorization mechanism for organizations with thousands of users and resources.
Reveal Answer
False

It is among the LEAST efficient for large-scale environments due to the sparse table problem. ACLs or RBAC are preferred.

Variant E — Capability List vs. ACL (Lecture 5.4)
A system stores a list for each user that says: "User Alice can access File1 (read), File2 (read/write), Printer1 (print)." This is organized by subject. What is this called?
Reveal Answer
Correct Answer: B) Capability List

A Capability List is created by dividing the Access Control Matrix row-wise (by subject). It records what each subject can access. An ACL is column-wise (by object) — it records who can access each object.

Question Type 7: Auditing / Accounting

Original: Logging data to verify if users have accessed unauthorized files is which step of IAAA?
📖 Source: 5_5_Auditing.txt — "Auditing involves tracking and recording user activity… verifying compliance… ensuring accountability through logs."
Variant A — Scenario-Based
After a data breach, the security team reviews server logs to determine which accounts accessed the compromised database and when. Which stage of IAAA is being leveraged?
Reveal Answer
Correct Answer: D) Auditing / Accounting

Reviewing logs after the fact to establish who did what and when is the core function of auditing.

Variant B — Short Answer
Why is Auditing considered essential for both security and compliance?
Reveal Answer
Auditing provides accountability by creating an irrefutable record of user actions. For security, it helps detect unauthorized access and breaches. For compliance, it provides the evidence needed to prove adherence to regulations (HIPAA, SOX, PCI-DSS, etc.).
Variant C — Multiple Choice (Different Angle)
Which of the following would be MOST useful during an audit?
Reveal Answer
Correct Answer: C) A detailed system access log with timestamps

Auditing depends on comprehensive logs that record who accessed what, when, and from where.

Variant D — True/False
True or False: Auditing only occurs after a security incident has been detected.
Reveal Answer
False

Auditing is a continuous process. Logs are generated in real-time during normal operations and are reviewed both routinely (for compliance) and reactively (after incidents).

Question Type 8: Subnet Host Addresses

Original: How many usable host addresses are available in the subnet 192.168.1.0/24?
📖 Source: Lecture 1.1_Network_Models.txt, Lecture 1_3_Network Communication.txt — "A /24 subnet has 256 total addresses. Subtract 2 (network address + broadcast) = 254 usable hosts."
Variant A — Different Subnet
How many usable host addresses are available in the subnet 10.0.0.0/16?
Reveal Answer
Correct Answer: B) 65,534

/16 = 16 host bits → 2^16 = 65,536 total − 2 (network + broadcast) = 65,534 usable.

Variant B — Conceptual
When calculating usable host addresses in a subnet, why must you always subtract 2 from the total number of addresses?
Reveal Answer
The first address (all host bits = 0) is reserved as the Network ID, and the last address (all host bits = 1) is reserved as the Broadcast Address. Neither can be assigned to a host.
Variant C — Calculation / Short Answer
A network has a /28 subnet mask. How many usable host addresses does it provide? Show your work.
Reveal Answer
/28 = 32 − 28 = 4 host bits → 2^4 = 16 total − 2 = 14 usable hosts.
Variant D — True/False
True or False: In a /24 network, the address 192.168.1.255 can be assigned to a host device.
Reveal Answer
False

192.168.1.255 is the broadcast address for the 192.168.1.0/24 subnet and cannot be assigned to any host.

Variant E — Formula-Based
What is the formula for calculating usable host addresses given a CIDR notation of /n?
Reveal Answer
Usable Hosts = 2^(32 − n) − 2

Where 32 is the total bits in an IPv4 address, n is the prefix length, and you subtract 2 for the network and broadcast addresses.

Question Type 9: Port-to-Service Mapping

Original: Match ports 22, 80, 443, 445 with SSH, HTTP, HTTPS, SMB.
📖 Source: Module_2.txt, Module 3.txt — "Common ports: 22 SSH, 80 HTTP, 443 HTTPS, 445 SMB… also 21 FTP, 23 Telnet, 25 SMTP, 53 DNS, 3389 RDP."
Variant A — Multiple Choice
Which port is used for encrypted web traffic (HTTPS)?
Reveal Answer
Correct Answer: C) 443
Variant B — Extended Matching (More Ports)
Match each port to its service: 21, 22, 23, 25, 53, 80, 443, 445, 3389
Reveal Answer
21 = FTP | 22 = SSH | 23 = Telnet | 25 = SMTP | 53 = DNS | 80 = HTTP | 443 = HTTPS | 445 = SMB | 3389 = RDP
Variant C — Scenario-Based
A network scan reveals an open port 445 on a Windows server. What service is likely running, and what type of attack might this be vulnerable to?
Reveal Answer
Port 445 runs SMB (Server Message Block) for Windows File Sharing. It has been the target of major exploits like EternalBlue (MS17-010), which was used by WannaCry ransomware.
Variant D — True/False
True or False: Port 22 is used for Telnet, a protocol that provides an unencrypted remote command-line interface.
Reveal Answer
False

Port 22 is SSH (Secure Shell), which is encrypted. Telnet runs on port 23 and is unencrypted.

Variant E — Security Implication
Why would a security analyst be concerned if they found port 23 (Telnet) open on a production server?
Reveal Answer
Telnet transmits data (including credentials) in plaintext, making it vulnerable to sniffing attacks. SSH (port 22) should be used instead as it encrypts all traffic.
Variant F — Extended Port Matching (Module 4)
Match each port to its service: 110, 123, 161, 389, 465, 587, 995
Reveal Answer
110 = POP3 | 123 = NTP (Network Time Protocol) | 161 = SNMP | 389 = LDAP | 465 = SMTPS (SMTP over SSL) | 587 = SMTP Submission (with STARTTLS) | 995 = POP3S (POP3 over SSL)
Variant G — Multiple Choice (LDAP/SNMP)
A network administrator needs to query a centralized directory to look up user accounts and group memberships. Which port and protocol would this traffic use?
Reveal Answer
Correct Answer: B) Port 389 — LDAP

LDAP (Lightweight Directory Access Protocol) on port 389 is used for directory services like Active Directory. SNMP (161) monitors network devices, POP3 (110) retrieves email, and NTP (123) synchronizes clocks.

Variant H — True/False (SNMP)
True or False: SNMP (Simple Network Management Protocol) uses ports 161 and 162 and is used for monitoring and managing network devices.
Reveal Answer
True

Port 161 is used for SNMP queries (polling devices), and port 162 is used for SNMP Traps (devices sending alerts to a management station).

Question Type 10: Vulnerability Scanning

Original: Which type of scanning compares results against a database of known signatures?
📖 Source: Module 3.txt — "Vulnerability scanning checks open ports and services against a CVE database… provides severity ratings and remediation guidance… Tools: Nessus, OpenVAS, Qualys."
Variant A — Compare & Contrast
What is the primary difference between a port scan and a vulnerability scan?
Reveal Answer
A port scan identifies which ports are open/closed/filtered on a target. A vulnerability scan goes further by probing those services, comparing them against a CVE/signature database, and reporting known vulnerabilities with severity levels and remediation steps.
Variant B — Multiple Choice (Tool-Focused)
Which of the following tools is primarily a vulnerability scanner?
Reveal Answer
Correct Answer: C) Nessus

Nmap is a port/network scanner. Wireshark is a packet analyzer. Netcat is a networking utility. Nessus is specifically designed for vulnerability assessment.

Variant C — Short Answer
What is a CVE database and how does a vulnerability scanner use it?
Reveal Answer
CVE (Common Vulnerabilities and Exposures) is a publicly available catalog of known security vulnerabilities, each with a unique ID. Vulnerability scanners compare the software versions and configurations they detect against CVE entries to identify known flaws and their severity.
Variant D — True/False
True or False: A vulnerability scanner can only detect network-level vulnerabilities and cannot identify web application flaws.
Reveal Answer
False

Modern vulnerability scanners (especially web application scanners like OWASP ZAP, Burp Suite, Nessus WAS) can detect web app flaws including XSS, SQL Injection, and path traversal.

Question Type 11: Legal Scanning Authorization

Original: True or False: Any user can legally scan any network because the Internet is open.
📖 Source: Module 3.txt — "Unauthorized scanning is illegal… requires explicit, documented permission… violations fall under CFAA."
Variant A — Scenario-Based
A security enthusiast discovers vulnerabilities on a local business's website using Nmap and Nessus, then emails the business about the findings. The enthusiast had no prior agreement with the business. Is this legal?
Reveal Answer
No, this is illegal.

Even with good intentions, scanning networks or systems without explicit, documented authorization violates computer fraud and abuse laws (e.g., the CFAA in the US). Always obtain written permission before testing.

Variant B — Multiple Choice
Before performing a penetration test on a client's network, what document should a tester obtain FIRST?
Reveal Answer
Correct Answer: B) Written authorization / Rules of Engagement

Without documented permission defining scope, timing, and methods, any scanning or testing is unauthorized and potentially illegal. (NDAs are also important but authorization comes first.)

Variant C — True/False (Reworded)
True or False: If you own a network, you can legally perform vulnerability scans on it without any additional authorization.
Reveal Answer
True

You have the legal right to scan and test systems you own. However, best practice is to still document the scope and ensure you don't accidentally scan systems outside your ownership (e.g., ISP or cloud infrastructure not covered by your agreement).

Question Type 12: NMAP Ping Scan / Host Discovery

Original: Which NMAP scan type is most useful for quickly identifying live hosts?
📖 Source: Module 3.txt — "Ping Scan (-sn) sends ICMP echo requests… skips port scanning… fastest method for host discovery."
Variant A — Command-Based
What does the Nmap flag -sn do?
Reveal Answer
Correct Answer: C)

-sn = "ping scan" or "no port scan." It only determines which hosts on the network are alive, without checking for open ports.

Variant B — Scenario-Based
You've been asked to quickly inventory all live devices on a 10.0.0.0/24 network. You don't need to know what services are running yet. Which Nmap scan type should you use?
Reveal Answer
Ping Scan: nmap -sn 10.0.0.0/24

This is the fastest way to enumerate live hosts without scanning ports.

Variant C — Compare & Contrast
Why is a Ping Scan faster than a TCP SYN Scan?
Reveal Answer
A Ping Scan only checks if hosts are alive (using ICMP/ARP), sending one or a few packets per host. A TCP SYN Scan probes individual ports (potentially thousands per host), requiring far more packets and time.
Variant D — True/False
True or False: A Ping Scan can identify which services are running on a target host.
Reveal Answer
False

A Ping Scan only identifies if a host is alive. To determine running services, you need a port scan (e.g., TCP SYN scan) and optionally a service/version detection scan (-sV).

Variant E — TCP ACK Scan (Module 4: -sA)
An Nmap scan returns results showing ports as either "filtered" or "unfiltered" but does NOT indicate whether ports are open or closed. Which scan type produces this kind of output?
Reveal Answer
Correct Answer: B) TCP ACK Scan (-sA)

The ACK scan doesn’t determine if ports are open/closed. Instead, it determines whether ports are filtered (blocked by a firewall) or unfiltered (reachable). It is primarily used for firewall rule mapping.

Variant F — XMAS Tree Scan (Module 4: -sX)
Which Nmap scan type sends packets with the FIN, URG, and PSH flags all set simultaneously, and gets its name from its packet resembling a “lit-up Christmas tree”?
Reveal Answer
Correct Answer: C) XMAS Tree Scan (-sX)

The XMAS scan sets FIN, URG, and PSH flags. If a port is closed, the target responds with RST. If open, there is no response. It can evade some simple firewalls and IDS that only look for SYN packets.

Variant G — Detection Evasion (Module 4: -D and -f)
Match each Nmap evasion technique to its flag and purpose:
1) Decoy Scan   2) Fragmented Packets
Reveal Answer
1) Decoy Scan (-D) — Spoofs additional source IP addresses so the target sees scan traffic from multiple IPs, making it harder to identify the real attacker.
2) Fragmented Packets (-f) — Splits probe packets into tiny IP fragments to evade packet inspection by firewalls and IDS that cannot reassemble fragments properly.

Question Type 13: UDP vs. TCP Scan Speed

Original: True or False: A UDP Scan is generally faster than a TCP SYN Scan because UDP is session-less.
📖 Source: Module 3.txt — "UDP scans are much slower… open ports may not respond at all… scanner must wait for timeouts… significantly longer than TCP scans."
Variant A — Multiple Choice
Why are UDP scans typically much slower than TCP SYN scans?
Reveal Answer
Correct Answer: B)

Because UDP is connectionless, an open port may simply accept the packet silently without responding. The scanner cannot distinguish between "open" and "filtered" without waiting for a timeout, which dramatically slows the scan.

Variant B — Compare & Contrast
Explain the key difference in how TCP SYN scans and UDP scans determine if a port is open.
Reveal Answer
TCP SYN scan: Sends a SYN packet. If the port is open, it receives a SYN-ACK back (definitive response). If closed, it gets a RST.

UDP scan: Sends a UDP packet. If the port is closed, it may get an ICMP "port unreachable" message. If the port is open, there may be NO response at all, requiring the scanner to wait for a timeout—making it ambiguous and slow.
Variant C — True/False (Reworded)
True or False: The lack of a response during a UDP scan definitively means the port is closed.
Reveal Answer
False

No response could mean the port is open (accepting traffic silently) OR filtered (a firewall dropped the packet). Only an ICMP "port unreachable" response definitively indicates a closed port.

Question Type 14: Vulnerability Scanner Attack Detection

Original: Which attacks can a Vulnerability Scanner help identify? (XSS, SQLi, Path Traversal)
📖 Source: Module 3.txt — "Vulnerability scanners can detect injection flaws, XSS, directory/path traversal… by sending test payloads to inputs."
Variant A — Multiple Choice (Negative)
Which of the following is LEAST likely to be detected by an automated vulnerability scanner?
Reveal Answer
Correct Answer: C) Business Logic Flaws

Automated scanners excel at detecting technical vulnerabilities (injection, XSS, traversal) by sending test payloads. Business logic flaws (like allowing a user to apply a discount code twice) require understanding of intended application behavior and typically need manual testing.

Variant B — Short Answer
Explain how a vulnerability scanner detects a SQL Injection vulnerability.
Reveal Answer
The scanner sends specially crafted SQL payloads (like ' OR 1=1 --) to input fields and URL parameters, then analyzes the response for signs of SQL errors, unexpected data returns, or behavior changes that indicate the input was executed as SQL code.
Variant C — Matching
Match the vulnerability type to its description:
1) XSS   2) SQL Injection   3) Path Traversal
Reveal Answer
1-b, 2-c, 3-a
Variant D — True/False
True or False: A vulnerability scanner can detect both Cross-Site Scripting (XSS) and SQL Injection vulnerabilities.
Reveal Answer
True

Modern vulnerability scanners are equipped to test for both by injecting test payloads and analyzing responses.

Question Type 15: CIA Triad + Authentication + Non-repudiation

Original: Match Confidentiality, Availability, Integrity, Authentication, and Non-repudiation with their descriptions.
📖 Source: Module_2.txt, 5_0_Introduction.txt — "CIA Triad: Confidentiality (encryption), Integrity (hashing), Availability (redundancy)… Non-repudiation: irrefutable proof of action."
Variant A — Multiple Choice (Single Concept)
Which security principle ensures that data has not been tampered with during transmission?
Reveal Answer
Correct Answer: B) Integrity

Integrity ensures data is only modified by authorized parties. Hashing algorithms (SHA-256, MD5) are commonly used to verify integrity.

Variant B — Scenario-Based
A hospital's patient records system goes down during a power outage and doctors cannot access critical information. Which principle of the CIA triad has been violated?
Reveal Answer
Availability

The data still exists and hasn't been stolen or modified, but it cannot be accessed when needed. UPS systems, redundancy, and failover clusters mitigate availability risks.

Variant C — Matching (Technologies)
Match each security technology to the CIA principle it primarily supports:
1) AES Encryption   2) SHA-256 Hash   3) RAID Storage   4) Digital Signatures
Reveal Answer
1) AES Encryption → Confidentiality
2) SHA-256 Hash → Integrity
3) RAID Storage → Availability
4) Digital Signatures → Non-repudiation (and Integrity)
Variant D — Short Answer
What is Non-repudiation and why is it important in digital communications?
Reveal Answer
Non-repudiation ensures that the sender of a message or performer of an action cannot deny doing so. It is achieved through digital signatures, audit trails, and logging. It is crucial for legal evidence, financial transactions, and contract enforcement in digital environments.
Variant E — True/False
True or False: Encrypting a file ensures both its Confidentiality and Integrity.
Reveal Answer
False (partially)

Encryption primarily ensures Confidentiality (only authorized parties can read it). While some encryption modes (like AES-GCM) provide integrity checks, standard encryption alone does not guarantee integrity. A separate hash or MAC is needed to verify data hasn't been modified.

Question Type 16: NIST and Standards Organizations

Original: Which organization develops cybersecurity standards, guidelines, and best practices?
📖 Source: Module_2.txt — "NIST (National Institute of Standards and Technology)… develops frameworks like NIST CSF… IEEE for hardware/networking standards (802.11)… IETF for internet protocols (RFCs)."
Variant A — Matching
Match each organization with its primary focus:
1) NIST   2) IEEE   3) IETF   4) PKCS
Reveal Answer
1-c, 2-d, 3-a, 4-b
Variant B — Multiple Choice (Specific Framework)
The NIST Cybersecurity Framework (CSF) is widely used by organizations to manage and reduce cybersecurity risk. Which agency publishes it?
Reveal Answer
Correct Answer: C) NIST

NIST publishes the CSF as well as SP 800-series publications covering topics from risk management to cryptographic standards.

Variant C — True/False
True or False: The IEEE is primarily responsible for developing standards for internet routing protocols like TCP/IP.
Reveal Answer
False

The IETF (Internet Engineering Task Force) manages TCP/IP and internet protocol standards through RFCs. IEEE focuses on hardware, networking standards (802.3 Ethernet, 802.11 Wi-Fi), and electrical engineering.

Variant D — Fill in the Blank
________ is a U.S. government agency that develops standards and guidelines for cybersecurity, including the widely-adopted ________ Cybersecurity Framework.
Reveal Answer
NIST; NIST (CSF)
Variant E — S/MIME and Email Security (Lecture 2.3)
Which standard, developed by the IETF, is used to ensure the authenticity, integrity, and confidentiality of email communications through digital signatures and encryption?
Reveal Answer
Correct Answer: B) S/MIME

S/MIME (Secure/Multipurpose Internet Mail Extensions) is an IETF standard for securing email with encryption and digital signatures. PKCS (Public Key Cryptography Standards) was developed by RSA Laboratories for general cryptographic operations. PGP is an alternative email encryption method. TLS secures transport-layer connections, not specifically email content.

Variant F — PKCS (Lecture 2.3)
True or False: The Public Key Cryptography Standards (PKCS) were developed by the IEEE to standardize wireless networking protocols.
Reveal Answer
False

PKCS was developed by RSA Laboratories (not IEEE) to standardize public-key cryptographic operations such as key exchange, digital signatures, and certificate requests. IEEE develops networking standards like 802.11 (Wi-Fi).

Question Type 17: Threat Definitions (Social Engineering, Trojan, DDoS)

Original: True/False on Social Engineering, Trojans, and DDoS definitions.
📖 Source: Module_2.txt, Module 3.txt — "Social engineering tricks humans… Trojans disguise as legitimate software but do NOT self-replicate… Worms auto-replicate… DDoS uses many machines (botnet) to overwhelm a target."
Variant A — Multiple Choice
Which type of malware disguises itself as legitimate software but does NOT self-replicate?
Reveal Answer
Correct Answer: C) Trojan

Trojans masquerade as useful programs. Worms self-replicate automatically. Viruses attach to files and require user action to spread.

Variant B — Matching
Match each malware type to its key characteristic:
1) Worm   2) Trojan   3) Virus   4) Ransomware
Reveal Answer
1-b, 2-c, 3-d, 4-a
Variant C — Scenario-Based
An attacker calls a company receptionist, pretends to be from IT support, and asks for the receptionist's login credentials "to fix a network issue." What type of threat is this?
Reveal Answer
Social Engineering (specifically, Pretexting or Vishing — voice phishing)

Social engineering manipulates humans into divulging sensitive information by exploiting trust and authority.

Variant D — Compare & Contrast
What is the difference between a DoS attack and a DDoS attack?
Reveal Answer
A DoS (Denial of Service) attack comes from a single source flooding a target. A DDoS (Distributed DoS) attack uses many compromised machines (a botnet) to simultaneously flood the target, making it much harder to block and far more powerful.
Variant E — True/False (Reworded)
True or False: A worm requires user interaction (like opening an email attachment) to propagate to other systems.
Reveal Answer
False

Worms self-replicate and spread automatically without user interaction, often exploiting network vulnerabilities. Viruses and Trojans typically require user action.

Variant F — Historical Malware Matching (Lecture Material)
Match each historical malware to its key characteristic or significance:
1) Morris Worm   2) Code Red   3) SQL Slammer   4) Michelangelo
Reveal Answer
1-b, 2-a, 3-c, 4-d

The Morris Worm (1988) was one of the first internet worms. Code Red exploited a buffer overflow in IIS. SQL Slammer exploited default blank admin passwords and propagated at record speed. Michelangelo was a date-triggered boot-sector virus.

Variant G — Scenario (Historical)
In 2003, a piece of malware infected over 75,000 SQL Server instances within 10 minutes by exploiting default blank administrator passwords. No user interaction was required. What type of malware was this, and what was its name?
Reveal Answer
SQL Slammer — a Worm

SQL Slammer was a worm because it self-replicated without user interaction, exploiting a known vulnerability (blank SA passwords) in Microsoft SQL Server.

Question Type 18: Attacker Categories

Original: Match descriptions with Hacktivism, Cyber Terrorism, and Cyber Criminals.
📖 Source: Module_2.txt — "Hacktivists are politically motivated… Cyber Terrorists cause fear through digital attacks… Cyber Criminals seek financial gain… Script Kiddies use tools without understanding… Nation States are government-sponsored."
Variant A — Multiple Choice
Anonymous, a group known for launching cyber attacks against governments and corporations that conflict with their political views, would best be classified as:
Reveal Answer
Correct Answer: B) Hacktivists

Hacktivists are politically or ideologically motivated, using hacking to promote their cause or protest organizations they oppose.

Variant B — Extended Matching
Categorize each attacker:
(a) A group deploys ransomware to extort millions from companies
(b) A teenager uses downloaded hacking tools to deface a website for fun
(c) A group attacks power grid infrastructure to instill fear
(d) A foreign government sponsors hackers to steal trade secrets
(e) Protesters DDoS a bank's website after a controversial policy
Reveal Answer
(a) Cyber Criminals
(b) Script Kiddie
(c) Cyber Terrorist
(d) Nation-State Actor
(e) Hacktivist
Variant C — Short Answer
What distinguishes a Hacktivist from a Cyber Criminal?
Reveal Answer
The primary motivation: Hacktivists are driven by political or ideological beliefs (activism). Cyber Criminals are driven specifically by financial gain (profit). Both may use similar techniques, but their goals differ.
Variant D — True/False
True or False: Cyber Terrorism is primarily motivated by financial gain.
Reveal Answer
False

Cyber Terrorism is motivated by a desire to cause fear, panic, or damage based on political, religious, or ideological objectives—not financial gain. Financial motivation characterizes Cyber Criminals.

Question Type 19: Network Reconnaissance Tools

Original: Match Ping, Trace Route, NSLookup, and Whois with their capabilities.
📖 Source: Module 3.txt, Lecture 1_3_Network Communication.txt — "Ping uses ICMP… Traceroute maps packet paths and hops… NSLookup queries DNS… Whois provides domain registration/ownership info."
Variant A — Multiple Choice
You want to find out who registered the domain "example.com" and when it expires. Which tool would you use?
Reveal Answer
Correct Answer: D) Whois

Whois queries domain registration databases to reveal ownership, registrar, creation/expiration dates, and often contact information.

Variant B — Scenario-Based
A user reports that the website "shop.company.com" is loading slowly. You want to see where the network delay is occurring along the route. Which tool do you use?
Reveal Answer
Traceroute (tracert on Windows, traceroute on Mac/Linux)

Traceroute shows each hop (router) along the path to the destination and the latency at each hop, helping you identify where delays occur.

Variant C — Command-Based
What is the difference between these two commands?
ping 8.8.8.8
traceroute 8.8.8.8
Reveal Answer
ping sends ICMP echo requests to check if the host is reachable and measures round-trip time. traceroute maps every intermediate router (hop) between your machine and the destination, showing the full network path and latency at each hop.
Variant D — Select All That Apply
Which of the following tools can be used during the reconnaissance phase of a penetration test? (Select all)
(a) Ping   (b) NSLookup   (c) Whois   (d) Traceroute   (e) Nmap
Reveal Answer
All of them: (a), (b), (c), (d), (e)

All five tools gather information about targets—live hosts, DNS records, domain ownership, network paths, and open ports.

Question Type 20: NSLookup Reverse Resolution

Original: True or False: NSLookup can only resolve domain→IP, not IP→domain.
📖 Source: Module 3.txt — "NSLookup can perform both forward (domain → IP) and reverse (IP → domain) lookups using PTR records."
Variant A — Multiple Choice
What type of DNS record is queried when performing a reverse DNS lookup (IP → domain)?
Reveal Answer
Correct Answer: D) PTR Record

PTR (Pointer) records map IP addresses back to domain names. A records do the opposite (domain → IP). CNAME is an alias. MX is for mail servers.

Variant B — Command-Based
How would you use NSLookup to find the domain name associated with IP address 93.184.216.34?
Reveal Answer
nslookup 93.184.216.34

Simply passing an IP address to nslookup triggers a reverse DNS lookup, querying PTR records to return the associated hostname.

Variant C — Short Answer
Name two types of DNS lookups that NSLookup can perform and describe each.
Reveal Answer
1) Forward Lookup: Resolves a domain name (e.g., google.com) to an IP address by querying A/AAAA records.
2) Reverse Lookup: Resolves an IP address to a domain name by querying PTR records.
Variant D — True/False (DNS Record Focus)
True or False: An "A Record" in DNS maps an IP address to a domain name.
Reveal Answer
False

An A Record maps a domain name to an IPv4 address (forward lookup). A PTR Record maps an IP address back to a domain name (reverse lookup).

Variant E — DNS Record Type Matching (Lecture 2.4)
Match each DNS record type to its function:
1) A   2) AAAA   3) MX   4) NS   5) CNAME   6) TXT   7) PTR
Reveal Answer
1) A — Maps a domain name to an IPv4 address
2) AAAA — Maps a domain name to an IPv6 address
3) MX — Specifies the mail exchange server(s) for a domain
4) NS — Identifies the authoritative name server(s) for a domain
5) CNAME — Creates an alias that points one domain name to another
6) TXT — Stores arbitrary text information (used for SPF, DKIM, domain verification)
7) PTR — Maps an IP address back to a domain name (reverse lookup)
Variant F — Multiple Choice (MX Record)
When you send an email to user@example.com, your mail server queries DNS to find out which server handles mail for example.com. Which DNS record type is queried?
Reveal Answer
Correct Answer: C) MX Record

MX (Mail Exchange) records specify which server(s) should receive email for a given domain. NS records identify the authoritative DNS server, not the mail server.

Variant G — True/False (AAAA vs. A)
True or False: An AAAA record serves the same function as an A record but maps a domain name to an IPv6 address instead of IPv4.
Reveal Answer
True

An A record maps domain → IPv4. An AAAA record maps domain → IPv6. The "AAAA" name reflects that IPv6 addresses are four times as long as IPv4.

Question Type 21: Root Name Servers

Original: How many Root Name Servers exist globally?
📖 Source: Module 3.txt — "13 logical root name server IP addresses (A through M)… managed by different organizations… hundreds of physical servers via Anycast."
Variant A — Multiple Choice (Reworded)
The global DNS root server system consists of how many unique logical server identities?
Reveal Answer
Correct Answer: B) 13

Named A through M. While there are hundreds of physical servers worldwide, they share only 13 IP addresses via Anycast routing.

Variant B — Short Answer
Explain how there can be only 13 root server IPs but hundreds of physical root servers worldwide.
Reveal Answer
Anycast routing allows multiple physical servers spread across different geographic locations to share the same IP address. When a DNS query is sent to a root server IP, the network routes it to the nearest physical instance, providing redundancy and low latency without needing more than 13 logical addresses.
Variant C — True/False
True or False: Each of the 13 root name servers is operated by the same organization.
Reveal Answer
False

The 13 root servers are managed by 12 different organizations including Verisign, ICANN, NASA, US Army, and various universities and research institutions.

Variant D — Conceptual
What role do Root Name Servers play in the DNS resolution process?
Reveal Answer
Root Name Servers are the first step in resolving a domain name when the answer isn't cached. They don't store individual domain records; instead, they direct queries to the appropriate Top-Level Domain (TLD) servers (e.g., .com, .org, .net), which then point to the authoritative name servers for the specific domain.

Question Type 22: Metasploit Payload Types

Original: Match Singles, Stagers, and Stages with their functionality.
📖 Source: Module_4.txt — "Singles: self-contained payloads… Stagers: tiny, establish connection back to attacker… Stages: larger payloads downloaded by stagers."
Variant A — Multiple Choice
In Metasploit, a small payload whose only job is to establish a communication channel between the attacker and victim is called a:
Reveal Answer
Correct Answer: B) Stager

Stagers are intentionally tiny so they fit within exploit buffer constraints. Their sole purpose is to open a connection, then download the larger Stage payload.

Variant B — Scenario-Based
An attacker exploits a buffer overflow vulnerability. Due to the limited buffer size, they can only inject a very small payload. This payload connects back to their server and downloads a full Meterpreter shell. Identify which payload types are being used and in what order.
Reveal Answer
First: A Stager (small payload that fits in the buffer and establishes the connection). Second: A Stage (the full Meterpreter shell downloaded by the stager).
Variant C — Compare & Contrast
What is the difference between a Single payload and a Stager + Stage combination in Metasploit?
Reveal Answer
A Single is completely self-contained — it performs its entire function in one payload (e.g., adding a user account). A Stager + Stage combination splits the work: the stager is small and only establishes a connection, then the Stage (the larger, feature-rich payload) is downloaded through that connection. The split approach is used when exploit buffer sizes are too small for the full payload.
Variant D — Naming Convention
In Metasploit, how can you tell the difference between a Single payload and a Stager/Stage payload just by looking at the payload name?
Reveal Answer
Singles use underscores ( _ ) between components: e.g., windows/shell_reverse_tcp. Stager/Stage combinations use forward slashes ( / ): e.g., windows/shell/reverse_tcp. The extra "/" separates the stage from the stager.
Variant E — True/False
True or False: A "Stage" payload in Metasploit is designed to be as small as possible to fit within an exploit's buffer space.
Reveal Answer
False

That describes a Stager, not a Stage. Stages are the larger payloads that get downloaded after the stager has already established a connection. Stages don't have the same size constraints because they're sent over the established channel.

Question Type 23: Meterpreter

Original: Which payload provides an interactive session between attacker and victim?
📖 Source: Module_4.txt — "Meterpreter is an advanced, dynamically extensible payload… runs entirely in memory… provides interactive command shell… can dump hashes, pivot, migrate processes."
Variant A — Multiple Choice (Feature-Focused)
Which Metasploit payload operates entirely in memory, never writing to disk, making it particularly difficult for antivirus to detect?
Reveal Answer
Correct Answer: B) Meterpreter

Meterpreter is designed to reside entirely in memory through DLL injection, never touching the disk, which is a key reason it evades many traditional antivirus solutions.

Variant B — Short Answer
List three things an attacker can do with a Meterpreter session.
Reveal Answer
1) Dump password hashes (hashdump)
2) Take screenshots or record keystrokes
3) Pivot to other systems on the network
(Also: migrate between processes, upload/download files, execute commands, escalate privileges, enable RDP, clear event logs)
Variant C — True/False
True or False: Meterpreter writes itself to the victim's hard drive as an executable file.
Reveal Answer
False

Meterpreter resides entirely in memory using DLL injection. This "fileless" approach helps it avoid detection by file-based antivirus scanners.

Variant D — Scenario-Based
After exploiting a vulnerability, an attacker gains a session that allows them to run hashdump, screenshot, getsystem, and portfwd commands on the victim machine. What type of session do they have?
Reveal Answer
A Meterpreter session

These are all Meterpreter-specific commands. A basic shell would not have these capabilities without additional tools.

Variant E — Compare & Contrast
What advantages does a Meterpreter session offer over a basic command shell?
Reveal Answer
Meterpreter advantages over a basic shell:
• Runs in memory (no files on disk = stealthier)
• Encrypted communication channel
• Dynamically extensible (load new modules on-the-fly)
• Built-in commands for privilege escalation, pivoting, hash dumping, keylogging, and more
• Can migrate between processes to avoid detection
• A basic shell only provides command-line access with no advanced post-exploitation features

Question Type 24: Kerberos & PKI Components

New: Match Kerberos components to their functions.
📖 Source: 5_3_Authentication.txt — "Kerberos uses a Key Distribution Center (KDC) consisting of an Authentication Server (AS) and a Ticket Granting Server (TGS)… tickets prove identity without resending credentials."
Variant A — Matching
Match each Kerberos component to its function:
1) Key Distribution Center (KDC)   2) Authentication Server (AS)   3) Ticket Granting Server (TGS)   4) Ticket Granting Ticket (TGT)
Reveal Answer
1) KDC — The trusted third party that manages the entire ticketing system; contains both the AS and TGS.
2) AS — Handles the initial authentication of a user and issues a Ticket Granting Ticket (TGT).
3) TGS — Accepts the TGT and issues service-specific tickets allowing access to particular resources.
4) TGT — A time-limited token issued by the AS that proves the user has already authenticated; presented to the TGS to request service tickets.
Variant B — Scenario-Based (Kerberos Flow)
Alice wants to access a file server. She first logs in with her password. The system verifies her credentials and gives her a special token. She then presents this token to request access specifically to the file server, and receives a service ticket. Identify each Kerberos step.
Reveal Answer
Step 1: Alice authenticates to the Authentication Server (AS) with her credentials.
Step 2: The AS issues a Ticket Granting Ticket (TGT).
Step 3: Alice presents the TGT to the Ticket Granting Server (TGS).
Step 4: The TGS issues a Service Ticket for the file server.
Step 5: Alice presents the Service Ticket to the file server to gain access.
Variant C — Multiple Choice
In Kerberos, which component is the trusted third party that manages the entire authentication and ticketing process?
Reveal Answer
Correct Answer: C) Key Distribution Center (KDC)

The KDC is the central trusted authority that contains both the AS and TGS. A Certificate Authority (CA) is part of PKI, not Kerberos.

Variant D — True/False
True or False: In Kerberos, a user must re-enter their password every time they want to access a different network resource.
Reveal Answer
False

Kerberos provides Single Sign-On (SSO). After the initial authentication, the user receives a TGT that can be presented to the TGS to obtain service tickets for different resources without re-entering credentials.

Variant E — Short Answer (Kerberos vs. PKI)
What is the key difference between Kerberos authentication and PKI (Public Key Infrastructure) authentication?
Reveal Answer
Kerberos uses symmetric-key cryptography and a centralized trusted third party (KDC) that issues time-limited tickets. PKI uses asymmetric (public/private) key pairs and digital certificates issued by a Certificate Authority (CA). Kerberos is typically used within a single organization's network (e.g., Active Directory), while PKI is used for broader trust (e.g., HTTPS, S/MIME).

Question Type 25: Network Topologies

New: Identify characteristics and failure points of network topologies.
📖 Source: Lecture 1_2_Network Topologies.txt — "Ring topology: failure of a single node can disrupt the entire network… Star: dependent on a centralized server/hub… Bus: shares a medium, requires collision controls."
Variant A — Matching
Match each topology to its primary vulnerability:
1) Ring   2) Star   3) Bus   4) Mesh
Reveal Answer
1-b, 2-a, 3-c, 4-d
Variant B — Scenario-Based
A company’s network uses a central switch. All 50 computers connect directly to this switch. When the switch fails, the entire office loses network connectivity. Which topology is this, and what is its weakness?
Reveal Answer
Star Topology. Its weakness is the single point of failure at the central device (switch/hub). If that device fails, all connected nodes lose connectivity.
Variant C — Multiple Choice
In which topology does data travel in one direction around a loop, and the failure of a single node can disrupt communication for all nodes?
Reveal Answer
Correct Answer: C) Ring

In a ring topology, each node connects to exactly two others forming a circle. Data passes sequentially. A break at any point disrupts the loop (unless a dual-ring/FDDI configuration is used).

Variant D — True/False
True or False: A Bus topology uses a shared communication medium and requires a mechanism like CSMA/CD to handle data collisions.
Reveal Answer
True

In a bus topology, all devices share a single cable (backbone). CSMA/CD (Carrier Sense Multiple Access with Collision Detection) is used to manage collisions when multiple devices transmit simultaneously.

Variant E — Network Scope Classification (Lecture 1.1)
Classify each network by its geographic scope:
1) Connects devices within a single building   2) Spans a city or campus   3) Connects networks across countries or continents
Reveal Answer
1) LAN (Local Area Network)
2) MAN (Metropolitan Area Network)
3) WAN (Wide Area Network)

Question Type 26: Disaster Management Categorization

New: Categorize disaster scenarios by severity level.
📖 Source: Module 3.txt (Lecture 3.4) — "Low-level: human errors, single server failure. Medium-level: virus attacks, prolonged power failures. High-level: earthquakes, fires, terrorism."
Variant A — Categorization
Categorize each event as Low, Medium, or High-level disaster:
(a) An intern accidentally deletes a database table
(b) A ransomware attack encrypts 60% of company servers
(c) An earthquake destroys the primary data center
(d) A single web server crashes due to a software bug
(e) A power outage lasts 48 hours affecting multiple systems
(f) A terrorist bomb threat forces evacuation of the building
Reveal Answer
Low: (a) Human error, (d) Single server failure
Medium: (b) Virus/ransomware attack, (e) Prolonged power failure
High: (c) Earthquake/natural disaster, (f) Terrorism
Variant B — Multiple Choice
According to disaster management classification, a widespread virus attack that takes down multiple systems for several days would be categorized as:
Reveal Answer
Correct Answer: B) Medium-level disaster

Virus attacks and prolonged outages are medium-level. High-level is reserved for events causing physical destruction or posing existential threats (natural disasters, terrorism, fires).

Variant C — Short Answer
What are the three levels of disaster categorization, and give one example of each?
Reveal Answer
Low-level: Minor incidents with limited impact (e.g., human error, single server failure).
Medium-level: Significant disruptions affecting multiple systems (e.g., virus/ransomware attacks, extended power failures).
High-level: Catastrophic events with widespread destruction (e.g., earthquakes, fires, terrorism).
Variant D — True/False
True or False: A single server failure caused by a software bug is classified as a High-level disaster.
Reveal Answer
False

A single server failure is a Low-level disaster. High-level disasters involve widespread physical destruction or threats such as earthquakes, fires, or terrorism.

Question Type 27: TCP/IP Model vs. OSI Model

New: Map protocols to their TCP/IP layers and compare TCP/IP to OSI.
📖 Source: Lecture 1_3_Network Communication.txt — "TCP/IP has 4 layers: Application, Transport, Internet/Network, Network Access… Transport layer contains TCP and UDP… Network layer uses IP and ICMP… Application layer includes HTTP, FTP, SMTP, DNS."
Variant A — Layer Mapping
Place each protocol into its correct TCP/IP layer:
HTTP, TCP, IP, ARP, FTP, UDP, ICMP, SMTP, DNS, Ethernet
Reveal Answer
Application Layer: HTTP, FTP, SMTP, DNS
Transport Layer: TCP, UDP
Internet/Network Layer: IP, ICMP
Network Access Layer: ARP, Ethernet
Variant B — Multiple Choice
In the TCP/IP model, which layer is responsible for end-to-end transport of messages between servers, and which two protocols operate at this layer?
Reveal Answer
Correct Answer: B) Transport Layer — TCP and UDP

The Transport Layer handles end-to-end communication. TCP provides reliable, connection-oriented delivery. UDP provides fast, connectionless delivery.

Variant C — OSI vs. TCP/IP Comparison
The OSI model has 7 layers while the TCP/IP model has 4. Which OSI layers are combined into the TCP/IP Application layer?
Reveal Answer
The TCP/IP Application layer combines OSI layers 5 (Session), 6 (Presentation), and 7 (Application).

Similarly, OSI layers 1 (Physical) and 2 (Data Link) combine into the TCP/IP Network Access layer.

Variant D — Scenario-Based
A network technician uses the ping command to test connectivity to a remote server. The ping command sends ICMP Echo Request packets. At which TCP/IP layer does ICMP operate?
Reveal Answer
Correct Answer: C) Internet/Network Layer

ICMP operates at the Internet (Network) layer alongside IP. It is used for error reporting and network diagnostics (ping, traceroute), not for transporting application data.

Variant E — True/False
True or False: DNS operates at the Transport layer of the TCP/IP model because it can use both TCP and UDP.
Reveal Answer
False

DNS is an Application layer protocol. While it does use UDP (port 53) for standard queries and TCP (port 53) for zone transfers, DNS itself operates at the Application layer. TCP and UDP are the Transport layer protocols it relies on.


📚 Total: 27 Question Types × ~5-7 Variants each = 150+ unique practice questions
Refined with lecture cross-referencing — Generated from /ExtractedText/