Module Assessment — Cybersecurity Fundamentals
Module Assessment — Cybersecurity Fundamentals
Section titled “Module Assessment — Cybersecurity Fundamentals”Assessment Overview
Section titled “Assessment Overview”Congratulations!
You have successfully completed Module 08 — Cybersecurity Fundamentals.
Throughout this module, you learned the foundational concepts that every cybersecurity professional must understand before working with enterprise environments, cloud platforms, and modern security technologies.
This assessment evaluates your understanding of the principles covered throughout the module and prepares you for more advanced cybersecurity and cloud security topics.
Assessment Information
Section titled “Assessment Information”| Item | Details |
|---|---|
| Module | Module 08 — Cybersecurity Fundamentals |
| Assessment Type | Module Assessment |
| Questions | 40 |
| Question Types | Multiple Choice & Scenario-Based |
| Passing Score | 70% |
| Time Limit | 60 Minutes |
| Difficulty | Beginner to Intermediate |
Skills Being Assessed
Section titled “Skills Being Assessed”This assessment covers:
- Security Mindset
- CIA Triad
- Risk Management
- Threats
- Vulnerabilities
- Cyber Attacks
- Security Controls
- Defense in Depth
- Zero Trust
- Security Architecture
- Secure Design
- Security Operations
- Enterprise Cybersecurity
- Cybersecurity Career Paths
Assessment Objectives
Section titled “Assessment Objectives”By completing this assessment, you should be able to:
- Apply cybersecurity principles to enterprise environments.
- Identify common cyber threats and vulnerabilities.
- Understand risk management concepts.
- Explain Zero Trust and Defense in Depth.
- Describe secure system design principles.
- Understand enterprise Security Operations.
- Recognize different cybersecurity career paths.
- Recommend appropriate security controls.
Enterprise Scenario
Section titled “Enterprise Scenario”You have recently joined CloudNova Technologies as an Associate Cloud Security Engineer.
Before being assigned to production cloud environments, your manager wants to ensure that you understand the cybersecurity principles required to secure enterprise infrastructure.
You are asked to complete this assessment to demonstrate your readiness for real-world security responsibilities.
Instructions
Section titled “Instructions”Before you begin:
- Read each question carefully.
- Choose the best answer.
- Consider enterprise security best practices.
- Think about real-world scenarios.
- Review your answers before submitting.
Section 1 — Security Fundamentals
Section titled “Section 1 — Security Fundamentals”Question 1
Section titled “Question 1”What is the primary purpose of a Security Mindset?
- A. Focus only on system functionality
- B. Continuously identify and reduce security risks
- C. Increase application performance
- D. Eliminate networking
Answer: B
Question 2
Section titled “Question 2”Which principle ensures information is only accessible to authorized users?
- A. Integrity
- B. Availability
- C. Confidentiality
- D. Accountability
Answer: C
Question 3
Section titled “Question 3”Which principle ensures information remains accurate and unaltered?
- A. Integrity
- B. Confidentiality
- C. Availability
- D. Authentication
Answer: A
Question 4
Section titled “Question 4”Which principle ensures systems remain operational when needed?
- A. Confidentiality
- B. Integrity
- C. Availability
- D. Authorization
Answer: C
Question 5
Section titled “Question 5”The CIA Triad consists of:
- A. Cloud, Internet, Access
- B. Confidentiality, Integrity, Availability
- C. Control, Inspection, Audit
- D. Compliance, Identity, Authentication
Answer: B
Section 2 — Risk Management
Section titled “Section 2 — Risk Management”Question 6
Section titled “Question 6”Risk is best defined as:
- A. Any software bug
- B. The possibility that a threat exploits a vulnerability and causes harm
- C. A firewall rule
- D. A compliance requirement
Answer: B
Question 7
Section titled “Question 7”Which of the following is a vulnerability?
- A. Hacker
- B. Weak Password
- C. Firewall
- D. Encryption
Answer: B
Question 8
Section titled “Question 8”Which risk treatment strategy reduces risk by implementing security controls?
- A. Avoidance
- B. Acceptance
- C. Mitigation
- D. Transfer
Answer: C
Question 9
Section titled “Question 9”Which document tracks identified risks within an organization?
- A. Password Policy
- B. Risk Register
- C. Firewall Rule
- D. Asset Inventory
Answer: B
Question 10
Section titled “Question 10”Business Impact Analysis (BIA) helps organizations determine:
- A. Employee salaries
- B. Recovery priorities and business impact
- C. Software licenses
- D. Internet bandwidth
Answer: B
Section 3 — Threats & Vulnerabilities
Section titled “Section 3 — Threats & Vulnerabilities”Question 11
Section titled “Question 11”Which threat actor is primarily motivated by financial gain?
- A. Cybercriminal
- B. Security Engineer
- C. Auditor
- D. System Administrator
Answer: A
Question 12
Section titled “Question 12”Which attack commonly tricks users into revealing credentials?
- A. SQL Injection
- B. Phishing
- C. Buffer Overflow
- D. DDoS
Answer: B
Question 13
Section titled “Question 13”What is a Zero-Day vulnerability?
- A. A vulnerability that has already been patched
- B. A vulnerability with no available fix or public awareness
- C. A weak password
- D. A backup failure
Answer: B
Question 14
Section titled “Question 14”What does CVE stand for?
- A. Cloud Verification Engine
- B. Common Vulnerabilities and Exposures
- C. Critical Vulnerability Evaluation
- D. Cyber Validation Environment
Answer: B
Question 15
Section titled “Question 15”Which score represents the highest severity in CVSS?
- A. Low
- B. Medium
- C. High
- D. Critical (9.0–10.0)
Answer: D
Section 4 — Attacks & Security Controls
Section titled “Section 4 — Attacks & Security Controls”Question 16
Section titled “Question 16”Which stage of the Cyber Kill Chain involves gathering information about the target?
- A. Delivery
- B. Reconnaissance
- C. Installation
- D. Actions on Objectives
Answer: B
Question 17
Section titled “Question 17”Which security control primarily prevents unauthorized access?
- A. Firewall
- B. Incident Report
- C. Audit Meeting
- D. Business Continuity Plan
Answer: A
Question 18
Section titled “Question 18”Which type of control detects malicious activity?
- A. Detective Control
- B. Preventive Control
- C. Administrative Control
- D. Physical Control
Answer: A
Question 19
Section titled “Question 19”Which strategy uses multiple layers of security controls?
- A. Password Reuse
- B. Defense in Depth
- C. Single Sign-On
- D. Shared Responsibility
Answer: B
Question 20
Section titled “Question 20”Which control restores business operations after an incident?
- A. Recovery Control
- B. Detective Control
- C. Preventive Control
- D. Deterrent Control
Answer: A
Section 5 — Zero Trust & Security Architecture
Section titled “Section 5 — Zero Trust & Security Architecture”Question 21
Section titled “Question 21”Zero Trust follows which guiding principle?
- A. Trust Everyone
- B. Never Trust, Always Verify
- C. Internal Networks are Always Safe
- D. Authentication Happens Only Once
Answer: B
Question 22
Section titled “Question 22”What is the goal of Least Privilege?
- A. Grant administrator access to everyone
- B. Provide only the permissions required
- C. Disable user accounts
- D. Share privileged accounts
Answer: B
Question 23
Section titled “Question 23”Micro-Segmentation helps:
- A. Increase storage capacity
- B. Limit attacker movement between systems
- C. Improve CPU performance
- D. Replace firewalls
Answer: B
Question 24
Section titled “Question 24”Security Architecture primarily provides:
- A. A software license
- B. A secure blueprint for enterprise systems
- C. A backup schedule
- D. A vulnerability database
Answer: B
Question 25
Section titled “Question 25”Trust Boundaries separate:
- A. Departments
- B. Security zones with different trust levels
- C. Databases
- D. User accounts
Answer: B
Section 6 — Secure Design
Section titled “Section 6 — Secure Design”Question 26
Section titled “Question 26”Which principle ensures systems deny access when failures occur?
- A. Secure Defaults
- B. Fail Secure
- C. Open Design
- D. Complete Mediation
Answer: B
Question 27
Section titled “Question 27”Which principle recommends keeping security mechanisms as simple as possible?
- A. Economy of Mechanism
- B. Least Privilege
- C. Defense in Depth
- D. Separation of Duties
Answer: A
Question 28
Section titled “Question 28”Which principle requires verifying every access request?
- A. Open Design
- B. Complete Mediation
- C. Fail Open
- D. Shared Responsibility
Answer: B
Question 29
Section titled “Question 29”Shift Left Security means:
- A. Delay security until production
- B. Integrate security early in development
- C. Remove security testing
- D. Reduce monitoring
Answer: B
Question 30
Section titled “Question 30”Which Secure Design principle separates critical tasks between multiple individuals?
- A. Secure Defaults
- B. Separation of Duties
- C. Economy of Mechanism
- D. Open Design
Answer: B
Section 7 — Security Operations
Section titled “Section 7 — Security Operations”Question 31
Section titled “Question 31”What is the primary purpose of a Security Operations Center (SOC)?
- A. Build software
- B. Monitor, detect, investigate, and respond to security events
- C. Manage payroll
- D. Design office buildings
Answer: B
Question 32
Section titled “Question 32”Which technology centralizes security logs and correlates events?
- A. VPN
- B. SIEM
- C. IDS
- D. DNS
Answer: B
Question 33
Section titled “Question 33”Threat Hunting is:
- A. Waiting for alerts only
- B. Proactively searching for hidden threats
- C. Installing software updates
- D. Creating user accounts
Answer: B
Question 34
Section titled “Question 34”Which phase comes after Containment in Incident Response?
- A. Recovery
- B. Eradication
- C. Preparation
- D. Detection
Answer: B
Question 35
Section titled “Question 35”MTTD stands for:
- A. Mean Time to Detect
- B. Maximum Threat Detection Delay
- C. Managed Threat Tracking Database
- D. Mean Threat Tracking Duration
Answer: A
Section 8 — Enterprise Cybersecurity
Section titled “Section 8 — Enterprise Cybersecurity”Question 36
Section titled “Question 36”Who is primarily responsible for defining an organization’s cybersecurity strategy?
- A. SOC Analyst
- B. Network Engineer
- C. Chief Information Security Officer (CISO)
- D. Help Desk Technician
Answer: C
Question 37
Section titled “Question 37”Which framework is widely used to improve enterprise cybersecurity programs?
- A. HTML
- B. NIST Cybersecurity Framework
- C. SMTP
- D. FTP
Answer: B
Question 38
Section titled “Question 38”Which team primarily manages governance, risk, and compliance activities?
- A. SOC
- B. DevOps
- C. GRC
- D. Help Desk
Answer: C
Question 39
Section titled “Question 39”Which cybersecurity career focuses on designing secure enterprise solutions?
- A. Security Architect
- B. SOC Analyst
- C. Help Desk Engineer
- D. Database Administrator
Answer: A
Question 40
Section titled “Question 40”Which statement best summarizes Enterprise Cybersecurity?
- A. It focuses only on firewalls.
- B. It combines people, processes, technology, governance, and continuous improvement to protect organizational assets.
- C. It replaces cloud computing.
- D. It eliminates all cyber risks.
Answer: B
Assessment Summary
Section titled “Assessment Summary”Congratulations on completing the Cybersecurity Fundamentals Module Assessment.
If you achieved a score of 70% or higher, you have demonstrated a solid understanding of:
- Security Mindset
- CIA Triad
- Risk Management
- Threats & Vulnerabilities
- Cyber Attacks
- Security Controls
- Defense in Depth
- Zero Trust
- Security Architecture
- Secure Design
- Security Operations
- Enterprise Cybersecurity
- Cybersecurity Career Paths
These concepts provide the foundation for every cybersecurity specialization, including Cloud Security, DevSecOps, Security Operations, Penetration Testing, Governance, Risk & Compliance, Digital Forensics, and Security Architecture.
Congratulations!
Section titled “Congratulations!”🎉 You have successfully completed Module 08 — Cybersecurity Fundamentals.
You now possess the core cybersecurity knowledge required to begin securing enterprise systems, cloud platforms, and modern applications.
This foundation will support everything you learn in advanced modules and throughout your cybersecurity career.
What’s Next?
Section titled “What’s Next?”➡️ Module 09 — Identity & Access Management (IAM)
In the next module, you’ll learn how enterprise organizations manage digital identities, control access to resources, and implement secure authentication and authorization across cloud, hybrid, and on-premises environments.
You’ll explore:
- Identity & Access Management (IAM) Fundamentals
- Authentication
- Authorization
- Multi-Factor Authentication (MFA)
- Identity Federation
- Single Sign-On (SSO)
- Role-Based Access Control (RBAC)
- Attribute-Based Access Control (ABAC)
- Privileged Access Management (PAM)
- Identity Governance & Administration (IGA)
- Enterprise IAM Architecture
Identity is the foundation of modern cybersecurity and Zero Trust. Mastering IAM is essential for Cloud Security Engineers, Security Engineers, DevSecOps Engineers, SOC Analysts, Security Architects, and anyone responsible for securing enterprise environments.
Welcome to Module 09 — Identity & Access Management! 🔐