Skip to content

Module Assessment — Cybersecurity Fundamentals

Module Assessment — Cybersecurity Fundamentals

Section titled “Module Assessment — Cybersecurity Fundamentals”

Congratulations!

You have successfully completed Module 08 — Cybersecurity Fundamentals.

Throughout this module, you learned the foundational concepts that every cybersecurity professional must understand before working with enterprise environments, cloud platforms, and modern security technologies.

This assessment evaluates your understanding of the principles covered throughout the module and prepares you for more advanced cybersecurity and cloud security topics.


Item Details
Module Module 08 — Cybersecurity Fundamentals
Assessment Type Module Assessment
Questions 40
Question Types Multiple Choice & Scenario-Based
Passing Score 70%
Time Limit 60 Minutes
Difficulty Beginner to Intermediate

This assessment covers:

  • Security Mindset
  • CIA Triad
  • Risk Management
  • Threats
  • Vulnerabilities
  • Cyber Attacks
  • Security Controls
  • Defense in Depth
  • Zero Trust
  • Security Architecture
  • Secure Design
  • Security Operations
  • Enterprise Cybersecurity
  • Cybersecurity Career Paths

By completing this assessment, you should be able to:

  • Apply cybersecurity principles to enterprise environments.
  • Identify common cyber threats and vulnerabilities.
  • Understand risk management concepts.
  • Explain Zero Trust and Defense in Depth.
  • Describe secure system design principles.
  • Understand enterprise Security Operations.
  • Recognize different cybersecurity career paths.
  • Recommend appropriate security controls.

You have recently joined CloudNova Technologies as an Associate Cloud Security Engineer.

Before being assigned to production cloud environments, your manager wants to ensure that you understand the cybersecurity principles required to secure enterprise infrastructure.

You are asked to complete this assessment to demonstrate your readiness for real-world security responsibilities.


Before you begin:

  • Read each question carefully.
  • Choose the best answer.
  • Consider enterprise security best practices.
  • Think about real-world scenarios.
  • Review your answers before submitting.

What is the primary purpose of a Security Mindset?

  • A. Focus only on system functionality
  • B. Continuously identify and reduce security risks
  • C. Increase application performance
  • D. Eliminate networking

Answer: B


Which principle ensures information is only accessible to authorized users?

  • A. Integrity
  • B. Availability
  • C. Confidentiality
  • D. Accountability

Answer: C


Which principle ensures information remains accurate and unaltered?

  • A. Integrity
  • B. Confidentiality
  • C. Availability
  • D. Authentication

Answer: A


Which principle ensures systems remain operational when needed?

  • A. Confidentiality
  • B. Integrity
  • C. Availability
  • D. Authorization

Answer: C


The CIA Triad consists of:

  • A. Cloud, Internet, Access
  • B. Confidentiality, Integrity, Availability
  • C. Control, Inspection, Audit
  • D. Compliance, Identity, Authentication

Answer: B


Risk is best defined as:

  • A. Any software bug
  • B. The possibility that a threat exploits a vulnerability and causes harm
  • C. A firewall rule
  • D. A compliance requirement

Answer: B


Which of the following is a vulnerability?

  • A. Hacker
  • B. Weak Password
  • C. Firewall
  • D. Encryption

Answer: B


Which risk treatment strategy reduces risk by implementing security controls?

  • A. Avoidance
  • B. Acceptance
  • C. Mitigation
  • D. Transfer

Answer: C


Which document tracks identified risks within an organization?

  • A. Password Policy
  • B. Risk Register
  • C. Firewall Rule
  • D. Asset Inventory

Answer: B


Business Impact Analysis (BIA) helps organizations determine:

  • A. Employee salaries
  • B. Recovery priorities and business impact
  • C. Software licenses
  • D. Internet bandwidth

Answer: B


Which threat actor is primarily motivated by financial gain?

  • A. Cybercriminal
  • B. Security Engineer
  • C. Auditor
  • D. System Administrator

Answer: A


Which attack commonly tricks users into revealing credentials?

  • A. SQL Injection
  • B. Phishing
  • C. Buffer Overflow
  • D. DDoS

Answer: B


What is a Zero-Day vulnerability?

  • A. A vulnerability that has already been patched
  • B. A vulnerability with no available fix or public awareness
  • C. A weak password
  • D. A backup failure

Answer: B


What does CVE stand for?

  • A. Cloud Verification Engine
  • B. Common Vulnerabilities and Exposures
  • C. Critical Vulnerability Evaluation
  • D. Cyber Validation Environment

Answer: B


Which score represents the highest severity in CVSS?

  • A. Low
  • B. Medium
  • C. High
  • D. Critical (9.0–10.0)

Answer: D


Which stage of the Cyber Kill Chain involves gathering information about the target?

  • A. Delivery
  • B. Reconnaissance
  • C. Installation
  • D. Actions on Objectives

Answer: B


Which security control primarily prevents unauthorized access?

  • A. Firewall
  • B. Incident Report
  • C. Audit Meeting
  • D. Business Continuity Plan

Answer: A


Which type of control detects malicious activity?

  • A. Detective Control
  • B. Preventive Control
  • C. Administrative Control
  • D. Physical Control

Answer: A


Which strategy uses multiple layers of security controls?

  • A. Password Reuse
  • B. Defense in Depth
  • C. Single Sign-On
  • D. Shared Responsibility

Answer: B


Which control restores business operations after an incident?

  • A. Recovery Control
  • B. Detective Control
  • C. Preventive Control
  • D. Deterrent Control

Answer: A


Section 5 — Zero Trust & Security Architecture

Section titled “Section 5 — Zero Trust & Security Architecture”

Zero Trust follows which guiding principle?

  • A. Trust Everyone
  • B. Never Trust, Always Verify
  • C. Internal Networks are Always Safe
  • D. Authentication Happens Only Once

Answer: B


What is the goal of Least Privilege?

  • A. Grant administrator access to everyone
  • B. Provide only the permissions required
  • C. Disable user accounts
  • D. Share privileged accounts

Answer: B


Micro-Segmentation helps:

  • A. Increase storage capacity
  • B. Limit attacker movement between systems
  • C. Improve CPU performance
  • D. Replace firewalls

Answer: B


Security Architecture primarily provides:

  • A. A software license
  • B. A secure blueprint for enterprise systems
  • C. A backup schedule
  • D. A vulnerability database

Answer: B


Trust Boundaries separate:

  • A. Departments
  • B. Security zones with different trust levels
  • C. Databases
  • D. User accounts

Answer: B


Which principle ensures systems deny access when failures occur?

  • A. Secure Defaults
  • B. Fail Secure
  • C. Open Design
  • D. Complete Mediation

Answer: B


Which principle recommends keeping security mechanisms as simple as possible?

  • A. Economy of Mechanism
  • B. Least Privilege
  • C. Defense in Depth
  • D. Separation of Duties

Answer: A


Which principle requires verifying every access request?

  • A. Open Design
  • B. Complete Mediation
  • C. Fail Open
  • D. Shared Responsibility

Answer: B


Shift Left Security means:

  • A. Delay security until production
  • B. Integrate security early in development
  • C. Remove security testing
  • D. Reduce monitoring

Answer: B


Which Secure Design principle separates critical tasks between multiple individuals?

  • A. Secure Defaults
  • B. Separation of Duties
  • C. Economy of Mechanism
  • D. Open Design

Answer: B


What is the primary purpose of a Security Operations Center (SOC)?

  • A. Build software
  • B. Monitor, detect, investigate, and respond to security events
  • C. Manage payroll
  • D. Design office buildings

Answer: B


Which technology centralizes security logs and correlates events?

  • A. VPN
  • B. SIEM
  • C. IDS
  • D. DNS

Answer: B


Threat Hunting is:

  • A. Waiting for alerts only
  • B. Proactively searching for hidden threats
  • C. Installing software updates
  • D. Creating user accounts

Answer: B


Which phase comes after Containment in Incident Response?

  • A. Recovery
  • B. Eradication
  • C. Preparation
  • D. Detection

Answer: B


MTTD stands for:

  • A. Mean Time to Detect
  • B. Maximum Threat Detection Delay
  • C. Managed Threat Tracking Database
  • D. Mean Threat Tracking Duration

Answer: A


Who is primarily responsible for defining an organization’s cybersecurity strategy?

  • A. SOC Analyst
  • B. Network Engineer
  • C. Chief Information Security Officer (CISO)
  • D. Help Desk Technician

Answer: C


Which framework is widely used to improve enterprise cybersecurity programs?

  • A. HTML
  • B. NIST Cybersecurity Framework
  • C. SMTP
  • D. FTP

Answer: B


Which team primarily manages governance, risk, and compliance activities?

  • A. SOC
  • B. DevOps
  • C. GRC
  • D. Help Desk

Answer: C


Which cybersecurity career focuses on designing secure enterprise solutions?

  • A. Security Architect
  • B. SOC Analyst
  • C. Help Desk Engineer
  • D. Database Administrator

Answer: A


Which statement best summarizes Enterprise Cybersecurity?

  • A. It focuses only on firewalls.
  • B. It combines people, processes, technology, governance, and continuous improvement to protect organizational assets.
  • C. It replaces cloud computing.
  • D. It eliminates all cyber risks.

Answer: B


Congratulations on completing the Cybersecurity Fundamentals Module Assessment.

If you achieved a score of 70% or higher, you have demonstrated a solid understanding of:

  • Security Mindset
  • CIA Triad
  • Risk Management
  • Threats & Vulnerabilities
  • Cyber Attacks
  • Security Controls
  • Defense in Depth
  • Zero Trust
  • Security Architecture
  • Secure Design
  • Security Operations
  • Enterprise Cybersecurity
  • Cybersecurity Career Paths

These concepts provide the foundation for every cybersecurity specialization, including Cloud Security, DevSecOps, Security Operations, Penetration Testing, Governance, Risk & Compliance, Digital Forensics, and Security Architecture.


🎉 You have successfully completed Module 08 — Cybersecurity Fundamentals.

You now possess the core cybersecurity knowledge required to begin securing enterprise systems, cloud platforms, and modern applications.

This foundation will support everything you learn in advanced modules and throughout your cybersecurity career.


➡️ Module 09 — Identity & Access Management (IAM)

In the next module, you’ll learn how enterprise organizations manage digital identities, control access to resources, and implement secure authentication and authorization across cloud, hybrid, and on-premises environments.

You’ll explore:

  • Identity & Access Management (IAM) Fundamentals
  • Authentication
  • Authorization
  • Multi-Factor Authentication (MFA)
  • Identity Federation
  • Single Sign-On (SSO)
  • Role-Based Access Control (RBAC)
  • Attribute-Based Access Control (ABAC)
  • Privileged Access Management (PAM)
  • Identity Governance & Administration (IGA)
  • Enterprise IAM Architecture

Identity is the foundation of modern cybersecurity and Zero Trust. Mastering IAM is essential for Cloud Security Engineers, Security Engineers, DevSecOps Engineers, SOC Analysts, Security Architects, and anyone responsible for securing enterprise environments.

Welcome to Module 09 — Identity & Access Management! 🔐