Network Security
Threats & Attacks
Authentication & Access Control
Cryptography
Security Best Practices
100

This device filters traffic between networks and blocks unauthorized access.

What is a firewall?

100

A fake email designed to trick users into revealing passwords or personal information.

What is phishing?

100

A security method requiring two forms of verification before access is granted.

What is multi-factor authentication (MFA)? 


100

The process of converting readable data into coded text.

What is encryption?

100

Regularly installing software patches helps fix these.

What are vulnerabilities?

200

The protocol commonly used for secure web browsing that encrypts traffic.

What is HTTPS?

200

Malware that locks files and demands payment for access.

What is ransomware?

200

Passwords should ideally include uppercase letters, lowercase letters, numbers, and these special symbols.

What are special characters?

200

AES is an example of this type of encryption where the same key encrypts and decrypts data.

What is symmetric encryption?

200

 Backing up data helps organizations recover from this type of malware attack.

What is ransomware?

300

This attack overwhelms a server with massive amounts of traffic to make it unavailable.

What is a DDoS attack?

300

This type of malware secretly records keystrokes on a computer.

What is a keylogger?

300

This biometric authentication method uses unique patterns inside the eye.

What is a retina scan?

300

RSA is an example of this type of encryption using public and private keys.

What is asymmetric encryption? 

300

Employees should lock their computers before leaving to prevent this type of unauthorized access.

What is physical access?

400

This wireless security protocol replaced WPA and provides stronger encryption for Wi-Fi networks.  

What is WPA3?

400

An attacker pretending to be tech support to gain sensitive information is using this type of attack.

What is social engineering?

400

The process of confirming a user's identity is called this.

What is authentication?

400

This cryptographic function converts data into a fixed-length value and is commonly used for password storage.

What is hashing?

400

This document outlines the rules and expectations for using company technology resources.

What is an acceptable use policy?

500

This principle gives users only the minimum permissions necessary to perform their job duties.

What is least privilege?

500

This attack intercepts communication between two parties without their knowledge.

What is a man-in-the-middle attack?

500

The security model where no user or device is automatically trusted is called this.

What is Zero Trust?

500

A digital certificate commonly uses this infrastructure to verify identity online.

What is PKI (Public Key Infrastructure)?

500

The practice of testing systems for weaknesses before attackers find them is called this.

What is penetration testing?