Unit 3: Securing Networks
Cybersecurity · Unit 3 · Paper 1

Securing Networks unit test

A test on this unit alone, marked as a percentage and a letter grade — for the test your class is actually sitting, rather than for May. Answer everything, then submit once: seeing the answer to question 3 before attempting question 4 makes the final percentage meaningless.

Each paper is built from this unit’s 40 terms and is the same for everyone, so a teacher can assign “Unit 3, Paper 1” and every student sits the identical test. Multiple choice is marked objectively; the written sections you mark yourself against the model answer and rubric.
Suggested time 33 min 30 points0/17 attempted
1

IP spoofing

2

SIEM

3

Rogue access point

4

Honeypot

5

SSID broadcast

6

Network segmentation

7

Implicit deny

8

Stateful firewall

9

DMZ (screened subnet)

10

Packet sniffing

11

WPA2

12

Next-generation firewall

Short answer 1. Define or explain: Firewall

3 pts

Short answer 2. Define or explain: WPA3

3 pts

Short answer 3. Define or explain: 802.1X

3 pts

Short answer 4. Define or explain: On-path (man-in-the-middle) attack

3 pts

Free response

6 pts

A company operates a single flat network. Guest Wi-Fi, employee workstations, printers, and the finance database server all share one address range, and the perimeter firewall contains a rule permitting any source to reach any destination on any port, which was added during a troubleshooting session two years ago.

Explain network segmentation and describe how VLANs would be applied in this environment.

Explain the default-deny principle and what is wrong with the existing firewall rule.

Explain the difference between a stateless access control list and a stateful firewall.

Explain what a DMZ is and identify what kind of system belongs in one.

Explain how a zero trust model differs from a traditional perimeter model.

Explain the difference between an intrusion detection system and an intrusion prevention system.