Unit 3: Securing Networks
Cybersecurity · Unit 3 · Paper 2

Securing Networks unit test

A test on this unit alone, marked as a percentage and a letter grade — for the test your class is actually sitting, rather than for May. Answer everything, then submit once: seeing the answer to question 3 before attempting question 4 makes the final percentage meaningless.

Each paper is built from this unit’s 40 terms and is the same for everyone, so a teacher can assign “Unit 3, Paper 2” and every student sits the identical test. Multiple choice is marked objectively; the written sections you mark yourself against the model answer and rubric.
Suggested time 33 min 30 points0/17 attempted
1

Network segmentation

2

Lateral movement

3

Next-generation firewall

4

DNS poisoning

5

False positive vs false negative

6

WEP

7

SSID broadcast

8

On-path (man-in-the-middle) attack

9

802.1X

10

IDS vs IPS

11

Botnet

12

WPA3

Short answer 1. Define or explain: SIEM

3 pts

Short answer 2. Define or explain: Signature-based vs anomaly-based detection

3 pts

Short answer 3. Define or explain: ARP poisoning

3 pts

Short answer 4. Define or explain: WPA2

3 pts

Free response

6 pts

A company operates a single flat network. Guest Wi-Fi, employee workstations, printers, and the finance database server all share one address range, and the perimeter firewall contains a rule permitting any source to reach any destination on any port, which was added during a troubleshooting session two years ago.

Explain network segmentation and describe how VLANs would be applied in this environment.

Explain the default-deny principle and what is wrong with the existing firewall rule.

Explain the difference between a stateless access control list and a stateful firewall.

Explain what a DMZ is and identify what kind of system belongs in one.

Explain how a zero trust model differs from a traditional perimeter model.

Explain the difference between an intrusion detection system and an intrusion prevention system.