Free Practice Quiz Question List

7 Defensive Security Practices Online Quiz Questions

Use this free practice quiz with 20 questions to review 7 Defensive Security Practices, test your knowledge, and prepare for your next test or exam.

20 questions
01
True or false
1 point

A file server does not need remote desktop access. Is it acceptable to expose that service broadly as long as the default credentials have been removed?

  1. A

    True

  2. B

    False

02
Choose one
1 point

An organization must decide which of several available patches to deploy first. Which approach best follows an effective patch process?

  1. A

    Install every available update immediately on every device, without testing or checking the source.

  2. B

    Prioritize updates by risk and importance, obtain them from trusted sources, test and install them, then verify installation.

  3. C

    Wait until users report problems before deciding whether to install updates.

03
Written response
1 point

What is one recommended characteristic of at least one backup copy relative to routine access? Enter one adjective.

04
Choose one
1 point

A company deploys endpoint detection and response (EDR). Which security decision is still appropriate?

  1. A

    Replace secure configuration and updates with EDR, since it can detect suspicious behavior.

  2. B

    Use EDR to help identify and investigate suspicious behavior while maintaining secure configuration and timely updates.

  3. C

    Disable EDR once host firewalls are enabled, because the controls serve the same purpose.

05
True or false
1 point

True or false: A completed backup proves that the data can be restored successfully.

  1. A

    True

  2. B

    False

06
Choose all
1 point

A team is establishing secure configurations for its systems. Which actions support that goal? Select all that apply.

  1. A

    Inventory systems and their owners before establishing approved baselines.

  2. B

    Allow settings to change without recording them, so administrators can work more quickly.

  3. C

    Disable services and features that are not needed.

  4. D

    Leave default credentials in place if a system is not directly internet-facing.

  5. E

    Record and review changes to detect drift from the baseline.

07
Written response
1 point

What two-word security principle describes limiting administrative privileges to what is needed? Enter the principle.

08
Choose one
1 point

A team has enabled logs but has not assigned anyone to handle alerts. What change would make its monitoring practice more actionable?

  1. A

    Generate alerts for every routine event, but do not assign anyone to review them.

  2. B

    Store logs only on the device where they were created and assume administrators will notice problems.

  3. C

    Define alerts for meaningful events and assign someone to investigate them.

09
Choose all
1 point

An organization is reviewing its incident response plan before an exercise. Which elements should the plan include? Select all that apply.

  1. A

    Name decision-makers and technical contacts.

  2. B

    Assume normal communication systems will always be available.

  3. C

    Describe how staff should report concerns.

  4. D

    Establish communication methods to use if normal systems are unavailable.

  5. E

    Leave coordination with leadership and outside parties undefined.

10
Open ended
1 point

After an incident has been contained and its cause addressed, what should an organization do to recover safely and learn from the event? Describe the key actions.

11
Choose one
1 point

An organization is setting backup frequency and retention for a critical service. Which approach best aligns those choices with recovery needs?

  1. A

    Choose backup frequency and retention based only on how much storage is currently available.

  2. B

    Determine what needs to be restored first and how quickly, then set backup frequency and retention to meet those needs.

  3. C

    Use the same backup schedule for every system, regardless of its recovery requirements.

12
Choose one
1 point

A proposed secure-configuration change could interrupt an essential service. What should the team do before deploying it broadly?

  1. A

    Deploy the change everywhere immediately to make settings consistent.

  2. B

    Test the change before broad deployment, especially if it could disrupt an essential service.

  3. C

    Skip the change and leave the current settings undocumented.

  4. D

    Disable all services on the system until the change is complete.

13
Choose one
1 point

A team has limited time for patching. Which system should generally receive higher priority?

  1. A

    Patch systems in alphabetical order by device name.

  2. B

    Update only systems that have reported a failure.

  3. C

    Prioritize actively exploited, internet-facing systems.

  4. D

    Wait until every system can be updated at the same time.

14
Choose one
1 point

An organization enables endpoint detection and response (EDR) on its laptops. Which statement best describes what EDR contributes?

  1. A

    It can help identify and investigate suspicious behavior, but does not replace secure configuration, least privilege, or timely updates.

  2. B

    It guarantees that every attack on a device will be prevented.

  3. C

    It makes software updates unnecessary once installed.

  4. D

    It removes the need to limit administrative privileges.

15
True or false
1 point

True or false: An organization should keep at least one backup copy offline or otherwise isolated from routine access.

  1. A

    True

  2. B

    False

16
Written response
1 point

What access status should at least one backup copy have to help protect it from routine access by compromised systems?

17
Choose one
1 point

A company collects login logs, but repeated failed logins do not prompt any follow-up. What change would most directly improve this monitoring practice?

  1. A

    Delete alerts as soon as they appear to prevent unnecessary work.

  2. B

    Keep logs only on the device that generated them and never review them.

  3. C

    Collect logs but avoid defining which events matter.

  4. D

    Assign someone to investigate meaningful alerts, such as repeated failed logins.

18
Written response
1 point

In the basic incident response sequence, what stage follows containment?

19
Fill in the blank
1 point

A legacy device cannot receive an update. The team adds alternative safeguards to reduce its risk; these are called .

20
Fill in the blank
1 point

An organization centralizes important logs. To keep the records trustworthy, it should protect them from unauthorized or deletion.