Fundamentals of Cybersecurity (EDU-102) Free Sample Questions

Create a free account to browse all 12 sample questions. The full practice test includes 150 questions. Use the simulator for timed and flashcard mode.

Try Simulator

EDU-102 Sample Questions

  1. Question 1

    Q1

    A financial services organization is migrating its core banking application to the cloud. The Chief Information Security Officer (CISO) emphasizes that the migration must not compromise the 'CIA Triad.' In this context, which of the following best describes the 'Integrity' component of the CIA Triad?

    Show answer & explanation

    Correct answer: B

    In the CIA Triad (Confidentiality, Integrity, Availability), Integrity refers to maintaining the accuracy, consistency, and trustworthiness of data over its entire lifecycle. It ensures that data cannot be altered in transit or at rest by unauthorized parties.

  2. Question 2

    Q2Multiple answers

    Nimbus Logistics recently transitioned to a fully remote workforce, allowing employees to access corporate resources from personal devices and public Wi-Fi networks. Which of the following factors contribute to the expansion of the company's attack surface in this scenario? (Select THREE)

    Show answer & explanation

    Correct answers: A, C, E

    Unmanaged personal devices introduce new potential entry points for attackers, increasing the attack surface.

    Unsecured public networks expose data in transit to interception, adding to the attack surface.

    Exposing services to the internet for VPN access creates discoverable nodes that attackers can target, expanding the attack surface.

  3. Question 3

    Q3

    A security architect at Globex Corp discovers that several marketing teams have been independently purchasing and using unauthorized SaaS applications for file sharing. This 'Shadow IT' behavior bypasses corporate security controls. How does this specifically impact the organization's attack surface?

    Show answer & explanation

    Correct answer: B

    Shadow IT significantly expands the attack surface because it introduces unmanaged, unmonitored assets and data flows. Security teams cannot protect what they cannot see, leaving these unauthorized apps vulnerable to exploitation and data leakage.

    flowchart LR User[Marketing User] -->|Sanctioned| IT[IT Monitored App] User -->|Shadow IT| Unmonitored[Unsanctioned SaaS App] Unmonitored -->|Data Leakage| Attacker((Attacker)) style Unmonitored fill:#f9f,stroke:#333,stroke-width:2px
  4. Question 4

    Q4

    True or False: The terms 'attack surface' and 'attack vector' can be used interchangeably, as they both refer to the total number of exploitable vulnerabilities in a network.

    Show answer & explanation

    Correct answer: B

    False. The 'attack surface' is the total sum of all potential points (or 'attack vectors') where an unauthorized user can try to enter data to or extract data from an environment. An 'attack vector' is the specific path or method (e.g., a phishing email, an open port) an attacker uses to exploit a vulnerability.

  5. Question 5

    Q5

    A hospital is deploying a new antivirus and endpoint detection and response (EDR) solution on all doctors' laptops and mobile devices. Which specific category of cybersecurity does this implementation primarily represent?

    Show answer & explanation

    Correct answer: C

    Endpoint security focuses on securing end-user devices such as laptops, smartphones, and tablets from malicious threats and cyberattacks. Deploying EDR and antivirus software on these devices is a textbook example of endpoint security.

  6. Question 6

    Q6

    An e-commerce startup hosts its database on a major public cloud provider (Infrastructure as a Service). The startup suffers a data breach because an administrator left an Amazon S3 bucket publicly readable. According to the principles of Cloud Security, who is ultimately responsible for this specific misconfiguration?

    Show answer & explanation

    Correct answer: B

    In cloud security, the Shared Responsibility Model dictates that the cloud provider secures the 'cloud' (infrastructure, hardware), while the customer secures what is 'in the cloud' (data, configurations, access management). An open S3 bucket is a customer misconfiguration.

Register free to unlock 6 more sample questions

Create a free account to continue with the rest of the EDU-102 sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 150 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon