EDU-102 Sample Questions & Answers
Zscaler's Zero Trust Exchange carries the single biggest share, next to what's exposed to attack and cybersecurity's branches, why it matters to a business, compliance frameworks, who attacks and how, staying cyber-safe, and perimeter-based versus zero-trust approaches.
Launch the full EDU-102 simulator →Free EDU-102 Sample Questions with Answers
Real questions from the Fundamentals of Cybersecurity (EDU-102) practice test — answers and explanations included. Showing 6 of 12 free samples.
- Question 1Intermediate
Describe cybersecurity and attack surface · Attack surface
True or False: The terms 'attack surface' and 'attack vector' can be used interchangeably, as they both refer to the total number of exploitable vulnerabilities in a network.
Show answer & explanation
Correct answer: B
False. The 'attack surface' is the total sum of all potential points (or 'attack vectors') where an unauthorized user can try to enter data to or extract data from an environment. An 'attack vector' is the specific path or method (e.g., a phishing email, an open port) an attacker uses to exploit a vulnerability.
- Question 2Beginner
List the types of cybersecurity · Categories of cybersecurity
A hospital is deploying a new antivirus and endpoint detection and response (EDR) solution on all doctors' laptops and mobile devices. Which specific category of cybersecurity does this implementation primarily represent?
Show answer & explanation
Correct answer: C
Endpoint security focuses on securing end-user devices such as laptops, smartphones, and tablets from malicious threats and cyberattacks. Deploying EDR and antivirus software on these devices is a textbook example of endpoint security.
- Question 3Intermediate
List the types of cybersecurity · Categories of cybersecurity
An e-commerce startup hosts its database on a major public cloud provider (Infrastructure as a Service). The startup suffers a data breach because an administrator left an Amazon S3 bucket publicly readable. According to the principles of Cloud Security, who is ultimately responsible for this specific misconfiguration?
Show answer & explanation
Correct answer: B
In cloud security, the Shared Responsibility Model dictates that the cloud provider secures the 'cloud' (infrastructure, hardware), while the customer secures what is 'in the cloud' (data, configurations, access management). An open S3 bucket is a customer misconfiguration.
- Question 4Advanced
List the types of cybersecurity · Categories of cybersecurity
Aarion Technologies is overhauling its security posture after a recent audit. The Chief Information Officer (CIO) has mandated specific initiatives across different domains:
- Implementing SAST (Static Application Security Testing) in the DevOps pipeline.
- Deploying a DLP (Data Loss Prevention) solution to monitor sensitive file transfers.
- Segmenting the internal LAN using VLANs and internal firewalls.
Which combination correctly maps these initiatives to their respective cybersecurity types?
Show answer & explanation
Correct answer: B
SAST is a core component of Application Security (finding flaws in source code). DLP is a prime control for Information/Data Security (preventing sensitive data exfiltration). VLANs and internal firewalls are foundational elements of Network Security (controlling traffic flow between network segments).
- Question 5IntermediateSelect 2
List the types of cybersecurity · Categories of cybersecurity
A software development firm is enhancing its 'Application Security' practices. Which of the following activities are primarily associated with the Application Security domain? (Select TWO)
Show answer & explanation
Correct answers: B, D
Application security involves identifying, fixing, and preventing security vulnerabilities in software applications. DAST is a key application security testing method.
Integrating secure coding practices and reviewing code for vulnerabilities before deployment are fundamental Application Security practices.
- Question 6Beginner
Discuss the importance of cybersecurity for businesses · Why cybersecurity matters to organizations
A well-known retail brand suffered a major data breach resulting in millions of leaked customer credit card numbers. Following the breach, the company experienced a 30% drop in stock price and lost thousands of loyal customers to competitors. Which business impact of poor cybersecurity does this primarily illustrate?
Show answer & explanation
Correct answer: B
The scenario highlights loss of customer trust (reputation) and a drop in stock value (financial damage), which are direct business consequences of a severe data breach.
Ready for the real thing?
The full EDU-102 simulator has every exam-style question, timed mode, and instant scoring.