Your question is Core Web and Crypto Security. Take a moment with it on the right.
Talk me through your thinking if you like. When you're confident, submit your answer and I'll grade it like a real screen (7/10 or better passes).
What is a man-in-the-middle attack and how do you defend against it? What is a brute force attack and how do you defend against it? What is the difference between a hash and encryption? What is the difference between a digital signature and a digital certificate? What is the first thing you should do if your company is infected by ransomware? How would you prioritize remediation of vulnerabilities?