wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Basic Cybersecurity Concepts 1

Total questions: 25

Worksheet time: 15mins

Name
Class
Date
1.

Which of the following steps is required to mitigate data breach risks?

a)

Use strong credentials and disable multi-factor authentication.

b)

Use strong credentials and enable multi-factor authentication.

c)

Reuse passwords, because it is easier that way.

2.

What is the most common password in 2019 according to NCSC?

(a)  

3.

CYDEO customers' personal information was breached, what should be done?

a)

Notify customers and let them know about the breach.

b)

Ignore customers and deal with them later.

c)

Not tell anyone about the breach and delay until things are calmed down.

4.

Which of the following should you monitor or include in the SIEM? (select multiple)

a)

Laptops

b)

Antivirus

c)

Servers

d)

Routers

e)

Firewall

5.

Can SIEM work by itself, or does it need input from other devices?

a)

It works directly with a firewall.

b)

It depends on the company's infrastructure.

c)

It needs input from other devices.

d)

It can work by itself.

6.

What would NOT be one of SOAR solutions for your company in case of a ransomware attack?

a)

Automate the steps to be taken once the incident was detected.

b)

Help to collaborate between SOC analysts.

c)

Automatically fix the issue.

d)

Provide a clear path on the escalation process.

7.

Which is the correct order of the incident response process steps?

a)

Preparation, Identification, Containment, Eradication, Recovery, Lessons Learned

b)

Lessons Learned, Recovery, Eradication, Containment, Identification, Preparation

c)

Identification, Preparation, Containment, Eradication, Lessons Learned, Recovery

d)

Identification, Preparation, Containment, Eradication, Recovery, Lessons Learned

8.

SOAR can help your company automatically decrypt files to avoid a ransomware attack.

a)

True

b)

False

9.

What type of security solution would allow you to tell whether a file was really malicious or a false-positive?

a)

Threat intelligence

b)

Playbook

c)

SOAR

d)

SIEM

10.

What does OSINT stand for?

a)

Open Source Intelligence

b)

Orchestrated Source Intelligence New Technology

c)

Open Source Interconnection

d)

Orchestrated Source Intelligence Network Technology

11.

SIEM can easily help your company automatically decrypt files to avoid a ransomware attack.

a)

True

b)

False

12.

What does OWASP stand for?

a)

Open Worldwide Application Security Project

b)

Orchestrated Web Application Security Protocols

c)

Open Web Appliance Security Platform

d)

Orchestrated Worldwide Application Security Project

13.

What does BCP stand for?

a)

Business Continuity Plan

b)

Business Correction Plan

c)

Business Continuity Project

d)

Bees Can Pollute

14.

What does DRP stand for?

a)

Disaster Recovery Plan

b)

Data Response Plan

c)

Disc Recovery Plan

d)

Directory Response Program

15.

What's the main difference between the BCP and DRP?

a)

BCP is focused on resuming the business operations, and DRP is focused on resuming the IT infrastructure that supports the business.

b)

Sometimes they are the same, sometimes they are not.

c)

DRP is focused on resuming the business operations, and BCP is focused on resuming the IT infrastructure that supports the business.

d)

It depends on the company's security policy.

16.

What is the term that best describes setting a lower priority to addressing a known vulnerability?

a)

Grey area

b)

Business continuity

c)

Acceptable risk

d)

Incident ignorance

17.

Which of the followings are the primary objectives of a SOC?

(Choose all that apply.)

a)

prevent

b)

detect

c)

publish findings on

d)

respond to

e)

ignore insignificant

18.

Which of the following is NOT a tool that is commonly managed by SOC analysts?

a)

Security Incident and Event Management solution

b)

Active Directory Domain

c)

Security Orchestration, Automation and Response solution

d)

Threat Intelligence Platform

e)

Firewall Policy

19.

Which of the following tasks are typically performed on a daily basis by a SOC Analyst?

a)

Reviewing alerts and logs

b)

Reverse engineering malware

c)

Defending against DDoS attacks launched by nation state threat actors

d)

Containing lateral movement

20.

What are some of the job roles commonly found in a SOC? (Choose all that apply.)

a)

DevOps engineer

b)

SOC analyst

c)

Threat hunter

d)

Reverse malware engineer

e)

SOC manager

21.

What are two methods used to protect confidentiality?

a)

Privileged access management

b)

Encryption

c)

Hashing

d)

Intrusion detection systems

22.

What is a common attack to disrupt availability?

a)

random attack

b)

data breach

c)

man in the middle

d)

DDoS attack

23.

Which factor of the triad is affected when security controls are too restrictive?

a)

Availability

b)

Integrity

c)

Confidentiality

24.

What is the process of taking a snapshot of a system to help protect its integrity?

a)

baselining

b)

silverlining

c)

crossroad

d)

overlining

25.

How do you feel this week?

a)
b)
c)
d)