wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Cybersecurity and Congress

Total questions: 44

Worksheet time: 22mins

Name
Class
Date
1.

What is identified as a priority for Congress and the Biden administration according to the executive summary?

a)

Economic reform

b)

Cybersecurity

c)

Health care improvement

d)

Education advancement

2.

Which sector is reported to struggle the most with cyberattacks according to the document?

a)

Large enterprises

b)

Small and medium-sized businesses (SMBs)

c)

Non-profit organizations

d)

Government agencies

3.

What is the document suggesting should be emphasized to improve cybersecurity?

a)

Advanced technological development

b)

Basic cybersecurity measures

c)

International cooperation

d)

Military defense strategies

4.

How many pieces of legislation addressing cybersecurity were introduced during 2021?

a)

Over 100

b)

157

c)

75

d)

50

5.

According to the text, what is considered more effective than trying to patch all system vulnerabilities?

a)

Focusing on arresting bad guys

b)

Protecting the "crown jewels" and accepting some level of vulnerability for other assets

c)

Creating a cyber version of the Peace Corps

d)

Sharing information about threats

6.

What can the federal government use its procurement power to do in the cybersecurity market?

a)

To arrest and prosecute cybercriminals

b)

To create a mandatory cybersecurity standard for products and services

c)

To share information about cyber threats

d)

To build a national cyber emergency response team

7.

What is emphasized as a necessary approach to creating the right cybersecurity talent?

a)

Increasing the number of cybersecurity practitioners

b)

Penalizing companies with poor cybersecurity measures

c)

Developing programs that address the cybersecurity workforce gap

d)

Sharing cybersecurity threats publicly

8.

What is essential for information sharing to be effective in cybersecurity?

a)

It must be actionable

b)

It should be kept confidential

c)

It needs to be regulated

d)

It must be punitive

9.

What is the role of Computer Emergency Response Teams (CERTs) in combating cyber actions?

a)

To patch system vulnerabilities

b)

To create cybersecurity standards

c)

To raise the cost of conducting malicious cyber actions

d)

To develop cybersecurity talent

10.

What approach is the Biden administration prioritizing for cybersecurity?

a)

Increasing domestic surveillance

b)

Reducing international cooperation

c)

Implementing a three-pronged approach

d)

Decreasing federal cybersecurity funding

11.

Which office was established by the Fiscal Year (FY) 2021's National Defense Authorization Act (NDAA) to address cybersecurity?

a)

Office of Cybersecurity and Communications

b)

Office of the National Cyber Director (ONCD)

c)

Cybersecurity Infrastructure Security Agency

d)

Bureau for Cyberspace and Digital Policy

12.

Who is responsible for coordinating the federal government's cybersecurity efforts according to the text?

a)

The National Security Council (NSC)

b)

The National Cyber Director

c)

The Department of Homeland Security (DHS)

d)

The Office of the Coordinator for Cyber Issues

13.

What is the new bureau created by the Department of State for dealing with cyberspace and digital policy?

a)

Bureau of Information Resource Management

b)

Bureau for Cyberspace and Digital Policy

c)

Office of Cybersecurity and Communications

d)

Digital Service Bureau

14.

What does the revised cyber social contract emphasize according to the text?

a)

The role of international agencies in cybersecurity

b)

The role of companies in distributing the burden of cyber defense

c)

The reduction of government involvement in cybersecurity

d)

The exclusive responsibility of the government in cybersecurity

15.

What does the National Information Assurance Partnership (NIAP) program offer as a precedent for cybersecurity?

a)

A cybersecurity framework for private-sector organizations

b)

A set of guidelines for patch management

c)

A standard for cybersecurity software in the Department of Defense

d)

A mandatory cybersecurity training for all companies

16.

What was the result of the Wyndham Worldwide Corporation failing to follow proper incident response procedures?

a)

They were given a warning by the Federal Trade Commission

b)

They had to pay for damages exceeding $10.6 million

c)

They lost over 619,000 payment card account numbers

d)

They were required to upgrade their cybersecurity measures

17.

According to the text, what is the role of the private sector in cybersecurity?

a)

To provide enterprise-ready products and services

b)

To solely focus on internal cybersecurity measures

c)

To follow government-imposed cybersecurity frameworks

d)

To outsource all cybersecurity responsibilities

18.

What is the purpose of the Minimum Viable Secure Product (MVSP) announced by companies like Salesforce, Google, and Okta?

a)

To establish a new government cybersecurity agency

b)

To set a minimum security requirement for technology products

c)

To create a new cybersecurity framework for the Department of Defense

d)

To mandate cybersecurity insurance for all businesses

19.

What is a significant challenge faced by Small and Medium-Sized Businesses (SMBs) in implementing cyber hygiene measures?

a)

They have too many resources dedicated to cybersecurity

b)

They often lack both resources and personnel

c)

They are not targeted by cybercriminals

d)

They have the most advanced cybersecurity programs

20.

What is the purpose of creating programs where SMBs receive better terms for loans if they reach a minimum security standard like using MFA?

a)

To increase the overall cybersecurity awareness among SMBs

b)

To provide financial assistance to SMBs without any additional conditions

c)

To prioritize cybersecurity measures in the overall environment

d)

To enforce government regulations on SMBs

21.

Which program offers a range of resources to show companies how to implement basic security measures against cyberattacks?

a)

The Cyber Essentials program

b)

The Cyber Incident Response network

c)

The Cyber Security Centre toolkit

d)

The ICS Cybersecurity Initiative

22.

What is the role of the United Kingdom's National Cyber Security Centre according to the text?

a)

It provides specific advice and resources tailored to organizations with dedicated cybersecurity teams.

b)

It sets the cybersecurity standards for small and medium-sized businesses.

c)

It offers financial incentives for businesses to improve cybersecurity.

d)

It provides a list of trusted cybersecurity vendors.

23.

What is the Cyber Incident Response network's function in the United Kingdom?

a)

It helps organizations prioritize their cybersecurity measures.

b)

It provides a validation process for SMBs to trust their cybersecurity vendors.

c)

It offers help to organizations after cyberattacks.

d)

It creates cybersecurity awareness among SMBs.

24.

What is the significance of protecting "crown jewels" in the context of cybersecurity?

a)

It refers to the prioritization of protecting high-value assets while accepting some level of vulnerability for other systems.

b)

It means implementing the highest level of security for all systems without prioritization.

c)

It is about sharing information about sector trends to identify what needs to be protected.

d)

It involves creating a list of trusted and verified cybersecurity vendors.

25.

Which sectors has the Biden administration developed action plans for in terms of cybersecurity?

a)

Electric, natural gas pipeline, and water sectors

b)

Healthcare, finance, and education sectors

c)

Technology, retail, and transportation sectors

d)

Agriculture, defense, and telecommunications sectors

26.

What is the estimated range for the federal cybersecurity market for FY 2022?

a)

$10 billion to $15 billion

b)

$14.4 billion to $20 billion

c)

$5 billion to $10 billion

d)

$20 billion to $25 billion

27.

Which act, passed in November 2021, includes close to $2 billion for cybersecurity?

a)

The Cybersecurity Enhancement Act

b)

The Infrastructure Investment and Job Act

c)

The Build Back Better Act

d)

The Federal Acquisition Regulation Act

28.

What would the Build Back Better Act provide if passed?

a)

A review of the Federal Acquisition Regulation

b)

Enhanced security and reporting from information technology operations

c)

Additional funding for cybersecurity programs

d)

A standard for Multi-Factor Authentication (MFA) products and services

29.

What is one of the proposed amendments to the Federal Acquisition Regulation (FAR) mentioned in the text?

a)

To decrease the sharing of information about cyber threats and incident information

b)

To increase the sharing of information about cyber threats and incident information

c)

To standardize common cybersecurity contractual requirements across Federal agencies

d)

Both B and C are correct

30.

What is the general perception of the government's relationship with the public and private sectors as expressed by some participants in the roundtables?

a)

Supportive and cooperative

b)

Confrontational, fueling distrust

c)

Indifferent and uninvolved

d)

Transparent and open

31.

What was one of CISA's first actions in response to the Log4Shell software flaw?

a)

Launching a nationwide cybersecurity alert

b)

Convening the JCDC

c)

Implementing a mandatory patch

d)

Increasing cybersecurity funding

32.

What is the estimated number of cybersecurity job openings according to the document?

a)

377,000

b)

597,000

c)

500,000

d)

1,000,000

33.

What is the proposed benefit of a CyberCorps program according to the document?

a)

It would provide cybersecurity training to existing federal employees.

b)

It would allow companies to outsource their cybersecurity needs.

c)

It would help recruit young people into the cybersecurity field.

d)

It would create a new government cybersecurity agency.

34.

According to the document, what percentage of cybersecurity workers self-identify as Hispanic?

a)

4%

b)

9%

c)

24%

d)

40%

35.

What is the ISC(2) report's concern regarding the consequences of the cybersecurity workforce shortage?

a)

Increased risk of software flaws like Log4Shell

b)

Lack of appropriate staff at the enterprise level

c)

Consequences such as misconfigured systems and slow patch cycles

d)

Overreliance on third-party cybersecurity services

36.

What is the primary concern mentioned in the text regarding government-funded programs for cybersecurity talent development?

a)

The programs are too expensive for the government to maintain.

b)

Companies may become reliant on federally funded talent and not build their own cyber operations.

c)

The programs do not include enough practical training exercises.

d)

There is a lack of interest from the private sector in these programs.

37.

According to the U.S. Cyberspace Solarium Commission report, what is recommended to incentivize better cybersecurity practices?

a)

Increasing the number of cybersecurity drills.

b)

Tying insurance coverage to the implementation of better cybersecurity practices.

c)

Mandating cybersecurity training for all employees in critical infrastructure entities.

d)

Offering tax incentives for companies that invest in cybersecurity.

38.

What was the outcome of the NotPetya malware incident in terms of insurance coverage?

a)

Insurance companies covered the full cost of the damages caused by the malware.

b)

The incident fell under the "hostile/warlike action exclusion" in December 2021, leading to a denial of coverage.

c)

All companies affected by NotPetya received compensation without any exclusions.

d)

The insurance companies went bankrupt due to the high payouts for the damages.

39.

What is the purpose of Section 1550 of the FY 2022 NDAA as mentioned in the text?

a)

To provide financial aid to companies affected by cyber attacks.

b)

To establish a voluntary process for companies to share information with Cyber Command.

c)

To create a new cybersecurity insurance policy for private companies.

d)

To mandate cybersecurity training for all government employees.

40.

What initiative did CISA launch in October 2021 to facilitate operational planning and collaborative analysis?

a)

Log4j vulnerability masks

b)

JCDC

c)

CERT partnerships

d)

Threat intelligence information-sharing guide

41.

According to the text, what is one of the challenges in cybersecurity information sharing?

a)

Determining the cost of information sharing

b)

Deciding which private companies should receive government data

c)

Determining who should integrate the data and who should participate

d)

Ensuring that all companies share their information publicly

42.

What is the primary reason for limiting the number of participants in a cybersecurity information sharing program?

a)

To reduce the complexity of the program

b)

To maintain effectiveness and boost capabilities

c)

To prevent private companies from gaining too much insight

d)

To ensure that only government agencies are involved

43.

Which country's National Cybersecurity Center implemented a cyber attack threat intelligence information-sharing guide?

a)

United States

b)

United Kingdom

c)

Canada

d)

Australia

44.

What is emphasized as a key part of the foreign policy agenda in relation to cybersecurity?

a)

Reducing the number of cybersecurity incidents

b)

Implementing international norms for cybersecurity

c)

Privatizing cybersecurity efforts

d)

Focusing solely on domestic cybersecurity issues