Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Cybersecurity Quiz

Total questions: 100

Worksheet time: 50mins

Name
Class
Date
1.

What does the term "Absolute file path" refer to in cybersecurity?

a)

A) A type of attack where data packets are manipulated in transit

b)

B) The full file path, which starts from the root

c)

C) A network protocol used to determine the MAC address of the next router or device on the path

d)

D) A detection method that identifies abnormal behavior

2.

What is "Access controls" in the context of cybersecurity?

a)

A) A set of rules used to solve a problem

b)

B) A type of legitimate software that displays digital advertisements

c)

C) Security controls that manage access, authorization, and accountability of information

d)

D) The investigation and validation of alerts

3.

What is "Active packet sniffing"?

a)

A) A detection method that identifies abnormal behavior

b)

B) A technique that manipulates AI and ML technology to conduct attacks

c)

C) A type of legitimate software used to display digital advertisements

d)

D) A type of attack where data packets are manipulated in transit

4.

What does "Address Resolution Protocol (ARP)" stand for?

a)

A) A technique where attackers impersonate customer service representatives on social media

b)

B) A set of rules used to solve a problem

c)

C) A network protocol used to determine the MAC address of the next router or device on the path

d)

D) A detection method that identifies abnormal behavior

5.

What is an "Advanced persistent threat (APT)"?

a)

A) A detection method that identifies abnormal behavior

b)

B) An instance when a threat actor maintains unauthorized access to a system for an extended period of time

c)

C) A type of legitimate software that is sometimes used to display digital advertisements

d)

D) A technique where attackers impersonate customer service representatives on social media

6.

What is "Adversarial artificial intelligence (AI)"?

a)

A) A detection method that identifies abnormal behavior

b)

B) A technique that manipulates AI and ML technology to conduct attacks more efficiently

c)

C) A network protocol used to determine the MAC address of the next router or device on the path

d)

D) A type of attack where data packets are manipulated in transit

7.

What is "Adware"?

a)

A) A type of attack where data packets are manipulated in transit

b)

B) A network protocol used to determine the MAC address of the next router or device on the path

c)

C) A type of legitimate software that is sometimes used to display digital advertisements

d)

D) A technique that manipulates AI and ML technology to conduct attacks more efficiently

8.

What is an "Algorithm" in the context of cybersecurity?

a)

A) A network protocol used to determine the MAC address of the next router or device on the path

b)

B) A type of legitimate software that is sometimes used to display digital advertisements

c)

C) A detection method that identifies abnormal behavior

d)

D) A set of rules used to solve a problem

9.

What does "Analysis" refer to in cybersecurity?

a)

A) A type of legitimate software that is sometimes used to display digital advertisements

b)

B) The full file path, which starts from the root

c)

C) The investigation and validation of alerts

d)

D) A network protocol used to determine the MAC address of the next router or device on the path

10.

What is "Angler phishing"?

a)

A) A detection method that identifies abnormal behavior

b)

B) A type of legitimate software that is sometimes used to display digital advertisements

c)

C) A technique where attackers impersonate customer service representatives on social media

d)

D) A network protocol used to determine the MAC address of the next router or device on the path

11.

What is "Anomaly-based analysis"?

a)

A) A technique where attackers impersonate customer service representatives on social media

b)

B) A set of rules used to solve a problem

c)

C) A type of legitimate software that is sometimes used to display digital advertisements

d)

D) A detection method that identifies abnormal behavior

12.

What is the purpose of antivirus software?

a)

To enhance the performance of applications

b)

To prevent, detect, and eliminate malware and viruses

c)

To store data in a comma-separated ordered list

d)

To map threats to assets

13.

What is an API token?

a)

A software program used to eliminate viruses

b)

A practice of labeling assets based on sensitivity

c)

A small block of encrypted code that contains information about a user

d)

A type of asymmetric encryption

14.

What is the fifth step of the NIST RMF that assesses if established controls are implemented correctly?

a)

Asset

b)

Assess

c)

Authorize

d)

Automation

15.

What does the term 'asset' refer to in an organizational context?

a)

A catalog of assets that need to be protected

b)

An item perceived as having value to an organization

c)

The process of tracking assets and the risks that affect them

d)

The practice of labeling assets based on sensitivity and importance

16.

What is asymmetric encryption?

a)

A diagram that maps threats to assets

b)

The use of a public and private key pair for encryption and decryption of data

c)

The process of verifying who someone is

d)

The idea that data is accessible to those who are authorized to access it

17.

What is an attack surface?

a)

The process of tracking assets

b)

The pathways attackers use to penetrate security defenses

c)

All the potential vulnerabilities that a threat actor could exploit

d)

A type of data that stores information in a list

18.

What is the purpose of authentication in security?

a)

To reduce human and manual effort to perform tasks

b)

To grant access to specific resources in a system

c)

To verify who someone is

d)

To label assets based on sensitivity and importance

19.

What does 'availability' mean in the context of data access?

a)

The use of technology to perform tasks

b)

The process of tracking assets

c)

The idea that data is accessible to those who are authorized to access it

d)

The practice of labeling assets

20.

What is the term for a social engineering tactic that tempts people into compromising their security?

a)

Bootloader

b)

Baiting

c)

Bit

d)

Bandwidth

21.

What does bandwidth refer to in a network?

a)

The default shell in most Linux distributions

b)

The maximum data transmission capacity over a network

c)

A collection of computers infected by malware

d)

The unique physical characteristics used to verify a person's identity

22.

What is a baseline configuration also known as?

a)

Baseline image

b)

Basic auth

c)

BIOS

d)

Bracket notation

23.

What is the default shell in most Linux distributions called?

a)

Bit

b)

Bootloader

c)

Bash

d)

Botnet

24.

What is the purpose of a bootloader?

a)

It is a microchip that contains loading instructions for the computer

b)

It is a software program that boots the operating system

c)

It is a tactic used in social engineering

d)

It is the smallest unit of data measurement on a computer

25.

What is a botnet?

a)

A function that exists within Python

b)

A software program that boots the operating system

c)

A collection of computers infected by malware under the control of a single threat actor

d)

The trial and error process of discovering private information

26.

What does the term "brute force attack" refer to?

a)

A documented set of specifications within a system for future builds

b)

A social engineering tactic

c)

The trial and error process of discovering private information

d)

A function that exists within Python

27.

What is a built-in function?

a)

A function that exists within Python and can be called directly

b)

A software program that boots the operating system

c)

The smallest unit of data measurement on a computer

d)

The maximum data transmission capacity over a network

28.

What is the purpose of a Business Continuity Plan (BCP)?

a)

To maintain an organization's productivity by establishing risk disaster recovery plans

b)

To document evidence possession and control during an incident lifecycle

c)

To encrypt information using an algorithm

d)

To analyze, retain, and search data using a cloud-native tool

29.

What does BEC stand for in cybersecurity?

a)

Business Email Compromise

b)

Business Enterprise Computing

c)

Basic Encryption Code

d)

Business Enhanced Cybersecurity

30.

What is CentOS?

a)

A cloud-native tool designed to analyze data

b)

A type of phishing attack

c)

An open-source distribution closely related to Red Hat

d)

A collection of servers or computers that store resources and data

31.

What is the role of a Central Processing Unit (CPU) in a computer?

a)

To encrypt information

b)

To host software firewalls

c)

To perform general computing tasks

d)

To ensure cloud security

32.

What is the purpose of cloud-based firewalls?

a)

To document evidence possession during an incident lifecycle

b)

To host software firewalls by the cloud service provider

c)

To provide instructions to the computer

d)

To maintain communications with compromised systems

33.

What is cloud computing?

a)

The process of documenting evidence possession and control

b)

The practice of using remote servers, applications, and network services hosted on the internet

c)

The process of ensuring that assets stored in the cloud are properly configured

d)

The techniques used by malicious actors to maintain communications with compromised systems

34.

What is a cloud network?

a)

An algorithm that encrypts information

b)

A computer's main processor

c)

A collection of servers or computers that store resources and data in remote data centers

d)

A type of phishing attack

35.

What is the focus of cloud security?

a)

Ensuring that assets stored in the cloud are properly configured and access is limited to authorized users

b)

Encrypting information using an algorithm

c)

Documenting evidence possession and control during an incident lifecycle

d)

Telling the computer to do something

36.

What does the term "Command" refer to in computing?

a)

An instruction telling the computer to do something

b)

A cloud-native tool designed to retain, analyze, and search data

c)

An open-source distribution that is closely related to Red Hat

d)

The process of documenting evidence possession and control during an incident lifecycle

37.

What is Command and Control (C2) in the context of cybersecurity?

a)

The process of ensuring that assets stored in the cloud are properly configured

b)

The techniques used by malicious actors to maintain communications with compromised systems

c)

A computer's main processor, which is used to perform general computing tasks

d)

An algorithm that encrypts information

38.

What is the purpose of a Command-line interface (CLI)?

a)

A graphical user interface that uses icons to interact with the computer

b)

A text-based user interface that uses commands to interact with the computer

c)

A programming language used for creating operating systems

d)

A tool for measuring the severity of computer vulnerabilities

39.

What does the Common Vulnerability Scoring System (CVSS) provide?

a)

A log format that uses key-value pairs to structure data

b)

A text-based user interface for computers

c)

A measurement system that scores the severity of a vulnerability

d)

A specialized group of security professionals

40.

What is the role of Computer security incident response teams (CSIRT)?

a)

To write malicious software

b)

To configure the settings of an application

c)

To manage and respond to computer security incidents

d)

To protect the internal network from the uncontrolled zone

41.

What does the Confidentiality, Integrity, Availability (CIA) triad model help organizations with?

a)

Configuring the settings of an application

b)

Structuring log data using key-value pairs

c)

Informing risk considerations when setting up systems and security policies

d)

Training specialized groups of security professionals

42.

What is the purpose of a containment strategy in cybersecurity?

a)

To configure the settings of an application

b)

To limit and prevent additional damage caused by an incident

c)

To provide a measurement system for vulnerabilities

d)

To create a log format for data structuring

43.

What is a cross-site scripting (XSS) attack?

a)

An attack that affects secure forms of communication between a sender and an intended recipient.

b)

A practice of gathering information using public input and collaboration.

c)

An injection attack that inserts code into a vulnerable website or web application.

d)

A malware that installs software to illegally mine cryptocurrencies.

44.

What is crowdsourcing?

a)

An attack that affects secure forms of communication between a sender and an intended recipient.

b)

A practice of gathering information using public input and collaboration.

c)

An injection attack that inserts code into a vulnerable website or web application.

d)

A malware that installs software to illegally mine cryptocurrencies.

45.

What is a cryptographic attack?

a)

An attack that affects secure forms of communication between a sender and an intended recipient.

b)

A practice of gathering information using public input and collaboration.

c)

An injection attack that inserts code into a vulnerable website or web application.

d)

A malware that installs software to illegally mine cryptocurrencies.

46.

What is a cryptographic key?

a)

A tool for locking and unlocking cryptographic functions

b)

A password for internet access

c)

A method for digital signatures only

d)

A type of software that manages digital communication

47.

What is cryptography?

a)

The study of planets

b)

The art of writing or solving codes

c)

The science of numbers

d)

The process of making software

48.

What is cryptojacking?

a)

A mechanism that decrypts encrypted text.

b)

A process that transforms information into a form that readers cannot understand.

c)

A malware that installs software to illegally mine cryptocurrencies.

d)

An organization that analyzes and distributes information about eligible CVEs.

49.

What is the CVE Numbering Authority (CNA)?

a)

A malware that installs software to illegally mine cryptocurrencies.

b)

A process that transforms information into a form that readers cannot understand.

c)

An organization that volunteers to analyze and distribute information about eligible CVEs.

d)

The practice of ensuring the confidentiality, integrity, and availability of information.

50.

What is cybersecurity?

a)

The practice of ensuring the confidentiality, integrity, and availability of information.

b)

A malware that installs software to illegally mine cryptocurrencies.

c)

An organization that volunteers to analyze and distribute information about eligible CVEs.

d)

Information that is translated, processed, or stored by a computer.

51.

What is "Data at rest"?

a)

Data traveling from one point to another.

b)

Data that is being accessed by one or more users.

c)

Data not currently being accessed.

d)

Unauthorized data transmission from a system.

52.

What is a database?

a)

A person who determines the procedure and purpose for processing data.

b)

Anyone or anything that is responsible for the safe handling, transport, and storage of information.

c)

An organized collection of information or data.

d)

Unauthorized transmission of data from a system.

53.

What is a data controller?

a)

A person who determines the procedure and purpose for processing data.

b)

Anyone or anything that is responsible for the safe handling, transport, and storage of information.

c)

An organized collection of information or data.

d)

Unauthorized transmission of data from a system.

54.

What is a data custodian?

a)

A person who determines the procedure and purpose for processing data.

b)

Anyone or anything that is responsible for the safe handling, transport, and storage of information.

c)

An organized collection of information or data.

d)

Unauthorized transmission of data from a system.

55.

What is data exfiltration?

a)

Data traveling from one point to another.

b)

Data being accessed by one or more users.

c)

Data not currently being accessed.

d)

Unauthorized transmission of data from a system.

56.

What does "Data in transit" mean?

a)

Data traveling from one point to another.

b)

Data that is being accessed by one or more users.

c)

Data not currently being accessed.

d)

Unauthorized transmission of data from a system.

57.

What is "Data in use"?

a)

Data traveling from one point to another.

b)

Data that is being accessed by one or more users.

c)

Data not currently being accessed.

d)

Unauthorized data transmission from a system.

58.

Who is responsible for deciding who can access, edit, use, or destroy their information?

a)

Data processor

b)

Data protection officer (DPO)

c)

Data owner

d)

Data point

59.

What is a data packet?

a)

A file that organizes where other files are stored

b)

A specific piece of information

c)

A basic unit of information that travels from one device to another within a network

d)

A software tool that helps to locate the source of an error

60.

What is the role of a Data protection officer (DPO)?

a)

Responsible for processing data on behalf of the data controller

b)

Monitors compliance of an organization's data protection procedures

c)

Identifies and fixes errors in code

d)

Collects and analyzes data to determine what happened after an attack

61.

What does 'Defense in depth' refer to?

a)

A plan to minimize the impact of a security incident

b)

A basic unit of information transfer within a network

c)

A layered approach to vulnerability management that reduces risk

d)

The practice of collecting and analyzing data after an attack

62.

What is a Denial of Service (DoS) attack?

a)

A file that verifies the identity of a public key holder

b)

An attack that targets a network or server and floods it with network traffic

c)

A practice of identifying and fixing errors in code

d)

A core function related to identifying potential security incidents

63.

What is the purpose of a Digital certificate?

a)

To organize where other files are stored

b)

To verify the identity of a public key holder

c)

To collect and analyze data to determine what happened after an attack

d)

To identify and fix errors in code

64.

What is the main focus of Digital forensics?

a)

Monitoring compliance of data protection procedures

b)

Collecting and analyzing data to determine what happened after an attack

c)

Identifying potential security incidents

d)

Managing vulnerabilities in a layered approach

65.

What is a Distributed Denial of Service (DDoS) attack?

a)

A type of malware that comes packed with malicious code

b)

A networking protocol that translates internet domain names into IP addresses

c)

A type of denial of service attack that uses multiple devices or servers to flood the target network with unwanted traffic

d)

An application that monitors an endpoint for malicious activity

66.

What are Distributions in the context of Linux?

a)

The different versions of Linux

b)

A type of malware

c)

A process performed by a VPN service

d)

An application that monitors for malicious activity

67.

What is the purpose of Documentation?

a)

To convert data from a readable format to an encoded format

b)

To provide a brief summary of your experience, skills, and background

c)

To record content that is used for a specific purpose

d)

To monitor an endpoint for malicious activity

68.

What does DOM-based XSS attack refer to?

a)

A networking protocol that translates internet domain names into IP addresses

b)

An instance when malicious script exists in the webpage a browser loads

c)

The complete removal of the incident elements from all affected systems

d)

A set of actions that outline how an incident should be handled

69.

What is the Domain Name System (DNS)?

a)

A type of malware

b)

A process performed by a VPN service

c)

A networking protocol that translates internet domain names into IP addresses

d)

An application that monitors an endpoint for malicious activity

70.

What is a Dropper in the context of malware?

a)

A brief summary of your experience, skills, and background

b)

A process performed by a VPN service

c)

A type of malware that comes packed with malicious code which is delivered and installed onto a target system

d)

An application that monitors an endpoint for malicious activity

71.

What is an exclusive operator?

a)

A network security device

b)

A variable that is available through the entire program

c)

An operator that does not include the value of comparison

d)

A section of code that can be reused in a program

72.

What does the term 'exploit' refer to in cybersecurity?

a)

A state where the presence of a threat is not detected

b)

A way of taking advantage of a vulnerability

c)

Selecting data that match a certain condition

d)

A server that regulates and restricts a person’s access to the internet

73.

What is a false positive in the context of network security?

a)

An alert that incorrectly detects the presence of a threat

b)

Malware that does not need to be installed by the user

c)

The location of a file or directory

d)

A variable that is available through the entire program

74.

What is the purpose of a firewall?

a)

To document a comprehensive review of an incident

b)

To monitor traffic to or from a network

c)

To store data consisting of a number with a decimal point

d)

To regulate and restrict a person’s access to the internet

75.

What is a foreign key in a database?

a)

A column in a table that is a primary key in another table

b)

A section of code that can be reused in a program

c)

A variable that is available through the entire program

d)

An operator that does not include the value of comparison

76.

What is a global variable in programming?

a)

A variable that is available through the entire program

b)

A network security device that monitors traffic

c)

An operator that does not include the value of comparison

d)

A server that regulates and restricts a person’s access to the internet

77.

What is a Graphical User Interface (GUI)?

a)

A user interface that uses icons on the screen to manage different tasks on the computer.

b)

A network protocol that provides a secure method of communication between clients and web servers.

c)

A hardware component used for long-term memory.

d)

A federal law in the U.S. that protects patients' health information.

78.

What is a hacker?

a)

Anyone who uses computers to gain access to computer systems, networks, or data.

b)

An application that monitors the host's activity on which it is installed.

c)

An algorithm that produces a code that cannot be deciphered.

d)

A network device that transmits information to every device on the network.

79.

What is a hacktivist?

a)

A person who uses hacking to achieve a political goal.

b)

A system or resource created as a vulnerable decoy to attract potential intruders.

c)

A hardware component used for long-term memory.

d)

A federal law in the U.S. that protects patients' health information.

80.

What is a hard drive?

a)

A hardware component used for long-term memory.

b)

A layer application protocol that provides a method of communication between clients and web servers.

c)

A system or resource created as a vulnerable decoy to attract potential intruders.

d)

An instance in which different inputs produce the same hash value.

81.

What is hardware?

a)

The physical components of a computer.

b)

An algorithm that produces a code that cannot be deciphered.

c)

An application that monitors the activity of the host on which it is installed.

d)

A network protocol that provides a secure method of communication between clients and web servers.

82.

What is a hash collision?

a)

An instance where different inputs produce the same hash value.

b)

An algorithm that produces a code that cannot be deciphered.

c)

A data structure that is used to store and reference hash values.

d)

A federal law in the U.S. that protects patients' health information.

83.

What is a hash function?

a)

An algorithm that produces a code that cannot be deciphered.

b)

A data structure that is used to store and reference hash values.

c)

A network protocol that provides a secure method of communication between clients and web servers.

d)

An application that monitors the activity of the host on which it is installed.

84.

What is a hash table?

a)

A data structure that is used to store and reference hash values.

b)

A federal law in the U.S. that protects patients' health information.

c)

A network protocol that provides a secure method of communication between clients and web servers.

d)

A system or resource created as a vulnerable decoy to attract potential intruders.

85.

What is the Health Insurance Portability and Accountability Act (HIPAA)?

a)

A federal law in the U.S. that protects patients' health information.

b)

A network protocol that provides a secure method of communication between clients and web servers.

c)

An algorithm that produces a code that cannot be deciphered.

d)

A data structure that is used to store and reference hash values.

86.

What is a honeypot?

a)

A system or resource created as a vulnerable decoy to attacks with the purpose of attracting potential intruders.

b)

A network protocol that provides a secure method of communication between clients and web servers.

c)

A hardware component used for long-term memory.

d)

A federal law in the U.S. that protects patients' health information.

87.

What is a host-based intrusion detection system (HIDS)?

a)

An application that monitors the activity of the host on which it is installed.

b)

A network protocol that provides a secure method of communication between clients and web servers.

c)

An algorithm that produces a code that cannot be deciphered.

d)

A network device that transmits information to every device on the network.

88.

What is a hub?

a)

A network device that transmits information to every device on the network.

b)

An application that monitors the activity of the host on which it is installed.

c)

An algorithm that produces a code that cannot be deciphered.

d)

A data structure that is used to store and reference hash values.

89.

What is the Hypertext Transfer Protocol (HTTP)?

a)

An application layer protocol that provides a method of communication between clients and web servers.

b)

A federal law in the U.S. that protects patients' health information.

c)

An algorithm that produces a code that cannot be deciphered.

d)

A network device that transmits information to every device on the network.

90.

What is the Secure Hypertext Transfer Protocol (HTTPS)?

a)

A network protocol that provides a secure method of communication between clients and web servers.

b)

A federal law in the U.S. that protects patients' health information.

c)

An algorithm that produces a code that cannot be deciphered.

d)

A network device that transmits information to every device on the network.

91.

What does "Identify" mean in the context of cybersecurity risk management according to NIST?

a)

A core function of NIST related to cybersecurity risk management and its effect on an organization's people and assets.

b)

A network protocol that provides a secure method of communication between clients and web servers.

c)

An algorithm that produces a code that cannot be deciphered.

d)

A network device that transmits information to every device on the network.

92.

What is the purpose of Identity and access management (IAM)?

a)

A set of standards for wireless communication

b)

A process for managing digital identities

c)

A security procedure for incident response

d)

A method for data encryption

93.

What does IEEE 802.11 refer to?

a)

A security breach protocol

b)

A type of security incident

c)

A set of standards for wireless LAN communication

d)

A data encryption method

94.

What is the meaning of 'Immutable' in the context of this document?

a)

A type of security incident

b)

A process in incident response

c)

An object that cannot be changed after creation

d)

A method for data encryption

95.

What is 'Incident escalation'?

a)

The process of documenting a security incident

b)

The process of identifying and handling a potential security incident

c)

The process of adding space at the beginning of a line of code

d)

The process of protecting unauthorized access and distribution of data

96.

What is an 'Indicator of compromise (IoC)'?

a)

A document that outlines incident response procedures

b)

Observable evidence that suggests signs of a potential security incident

c)

A series of observed events indicating a real-time incident

d)

A number assigned to every element in a sequence

97.

What is the purpose of 'Information privacy'?

a)

To include the value of comparison in operations

b)

To add space at the beginning of a line of code

c)

To protect against unauthorized access and distribution of data

d)

To assign a number to every element in a sequence

98.

What is the practice of keeping data in all states away from unauthorized users known as?

a)

Input validation

b)

Information security (InfoSec)

c)

Internal hardware

d)

IP spoofing

99.

What does an Injection attack involve?

a)

Validating inputs from users and other programs

b)

Malicious code inserted into a vulnerable application

c)

Translating Python code into runnable instructions

d)

Monitoring system activity for possible intrusions

100.

What is an Integrated development environment (IDE) used for?

a)

Keeping data secure from unauthorized users

b)

Inserting malicious code into applications

c)

Writing code that provides editing assistance and error correction tools

d)

Translating code into runnable instructions