WorksheetsMalhub Cybersecurity Quiz 1
Total questions: 35
Worksheet time: 17mins
What does CIA stand for in cybersecurity?
Cybercrime Investigation Agency
Confidentiality, Integrity, Availability
Cloud Infrastructure Architecture
Certified Information Auditor
Which of the following is NOT a principle of the CIA triad?
Reliability
Confidentiality
Integrity
Availability
An employee accidentally clicks on a malicious link in a phishing email. This scenario represents what type of threat?
External threat
Internal threat (accidental)
Internal threat (intentional)
Network vulnerability
A weakness in a software program that could allow attackers to gain unauthorized access is an example of a:
Phishing attack
Denial-of-service attack
Vulnerability
Social engineering tactic
Which of the following is NOT a common type of cyberattack?
Cryptojacking
Data encryption
Password attack
Man-in-the-middle attack
Why is it important to understand vulnerabilities in cybersecurity?
To comply with fashion trends
To prioritize security efforts effectively
To learn how to exploit them ethically
To understand the history of hacking
Malicious software that aims to disrupt systems, steal data, or extort money is classified as:
Zero-day exploit
Malware
Denial-of-service attack
Phishing email
Which of the following statements about social engineering is TRUE?
It relies solely on technical exploits.
It exploits human vulnerabilities and emotions.
It is always detected by antivirus software
It involves no human interaction.
What is the main purpose of a Denial-of-Service (DoS) attack?
To steal sensitive information
To gain unauthorized access to a system
To overload a system and make it unavailable
To inject malicious code into a database
What is the best way to stay informed about new cyber threats?
Rely solely on your existing security software.
Regularly update software and follow cybersecurity news.
Never click on any links in emails.
Trust all messages that appear legitimate.
What kind of hacker is one who intends to do harm?
Grey Hat
White Hat
Black Hat
Hacker
What is the primary purpose of a firewall in a cybersecurity context?
To prevent physical access to a computer.
To block all incoming and outgoing network traffic.
To monitor and control network traffic based on a set of security rules.
To encrypt all data on a computer.
Phishing is a cyberattack method that involves tricking individuals into revealing sensitive information through deceptive emails or websites.
True
False
What type of Malware is this:
Transnet has been hacked through a Denial of Service attack , the hackers want money in crypto to allow Transet to resume operations.
Adware
Spyware
Ransomware
Malware
Which of the following is an example of two-factor authentication (2FA)?
Using a username and password to log in.
Using a fingerprint scan and a retinal scan to log in.
Using a smart card and a PIN to log in.
Using a CAPTCHA to log in.
What is the main goal of a DDoS (Distributed Denial of Service) attack?
To steal sensitive data from a computer .
To overload a network or website with traffic, making it unavailable to users.
To gain unauthorized access to a computer system.
To spread malware to multiple devices.
Which encryption protocol is commonly used to secure web traffic by ensuring data confidentiality and integrity?
HTTPS
FTP
SMTP
SNMP
What does the acronym "VPN" stand for in the context of cybersecurity?
Virtual Private Network.
Very Personal Network.
Virtual Public Network
Visual Private Network
Imagine you've been hired to break into a top-secret facility guarded by a highly advanced AI security system.
To bypass it, you decide to use a classic hacking technique.
What is the name of this technique where you attempt to guess a secret password by trying many combinations until you succeed?
Cybersleuthing
Whiz-hacking
Brute-force attack
Quantum phreaking
Which Port Numbers are part of the File Transfer Protocol (FTP)?
50
20/21
62/63
1/0
Encryption is the process of converting data into a code to prevent unauthorized access, and it can be used to protect data both at rest and in transit.
True
False
The process of verifying the identity of a user or system is known as:
Encryption
Authentication
Authorization
Accounting
What solution is recommended to address the risk posed by outdated software and systems?
Implement multi-factor authentication (MFA)
Encourage the use of weak passwords
Regularly update and patch software
Increase user access privileges
The main difference between an IDS and an IPS is:
An IDS detects and prevents attacks, whereas an IPS only detects attacks
An IDS encrypts data, whereas an IPS does not
An IPS can take actions to prevent threats, whereas an IDS only monitors and alerts
An IPS is software-based, while an IDS is hardware-based
What does encryption protect?
Physical access to computer hardware
The identity of the user
The network from all forms of cyber attacks
Data Privacy by making it unreadable without the correct key.
Which principle aims to limit user access to only the necessary permissions for their roles?
Defense in Depth
The CIA Triad
Non-repudiation
The Principle of Least Privilege
What is the primary goal of cybersecurity?
To promote software sales
To increase internet speed
To protect digital assets and information from cyber threats
To ensure the fastest data transmission
Multifactor Authentication (MFA) enhances security by:
Allowing users to choose any form of identity verification they prefer
Using only biometric verification for all users
Using a single, complex password
Requiring multiple methods of authentication from different categories of credentials
Which of the following best exemplifies the concept of Defense in Depth?
Layering multiple security measures such as firewalls, antivirus software, and encryption
Keeping software up to date
Implementing a strong policy against sharing passwords
Using a strong password
A zero-day vulnerability is:
A vulnerability that is fixed within a day of discovery
A flaw in software that is unknown to the vendor
A type of virus that spreads in 24 hours
A security patch released by software vendors
In the context of cybersecurity, __________ is to preserving secrecy as __________ is to ensuring data is accurate and untampered.
Authentication, Authorization
Confidentiality, Integrity
Firewall, Encryption
Risk reduction, Risk acceptance
__________ exploit unknown vulnerabilities, similarly, __________ can bypass security from within the organization.
Hacktivists, Criminals
Cyber espionage, DDoS attacks
Zero-day exploits, Insider threats
Malware, Phishing attacks
The goal of __________ is to steal information, whereas __________ aims to overload and disrupt services.
Cyber espionage, SQL injection
DDoS attacks, Insider threats
Hacktivists, Nation-states
Cyber espionage, DDoS attacks
What is the primary difference between vulnerabilities and risks in cybersecurity?
Vulnerabilities focus on potential loss, while risks focus on system weaknesses
Vulnerabilities depend on external factors, while risks exist independently
Vulnerabilities are conditional, while risks are inherent
Vulnerabilities represent system weaknesses, while risks represent potential loss or damage
Hackers are to malicious intent as hacktivists are to which motivation?
Financial gain
Social or political agenda
Personal curiosity
Technical skills
