wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Cybersecurity Units 2-4 Review

Total questions: 85

Worksheet time: 3hrs 33mins

Name
Class
Date
1.

A set of methods used by cyber criminals to deceive individuals into handing over information that they can use for fraudulent purposes’ is a definition of what?

a)

Impersonatin

b)

Shoulder Surfing

c)

Phishing

d)

Social Engineering

2.

What is one way somebody could protect themselves from shoulder surfing?

a)

share your pin with someone you trust

b)

create a pin that is easy to remember

c)

have a pin that is the same as your friends

d)

be aware of who is around you

3.

While waiting in the lobby of your building for a guest, you notice a man in a red shirt standing close to a locked door with a large box in his hands. He waits for someone else to come along and open the locked door and then proceeds to follow her inside. What type of social engineering attack have you just witnessed?

a)

Impersonation

b)

Phishing

c)

Boxing

d)

Tailgating

4.

 A user in your organization contacts you to see if there’s any update to the “account compromise” that happened last week. When you ask him to explain what he means, and the user tells you he received a phone call earlier in the week from your department and was asked to verify his user ID and password. The user says he gave the caller his user ID and password. This user has fallen victim to what specific type of attack?

a)

Spear phishing

b)

Vishing

c)

Phishing

d)

Replication

5.

Coming into your office, you overhear a conversation between two security guards. One guard is telling the other she caught several people digging through the trash behind the building early this morning. The security guard says the people claimed to be looking for aluminum cans, but only had a bag of papers—no cans. What type of attack has this security guard witnessed?

a)

Spear phishing

b)

Pharming

c)

Dumpster diving

d)

Rolling refuse

6.

Which of the following is a type of social engineering attack in which an attacker attempts to obtain sensitive information from a user by masquerading as a trusted entity in an e-mail?

a)

Phishing

b)

Pharming

c)

Spam

d)

Vishing

7.

Which of the following is/are psychological tools used by social engineers to create false trust with a target?

a)

Impersonation

b)

Urgency or scarcity

c)

Authority

d)

All of the above

8.

Your boss thanks you for pictures you sent from the recent company picnic. You ask him what he is talking about, and he says he got an e-mail from you with pictures from the picnic. Knowing you have not sent him that e-mail, what type of attack do you suspect is happening?

a)

Phishing

b)

Spear phishing

c)

Reconnaissance

d)

Impersonation

9.

Lisa received a phone call at work from someone identifying themselves as a person who sells the company hardware regularly. He said he's calling customers to inform them of a problem with database servers they've sold, but he said the problem only affects servers running a specific operating system version. He asks Lisa what OS versions the company is running. Which BEST describes this tactic?

a)

Pretexting

b)

Tailgating

c)

Pharming

d)

Smishing

10.

A man in a maintenance uniform walked up to your organization's receptionist desk. He said he was called by the CIO (Chief Information Officer) and asked to fix an issue with the phones and needed access to the wiring closet. The receptionist asked the man to show his building access badge, and then she verified that he was on the list of approved personnel to access this secure area. What type of attack will the checks the receptionist performed prevent?

a)

Tailgating

b)

Phishing

c)

Impersonation

d)

Whaling

11.

A company's security policy requires employees to place all discarded paper documents in containers for temporary storage. These papers are later burned in an incinerator. Which of the following attacks are these actions MOST likely trying to prevent?

a)

Shoulder surfing

b)

Tailgating

c)

Smishing

d)

Dumpster Diving

12.

Homer, the Chief Financial Officer of a bank, received an email from Lisa, the company's Chief Executive Officer (CEO). Lisa states she is on vacation and that she lost her purse and all her credit cards. She asks Homer to transfer $5,000 to her account. Which of the following best identifies this attack?

a)

Phishing

b)

Vishing

c)

Smishing

d)

Whaling

13.

Homer has been looking for the newest version of a popular smartphone. However, he can't find it in stock anywhere. Today, he received an email advertising the smartphone. After clicking the link, his system was infected with malware. Which of the following principles is the email sender employing?

a)

Authority

b)

Intimidation

c)

Scarcity

d)

Trust

14.

How can we make sure an email is not a phishing scam?

(select all that apply)

a)

Check 'from' address

b)

Hover over links to check URL

c)

Be careful opening attachments

d)

Reply asking for more information

15.

What does OSINT stand for?

a)

Open Source Intelligence

b)

Open Source Interals

c)

Official Secure Information Neutralisation

d)

Official Standard Intelligence Technology

16.

What types of information are hackers looking for when performing an OSINT attack?

(select all that apply)

a)

Addresses

b)

Jobs

c)

Devices used

d)

Family

e)

How funny someone is

17.

Which of these can help protect against OSINT attacks?

a)

Don't post personal information online

b)

Never post fake information

c)

Trust everyone online

d)

Uncheck all privacy options

18.

Scammers may ​ (a)   vendors, clients, or executives to ​ (b)   into ​ (c)   or sharing sensitive​ (d)   .

Choose from the below words
impersonate
trick employees
transferring funds
information
19.

Phishing is a technique where attackers ​ (a)   legitimate entities, such as banks or businesses, to ​ (b)   into ​ (c)   sensitive ​ (d)   like passwords or credit card details.

Choose from the below words
impersonate
trick individuals
providing
information
20.

A data ​ (a)   attack is where an attacker ​ (b)   ​all (c)   between two parties. To the users, appears as if they are connected directly with each other, while the attacker secretly ​ (d)   and controls the information being exchanged.

Choose from the below words
interception
captures
communications
copies
malware
phishes
deletes
21.

Phishing attacks often come in the form of ​ (a)   emails, but they can also occur via ​ (b)   , SMS (smishing) or phone calls. During a cybersecurity workshop, Daniel, Maya, and Abigail learned that by ​ (c)   into disclosing confidential information, attackers can ​ (d)   access to the university's systems or networks.

Choose from the below words

deceptive

text messages

tricking employees

gain unauthorised

22.
Claire,a co-worker,is browsing the internet and wants to know if it's safe to enter her credit card information into a website.what do you tell her to look for?
a)
HTTPS://
b)
HTTP://
c)
SSL://
d)
TLS://
23.
Ray, a co-worker,is concerned that his computer is infected with adware. what symptoms should you tell ray to look for to confirm his suspicions?
a)
Excessive pop-ups.
b)
pizza
c)
search polo
d)
multifactor login redirection
24.
Which type of software will help protect your computer from malicious network traffic?
a)
Software firewall 
b)
password complexity tool
c)
antispyware
d)
antivirus
25.
Your manager just got a new workstation and is not part of a domain.he wants to know which user account he should disable to increase security. what should you telll him?
a)
Guest
b)
users
c)
power users
d)
administrator
26.
The managers at your company have decided to implement stricter security policies.which of the following login schemes will help them achieve this goal? 
a)
single sign-on
b)
Multifactor authentication
c)
password confidentication
d)
HTTPS
27.
Your coworker Rachel has recently discovered that when she starts typing her name into a field in a web browser,her whole name appears as well as her address in the appropriate boxes.what is this due to?
a)
adware infection
b)
single sign-on
c)
suspicious hyperlinks
d)
Autofill
28.
You have been asked to give training on network security.for your section on password management,which options should you recommend to users?
a)
do not use complex passwords because they are easy to forget
b)
Change default passwords on systems.
c)
use the same password on multiple systems so they are easy to remember
d)
do nothing
29.
You receive an email in your inbox from your friend sara. the title of the email is "this is so cool!" and inside the email is an attachment with an .exe extension.what should you do?
a)
delete the email
b)
click the attachment
c)
run virus scan,then click the attachment 
d)
call sara to see if she sent you the mail.
30.

What is the purpose of a vulnerability assessment?

a)

To identify and mitigate vulnerabilities in a system

b)

To analyze the security of digital products

c)

To reduce the attack surface of a system

d)

To harden a system against cyber attacks

31.

William, a cybersecurity student, is working on a project to analyze vulnerability data. He needs to use a database that is commonly used as an industry repository of vulnerability data. Which database should he use?

a)

Common Vulnerability and Exposure (CVE) database

b)

National Vulnerability Database (NVD)

c)

Microsoft Baseline Security Analyzer (MBSA)

d)

Cybersecurity & Infrastructure Security Agency (CISA)

32.

What is the purpose of system hardening?

a)

To secure user access and backups

b)

To identify and mitigate vulnerabilities

c)

To analyze the security of digital products

d)

To reduce the attack surface of a system

33.

What is the purpose of user access control (UAC) settings?

a)

To restrict user actions and limit vulnerabilities

b)

To secure user access and backups

c)

To analyze the security of digital products

d)

To reduce the attack surface of a system

34.

Abigail received an email warning about the increasing threat of ransomware and data loss. She wants to know, what is the first level of defense she should consider?

a)

Creating system images of her computer

b)

Using sync services like Dropbox or Google Drive

c)

Performing regular software updates

d)

Maintaining regular backups of her data

35.

Charlotte, Anika, and Mason are part of the IT team in a company. They are discussing the best practices for securing user access. Which of the following practices mentioned by them is NOT recommended?

a)

Severely restrict administrative rights

b)

Implement strong password policies

c)

Grant unlimited access to all users

d)

Follow the least privilege principle

36.

What is the purpose of system images?

a)

To restrict user actions and limit vulnerabilities

b)

To secure user access and backups

c)

To analyze the security of digital products

d)

To create backups that include the operating system

37.

What is the primary function of the least privilege principle in system security?

a)

To grant all users unrestricted access

b)

To limit user access based on their role and responsibilities

c)

To ensure regular software updates

d)

To backup important data regularly

38.
A technician is installing a private PC in a public workspace. Which of the following password practices should the technician implement on the PC to secure network access?
a)
A. Remove the guest account from the administrator's group
b)
B. Disable single sign-on
c)
C. Issue a default strong password for all users
d)
D. Require authentication on wake-up
39.
A new company policy states that all end-user access to network resources will be controlled based on the users' roles and responsibilities within the organization. Which of the following security concepts has the company just enabled?
a)
A. Certificates
b)
B. Least privilege
c)
C. Directory permissions
d)
D. Blacklists
40.

Lists directory contents. You will use this to display information about files and

directories.



(a)  

41.

Changes the current directory to dir. If you execute it without specifying

a directory, it changes the current directory to your home directory. This is how you

navigate around the system.



(a)  

42.

Displays the present working directory name. If you don't know what directory

you are in, it will tell you.



(a)  

43.

Concatenates and displays files. This is the command you run to view

the contents of a file.

(a)  

44.

Displays arguments to the screen

(a)  

45.

Displays the online manual for command.

(a)  

46.

How do you change permissions for a file?

a)

chmod

b)

chown

c)

chper

d)

permission

47.

How can you show hidden files?

a)

ls -a

b)

dir

c)

show -h

d)

unhide

48.
Move files and directories/ Rename files and directories
a)
mv
b)
rmdir
c)
mkdir
49.
Make a new directory
a)
rmdir
b)
mkdir
c)
mv
50.
Copy files
a)
cp
b)
rmdir
c)
mkdir
51.

A command-line command in Linux that allows to search files for lines containing a match to a given pattern is called:

a)

grep

b)

find

c)

cat

d)

touch

52.

In order to create an empty file one must use ​ (a)  

Choose from the below words
touch
blend
copy
ls
53.

The output of whoami is a:

a)

string

b)

file

c)

directory

d)

username

54.

Display contents of a file hello.txthello.txt

(a)  

55.
What is the following word ... 79 70 70
a)
ON
b)
OFF
c)
OR
d)
ONE
56.
Convert 1011 0011 into hexadecimal
a)
3D
b)
D3
c)
B3
d)
3B
57.
11111 can be read as what decimal number?
a)
31
b)
10
c)
18
d)
63
58.
Binary is:
a)
a system using the digits 0 and 1 to represent a letter, digit, or other character in a computer or other electronic device.
b)
the most common format for text files in computers and on the Internet
59.

What is ASCII for

a)

a numerical code for letters

b)

A way of checking binary numbers

c)

American writing rules

d)

Chinese letters

60.

Which of the following number systems do we tend to use in computing?

a)

Decimal

b)

Binary

c)

Hexadecimal

d)

Quinary

61.

When viewing data if a 0x comes up we know the next value is represented as ​ ​ (a)  

Choose from the below words
hexadecimal
decimal
binary
octal
62.

What is 0x110 represented as a decimal?

a)

272

b)

25616

c)

110

d)

284

63.

How many bits are in a byte?

a)

1

b)

2

c)

4

d)

8

64.

The smallest unit of information in a computer

a)

Byte

b)

Bit

c)

Pixel

d)

It's too small I can't see it

65.
Upper and lower case letters have a different ASCII code. (3-4)
a)
True
b)
False
66.

The image above most likely represents which type of number system?

a)

Hexadecimal Number

b)

Decimal Number

c)

Octal Number

d)

Binary Number

67.

What is the decimal equivalent of the hexadecimal digit B?

a)

10

b)

11

c)

12

d)

13

68.

Why do we need to encode all data in binary?

a)

Because binary is very small

b)

Because computers only understand binary

c)

Because binary is very fast

d)

Because binary is space efficient

69.

Hexadecimal number system is a base (a)   system

70.
What is the significance of zero-day vulnerabilities in system security?
a)
They are vulnerabilities that have been present for a long time
b)
They are vulnerabilities that are unknown to the software vendor
c)
They are vulnerabilities that only affect outdated systems
d)
They are vulnerabilities that are easily patched
71.
How can the use of outdated software contribute to system vulnerabilities?
a)
By reducing the risk of exploitation
b)
By introducing known security flaws
c)
By increasing system security measures
d)
By enhancing data protection
72.
What is a crucial step in mitigating and preventing vulnerabilities?
a)
Visiting suspicious websites
b)
Regular software updates
c)
Using weak passwords
d)
Disabling security protocols
73.
What are computer system vulnerabilities?
a)
Characteristics of efficient computing systems
b)
Strengths and advantages of computing systems
c)
Weaknesses or flaws found in computing systems
d)
Features that enhance the security of computing systems
74.
How can social engineering tactics contribute to system vulnerabilities?
a)
By conducting regular vulnerability assessments
b)
By increasing user awareness
c)
By improving system security measures
d)
By manipulating individuals to disclose sensitive information
75.

What is a potential threat of using USB storage devices?

a)

Introduction of viruses to a system

b)

Increased system performance

c)

Enhanced data security

d)

Improved file transfer speed

76.

William, a cybersecurity student, is working on a project to analyze vulnerability data. He needs to use a database that is commonly used as an industry repository of vulnerability data. Which database should he use?

a)

Common Vulnerability and Exposure (CVE) database

b)

National Vulnerability Database (NVD)

c)

Microsoft Baseline Security Analyzer (MBSA)

d)

Cybersecurity & Infrastructure Security Agency (CISA)

77.
You are visiting a website and accidentally click on a link to accept free software. Which tool will keep the software from installing on your PC?
a)
UAC
b)
Windows Defender
c)
AppLocker
d)
Avast Antivirus
78.

This is to minimize the risk

a)

mitigate

b)

vulnerability

c)

exploit

d)

redundancy

79.

A security flaw, glitch, or weakness found in software code that could be exploited by an attacker

a)

vulnerability

b)

exploit

c)

redundancy

d)

mitigate

80.

specific code or attack technique that uses a vulnerability to carry out an attack or gain unauthorized access

a)

vulnerability

b)

exploit

c)

redundancy

d)

mitigate

81.

a tweak to the OS code that will fix an issue in how it runs or compatibility with devices and applications

a)

Patch / Update

b)

Hotfix

c)

Critical

d)

Security

82.

fix for a bug that is affecting OS functionality

a)

Patch / Update

b)

Hotfix

c)

Critical

d)

Security

83.

By disabling unnecessary services, the performance can be improved significantly, especially on computers with low system resources.

a)

True

b)

False

84.

Common Device Hardening Techniques

a)

Anti-virus Software

1.

Scans for malware and removes it

b)

Encryption

2.

Scrambles the contents of a message or file

c)

Firewalls

3.

Monitors and blocks unwanted data accessing the system

d)

Auto -Installing software Updates

4.

Updates include patches which fixes know vulnerabilities

e)

Blocking USB ports

5.

Stops users transferring malware using a physical medium

85.

Another method of device hardening is ​​ (a)   user ​ (b)   . This involves ​ (c)   old user accounts

Choose from the below words
limiting
access
disabling