Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

ICITP Certification Quiz

Total questions: 100

Worksheet time: 1hrs 8mins

Name
Class
Date
1.

What is a common method used by cybercriminals to trick individuals into providing sensitive information such as passwords or credit card details?

a)

Spoofing

b)

Malware

c)

Shoulder surfing

d)

Phishing

2.

Which component acts as a barrier between a trusted internal network and untrusted external networks in order to control incoming and outgoing network traffic?

a)

Router

b)

Switch

c)

Firewall

d)

Antivirus

3.

What process converts sensitive information into a secret code to protect it during transmission or storage?

a)

Obfuscation

b)

Decryption

c)

Encoding

d)

Encryption

4.

What type of software is designed to infiltrate or damage a computer system without the owner's consent?

a)

Spyware

b)

Trojan

c)

Malware

d)

Ransomware

5.

How can individuals protect themselves from social engineering attacks that manipulate human behavior to divulge confidential information?

a)

Ignore any security warnings

b)

Be cautious of unsolicited requests, verify identities, avoid suspicious links, update passwords regularly.

c)

Share passwords with strangers

d)

Click on all links in emails

6.

What is the term used to describe a type of cyber attack where the attacker pretends to be someone else in order to steal sensitive information?

a)

Impersonation

b)

Eavesdropping

c)

Denial of Service

d)

Packet Sniffing

7.

Which of the following is a common method used by cybercriminals to gain unauthorized access to a system by guessing passwords?

a)

Brute Force Attack

b)

Phishing Attack

c)

SQL Injection

d)

Man-in-the-Middle Attack

8.

What security measure involves verifying the identity of a user by requiring two or more pieces of evidence?

a)

Single Sign-On

b)

Multi-Factor Authentication

c)

Biometric Authentication

d)

Single-Factor Authentication

9.

Map Identification and Authentication with the corresponding attribute of CIA

a)

Confidentiality

b)

Integrity

c)

Availability

10.

What is a keylogger

a)

Virus

b)

Spyware

c)

Adware

d)

Windows Analysis tool

11.

Special types of viruses that can travel from computer to computer without human action; self-replicating and can multiply until it uses up the computer's resources

a)

Spyware

b)

Worms

c)

Trojans

d)

Phishing

12.
What type of key is not shared and computers cannot decrypt a message without it?
a)
Free key
b)
Private key
c)
Public key
d)
Personal key
13.

Asymmetric encryption uses only 1 key.

a)

True

b)

False

c)

Maybe

d)

God Knows

14.

The process of converting a ciphertext into plaintext.

a)

encryption

b)

decryption

c)

plaintext

d)

cryptography

15.

In public key cryptography, what is the private key used for?

a)

Encrypting data

b)

Decrypting data

c)

Verifying digital signatures

d)

Generating digital signatures

16.

What does SSL stand for?

a)

Secure Socket Layer

b)

Secret Secure Layer

17.

In the realm of cybersecurity, how is the term "vulnerability" defined?

a)

An impenetrable system

b)

A system flaw susceptible to exploitation

c)

An encryption standard

d)

A network communication protocol

18.

What does availability of data refer to?

a)

The level of assurance that data exists

b)

The level of assurance that data will be restricted to people who need it, when they need it

c)

The level of assurance that data will be accurate and trustworthy

d)

The level of assurance that data will be available to people who need it, when they need it

19.

What does integrity of data refer to?

a)

The level of assurance which can be given as to how structured data is

b)

The level of assurance which can be given as to how accurate and trustworthy data is

c)

The level of assurance which can be given as to how strong data is

d)

The level of assurance which can be given as to how relevant the data is

20.

Emma is working at a bank and discovers that she is able to transfer $10,000 to her account from a customer's account without any authorization.

Which part of the CIA triad has been broken?

a)

C

b)

I

c)

A

d)

None of the above

21.

What does integrity of data refer to?

a)

The level of assurance which can be given as to how structured data is

b)

The level of assurance which can be given as to how accurate and trustworthy data is

c)

The level of assurance which can be given as to how strong data is

d)

The level of assurance which can be given as to how relevant the data is

22.

What does availability of data refer to?

a)

The level of assurance that data exists

b)

The level of assurance that data will be restricted to people who need it, when they need it

c)

The level of assurance that data will be accurate and trustworthy

d)

The level of assurance that data will be available to people who need it, when they need it

23.

What is the principle of "Least Privilege" in cybersecurity?

a)

Changing passwords frequently

b)
Granting users access to all resources except for critical ones.
c)
Granting users access to all resources without any restrictions.
d)
Granting users the minimum level of access necessary to perform their job functions.
24.

Anika opens her fitness tracking app to start logging a workout. The app crashes, and she is unable to log her workout.

a)

C

b)

I

c)

A

d)

None of the above

25.

Ensuring the safety of the school premises, conducting regular fire drills, installing security cameras, providing emergency response training, and having a well-defined evacuation plan are methods to ensure

a)

Protection

b)

Integrity

c)

Confidentiality

d)

Availability

26.

What is the process of verifying a person's identity?

a)

Authentication

b)

Authorization

c)

Auditing

d)

Accounting

27.

In the realm of cybersecurity, how is the term "vulnerability" defined?

a)

An impenetrable system

b)

A system flaw susceptible to exploitation

c)

An encryption standard

d)

A network communication protocol

28.

What does GUI stand for in the context of computer technology?

a)

General Utilities Intervention

b)

Graphical User Interface

c)

General User Intervention

d)

Graphical Utilities Interface

29.

Which best describes a "botnet"?

a)

A malware persistence mechanism

b)

ChatGPT

c)

A collection of automated scripts used for system compromise

d)

A collection of infected computers controlled by a hacker

30.

"WannaCry" is a type of what?

a)

exploit

b)

worm

c)

ransomware

d)

trojan

31.

Which type of malware disguises itself as a legitimate software update to trick users into downloading and executing it?

a)

Virus

b)

Worm

c)

Trojan

d)

Ransomware

32.

What cybersecurity principle involves protecting sensitive information from unauthorized access or disclosure?

a)

Availability

b)

Integrity

c)

Confidentiality

d)

Authentication

33.

Olivia suspects that her computer has been infected with malware. Which type of malware collects user data, including keystrokes and browsing habits, without their knowledge?

a)

Adware

b)

Spyware

c)

Ransomware

d)

Worm

34.

Which cybersecurity concept focuses on ensuring that critical systems are available and accessible when needed during a cyber attack?

a)

Integrity

b)

Confidentiality

c)

Availability

d)

Authorization

35.

Enumerate the various categories of hackers in the context of a cybersecurity workshop.

a)

Insider Threat, Phishing, Ransomware, Firewall

b)

Malware, Spyware, Adware, Worm

c)

Black Hat, White Hat, Blue Hat, Red Hat

d)

White Hat, Black Hat, Grey Hat.

36.
When responding to a security incident, your team determines that the vulnerability that was exploited was not widely known to the security community, and that there are no currently known definitions/listings in common vulnerability databases or collections. This vulnerability and exploit might be called ______?
a)
Malware
b)
Critical
c)
Intrusion
d)
Zero-day
37.

The presence of a weakness in a system, program, or network is referred to as a:

a)

vulnerability

b)

exploit

c)

adware

d)

malware

38.

 John finds a message on his phone that he thinks might be a scam.  He should:

a)

Forward the message to his friends to see if they think it's a scam too.

b)

Reply and ask the sender not to send more mail.

c)

Delete the message

d)

Change your phone number

39.

What purpose does a hypervisor serve in the context of virtualization?

a)

Ensuring secure network traffic

b)

Facilitating the creation of virtual machines

c)

Guarding against phishing attacks

d)

Encrypting data at rest

40.
It helps keep data and equipment safe by giving only the appropriate people access.
a)
network security
b)
firewall
c)
antivirus
d)
security threats
41.
It is a self-replicating program that is harmful to networks.
a)
Worm
b)
Trojan Horse
c)
Virus
42.
It disguises as useful software.
a)
Worm
b)
Virus
c)
Trojan Horse
43.
You receive an email with an attachment that says 'Winner' but you don't remember entering any competition. What do you do?
a)
Reply to the message asking them to stop sending you mail.
b)
Open the attachment, you've won something!
c)
Delete the email without reading it.
d)
Forward the email to a friend, it will be funny to trick them too.
44.

WHAT THE MEANING OF CLI?

a)

control command line

b)

command line interface

c)

central line Interface

d)

command line intranet

45.

WHAT THE MEANING OF GUI

a)

Graphical User Internet

b)

Graphical Union Interface

c)

Grep Universal Interface

d)

Graphical User Interface

46.

................................ is way to run multiple operating systems and user applications on the same hardware

a)

Virtualization

b)

Storage

c)

Data Warehousing

d)

Data Mining

47.

Type 1 Hypervisor.......................

Type 2 Hypervisor .......................

a)

also called bare metal or native

also known as hosted hypervisors

b)

also known as hosted hypervisors

also called bare metal or native

c)

also called as full virtualization

also called as new virualization

d)

None of the above

48.

An Operating System is a program that helps the user to communicate between the software and ___________

a)

Memory

b)

Hardware

49.

Alice told her friend Bob about her email password. And then she found Bob changed some her emails and sent emails to others. What traids are involved into this case?

a)

Confidentially and Integrity

b)

Integrity and Availability

c)

Confidentally and Availability

d)

Confidentally, Integrity and Availability

50.

The process of converting a ciphertext into plaintext.

a)

encryption

b)

decryption

c)

plaintext

d)

cryptography

51.

If your friend asks you to share your password to use your computer for work, what should you do?

a)

Being your friend, you share the password

b)

You decline to provide

c)

You login yourself and allow him to work

d)

You create his login on your computer

52.

Turning off the GPS functions on your smartphone prevents any tracking of your phone’s location.?

a)

True

b)

False

53.

Which of these isn't a cyber crime?

a)

Accessing unauthorized data/ using someone's computer without permission

b)

Tricking people into downloading malware

c)

Accessing the DarkWeb

d)

Creating an account on something you're not old enough for

54.

What is meant by non-repudiation?

a)

If a user does something, they can't later claim that they didn't do it.

b)

Controls to protect the organization's reputation from harm due to inappropriate social media postings by employees, even if on their private accounts and personal time. 

c)

It is part of the rules set by administrative controls.

d)

It is a security feature that prevents session replay attacks.

55.

The concept of "secrecy" is most related to which foundational aspect of security?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Plausibility

56.

Which of the following is an example of a "something you are" authentication factor?

a)

A credit card presented to a cash machine

b)

Your password and PIN

c)

A user ID

d)

A photograph of your face

57.

What are the three pillars of information assurance?

a)

Identification, Authentication, Non-repudiation

b)

Data, User, Infrastructure

c)

Confidentiality, Integrity, Availability

d)

PII, PHI, Sensitive information

58.

Sensitivity is a measure of the ...?

a)

… pertinence assigned to information by its owner, or the purpose of representing its need for urgency.

b)

… importance assigned to information by its owner, or the purpose of representing its need for protection.

c)

… urgency and protection assigned to information by its owner.

d)

… protection and timeliness assigned to information by its owner, or the purpose of representing its need for urgency.

59.

The process of verifying or proving the user's identification is known as:?

a)

Confidentiality

b)

Authentication

c)

Authorization

d)

Identification

60.

Which of the following Cybersecurity concepts guarantees that information is accessible only to those authorized to access it?

a)

Non-repudiation

b)

Authentication

c)

Confidentiality

d)

Accessibility

61.

A USB pen with data passed around the office is an example of:?

a)

Data in transit

b)

Data at rest

c)

Data in use

d)

Data in motion

62.

Passport, ID card, and security token are examples of:?

a)

Multi-factor Authentication

b)

Something you have

c)

Something you are

d)

Something you know

63.

A file that is open is an example of:?

a)

Data in motion

b)

Data in storage

c)

Data during processing

d)

Data open

64.

You try to install a program, but the system tells you that only administrators can do that, you probably don't have enough?

a)

Authentication

b)

Non-repudiation

c)

Availability

d)

Authorization

65.
What are vulnerabilities in the context of risk management?
a)
The consequences or impacts of a risk event
b)
The potential threats that could exploit vulnerabilities
c)
The weaknesses or flaws in assets that can be exploited by threat actors
d)
The likelihood of a risk occurring
66.
Which of the following is an example of a tangible asset?
a)
Intellectual property
b)
Customer database
c)
Data center server
d)
Software application
67.
Which of the following threat actors would be generally considered the most dangerous?
a)
Insiders
b)
Script kiddies
c)
Outside individuals
d)
Intelligence
68.
What is the purpose of risk assessment in risk management?
a)
To identify potential vulnerabilities in an organization's assets
b)
To analyze the likelihood and impacts of various threats
c)
To transfer risks to external parties
d)
To implement security controls to mitigate risks
69.
Which of the following is a common risk assessment technique?
a)
Risk avoidance
b)
Risk acceptance
c)
Risk analysis
d)
Risk transference
70.
To which of the following should a security professional report violations of a security policy when working for a company?
a)
National authorities
b)
Company management
c)
A court of law
d)
Nobody
71.

What does this padlock sign mean in the address bar of your browser?

a)

The site is secure and data is transmitted using SSL

b)

There is a padlock available for purchase

c)

The website does not include "safety locks"

d)

The page is locked down for some odd reason

72.
If the same key is used to encrypt and decrypt a message, this is known as? 
a)
Symmetric encryption
b)
Encryption doesn't exist!
c)
Asymmetric encryption
d)
Same-key encryption
73.
If there’s no lock in the address bar and the web address says HTTP without an S, that means every bit of data you send is private and safe.
a)
True
b)
False
74.
What type of key can be freely shared with anyone so that they can encrypt a message?
a)
Personal key
b)
Private key
c)
Free key
d)
Public key
75.

Asymmetric encryption uses only 1 key.

a)

True

b)

False

c)

Maybe

d)

God Knows

76.
If a friend of yours had this stuck on their laptop, what would you advise them to do?
a)
Great idea, you should always write down your password somewhere so you don't forget it!
b)
You need to make sure all your passwords are the same as this one!
c)
You should use a stronger password which includes letters and symbols and more characters, yours is too easy to guess!
d)
Use a shorter password so you can remember it better!
77.
DDoS is a type of cyber attack which stands for?
a)
Distributed Delivery Of Service
b)
Delivery Denial Of System
c)
Distributed Denial Of Service
d)
Denial Distribution Of Service
78.
DDoS is a type of cyber attack which stands for?
a)
Distributed Delivery Of Service
b)
Delivery Denial Of System
c)
Distributed Denial Of Service
d)
Denial Distribution Of Service
79.

What do we call unscrambled, readable data?

a)

ASCII

b)

Ciphertext

c)

Plaintext

d)

Purple prose

80.

How does asymmetric encryption differ from symmetric encryption?

a)

Asymmetric encryption uses the same key for both encryption and decryption

b)

Asymmetric encryption uses different keys for encryption and decryption

c)

Asymmetric encryption is only used for data storage

d)

Asymmetric encryption is less secure than symmetric encryption

81.

How can DDoS attacks be prevented?

a)

Ignoring the issue and hoping it goes away on its own

b)

Allowing all incoming traffic without any filtering

c)

Installing more servers to handle the traffic

d)

Using firewalls, intrusion detection systems, and load balancers to filter and manage incoming traffic

82.

What is a common method for detecting DDoS attacks?

a)

Scanning for viruses

b)

Analyzing server logs

c)

Monitoring network traffic

d)

Updating software patches

83.

What is the difference between a DoS and a DDoS attack?

a)

A DoS attack is carried out by a group of hackers, while a DDoS attack is carried out by a single hacker.

b)

A DoS attack is more difficult to detect than a DDoS attack.

c)

A DDoS attack is less harmful than a DoS attack.

d)

A DoS attack is carried out by a single source, while a DDoS attack is carried out by multiple sources.

84.

How can businesses prepare for potential DDoS attacks?

a)

Only focusing on cybersecurity after an attack has already occurred

b)

Hiring more salespeople to increase revenue

c)

Ignoring the potential threat and hoping it never happens

d)

Implementing DDoS protection solutions, regularly testing network infrastructure, and having a response plan in place

85.

Malicious emails that aim to attack company executives are an example of:?

a)

DDOS

b)

Spear phishing

c)

Phishing

d)

Whaling

86.

An Internet Service Provider (ISP)

a)

is a web page

b)

is a web browser

c)

provides access to internet

d)

Funds access to the internet for 3rd World CountriesThis is a wrong answer

87.

Which connection type is a wireless method of sending information using radio waves?

a)

Fibre optic

b)

Wi-Fi

c)

Broadband

d)

Cable

88.

What are the upper layers of the OSI layer?

a)

Transfer

b)

Data link and network

c)

Application, presentation, and session

d)

Physical, data link and network

89.

It is a number identifying of a computer or another device on the Internet

a)

Machine Language

b)

Binary Number

c)

IP Address

d)

Signal

90.

It is small network constrained to a small geographic area.

a)

LAN

b)

MAN

c)

PAN

d)

WAN

91.

For a Class C IPv4 Address, how many usable hosts are there by default?

a)

254

b)

64516

c)

65536

d)

255

e)

32768

92.
A network sniffer is software or hardware that:
a)
Records user activity and transmits it to the server
b)
Captures and analyzes network communication
c)
Protects workstations from intrusions
d)
Catalogs network data to create a secure index
93.

What is the default subent mask for the Class C network?

a)

255.255.254.0

b)

255.255.252.0

c)

255.255.255.128

d)

255.255.255.0

94.
What does "MAC" stand for in "MAC Address"?
a)
Media Access Control
b)
Mandatory Access Control
c)
Micro Access Control
d)
Media Access Certificate
95.
What are MAC addresses used to identify?
a)
Hardware
b)
Networking software
c)
DSI-Ware
d)
Firmware
96.
Which device is the MAC address hard coded in to ?
a)
Hub
b)
Switch
c)
Router
d)
Network interface card
97.

HTTP stands for..

a)

.. Hyper Technology Transmission Piece

b)

Hypertext Transfer Protocol

c)

Hypertext Talking Package

d)

Hypertext Transfer Program

98.

MODEM is

a)

Modulation Demodulation

b)

Modulator Demodulator

c)

Model Demodulator

99.

What is layer 6 of the OSI model?

a)

Spooky

b)

Presentation

c)

Session

d)

Transport

100.

What does TCP guarantee?

a)

delivery of data and packets delivered in the right order

b)

the route data will take

c)

fast, low latency delivery of data

d)

safe data without viruses