wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Cybersecurity Quiz

Total questions: 60

Worksheet time: 30mins

Name
Class
Date
1.

The board of directors is responsible for which of the following?

a)

Transference

b)

Avoidance

c)

Mitigation

d)

Acknowledgement

2.

A forensic analyst needs to identify the hash value of a disk image. Which of the following is the most appropriate tool to use?

a)

Calculate the checksum

b)

Look for the hash value in the image

c)

Ensure proper procedures for chain of custody are followed

3.

A security manager has to map a network drive. Which of the following commands should be used?

a)

map-p 80 to 10.10.0.2

b)

nslookup 10.10.0.2

c)

pathping 10.10.10.0 -p 80

4.

A security manager has to map a network drive. Which of the following commands should be used?

a)

map-p 80 to 10.10.0.2

b)

Most VDI

c)

Avoidance

d)

Acknowledgement

5.

A help desk technician receives a call from a user who is unable to access a file. Which of the following should the technician do first?

a)

Check the metadata in the file

b)

Hover the mouse over the file

c)

Forward the email to the CIO and ask if the CIO sent it

6.

Which of the following is the best method to prevent a phishing attack?

a)

A visiting email stating a cash settlement has been approved

b)

A phishing email stating a cash settlement has been approved

c)

A phishing email stating a cash settlement has been approved

d)

A phishing email stating a cash settlement has been approved

7.

A security forensic analyst needs to identify the hash value of a disk image. Which of the following is the most appropriate tool to use?

a)

Snapshot

b)

Incremental

c)

Full

8.

The Chief Information Security Officer (CISO) is responsible for which of the following?

a)

Lessons learned

b)

Preparation

c)

Detection

d)

Containment

9.

Which of the following controls is used to prevent unauthorized access to a system?

a)

Preventive

b)

Deterrent

c)

Detective

10.

A security manager has to map a network drive. Which of the following commands should be used?

a)

map-p 80 to 10.10.0.2

b)

nslookup 10.10.0.2

c)

pathping 10.10.10.0 -p 80

11.

A cloud service provider offers a hybrid model. Which of the following is an example of a hybrid model?

a)

Public

b)

Community

c)

Private

12.

A security engineer is building a secure network. Which of the following protocols should be used to encrypt data in transit?

a)

AES

b)

EAP

c)

TLS

13.

A security engineer is building a secure network. Which of the following protocols should be used to encrypt data in transit?

a)

SSH

b)

S/MIME

c)

LDAPS

14.

Which of the following is a data loss prevention (DLP) technique?

a)

DLP

b)

TPM

c)

NIDS

15.

A cloud service provider offers a hybrid model. Which of the following is an example of a hybrid model?

a)

Hybrid VDI

b)

Private VDI

c)

Community VDI

16.

A company discovered that an attacker used a protocol to gain unauthorized access to their network. Which protocol was likely used?

a)

SNMPv3

b)

SFTP

c)

Telnet

17.

Which of the following is a data loss prevention (DLP) technique?

a)

DLP

b)

TPM

c)

FDE

18.

A security engineer is building a secure network. Which of the following protocols should be used to encrypt data in transit?

a)

TLS

b)

EAP

c)

HTTPS

19.

Which of the following is the best method to prevent a phishing attack?

a)

Network segmentation

b)

Patch management

c)

Multiple vulnerability scanners

20.

A security engineer is building a secure network. Which of the following protocols should be used to encrypt data in transit?

a)

AES

b)

HTTPS

c)

TLS

21.

A security analyst wants to test the connectivity to a remote server. Which of the following commands should be used?

a)

curl -head http://192.168.0.1

b)

ping -t 192.168.0.10

22.

Which of the following documents outlines the service levels and expectations between a service provider and a customer?

a)

SLA

b)

EOL

c)

MOU

23.

Multiple business accounts have been compromised. Which of the following is the most likely cause?

a)

Password history

b)

Complexity requirements

c)

Shared accounts

24.

An amusement park is concerned about the security of their ticketing system. Which of the following should be implemented first?

a)

Low FRR

b)

Low FAR

c)

Low efficacy

d)

Low CER

25.

A report from the company's Information Security Office indicates that a system has a false positive. Which of the following is the most likely cause?

a)

False positive

b)

True Negative

c)

False Negative

26.

Which biometric error would allow an unauthorized user to gain access to a system?

a)

False acceptance

b)

False rejection

c)

False denial

27.

A company suspects that an employee is accessing sensitive information without authorization. Which of the following should be implemented to prevent this?

a)

Enforce MFA when an employee logs in

b)

Implement geofencing

c)

Shift the access control scheme to a discretionary access control (DAC) model

28.

Employees who travel need to access the company's network securely. Which of the following should be implemented?

a)

PKI

b)

Blockchain

c)

OAuth

29.

C. SAML partners with which of the following to provide single sign-on (SSO) capabilities?

a)

Blockchain

b)

OAuth

c)

SAML

30.

Several universities are planning to collaborate on a research project. Which of the following cloud deployment models would be most appropriate?

a)

Community

b)

Private

c)

Public

d)

Hybrid

31.

A security analyst is working on a behavior-based detection method. Which of the following is the analyst most likely to use?

a)

Vulnerability scans

b)

User behavior analysis

c)

Security orchestration

d)

Threat hunting

32.

A company discovered an attack that is using a zero-day exploit. Which of the following is the company most likely experiencing?

a)

Insider threat

b)

APT

c)

Script kiddies

d)

Shadow IT

33.

The Chief Compliance Officer (CCO) is concerned about insider threats. Which of the following would be the best method to mitigate this risk?

a)

Filtering applicants who have worked at other banks

b)

Preventing any current employees from working at other banks

c)

Ensuring no new hires have worked at other banks

d)

Ensuring no new hires have worked at other banks that have had insider threats

34.

Which of the following techniques is used to hide the true nature of an attack?

a)

Obfuscation

b)

Normalization

c)

Execution

d)

Reuse

35.

Certain users are reporting issues where workstations are being accessed without their knowledge. Which of the following should be checked to identify the issue?

a)

Endpoint protection

b)

Travel times on logins

c)

Sensitive data is being accessed

d)

All user account passwords

36.

Which of the following attacks uses a program that captures keystrokes?

a)

Keylogger

b)

Brute-force

c)

Dictionary

d)

Rainbow

37.

An organization discovered an attack that is using a program to capture keystrokes. Which of the following is the organization most likely experiencing?

a)

Keylogger

b)

Brute-force

c)

Dictionary

d)

Remote access Trojan

38.

Officers log in to the file server and notice that the system is running slowly. Which of the following is the most likely cause?

a)

Logic bomb

b)

Cryptominer

c)

Spyware

d)

Remote access Trojan

39.

Certain users are reporting issues where workstations are being accessed without their knowledge. Which of the following should be checked to identify the issue?

a)

Endpoint protection

b)

Travel times on logins

c)

Sensitive data is being accessed

d)

All user account passwords

40.

A security analyst is reviewing logs and notices that several accounts have been locked out. Which of the following is the most likely cause?

a)

Keylogger

b)

Brute-force

c)

Dictionary

d)

Rainbow

41.

Which of the following is a type of malware that is designed to gain unauthorized access to a system?

a)

SQL Most Voted

b)

API attack

c)

DLL injection

d)

XSS

42.

A DBA reports that several databases have been compromised. Which of the following is the most likely cause?

a)

Logic bomb

b)

Fileless virus

c)

Remote access Trojan

d)

Rootkit

43.

A security analyst is reviewing logs and notices that several accounts have been locked out. Which of the following is the most likely cause?

a)

SQL injection

b)

XSS attack

c)

XSRF attack

d)

Replay attack

44.

An organization discovered an attack that is using a program to capture keystrokes. Which of the following is the organization most likely experiencing?

a)

Logic bomb

b)

Cryptominer

c)

Spyware

d)

Remote access Trojan

45.

A systems administrator is reviewing logs and notices the following entries: **1244** Timecard.exe **1244** ERROR: SUM **1244** Timecard.exe **1244** malcode: 8211 **1244** Checkfile: 8211 **1244** Checkfile: 8211 The administrator identifies the issue as a buffer overflow. Which of the following is the most likely cause?

a)

DLL injection

b)

API attack

c)

Buffer overflow

d)

Memory leak

46.

An organization discovered an attack that is using a program to capture keystrokes. Which of the following is the organization most likely experiencing?

a)

Logic bomb

b)

Cryptominer

c)

Spyware

d)

Remote access Trojan

47.

An employee received a suspicious email with an attachment. Which of the following is the most likely cause?

a)

Macro-enabled file

b)

Embedded Python code

c)

Bash scripting

d)

Credential-harvesting website

48.

A security analyst is reviewing logs and notices that several accounts have been locked out. Which of the following is the most likely cause?

a)

SQL injection

b)

API attack

c)

DLL injection

d)

XSS

49.

Which of the following is a type of malware that is designed to gain unauthorized access to a system?

a)

Shared Tenancy

b)

Zero-day

c)

Insider Threat

d)

Unsecured root accounts

50.

An organization maintains a development environment for testing new applications. Which of the following is the most likely stage of the environment?

a)

Development

b)

Production

c)

Test

d)

Staging

51.

Which of the following is the most likely stage of the environment where new applications are tested before being moved to production?

a)

Stage

b)

Development

c)

Production

d)

Test

52.

A Chief Security Officer is reviewing the network configuration and notices that several servers are using NIC teaming. Which of the following is the most likely reason for this configuration?

a)

Improved performance

b)

Automated patch management

c)

Snapshots

d)

NIC Teaming

53.

Which of the following is the most likely reason for implementing a GPO?

a)

Putting security controls in place

b)

Installing an endpoint agent to detect connectivity issues

c)

Placing systems into a specific OU

d)

SDN

54.

A company is looking to migrate its infrastructure to the cloud. Which of the following is the most likely model they will use?

a)

SaaS

b)

IaaS

c)

PaaS

d)

SDN

55.

A company is looking to migrate its infrastructure to the cloud. Which of the following is the most likely model they will use?

a)

SaaS

b)

PaaS

c)

IaaS

d)

SDN

56.

A cloud service provider is offering a hybrid model. Which of the following is the most likely reason for this offering?

a)

Public

b)

Community

c)

Private

d)

Hybrid

57.

A security professional is reviewing backup strategies. Which of the following is the most likely type of backup that includes all data?

a)

Snapshot

b)

Differential

c)

Cloud

d)

Full

58.

Which of the following is the most likely stage of the environment where new applications are tested before being moved to production?

a)

Stage

b)

Development

c)

Production

d)

Test

59.

A company is looking to implement a cloud service model that provides virtualized computing resources over the internet. Which model should they choose?

a)

SaaS

b)

IaaS

c)

PaaS

d)

SDN

60.

A company wants to simplify the management of SSL certificates across multiple subdomains. Which type of certificate should they use?

a)

Wildcard

b)

Subject alternative name

c)

Self-signed

d)

Domain validation