wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Ethical Hacking - Social Engineering

Total questions: 66

Worksheet time: 33mins

Name
Class
Date
1.

What is Social Engineering?

a)

The use of technology to improve social interactions

b)

Any action that influences a person to do something that may not be in their best interest

c)

The process of designing social media platforms

d)

A method of constructing social policies

2.

What is the primary goal of Social Engineering?

a)

To enhance user experience on social media

b)

To gain access to restricted computer systems, areas, or sensitive information

c)

To develop new social policies

d)

To improve communication between people

3.

Which of the following is NOT a method used in Social Engineering?

a)

Con-tricks

b)

Manipulation

c)

Deceit

d)

Physical force

4.

What is often the intention behind Social Engineering?

a)

To create new social networks

b)

To steal or commit fraud

c)

To improve public relations

d)

To develop new software

5.

What is phishing?

a)

The act of catching fish in a river

b)

The act of pretending to be a legitimate organization to steal sensitive information

c)

The act of sending legitimate emails to customers

d)

The act of creating a new bank account

6.

Which of the following is NOT a sign of phishing?

a)

Ambiguous Greeting

b)

Poor Spelling/Grammar

c)

Clear and professional language

d)

Tempting offers

7.

Phishing emails often ask for which type of information?

a)

Favorite color

b)

Bank details or usernames and passwords

c)

Movie preferences

d)

Travel history

8.

Which of the following is a common characteristic of phishing emails?

a)

Sense of urgency

b)

Detailed company history

c)

Personal anecdotes

d)

High-quality images

9.

What is a common tactic used in phishing emails to trick recipients?

a)

Offering free software

b)

Providing accurate weather forecasts

c)

Sending ambiguous greetings

d)

Sharing cooking recipes

10.

What is spear phishing?

a)

A phishing attack targeting thousands of random people

b)

A phishing attack targeting a few key individuals

c)

A type of cyber attack that involves physical harm

d)

A method of fishing using a spear

11.

What do cyber criminals do in spear phishing attacks?

a)

Send out mass emails to random people

b)

Conduct reconnaissance to gather information about key individuals

c)

Use physical force to obtain information

d)

Hack into random computers without any specific target

12.

What makes spear phishing attacks seem genuine?

a)

The use of advanced hacking tools

b)

The inclusion of a small nugget of information about the personnel involved

c)

The large number of emails sent out

d)

The use of physical threats

13.

How do spear phishing attacks differ from regular phishing attacks?

a)

They target thousands of random people

b)

They target a few key individuals

c)

They do not involve any preparation

d)

They are less harmful than regular phishing attacks

14.

What is the act of forging an e-mail header so that it appears to originate from someone else called?

a)

Phishing

b)

E-mail Spoofing

c)

Social Engineering

d)

Psychological Manipulation

15.

Which technique involves getting someone to do something they should not by preying on human weaknesses?

a)

Phishing

b)

E-mail Spoofing

c)

Social Engineering

d)

Psychological Manipulation

16.

What is a common technique used in conjunction with e-mail spoofing?

a)

Phishing

b)

Social Engineering

c)

Psychological Manipulation

d)

Hacking

17.

Why are people more likely to open and trust an e-mail that has been spoofed?

a)

Because it looks professional

b)

Because it appears to be sent from someone they know

c)

Because it contains a catchy subject line

d)

Because it is marked as important

18.

What does psychological manipulation often prey on?

a)

Human strengths

b)

Human weaknesses

c)

Human intelligence

d)

Human curiosity

19.

What is tailgating in the context of social engineering?

a)

A method of gaining access to a restricted area by waiting for someone with authorization to open the door and then following them in.

b)

A method of hacking into a computer system remotely.

c)

A technique used to steal someone's identity online.

d)

A way to intercept phone calls and messages.

20.

In which situations is suspicion avoided when using tailgating as a social engineering technique?

a)

When there are crowds of people.

b)

When there are security cameras.

c)

When there are no people around.

d)

When there are security guards present.

21.

Which of the following is NOT a method mentioned for avoiding suspicion while tailgating?

a)

Dressing as delivery staff carrying a heavy-looking box.

b)

Putting on overalls.

c)

Carrying clipboards and pushing trolleys.

d)

Wearing a security uniform.

22.

What is the method called that involves raiding bins to find sensitive information?

a)

Phishing

b)

Dumpster Diving

c)

Watering Hole Attack

d)

Baiting

23.

Which social engineering technique involves observing websites often visited by a victim and infecting those sites with malware?

a)

Phishing

b)

Dumpster Diving

c)

Watering Hole Attack

d)

Pretexting

24.

What type of information might be found through dumpster diving?

a)

Encrypted passwords

b)

Bank statements with sort codes and account numbers

c)

Social media profiles

d)

Encrypted emails

25.

What is a common characteristic of a watering hole attack?

a)

It involves physical theft

b)

It targets websites often visited by a specific group

c)

It requires direct communication with the victim

d)

It uses social media to gather information

26.

What is an insider threat?

a)

A threat that originates from outside the organization.

b)

A threat that originates from someone inside the organization.

c)

A threat that originates from a competitor.

d)

A threat that originates from a natural disaster.

27.

What is an accidental insider threat?

a)

Damage caused by a natural disaster.

b)

Damage caused by a competitor.

c)

Damage caused by an employee accidentally divulging or deleting data.

d)

Damage caused by a cyber attack.

28.

What is a malicious insider threat?

a)

Deliberate actions intended to cause harm or disruption to the company.

b)

Accidental actions that cause harm to the company.

c)

Natural disasters that disrupt company operations.

d)

Competitor actions that harm the company.

29.

Which of the following could be an example of a malicious insider threat?

a)

An employee accidentally deleting important files.

b)

A natural disaster causing damage to company property.

c)

A disgruntled employee who wishes to damage the organization for any reason.

d)

A competitor launching a cyber attack.

30.

What is the primary focus of cyber resilience?

a)

Preventing cyber attacks

b)

Ensuring no security breaches occur

c)

Preparing for and recovering from security breaches

d)

Eliminating all cyber threats

31.

How does cyber resilience differ from preventing a cyber attack?

a)

It assumes no attacks will occur

b)

It focuses on preventing all attacks

c)

It assumes a security breach will happen and prepares for it

d)

It eliminates the need for security measures

32.

What does cyber resilience assume about the individual or organization?

a)

They will never face a security breach

b)

They will suffer a security breach

c)

They are immune to cyber attacks

d)

They do not need to prepare for cyber threats

33.

What is the ultimate goal of cyber resilience?

a)

To prevent all cyber attacks

b)

To ensure no data is ever compromised

c)

To recover quickly from a successful cyber attack

d)

To eliminate the need for cybersecurity

34.

When assessing the potential damage of a cyber attack, which three aspects concerning the compromised data should be considered?

a)

Confidentiality, Integrity, and Availability

b)

Confidentiality, Integrity, and Accessibility

c)

Confidentiality, Information, and Availability

d)

Confidentiality, Information, and Accessibility

35.

What does it mean if the confidentiality of data is compromised?

a)

The data is deleted permanently.

b)

The data is altered or modified.

c)

An attack was able to see the data and perhaps take a copy of it.

d)

The data is made available to everyone.

36.

What does it mean if the integrity of data has been compromised?

a)

The data has been deleted.

b)

The data has been changed in some way.

c)

The data has been encrypted.

d)

The data has been backed up.

37.

What is the consequence of an integrity breach?

a)

The data can no longer be trusted.

b)

The data is permanently lost.

c)

The data is made public.

d)

The data is encrypted.

38.

What does it mean if the availability of data is affected?

a)

The data is deleted.

b)

The data is encrypted.

c)

Legitimate users no longer have access to it.

d)

The data is duplicated.

39.

What type of attack is based on affecting the availability of data?

a)

Phishing attack

b)

Ransomware attack

c)

Man-in-the-middle attack

d)

SQL injection attack

40.

What is a tabletop exercise?

a)

A planned exercise where employees of an organization work through a hypothetical real-world scenario.

b)

A physical exercise to improve employee health.

c)

A training session for new employees.

d)

A meeting to discuss company policies.

41.

What is the purpose of a firewall in a computer system or network?

a)

To act as a filter, analyzing data packets for malicious intent before they are allowed into the network.

b)

To store data securely.

c)

To manage user passwords.

d)

To provide internet access.

42.

What do employees do during a tabletop exercise?

a)

Simulate a security breach and rehearse their response to such an incident.

b)

Perform physical exercises.

c)

Attend a training session on new software.

d)

Discuss their daily tasks.

43.

Why should every computer system and/or network have a firewall?

a)

To protect against malicious data packets.

b)

To increase internet speed.

c)

To store large amounts of data.

d)

To manage employee schedules.

44.

Who is typically in charge of setting up and maintaining access controls within an organization?

a)

Teacher

b)

Student

c)

Network Administrator

d)

Principal

45.

In a school scenario, what type of files would a central file server store?

a)

Only exam papers

b)

All files

c)

Only learning materials

d)

Only sensitive information

46.

What type of access is appropriate for pupils in a school scenario?

a)

Access to exam papers

b)

Access to sensitive information

c)

Access to learning materials

d)

Access to both exam papers and sensitive information

47.

Who will need access to both exam papers and sensitive information in a school scenario?

a)

Pupils

b)

Teachers

c)

Network Administrators

d)

Parents

48.

What is the purpose of Two-Factor Authentication?

a)

To provide an additional layer of security when accessing computer systems.

b)

To make logging in faster.

c)

To store passwords securely.

d)

To allow multiple users to access the same account.

49.

What happens when Two-Factor Authentication is enabled and an attempt is made to log in from an unknown device?

a)

The account is automatically locked.

b)

A special code is sent to the user's mobile device or email.

c)

The user is logged out of all devices.

d)

The password is reset.

50.

What must the user do after receiving the special code in Two-Factor Authentication?

a)

Ignore the code and continue.

b)

Enter the code to log into the application.

c)

Change their password.

d)

Contact customer support.

51.

What is the term used for any type of authentication method that uses a biological characteristic to verify someone's identity?

a)

Password authentication

b)

Token-based authentication

c)

Biometrics

d)

Two-factor authentication

52.

Which of the following is NOT an example of biometric authentication?

a)

Retina scanners

b)

Face recognition

c)

Voiceprint

d)

Password

53.

Which biometric method uses the unique patterns in the eyes to verify identity?

a)

Face recognition

b)

Retina scanners

c)

Voiceprint

d)

Fingerprint

54.

Which biometric method uses the unique features of a person's face to verify identity?

a)

Retina scanners

b)

Face recognition

c)

Voiceprint

d)

Fingerprint

55.

Which biometric method uses the unique characteristics of a person's voice to verify identity?

a)

Retina scanners

b)

Face recognition

c)

Voiceprint

d)

Fingerprint

56.

What is a software patch?

a)

A new version of the software

b)

A fix for a discovered flaw or vulnerability

c)

A backup of the software

d)

A user manual for the software

57.

Why is it important to download and install all security patches as soon as they are released?

a)

To increase the speed of the system

b)

To ensure the system is up to date and protected from the latest threats

c)

To reduce the size of the software

d)

To improve the graphics of the software

58.

Who develops the fix for a discovered flaw or vulnerability in software?

a)

The users

b)

The software manufacturers

c)

The hardware manufacturers

d)

The operating system developers

59.

What do software manufacturers recommend all users do with a software patch?

a)

Ignore it

b)

Download and install it

c)

Delete it

d)

Share it with others

60.

What does a full backup do?

a)

Copies only new data

b)

Copies every item of data

c)

Copies only modified data

d)

Copies only system files

61.

Why is data from a full backup usually stored in a different location?

a)

To save storage space

b)

To make it easier to access

c)

To protect against physical damage

d)

To reduce backup time

62.

What is one example of physical damage that storing data in a different location can protect against?

a)

Data corruption

b)

Fire

c)

Virus attack

d)

Software malfunction

63.

What is a key characteristic of a differential backup?

a)

It saves all data regardless of changes.

b)

It only saves data that has changed since the last full backup.

c)

It requires more storage space than a full backup.

d)

It takes more time than a full backup.

64.

Which type of backup is described as more efficient because it only saves changes since the last backup of any kind?

a)

Full Backup

b)

Differential Backup

c)

Incremental Backup

d)

Redundant Backup

65.

Which type of backup requires less storage space compared to a full backup?

a)

Full Backup

b)

Differential Backup

c)

Incremental Backup

d)

Redundant Backup

66.

What does an incremental backup save?

a)

All data since the last full backup

b)

Only the data that has changed since the last full backup

c)

Only the data that has changed since the last backup of any kind

d)

All data regardless of changes