wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

ATTACK CONCEPTS AND TECHNIQUES!

Total questions: 35

Worksheet time: 19mins

Name
Class
Date
1.

During a class project, Abigail received a suspicious email claiming to be from the school's IT department, asking her to confirm her login credentials for a system upgrade. What is a tactic that manipulates individuals into divulging confidential information through deceptive means?

a)

Botnet

b)

On-Path Attacks

c)

Distributed DoS

d)

Denial of Service

e)

Social Engineering

2.

What is the process of applying patches and updates to software to fix vulnerabilities?

a)

Software Updates

b)

Malware Removal

c)

System Restoration

d)

Data Backup

3.

What is the unauthorized use of someone’s computer to mine cryptocurrency?

a)

Crypto-jacking

b)

Phishing

c)

Ransomware

d)

Spyware

4.

Malware used to take over and link a large number of computers in order to execute a attack.

a)

Phishing

b)

Zero-Day Exploit

c)

Social Engineering

d)

Backdoor

e)

Botnet

5.

What's a trojan virus?

a)

It tricks people into thinking it's nasty

b)

A virus disguised as a virus

c)

A virus disguised as a gift

d)

A virus disguised as a worm

6.

What's the difference between a worm and a virus?

a)

A virus is green and a worm is brown

b)

A worm can't be caught

c)

A worm needs to be activated by a human

d)

A worm doesn't need to be activated by a human

7.

What is malware?

a)

A computer bug

b)

A computer program

c)

A piece of hardware

d)

An operating system

8.

What do you call the process in which a user is identified via a username and password

a)

Authorization

b)

Authentication

c)

Accounting

d)

Auditing

9.

What is the process of giving individual access to a system or resource?

a)

Auditing

b)

Authorization

c)

Accounting

d)

Authentication

10.

What is the process of identifying an individual?

a)

Authentication

b)

Authorization

c)

Auditing

d)

Accounting

11.

System redundancy, system backups, increased system resiliency, equipment maintenance, up-to-date operating systems and software, and plans in place to recover quickly from unforeseen disasters are methods to ensure

a)

Protection

b)

Integrity

c)

Confidentiality

d)

Availability

12.

Hashing, data validation checks, data consistency checks, and access controls are used to ensure.

a)

Data Transmission

b)

Data Security

c)

Data Integrity

d)

Data Warehouse

13.

Which of the following contains the primary goals and objectives of security?

a)

Social Media

b)

The CIA triad

c)

The Internet

d)

None of the above

14.

According to the CIA triad, which of the following is not considered in the triad?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Authenticity

15.

John is working on his college applications online, when the admissions website crashes. He is unable to turn in his college application on time.

Which part of the CIA triad has been broken?

a)

C

b)

I

c)

A

d)

None of the above

16.

Kim takes her college admissions test and is waiting to get her results by email. By accident, Kim’s results are sent to Karen.

Which part of the CIA triad has been broken?

a)

C

b)

I

c)

A

d)

None of the above

17.

Alice is buying books from an online retail site, and she finds that she is able to change the price of a book from $20 to $1.

Which part of the CIA triad has been broken?

a)

C

b)

I

c)

A

d)

None of the above

18.

In cybersecurity, what does CIA stand for?

a)

Confidentiality, Integrity, Availability

b)

Central Intelligence Agency

c)

Cybersecurity Investigation Agency

d)

Cybersecurity, Internet, Accessibility

19.

Which of the following should you do to restrict access to your files and devices?

a)

Update your software once a year.

b)

Share passwords only with colleagues you trust.

c)

Have your staff members access information via an open Wi-Fi network.

d)

Use multi-factor authentication.

20.

Backing up important files offline, on an external hard drive or in the cloud, will help protect your business in the event of a cyber attack.

a)

True

b)

False

21.

Which is the best answer for which people in a business should be responsible for cybersecurity?

a)

Business owners. They run the business, so they need to know cybersecurity basics and put them in practice to reduce the risk of cyber attacks.

b)

IT specialists, because they are in the best position to know about and promote cybersecurity within a business.

c)

Managers, because they are responsible for making sure that staff members are following the right practices.

d)

All staff members should know some cybersecurity basics to reduce the risk of cyber attacks.

22.

Which one of these statements is correct?

a)

If you get an email that looks like it's from someone you know, you can click on any links as long as you have a spam blocker and anti-virus protection.

b)

You can trust an email really comes from a client if it uses the client's logo and contains at least one fact about the client that you know to be true.

c)

If you get a message from a colleague who needs your network password, you should never give it out unless the colleague says it's an emergency.

d)

If you get an email from Human Resources asking you to provide personal information right away, you should check it out first to make sure they are who they say are.

23.

An email from your boss asks for the name, addresses, and credit card information of the company's top clients. The email says it's urgent and to please reply right away. You should reply right away.

a)

True

b)

False

24.

You get a text message from a vendor who asks you to click on a link to renew your password so that you can log in to its website. You should:

a)

Reply to the text to confirm that you really need to renew your password.

b)

Pick up the phone and call the vendor, using a phone number you know to be correct, to confirm that the request is real.

c)

Click on the link. If it takes you to the vendor's website, then you'll know it's not a scam.

25.

Email authentication can help protect against phishing attacks.

a)

True

b)

False

26.

If you fall for a phishing scam, what should you do to limit the damage?

a)
  • Delete the phishing email.

b)

Unplug the computer. This will get rid of any malware.

c)
  • Change any compromised passwords.

27.

Strong passwords can be difficult to remember. What can you do to avoid forgetting them?

a)

Use mnemonics (acronyms or phrases that are easy for you to remember)

b)

Develop a password strategy

c)

Use password management software with encryption.

d)

All of the above

28.

Cybersecurity involves...

a)

techniques that help in securing various digital components, networks, data, and computer systems from unauthorized digital access.

b)

techniques that don't help in securing various digital components, networks, data, and computer systems from unauthorized digital access.

c)

techniques that help in giving various digital components, networks, data, and computer systems to unauthorized digital access.

d)

techniques that help in getting various digital components, networks, data, and computer systems for an unauthorized use.

29.

One of the most common types of cyber attacks is a malware attack (troyan, adware, and spyware).

a)

True

b)

False

30.

What is a phishing attack?

a)

It is a cyber attack in which the hacker sends fraudulent e-mails which appear to be coming from a illegitimate source.

b)

It is a cyber attack in which the hacker sends trustworthy e-mails which come from a legitimate source.

c)

It is a cyber attack in which the hacker sends fraudulent e-mails which appear to be coming from a legitimate source.

d)

It is a cyber attack in which the hacker doesn't send fraudulent e-mails.

31.

What is the phishing attack used for?

a)

To install a new software to protect data.

b)

To protect data from malware.

c)

To secure sensitive data.

d)

To install malware or to steal sensitive data.

32.

What is the man-in-the- middle attack?

a)

It is when the hacker gains access to the information path between someone's device and the website's server.

b)

It is when the hacker takes over someone's IP address.

c)

It is when the communication line between someone and the website is secretly intercepted.

d)

it is when the hacker protects the someone's information from malware.

33.

The password attack is one of the most difficult ways to attack a system?

a)

True

b)

False

34.

What are some cybersecurity practices?

a)

To Install a firewall and implement honeypots.

b)

To use alphanumeric passwords and antivirus software.

c)

To use alphabetic password.

d)

To accept e-mails from unknown senders.

35.

What does an ethical hacker do?

a)

Tries to a network's vulnerabilities just how a hacker would do.

b)

Identifies vulnerabilities and resolve them for protection against an actual cyber attack.

c)

Gets the company's information to give it to other hackers for future attacks.

d)

Installs malware to get data to sell to others.