wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Cyber Security Quiz

Total questions: 55

Worksheet time: 28mins

Name
Class
Date
1.

What is the role of the CISO according to the CEA Cyber Security Regulations 2024?

a)

Monitoring physical security of facilities

b)

Overseeing cyber security initiatives and reporting to the CEO

c)

Managing financial aspects of the organization

d)

Designing electrical infrastructure

2.

Which document must be reviewed and approved by the board of an entity?

a)

Cyber Crisis Management Plan (CCMP)

b)

Employee Training Plan

c)

Vendor Selection Protocol

d)

Power Supply Audit

3.

According to the draft regulations, who must complete cyber security training courses?

a)

All employees of the entity

b)

Only IT department personnel

c)

Personnel operating IT and OT systems

d)

Board members only

4.

CSIRT-Power is primarily responsible for which of the following?

a)

Financial auditing

b)

Creating SOPs for incident response activities

c)

Monitoring physical access to OT systems

d)

Managing human resources

5.

The Cyber Security Policy of an entity must include which of the following elements?

a)

Physical layout of facilities

b)

Access control and vulnerability management processes

c)

Budget allocation for each department

d)

Supply chain logistics

6.

What is the minimum retention period for cybersecurity incident logs as per the regulations?

a)

30 days

b)

60 days

c)

90 days

d)

180 days

7.

Which certificate should Responsible Entities acquire according to the draft regulations?

a)

ISO/IEC 27001

b)

ISO 9001

c)

IEEE 1588

d)

ANSI Z10

8.

The draft regulations require vendors to provide a Software Bill of Materials for what purpose?

a)

To outline the software components used in critical applications

b)

To track financial expenditures

c)

To list employee assignments

d)

To define maintenance schedules

9.

What should the Cyber Security Policy address in terms of data protection?

a)

Data encryption and privacy protocols

b)

Data sharing across international borders

c)

Only physical copies of data

d)

Limiting employee data access

10.

According to the draft, how frequently should an IT system cyber security audit occur?

a)

Once every three years

b)

Once every year

c)

Twice a year

d)

Quarterly

11.

Which of the following must be physically isolated from the Internet as per the draft regulations?

a)

Email servers

b)

Employee desktops

c)

Critical OT systems

d)

Cloud storage solutions

12.

What is the main purpose of the Cyber Crisis Management Plan (CCMP)?

a)

To regulate financial practices during crises

b)

To set guidelines for employee conduct

c)

To manage cyber incidents and ensure coordinated responses

d)

To ensure compliance with power generation protocols

13.

Who approves the Cyber Crisis Management Plan (CCMP) in an organization?

a)

IT Department

b)

Board of Directors

c)

Human Resources Department

d)

Legal Department

14.

Which agency is responsible for issuing directives to CSIRT-Power?

a)

Ministry of Health

b)

CERT-In

c)

Ministry of Education

d)

Department of Labor

15.

What are 'Critical Assets' as defined in the CEA Cyber Security Regulations?

a)

Systems necessary for the reliable operation of the power system

b)

Employee workstations

c)

Office supplies

d)

Non-essential systems in the organization

16.

Under the CEA Cyber Security Regulations, what specific responsibility does the Information Security Division (ISD) have concerning Cyber Security audits?

a)

Conduct quarterly audits of employee performance

b)

Review audit reports and ensure implementation of audit recommendations

c)

Prepare financial reports related to cyber security

d)

Develop marketing strategies for cyber security tools

17.

What is required from vendors regarding security patches under the CEA Cyber Security in Power Sector Regulations?

a)

Vendors must provide patches only at the start of the contract

b)

Vendors must make patches available for all system components during the contract duration

c)

Vendors need to ensure patches are applied automatically

d)

Vendors are not responsible for patches according to the regulations

18.

What is the main purpose of Perfect Forward Secrecy (PFS) in cryptographic communications?

a)

Ensuring that encrypted data remains secure even if the server’s private key is compromised

b)

Allowing symmetric keys to be reused for faster decryption

c)

Maintaining long-term storage of cryptographic keys for auditing purposes

d)

Encrypting data at rest to prevent unauthorized access

19.

What is the stipulated process for remote access in the Responsible Entities' Cyber Security Policy?

a)

Remote access should be allowed only for international users

b)

Multi-factor authentication and least-privilege access should be ensured

c)

Remote access is to be granted on a temporary basis without authentication

d)

No specific access controls are mentioned

20.

What is the minimum cybersecurity course requirement for CISO and ISD members per the regulations?

a)

At least five person-days per year

b)

Only one training session per year

c)

Ten person-days per year or as directed by the authority

d)

No mandatory training requirement specified

21.

According to the regulations, what is the role of CSIRT-Power in collaborating with CERT-In and NCIIPC?

a)

To enhance financial transparency in the power sector

b)

To resolve cyber incidents and develop incident response procedures

c)

To streamline supply chain logistics

d)

To manage power distribution systems directly

22.

What type of separation is required between IT and OT systems if physical separation is not possible?

a)

The two systems must be connected via public networks

b)

Logical separation with hardened security measures must be implemented

c)

No separation is required if they are in the same location

d)

Use of basic firewall protocols suffices for separation

23.

What does the Cyber Security Policy mandate regarding outdated or obsolete cyber assets?

a)

They must be discarded immediately upon reaching end-of-life

b)

A phase-out plan must be defined, with secure disposal procedures in place

c)

They should be repurposed for non-critical functions

d)

No action is required until they are non-operational

24.

What are the responsibilities of the ISD concerning inventory management as outlined in the regulations?

a)

ISD should manage physical assets only, excluding cyber assets

b)

ISD must keep an updated inventory of IT and OT assets with network architecture documentation

c)

ISD should outsource inventory management to third parties

d)

ISD should periodically update inventory every 5 years

25.

In terms of incident reporting, within what timeframe must incidents involving cyber sabotage in Critical Systems be reported to CSIRT-Power?

a)

Within 48 hours

b)

Within 7 days

c)

Immediately, or within 24 hours

d)

Only after a formal investigation is complete

26.

What is the primary function of an Electronic Security Perimeter in the context of the Draft CEA Cyber Security Regulations?

a)

To define the physical boundary of critical assets

b)

To logically isolate networks connected to cyber systems of the power system

c)

To facilitate controlled public access to critical systems

d)

To manage vendor communications for IT systems

27.

Which of the following is not a stipulated responsibility of CSIRT-Power?

a)

Implementing Cyber Crisis Management Plans

b)

Conducting financial audits for cybersecurity expenditures

c)

Developing SOPs in consultation with CERT-In and NCIIPC

d)

Sharing cyber threat intelligence within the power sector

28.

What specific feature must firewalls used in critical systems include as per the draft regulations?

a)

A user-friendly interface for employee training

b)

Capability to identify behavioral anomalies

c)

Integration with physical access systems

d)

Auto-updates without administrator intervention

29.

What is a Software Bill of Materials (SBOM), and why is it mandated in the draft regulations?

a)

A cost estimate document for software procurement

b)

A list detailing supply chain components of software to ensure security

c)

An operational guide for system maintenance

d)

A document outlining software vendor terms

30.

In the case of an identified cyber security vulnerability, what is the maximum allowable time to address critical vulnerabilities?

a)

One month

b)

Three months

c)

Six weeks

d)

Before the next audit period

31.

What is the minimum required frequency for updating firmware and software in critical systems as per the regulations?

a)

Monthly

b)

Quarterly, with digitally signed OEM patches only

c)

Biannually, during audit periods

d)

Only when vulnerabilities are discovered

32.

What critical requirement is stipulated for all control and operation of power system elements?

a)

They must use public networks for efficient communication

b)

Control must occur entirely within national boundaries

c)

Operators must have remote access capabilities at all times

d)

Real-time operational data must be shared with international entities

33.

What is the main purpose of the Cyber Supply Chain Risk Management (CSCRM) plan under the regulations?

a)

To identify budget constraints in the procurement process

b)

To include cybersecurity requirements in outsourcing and NDA in SLA agreements

c)

To enhance vendor operational efficiency

d)

To optimize delivery timelines of equipment

34.

Which of the following represents the correct order of actions in a certification scheme?

a)

Selection → Determination → Decision → Review → Certification

b)

Review → Selection → Certification → Determination → Decision

c)

Selection → Determination → Review → Decision → Certification

d)

Certification → Selection → Decision → Review → Determination

35.

What is explicitly prohibited regarding data related to grid operations?

a)

Sharing grid operational data with domestic entities

b)

Transferring real-time operational data across national borders

c)

Using encrypted communication channels for data sharing

d)

Storing operational data on cloud systems

36.

Which entity is responsible for approving the Cyber Security Policy of a Responsible Entity?

a)

Ministry of Power

b)

Board of Directors of the Responsible Entity

c)

CERT-In

d)

CSIRT-Power

37.

What is the minimum interval between two IT system cybersecurity audits in the same financial year?

a)

Three months

b)

Four months

c)

Six months

d)

Nine months

38.

What action must a Responsible Entity take if a CISO position becomes vacant?

a)

Assign the role to the alternate CISO immediately

b)

Suspend all cybersecurity operations until the role is filled

c)

Leave the role vacant temporarily

d)

Outsource the CISO responsibilities to a third-party consultant

39.

What must all personnel engaged in IT and OT operations sign as per the regulations?

a)

Employment contract

b)

Non-disclosure agreement

c)

Vendor compliance form

d)

Risk assessment report

40.

Who is responsible for implementing the Cyber Crisis Management Plan (CCMP) in a Responsible Entity?

a)

IT Manager

b)

Chief Information Security Officer (CISO)

c)

External cybersecurity consultants

d)

Board of Directors

41.

What is a key characteristic of an Advanced Persistent Threat (APT)?

a)

Immediate and large-scale impact on systems

b)

Focus on financial gain through ransomware

c)

Persistent and covert operations over a long period

d)

Solely targeting end-user devices

42.

Which cryptographic algorithm is considered quantum-resistant?

a)

RSA

b)

ECC

c)

Lattice-based cryptography

d)

SHA-256

43.

What does the principle of "least privilege" entail in access control?

a)

Assigning minimal permissions necessary for a user to perform their job

b)

Allowing full access to senior employees regardless of their role

c)

Periodically rotating user credentials to prevent breaches

d)

Denying access to all users by default

44.

What is the main purpose of a honey pot in cybersecurity?

a)

To secure critical data using encryption

b)

To trap attackers and study their tactics without affecting actual systems

c)

To scan the network for vulnerabilities

d)

To protect against Distributed Denial of Service (DDoS) attacks

45.

Which of the following represents an example of a buffer overflow attack?

a)

Flooding a server with traffic to exhaust resources

b)

Injecting malicious SQL queries into a database

c)

Overwriting adjacent memory locations due to excessive data input

d)

Stealing session cookies for user impersonation

46.

What is the primary difference between symmetric and asymmetric encryption?

a)

Symmetric encryption uses two keys, while asymmetric uses one key

b)

Symmetric encryption uses one key for both encryption and decryption, while asymmetric uses a pair of keys

c)

Asymmetric encryption is faster than symmetric encryption

d)

Asymmetric encryption is less secure than symmetric encryption

47.

In the context of cybersecurity, what is a "zero-day" vulnerability?

a)

A vulnerability that is detected during system testing

b)

A vulnerability exploited by attackers on the same day it is patched

c)

A vulnerability unknown to the software vendor and unpatched at the time of exploitation

d)

A vulnerability introduced on the first day of system deployment

48.

What type of attack relies on repeatedly guessing a password until the correct one is found?

a)

Phishing

b)

Brute-force attack

c)

Man-in-the-middle attack

d)

Cross-site scripting

49.

What does Multi-Factor Authentication (MFA) typically combine?

a)

Username and password

b)

Something the user knows, something the user has, and something the user is

c)

Encrypted data and session tokens

d)

Passwords and session cookies

50.

Which of the following is a characteristic of a polymorphic virus?

a)

It hides in the boot sector of a hard drive

b)

It self-replicates without user interaction

c)

It modifies its code to avoid detection by antivirus software

d)

It targets only specific file types like .exe files

51.

Which of the following is an example of social engineering?

a)

A user clicks on a malicious email link that installs malware

b)

An attacker exploits a software vulnerability

c)

A network is flooded with traffic to cause a denial of service

d)

A person poses as IT support to obtain user credentials

52.

What is the purpose of a firewall in network security?

a)

To encrypt sensitive data in storage

b)

To prevent unauthorized access to or from a private network

c)

To detect malware on endpoints

d)

To manage software updates across devices

53.

Which of the following best describes phishing?

a)

Scanning networks for open ports

b)

Using fake communication to trick users into revealing sensitive information

c)

Infecting systems with ransomware

d)

Exploiting software vulnerabilities for privilege escalation

54.

What does "patch management" refer to in cybersecurity?

a)

Testing software compatibility with different operating systems

b)

Applying updates to software to fix vulnerabilities or improve functionality

c)

Monitoring network traffic for anomalies

d)

Identifying and removing malware from systems

55.

What does the CIA triad stand for in cybersecurity?

a)

Communication, Information, Accessibility

b)

Confidentiality, Integrity, Availability

c)

Cybersecurity, Intelligence, Authentication

d)

Control, Identification, Authorization