wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Cyber security revision for Jan 25 exam

Total questions: 60

Worksheet time: 53mins

Name
Class
Date
1.

Which of these is not a field in a Cyber Security Incident Report

a)

Target of the incident

b)

Incident category

c)

Type of attacker

d)

Name of the incident

2.

Which of these is the most serious category of incident

a)

Critical

b)

Significant

c)

Minor

d)

Negligible

3.

Anyone who commits a cyber crime by breaking national or international law

a)

Cyber Terrorist

b)

Scammer

c)

Phisher

d)

Cyber Criminal

4.

Allowing information to pass to any person without permission

a)

Unauthorised Access

b)

Unauthorised Inspection

c)

Unaithorised Modification

d)

Unauthorised Disclosure

5.

The first phase of the vulnerability management lifecycle

a)

Verify

b)

Assess

c)

Discover

d)

Remediate

6.

Once a vulnerability is identified we have to take corrective action, this is known as

a)

Fixing

b)

Remediation

c)

Monitoring

d)

Assessing

7.

Which of these is a valid type of privilege escalation?

a)

Vertical

b)

Positional

c)

Subterranean

d)

Global

8.

Which of these is a possible motivation of an insider?

a)

Public Good

b)

Income Generation

c)

Settle a score

d)

Fraud

9.

Which of these are programs that detect attempts at intrusion and take action to prevent them

a)

IDS

b)

NIDS

c)

HIDS

d)

IPS

10.

The level of assurance that the data will be accessible to those who need it when they want it

a)

Confidentiality

b)

Availability

c)

Integrity

d)

Accuracy

11.

What would be the main motivation of a hacktivist?

a)

Public Good

b)

Settle a score

c)

Thrill

d)

Income Generation

12.

Someone who tries to cheat you by offering goods or opportunities to make money quickly is a​ (a)  

Choose from the below words

Hacker

Phisher

Cyber Criminal

Scammer
Hacktivist
13.

What does BYOD stand for?

a)

Bring your own data

b)

Buy your own device

c)

Bring your old device

d)

Bring your own device

14.

Which group of asset does a router fall into?

a)

Hardware

b)

Software

c)

Communications Equipment

d)

Information and data

15.

Which of these is a symmetric method of cryptography

a)

Blowfish

b)

El Gamal

c)

RSA

d)

DSA

16.

The level of assurance which can be given as to the accuracy and trustworthiness of the data

a)

Confidentiality

b)

Integrity

c)

Availability

17.

Fixes issues and bugs within the software

a)

Patch

b)

Update

18.

Adds new features and functionality to the software

a)

Patch

b)

Update

19.

Which law makes it an offence to send malicious and offensive communications.

a)

Data Protection Act

b)

Computer Misuse Act

c)

Communications Act

d)

Equality Act

20.

Reading data, information or systems documentation without permission of the appropriate owner is unauthorised (a)  

21.

People that try and acquire your personal information usually via email

a)

Phisher

b)

Scammer

c)

White hat hacker

d)

Vulnerability Broker

22.

Attackers place a piece of malware on a group of computers to form a network under their control

a)

Virus

b)

Dictionary Attack

c)

DDOS Attack

d)

BotNet Attack

23.

The use of sophisticated tools to collect information and indentify trends and patterns

a)

Data Mining

b)

Cyber enabled crime

c)

Cyber dependent crime

d)

Money Laundering

24.

These are cyber security incidents that cause a world wide problem for individuals, organisations or states.

a)

Loss Incident

b)

Global Incident

c)

Disruption Incident

d)

Saftey Incident

25.

IT specialists employed or contracted by system owners to methodically attempt to penetrate a computer system

a)

Scammer

b)

Phisher

c)

Ethical Hacker

d)

Hacktivist

26.

The information commisioner is responsible for enforcing which law

a)

Data Protection Act/GDPR

b)

Regulation of investigatory powers act

c)

Computer Misuse Act

d)

Communications Act

27.

A premeditated, attack against information in order to cause fear or intimidation in society.

a)

Cyber Criminal

b)

Cyber Terrorist

c)

Hacktivist

d)

Script Kiddie

28.

This attacker is usually young, intelligent, IT expert

a)

Hacktivist

b)

Hacker

c)

Scammer

d)

Cyber Criminal

29.

Detects unusual or suspicious activity on a specific device.

a)

IPS

b)

IDS

c)

NIDS

d)

HIDS

30.

The act of exploiting a bug, design flaw to gain elevated access to resources.

a)

Escalation of priviledges

b)

Unauthorised Modification

c)

Phishing

d)

Hacking

31.

Is allowing information to pass to any person or organisation without permission.

a)

Unauthorised Disclosure

b)

Unauthorised Modification

c)

Unauthorised Inspection

d)

Unauthorised Access

32.

The use of sophisticated tools to identify trends and patterns in large data stores.

a)

Hacking

b)

Money Laundering

c)

Phishing

d)

Data Mining

33.

On unsecure public Wi-Fi, attackers can insert themselves between a visitor's device and the network.

a)

Phishing

b)

Hacking

c)

DOS

d)

Man in the middle attack

34.

Uses existing computer scripts or codes to hack into computers, lacking the expertise to write their own ...

(a)  

35.

What is the main motivation of a vulnerability broker

a)

Financial Gain

b)

Righting a perceived wrong

c)

Thrill

d)

Espionage

36.

A form of malware that encrypts a victim's files. The attacker then demands money from the victim

a)

Spyware

b)

Worm

c)

Ransomware

d)

Trojan

37.

This law makes it an offence to transmit text messages which are offensive

a)

Regulation of investigatory powers act

b)

Computer Misuse Act

c)

Communication Act

d)

Data Protection Act

38.

Categorize assets into groups or business units, and assign a business value to the asset

a)

Verify

b)

Remediate

c)

Prioritize Assets

d)

Discover

39.

Which one of the following is NOT a type of CyberSecurity Attack?

a)

Worm

b)

Ransomware

c)

Spyware

d)

Password Management

e)

DDoS

40.

The technology and process that is designed to protect networks and devices from attack, damage, or unauthorized access

a)

Cyber Security

b)

White Hat Hacker

c)

Domain Name Server

d)

All of the above

41.

What are the motives behind cyber crime?

a)

Demanding ransom

b)

Propagating religious or political beliefs

c)

Financial loss to the target

d)

Information thefts and manipulating data

e)

All of the above

42.

Individuals with wide range of skills motivated by religious or political beliefs to create fear by large- scale disruption of computer networks

a)

State sponsored hacker

b)

Hactivist

c)

Cyber terrorist

d)

Black hat hacker

43.

Which of these are examples of system vulnerabilities?

a)

Environmental

b)

Updated software

c)

Firewall

d)

Systems Attacks

e)

Physical

44.

Which of these are targets for cyber security threats?

a)

People

b)

Equipment

c)

paperwork

d)

car keys

e)

Locked doors

45.

The Computer Misuse Act 1990 covers what area of law?

a)

Controls how date is used by organisations

b)

Governs the use of covert surveillance

c)

Unauthorised access to computer material

d)

Sending malicous communication over the internet

46.

Which of these are types of system vulnerabilities?

a)

Zero day

b)

Social engineering

c)

Encryption

d)

Staff training

e)

Two-factor authentication

47.

What is the correct term for the use of sophisticated tools, such as AI techniques and statistical tools to identify trends and patterns in large data stores?

a)

Key logging

b)

Data mining

c)

Currency tumbling

d)

Money laundering

48.

Which of these is an example of personal data?

a)

Botnet

b)

Bank account details

c)

Social media profile

d)

eBooks

49.

What is a Cookie?

a)

A vulnerability that presents a danger to your computer

b)

A type of Spyware that reports your internet activities

c)

A form of storage used by the browser for backing up websites

d)

A small text file stored on a computer for tracking/storing user activites

50.

Some websites have “http://” extension while some have “https://”

What does the ‘s’ mean?

a)

That the data entered on the website is secure and encrypted.

b)

It’s a special website.

c)

That it’s the latest version of the site.

d)

Its being loaded in a simple format.

51.

According to the pre-release materials, what was the first recommended step for Triangle Widgets after the cyber security course?

a)

Implement new security measures immediately

b)

Conduct a review of existing cyber security measures and controls

c)

Run table top exercises

d)

Contact external organisations

52.

In the table top exercise scenario described in the pre-release, what type of breach was simulated?

a)

A physical security breach

b)

A malware attack

c)

A compromised manager's password

d)

A social engineering attack

53.

Which of the following was NOT mentioned as data accessed by the hacker in the pre-release scenario?

a)

Financial transaction records

b)

Customer information

c)

Employee information

d)

Organisational data

54.

According to the pre-release, what is the primary purpose of conducting table top exercises?

a)

To create new security policies

b)

To identify compromised passwords

c)

To train new employees

d)

To test procedures and familiarise staff with CISR creation

55.

In the pre-release, the course emphasised that cyber security is:

a)

Only important for large corporations

b)

A global responsibility affecting everyone

c)

Limited to individual companies

d)

Only relevant to IT departments

56.

In the pre-release, what document is specifically mentioned as being created during table top exercises?

a)

Security Breach Report

b)

Incident Management Plan

c)

Cyber Security Incident Report (CISR)

d)

Risk Assessment Document

57.

In the pre-release, the cyber security course covered incident response basics that included all EXCEPT:

a)

How to respond to incidents

b)

Financial compensation procedures

c)

Containing and eradicating incidents

d)

Dealing with affected parties

58.

In the pre-release, the name of the company is?

(a)  

59.

According to the pre-release, what type of information should be identified during the security review?

a)

Only digital assets

b)

Just company policies

c)

Employee performance records

d)

Assets, procedures, policies, and vulnerabilities

60.

The pre-release materials suggest further research on all topics EXCEPT:

a)

How to analyse risk and identify vulnerable assets

b)

Social media security protocols

c)

Impact of incidents beyond the company

d)

Responses to different categories of incidents