wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

ANTT

Total questions: 109

Worksheet time: 3615secs

Name
Class
Date
1.

What threat involves a hacker intercepting and altering messages between two parties to manipulate the conversation?


a)

Man-in-the-middle

b)

Phishing

c)

SQL Injection

d)

Spear-phishing

2.

Which two actions can help prevent malware infections? (choose two)

a)

Updating software regularly

b)

Using strong, unique passwords

c)

Disabling antivirus software

d)

Opening suspicious email attachments

3.

A CEO receives a fake email from their “IT department” asking to reset their password. This is an example of which type of attack?

a)

DDoS

b)

Phishing

c)

SQL Injection

d)

Social Engineering

4.

A user notices unwanted pop-ups and advertisements while browsing. Which type of malware is likely responsible?

a)

Adware

b)

Trojan

c)

Spyware

d)

Ransomware

5.

Which of the following are examples of malware? (Choose two)

a)

Spyware

b)

Trojan

c)

Firewall

d)

SSL

6.

Keyloggers are mainly used for tracking and advertising purposes

a)

True

b)

False

7.

A worm needs user interaction to spread to other devices

a)

True

b)

False

8.

A company notices that an unknown user has been attempting to connect to their servers using brute-force methods. What type of threat is this?

a)

Insider threat

b)

Malware

c)

Password attack

d)

Zero-day exploit

9.

In SSL/TLS certificates, which encryption algorithm is commonly used to verify the server’s identity?

a)

3DES

b)

AES

c)

MD5

d)

RSA

10.

Which encryption algorithm is preferred for securing real-time video streaming due to its speed?

a)

RSA

b)

AES

c)

Triple DES

d)

SHA-256

11.

Which hashing algorithm would be appropriate for ensuring data integrity in blockchain transactions?

a)

SHA-256

b)

SHA-3

c)

AES

d)

MD5

12.

Which symmetric encryption algorithm uses a 128-bit block size and variable key lengths?

a)

DES

b)

Blowfish

c)

AES

d)

RSA

13.

For securing IoT devices with limited processing power, which lightweight symmetric algorithm is often used?

a)

ChaCha20

b)

AES

c)

RSA

d)

3DES

14.

 Which type of attack involves overwhelming a server with requests to make it unavailable?

a)

Phishing

b)

Man-in-the-Middle

c)

DoS (Denial of Service)

d)

SQL Injection

15.

What encryption method is often used to protect passwords stored in databases?

a)

RSA

b)

AES

c)

DES

d)

Hashing

16.

What is a common use of the Nmap tool in security?

a)

To break passwords

b)

To scan networks for open ports and services

c)

To monitor employee activity

d)

To encrypt files

17.

 Which tool monitors network traffic for suspicious activity in real-time?

a)

Firewall

b)

Antivirus

c)

Intrusion Detection System (IDS)

d)

VPN

18.

An antivirus software scans for and removes which type of the following threats?

a)

Physical threats

b)

Phishing attempts

c)

Malware

d)

Social engineering attacks 

19.

Which of the following are common goals of ransomware attacks? (Choose two)

a)

To lock files for ransom

b)

To monitor keystrokes

c)

To gain political leverage

d)

To delete important files permanently

20.

Which tools can a hacker use to scan a network for open ports? (Choose two)

a)

Wireshark

b)

Nmap

c)

Angry IP Scanner

d)

VPN

21.

An organization tracks and logs each entry into a data center. Reviewing these logs helps fulfill which security objective?

a)

Availability

b)

Encryption

c)

Confidentiality

d)

Non-repudiation

22.

Which two tools or practices enhance data integrity?

a)

Firewalls

b)

Hash functions

c)

Data backups

d)

Digital signatures

23.

A denial-of-service (DoS) attack mainly impacts which component of the CIA Triad?

a)

Confidentiality

b)

Availability

c)

Accountability

d)

Integrity

24.

An online store asks for a customer’s fingerprint in addition to their password. What security measure is this?

a)

Multi Factor Authentication

b)

Two-step verification

c)

Password policy

d)

Biometric policy

25.

An organization uses VLANs to separate network traffic between its sales and HR departments. This primarily serves to _______

a)

Enhance network speed

b)

Strengthen data confidentiality

c)

Improve employee collaboration

d)

Reduce data redundancy

26.

Which of the following practices help prevent data breaches? (Choose two)

a)

Using multi-factor authentication

b)

Weak password policies

c)

Monitoring for unusual network activity

d)

Limiting access to sensitive data

27.

Which two principles are most critical in a hospital’s electronic health record system?

a)

Availability

b)

Usability

c)

Confidentiality

d)

Authenticity

28.

Which of these combinations best illustrates two-factor authentication?

a)

Username and password

b)

Password and security question

c)

Password and a one-time code sent to a mobile device

d)

Password and security

29.

A retail chain faces frequent thefts and unauthorized access in its warehouse storage areas. Which two physical security solutions could help reduce these incidents? (Select two)

a)

Installing CCTV cameras throughout the warehouse

b)

Implementing multi-factor authentication for online store access

c)

Using RFID-tagged access cards for entry control

d)

Encrypting customer data

30.

A company’s data center has biometric scanners and security guards in place to restrict access. What kind of security control is this?

a)

Physical control

b)

Administrative control

c)

Logical control

d)

Recovery control

31.

An employee installs software that secretly records passwords entered on their device. What type of malware is this?

a)

Virus

b)

Worm

c)

Keylogger

d)

Ransomware

32.

Ransomware is only found on Windows systems

a)

True

b)

False

33.

Leaving software unpatched in a public network environment can result in what kind of vulnerability?

a)

Zero-day vulnerability

b)

Insider threat

c)

Password attack

d)

Social Engineering

34.

What type of attack targets an SQL database using the input field of a user?

a)

SQL Injection

b)

Cross-site scripting

c)

XML Injection

d)

Buffer overflow

35.

Storing passwords in plain text within a database is an example of a ___________


a)

Physical security vulnerability

b)

Secure configuration

c)

Misconfiguration vulnerability

d)

Social engineering

36.

Which encryption algorithm was replaced by AES due to vulnerabilities?

a)

RSA

b)

DES

c)

SHA-1

d)

MD5

37.

Which measure is most effective in preventing brute-force attacks on passwords?

a)

Encryption

b)

Rate limiting

c)

Close unused ports

d)

Increased bandwidth

38.

Which encryption algorithm is commonly used to secure online transactions, such as credit card payments?

a)

AES

b)

RSA

c)

MD5

d)

DES

39.

If a company wants to encrypt large volumes of data quickly without compromising security, which algorithm should they choose?

a)

AES

b)

RSA

c)

SHA-256

d)

ECC

40.

Zero-day vulnerabilities are immediately exploitable weaknesses unknown to the software vendor.

a)

True

b)

False

41.

A bank installs anti-malware software on all employee computers to prevent infection. What is the main purpose of this security measure?

a)

To encrypt data

b)

To enable faster internet speed

c)

To bypass firewall restrictions

d)

To detect and remove malicious software

42.

In a Man-in-the-Middle attack, what is the attacker attempting to do?

a)

Block all communications

b)

Encrypt all data being transmitted

c)

Intercept and potentially alter communications between two parties

d)

Gain physical access to a device

43.

Which of these would be considered a vulnerability rather than a threat?

a)

Misconfigured firewall

b)

Malware infection

c)

Phishing email

d)

Unauthorized insider

44.

A hacktivist is a hacker who breaks into systems to expose information for political or social causes.

a)

True

b)

False

45.

 Phishing emails often use social engineering to trick users into revealing sensitive information.

a)

True

b)

False

46.

Which type of hacker is known for exploiting security weaknesses to improve security systems?

a)

White Hat

b)

Black Hat

c)

Script Kiddie

d)

Hacktivist

47.

Which technology enhances confidentiality when accessing a public Wi-Fi network?

a)

Firewall

b)

Antivirus software

c)

VPN

d)

Network switch

48.

Which of the following best describes an SQL Injection attack?

a)

Inserting malicious code into a database query

b)

Injecting code into a website to alter its appearance

c)

Stealing files from a compromised device

d)

Stealing files from a compromised device

49.

Tools like John the Ripper are used for password cracking by systematically guessing passwords.

a)

True

b)

False

50.

What is the main goal of a security guard stationed at the entrance of a restricted area in a corporate building?

a)

To assist with network setup

b)

To monitor internet traffic

c)

To block cyber attacks

d)

To prevent unauthorized physical access

51.

What is the main purpose of CCTV in physical security?

a)

To deter and monitor unauthorized access

b)

To record staff working hours

c)

To increase power efficiency

d)

To assist in network monitoring

52.

A hospital wants to protect sensitive patient information stored in a physical records room. Which two measures should the hospital implement to secure the room? (Select two)

a)

Implementing keycard access control

b)

Using water sensors to detect leaks

c)

Setting up firewall protection

d)

Establishing password policies for digital systems

53.

Which of the following actions can improve physical security at an office? (Choose two)

a)

Locking doors after hours

b)

Installing antivirus software

c)

Using keycard access

d)

Blocking certain websites

54.

In a scenario where a company faces frequent power outages, which solution would help ensure continuous power to critical systems?

a)

Security cameras

b)

Uninterruptible Power Supply (UPS)

c)

Access control systems

d)

Badge system

55.

An organization creates daily backups of its customer database to an offsite location. This measure primarily protects against ___________

a)

Phishing attacks

b)

Data loss due to hardware failure or natural disaster

c)

Unauthorized access

d)

Malware infections

56.

Which two of the following are common internal threats to information security?

a)

Phishing attacks

b)

Insider threats

c)

Human error

d)

Natural disasters

57.

Which of the following is a primary reason organizations require information security?

a)

To ensure data privacy and protect resources

b)

To avoid technological advancements

c)

To reduce customer base

d)

To eliminate competition

58.

 What is considered a critical element of information security that ensures only authorized users can access certain resources?

a)

Authentication

b)

Integrity

c)

Confidentiality

d)

Availability

59.

What two elements support integrity in an online shopping platform’s payment system?

a)

Data hashing

b)

Open public access

c)

Secure Socket Layer (SSL)

d)

Limiting customer information

60.

What are two effective ways to ensure data availability?

a)

Firewalls

b)

Redundant servers

c)

Data encryption

d)

Backup solutions

61.

Confidentiality ensures that only authorized personnel can access sensitive data.

a)

True

b)

False

62.

An organization uses VLANs to separate network traffic between its sales and HR departments. This primarily serves to __________

a)

Enhance network speed

b)

Strengthen data confidentiality

c)

Improve employee collaboration

d)

Reduce data redundancy

63.

To prevent malware, an organization restricts employee access to only necessary data. Which principle is this?

a)

Authentication

b)

Availability

c)

Encryption

d)

Least Privilege

64.

Which document outlines an organization’s strategy for dealing with security breaches?

a)

Security Policy

b)

Risk Assessment Report

c)

Disaster Recovery Plan

d)

User Manual

65.

A company implements digital certificates for authenticating its servers to users. This helps achieve which security goal?

a)

Confidentiality

b)

Authentication

c)

Integrity

d)

Availability

66.

What are two primary methods used to deliver ransomware?

a)

Phishing emails

b)

Software vulnerabilities

c)

Pop-up ads

d)

Hardware issues

67.

Which type of malware encrypts files on a computer and demands payment to decrypt them? 

a)

Adware

b)

Spyware

c)

Worm

d)

Ransomware

68.

An employee receives an email with an urgent message asking for their login credentials. This is an example of what kind of attack?

a)

SQL Injection

b)

DDoS attack

c)

Phishing

d)

Man-in-the-middle

69.

Allowing users to use easily guessable passwords, like “12345,” represents a vulnerability in ____________

a)

Password policy

b)

Patch management

c)

Access control

d)

Encryption

70.

A company network is slow and seems overloaded. The IT team suspects an attack. Which is likely?

a)

Phishing

b)

Man-in-the-middle

c)

DDoS

d)

Keylogger

71.

Which hashing algorithm is currently recommended for secure data hashing due to its resistance to collision attacks?

a)

SHA-256

b)

SHA-1

c)

MD5

d)

AES

72.

Which symmetric encryption algorithm is currently the standard for protecting government data?

a)

AES

b)

Blowfish

c)

RSA

d)

3DES

73.

Which type of encryption uses separate keys for encryption and decryption?

a)

Symmetric encryption

b)

Block encryption

c)

Asymmetric encryption

d)

Stream encryption

74.

A customer service employee receives an email claiming to be from a bank, requesting verification of account details. This is an example of __________

a)

SQL injection

b)

Social engineering

c)

DoS attack

d)

Man-in-the-middle (MitM) attack

75.

An anti-virus software scans for and removes which type of the following threats?

a)

Physical threats

b)

Phishing attempts

c)

Malware

d)

Social engineering attacks

76.

A disgruntled employee with access to sensitive data is considered as __________

a)

A vulnerability

b)

A threat

c)

A risk

d)

A mitigation

77.

What tool might a hacker use to capture and analyze network traffic?

a)

Metasploit

b)

Wireshark

c)

Firewall

d)

VPN

78.

A company installs fences, gates, and security guards at the entrance to its data center. What physical security strategy is this an example of?

a)

Layered security

b)

Risk mitigation

c)

Encryption

d)

Remote access control

79.

What is the primary difference between passive and active attacks?

a)

Passive attacks are illegal; active attacks are legal

b)

Passive attacks observe; active attacks interfere

c)

Active attacks are undetectable

d)

Passive attacks damage the system

80.

In the context of information security, what is a ‘threat’?

a)

A software bug

b)

A potential danger to information systems

c)

A security policy

d)

A virus

81.

An attacker scans a company’s network for open ports and available services without attempting to breach it. This is an example of ____________

a)

Active attack

b)

Passive attack

c)

Social engineering

d)

Phishing

82.

What measures support the confidentiality of customer data? (Choose two)

a)

Strong encryption

b)

Regular backups

c)

Multi-factor authentication

d)

Public Wi-fi access

83.

Which two are examples of human-made threats to information security?

a)

Earthquakes

b)

Malware attacks

c)

Flooding

d)

Phishing scams

84.

Rootkits are easy to detect with standard antivirus software

a)

True

b)

False

85.

Which of the following are common signs of a malware infection? (Choose two)

a)

Frequent updates

b)

Short battery life

c)

Slow system performance

d)

Unexpected pop-up ads

86.

Which algorithm is best suited for generating digital signatures due to its support for key pair generation?

a)

DSA

b)

DES

c)

AES

d)

Blowfish

87.

What encryption algorithm is commonly used to secure Wi-Fi networks in WPA2 encryption?

a)

RSA

b)

AES

c)

DES

d)

MD5

88.

What are two common signs of a phishing email?

a)

Generic greetings like “Dear Customer”

b)

Specific details about a recent conversation

c)

Urgent language requesting immediate action

d)

Familiar senders with exact email addresses

89.

Which of the following describes a white-hat hacker?

a)

A hacker working illegally

b)

An ethical hacker helping improve security

c)

A hacker exploiting vulnerabilities for profit

d)

A hacker targeting government systems

90.

What is a popular hacking tool for simulating network attacks on Windows environments?

a)

MacOS

b)

Window Phone

c)

Ubuntu

d)

Kali Linux

91.

Script kiddies are highly skilled hackers who create sophisticated tools.

a)

True

b)

False

92.

Which type of hacker performs illegal activities for financial gain?

a)

White Hat

b)

Gray Hat

c)

Black Hat

d)

Red Hat

93.

Keyloggers record every keystroke on a device to capture passwords and other data.

a)

True

b)

False

94.

Ransomware attacks typically aim to impact which aspect of the CIA Triad?

a)

Confidentiality

b)

Availability

c)

Authenticity

d)

Integrity

95.

Encryption ensures data integrity by preventing unauthorized access.

a)

True

b)

False

96.

What two measures are important for network availability in a university? (choose two)

a)

Data encryption

b)

Distributed denial-of-service (DDoS) protection

c)

Redundant Internet connections

d)

Public Wi-fi without security

97.

 Which malware types typically involve data theft? (Choose two)

a)

Spyware

b)

Keylogger

c)

Worm

d)

Ransomware

98.

 A hacker who discloses a security flaw to a company without expecting payment is known as a _______

a)

Ethical hacker

b)

Red-team member

c)

Script kiddie

d)

Gray-hat hacker

99.

 An organization implements a backup system to protect against data loss. Which principle of information security does this support?

a)

Integrity

b)

Availability

c)

Confidentiality

d)

Authentication

100.

An organization has adopted a policy where users are only granted access to data necessary for their roles. This approach is known as ___________

a)

Access whitelisting

b)

Principle of least privilege

c)

Data segregation

d)

Open access policy

101.

What is the primary difference between passive and active attacks?

a)

Airplane hijacker

b)

Browser hijacker

c)

Adware

d)

Spyware

102.

An attacker sends a large number of requests to a website, causing it to slow down and become inaccessible. This is an example of what attack?

a)

DoS

b)

Phishing

c)

SQL Injection

d)

Backdoor

103.

What is the purpose of using a firewall in a network?

a)

Encrypts data

b)

Detects malware

c)

Controls incoming and outgoing traffic based on security rules

d)

Manages passwords

104.

A financial institution needs to safeguard its ATMs from physical tampering and vandalism. Which two security measures would be most effective? (Select two)

a)

Anti-skimming devices

b)

Installing network firewalls

c)

Surveillance cameras near ATMs

d)

Regularly updating ATM software

105.

 What methods protect data availability during a server outage? (choose two)

a)

Data encryption

b)

Backup servers

c)

Redundant network connections

d)

Strong password policie

106.

An IT administrator configures an Access Control List (ACL) to allow only certain IP addresses to connect to a server. This measure primarily protects against _________

a)

Malware

b)

Data breaches

c)

Phishing

d)

Unauthorized access

107.

Which two principles are at risk when an employee downloads sensitive data onto an unsecured device?

a)

Confidentiality

b)

Integrity

c)

Non-repudiation

d)

Availability

108.

Spyware is often used to collect user data without consent

a)

True

b)

False

109.

What are the three main goals of information security?

a)

Risk, Threat, Vulnerability

b)

Authentication, Authorization, Accounting

c)

Confidentiality, Integrity, Availability

d)

Encryption, Decryption, Firewall