Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

attt

Total questions: 89

Worksheet time: 36mins

Name
Class
Date
1.
Which type of malware encrypts files on a computer and demands payment to decrypt them?
a)
Ransomware
b)
Adware
c)
Spyware
d)
Worm
2.
A CEO receives a fake email from their “IT department” asking to reset their password. This is an example of which type of attack?
a)
DDoS
b)
Phishing
c)
SQL Injection
d)
Social Engineering
3.
An employee receives an email with an urgent message asking for their login credentials. This is an example of what kind of attack?
a)
Phishing
b)
DDoS attack
c)
SQL Injection
d)
Man-in-the-middle
4.
What type of attack targets an SQL database using the input field of a user?
a)
SQL Injection
b)
Cross-site scripting
c)
XML Injection
d)
Buffer overflow
5.
Keyloggers are mainly used for tracking and advertising purposes
a)
True
b)
False
6.
A worm needs user interaction to spread to other devices
a)
True
b)
False
7.
Rootkits are easy to detect with standard antivirus software
a)
True
b)
False
8.
Which of the following describes a white-hat hacker?
a)
A hacker working illegally
b)
An ethical hacker helping improve security
c)
A hacker exploiting vulnerabilities for profit
d)
A hacker targeting government systems
9.
Which type of hacker performs illegal activities for financial gain?
a)
White Hat
b)
Gray Hat
c)
Black Hat
d)
Red Hat
10.
Keyloggers record every keystroke on a device to capture passwords and other data.
a)
True
b)
False
11.
A customer service employee receives an email claiming to be from a bank, requesting verification of account details. This is an example of __________
a)
Social Engineering
b)
SQL injection
c)
DoS attack
d)
Man-in-the-middle (MitM) attack
12.
Which tool monitors network traffic for suspicious activity in real-time?
a)
Firewall
b)
Antivirus
c)
VPN
d)
Intrusion Detection System (IDS)
13.
A bank installs anti-malware software on all employee computers to prevent infection. What is the main purpose of this security measure?
a)
To encrypt data
b)
To detect and remove malicious software
c)
To enable faster internet speed
d)
To bypass firewall restrictions
14.
What is a popular hacking tool for simulating network attacks on Windows environments?
a)
Kali Linux
b)
Ubuntu
c)
MacOS
d)
Window Phone
15.
An IT administrator configures an Access Control List (ACL) to allow only certain IP addresses to connect to a server. This measure primarily protects against _________
a)
Malware
b)
Data breaches
c)
Phishing
d)
Unauthorized access
16.
In the context of information security, what is a ‘threat’?
a)
A software bug
b)
A potential danger to information systems
c)
A security policy
d)
A virus
17.
Ransomware attacks typically aim to impact which aspect of the CIA Triad?
a)
Confidentiality
b)
Availability
c)
Authenticity
d)
Integrity
18.
Which document outlines an organization’s strategy for dealing with security breaches?
a)
Security Policy
b)
Risk Assessment Report
c)
Disaster Recovery Plan
d)
User Manual
19.
A denial-of-service (DoS) attack mainly impacts which component of the CIA Triad?
a)
Confidentiality
b)
Availability
c)
Accountability
d)
Integrity
20.
An organization has adopted a policy where users are only granted access to data necessary for their roles. This approach is known as ___________
a)
Access whitelisting
b)
Principle of least privilege
c)
Data segregation
d)
Open access policy
21.
What is considered a critical element of information security that ensures only authorized users can access certain resources?
a)
Authentication
b)
Integrity
c)
Confidentiality
d)
Availability
22.
To prevent malware, an organization restricts employee access to only necessary data. Which principle is this?
a)
Authentication
b)
Availability
c)
Encryption
d)
Least Privilege
23.
What are the three main goals of information security?
a)
Confidentiality, Integrity, Availability
b)
Authentication, Authorization, Accounting
c)
Encryption, Decryption, Firewall
d)
Risk, Threat, Vulnerability
24.
Which method of risk control involves implementing security controls like firewalls and encryption to protect against potential threats?
a)
Risk Mitigation
b)
Risk Transfer
c)
Risk Avoidance
d)
Risk Acceptance
25.
What does risk transfer typically involve in the context of risk control?
a)
Sharing the risk with another party, such as through insurance
b)
Accepting the potential impact of a risk
c)
Eliminating the risk by stopping the associated activity
26.
In risk control, what does “defense” typically involve?
a)
Preventing the occurrence of threats
b)
Transferring the risk to a third party
c)
Implementing measures to reduce risk impact
d)
Ignoring minor risks
27.
Leaving software unpatched in a public network environment can result in what kind of vulnerability?
a)
Zero-day vulnerability
b)
Insider threat
c)
Password attack
d)
Social Engineering
28.
Ransomware is only found on Windows systems
a)
True
b)
False
29.
An employee installs software that secretly records passwords entered on their device. What type of malware is this?
a)
Virus
b)
Worm
c)
Keylogger
d)
Ransomware
30.
What threat involves a hacker intercepting and altering messages between two parties to manipulate the conversation?
a)
Man-in-the-middle
b)
Phishing
c)
SQL Injection
d)
Spear-phishing
31.
An employee receives an email with an urgent message asking for their login credentials. This is an example of what kind of attack?
a)
Phishing
b)
DDoS attack
c)
SQL Injection
d)
Man-in-the-middle
32.
Allowing users to use easily guessable passwords, like “12345,” represents a vulnerability in ____________
a)
Password policy
b)
Patch management
c)
Access control
d)
Encryption
33.
Which hashing algorithm would be appropriate for ensuring data integrity in blockchain transactions?
a)
SHA - 256
b)
SHA - 3
c)
AES
d)
MD5
34.
Which symmetric encryption algorithm uses a 128-bit block size and variable key lengths?
a)
AES
b)
DES
c)
Blowfish
d)
RSA
35.
What encryption algorithm is commonly used to secure Wi-Fi networks in WPA2 encryption?
a)
AES
b)
RSA
c)
DES
d)
MD5
36.
Which type of encryption uses separate keys for encryption and decryption?
a)
Asymmetric encryption
b)
Symmetric encryption
c)
Block encryption
d)
Stream encryption
37.
What tool might a hacker use to capture and analyze network traffic?
a)
Metasploit
b)
Wireshark
c)
Firewall
d)
VPN
38.
A hacker who discloses a security flaw to a company without expecting payment is known as a _______
a)
Ethical hacker
b)
Red-team member
c)
Script kiddle
d)
Gray-hat hacker
39.
Which of the following best describes an SQL Injection attack?
a)
Inserting malicious code into a database query
b)
Injecting code into a website to alter its appearance
c)
Stealing files from a compromised device
d)
Encrypting files on a server
40.
In a Man-in-the-Middle attack, what is the attacker attempting to do??
a)
Block all communications
b)
Encrypt all data being transmitted
c)
Intercept and potentially alter communications between two parties
d)
Gain physical access to a device
41.
An anti-virus software scans for and removes which type of the following threats?
a)
Physical threats
b)
Phishing attempts
c)
Malware attacks
d)
Social engineering attacks
42.
What is a common use of the Nmap tool in security?
a)
To break passwords
b)
To scan networks for open ports and services
c)
To monitor employee activity
d)
To encrypt files
43.
When an organization decides to accept the consequences of a risk because the cost of mitigation is too high, which method of risk control is it using?
a)
Risk Acceptance
b)
Risk Avoidance
c)
Risk Transfer
d)
Risk Reduction
44.
What is the purpose of implementing risk control measures?
a)
To reduce risks to an acceptable level
b)
To increase asset value
c)
To eliminate all risks
d)
To promote organizational branding
45.
An employee installs software that secretly records passwords entered on their device. What type of malware is this?
a)
Virus
b)
Worm
c)
Keylogger
d)
Ransomware
46.
An attacker sends a large number of requests to a website, causing it to slow down and become inaccessible. This is an example of what attack?
a)
DoS
b)
Phishing
c)
SQL Injection
d)
Backdoor
47.
Storing passwords in plain text within a database is an example of a ___________
a)
Misconfiguration vulnerability
b)
Physical security vulnerability
c)
Secure configuration
d)
Social engineering
48.
Malware that modifies web browser settings to redirect users to unwanted sites is called ________
a)
Browser hijacker
b)
Airplane hijacker
c)
Adware
d)
Spyware
49.
A company notices that an unknown user has been attempting to connect to their servers using brute-force methods. What type of threat is this?
a)
Password attack
b)
Insider threat
c)
Malware
d)
Zero-day exploit
50.
Spyware is often used to collect user data without consent
a)
True
b)
False
51.
Which type of malware encrypts files on a computer and demands payment to decrypt them?
a)
Ransomware
b)
Adware
c)
Spyware
d)
Worm
52.
Rootkits are easy to detect with standard antivirus software
a)
True
b)
False
53.
Which symmetric encryption algorithm is currently the standard for protecting government data?
a)
AES
b)
Blowfish
c)
RSA
d)
3DES
54.
Which symmetric encryption algorithm uses a 128-bit block size and variable key lengths?
a)
AES
b)
DES
c)
Blowfish
d)
RSA
55.
Which encryption algorithm is commonly used to secure online transactions, such as credit card payments?
a)
RSA
b)
AES
c)
MD5
d)
DES
56.
Which encryption algorithm was replaced by AES due to vulnerabilities?
a)
DES
b)
RSA
c)
SHA-1
d)
MD5
57.
Which encryption algorithm is preferred for securing real-time video streaming due to its speed?
a)
AES
b)
RSA
c)
Triple DES
d)
SHA - 256
58.
What encryption method is often used to protect passwords stored in databases?
a)
Hashing (e.g., SHA-256)
b)
AES
c)
RSA
d)
DES
59.
Which measure is most effective in preventing brute-force attacks on passwords?
a)
Encryption
b)
Rate limiting
c)
Close unused ports
d)
Increased bandwidth
60.
If a company wants to encrypt large volumes of data quickly without compromising security, which algorithm should they choose?
a)
AES
b)
RSA
c)
SHA-256
d)
ECC
61.
In SSL/TLS certificates, which encryption algorithm is commonly used to verify the server’s identity
a)
RSA
b)
AES
c)
DES
d)
MD5
62.
For securing IoT devices with limited processing power, which lightweight symmetric algorithm is often used?
a)
ChaCha20
b)
AES
c)
RSA
d)
3DES
63.
Which type of hacker is known for exploiting security weaknesses to improve security systems?
a)
White Hat
b)
Black Hat
c)
Script Kiddie
d)
Hacktivist
64.
Phishing emails often use social engineering to trick users into revealing sensitive information.
a)
True
b)
False
65.

Which of the following are examples of malware? (Choose two)

a)

Trojan

b)

Spyware

c)

Firewall

d)

SSL

66.

Which two actions can help prevent malware infections? (choose two)

a)

Updating software regularly

b)

Using strong, unique passwords

c)

Disabling antivirus software

d)

Opening suspicious email attachments

67.

Which tools can a hacker use to scan a network for open ports? (Choose two)

a)

Wireshark

b)

Nmap

c)

Angry IP Scanner

d)

VPN

68.

Which two are examples of human-made threats to information security?

a)

Earthquakes

b)

Malware attacks

c)

Flooding

d)

Phishing scams

69.

What is the main purpose of CCTV in physical security?  

a)

To deter and monitor unauthorized access

b)

To record staff working hours

c)

To increase power efficiency

d)

To assist in network monitoring

70.

A retail chain faces frequent thefts and unauthorized access in its warehouse storage areas. Which two physical security solutions could help reduce these incidents? (Select two)

a)

Installing CCTV cameras throughout the warehouse

b)

Implementing multi-factor authentication for online store access

c)

Using RFID-tagged access cards for entry control

d)

Encrypting customer data

71.

A company’s data center has biometric scanners and security guards in place to restrict access. What kind of security control is this?

a)

Physical control

b)

Administrative control

c)

Logical control

d)

Recovery control

72.

What is the main goal of a security guard stationed at the entrance of a restricted area in a corporate building?

a)

To prevent unauthorized physical access

b)

To block cyber attacks

c)

To assist with network setup

d)

To monitor internet traffic

73.

In a scenario where a company faces frequent power outages, which solution would help ensure continuous power to critical systems?

a)

Uninterruptible Power Supply (UPS)

b)

Security cameras

c)

Access control systems

d)

Badge system

74.

A hospital wants to protect sensitive patient information stored in a physical records room. Which two measures should the hospital implement to secure the room? (Select two)

a)

Implementing keycard access control

b)

Using water sensors to detect leaks

c)

Setting up firewall protection

d)

Establishing password policies for digital systems

75.

Which of these combinations best illustrates two-factor authentication?

a)

Username and password

b)

Password and security question

c)

Password and a one-time code sent to a mobile device

d)

Password and PIN

76.

What methods protect data availability during a server outage? (choose two)

a)

Data encryption

b)

Backup servers

c)

Redundant network connections

d)

Strong password policy

77.

What two elements support integrity in an online shopping platform’s payment system?

a)

Data hashing

b)

Open public access

c)

Secure Socket Layer (SSL)

d)

Limiting customer information

78.

An IT administrator configures an Access Control List (ACL) to allow only certain IP addresses to connect to a server. This measure primarily protects against _________

a)

Malware

b)

Data breaches

c)

Phishing

d)

Unauthorized access

79.

An attacker scans a company’s network for open ports and available services without attempting to breach it. This is an example of ____________

a)

Active attack

b)

Passive attack

c)

Social engineering

d)

Phishing

80.

An organization tracks and logs each entry into a data center. Reviewing these logs helps fulfill which security objective?

a)

Availability

b)

Encryption

c)

Confidentiality

d)

Non-repudiation

81.

An organization implements a backup system to protect against data loss. Which principle of information security does this support?

a)

Integrity

b)

Availability

c)

Confidentiality

d)

Authentication

82.

An organization uses VLANs to separate network traffic between its sales and HR departments. This primarily serves to __________

a)

Enhance network speed

b)

Strengthen data confidentiality

c)

Improve employee collaboration

d)

Reduce data redundancy

83.

Confidentiality ensures that only authorized personnel can access sensitive data.

a)

True

b)

False

84.

Which two options are effective risk mitigation strategies? (Select two)

a)

Accepting the risk

b)

Implementing firewalls

c)

Ignoring potential threats

d)

Conducting regular backups

85.

What does Single Loss Expectancy (SLE) represent in risk analysis?

a)

The expected monetary loss every time a risk occurs

b)

The total value of an asset

c)

The percentage of asset loss due to an incident

d)

The annual rate of risk occurrence

86.

In what scenario would an organization most likely use risk transfer as a method of risk control?

a)

When the organization purchases insurance to cover potential damages

b)

When the organization is confident it can absorb the financial impact of a risk

c)

When the organization increases its security budget

d)

When the organization increases its security budget

87.

Which of the following is the first step in the risk management process?

a)

Risk Assessment

b)

Risk Mitigation

c)

Risk Identification

d)

Risk Control

88.

What is the primary purpose of a risk assessment?

a)

To identify potential risks

b)

To calculate the costs of all assets

c)

To monitor risk controls continuously

d)

To implement backup systems

89.

In quantitative risk analysis, which factor is not typically considered?

a)

Qualitative feedback from employees

b)

Asset Value

c)

Single Loss Expectancy

d)

Annualized Rate of Occurrence