wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Topic 1-12 Cybersecurity Quiz

Total questions: 142

Worksheet time: 1hrs 11mins

Name
Class
Date
1.

What is the primary aim of the cybersecurity course?

a)

Focusing solely on physical security

b)

Covering policy and procedures for securing large systems

c)

Teaching programming skills

d)

Analyzing software development lifecycle

2.

What are the three major threats to information security?

a)

Hardware, software, and users

b)

Confidentiality, integrity, and availability

c)

Networking, data storage, and access control

d)

Authentication, authorization, and auditing

3.

What has led to an increased need for security in modern organizations?

a)

Limited connectivity

b)

Simple computing models

c)

Pervasive computing and advanced technology

d)

Decreased user interaction

4.

What were mainframes typically used for in the past?

a)

Handling elaborate computing tasks

b)

Providing user-friendly access

c)

Performing specialized jobs with controlled access

d)

Supporting mobile devices

5.

What is a drawback of a compromised security system?

a)

Increased data integrity

b)

Improved user experience

c)

Short- and long-term damage

d)

Decreased need for monitoring

6.

What type of attacks involve manipulating people to reveal confidential information?

a)

Malware attacks

b)

Phishing attacks

c)

Social engineering attacks

d)

Brute-force attacks

7.

Which factor is not a reason for increased security challenges in organizations?

a)

Distributed computing

b)

Increased data connectivity

c)

Limited computing capabilities

d)

Mobile computing growth

8.

What was the primary goal of mainframe operators in early computing models?

a)

Ensuring user satisfaction

b)

Providing open access to everyone

c)

Maintaining system control and limited access

d)

Enhancing user interaction

9.

Why is data considered a critical component in modern organizations?

a)

It is easy to replace

b)

Both public and private sectors rely on it

c)

It requires minimal security

d)

It is not a valuable resource

10.

Which of the following is not a type of threat that organizations face online?

a)

Phishing attacks

b)

Malware attacks

c)

Ransomware

d)

Local database failure

11.

What is a cybersecurity framework designed to do?

a)

Simplify data processing

b)

Set guidelines to assess, monitor, and mitigate risks

c)

Minimize the need for documentation

d)

Provide hardware for security

12.

What does ITIL stand for?

a)

Information Technology Infrastructure Library

b)

Information Transmission and Logistics

c)

International Technical Integration Level

d)

Internet Technology Implementation Lab

13.

What is the purpose of ISO 27001?

a)

Define mandatory risk controls

b)

Provide guidelines for implementing controls

c)

Explain software requirements

d)

List basic software licenses

14.

Which stage in ISO 27000 involves assessing risk and handling parameters?

a)

Implementation

b)

Planning

c)

Act

d)

Monitor

15.

Which process is critical for achieving compliance in ISO 27000?

a)

Documentation

b)

Redundancy

c)

User training

d)

Equipment maintenance

16.

What does ISMS stand for in ISO 27000?

a)

Information Security Management System

b)

Internet Security Module System

c)

International Safety Management System

d)

Integrated Security Management System

17.

Which ISO 27000 stage focuses on incident handling?

a)

Act

b)

Monitor

c)

Plan

d)

Document

18.

What is a drawback of not having continuous evaluation in ISO 27000?

a)

Excessive compliance

b)

Over-reliance on outdated documentation

c)

Inconsistent security

d)

Lower equipment costs

19.

What is the purpose of an audit in the ISO 27000 framework?

a)

To streamline cost-effectiveness

b)

To test and improve processes

c)

To replace security policies

d)

To increase network connectivity

20.

What is a key component of certification in ISO 27000?

a)

Compliance with outdated standards

b)

Incident handling without review

c)

Risk assessment and implementation order

d)

Simplifying risk mitigation

21.

Who is typically involved in an organizational security system?

a)

Only senior management

b)

Only IT users

c)

Senior management, security staff, IT users, and third parties

d)

Only third parties

22.

What do security policies define in an organization?

a)

Step-by-step implementation instructions

b)

Broad statements about organizational objectives

c)

Specific hardware configurations

d)

Guidelines for financial investments

23.

What is the goal of 'Defense in Depth' in organizational security?

a)

Simplify all security measures

b)

Provide multiple layers of defense

c)

Reduce security redundancy

d)

Increase system complexity

24.

Which model is core to most organizational security frameworks?

a)

Physical security

b)

Client-server

c)

Layered security

d)

Single-level security

25.

Who develops security policies in an organization?

a)

IT users

b)

Only external consultants

c)

Senior management

d)

Only third parties

26.

What type of security document is not mandatory but encouraged to follow?

a)

Security policies

b)

Security standards

c)

Security guidelines

d)

Security procedures

27.

What strategic goal does an organizational security model aim to achieve?

a)

IT support

b)

Risk assessment and compliance

c)

Simplified data processing

d)

Limited user access

28.

What does ISO 27002 focus on?

a)

Developing software

b)

Implementing security guidelines

c)

Eliminating user roles

d)

Increasing IT costs

29.

What question should a security policy address during development?

a)

What assets should be protected?

b)

What is the policy effective date?

c)

Who enforces the policy?

d)

All of the above

30.

Which security component is essential for continuity in organizational security?

a)

Redundancy

b)

Limited connectivity

c)

Low-cost solutions

d)

Minimum compliance

31.

What is a vulnerability in cybersecurity terms?

a)

A strong password

b)

A weakness in systems or procedures

c)

An external attack

d)

A user error

32.

What is a threat vector?

a)

A secured pathway

b)

A means to access a system via a vulnerability

c)

A list of software updates

d)

A type of firewall

33.

What is the first step in handling risk?

a)

Ignore the risk

b)

Transfer the risk

c)

Identify the risk

d)

Retain the risk

34.

What is risk mitigation?

a)

Ignoring risk

b)

Eliminating all risks

c)

Reducing the impact of risks

d)

Transferring risks

35.

What does qualitative risk assessment focus on?

a)

Quantifying cost-related risks

b)

Measuring subjective factors

c)

Eliminating all risks

d)

Improving system performance

36.

What does risk retention mean?

a)

Ignoring the risk

b)

Budgeting for potential claims or losses

c)

Transferring risk to another party

d)

Reducing risk exposure

37.

What factor is not typically considered in asset assessment?

a)

Cost to obtain the asset

b)

Value to opponents

c)

Number of users

d)

Replacement cost

38.

What is a key objective of risk analysis?

a)

Reducing maintenance cost

b)

Simplifying network infrastructure

c)

Enabling cost vs. benefit evaluation

d)

Ignoring user activity

39.

What is one aim of a risk plan?

a)

To eliminate all organizational risks

b)

To reduce risks to an acceptable level

c)

To monitor software updates only

d)

To avoid asset replacement

40.

What does risk transfer typically involve?

a)

Eliminating risk

b)

Keeping risk in-house

c)

Utilizing insurance or third parties

d)

Ignoring the risk

41.

What does ISO 27002 provide?

a)

Guidelines on asset inventory

b)

Description of requirements for external party dealings

c)

IT support policies

d)

Employee guidelines

42.

What is a key aspect in dealing with third parties?

a)

Customer satisfaction

b)

Legal compliance

c)

Risk assessment and re-evaluation of controls

d)

Financial stability

43.

Why is access to assets granted to external parties?

a)

For software/hardware development

b)

For advertising purposes

c)

For inventory management

d)

For legal counsel

44.

Who are considered Curtin University's clients?

a)

Contractors

b)

Alumni

c)

Staff and students

d)

Security personnel

45.

What must the outside party specify regarding security arrangements?

a)

Data transfer protocols

b)

Security compliance methods

c)

Asset valuation metrics

d)

Database structures

46.

Outsourcing affects the organization by transferring what to an external party?

a)

Financial obligations

b)

Security of information and services

c)

Customer data only

d)

Payroll systems

47.

Which of the following is an example of physical access control?

a)

Passwords

b)

Firewalls

c)

Video cameras

d)

Encryption

48.

What must organizations carefully evaluate before granting customer access to assets?

a)

The value of shared data

b)

The total cost of the contract

c)

Marketing potential

d)

Client satisfaction

49.

What kind of access is typically required by partners?

a)

Administrative access

b)

Shared information access

c)

Physical building access

d)

Financial data access

50.

In case of customer access, what must organizations determine?

a)

The value of customer feedback

b)

The best asset protection methods

c)

The total inventory of assets

d)

The organization's social media reach

51.

What is critical to do before contracting out services?

a)

Increase marketing efforts

b)

Conduct a detailed assessment

c)

Survey employee satisfaction

d)

Update the company website

52.

What is required of the owner of an asset?

a)

Monthly reporting

b)

Maintenance and integrity of the asset

c)

Marketing of the asset

d)

Legal analysis

53.

What is a form of documentation required by ISO 27002?

a)

Financial projections

b)

Outsourced service contracts

c)

Record of asset ownership

d)

Product marketing plans

54.

Who might require access to source code?

a)

Developers

b)

Security personnel

c)

Financial analysts

d)

Maintenance staff

55.

What should be in place for any data-related outsourcing?

a)

Standard advertising formats

b)

Data protection policies

c)

Financial documents

d)

Legal marketing contracts

56.

Why is asset ownership classified and documented?

a)

To promote the asset's visibility

b)

To manage the asset more cost-effectively

c)

To meet marketing demands

d)

To improve staff compliance

57.

What must organizations consider when sharing data with an external party?

a)

Contract duration

b)

Cost of service

c)

Access control

d)

Marketing value

58.

Which type of control involves limiting access to confidential information?

a)

Marketing control

b)

Access control

c)

Financial control

d)

Security clearance

59.

What is the primary aim of ISO 27002 in terms of human resources security?

a)

Increase productivity

b)

Enhance employee engagement

c)

Reduce losses from human error or malicious activity

d)

Improve training efficiency

60.

According to ISO 27000, what type of checks must be conducted on all staff?

a)

Annual performance reviews

b)

Legal compliance checks

c)

Character and CV checks

d)

Social media checks

61.

Why should a credit check be conducted regularly for certain roles?

a)

To ensure they meet financial stability

b)

To prevent identity theft

c)

To safeguard access to privileged information

d)

To assess productivity

62.

Which ISO standard addresses the physical and environmental aspects of security systems?

a)

ISO 27001

b)

ISO 9001

c)

ISO 14000

d)

ISO 31000

63.

What is a common pitfall in physical security management?

a)

Excessive documentation

b)

Neglecting infrastructure security controls

c)

Overstaffing security teams

d)

Lack of regular audits

64.

Which type of security model involves multiple layers working together to protect an asset?

a)

Open source security model

b)

Multi-layer physical security model

c)

Zero-trust security model

d)

Cloud security model

65.

What is required for compliance with ISO 27001's physical security requirements?

a)

Unrestricted access to secure areas

b)

Fire safety training

c)

Documented risk assessment for auditors

d)

Third-party outsourcing for security

66.

Which threat type is NOT part of physical security challenges mentioned?

a)

Environmental threats

b)

Supply threats

c)

Technological threats

d)

Politically motivated threats

67.

According to ISO 27002, what must all staff wear in a secure facility?

a)

Uniforms

b)

Name tags or identification

c)

Body armor

d)

Protective gloves

68.

Why should privileged information be stored in secure areas?

a)

To avoid data redundancy

b)

To meet compliance standards

c)

To provide an additional layer of protection

d)

To facilitate easy access

69.

Which type of physical security threat is most likely to cause significant damage due to access knowledge?

a)

Insider threat

b)

Environmental threat

c)

Outside threat

d)

Digital threat

70.

ISO 27001 recommends monitoring fire doors to allow only:

a)

Two-way access

b)

Outward opening

c)

Limited use during business hours

d)

One-way opening

71.

According to ISO 27002, who should supervise visitors in secure areas?

a)

Human resources staff

b)

Security guards

c)

IT personnel

d)

Cleaning staff

72.

Which measure is essential in the physical security approach for securing information?

a)

Reducing staff training

b)

Limiting software updates

c)

Implementing perimeter barriers

d)

Centralizing IT support

73.

What should facilities handling confidential information avoid?

a)

High visibility and advertisement of their role

b)

Central locations within the building

c)

Secure locks on all doors

d)

Regular risk assessments

74.

Where should equipment with data access capabilities be positioned?

a)

Near windows

b)

In common areas

c)

Away from visibility by unauthorized users

d)

By the main entrance

75.

What is a crucial factor for ensuring continuous working order of sensitive equipment?

a)

Employee training sessions

b)

Regular software updates

c)

Continuous environmental monitoring

d)

Increased physical size of equipment

76.

Equipment to be taken off-site must be:

a)

Logged and provided with a detailed responsibility checklist

b)

Stored in non-secure areas

c)

Shared among different employees

d)

Taken without approval

77.

When disposing of equipment, ISO 27002 specifies:

a)

Minimal documentation is needed

b)

Disposal must ensure no data recovery is possible

c)

Disposal can be completed off-site without supervision

d)

Disposal records are unnecessary

78.

In terms of facility security, what should access to daily office equipment require?

a)

Enhanced privileges

b)

Basic privileges only

c)

Shared passwords

d)

No restrictions

79.

Why should dangerous materials be stored in separate locations?

a)

To reduce equipment maintenance costs

b)

To comply with storage requirements

c)

To ensure safety and minimize risks

d)

To increase accessibility

80.

What type of access is recommended for backup system media?

a)

Immediate access for all staff

b)

Accessible only within the secure area

c)

Stored off-site from backup equipment

d)

Full access for contractors

81.

What should be restricted when dealing with outside parties in secure processing facilities?

a)

Shared software usage

b)

Multiple entry points

c)

Access to phones and privileged information

d)

Open communication policies

82.

Who is primarily responsible for equipment repairs and upgrades in a secure facility?

a)

Contractors

b)

Security guards

c)

Cleared staff following risk assessment

d)

General employees

83.

Which ISO 27002 control is aimed at preventing unauthorized viewing of data on monitors?

a)

Increased screen brightness

b)

Data encryption

c)

Strategic equipment positioning

d)

Security camera installation

84.

What is the main goal of communications security?

a)

To reduce network traffic

b)

To ensure confidentiality, integrity, and availability of information

c)

To increase the speed of data transfer

d)

To minimize hardware costs

85.

Which area is NOT included in network security management?

a)

Cryptosecurity

b)

Emission security

c)

Data replication

d)

Traffic-flow security

86.

What is cryptosecurity primarily concerned with?

a)

Monitoring data traffic

b)

Using cryptographic techniques to protect communication content

c)

Blocking unauthorized access to devices

d)

Creating backup data copies

87.

ISO 27001 recommends starting cryptographic control implementation with which step?

a)

Key management

b)

Encryption algorithm selection

c)

Risk assessment

d)

Access control setup

88.

Which of the following is an essential part of proper key management in cryptosecurity?

a)

Disabling key rotation

b)

Random key generation

c)

Storing keys securely

d)

Publishing keys publicly

89.

Transmission security aims to protect data while it is:

a)

Stored on hard drives

b)

In use by applications

c)

Being transmitted

d)

Archived in servers

90.

Which protocol is commonly used to secure web traffic?

a)

IPsec

b)

FTP

c)

HTTP

d)

SSL/TLS

91.

What does emission security, also known as TEMPEST, aim to prevent?

a)

Data redundancy

b)

Electromagnetic emissions from being intercepted

c)

Unauthorized network access

d)

Inadequate encryption protocols

92.

Which organization publishes lists of approved TEMPEST testing labs?

a)

United Nations

b)

NSA-USA

c)

FCC

d)

ISO

93.

Traffic-flow security protects which type of information?

a)

The content of communications

b)

The metadata associated with communications

c)

Network bandwidth

d)

File encryption keys

94.

Why is it important to conceal metadata about communications?

a)

To reduce server load

b)

To prevent traffic analysis attacks

c)

To increase data throughput

d)

To save storage space

95.

What is the benefit of segregating networks into domains?

a)

Improved cryptographic security

b)

Faster data transmission

c)

Reduced hardware costs

d)

Increased number of access points

96.

How should sensitive information be handled in voicemail systems?

a)

Allowed to be shared freely

b)

Avoided to prevent unauthorized access

c)

Recorded on public servers

d)

Open to all employees

97.

What is a key element in information exchange agreements?

a)

Assigning responsibilities for handling sensitive information

b)

Allowing unrestricted information flow

c)

Random labeling of data

d)

Frequent policy updates

98.

Why are technical controls for traceability and non-repudiation essential in information exchange?

a)

To prevent data loss

b)

To prove information was sent and received as claimed

c)

To reduce data encryption costs

d)

To ensure faster data transfer

99.

What is required when couriers are used for physical information transfer?

a)

No identification needed

b)

Standard delivery protocol

c)

Identification procedures to verify courier authenticity

d)

Open access to all employees

100.

For sensitive information exchange, an agreement on which of the following is recommended?

a)

File format and encryption standards

b)

Storage capacity requirements

c)

Open access policies

d)

Color coding of documents

101.

What should be consistent with the receiving organization's internal labeling system?

a)

Encryption method

b)

Labeling system for protection levels

c)

Internet access settings

d)

User roles

102.

Information exchange policies should align protection methods with:

a)

Employee preferences

b)

Financial goals

c)

Information classification levels

d)

Network load capacity

103.

Which procedure is essential for securely disposing of traffic-flow data?

a)

Copying the data to external devices

b)

Following data retention and disposal policies

c)

Encrypting all archived data

d)

Releasing data to public domain

104.

What is essential for implementing an effective security system for staff?

a)

Limiting staff access

b)

Regular security training

c)

Keeping staff informed about security changes

d)

Restricting all online access

105.

ISO 27002 suggests that which platform can help staff access security information?

a)

Social media

b)

Intranet

c)

Local server

d)

External drive

106.

Which of the following is a common type of malware?

a)

Firewall

b)

Antivirus

c)

Worm

d)

VPN

107.

Viruses have which key characteristic?

a)

Self-replication and host dependency

b)

Independence from a host

c)

Block all system files

d)

Only affects network traffic

108.

Which type of malware does NOT need a host to spread?

a)

Virus

b)

Worm

c)

Spyware

d)

Trojan

109.

What is a defining feature of spyware?

a)

Automatically cleans up data

b)

Collects information about the system

c)

Encrypts files for security

d)

Only affects Windows operating systems

110.

What is a botnet?

a)

A network of infected machines

b)

A type of antivirus software

c)

A secure network protocol

d)

A form of firewall protection

111.

According to ISO 27002, what should organizations prohibit to prevent malware?

a)

Use of unauthorized software

b)

Access to the internet

c)

External email access

d)

File transfers within the network

112.

What is required for handling files from external sources?

a)

Ignore security checks

b)

Archive files immediately

c)

Check files for malware

d)

Install additional software

113.

Why is it essential to monitor email attachments according to malware procedures?

a)

To reduce email load

b)

To protect against malware infections

c)

To enable faster data access

d)

To increase email storage

114.

ISO 27002 recommends which approach to manage mobile code security?

a)

Install mobile code on all devices

b)

Block mobile code entirely

c)

Limit mobile code to its intended environment

d)

Share mobile code across all devices

115.

What is the primary objective of back-up mechanisms?

a)

To store data off-site only

b)

To ensure data recovery in case of loss

c)

To increase storage space

d)

To improve network speed

116.

Where should back-up data ideally be stored?

a)

On the local server

b)

On external hard drives

c)

Off-site

d)

In cloud storage only

117.

Which technology does ISO 27002 suggest using for critical servers?

a)

Firewall

b)

RAID

c)

Proxy

d)

DNS

118.

What should be tested regularly to ensure effective back-up?

a)

Software licenses

b)

Network speeds

c)

Recovery procedures

d)

Email attachments

119.

What type of information also requires off-site back-up according to ISO 27002?

a)

Personal emails

b)

Music files

c)

Paper-based information

d)

Unclassified digital files

120.

What is the common target platform for viruses?

a)

Linux

b)

macOS

c)

Android

d)

Windows

121.

What characteristic distinguishes worms from viruses?

a)

Need for user action to spread

b)

Dependence on a host

c)

Ability to replicate independently

d)

Only affecting emails

122.

What is the primary purpose of spyware?

a)

Encrypts all files

b)

Deletes unauthorized software

c)

Collects and sends data from the infected system

d)

Optimizes system performance

123.

What kind of activity is a botnet often used for?

a)

Regular system updates

b)

Denial-of-Service (DDOS) attacks

c)

Data backups

d)

System encryption

124.

What measure does ISO 27002 recommend for handling malware in downloaded files?

a)

Immediate download and storage

b)

Ignoring unknown files

c)

Documenting malware check findings

d)

Direct file sharing across the network

125.

Which type of malware has the ability to mutate and change its code?

a)

Standard virus

b)

Worm

c)

Polymorphic malware

d)

Spyware

126.

Which method is recommended to mitigate mobile device risks in an organization?

a)

Block all mobile access

b)

Limit internet access on mobile devices

c)

Limit execution of mobile code

d)

Allow open access on devices

127.

What is an effective control for preventing botnet attacks?

a)

Allowing unrestricted network access

b)

Implementing access controls and monitoring

c)

Avoiding software updates

d)

Disabling antivirus programs

128.

What is one way to ensure unauthorized software use is prevented?

a)

Allowing all downloads

b)

Enforcing software compliance

c)

Increasing download speeds

d)

Allowing free data transfer

129.

Which approach provides the best outcome for software control?

a)

Application only

b)

Database control only

c)

Operating system only

d)

All three in combination

130.

What is a common issue with poorly configured security packages?

a)

They don't require maintenance

b)

They allow high user functionality

c)

They may cause more harm than good

d)

They require minimal specialist knowledge

131.

ISO 27002 recommends which control for database access?

a)

Unrestricted user access

b)

Asset or data ownership only

c)

Isolating critical systems

d)

Unlimited privileges for all users

132.

Which of the following is NOT a function of the NIST Cyber Security Framework?

a)

Identifying incidents

b)

Limiting incident damage

c)

Ensuring data redundancy

d)

Restoring capabilities

133.

Which control method is recommended by ISO 27002 for application input validation?

a)

Buffer Overflow Management

b)

Batch, Balancing, and Integrity checks

c)

Only Batch processing

d)

Selective Application Logs

134.

Which protocol ensures a secure internet connection and prevents data modification?

a)

IPSec

b)

SSL

c)

S/MIME

d)

SMTP

135.

What is the primary issue with social engineering attacks in e-commerce?

a)

It increases site traffic

b)

It leverages insider information

c)

It uses knowledge from the internet

d)

It requires face-to-face interaction

136.

Which ISO standard is relevant to e-commerce security and internet use?

a)

ISO 9001

b)

ISO 27001

c)

ISO 14000

d)

ISO 31000

137.

How does IPSec contribute to secure e-commerce?

a)

It provides SSL certificates

b)

It authenticates payment transactions

c)

It encrypts IP packets and authenticates their source

d)

It monitors data streams

138.

Which aspect is NOT covered in an organization's acceptable internet usage policy?

a)

Allowed download activities

b)

Privacy and monitoring rules

c)

Staff salaries

d)

Consequences for policy breaches

139.

Which activity is part of the monitoring phase in incident response?

a)

Creating user accounts

b)

Setting up virtual meetings

c)

Monitoring unauthorized access attempts

d)

Updating HR records

140.

ISO27002 requires which type of clock synchronization for accurate incident recording?

a)

Pacific Time

b)

Daylight Saving Time

c)

Local Office Time

d)

Universal Coordinated Time (UCT)

141.

Incident response responsibilities include:

a)

System start-up updates

b)

User ID configuration

c)

Communication with affected parties

d)

Financial budgeting

142.

What does a tabletop exercise in business continuity planning involve?

a)

Real-life recovery testing

b)

A theoretical plan walkthrough

c)

Physical equipment handling

d)

Financial simulations