Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Social Engineering & Access Control Quiz

Total questions: 25

Worksheet time: 13mins

Name
Class
Date
1.

How can users defend against watering hole attacks?

a)

By installing anti-virus and anti-malware programs.

b)

By avoiding common websites frequented by many users.

c)

By relying on browser extensions to detect malicious URLs.

2.

Which of the following best describes phishing?

a)

Fishing for compliments on social media

b)

Attempting to gain sensitive information through electronic communication by posing as a trustworthy source

c)

Using real fishing as a metaphor for online security

d)

Sending out random emails without a specific target

3.

What is a common characteristic of obvious phishing attempts?

a)

Proper grammar and spelling

b)

Well-designed graphics and fonts

c)

Misspelled words and odd graphics

d)

Promises that seem too good to be true

4.

What is another term for phishing done by phone call or voice message?

a)

Voice Broadcasting

b)

Voice Messaging

c)

Vishing

d)

Audio Phishing

5.

What is whaling in the context of phishing?

a)

Phishing attempt directed at high-profile targets like CEOs

b)

Phishing attempt directed at low-profile individuals

c)

Phishing attempt using cloned email addresses

d)

Phishing attempt through voice messages

6.

What is social engineering?

a)

A form of psychological manipulation to gain access to sensitive information or perform unauthorized actions

b)

A technique used by hackers to exploit software vulnerabilities

c)

A physical intrusion into a secure facility

d)

A marketing strategy to promote products on social media

7.

How can individuals defend against social engineering attacks?

a)

By complying with all requests received via email

b)

By ignoring any communication from unknown sources

c)

By sharing personal information freely

d)

By using the same password for all accounts

8.

SPAM emails can be identified by:

a)

Their personalized content

b)

Their encrypted attachments

c)

Their generic and unsolicited nature

d)

Their secure links

9.

Which group of threat actors is fueled by money and the desire to gain power to continue their influence?

a)

Hacktivists

b)

Shadow IT

c)

Nation States and APT

d)

Competition

10.

What do Insider Threats primarily exploit to cause damage within an organization?

a)

Exploits and attacks for a cause

b)

Advanced government or military organizations

c)

Shadow IT infrastructure

d)

Weak points known within the organization

11.

Which type of hackers intend to cause damage and harm to their targets?

a)

White hat hackers

b)

Grey hat hackers

c)

Black hat hackers

d)

Ethical hackers

12.

Shadow IT operates:

a)

As part of larger organizations, following IT department rules strictly

b)

Within larger organizations but not following IT department rules

c)

Independently, without any connection to larger organizations

d)

Solely for financial gain without regard to organizational rules

13.

What principle of the CIA Triad ensures that authorized users have timely and reliable access to information and systems when needed?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Authorization

14.

What is the purpose of the CIA Triad in information security?

a)

To authenticate users accessing the system

b)

To provide a framework for developing and implementing security controls

c)

To enforce access control policies

d)

To monitor network traffic and detect anomalies

15.

What is Phishing?

a)

Web pages you have visited that are stored on your hard drive

b)

Text files some websites use to identify users

c)

A scam to get confidential information

d)

A form where you type confidential information

16.

What is the best definition of Spear Phishing?

a)

"A Phishing email aimed directly at you"

b)

"A malicious virus that can encrypt or lock your computer"

c)

"A method hackers can use to guess your password"

d)

"A random Phishing email sent to a massive group"

17.

Which of these is the best definition of Shoulder Surfing?

a)

Calling someone to create an invented situation that increases the chance they will share sensitive information with you.

b)

Sending an email that pretends to be from a reputable company which usually has a link to click that takes you to a website that looks real but is not.

c)

A cyber attack that redirects a user from a real URL to a website that looks real but is not.

d)

Looking at someone entering their personal data into a system and copying what you see.

18.

Which of the following is a common sign of a phishing email?

a)

Personalized greeting with your full name

b)

Professional language and formatting

c)

Urgent request for sensitive information

d)

Emails from known contacts only

19.

Which of the following is a method to prevent unauthorized access to a network?

a)

Allowing guest access to all network resources

b)

Using strong passwords and two-factor authentication

c)

Sharing passwords with trusted colleagues

d)

Disabling firewalls for easier access

20.

What is a watering hole attack?

a)

A type of attack where hackers target a specific website frequented by a particular group

b)

A technique used to exploit software vulnerabilities in outdated systems

c)

An attack that involves sending phishing emails to random users

d)

A method of social engineering that involves impersonating a trusted source

21.

Which of the following is a common defense against watering hole attacks?

a)

Visiting only untrusted websites

b)

Regularly updating and patching software

c)

Disabling all browser extensions

d)

Using the same password across multiple sites

22.

How do attackers typically choose their targets in a watering hole attack?

a)

By identifying websites frequently visited by a specific group or organization

b)

By focusing on websites with strong security measures

c)

By selecting random websites with high traffic

d)

By targeting websites with outdated content

23.

How can users protect themselves from typosquatting attacks?

a)

By disabling browser security features

b)

By carefully checking the URL before entering sensitive information

c)

By using a single password for all accounts

d)

By frequently changing their email address

24.

Which of the following is a common sign of a typosquatting website?

a)

Secure HTTPS connection

b)

URL with minor spelling errors or extra characters

c)

High-quality content and design

d)

Official contact information

25.

How can organizations promote continuous learning in security practices?

a)

Ignore security threats

b)

Discourage employees from reporting suspicious behavior

c)

Hold regular interactive training sessions

d)

Limit access to security resources