wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Security

Total questions: 20

Worksheet time: 20mins

Name
Class
Date
1.

Which type of denial-of-service (DoS) attack occurs when a name server receives malicious or misleading data that incorrectly maps host names and IP addresses?

a)

Spam

b)

DNS poisoning

c)

SYN flood

d)

ARP poisoning

2.

While using the internet, you type the URL of one of your favorite sites in the browser. Instead of going to the correct site, the browser displays a completely different website. When you use the IP address of the web server, the correct site is displayed.

Which type of attack has likely occurred?

a)

Spoofing

b)

Hijacking

c)

Man-in-the-middle

d)

DNS poisoning

3.

An attacker uses an exploit to push a modified hosts file to client systems. This hosts file redirects traffic from legitimate tax preparation sites to malicious sites to gather personal and financial information.

Which kind of exploit has been used in this scenario?

a)

Domain name kiting

b)

Man-in-the-middle

c)

DNS poisoning

d)

Reconnaissance

4.

An attacker sets up 100 drone computers that flood a DNS server with invalid requests. This is an example of which kind of attack?

a)

Replay

b)

Backdoor

c)

Spamming

d)

DDoS

5.

Which of the following is the BEST definition of the term hacker?

a)

A general term used to describe any individual who uses their technical knowledge to gain unauthorized access to an organization.

b)

A threat actor whose main goal is financial gain.

c)

The most organized, well-funded, and dangerous type of threat actor.

d)

Any individual whose attacks are politically motivated.

e)

A threat actor who lacks skills and sophistication but wants to impress their friends or garner attention.

6.

Which of the following is the correct definition of a threat?

a)

Any potential danger to the confidentiality, integrity, or availability of information or systems

b)

Instance of exposure to losses from an attacker

c)

The likelihood of an attack taking advantage of a vulnerability

d)

Absence or weakness of a safeguard that could be exploited

7.

Which of the following BEST describes a cyber terrorist?

a)

Desires some kind of financial reward or revenge

b)

Exploits internal vulnerabilities to steal information

c)

Disrupts network-dependent institutions

d)

Downloads and runs attacks available on the internet

8.

An employee stealing company data could be an example of which kind of threat actor?

a)

Insider

b)

Nation state

c)

Competitor

d)

Hacktivist

e)

Script kiddie

9.

The IT manager in your organization proposes taking steps to deflect a potential threat actor. The proposal includes the following:

Create and follow onboarding and off-boarding procedures.

Employ the principal of least privilege.

Have appropriate physical security controls in place.

Which type of threat actor do these steps guard against?

a)

Script kiddie

b)

Hacktivist

c)

Insider

d)

Competitor

10.

A script kiddie is a threat actor who lacks knowledge and sophistication. Script kiddie attacks often seek to exploit well-known vulnerabilities in systems.

What is the BEST defense against script kiddie attacks?

a)

Build a comprehensive security approach that uses all aspects of threat prevention and protection.

b)

Implement email filtering systems.

c)

Properly secure and store data backups.

d)

Have appropriate physical security controls in place.

e)

Keep systems up to date and use standard security practices.

11.

Which of the following BEST describes an inside attacker?

a)

A good guy who tries to help a company see their vulnerabilities.

b)

An attacker with lots of resources and money at their disposal.

c)

An unintentional threat actor. This is the most common threat.

d)

An agent who uses their technical knowledge to bypass security.

12.

Which of the following best describes a script kiddie?

a)

A hacker willing to take more risks because the payoff is a lot higher

b)

A hacker whose main purpose is to draw attention to their political views

c)

A hacker who uses scripts written by much more talented individuals

d)

A hacker who helps companies see the vulnerabilities in their security infrastructure

13.

Which of the following is the single greatest threat to network security?

a)

Employees

b)

Weak passwords

c)

Email phishing

d)

Unsecure physical access to network resources

14.

Which of the following could an employee also be known as?

a)

Cybercriminal

b)

Exploit

c)

Internal threat

d)

Script kiddie

15.

What is the storage location called that holds all the development source files that version control systems use?

a)

Memory management

b)

Stored procedures

c)

Normalization

d)

Repository

16.

Which of the following includes all hardware and software necessary to secure data, such as firewalls and antivirus software?

a)

Policies

b)

Assets

c)

Users and administrators

d)

Physical security

17.

In your role as a security analyst, you need to stay up to date on the latest threats. You are currently reviewing the latest real-time updates on cyberthreats from across the world.

Which of the following resources are you MOST likely using?

a)

Threat hunting

b)

Threat feeds

c)

Intelligence fusion

d)

Advisories and bulletins

18.

Which of the following is an example of a vulnerability?

a)

Virus infection

b)

Denial-of-service attack

c)

Unauthorized access to confidential resources

d)

Misconfigured server

19.

A wireless access point configured to use Wired Equivalent Privacy (WEP) is an example of which kind of vulnerability?

a)

Unpatched software

b)

Default settings

c)

Weak security configurations

d)

Zero-day exploit

20.

Every ACME computer comes with the same account created at the factory. Which kind of vulnerability is this?

a)

Backdoor

b)

Misconfigurations

c)

Default accounts and passwords

d)

Weak passwords