wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

ISF 2

Total questions: 20

Worksheet time: 10mins

Name
Class
Date
1.

What is an example of a vulnerability in a cybersecurity context?

a)

Weak encryption on stored data

b)

Strong password policies

c)

Regular software updates

d)

Two-factor authentication

2.

Which cybersecurity measure ensures secure communication with suppliers?

a)

Use virtual private networks (VPNs)

b)

Implement firewalls

c)

Conduct regular security audits

d)

Utilize antivirus software

3.

What is ransomware?

a)

A type of malware that encrypts data for ransom

b)

A software that speeds up computer performance

c)

A program that removes viruses from a system

d)

A tool for managing network traffic

4.

Which factor makes polymorphic malware particularly challenging for traditional antivirus programs?

a)

It constantly changes its code signature to evade detection

b)

It is always distributed through email attachments

c)

It can only infect Windows operating systems

d)

It requires user interaction to execute

5.

Sensitive emails sent without encryption could lead to:

a)

Data breaches

b)

Increased email delivery speed

c)

Improved user experience

d)

Enhanced data storage

6.

What is one key feature of polymorphic malware?

a)

It changes its code to evade detection

b)

It is designed to spread rapidly across networks

c)

It requires user interaction to activate

d)

It is always detected by antivirus software

7.

How do you change permissions in absolute mode?

a)

. chmod numeric_value

b)

chmod -R value

c)

chmod +x filename

d)

chmod 777 filename

8.

A critical reason for using two-factor authentication is:

a)

Adding an additional layer of security

b)

Making passwords longer

c)

Reducing the need for passwords

d)

Eliminating the risk of phishing attacks

9.

Which of the following is an example of a technical security control?

a)

Firewall configuration

b)

Security policy documentation

c)

Employee training programs

d)

Physical access controls

10.

In the context of intrusion detection logs, organizations should:

a)

Regularly analyze and act on them

b)

Ignore them unless an incident occurs

c)

Only review them annually

d)

Store them without analysis

11.

What are the two most commonly used malware families in the Healthcare industry, according to FIREEYE?

a)

XtremeRAT and WITCHCOVEN

b)

Trojan and Ransomware

c)

Adware and Spyware

d)

WannaCry and Emotet

12.

What is the purpose of the CISA Services Catalog?

a)

To provide a centralized document with cybersecurity services and alerts

b)

To list all cybersecurity professionals in the country

c)

To serve as a guide for cybersecurity training programs

d)

To outline the history of cybersecurity threats

13.

Why is PowerShell frequently used in malware attacks?

a)

It provides a command-line interface to execute scripts

b)

It is a graphical user interface for managing files

c)

It is a web-based application for remote access

d)

It is a programming language for developing software

14.

Which method can help reduce data exfiltration in case of a network breach?

a)

Using Data Loss Prevention (DLP) tools to monitor and restrict sensitive data transfers.

b)

Implementing stronger password policies for user accounts.

c)

Increasing the bandwidth of the network to handle more traffic.

d)

Regularly updating software to patch vulnerabilities.

15.

What is a common countermeasure for preventing brute-force attacks?

a)

Implementing strong password policies and account lockouts

b)

Using simple passwords for easier access

c)

Allowing unlimited login attempts

d)

Disabling two-factor authentication

16.

Which cybersecurity model assumes that no user or device should be trusted by default?

a)

Zero Trust model

b)

Trusted Network model

c)

Defense in Depth model

d)

Perimeter Security model

17.

Which of the following would be classified as a vulnerability in a cybersecurity risk assessment?

a)

A software bug that allows unauthorized access to sensitive data.

b)

A strong password policy that prevents unauthorized access.

c)

Regular software updates to patch security flaws.

d)

A firewall that blocks unauthorized network traffic.

18.

What is a common attack that exploits weak passwords?

a)

Phishing attack

b)

Brute-force attack

c)

SQL injection

d)

Man-in-the-middle attack

19.

Which of the following vulnerabilities allows attackers to access systems without formal authorization?

a)

Unauthorized privilege escalation

b)

SQL injection

c)

Cross-site scripting

d)

Buffer overflow

20.

What is a common cybersecurity risk associated with remote learning and hybrid workspaces?

a)

Increased risk of physical theft of devices

b)

Greater exposure to phishing and video conferencing attacks

c)

Higher chances of malware from USB drives

d)

Reduced need for strong passwords