wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Cybersecurity Basics Pt.1

Total questions: 105

Worksheet time: 3hrs 15mins

Name
Class
Date
1.

In cybersecurity, what does CIA stand for?

a)

Confidentiality, Integrity, Availability

b)

Central Intelligence Agency

c)

Cybersecurity Investigation Agency

d)

Cybersecurity, Internet, Accessibility

2.

Alice is buying books from an online retail site, and she finds that she is able to change the price of a book from $20 to $1.

Which part of the CIA triad has been broken?

a)

C

b)

I

c)

A

d)

None of the above

3.

John is working on his college applications online, when the admissions website crashes. He is unable to turn in his college application on time.

Which part of the CIA triad has been broken?

a)

C

b)

I

c)

A

d)

None of the above

4.

Tony gets his phone bill in the mail. The bill was supposed to be for $80, but the mail person spilled water on the bill, smearing the ink. The bill now asks for $8.

Which part of the CIA triad has been broken?

a)

C

b)

I

c)

A

d)

None of the above

5.

Kim takes her college admissions test and is waiting to get her results by email. By accident, Kim’s results are sent to Karen.

Which part of the CIA triad has been broken?

a)

C

b)

I

c)

A

d)

None of the above

6.

Rob opens his fitness tracking app to start logging a workout. The app crashes, and he is unable to log his workout.

Which part of the CIA triad has been broken?

a)

C

b)

I

c)

A

d)

None of the above

7.

According to the CIA triad, which of the following is not considered in the triad?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Authenticity

8.

Which of the following contains the primary goals and objectives of security?

a)

Social Media

b)

The CIA triad

c)

The Internet

d)

None of the above

9.

What does confidentiality of data refer to?

a)

Rules which allow access only to all parties

b)

Rules which hide data

c)

Rules which restrict access only to those who need to know

d)

Rules which prevent data from being changed

10.

What does integrity of data refer to?

a)

The level of assurance which can be given as to how structured data is

b)

The level of assurance which can be given as to how accurate and trustworthy data is

c)

The level of assurance which can be given as to how strong data is

d)

The level of assurance which can be given as to how relevant the data is

11.

What does availability of data refer to?

a)

The level of assurance that data exists

b)

The level of assurance that data will be restricted to people who need it, when they need it

c)

The level of assurance that data will be accurate and trustworthy

d)

The level of assurance that data will be available to people who need it, when they need it

12.

Cynthia is working on her university applications online, when the admissions website crashes. She is unable to turn in her application on time.

a)

C

b)

I

c)

A

d)

None of the above

13.

Implementing data validation checks can prevent errors such as incorrect medication dosages or patient information.

a)

Confidentiality

b)

Integrity

c)

Availability

14.

Encrypted Messages:

When you send a private message to a friend, you use a special code (encryption) that only you and your friend can understand.

a)

Confidentiality

b)

Integrity

c)

Availability

15.

Using encrypted email systems or secure messaging apps ensures that patient information shared between doctors and specialists remains secret.

a)

Confidentiality

b)

Integrity

c)

Availability

16.

A doctor writes a prescription for a patient. If the prescription is altered or tampered with, the patient might get the wrong medication.

a)

Confidentiality

b)

Integrity

c)

Availability

17.

In the event of a system failure, the backup system can take over, ensuring that healthcare providers have continuous access to necessary information.

a)

Confidentiality

b)

Integrity

c)

Availability

18.

Password Protection:

Imagine you have a diary that you don't want anyone else to read. You put a lock on it and keep the key hidden.

a)

Confidentiality

b)

Integrity

c)

Availability

19.

When a system prompts for confirmation ensuring that the data is correct before it is saved.

a)

Confidentiality

b)

Integrity

c)

Availability

20.

Banks ensure that ATM machines are operational and have cash available for customers to withdraw money at any time

a)

Confidentiality

b)

Integrity

c)

Availability

21.

An audit trail logs every access and change made to a patient's record, including who made the change and when.

a)

Confidentiality

b)

Integrity

c)

Availability

22.

Only authorized healthcare professionals should have access to a patient's electronic health records.

a)

Confidentiality

b)

Integrity

c)

Availability

23.

A person completed a form on a website. They provided gender as “Female” when they logged into their account the following day, their gender information displayed as “male”.

a)

Confidentiality

b)

Integrity

c)

Availability

24.

Developing and regularly testing disaster recovery plans ensures that healthcare facilities can quickly restore services after a disruption, such as a natural disaster or cyberattack.

a)

Confidentiality

b)

Integrity

c)

Availability

25.

When you buy something, you get a receipt that shows exactly what you purchased and the amount you paid.

a)

Confidentiality

b)

Integrity

c)

Availability

26.

You visit amazon.co.uk to purchase an item but the website is offline.

a)

Confidentiality

b)

Integrity

c)

Availability

27.

How does limiting access contribute to maintaining confidentiality?

a)
By ensuring that only authorized individuals can view or access confidential information
b)
By posting confidential information publicly
c)
By sharing confidential information with unauthorized individuals
d)
By allowing everyone to view or access confidential information
28.

Why is it important to maintain the integrity of data like grades?

a)
To make the data more entertaining
b)
To confuse students and teachers
c)
To create an unfair advantage for certain students
d)
To ensure accuracy, fairness, and trust in the educational system.
29.

What does CIA stand for in the context of information security?

a)

Confidentiality, Integrity, and Authentication.

b)

Confidentiality, Integrity, and Authorization.

c)

Confidentiality, Integrity, and Accountability.

d)

Confidentiality, Integrity, and Availability

30.

Which subtopic of CIA Triad focuses on keeping information private and protected from unauthorized access?

a)

confidentiality

b)

authentication

c)

availability

d)

integrity

31.

Which subtopic of CIA Triad ensures that information is accurate, complete, and trustworthy?

a)

Authentication

b)

Integrity

c)

Confidentiality

d)

Availability

32.

Which subtopic of CIA Triad ensures that information is accessible and usable when needed?

a)

Non-repudiation

b)

Confidentiality

c)

Availability

d)

Integrity

33.
Which technique is used to detect and prevent unauthorized changes to data?
a)
Firewall
b)
Access controls
c)
Encryption
d)
Data validation
34.
Which measures are used to maintain Confidentiality?
a)
Data validation, checksums, digital signatures
b)
Encryption, access controls, user authentication
c)
Redundancy, backups, robust infrastructure
d)
Firewall, Antivirus, Encryption
35.
How is Availability ensured in cybersecurity?
a)
Firewall, Antivirus, Encryption
b)
Redundancy, backups, robust infrastructure
c)
Encryption, access controls, user authentication
d)
Data validation, checksums, digital signatures
36.
How is Integrity preserved in cybersecurity?
a)
Encryption, access controls, user authentication
b)
Data validation, checksums, digital signatures
c)
Redundancy, backups, robust infrastructure
d)
Phishing, Malware, Ransomware
37.
What is the purpose of redundancy in ensuring Availability?
a)
To slow down network traffic
b)
To provide backup resources
c)
To increase system complexity
d)
To confuse hackers
38.
How do access controls contribute to maintaining Confidentiality?
a)
By ensuring data accuracy
b)
By preventing data modification
c)
By controlling who can access information
d)
By creating backups
39.
What role do backups play in ensuring Availability?
a)
To provide redundancy in case of failures
b)
To slow down network traffic
c)
To confuse hackers
d)
To increase system complexity
40.

Explain how data integrity can be compromised in a network.

a)

By using strong passwords

b)

Through unauthorized data modification

c)

By implementing firewalls

d)

Through regular data backups

41.

Which of the following best describes the concept of data integrity?

a)

Ensuring data is available when needed

b)

Ensuring data is accurate and unaltered

c)

Ensuring data is encrypted

d)

Ensuring data is backed up

42.

What is the primary goal of ensuring system availability in cybersecurity?

a)

To prevent unauthorized access

b)

To ensure systems are operational and accessible

c)

To encrypt sensitive data

d)

To verify user identities

43.

Identify a common threat to system availability.

a)

Data encryption

b)

Denial of Service (DoS) attack

c)

Data redundancy

d)

User authentication

44.

Discuss how multi-factor authentication enhances security.

a)

By requiring only a password

b)

By using multiple methods to verify identity

c)

By encrypting data

d)

By backing up data

45.

Which of the following is an example of an authentication method?

a)

Data encryption

b)

Passwords

c)

Data compression

d)

Data fragmentation

46.

Evaluate the effectiveness of biometric authentication compared to traditional passwords.

a)

Biometric authentication is less secure

b)

Biometric authentication is more secure and convenient

c)

Traditional passwords are more secure

d)

Both are equally secure

47.

What is a potential drawback of using biometric authentication?

a)

It is less secure than passwords

b)

It can be expensive to implement

c)

It requires frequent password changes

d)

It is not user-friendly

48.

How does encryption contribute to data confidentiality?

a)

By making data accessible to everyone

b)

By converting data into a secure format

c)

By deleting unnecessary data

d)

By compressing data

49.

Phish or No Phish?

(Click on the image to see a larger version)

a)

Phish

b)

No Phish

50.

Scam or Real?

(Click on the image to see a larger version)

a)

Scam

b)

Real

51.

What should you look for in the URL to make sure that a site is safe before adding personal information?

a)

https: and a padlock

b)

www. and a globe symbol

c)

that it ends with .com

52.

The weakest point in a security system, is usually:

a)

Poorly coded software

b)

People

c)

Unreliable hardware

d)

Poor network connections

53.

What is PHISHING?

a)

Where a device is used to intercept packets of data as they are transferred across a network. This data is then analysed to look for passwords and other personal data.

b)

Where an executable file is secretly installed to record each key pressed and send

c)

Writing a snippet of code to try and retrieve data from a machine

d)

Sending emails pretending to be from reputable companies to try and get people to reveal personal information

54.

Which of the following people should you share your school password with when they ask?

a)

Your teacher

b)

The head teacher

c)

IT support

d)

Your parents/carers

e)

Nobody

55.

What should you do with a phishing email?

a)

Delete it

b)

Forward it to your friends

c)

Check out the links to see whether they are real

d)

Reply and ask them to stop spamming you

56.

What is the best defense against email scams?

a)

Delete your email when there are links

b)

Avoid email and use social media

c)

Disconnect your home phone because who uses them anyway?

d)

Be skeptical when you are asked for personal information

57.

Which of the following should you NOT do in response to an email scam?

a)

Tell your parents

b)

Reply to the email

c)

Report the email as spam

d)

Delete the email

58.

Which of the following is NOT a tactic commonly used by scammers?

a)

Asking to verify your account information

b)

Asking you to tell your friends about their offer

c)

Making you feel like you have to reply immediately

d)

Telling you that there is a problem with your account that needs to be fixed

59.

Which of the following are often signs that an email is a scam (Tick all that apply)?

a)

Bad grammar and spelling

b)

A link to a fake website

c)

Asking for personal information, such as usernames and passwords

d)

Addressed to you by name

60.

Is this a phishing scam?

a)

Yes

b)

No

61.

Is this a phishing scam?

a)

Yes

b)

No

62.

Is this a phishing scam?

a)

Yes

b)

No

63.

Is this a phishing scam?

a)

Yes

b)

No

64.

Is this a phishing scam?

a)

Yes

b)

No

65.

Is this a phishing scam?

a)

Yes

b)

No

66.
Firewall prevents hackers and viruses
a)
true
b)
false
67.

Phishing attacks are mainly using links (shortened URLS) to get you to give them...

a)

money

b)

coffee

c)

personal information

68.

True or False: Phishing attacks are NOT common

a)

True

b)

False

69.

Targeted attacks that focus on ONE person are called __________ phishing.

a)

ninja

b)

spear

c)

sword

d)

big

70.

What 2 places do scammers commonly use information from to create targeted spear phishing attacks? [Choose 2]

a)

Social Media

b)

Identification Cards

c)

Online public records

d)

Libraries

71.

What made Mike McFly (and others) easy to target for a spear phishing attack?

a)

Uses Facebook

b)

Uses Social Media

c)

Privacy settings allows anyone AND everyone to know where he is and what he is doing.

d)

Doesn't like coffee

72.

True or False: The best way to avoid a URL or Link that you don't trust from an EMAIL is to go to the website independently without using the URL.

a)

True

b)

False

73.

The Phishing video author's best advice when opening an unknown link or URL is...

a)

Open every and all shortened URLS and Links

b)

Exercise Extreme Caution

c)

Open some URLS, but not unknown Links

74.

"When someone poses (acts) as an institution, like a bank or a school, and sends you a personalized message asking you to provide private information." is called...

a)

internet scam

b)

identity theft

c)

private information

d)

phishing

75.

"A type of crime in which your private information is stolen and used for criminal activity." is called...

a)

internet scam

b)

identity theft

c)

private information

d)

phishing

76.

"Information that can be used to identify you because it is unique to you." is called...

a)

internet scam

b)

identity theft

c)

private information

d)

phishing

77.

One of the first steps you should take to identify a phishing website is to look at the URL.

a)

true

b)

false

78.

When a malicious actor is attempting to illicit information from a victim, what types of information might they be trying to obtain?

a)

Mother’s maiden name

b)

Addresses

c)

Credit card information

d)

Birthdays

e)

All of these

79.

Phishing attack that is directed towards specific individuals 

a)

Spear Phishing

b)

Whaling

c)

SPIM

d)

Smishing

80.

A spear phishing attack that is specific towards a high profile target 

a)

Spear Phishing

b)

SPIM

c)

Whaling

d)

Invoice Scam

81.

91% of phishing attacks that successfully get their recipients to click on a link and disclose personal information use a technique called "spear phishing". What is it about spear phishing that’s so effective?

a)

They use very sharp bait hooks.

b)

They use your computer's webcam to make sure it's you.

c)

They personalize the information in the email so you'll believe it's real.

d)

They make use of virtual reality to fool you.

82.

A second type of phishing that's particularly effective is called "clone phishing", so named because...

a)

Each one features C3PO and other Star Wars actors.

b)

They send you the same message over and over and over...

c)

All these emails are created by robots.

d)

The senders replace an email with an attachment you've already received with a similar one that has an infected attachment for you to download.

83.

One kind of phishing that’s used to snare you as you surf the web is called "forgery," where a fake website looks just like a real one. How do they accomplish that forgery?

a)

In the web address, they use “1” instead of “l”, “0” instead of “O” and so on.

b)

They use visual trickery to get you to look away for a moment while they load the bogus website.

c)

They are so smart, they take down the real website and replace it with a criminal one.

d)

They alter the legitimate website so it rips you off.

84.

Not all phishing is done with email and websites. Sometimes fraudsters use your phone to text or call you. They say there's a problem with your bank account and use the information you give them to access and withdraw money or make purchases. They do that by...

a)

Making your phone's caller ID look like it's coming from your bank.

b)

Sounding super convincing using lots of financial words.

c)

Choosing only people with lots of money.

d)

Making sure you're comfortable with them on the phone while they're ripping you off.

85.

Which protocol is secure when browsing website?

a)

HTTP

b)

HTTPS

c)

TELNET

d)

IPV4

86.

When using an untrusted network, what should a person do?

a)

Use a VPN

b)

Use a hotspot instead

c)

Only go to certain sites

d)

No steps are needed

87.

Mr. Taylor normally sits and waits on a target. He sends out anonymous emails hoping that someone would answer the call.

Beware, he seems legitimate.

a)

Hacking

b)

Identify Theft

c)

Phishing

d)

Cyberstalking

88.

Cute smiles and rosy cheeks always makes a heart melt. Be aware, that's a cover up in disguise. When you're not looking she steals the money from your possession without you knowing.

Don't fall for it!

a)

Forgery

b)

Embezzlement

c)

Hacking

d)

Cyberstalking

89.

Just sign on the dotted line and it's yours!

Many persons sign your name as theirs to get loans, cars and many other things.

a)

Phishing

b)

Forgery

c)

Electronic Eavesdropping

d)

Denial of Service Attack

90.

Many persons just feel as though they could ruin other people's lives for the fun of it.

People tend to feel that if they ruin someone's lives, it will also make them feel better about themselves.

a)

Electronic Eavesdropping

b)

Forgery

c)

Phishing

d)

Sabotage

91.

"Shiver me timbers and away I blow", with all of the copying and illegal downloading I go.

Make sure you know where merchants are getting their product from.

a)

Denial of Service Attack

b)

Phishing

c)

Software Piracy

d)

Electronic Eavesdropping

92.

Boy this new look sure looks good to me. Everything about this guy is perfect!

Be careful, people can steal your information to use for their own.

a)

Cyberstalking

b)

Identity Theft

c)

Hacking

d)

Phishing

93.

How many of the following are reasons why someone might want hack a computer system? (Choose 1 - 4 answers)

a)

For political reasons

b)

For ethical reasons

c)

For fun

d)

To steal data

94.

To avoid your computer being infected by malware, you should not:

a)

Download music, movies or software from illegal sites

b)

open emails from people you don’t know

c)

open email attachments

d)

post personal details on social networking sites

95.

Hackers:

a)

will destroy your computer hardware

b)

are rarely able to steal personal data

c)

sometimes steal passwords so they can access your online account

d)

can only steal one password at a time

96.

You can protect yourself against spam or fraudulent emails by:

a)

using a spam filter

b)

never clicking on links that you are suspicious of

c)

being aware of different types of fraudulent email

d)

all of the above

97.

If you receive an email from a well-known company, but its name is misspelt in the sender’s address, you should:

a)

click on the link in the email to check if it’s genuine

b)

reply, pointing out the error

c)

report it as a possible phishing scam

d)

forward the email to a friend to check

98.

A phishing email is one which:

a)

requests a payment for goods you have not received

b)

offers you products in which you may have no interest

c)

encourages you to click on a link to a fraudulent website

d)

contains abusive and threatening language

99.
What is malware?
a)
Software made a man called Mal (Malcom)
b)
Malicious Software
c)
Type of games software
d)
Software from before the year 2000
100.
What is a man-in-the-middle attack?
a)
Code that will run a malicious function if certain functions are met
b)
Malware that steals senstive information.
c)
Someone that intercepts data from a user, pretending to be a website
101.

Define a cyber threat and explain how it differs from a cyberattack.

4 lines
102.

Explain the purpose and importance of strong passwords.

4 lines
103.

Describe the three key principles of the CIA triad and explain why each is important in cybersecurity.

4 lines
104.

How can regular software updates help prevent cyberattacks?

4 lines
105.

Describe what a vulnerability is in the context of cybersecurity.

4 lines