wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Chapter 21: Common Types of Attacks

Total questions: 99

Worksheet time: 50mins

Name
Class
Date
1.

Explain the term (IoT) Internet of Things.

a)

A network of interconnected devices that communicate and exchange data with each other.

b)

A type of internet service provider.

c)

A programming language used for web development.

d)

A social media platform for sharing images.

2.

The (IIoT) Industrial Internet of Things is:

a)

a network of interconnected devices in the industrial sector

b)

a type of internet service for homes

c)

a new programming language

d)

a type of industrial machinery

3.

Describe (SCADA) Supervisory control and data acquisition.

a)

A system used for remote monitoring and control.

b)

A type of database management system.

c)

A programming language for web development.

d)

A method for data encryption.

4.

What does (ICS) Industrial control System refer to?

a)

A system used for controlling industrial processes

b)

A type of computer software

c)

A method of data encryption

d)

A type of industrial machinery

5.

Explain the concept of (OT) operational technology.

a)

Operational technology (OT) refers to hardware and software that detects or causes changes through direct monitoring and control of physical devices, processes, and events.

b)

Operational technology (OT) is a type of technology used primarily in the financial sector for managing transactions.

c)

Operational technology (OT) is a software development methodology focused on operational efficiency.

d)

Operational technology (OT) is a branch of information technology focused on data analysis.

6.

Who is considered a Guest in network security terms?

a)

A user with full access rights

b)

A user with limited access rights

c)

A network administrator

d)

A hacker

7.

What does (BYOD) Bring your own device mean?

a)

A policy allowing employees to bring personal devices to work

b)

A type of device provided by the company

c)

A software used for device management

d)

A security protocol for company devices

8.

Define (DoS) Denial-of-service.

a)

A type of cyber attack that aims to make a machine or network resource unavailable to its intended users.

b)

A method of encrypting data to protect it from unauthorized access.

c)

A protocol for secure communication over a computer network.

d)

A software tool used for network monitoring and analysis.

9.

What is (DDoS) distributed denial-of-service?

a)

A type of cyber attack that aims to make a service unavailable by overwhelming it with traffic.

b)

A method of encrypting data to protect it from unauthorized access.

c)

A software tool used to detect and remove malware from a computer.

d)

A protocol for secure communication over a computer network.

10.

VLAN hopping is a network security vulnerability that allows an attacker to:

a)

Access data on a different VLAN without authorization

b)

Improve network performance

c)

Securely connect to a VLAN

d)

Monitor network traffic

11.

What is (MAC) Media Access Control Flooding?

a)

A technique used to overload a network switch's MAC address table

b)

A method to enhance network security by filtering MAC addresses

c)

A protocol for wireless communication

d)

A type of malware that targets MAC addresses

12.

Describe (ARP) Address Resolution Protocol poisoning.

a)

ARP poisoning is a type of cyber attack where an attacker sends falsified ARP messages over a local area network.

b)

ARP poisoning is a method used to enhance network security by encrypting ARP messages.

c)

ARP poisoning is a technique for improving network speed by optimizing ARP message routing.

d)

ARP poisoning is a protocol used for secure communication between network devices.

13.

ARP spoofing is a technique used to:

a)

Intercept network traffic by associating the attacker's MAC address with the IP address of another host

b)

Encrypt data for secure transmission

c)

Improve network speed by caching IP addresses

d)

Authenticate users on a network

14.

DNS poisoning is a type of attack that involves what?

a)

Altering DNS records to redirect traffic

b)

Encrypting DNS queries for security

c)

Blocking DNS requests from certain IPs

d)

Increasing DNS query speed

15.

Key management involves:

a)

storing and organizing cryptographic keys

b)

managing user access to a network

c)

developing software applications

d)

designing user interfaces

16.

DNS spoofing is a type of cyber attack that involves:

a)

Altering DNS records to redirect traffic

b)

Encrypting DNS queries for security

c)

Blocking DNS requests to prevent access

d)

Monitoring DNS traffic for analysis

17.

What are Rogue devices and services?

a)

Unauthorized devices and services that connect to a network without permission

b)

Devices and services that are officially sanctioned by the network administrator

c)

Devices and services that are used exclusively for gaming purposes

d)

Devices and services that are used for educational purposes

18.

The role of DHCP in network security is to:

a)

Assign IP addresses dynamically to devices on a network, reducing the risk of IP conflicts.

b)

Encrypt data transmitted over the network to prevent unauthorized access.

c)

Monitor network traffic for suspicious activity and block potential threats.

d)

Provide a secure channel for remote access to the network.

19.

An AP in network security is:

a)

Access Point

b)

Application Protocol

c)

Authentication Process

d)

Advanced Protection

20.

Evil twin in the context of network security is:

a)

A type of phishing attack

b)

A rogue Wi-Fi access point

c)

A type of malware

d)

A network firewall

21.

An On-path attack is a type of cyber attack where an attacker secretly intercepts and relays communications between two parties who believe they are directly communicating with each other.

a)

A type of cyber attack where an attacker intercepts and relays communications.

b)

A method of secure communication between two parties.

c)

A legal way to monitor network traffic.

d)

A technique for improving network speed.

22.

Social engineering is a technique used to:

a)

steal personal information through manipulation

b)

improve social skills

c)

engineer social networks

d)

develop social policies

23.

What is Phishing?

a)

A type of fishing technique

b)

A method of secure communication

c)

A cyber attack method to steal sensitive information

d)

A programming language

24.

Dumpster diving in network security involves:

a)

Searching through trash to find sensitive information

b)

Hacking into secure networks

c)

Phishing for user credentials

d)

Installing malware on devices

25.

What is Shoulder surfing?

a)

A technique used to steal someone's personal information by looking over their shoulder.

b)

A method of surfing on the internet using shoulder movements.

c)

A type of surfing sport performed on the shoulders of waves.

d)

A dance move involving shoulder movements.

26.

Explain Tailgating in the context of security.

a)

Tailgating is a method of social engineering where an unauthorized person gains access to a restricted area by following an authorized person.

b)

Tailgating is a technique used in cybersecurity to protect data from unauthorized access.

c)

Tailgating refers to the practice of monitoring network traffic to prevent data breaches.

d)

Tailgating is a method of encrypting sensitive information to ensure privacy.

27.

What is Malware?

a)

A type of software designed to protect computers

b)

A type of software designed to harm or exploit any programmable device or network

c)

A type of hardware used to enhance computer performance

d)

A type of software used for creating documents

28.

Device hardening involves:

a)

Installing antivirus software

b)

Updating device firmware

c)

Disabling unnecessary services

d)

All of the above

29.

Disabling unused ports and services means:

a)

Turning off ports and services that are not in use to enhance security.

b)

Keeping all ports and services active regardless of usage.

c)

Enabling additional ports and services for better performance.

d)

Ignoring unused ports and services.

30.

It is important to change default passwords because:

a)

they are easy to guess and can lead to unauthorized access.

b)

they are difficult to remember.

c)

they are unique to each device.

d)

they improve the speed of the device.

31.

What is (NAC) Network access control?

a)

A security solution to control access to a network

b)

A type of network protocol

c)

A hardware device for network management

d)

A software application for data analysis

32.

Port security is a feature used to:

a)

Control access to a network by limiting the number of MAC addresses allowed on a port

b)

Encrypt data transmitted over a network

c)

Monitor network traffic for suspicious activity

d)

Provide wireless connectivity to devices

33.

What is 802.1X in network security?

a)

A network protocol for secure communication

b)

A standard for network access control

c)

A type of firewall

d)

A wireless communication protocol

34.

MAC filtering is a security access control method that allows or denies network access based on the MAC address of a device. Which of the following best describes MAC filtering?

a)

A method to control access to a network based on the MAC address of a device.

b)

A technique to filter emails based on their content.

c)

A process to enhance the speed of a network by prioritizing certain devices.

d)

A method to encrypt data before transmission over a network.

35.

What are Security rules?

a)

Security rules are guidelines to protect data and resources.

b)

Security rules are a type of software.

c)

Security rules are irrelevant in modern technology.

d)

Security rules are only applicable to physical security.

36.

Explain (ACL) Access control list.

a)

An ACL is a set of rules that control network traffic and limit access to resources.

b)

An ACL is a type of encryption algorithm used to secure data.

c)

An ACL is a protocol for transferring files over the internet.

d)

An ACL is a software application for managing databases.

37.

What is (URL) Uniform Resource Locator filtering?

a)

A method to block access to certain websites based on their URLs

b)

A technique to enhance website loading speed

c)

A process to encrypt URL data for security

d)

A way to categorize websites based on content

38.

Content filtering is a technique used to:

a)

Block or allow access to specific content based on predefined criteria

b)

Enhance the speed of internet connection

c)

Monitor user activity without restrictions

d)

Provide unlimited access to all online content

39.

What are Zones: Trusted vs. untrusted?

a)

Zones are network segments that are either trusted or untrusted based on security policies.

b)

Zones are geographical areas with different time zones.

c)

Zones refer to different climate regions in the world.

d)

Zones are sections of a hard drive used for data storage.

40.

A Screened subnet is a network security architecture that involves:

a)

A single firewall protecting the entire network

b)

Multiple firewalls with a DMZ between them

c)

A network without any firewalls

d)

A network with only internal firewalls

41.

What is a Botnet in the context of network attacks?

a)

A network of private computers infected with malicious software and controlled as a group without the owners' knowledge

b)

A type of firewall used to protect against network attacks

c)

A software tool used by network administrators to monitor traffic

d)

A secure network protocol for encrypting data

42.

Explain the MITM attack as shown in the diagram.

a)

A type of attack where the attacker secretly intercepts and relays communications between two parties.

b)

A method of encrypting data to prevent unauthorized access.

c)

A protocol for secure communication over a computer network.

d)

A technique for improving network performance by caching data.

43.

DNS Spoofing is a type of cyber attack. How does it work according to the diagram?

a)

By redirecting traffic to a malicious server

b)

By encrypting DNS queries

c)

By blocking DNS requests

d)

By speeding up DNS resolution

44.

Describe IP Spoofing based on the information provided.

a)

IP Spoofing is a technique used to gain unauthorized access to computers by tricking the system into believing that the messages are coming from a trusted source.

b)

IP Spoofing is a method of encrypting data to ensure secure communication over the internet.

c)

IP Spoofing is a process of compressing data to save bandwidth during transmission.

d)

IP Spoofing is a technique used to improve the speed of data transmission over networks.

45.

DDoS stands for Distributed Denial of Service. How is it depicted in the diagram?

a)

A single computer attacking a server

b)

Multiple computers attacking a server

c)

A server attacking multiple computers

d)

A single computer defending against an attack

46.

What are Rootkits and how do they function as per the diagram?

a)

Rootkits are software tools that allow unauthorized access to a computer system.

b)

Rootkits are hardware devices used to enhance computer performance.

c)

Rootkits are antivirus programs designed to protect against malware.

d)

Rootkits are network protocols used for secure communication.

47.

What are technology-based attacks in cybersecurity?

a)

Phishing, malware, and ransomware

b)

Social engineering and insider threats

c)

Physical theft and natural disasters

d)

Regulatory compliance and audits

48.

Network attacks can be prevented by:

a)

Using strong passwords and firewalls

b)

Ignoring software updates

c)

Sharing passwords openly

d)

Disabling antivirus software

49.

Explain the concept of rogue devices and services in cybersecurity.

a)

Rogue devices and services are unauthorized and potentially harmful devices or services connected to a network.

b)

Rogue devices and services are authorized and secure devices connected to a network.

c)

Rogue devices and services are devices that enhance network security.

d)

Rogue devices and services are devices that are always visible and easily detectable.

50.

Password attacks can be mitigated by:

a)

Using strong, unique passwords and enabling two-factor authentication

b)

Sharing passwords with trusted friends

c)

Writing passwords on a sticky note

d)

Using the same password for all accounts

51.

Malware threats and their impact on cybersecurity can be described as:

a)

A type of software designed to protect systems from cyber attacks.

b)

A type of software that disrupts, damages, or gains unauthorized access to a computer system.

c)

A method of encrypting data to secure it from unauthorized access.

d)

A legal framework for managing digital rights and copyrights.

52.

What are human and environmental threats in the context of cybersecurity?

a)

Human threats include insider threats and social engineering, while environmental threats include natural disasters and power failures.

b)

Human threats include natural disasters and power failures, while environmental threats include insider threats and social engineering.

c)

Human threats and environmental threats are the same in the context of cybersecurity.

d)

There are no human or environmental threats in the context of cybersecurity.

53.

What are hardening security measures and why are they important?

a)

Hardening security measures are techniques to enhance system security and they are important to protect against vulnerabilities.

b)

Hardening security measures are methods to increase system speed and they are important for performance optimization.

c)

Hardening security measures are strategies to improve user interface and they are important for user satisfaction.

d)

Hardening security measures are tools to expand storage capacity and they are important for data management.

54.

What is network access control and filtering in cybersecurity?

a)

A method to monitor and control incoming and outgoing network traffic

b)

A technique to enhance the speed of a network

c)

A process to install antivirus software

d)

A way to design network architecture

55.

Explain network segmentation and enforcement in cybersecurity.

a)

Network segmentation divides a network into smaller parts to improve security, while enforcement ensures policies are followed.

b)

Network segmentation is about connecting all devices, and enforcement is about monitoring traffic.

c)

Network segmentation and enforcement are methods to increase network speed.

d)

Network segmentation and enforcement are unrelated concepts in cybersecurity.

56.

Secure communication and infrastructure in cybersecurity refers to:

a)

The use of encryption and secure protocols to protect data during transmission and storage.

b)

The physical security measures to protect hardware from theft.

c)

The use of antivirus software to protect against malware.

d)

The implementation of firewalls to block unauthorized access.

57.

Describe physical security measures in the context of cybersecurity.

a)

Physical security measures include firewalls and antivirus software.

b)

Physical security measures involve encryption and secure passwords.

c)

Physical security measures include surveillance cameras and access control systems.

d)

Physical security measures are about data backup and recovery.

58.

What is industrial security and segmentation in cybersecurity?

a)

Industrial security and segmentation are methods to protect industrial systems from cyber threats by dividing networks into segments.

b)

Industrial security and segmentation refer to the physical security measures in factories.

c)

Industrial security and segmentation are unrelated to cybersecurity.

d)

Industrial security and segmentation are methods to enhance the speed of industrial networks.

59.

Explain the concept of trusted vs. untrusted zones in cybersecurity.

a)

Trusted zones are areas within a network that are considered secure, while untrusted zones are areas that are not considered secure.

b)

Trusted zones are areas outside a network that are considered secure, while untrusted zones are areas within a network that are not considered secure.

c)

Trusted zones and untrusted zones are both considered secure areas within a network.

d)

Trusted zones and untrusted zones are both considered insecure areas outside a network.

60.

Which of the following is a best practice for cybersecurity preventive measures?

a)

Regularly updating software and systems

b)

Ignoring software updates

c)

Using the same password for all accounts

d)

Sharing passwords with others

61.

What is a Technology-Based Attack?

a)

A type of attack that uses technology to exploit vulnerabilities.

b)

A physical attack on technological devices.

c)

An attack that does not involve any technology.

d)

A type of attack that only targets software.

62.

A Denial-of-Service (DoS) attack is:

a)

a type of cyber attack where the attacker seeks to make a machine or network resource unavailable to its intended users by temporarily or indefinitely disrupting services of a host connected to the Internet.

b)

a method of encrypting data to protect it from unauthorized access.

c)

a technique used to improve the speed and efficiency of a computer network.

d)

a process of backing up data to prevent loss in case of hardware failure.

63.

Which of the following is a characteristic of a Denial-of-Service (DoS) attack?

a)

It uses multiple computers to attack.

b)

It overloads resources like CPU and memory.

c)

It is a type of phishing attack.

d)

It encrypts data on the server.

64.

The difference between a DoS and a DDoS attack is:

a)

A DoS attack is from a single source, while a DDoS attack is from multiple sources.

b)

A DoS attack is more powerful than a DDoS attack.

c)

A DoS attack targets multiple systems, while a DDoS attack targets a single system.

d)

There is no difference between a DoS and a DDoS attack.

65.

What is a Reflective Attack?

a)

An attack that uses open services to disguise the attacker's identity.

b)

An attack that directly targets the victim's server.

c)

An attack that uses malware to infect the victim's system.

d)

An attack that encrypts the victim's data.

66.

Describe the process of a Reflective Attack.

a)

A Reflective Attack involves sending a request to a server that appears to come from a trusted source.

b)

A Reflective Attack is a type of cyber attack where the attacker sends a request to a third-party server, which then reflects the request back to the target.

c)

A Reflective Attack is a method of encrypting data to prevent unauthorized access.

d)

A Reflective Attack is a technique used to improve the performance of a network by caching responses.

67.

What is an Amplified Attack?

a)

A) A type of DoS attack that uses small requests to generate large responses.

b)

B) A type of attack that encrypts data.

c)

C) A type of attack that uses phishing techniques.

d)

D) A type of attack that uses social engineering.

68.

Explain the process of an Amplified Attack.

a)

An attack that increases the volume of traffic using reflection techniques.

b)

A method to reduce network congestion.

c)

A process to enhance data encryption.

d)

A strategy to improve server performance.

69.

What type of attack is depicted in the first diagram?

a)

Reflection attack

b)

Amplification attack

c)

Phishing attack

d)

Man-in-the-middle attack

70.

An amplification attack works by exploiting vulnerabilities in network protocols to increase the volume of traffic sent to a target. Which of the following best describes this process?

a)

The attacker sends a small request to a server, which then sends a much larger response to the target.

b)

The attacker directly sends a large volume of traffic to the target.

c)

The attacker uses malware to take control of the target's system.

d)

The attacker encrypts the traffic to make it untraceable.

71.

What is a Friendly DoS Attack?

a)

A type of cyber attack that is unintentional and caused by legitimate users.

b)

A deliberate attempt to disrupt a network by overwhelming it with traffic.

c)

A security measure to prevent unauthorized access to a network.

d)

A software tool used to enhance network performance.

72.

Which of the following is an example of a Friendly DoS Attack?

a)

Unplugging cables to disrupt connections.

b)

A flash sale on an e-commerce site causing server crashes due to high traffic.

c)

Cutting fiber optic lines to isolate networks.

d)

Overheating network hardware to cause failures.

73.

What is a Physical DoS Attack?

a)

A type of cyber attack that targets physical infrastructure to disrupt services.

b)

A method of enhancing physical security measures.

c)

A strategy for improving network performance.

d)

A technique for optimizing data storage.

74.

Which of the following actions can cause a Physical DoS Attack?

a)

High demand for services.

b)

Unpatched software causing infinite loops.

c)

Overheating network hardware to cause failures.

d)

Large file downloads overwhelming bandwidth.

75.

What does a Permanent Denial-of-Service (PDoS) attack do to devices?

a)

It temporarily disrupts device services.

b)

It permanently damages the device hardware.

c)

It encrypts device data for ransom.

d)

It slows down the device's network connection.

76.

What type of malware is used by attackers to overwrite device firmware permanently?

a)

Ransomware

b)

Adware

c)

Firmware rootkit

d)

Spyware

77.

In the example provided, what does an attacker do to IoT devices?

a)

Gain unauthorized access

b)

Improve security

c)

Monitor performance

d)

Update firmware

78.

Which of the following is a method to prevent DoS and DDoS attacks?

a)

Use Firewalls & Intrusion Prevention Systems (IPS)

b)

Disable Rate Limiting

c)

Ignore Load Balancers

d)

Avoid DDoS Mitigation Services

79.

Which service can be used for DDoS mitigation?

a)

Cloudflare

b)

AWS Shield

c)

Both A and B

d)

None of the above

80.

Why is it important to keep systems updated in the context of preventing DoS and DDoS attacks?

a)

To ensure compatibility with new software

b)

To improve system performance

c)

To patch security vulnerabilities

d)

To enhance user experience

81.

Which of the following is an example of a network attack?

a)

Data Theft

b)

VLAN Hopping

c)

Service Disruption

d)

Identity Fraud

82.

What occurs during an On Path Attack (Man-in-the-Middle)?

a)

Data is encrypted end-to-end

b)

The attacker intercepts and possibly alters the communication between two parties

c)

The attacker gains physical access to the device

d)

The attacker uses social engineering to gain information

83.

Which of the following is a process involved in an On Path Attack?

a)

A) Attacker inserts themselves between two communicating hosts.

b)

B) Attacker sends a direct message to the user.

c)

C) Attacker encrypts the communication.

d)

D) Attacker deletes all data.

84.

Wi-Fi Eavesdropping in the context of On Path Attack is:

a)

A method of intercepting data over a wireless network.

b)

A technique to improve Wi-Fi signal strength.

c)

A way to connect multiple devices to a single network.

d)

A process to enhance internet speed.

85.

Which of the following is a common On Path Attack method?

a)

SSL Stripping

b)

Data Encryption

c)

Direct Messaging

d)

Data Deletion

86.

Fill in the blank: DNS Poisoning is a cyberattack where attackers manipulate the DNS cache to redirect traffic to ________ sites.

a)

malicious

b)

legitimate

c)

secure

d)

trusted

87.

List the process steps involved in DNS Spoofing.

a)

Reconnaissance, Crafting Malicious Response, Injecting Malicious Response, Redirecting Traffic

b)

Crafting Malicious Response, Injecting Malicious Response, Redirecting Traffic, Reconnaissance

c)

Injecting Malicious Response, Redirecting Traffic, Reconnaissance, Crafting Malicious Response

d)

Redirecting Traffic, Reconnaissance, Crafting Malicious Response, Injecting Malicious Response

88.

Which of the following is a type of DNS attack?

a)

DNS Cache Poisoning

b)

Pharming

c)

Rogue DNS Server

d)

All of the above

89.

Explain the example given for DNS Spoofing involving a fake PayPal login page.

a)

A fake PayPal login page is created to steal user credentials.

b)

DNS Spoofing redirects users to a legitimate PayPal page.

c)

Users are warned about DNS Spoofing through email alerts.

d)

DNS Spoofing is used to enhance PayPal security.

90.

A VLAN Hopping Attack is:

a)

a method to bypass network security by exploiting VLAN tagging and trunking.

b)

a technique to enhance network performance by optimizing VLAN configurations.

c)

a strategy to improve wireless network coverage by using VLANs.

d)

a process to secure VLANs by implementing strict access controls.

91.

Which of the following is a method of VLAN Hopping?

a)

Port Mirroring

b)

Switch Spoofing

c)

MAC Flooding

d)

ARP Spoofing

92.

An attacker exploits what in a VLAN Hopping Attack?

a)

VLAN tagging

b)

MAC address spoofing

c)

IP address spoofing

d)

Port mirroring

93.

In the context of VLAN Hopping, what does Double Tagging involve?

a)

A method where an attacker adds an additional VLAN tag to packets.

b)

A technique to encrypt VLAN traffic.

c)

A process to merge two VLANs into one.

d)

A strategy to prevent VLAN hopping.

94.

ARP Spoofing is:

a)

A technique used to intercept network traffic by sending fake ARP messages.

b)

A method to enhance network security by encrypting ARP messages.

c)

A protocol used to assign IP addresses to devices on a network.

d)

A tool for monitoring network performance.

95.

Which of the following is a consequence of ARP Spoofing?

a)

Data Interception

b)

Improved Network Speed

c)

Enhanced Security

d)

None of the above

96.

In the process of ARP Spoofing, what does the attacker do with the victim's traffic?

a)

Reroutes it through themselves

b)

Deletes it

c)

Encrypts it

d)

Ignores it

97.

Explain how an attacker uses ARP Spoofing on a public Wi-Fi network.

a)

By sending fake ARP messages to associate their MAC address with the IP address of another device

b)

By encrypting all data packets on the network

c)

By physically tampering with the network hardware

d)

By using a VPN to mask their IP address

98.

Which of the following devices is not a part of the Internet of Things?

a)

A watch that allows you to measure and track your activity through a mobile app

b)

A security system that lets you remotely monitor your home

c)

A physical combination padlock for your gym locker

d)

A car with a built-in navigation system

99.

A computing concept that describes the network of physical devices and everyday devices (including refrigerators, thermostats, streetlights, and environmental tracking systems) that communicate with the internet.

a)

Internet of Things (IoT)

b)

Virtual Network

c)

Augmented Reality (AR)

d)

World Wide Web