wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Introduction to Cybersecurity Tools and Cyberattacks

Total questions: 85

Worksheet time: 44mins

Name
Class
Date
1.

Which of the following legislative acts or agencies effectively ended the National Security Agency’s bulk collection of phone metadata?

a)

USA Freedom Act

b)

National Cyber Security Division(NCSD)

c)

USA Patriot Act

d)

Department of Homeland Security(DHS)

2.

How are organizations safeguarding their resources with the virtual shift following the COVID-19 pandemic? Select all that apply.

a)

Creating bring-your-own-device(BYOD) policies

b)

Intensifying cybersecurity awareness training for employees

c)

Encoutaging employees to use public Wi-Fi networks for work

d)

Providing employees with antivirus licenses for their personal computers

3.

State True or False
National Security Decision Directives (NSDD 145) was America’s first national policy on telecommunication and automated information systems security.

a)

True

b)

False

4.

The history of cybersecurity dates back several decades. When did the first computer worm, Creeper, emerge?

a)

2000

b)

1971

c)

2010

d)

1987

5.

Which concept encourages software and system developers to integrate security features at the start of the development cycle?

a)

Advanced encryption

b)

National cybersecurity

c)

Global surveillance

d)

Security by design

6.

Which of the following illustrates the application of critical thinking in cybersecurity?

a)

Performing routine backups

b)

Conducting vulnerability scans

c)

Installing antivirus software

d)

Performing root cause analysis

7.

According to the critical thinking model, what skills do you require to effectively perform particular tasks or functions within cybersecurity?

a)

Administrative skills

b)

Intellectual abilities

c)

Technical skills

d)

Interpersonal skills

8.

If you are a Human Resource Manager conducting interviews for a cybersecurity analyst position, what specific competencies will you look for in candidates to assess their interpersonal skills?

a)

Clear communication

b)

Logical reasoning

c)

Knowledge of a renge of IT protocols

d)

Focused attention

9.

Imagine you are a data analyst researching customer behavior for a marketing campaign. When evaluating data, what should you do if the data does not support the hypothesis?

a)

Disregard the data and proceed with the original hipothesis

b)

Confirm the hypothesis

c)

Ignore the data

d)

Revisit assumptions and consider alternate explanations

10.

How does critical thinking empower cybersecurity professionals? Select all that apply.

a)

Recognize programming languages

b)

Make logical decisions

c)

Solve problems effectively

d)

Memorize cybersecurity laws

11.

The WarGames movie prompted US President Ronald Reagan to _______________.

a)

Create a new federal agency for cybersecurity

b)

Ban computer games

c)

Implement the country's first national cybersecurity policy

d)

Conduct cybersecurity training for military personnel

12.

As a privacy advocate, you’re investigating the implications of the recent legislation on government surveillance practices. Which law or agency significantly broadened the state’s surveillance capabilities?

a)

USA PATRIOT Act

b)

National Seciruty Decision Directives(NSDD 145)

c)

USA Freedom Act

d)

Department of Homeland Security(DHS)

13.

What is one of the primary impacts of COVID-19 on the global approach to cybersecurity?

a)

Remote access policies have become less stringent

b)

There is decreased public awareness of cyberthreats

c)

Organization have recognuzed the need to invest in cybersecurity infrastructure

d)

The demand for cybersecurity professionals has decreased

14.

When was the term “ethical hacking” coined?

a)

2003

b)

1983

c)

2000

d)

1995

15.

As a cybersecurity analyst at TechEase Securities, you received an email from an unknown sender claiming to be from your company’s IT department. The email requests that you urgently click a link to verify your account information due to alleged suspicious activity. How would you apply critical thinking in this situation?

a)

Click the link immediately to verify your account information

b)

Forward the email to the IT department

c)

Strutinize the email for sender information, language error, and signs of urgency before ckicking any link

d)

Delete the email because it appears to be spam

16.

A cybersecurity professional comes across an online article warning about a critical vulnerability in popular software and urging immediate patching. How can they use critical thinking to determine the best course of action?

a)

Forward the article to the IT department and engage in discussions

b)

Embrace new technologies based on the article

c)

Verify the reported vulnerability with official security advisories from trusted sources

d)

Ignore the article, as it might contain misleading information

17.

What skills will help a cybersecurity manager convince the executive team to allocate more resources for cybersecurity initiatives despite budget constraints?

a)

Skepticism

b)

Project management skills

c)

Negotiation skills

d)

Technical expertise

18.

How does objectivity enhance critical thinking for cybersecurity professionals?

a)

It enables them to validate the information before accepting it as factual

b)

It enables them to communicate complex issues effectively

c)

It allows them to combine diverse expertise and perspectives

d)

It motivates them to make unbiased judgments

19.

The IT department recently implemented a multifactor authentication (MFA) system for all employee logins and assumes this system has eliminated the risk of unauthorized access. How can a cybersecurity analyst leverage critical thinking to ensure the company’s security remains robust?

a)

Implement additional user authentication methods

b)

Provide comprehensive training on MFA best practices to employees

c)

Analyze data logs for patterns of unauthorized access attempts

d)

Challenge the effectiveness of the MFA system to mitigate access risks and eveluate for existing vulnerabilities

20.

When Emily, a cybersecurity manager, empathizes with different stakeholders to gain alternate perspectives on a security issue, which critical thinking skill is she using?

a)

Undertanding context

b)

Considering alternatives

c)

Evaluating data

d)

Challenging assumptions

21.

Which of the following threat actors are driven by political or social agendas?

a)

Organized crime groups

b)

Hacktivist

c)

Nation-state actors

d)

Script kiddies

22.

Which insider threat occurs out of malice, grievance, or financial incentives?

a)

Unintentional

b)

External

c)

Intentional

d)

State-sponsored

23.

Which of the following is an example of an action carried out by a negligent insider?

a)

Sharing sensitive information over unencrypted channels

b)

Falling victim to a phishing scam

c)

Selling confidential information

d)

Gathering and leaking intellectual property

24.

The IBM X-Force Threat Intelligence Index is designed to _______________.

a)

Offer cybersecurity services to individuals

b)

Profile and track individual hackers

c)

Serve as a legal database for cybercrime prosecution

d)

Provide insights into cybersecurity trends and threat landscape

25.

According to Jeff Crume, which technology can simulate an individual’s voice, image, and likeness on a mobile phone?

a)

Hallucinations

b)

Phishing

c)

Deep fake

d)

Retrieval augmented generation(RAG)

26.

Which of the following is a recommended measure for preventing malware attacks?

a)

Using simple, common passwords

b)

Using outdated software

c)

Using reputable antivirus and anti-malware software

d)

Avoiding software updates

27.

What is the term used to describe automated software that performs malicious tasks over the internet?

a)

Adware

b)

Keylogger

c)

Bot

d)

Rootkit

28.

Why is regular data backup important for cybersecurity?

a)

Ensures data recovery in the event of malware attacks

b)

Speeds up the system

c)

Meets legal requirements

d)

Makes the system immune to viruses

29.

How can you enhance account security beyond just using a password?

a)

Enabling multifactor authentication(MFA)

b)

Storing your password on your mobile phone

c)

Choosing an easy-to-remember password

d)

Using the same password across multiple accounts

30.

What does “https://” signify in a website’s URL?

a)

The site is not secure

b)

The site is for HTTP services only

c)

The connection to the site is encrypted and secure

d)

The site is under maintenance

31.

Which solution aims to inform users about the possibility of spear-phishing attacks?

a)

Quad 9

b)

Critical thinking skills

c)

Multifactor authentication(MFA)

d)

User education

32.

A cybersecurity specialist at a financial institution is tasked with finding ways to protect the company's executives from potential deep fake call scams. Which solution is most effective in addressing the issue? [Select two]

a)

User education

b)

Critical Thinking skills

c)

Quad 9

d)

Multifactor authentication(MFA)

33.

What is whaling?

a)

A targeted attack directed at spacific individuals or organizations

b)

To pollute search engine results with harmful links

c)

Employ fraudulent text messages to deceive individuals

d)

A specialized form of spear phishing aimed at high-profile targets like executives

34.

As an IT manager in a corporate setting, you are responsible for safeguarding the company's network against cybersecurity threats. What solution would you implement to ensure the software is regularly updated to mitigate phishing attacks?

a)

Email security program

b)

Patching

c)

Antivirus

d)

Secure DNS

35.

What is Vishing?

a)

A targeted attack directed at specific individuals or organizations

b)

Employ fraudulent text messages to deceive individuals

c)

Phishing using generative AI

d)

Use phone calls or voice messages to deceive individuals into divulging personal or sensitive information

36.

You are a cybersecurity analyst investigating a series of cyberattacks targeting critical infrastructure. You discover that a government entity sponsored the attacker. How would you categorize this threat actor?

a)

Insider threat actor

b)

Organized crime syndicate

c)

Script kiddie

d)

Nation-state actor

37.

A marketing manager at a clothing company accidentally leaves a document containing upcoming product designs on a public printer. A competitor’s employee later finds this document. What type of insider threat does this scenario represent?

a)

Malicious insider

b)

Professional insider

c)

Oblivious insider

d)

Negligent insider

38.

The product team is developing an AI assistant that will recommend purchases and answer customer queries on products. Why is it crucial to be aware of potential hallucinations?

a)

Prevents customers from receiving spam emails from the AI assistant

b)

Prevents deepfakes

c)

Prevents hackers from injucting malicious code into the AI assistant

d)

Ensures the assistant answers customet queries accurately

39.

As an engineering student who frequently communicates with peers through emails, what steps will you take to safeguard your system against malware?

a)

Use systems with suitable graphic processing units(GPUs)

b)

Learn about botnets

c)

Use system belonging to others

d)

Never download files directly

40.

While conducting malware analysis, you come across a suspicious program disguised as a legitimate application. What type of malware could this be?

a)

Keylogger

b)

Worm

c)

Bot

d)

Trojan

41.

Jane, an IT security analyst tasked with enhancing her company’s cybersecurity measures, is evaluating various strategies to detect and prevent malware attacks. Which preventive measure detects new, previously unknown malware by analyzing patterns and behaviors akin to known threats?

a)

Caution with email and downloads

b)

Heuristic analysis

c)

Strong and robust passwords

d)

Regular OS and software updates

42.

What is the primary purpose of Quad9?

a)

Adds an extra layer of security by requiring additional forms of authentication

b)

Safeguards users against malware and phishing threats

c)

Informs users about the possibility of spear-phishing attacks

d)

Enhances critical thinking skill

43.

Imagine you’re a cybersecurity analyst tasked with ensuring the security of your company’s Linux-based servers. Which tool would you use to mitigate malware attacks?

a)

Spyware

b)

Backdoors

c)

Keyloggers

d)

Rootkit hunter

44.

John, a delivery boy, needs to hand over a package at a secure facility. As he approaches the building, he notices an employee leaving. John strategically positions himself near the door and requests the employee to hold it open for him, pretending to struggle with a package. Which category of social engineering does this breach fall under?

a)

Shoulder surfing

b)

Whaling

c)

Tailgating

d)

Dumpster diving

45.

Emma just got a new phone number. Shortly afterward, she receives a text message that warns of a potential service interruption and instructs her to click a link to update her account details. The message uses informal language and does not address Emma by name. What type of phishing attack is Emma most likely experiencing?

a)

SEO poisoning

b)

Vishing

c)

Smishing

d)

Spoofing

46.

You’re responsible for enhancing security measures in a server room housing critical data and infrastructure. Which physical control measure will you implement to stop security breaches before they occur?

a)

Clear signage indicating surveillance and restricted access

b)

Keycard access systems

c)

Lockdown protocols

d)

CCTV surveillance systems

47.

Which security measure should you use to regulate who can view or utilize resources within a computing system?

a)

Encryption

b)

Patching

c)

Access controls

d)

System-level firewalls

48.

You work at an organization where employees regularly access sensitive data through various devices. They are concerned about cybersecurity threats and approach you for advice on securing their endpoints. Which of the following components is typically included in comprehensive endpoint security solutions?

a)

Network access controls(NACs)

b)

Antivirus software

c)

Instrusion detection and prevention system(IDPSs)

d)

Virtual private networks(VPNs)

49.

When should recurrent vulnerability scans ideally be scheduled to minimize disruption to the organization’s operations?

a)

During off-peak hours to avoid impacting productivity

b)

Right before the monthly IT maintenance window

c)

Randomly, to catch any time-based vulnerabilities

d)

During the busiest hours, to simulate an attack under load

50.

During the detection and analysis phase, the incident response (IR) team identifies a ransomware attack on a critical server. What immediate action must the team take to address this situation?

a)

Pay the ransom to regain access to the files quickly

b)

Attempt to remove the ransomware using antivirus software

c)

Disconnect the infected server the netwoks

d)

Perform complete system backup

51.

How does Wireshark offer visibility into specific network traffic details?

a)

Captures and interactively displays detailed networks traffic patterns

b)

Uses raw IP packets to identify devices available on the networks

c)

Enables administrators to identify the devices operating in their systems

d)

Represents network components and their interconnections

52.

An IT professional implements additional verification methods like multifactor authentication (MFA) to protect their network against unauthorized packet sniffing. What security strategy is the IT professional using?

a)

Strengthening login measures

b)

Navigating to HTTPS-secured websites

c)

Privately browsing woth a virtual private networks(VPN)

d)

Maintaining up-to-date systems

53.

True or False:

Passive sniffing involves manipulating network traffic to intercept data packets.

a)

True

b)

False

54.

What are the primary objectives of ingress filtering? Select two.

a)

Block access to unauthorized or potentially harmful data packets

b)

Scrutinize outgoing IP packets, verifying that they possess authentic source headers

c)

Scrutinize incoming IP packets

d)

Dater individuals inside the network from exporting spoofed packets

55.

You are a database administrator investigating a recent security breach that may have involved a structured query language (SQL) injection attack. Which consequence of an SQL injection attack involves manipulating access permissions in a database?

a)

Authorization loss

b)

Authentication compromise

c)

Integrity violation

d)

Confidentiality breach

56.

What is the primary objective of attackers using advanced persistent threats (APTs) in a cyberattack?

a)

Uncover information about the network's structure

b)

Move laterally within a network undetected and escalate privileges

c)

Prioritize target segments within a network

d)

Identify and troubleshoot network issues

57.

The primary purpose of packet sniffing is to ________________.

a)

Introduce harmful code into data streams using methods like SQL injection

b)

Disrupt networks operations and cause downtime

c)

Protect networks from unauthorized access

d)

Analyze data packets and diagnose network issues

58.

Imagine you’re on a familiar e-commerce website you’ve used securely before. While entering your contact details during checkout, you notice unusual text within the address field, like extra letters or symbols you didn’t type. What kind of attack could this be?

a)

Integrity violation

b)

Cross-site scripting(XSS) attack

c)

Structured auery language(SQL) injection attack

d)

Authorization loss

59.

Imagine you’re a security manager at a financial company. Recently, employees have been using personal email accounts for business communications, violating the company’s security policies. What type of controls should you implement to effectively discourage employees from using insecure methods for business communications?

a)

Detective controls

b)

Physical controls

c)

Deterrent controls

d)

Corrective controls

60.

Why is encryption considered one of the most secure ways to ensure data confidentiality?

a)

Inspects incoming and outgoing networks packets

b)

Converts information into a code obscuring the original content

c)

Acts as the first line of defense agains viruses and malware

d)

Fixes vulnerabilities and bugs and enhances functionality

61.

You are developing a banking application where users can input their financial data. How would you explain the use of input validation to ensure the security of sensitive information stored within the application’s database?

a)

Responds to errors

b)

Reduces code processing time

c)

Prevents attackers from injecting malicious code into the application

d)

Simplifies the debugging process for developers

62.

Which application security testing technique inspects the source code without executing the program?

a)

OpenVAS

b)

Interactive application security testing(IAST) tool

c)

Dynamic application security testing(DAST) tool

d)

Static application security testing(SAST) tool

63.

A large corporation with robust cybersecurity measures in place experiences a data breach caused by a phishing attack. The company activates its incident response (IR) team to contain the damage. What role will digital forensics play in the detection and analysis stage?

a)

Conduct a post-incident review to identify areas for improvement

b)

Provide tools and techniques to collect and analyze digital evidence

c)

Initiate legal proceedings against the attacker

d)

Document all actions

64.

Employees at a large financial organization are seeing unusual pop-up windows redirecting them to unfamiliar websites while working remotely. What type of security breach is the organization experiencing?

a)

Egress filtering

b)

Distributed denial-of-service(DDoS)

c)

Botnet infiltration

d)

Man-in-the middle attack

65.

Why do cybersecurity professionals combine security information and event management (SIEM) systems with security orchestration, automation, and response (SOAR) platforms?

a)

Prioritize alert management over incident response

b)

Automate the identification of sophisticated threats

c)

Streamline security operations in high-volume environments

d)

Increase the complexity of security operations

66.

As an IT consultant in a multinational organization, you manage user accounts on the company’s network, from account creation to deletion. Which identity and access management (IAM) component does this task fall under?

a)

Administration

b)

Authentication

c)

Authorization

d)

Audit

67.

You are a cybersecurity specialist implementing multifactor authentication (MFA) for your employees. What solution will you deploy for users to verify login attempts by approving notifications sent to their devices through an application?

a)

Mobile push notifications

b)

Security tokens

c)

Biometrical authentication

d)

Smart cards

68.

File access controls allow administrators to delegate authority to users, enabling them to dictate access permissions to various resources. Which file access control enables users to view file contents?

a)

Read permission

b)

Execute permission

c)

Write permission

d)

System permission

69.

An IT company wants to improve its security system. How can it establish digital identities and implement secure authentication using innovative access control methods?

a)

Geolocation and time-based restrictions

b)

Certificates

c)

Tokens

d)

Secure shell(SHH) keys

70.

What is the main advantage of Fast IDentity Online (FIDO) over traditional passwords?

a)

FIDO sends the secrets across the internet for authentication

b)

FIDO synchronizes secrets across multiple devices

c)

FIDO stores the secret on the user's device during authentication

d)

FIDO relies on password exchange for user authentication

71.

An unauthorized individual manages to access sensitive information that the organization has discarded. What kind of security threat is the organization facing?

a)

Taligating

b)

Unauthorized access

c)

Dumpster diving

d)

Vandalism

72.

You are a facilities manager tasked with enhancing the outdoor security measures of a high-profile government facility located in a densely populated area. What measure will you take to diminish the visibility of the infrastructure?

a)

Industrial camouflage

b)

Fences

c)

Lighting

d)

Cameras

73.

What outdoor security measure will you implement to discourage unauthorized access and guide behavior to ensure safety and protection for everyone in an office building?

a)

Signages

b)

Locks

c)

Alarm systems

d)

Access controls

74.

How can low temperatures impact an organization’s cybersecurity and physical infrastructure?

a)

Condensation

b)

Electrostatic discharge

c)

Overheating

d)

Corrosion

75.

You share workspace with colleagues from different departments. How can you limit the viewing angle and prevent visual hacking?

a)

Apply screen filters

b)

Use cable locks

c)

Use port locks

d)

Implement asset tags and tracking software

76.

You are responsible for managing user accounts and access permissions. Which of the following actions involves verifying if a staff member has the required permissions to do the action they are attempting?

a)

Authorization

b)

Identify management

c)

Deprovisioning

d)

Provisioning

77.

You’re a security consultant evaluating access control measures for your organization’s high-security research lab. Which authentication method involving unique behavioral and physical characteristics would you choose?

a)

One-time password(OTP)

b)

Remote user authentication

c)

Kerberos

d)

Biometric authentication

78.

As a systems administrator in the military, you oversee file permissions management. Which access control scheme should you use to ensure users cannot alter file access permissions or modify established security protocols?

a)

Role-based access control(RBAC)

b)

Rule-based access control(RBAC or RuBAC)

c)

Attribute-based access control(ABAC)

d)

Mandatory access control(MAC)

79.

Which access control method is equipped with chips to store credentials and perform cryptographic operations securely?

a)

Certificates

b)

Smart cards

c)

Secure shell(SHH) keys

d)

Tokens

80.

Ann, a software engineer, wants to implement multifactor authentication (MFA) to enhance system security. What factors should she consider integrating?

a)

Fingerprint and retina pattern

b)

Security question and password

c)

Password and PIN

d)

Iris scan and PIN

81.

Roy, a former employee, visits the organization to collect his settlement papers. He enters the building with a concealed camera on his backpack. What type of security threat does this action pose?

a)

Dumpster diving

b)

Surveillance

c)

Tailgating

d)

Unauthorized access

82.

Which of the following is an example of human vigilance?

a)

Surveillance cameras

b)

Motion sensor lights

c)

Vigilant receptionists

d)

Biometric readers

83.

Your organization is facing operational delays because of frequent power disruptions. How can you address this issue?

a)

Install climate control systems

b)

Use power surge protectors

c)

Implement electrostatic discharge(ESD) protection equipment

d)

Install backup power supplies

84.

In a government research laboratory, alarms are triggered whenever cattle graze close to the building walls, creating chaos. What security measures should be implemented to distinguish between harmless entities and potential threats?

a)

Robotic security guards

b)

Atrificial intelligence(AI) security systems

c)

Intelligent perimeter security systems

d)

Drone detection systems

85.

What outdoor security measure should you install to maintain a record of all entries and enable efficient permissions management?

a)

Signage

b)

Access control

c)

Cameras

d)

Alarms