wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Cybersecurity Core Functions-QUIZ

Total questions: 27

Worksheet time: 17mins

Name
Class
Date
1.

RESPONSE: What are the key steps in an effective response plan?

a)

Identify the threat, assess the impact, develop a strategy, implement the plan, review and revise

b)

Identify the threat, plan for impact, develop a strategy, implement the plan, review and revise

c)

Identify the threat, assess the impact, develop a strategy, implement the plan

d)

Identify the threat, assess the impact, develop a strategy, plan, review and revise

2.

IDENTITY: The five core functions of the NIST Cybersecurity Framework are:

a)

Prepare, Prevent, Respond, Mitigate, Restore

b)

Identify, Protect, Detect, Respond, Recover

c)

Plan, Execute, Monitor, Control, Close

d)

Assess, Implement, Evaluate, Report, Improve

3.

The purpose of a risk assessment in the Identify function is to:

a)

Identify potential risks and vulnerabilities.

b)

Identify who is responsible

c)

Recover from security breaches.

d)

Respond to security incidents.

4.

PROTECT: What are the key security measures in the Protect function of NIST?

a)

Access Control, Awareness and Training, Data Security, Information Protection Processes and Procedures, Maintenance, and Protective Technology

b)

Risk Assessment, Risk Management Strategy, Supply Chain Risk Management

c)

Protecting from Anomalies and Events, through Continuous Monitoring, Detection Processes

d)

Response Planning, Communications, Analysis, Mitigation, Improvements

5.

IDENTIFY: Why is asset management critical in the Identify function of NIST?

a)

Asset management helps in identifying and managing cybersecurity risks to systems, people, assets, data, and capabilities.

b)

Asset management is critical to the Recovery function of NIST.

c)

Asset management only deals with allocating financial assets properly

d)

Asset management is only about maintaining an monitoring the inventory of assets.

6.

The purpose of forensic analysis in the response process is to:

a)

usually useless to solving the problem

b)

Identify the cause of a security breach

c)

improve the ability to repel a similar future attack

d)

Improve the time it takes to shutdown a network.

7.

The primary goal of the Detect function in the NIST framework is to:

a)

Identify cybersecurity events in a timely manner

b)

Protect data from unauthorized access

c)

Respond to detected cybersecurity events

d)

Recover from cybersecurity incidents

8.

PROTECT: How does multi-factor authentication (MFA) contribute to the Protect function?

a)

By requiring biometric scans

b)

By providing an additional layer of security

c)

By frustrating the attacker

d)

By eliminating the need for passwords

9.

Continuous monitoring is important for cybersecurity because:

a)

it helps in early detection of threats and vulnerabilities.

b)

it reduces the need for cybersecurity professionals.

c)

it eliminates all cyber threats.

d)

it is a regulatory requirement only.

10.

RESPONSE: Why is it important to have a pre-defined communication plan in the Respond function?

a)

To allow for spontaneous decision-making

b)

To ensure clear and efficient communication during a response

c)

To increase the number of communication channels

d)

To reduce the need for training

11.

DETECT: What type of tools are commonly used in the Detect function?

a)

Network monitoring tools

b)

Data analysis tools

c)

Communication tools

d)

Project management tools

12.

PROTECT: The role of security awareness training in the Protect function is to:

a)

Enhance staff skills in identifying a hacking attempt

b)

Improve social engineering attempts

c)

Educate employees on security best practices

d)

Increase software efficiency

13.

The main activities in the Recover function of NIST are:

a)

Detecting and monitoring bad hombres

b)

Implementing security measures

c)

Planning and improving resilience and recovery

d)

Conducting regular audits

14.

RECOVER: A business continuity plan is important in cybersecurity recovery because it:

a)

ensures that critical business functions continue during and after a disaster.

b)

focuses solely on preventing cyber attacks.

c)

eliminates the need for cybersecurity measures.

d)

is only necessary for large corporations.

15.

Lessons that should be learned from a cybersecurity incident recovery include:

a)

Social Engineering is the number one reason for coporate data loss.

b)

Improving security protocols

c)

Training on how to respond to a cyber incident is vital to sucess.

d)

Continuous Training staff to identify social engineering patterns is a skill worth learning

16.

which three elements of a phishing attempt are correct

a)

Urgency

threat of access loss if you don't act

bad breath

b)

Your a winner!

unsolicited email

from another country

c)

Tells you to pick up your clothes

unusual time to receive an email

demanding tone

d)

asks you to update your personal infomation

threatens loss of access if you don't act

requests you to click or open an attachment

17.

What is an Intrusion Detection System (IDS) used for?

a)

Blocking malware in emails

b)

Detecting and monitoring suspicious network activity

c)

Creating backup copies of data

d)

Preventing unauthorized software downloads

18.

Why are data backups important in cybersecurity?

a)

They prevent cyberattacks from happening

b)

They allow recovery of lost or encrypted data after a cyberattack

c)

They make sharing sensitive data safer

d)

hey are only useful for legal compliance

19.

What is the NIST and ED Law 2d standard for employee access to sensitive data?

a)

Education level determines access to sensitive data.

b)

The level of sensitive data access is strictly determined by required job duties

c)

Access to sensitive data is determined by Department Heads

d)

Access to sensitive data access should be determined based on every possible scenario I may need

20.

What role does a Security Information and Event Management (SIEM) system play?

Get it right and gain 10 points!

(a)  

21.

What is business continuity planning (BCP)? Get it right and get 10 points!

(a)  

22.

What is the purpose of an incident response plan?

(a)  

23.

What is endpoint security?

(a)  

24.

What should be included in an incident report?

a)

Type of vulnerability

what happened

why it happened

whose in trouble

b)

Type of incident, affected systems, timeline, actions taken, and recommendations

c)

The people involved

The amount of money paid

The time we were down

The lost revenue

d)

Type of Incident

affected people

actions considered

people contacted

25.

What is the difference between a vulnerability and a threat?

Get it right get 10 points!

(a)  

26.

What is behavioral analysis in cybersecurity?

a)

A process for scheduling system updates

b)

A subtle way to train employees on company policies

c)

A systematic process of randomly sampling network user activity for anomalies

d)

A software/Hardware that can detect when a user or device is acting outside standard benchmarks

27.

What is the purpose of a risk assessment?

a)

To identify critical finance platforms, assess and report on corporate ability to repel and recover from a cyber attack

b)

To keep the auditors happy and off my back

c)

To assess and protect critical business platfroms with a super backup solution

d)

To determine where a corporations risk is and steps they can take to mitigate those risks