wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

CyberSecurity Training-Quiz

Total questions: 19

Worksheet time: 10mins

Name
Class
Date
1.

INCIDENCE RESPONSE PROCESS: What is the first step in the incident response process?

a)

Preparation

b)

Identification

c)

Containment

d)

Eradication

2.

A company detects unusual outbound network traffic that could indicate data exfiltration. What should be done next?

a)

Identify and confirm the incident by analyzing logs and alerts.

b)

Ignore the traffic as it might be a false alarm.

c)

Immediately shut down all network operations.

d)

Contact the internet service provider to block the traffic.

3.

Employees report receiving emails from a compromised internal account requesting sensitive data. What should be done next?

a)

Yes, because it indicates a potential account takeover and requires immediate containment.

b)

No, because it might be a false alarm and can be ignored.

c)

Yes, because it is a common occurrence and does not require immediate action.

d)

No, because it is not related to cybersecurity threats.

4.

INCIDENCE RESPONSE PROCESS Scenario: A ransomware infection has locked multiple workstations. The IT team is unsure whether to shut down affected systems. What should they do?

a)

Shut down the affected systems immediately.

b)

Disconnect the affected systems from the network.

c)

Wait for instructions from higher authorities.

d)

Attempt to decrypt the files themselves.

5.

Scenario: A malware outbreak spreads across the network. What actions should be taken?

a)

Isolate affected systems and update antivirus software.

b)

Ignore the outbreak and continue normal operations.

c)

Unplug all network cables immediately.

d)

Contact the media to report the outbreak.

6.

INCIDENCE RESPONSE PROCESS Containment and Mitigation Scenario: A phishing attack compromised employee credentials. The attacker is attempting to access sensitive data. What should be done?

a)

Notify the IT department and change all passwords immediately.

b)

Ignore the attack and continue working.

c)

Share credentials with the attacker to monitor their actions.

d)

Wait for the attacker to make the next move.

7.

Scenario: The IT team detects unauthorized administrative access on a critical server. What steps should be taken?

a)

Investigate the source of access and revoke permissions

b)

Ignore the access as it might be a false alarm

c)

Immediately shut down the server

d)

Notify all users about the breach

8.

After a successful incident containment, what should be done next?

a)

Reimage infected systems and update security patches to prevent reinfection.

b)

Document the incident and lessons learned.

c)

Ignore the incident and move on.

d)

Notify the media about the incident.

9.

A cyberattack exploited a known vulnerability. What steps should be taken?

a)

Patch the vulnerability, enhance monitoring, and update access controls.

b)

Ignore the vulnerability and hope it doesn't happen again.

c)

Only update access controls without patching.

d)

Enhance monitoring but leave the vulnerability unpatched.

10.

Handling Critical Escalations: A data breach affecting customer records is confirmed. What actions should be taken?

a)

Notify affected customers and authorities immediately.

b)

Ignore the breach and continue operations.

c)

Delete all customer records to prevent further issues.

d)

Wait for further instructions from management.

11.

A company recovers from a data breach but wants to prevent future incidents. What should they do?

a)

Conduct a post-mortem analysis, update policies, and improve employee training.

b)

Ignore the incident and continue as usual.

c)

Only focus on updating software without training employees.

d)

Blame employees without changing any policies.

12.

A user reports their account being locked out multiple times, but IT sees no signs of brute-force attempts. Is this a cause for concern?

a)

Yes

b)

No

13.

Scenario: The security team detects a small number of failed logins from an overseas location. What should be the next step?

a)

Investigate the source of the failed logins

b)

Ignore the failed logins

c)

Block the overseas IP address

d)

Notify the user of the failed logins

14.

Scenario: A phishing email is reported, but only one employee received it. What should be the next step?

a)

Ignore the email since only one employee received it

b)

Investigate the email to ensure it is not part of a larger attack

c)

Delete the email immediately without further action

d)

Forward the email to all employees as a warning

15.

Scenario: A department reports repeated malware infections on different machines. What should be the next step?

a)

Conduct a full system scan on all machines

b)

Ignore the issue and monitor the situation

c)

Reinstall the operating system on all machines

d)

Disconnect the affected machines from the network

16.

Scenario: A suspected insider threat is exfiltrating sensitive documents. What should be the next step?

a)

Monitor the employee's activities closely

b)

Immediately terminate the employee

c)

Report to the authorities

d)

Conduct a thorough investigation

17.

Determining Escalation Paths: A third-party vendor informs the company of a possible data exposure but provides limited details. What should be the next step?

a)

Investigate the data exposure internally

b)

Ignore the vendor's information

c)

Immediately inform all customers

d)

Wait for more details from the vendor

18.

Handling Critical Escalations: IT discovers that an active attacker has gained administrator access to key servers. What should be done in this situation?

a)

Immediately revoke the attacker's access and investigate the breach

b)

Monitor the attacker's activities for further information

c)

Ignore the situation and hope it resolves itself

d)

Inform the attacker that they have been detected

19.

Scenario: Ransomware has locked critical systems, and the attacker demands immediate payment. Who should be involved in handling this critical escalation?

a)

IT Security Team

b)

Finance Department

c)

Legal Team

d)

All of the above