Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Cyber Challenge Final Round

Total questions: 30

Worksheet time: 5mins

Name
Class
Date
1.

What is the primary purpose of a "canary" in cybersecurity?

a)

To detect SQL injection attempts

b)

To serve as a decoy for attackers (honeypot)

c)

To monitor memory corruption in stack-based buffer overflows

d)

To encrypt sensitive data in transit

2.

Which of the following is NOT a common use of steganography?

a)

Hiding malware in image files

b)

Concealing data within DNS queries

c)

Encrypting emails with PGP

d)

Embedding secret messages in audio files

3.

In Linux, what does the command chmod 4755 set on a file?

a)

Read, write, execute for owner; read & execute for group/others

b)

Read, write, execute for owner; SUID bit set

c)

Full permissions for owner, read-only for others

d)

SUID bit with execute permissions for all

4.

Which attack exploits the race condition between checking and using a resource?

a)

XSS

b)

TOCTOU

c)

CSRF

d)

ARP poisoning

5.

What does the term "Living Off the Land" (LOTL) refer to in cybersecurity?

a)

Using cloud services for anonymity

b)

Attackers using legitimate system tools for malicious purposes

c)

Harvesting credentials from phishing sites

d)

Exploiting zero-day vulnerabilities

6.

Which Linux command lists all open files and the processes using them?

a)

netstat -tuln

b)

lsof

c)

ps aux

d)

ss -a

7.

What is the main risk of a "Pass-the-Hash" attack?

a)

Brute-forcing password hashes offline

b)

Bypassing authentication using stolen hash values

c)

Exploiting weak hash algorithms like MD5

d)

Intercepting hashes in transit

8.

Which of the following is NOT a valid method to prevent CSRF attacks?

a)

Using SameSite cookies

b)

Implementing CAPTCHAs

c)

Adding CSRF tokens

d)

Disabling JavaScript

9.

What does the Linux command grep -r "password" /etc/ do?

a)

Searches for the word "password" recursively in /etc/

b)

Replaces "password" with "********" in /etc/

c)

Lists all files in /etc/ containing passwords

d)

Encrypts passwords in /etc/shadow

10.

Which cryptographic attack exploits small differences in encryption time?

a)

Birthday attack

b)

Timing attack

c)

Rainbow table attack

d)

Meet-in-the-middle attack

11.

What is the primary purpose of SELinux in Linux?

a)

To block all incoming network traffic

b)

To enforce mandatory access control (MAC) policies

c)

To encrypt filesystem data

d)

To prevent buffer overflow attacks

12.

Which protocol is most vulnerable to "Downgrade Attacks"?

a)

SSH

b)

TLS

c)

IPsec

d)

DNSSEC

13.

What does the Linux command iptables -A INPUT -p tcp --dport 22 -j DROP do?

a)

Allows SSH traffic on port 22

b)

Blocks all incoming SSH connections

c)

Logs SSH connection attempts

d)

Redirects port 22 traffic

14.

Which of the following is NOT a side-channel attack?

a)

Spectre

b)

Meltdown

c)

Heartbleed

d)

Rowhammer

15.

What is the main purpose of a "Nonce" in cryptography?

a)

To ensure data integrity

b)

To prevent replay attacks

c)

To generate random keys

d)

To encrypt large files

16.

Which Linux file contains encrypted password hashes?

a)

/etc/passwd

b)

/etc/shadow

c)

/etc/group

d)

/etc/security

17.

What does the command netcat -lvp 4444 do?

a)

Starts a reverse shell listener

b)

Scans open ports on a remote host

c)

Encrypts traffic on port 4444

d)

Blocks incoming connections on port 4444

18.

Which Linux tool is used for auditing file integrity?

a)

tripwire

b)

snort

c)

nmap

d)

metasploit

19.

What is the purpose of sudo visudo?

a)

To edit the sudoers file safely

b)

To escalate privileges without a password

c)

To disable sudo access for all users

d)

To log all sudo commands

20.

Which Linux command displays kernel-level process activity?

a)

top

b)

htop

c)

dmesg

d)

strace

21.

What attack abuses DNS to redirect traffic to malicious servers?

a)

DNS tunneling

b)

DNS spoofing

c)

DNS amplification

d)

DNSSEC hijacking

22.

Which encryption mode is vulnerable to "Padding Oracle Attacks"?

a)

AES-GCM

b)

RSA-OAEP

c)

CBC

d)

ECDSA

23.

What is the primary risk of "Kerberoasting"?

a)

Exploiting weak Kerberos TGTs

b)

Stealing service account password hashes

c)

Bypassing MFA in Active Directory

d)

Spoofing Kerberos tickets

24.

Which tool is used for network traffic analysis and packet sniffing?

a)

Burp Suite

b)

Wireshark

c)

Nmap

d)

John the Ripper

25.

What does "RAID 1" provide in terms of security?

a)

Data striping for performance

b)

Disk mirroring for redundancy

c)

Parity-based error correction

d)

Encryption at rest

26.

Which vulnerability allows attackers to inject malicious scripts into trusted websites?

a)

CSRF

b)

SSRF

c)

XSS

d)

RCE

27.

What is the main purpose of "Shodan"?

a)

Password cracking

b)

Searching for vulnerable IoT devices

c)

Encrypting network traffic

d)

Detecting malware signatures

28.

Which attack involves forcing a system to downgrade its security protocols?

a)

FREAK attack

b)

BEAST attack

c)

POODLE attack

d)

CRIME attack

29.

What does "ASLR" protect against?

a)

Buffer overflow exploits

b)

Phishing attacks

c)

Man-in-the-middle attacks

d)

SQL injection

30.

Which of the following is NOT a valid OWASP Top 10 vulnerability?

a)

Insecure Deserialization

b)

XML External Entities (XXE)

c)

ARP Spoofing

d)

Broken Access Control