Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Control Types Quiz

Total questions: 98

Worksheet time: 49mins

Name
Class
Date
1.

Which of the following is an example of a technical control?

a)

Firewalls

b)

Risk assessments

c)

Incident response

d)

Locks

2.

What type of control involves high-level policy and decision making?

a)

Technical Controls

b)

Managerial Controls

c)

Operational Controls

d)

Physical Controls

3.

Which control type is designed to detect and report events?

a)

Preventive Controls

b)

Detective Controls

c)

Corrective Controls

d)

Compensating Controls

4.

What is an example of a compensating control?

a)

Firewalls

b)

Security cameras

c)

Patches

d)

Using a camera system when no physical guards exist

5.

Which control category focuses on day-to-day operational activities?

a)

Technical Controls

b)

Managerial Controls

c)

Operational Controls

d)

Physical Controls

6.

What is the primary purpose of deterrent controls in security?

a)

Enforce expected behaviors

b)

Deter attacks

c)

Grant permissions

d)

Track user actions

7.

Which of the following is an example of directive controls?

a)

Surveillance cameras

b)

Acceptable Use Policies (AUP)

c)

Firewalls

d)

Encryption

8.

What does confidentiality in core security concepts aim to prevent?

a)

Unauthorized access to information

b)

Unauthorized changes to information

c)

Unauthorized user actions

d)

Unauthorized identity verification

9.

In the AAA framework, what is the role of authentication?

a)

Granting permission

b)

Verifying identity

c)

Tracking user actions

d)

Enforcing policies

10.

What is the main focus of a gap analysis in security?

a)

Continuous verification

b)

Identifying differences between current and desired states

c)

Adaptive identity validation

d)

Enforcing expected behaviors

11.

What is the purpose of bollards in physical security?

a)

To provide lighting in dark areas

b)

To block vehicle entry

c)

To detect motion using microwaves

d)

To monitor CCTV footage

12.

Which type of sensor is used for heat detection?

a)

Pressure

b)

Infrared

c)

Microwave

d)

Ultrasonic

13.

What is the role of access control vestibules in security?

a)

To provide identity credentials

b)

To control entry using mantraps

c)

To deter crime with bright areas

d)

To monitor with CCTV

14.

How do ultrasonic sensors contribute to security?

a)

By detecting weight changes

b)

By detecting motion using high-frequency sound

c)

By providing identity credentials

d)

By blocking vehicle entry

15.

What is eliminated in the data plane of Zero Trust architecture?

a)

Policy-driven access decisions

b)

Implicit trust zones

c)

Threat surface reduction

d)

Identity credentials

16.

What is a honeypot used for in cybersecurity?

a)

To store sensitive data securely

b)

To lure attackers with a fake system

c)

To encrypt data transmissions

d)

To monitor network traffic

17.

Which of the following is a network of honeypots?

a)

Honey file

b)

Honeytoken

c)

Honeynet

d)

Firewall

18.

What is the primary purpose of change management in IT?

a)

To increase system complexity

b)

To prevent unexpected downtime

c)

To reduce employee workload

d)

To enhance user interface design

19.

Which key element of change management involves planning to reverse changes if needed?

a)

Approval Process

b)

Impact Analysis

c)

Backout Plan

d)

Maintenance Window

20.

What is the role of allow lists/deny lists in technical implications?

a)

To enhance user experience

b)

To restrict what can/can't run

c)

To improve system aesthetics

d)

To increase data storage capacity

21.

What is the purpose of downtime planning in system management?

a)

To enhance software features

b)

To account for system interruptions

c)

To increase network speed

d)

To reduce hardware costs

22.

Which of the following is required after updates in system management?

a)

Data backup

b)

Service/Application Restarts

c)

User training

d)

Hardware replacement

23.

What is a characteristic of a public key in Public Key Infrastructure (PKI)?

a)

Kept secret

b)

Shared with everyone

c)

Used for encryption only

d)

Held by a third party

24.

In Public Key Infrastructure (PKI), what is the role of key escrow?

a)

Encrypts data

b)

Decrypts data

c)

Third party holds a backup key

d)

Generates public keys

25.

Which of the following is not an encryption level mentioned in the document?

a)

Full disk

b)

Partition

c)

File

d)

Network

26.

What is the primary purpose of transport encryption?

a)

Secure data at rest

b)

Secure data in motion

c)

Encrypt database records

d)

Encrypt hardware components

27.

Which type of encryption uses two keys, one for encryption and one for decryption?

a)

Symmetric Encryption

b)

Asymmetric Encryption

c)

Transport Encryption

d)

Key Exchange Protocols

28.

What is an example of symmetric encryption?

a)

RSA

b)

ECC

c)

AES

d)

TLS

29.

What is the role of a Trusted Platform Module (TPM)?

a)

Encrypt data in motion

b)

Secure crypto processor on motherboard

c)

Store symmetric keys

d)

Perform key exchange

30.

Which of the following is a key exchange protocol?

a)

AES

b)

Diffie-Hellman

c)

RSA

d)

ECC

31.

What is the primary function of a Key Management System?

a)

To encrypt data

b)

To manage keys throughout their lifecycle

c)

To store passwords

d)

To generate random numbers

32.

Which cryptographic technique involves hiding data inside other files?

a)

Tokenization

b)

Data Masking

c)

Steganography

d)

Hashing

33.

What is the purpose of salting in cryptography?

a)

To encrypt data

b)

To add random data to input before hashing

c)

To replace sensitive data with non-sensitive equivalents

d)

To verify sender and data integrity

34.

What does a Certificate Authority (CA) do?

a)

Encrypts data

b)

Issues and manages certificates

c)

Validates passwords

d)

Hides data inside other files

35.

What is the role of a Root of Trust in cryptographic systems?

a)

To encrypt data

b)

To establish trust starting with a root CA

c)

To hide parts of sensitive data

d)

To produce a fixed-size digest of data

36.

What is the purpose of a Certificate Signing Request (CSR)?

a)

To secure all subdomains

b)

To request a certificate

c)

To revoke a certificate

d)

To encrypt data

37.

Which type of threat actor is typically government-sponsored and focuses on espionage or disruption?

a)

Hacktivist

b)

Insider Threat

c)

Nation-State

d)

Organized Crime

38.

What is a characteristic of an Unskilled Attacker, also known as a Script Kiddie?

a)

Uses sophisticated tools

b)

Motivated by political causes

c)

Uses existing tools without understanding

d)

Seeks financial profit

39.

Which attribute of threat actors involves insider versus outsider origin?

a)

Resources/Funding

b)

Internal vs. External

c)

Sophistication/Capability

d)

Motivations

40.

What is the primary goal of data exfiltration?

a)

Gathering intelligence

b)

Stealing sensitive information

c)

Denial-of-service attacks

d)

Hacktivism

41.

Which of the following is an example of a message-based threat?

a)

Phishing emails

b)

Denial-of-service attacks

c)

Hacktivism

d)

Cyberwarfare

42.

What is the main purpose of espionage in cybersecurity?

a)

To cause instability

b)

To gather intelligence

c)

To steal money

d)

To expose for ransom

43.

What type of attack involves threatening exposure for ransom?

a)

Espionage

b)

Blackmail

c)

Ethical hacking

d)

Chaos/Disruption

44.

What is "smishing" primarily associated with?

a)

Email

b)

Short Message Service (SMS)

c)

Instant Messaging (IM)

d)

Social media

45.

Which type of threat involves embedding malicious code inside images?

a)

File-Based Threats

b)

Image-Based Threats

c)

Voice Call Threats

d)

Open Service Ports

46.

What is an example of a file-based threat?

a)

USB drives loaded with malware

b)

Executable files (.exe)

c)

Open Wi-Fi networks

d)

Unsupported Linux distros

47.

What does "vishing" refer to in the context of voice call threats?

a)

Embedding code in images

b)

Voice phishing to extract information

c)

Using USB drives for attacks

d)

Exploiting open service ports

48.

Which of the following is a vulnerability associated with removable devices?

a)

Steganography attacks

b)

USB drop attacks

c)

Bluejacking

d)

Malicious PDFs

49.

What is a characteristic of unsecure wireless networks?

a)

No WPA2/WPA3 protection

b)

Poor physical security

c)

Unsupported Linux distros

d)

Malicious macros

50.

What is a common risk associated with leaving unnecessary ports open, such as telnet or FTP?

a)

Increased network speed

b)

Enhanced data encryption

c)

Vulnerability to unauthorized access

d)

Improved firewall protection

51.

What are default credentials typically associated with?

a)

Custom security settings

b)

Factory default usernames/passwords

c)

Advanced encryption methods

d)

User-defined passwords

52.

Which of the following is an example of a supply chain attack?

a)

Phishing emails

b)

Compromising Managed Service Providers (MSPs)

c)

Using strong passwords

d)

Installing antivirus software

53.

What is the primary goal of phishing attacks?

a)

To improve network speed

b)

To ask for credentials through deceptive emails

c)

To enhance data encryption

d)

To provide technical support

54.

What does the term "vishing" refer to?

a)

Email scams

b)

Fraudulent phone calls

c)

SMS text scams

d)

Fake websites

55.

What is the purpose of a watering hole attack?

a)

To improve website performance

b)

To infect a site commonly visited by the target

c)

To enhance user experience

d)

To provide free software updates

56.

Which of the following is an example of a physical attack surface?

a)

Open Wi-Fi

b)

Unlocked server rooms

c)

Poorly coded web apps

d)

Untrained employees

57.

What is typo squatting?

a)

A type of phishing scam

b)

Registering domains similar to legitimate ones

c)

Exposing network ports

d)

Using outdated software versions

58.

How can attack surfaces grow?

a)

By using strong passwords

b)

Through cloud services and IoT devices

c)

By updating software regularly

d)

By training employees

59.

Which of the following is a network attack surface?

a)

Vulnerable IoT devices

b)

Exposed APIs

c)

Untrained employees

d)

Lack of change management

60.

What is a Memory Injection attack?

a)

An attack that manipulates memory during program execution.

b)

An attack that injects SQL statements into databases.

c)

An attack that changes the state of a system before use.

d)

An attack that injects scripts into web pages.

61.

Which of the following describes a Buffer Overflow?

a)

Injecting scripts into web pages.

b)

Excess data overflowing into adjacent memory.

c)

Changing a state before it is used.

d)

Injecting SQL statements into databases.

62.

What is a Time-of-Check (TOC) vulnerability?

a)

An attack that occurs between the check and use of a resource.

b)

A state that is verified but changed before use.

c)

An attack that injects SQL statements into databases.

d)

An attack that manipulates memory during execution.

63.

What is SQL Injection (SQLi)?

a)

Injecting malicious scripts into web pages.

b)

Injecting malicious SQL statements into input fields.

c)

Manipulating memory during program execution.

d)

Changing a state before it is used.

64.

What is Cross-Site Scripting (XSS)?

a)

An attack that manipulates memory during execution.

b)

An attack that injects SQL statements into databases.

c)

An attack that injects malicious scripts into web pages.

d)

An attack that changes a state before it is used.

65.

What is a potential risk associated with firmware vulnerabilities?

a)

They can be easily updated by users.

b)

They are immune to attacks if not patched.

c)

They can be attacked if not patched.

d)

They are only a concern for software developers.

66.

What does "End-of-Life (EOL) Devices" refer to?

a)

Devices that are newly released.

b)

Devices that are no longer supported or patched by vendors.

c)

Devices that are immune to modern threats.

d)

Devices that are only used in legacy systems.

67.

What is a VM Escape in virtualization vulnerabilities?

a)

A VM that runs without any issues.

b)

Malicious code running in a VM breaks out to attack the host machine.

c)

A VM that is immune to attacks.

d)

A VM that is properly isolated from the host machine.

68.

What is a common issue with cloud-specific vulnerabilities?

a)

Perfectly configured cloud storage.

b)

Insecure APIs.

c)

Strong identity and access management controls.

d)

Fully secure cloud environments.

69.

What is a service provider risk in supply chain vulnerabilities?

a)

Cloud providers ensuring perfect security.

b)

Hosting companies mishandling security.

c)

Service providers offering free services.

d)

Vendors providing regular updates.

70.

What is a potential risk associated with hardware providers?

a)

Malicious components inserted into motherboards, network cards

b)

Libraries, updates infected at the source

c)

Weak algorithms like MD5, SHA-1

d)

Publicly exposed data due to misconfigured cloud services

71.

Which of the following is an example of a cryptographic vulnerability?

a)

Side loading apps from official stores

b)

Predictable random number generation

c)

Removing device restrictions

d)

No patch available yet

72.

What does "jailbreaking" a mobile device involve?

a)

Installing apps from official stores

b)

Removing device restrictions, exposing users to security threats

c)

Updating the device's operating system

d)

Encrypting the device's data

73.

What characterizes a zero-day vulnerability?

a)

Known to vendors and users before exploitation

b)

No patch available yet

c)

Strong encryption methods

d)

Secure cloud configurations

74.

What is a characteristic of ransomware?

a)

Unauthorized data collection

b)

Systems locked, ransom notes, encrypted file extensions

c)

Legit-looking software that performs malicious actions

d)

Rapid self-replication across networks

75.

Which type of malware is known for rapid self-replication across networks?

a)

Spyware

b)

Trojan Horse

c)

Worm

d)

Keylogger

76.

What does a keylogger do?

a)

Hides the presence of malware

b)

Monitors keystrokes and may cause unusual login behavior

c)

Triggers malicious code on specific dates

d)

Slows down devices with unwanted programs

77.

Which attack indicator involves multiple login failures and account lockouts?

a)

RFID Cloning

b)

Brute Force Attacks

c)

Environmental Disruptions

d)

Distributed Denial-of-Service (DDoS)

78.

What is the main purpose of a rootkit?

a)

To encrypt files and demand ransom

b)

To hide the presence of malware

c)

To replicate rapidly across networks

d)

To monitor keystrokes

79.

What is an Amplified DDoS attack?

a)

A small request triggers massive responses.

b)

Attack appears to originate from legitimate sources.

c)

Data interception between sender and receiver.

d)

Reusing stolen credentials to gain unauthorized access.

80.

Which type of attack involves DNS cache poisoning?

a)

Wireless Attacks

b)

DNS Attacks

c)

Buffer Overflows

d)

Replay Attacks

81.

What is a characteristic of a Reflected DDoS attack?

a)

Attack appears to originate from legitimate sources.

b)

Evil twin access points.

c)

SQLi attempts visible in logs.

d)

Malware spreading across systems.

82.

Which attack involves data interception between sender and receiver?

a)

On-Path Attacks (Man-in-the-Middle)

b)

Buffer Overflows

c)

Injection Attacks

d)

Replay Attacks

83.

What is a common indicator of a Buffer Overflow?

a)

Crashes, unusual application behavior.

b)

Captured valid data resent to mimic legitimate access.

c)

DNS tunneling.

d)

Rogue hotspots.

84.

What is a common indicator of privilege escalation?

a)

Access to unintended files

b)

Unusual user permission changes

c)

Forcing weaker encryption

d)

Single passwords tried across many users

85.

Which attack involves two different inputs producing the same hash?

a)

Downgrade Attack

b)

Password Spraying

c)

Collision Attack

d)

Account Lockout

86.

What is a characteristic of a brute force password attack?

a)

Forcing weaker encryption

b)

Systematic password guessing until access is gained

c)

Exploiting hash collisions

d)

Access to unintended files

87.

What does a downgrade attack typically involve?

a)

Exploiting hash collisions

b)

Forcing weaker encryption during handshake processes

c)

Single passwords tried across many users

d)

Unusual user permission changes

88.

What is an indicator of concurrent session usage?

a)

Sudden lockout due to too many login attempts

b)

Same account active in multiple locations

c)

Users reporting denied access to legitimate resources

d)

Systematic password guessing

89.

What is an example of an "Impossible Travel Event" in cybersecurity?

a)

Logins from geographically impossible locations

b)

CPU usage abnormally high

c)

Systems becoming unresponsive

d)

Unexpected timestamps in logs

90.

Which of the following describes "Resource Consumption Spikes"?

a)

Systems becoming unresponsive

b)

CPU/memory/network usage abnormally high

c)

Deletion of log files

d)

Unexpected system activity

91.

What is the purpose of dividing networks into smaller segments?

a)

To increase network speed

b)

To limit attacker movement

c)

To reduce hardware costs

d)

To simplify network management

92.

What do Access Control Lists (ACLs) specify in a network?

a)

Network speed

b)

Who can access what

c)

Hardware requirements

d)

Software updates

93.

What is the function of Application Allow Lists?

a)

To allow all applications to run

b)

To block unknown or malicious programs

c)

To increase application speed

d)

To reduce application size

94.

What is the purpose of using sandbox environments for suspicious apps?

a)

To enhance app performance

b)

To test app functionality

c)

To isolate and analyze potential threats

d)

To improve user interface

95.

Why is it critical to maintain current security patches?

a)

To increase software speed

b)

To fix vulnerabilities and enhance security

c)

To add new features

d)

To reduce software size

96.

What is the role of encryption in data security?

a)

To compress data for storage

b)

To enhance data readability

c)

To protect data at rest, in transit, and in use

d)

To increase data transfer speed

97.

How does the principle of least privilege help in security?

a)

By granting all users full access

b)

By reducing the impact of compromised accounts

c)

By increasing system complexity

d)

By allowing unrestricted data sharing

98.

What is the purpose of configuration management tools like Chef and Puppet?

a)

To design user interfaces

b)

To enforce secure settings across systems

c)

To develop mobile applications

d)

To manage network traffic