Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Kiberbiztonsag alapjai 4

Total questions: 97

Worksheet time: 49mins

Name
Class
Date
1.

What is the main goal of patching in the SDLC?

a)

To add new features

b)

To fix security vulnerabilities

c)

To improve UI

d)

To reduce code size

2.

What is the impact of the Log4Shell vulnerability?

a)

Slower logging

b)

Remote code execution in millions of applications

c)

Memory leaks

d)

SQL injection

3.

What is the CVSS score of the Log4Shell vulnerability?

a)

5.0

b)

7.5

c)

9.0

d)

10.0

4.

What is the main risk of insecure deserialization?

a)

Data loss

b)

Remote code execution

c)

Memory leaks

d)

SQL injection

5.

What is the purpose of monitoring in the SDLC?

a)

To test performance

b)

To detect and respond to security incidents

c)

To encrypt logs

d)

To compile code

6.

What makes mobile devices particularly attractive targets for attackers?

a)

They are rarely used

b)

They store minimal personal data

c)

They contain a wealth of sensitive personal information

d)

They are not connected to the internet

7.

What was the first known mobile malware?

a)

Pegasus

b)

FluBot

c)

Cabir

d)

Zeus

8.

What is a key risk of using public Wi-Fi networks?

a)

Faster speeds

b)

Man-in-the-middle attacks

c)

Better encryption

d)

Reduced latency

9.

What is a “zero-click” exploit, as seen in Pegasus spyware?

a)

Requires user to click a malicious link

b)

Requires physical access to the device

c)

Exploits vulnerabilities without user interaction

d)

Only affects Android devices

10.

What is the main benefit of biometric authentication?

a)

It is always more secure than passwords

b)

It replaces encryption

c)

It offers fast and user-friendly authentication

d)

It stores data in the cloud

11.

What is the purpose of the secure boot process?

a)

To speed up device startup

b)

To encrypt user data

c)

To verify each stage of the boot chain and prevent tampering

d)

To allow app installation

12.

What is a key difference between full disk encryption and file-based encryption?

a)

Full disk encryption is faster

b)

File-based encryption allows more granular access control

c)

File-based encryption is less secure

d)

Full disk encryption uses multiple keys

13.

What is a major limitation of VPNs?

a)

They encrypt all traffic

b)

They prevent fingerprinting

c)

They can be slow and require trust in the provider

d)

They are free and unlimited

14.

What is a common attack on mobile networks like 2G and 3G?

a)

SQL injection

b)

IMSI catching and downgrade attacks

c)

Cross-site scripting

d)

DNS spoofing

15.

What is the main goal of app sandboxing?

a)

To improve app performance

b)

To isolate apps and limit their access to system resources

c)

To allow background services

d)

To enable root access

16.

What is a key security feature of modern Android and iOS systems?

a)

Open bootloaders

b)

Side-loading by default

c)

Runtime permissions and app signing

d)

No encryption

17.

What is a major risk of granting accessibility permissions to apps?

a)

They can access the camera

b)

They can bypass biometric authentication

c)

They can control the device and steal data

d)

They can disable encryption

18.

What is the main purpose of secure enclaves in mobile hardware?

a)

To store photos

b)

To run apps faster

c)

To securely store biometric data and cryptographic keys

d)

To manage network connections

19.

What is a key takeaway from the FluBot malware case?

a)

SMS is a secure communication method

b)

Accessibility permissions are harmless

c)

Malware can spread via contact lists and steal banking data

d)

Android is immune to malware

20.

What is a common feature of secure mobile operating systems like GrapheneOS?

a)

No app permissions

b)

Enhanced privacy and hardened security

c)

No encryption

d)

Unlimited root access

21.

What is the main purpose of app permissions?

a)

To allow all apps to access everything

b)

To restrict app access to sensitive data and features

c)

To improve app speed

d)

To enable background updates

22.

What is a key difference between Android and iOS in terms of app distribution?

a)

Android only allows apps from the Play Store

b)

iOS allows side-loading by default

c)

Android supports side-loading; iOS uses a stricter app review process

d)

iOS has no app sandboxing

23.

What is the main security concern with free VPNs?

a)

They are too fast

b)

They may sell user data

c)

They encrypt too much traffic

d)

They block HTTPS

24.

What is the role of hardware-backed keys in mobile security?

a)

To store passwords in RAM

b)

To enable faster boot times

c)

To securely store cryptographic keys in hardware

d)

To allow app updates

25.

What is the best practice regarding app permissions?

a)

Grant all permissions by default

b)

Disable all permissions

c)

Request only the minimum necessary

26.

What is the best practice regarding app permissions?

a)

Grant all permissions by default

b)

Disable all permissions

c)

Request only the minimum necessary and explain why

d)

Use root access to manage permissions

27.

What is the main security risk of side-loading apps on Android?

a)

Reduced performance

b)

Exposure to unverified and potentially malicious apps

c)

Slower updates

d)

Increased battery usage

28.

What is a key limitation of biometric authentication?

a)

It is always more secure than passwords

b)

It can’t be used on Android

c)

It may lack recovery options if compromised

d)

It stores data in the cloud

29.

What is the function of the “chain of trust” in secure boot?

a)

To allow faster app loading

b)

To verify each boot stage using cryptographic signatures

c)

To encrypt user data

d)

To enable root access

30.

What is the main reason 2G networks are considered insecure?

a)

They use AES encryption

b)

They support VPNs

c)

They lack proper network authentication and use weak ciphers

d)

They are not widely used

31.

What is the purpose of runtime permissions in mobile apps?

a)

To allow apps to run in the background

b)

To request access to sensitive features only when needed

c)

To improve app speed

d)

To bypass encryption

32.

What is a key privacy feature introduced in iOS?

a)

Side-loading

b)

App tracking transparency

c)

Unlimited background access

d)

Root access

33.

What is the main risk of granting apps access to your contact list?

a)

Slower performance

b)

Increased battery usage

c)

Potential for malware to spread via social engineering

d)

Reduced encryption

34.

What is the role of AES-256 in mobile security?

a)

It compresses files

b)

It encrypts data at rest

c)

It speeds up app loading

d)

It disables root access

35.

What is a key difference between 4G and 5G in terms of security?

a)

5G has weaker encryption

b)

4G supports biometric authentication

c)

5G includes enhanced privacy features (depending on provider)

d)

4G is not encrypted

36.

What is the best way to protect your mobile device from malware?

a)

Disable all updates

b)

Use only trusted app stores and review permissions

c)

Enable root access

d)

Use public Wi-Fi without a VPN

37.

What is the primary goal of malware?

a)

To optimize system performance

b)

To update software

c)

To protect user data

d)

To harm or exploit devices or networks

38.

Which of the following is a self-replicating malware that does not require a host file?

a)

Virus

b)

Trojan

c)

Rootkit

d)

Worm

39.

What distinguishes a Trojan from a virus or worm?

a)

It replicates itself

b)

It spreads via networks

c)

It disguises itself as legitimate software

d)

It infects executable files

40.

What is the main function of ransomware?

a)

To delete system files

b)

To spy on users

c)

To display ads

d)

To extort users by encrypting their data

41.

Which malware type is designed to remain hidden and collect information?

a)

Adware

b)

Scareware

c)

Ransomware

d)

Spyware

42.

What is the purpose of scareware?

a)

To encrypt files

b)

To steal credentials

c)

To display ads

d)

To frighten users into taking action

43.

What is a rootkit primarily used for?

a)

Encrypting files

b)

Displaying ads

c)

Establishing remote access

d)

Sending spam

44.

Which malware spreads via social engineering and email attachments, as seen in ILOVEYOU?

a)

RAT

b)

Worm

c)

Virus

d)

Rootkit

45.

What was the main infection method used by the WannaCry ransomware?

a)

Email phishing

b)

USB drives

c)

Exploiting SMB vulnerabilities

d)

Fake antivirus popups

46.

What is the role of antivirus software?

a)

To create malware

b)

To slow down systems

c)

To detect, prevent, and remove malware

d)

To encrypt user data

47.

What is signature-based detection in antivirus software?

a)

Detecting unknown threats

b)

Using AI to detect malware

c)

Matching known malware patterns

d)

Executing malware in a sandbox

48.

What is sandbox execution used for in antivirus tools?

a)

Encrypting files

b)

Running malware in a safe environment

c)

Updating software

d)

Speeding up performance

49.

What is heuristic detection?

a)

Detecting malware based on exact matches

b)

Using AI to create malware

c)

Using generic patterns to detect variants

d)

Encrypting antivirus databases

50.

What is a zero-day exploit?

a)

A known vulnerability

b)

A patched vulnerability

c)

A vulnerability with no known fix

d)

A malware that deletes itself

51.

What is polymorphic malware?

a)

Malware that deletes files

b)

Malware that changes its code on each execution

c)

Malware that only runs once

d)

Malware that targets mobile devices

52.

What is polymorphic malware?

a)

Malware that deletes files

b)

Malware that changes its code on each execution

c)

Malware that only runs once

d)

Malware that targets mobile devices

53.

What is metamorphic malware?

a)

Malware that replicates itself

b)

Malware that encrypts its code

c)

Malware that rewrites its own code to avoid detection

d)

Malware that uses phishing

54.

What is fileless malware?

a)

Malware that infects only USB drives

b)

Malware that operates entirely in memory

c)

Malware that deletes system files

d)

Malware that uses rootkits

55.

What is the purpose of code obfuscation in malware?

a)

To speed up execution

b)

To make analysis harder

c)

To improve compatibility

d)

To reduce file size

56.

What is VirusTotal?

a)

A malware family

b)

A type of ransomware

c)

A free online malware analysis tool

d)

A government agency

57.

What is an APT group?

a)

A type of antivirus

b)

A malware detection tool

c)

A state-sponsored hacking group

d)

A sandbox environment

58.

What is the main limitation of signature-based antivirus detection?

a)

It is too fast

b)

It uses too much memory

c)

It cannot detect unknown threats

d)

It encrypts files

59.

How do malware authors bypass sandbox detection?

a)

By using stronger encryption

b)

By disabling antivirus

c)

By delaying malicious actions

d)

By using phishing emails

60.

What is the difference between polymorphic and metamorphic malware?

a)

Polymorphic malware deletes itself

b)

Metamorphic malware rewrites its own engine

c)

Polymorphic malware is easier to detect

d)

Metamorphic malware uses social engineering

61.

Why is fileless malware harder to detect?

a)

It uses outdated libraries

b)

It runs in safe mode

c)

It never writes to disk

d)

It uses email attachments

62.

What is the role of anomaly detection in antivirus software?

a)

To detect known malware

b)

To scan USB drives

c)

To identify unusual system behavior

d)

To encrypt user data

63.

What is a common social engineering tactic used to bypass antivirus?

a)

Sending encrypted files

b)

Convincing users to disable antivirus

c)

Using polymorphic code

d)

Exploiting SMB vulnerabilities

64.

What is the historical significance of the Creeper worm?

a)

It was the first ransomware

b)

It was the first virus

c)

It was the first worm and led to the first antivirus

d)

It was the first spyware

65.

What is the main goal of scareware?

a)

To encrypt files

b)

To steal passwords

c)

To scare users into installing fake software

d)

To disable antivirus

66.

What is the function of threat intelligence in antivirus systems?

a)

To scan USB drives

b)

To update the operating system

c)

To provide real-time data on emerging threats

d)

To encrypt malware

67.

What is a RAT (Remote Access Trojan) designed to do?

a)

Encrypt files

b)

Display ads

c)

Provide remote control over a system

d)

Scan for vulnerabilities

68.

What is Artificial Intelligence (AI)?

a)

A type of hardware

b)

A programming language

c)

A method for encrypting data

d)

The simulation of human intelligence by machines

69.

What is a Large Language Model (LLM)?

a)

A database of human languages

b)

A type of antivirus

c)

A neural network trained to understand and generate human language

d)

A compiler for machine code

70.

What architecture is commonly used in LLMs?

a)

Convolutional networks

b)

Decision trees

c)

Transformers

d)

Linear regression

71.

What is the purpose of tokenization in LLMs?

a)

To encrypt the input

b)

To split input into smaller units for processing

c)

To compress the output

d)

To translate the input into binary

72.

What is prompt injection?

a)

A method of training AI

b)

A way to speed up inference

c)

A technique to manipulate AI behavior through crafted inputs

d)

A method for compressing prompts

73.

What is a system prompt?

a)

A user command

b)

A type of malware

c)

A background instruction that shapes AI behavior

d)

A debugging tool

74.

What is a user prompt?

a)

A system-level instruction

b)

A training dataset

c)

The input given by the user to the AI

d)

A type of encryption

75.

What is a key defensive use of AI in cybersecurity?

a)

Creating phishing emails

b)

Generating malware

c)

Threat detection and anomaly analysis

d)

Jailbreaking models

76.

What is a key offensive use of AI in cybersecurity?

a)

SIEM augmentation

b)

Secure boot validation

c)

Automated phishing and malware generation

d)

Threat intelligence sharing

77.

What is a major risk of using LLMs in software development?

a)

They are too slow

b)

They require no training

c)

They may introduce security vulnerabilities

d)

They cannot generate code

78.

What is model hallucination?

a)

When a model crashes

b)

When a model generates incorrect or fabricated information

c)

When a model repeats input

d)

When a model fails to tokenize

79.

What is a jailbreaking attack in AI security?

a)

Unlocking a phone

b)

Bypassing safety filters in AI models

c)

Encrypting AI weights

d)

Updating the model

80.

What is model inversion?

a)

Reversing the training process

b)

Reconstructing training data from model weights

c)

Encrypting model outputs

d)

Compressing the model

81.

What is poisoning in AI security?

a)

Injecting malware into AI

b)

Adding falsified data to training sets

c)

Encrypting training data

d)

Disabling AI models

82.

What is the main concern with LLM-generated code?

a)

It is always encrypted

b)

It is too optimized

c)

It may contain vulnerabilities

d)

It cannot be compiled

83.

What is the CASTLE benchmark used for?

a)

Evaluating antivirus software

b)

Testing AI-generated C code for vulnerabilities

c)

Measuring AI speed

d)

Encrypting AI models

84.

What is the main difference between traditional and AI cybersecurity?

a)

AI security focuses on protecting networks

b)

Traditional security uses AI models

c)

AI security focuses on protecting models and data pipelines

d)

Traditional security uses transformers

85.

What is a key risk of overreliance on LLMs in development?

a)

Faster debugging

b)

Reduced memory usage

c)

Reduced critical thinking and unsafe code

d)

Improved documentation

86.

What is the role of adversarial testing in AI security?

a)

Encrypting AI models

b)

Testing AI with malicious inputs to find weaknesses

c)

Speeding up inference

d)

Compressing training data

87.

What is the future of AI in cybersecurity likely to include?

a)

Less automation

b)

Manual code reviews

c)

AI systems attacking and defending against each other

d)

No use in security

88.

What is the main challenge with protecting data in an LLM’s context window?

a)

It is encrypted

b)

It is stored offline

c)

It is difficult to prevent leakage once loaded

d)

It is always deleted

89.

What is a key limitation of LLMs in answering difficult questions?

a)

They are too fast

b)

They hallucinate less

c)

They often overestimate their capabilities

d)

They require no tools

90.

What is the main concern with AI-generated phishing emails?

a)

They are easy to detect

b)

They are poorly written

c)

They are highly personalized and convincing

d)

They are only used in spam

91.

What is the main risk of model theft?

a)

Slower inference

b)

Loss of intellectual property and data leakage

c)

Increased training time

d)

Reduced accuracy

92.

What is the main benefit of using LLMs in security automation?

a)

Slower response time

b)

Manual triaging

c)

Automatic playbook generation and triage

d)

Reduced detection

93.

What is the main concern with explainability in AI?

a)

It improves accuracy

b)

It reduces hallucinations

c)

It makes it hard to understand model decisions

d)

It increases training time

94.

What is the role of embeddings in AI security?

a)

Encrypting data

b)

Representing data in vector space for analysis

c)

Compressing models

d)

Speeding up tokenization

95.

What is the main concern with AI-generated documentation?

a)

It is too detailed

b)

It is always accurate

c)

It may contain hallucinated or incorrect information

d)

It is encrypted

96.

What is the main reason AI is used in fuzzing?

a)

To encrypt inputs

b)

To generate random passwords

c)

To discover vulnerabilities through automated input generation

d)

To compress logs

97.

What is the main concern with using LLMs for secure code generation?

a)

They are too slow

b)

They always use best practices

c)

They may introduce unsafe patterns even without being asked

d)

They require manual compilation