wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Cybersecurity Controls and Threat Intelligence Quiz

Total questions: 30

Worksheet time: 15mins

Name
Class
Date
1.

Which of the following is an example of a technical control?

a)

Annual security awareness training

b)

Role-based access control (RBAC)

c)

Disaster recovery policy

d)

Hiring background checks

2.

A company implements automatic patch updates for its systems every week. What type of control is this?

a)

Detective

b)

Operational

c)

Technical

d)

Compensating

3.

After a phishing attack compromises user accounts, the security team restores affected systems from clean backups. What type of control is this?

a)

Preventive

b)

Detective

c)

Corrective

d)

Managerial

4.

Due to high cost, a company decides not to use a fingerprint scanner and instead implements multi-factor authentication. What kind of control is MFA in this context?

a)

Technical

b)

Compensating

c)

Preventive

d)

Managerial

5.

Which control type involves creating policies and oversight for how security measures are developed and managed?

a)

Operational

b)

Technical

c)

Managerial

d)

Corrective

6.

A cybersecurity analyst detects unusual outbound traffic from a workstation and uses log analysis to investigate. What control type is being used?

a)

Preventive

b)

Detective

c)

Responsive

d)

Operational

7.

Which of the following best describes the purpose of passive discovery?

a)

Simulate attacks to test systems

b)

Actively probe devices for weaknesses

c)

Gather network information without direct interaction

d)

Document known vulnerabilities

8.

An organization maps out all possible ways a threat actor might infiltrate its systems. What is this process called?

a)

Asset inventory

b)

Threat modeling

c)

Log analysis

d)

Risk mitigation

9.

Which control type is designed to stop a threat before it causes harm?

a)

Detective

b)

Responsive

c)

Preventive

d)

Corrective

10.

A server is scanned by an unknown external IP. The security team follows a documented checklist to analyze the event. What type of control is being applied?

a)

Responsive

b)

Preventive

c)

Detective

d)

Managerial

11.

Your company cannot patch a known vulnerability due to compatibility issues. A temporary access control is put in place instead. What type of control is this?

a)

Preventive

b)

Compensating

c)

Detective

d)

Corrective

12.

Before applying a security patch to a production environment, a team ensures the update won't impact operations. What step of the patch management process is this?

a)

Rollback

b)

Testing

c)

Validation

d)

Implementation

13.

A critical patch is applied during scheduled downtime. Post-deployment, systems begin to crash. What should the administrator do next?

a)

Reapply the patch

b)

Execute rollback procedures

c)

Wait for vendor updates

d)

Isolate affected users

14.

Which control type is most concerned with creating policies and aligning security objectives with business goals?

a)

Technical

b)

Operational

c)

Corrective

d)

Managerial

15.

What risk management strategy is being applied when an organization purchases cyber insurance to cover potential breaches?

a)

Accept

b)

Transfer

c)

Avoid

d)

Mitigate

16.

A development team is coding a web application and wants to prevent XSS and SQL injection attacks. Which practice should they prioritize?

a)

Data encryption

b)

Secure file permissions

c)

Input validation and output encoding

d)

Role-based access controls

17.

What is the main purpose of governance in patch and configuration management?

a)

Monitor patch deployment tools

b)

Enforce antivirus updates

c)

Define frameworks and security policies

d)

Select hardware and vendor solutions

18.

What does a bug bounty program encourage?

a)

Internal audits by security staff

b)

Attack simulations using red teams

c)

Ethical hackers to report vulnerabilities

d)

Patch updates from vendors

19.

A third-party library used by your application has a critical vulnerability, but no patch has been released. Your team applies firewall rules and limits access to reduce risk. What strategy is this?

a)

Accept

b)

Transfer

c)

Mitigate

d)

Avoid

20.

Which of the following steps comes before deploying a patch to production environments?

a)

Monitoring system logs

b)

Testing the patch in a sandbox

c)

Disabling backups

d)

Encrypting affected data

21.

Employees in your organization unknowingly install malware from a trusted vendor's update server that was compromised. What type of attack is this?

a)

Social engineering

b)

Supply chain attack

c)

Insider threat

d)

Zero-day exploit

22.

A threat actor uses custom tools to remain undetected for months while targeting a government database. What type of actor is most likely responsible?

a)

Script kiddie

b)

Hacktivist

c)

Nation-state

d)

Insider

23.

An analyst maps out a cyber intrusion by focusing on the adversary, infrastructure, capability, and victim. Which analytical model is being used?

a)

MITRE ATT&CK

b)

Diamond Model

c)

Cyber Kill Chain

d)

STRIDE

24.

Which framework is specifically used to track attacker behaviors by documenting tactics, techniques, and procedures (TTPs)?

a)

OWASP

b)

MITRE ATT&CK

c)

Cyber Kill Chain

d)

NIST RMF

25.

A junior analyst detects brute-force login attempts and references the MITRE ATT&CK database to determine tactics used. What is she doing?

a)

Mapping adversarial behavior

b)

Verifying application versioning

c)

Writing a risk report

d)

Performing vulnerability scanning

26.

Which of the following best describes 'TTPs' used in cyber threat intelligence?

a)

Time-sensitive parameters

b)

Transport tunneling protocols

c)

Tactics, Techniques, and Procedures

d)

Tool Testing Parameters

27.

Which framework breaks a cyberattack into steps like reconnaissance, delivery, exploitation, and actions on objectives?

a)

OWASP Testing Guide

b)

Cyber Kill Chain

c)

MITRE ATT&CK

d)

Diamond Model

28.

A user bypasses monitoring controls to send sensitive data outside the organization using a software flaw. What type of insider threat is this?

a)

Passive

b)

Unintentional

c)

Intentional

d)

Negligent

29.

Which intelligence source usually requires a paid subscription or vendor relationship to access?

a)

Open source

b)

Internal logs

c)

Social media

d)

Closed source

30.

Which of the following traits determine the quality of threat intelligence?

a)

Speed, simplicity, and control

b)

Encryption, integrity, and trust

c)

Timeliness, relevancy, and accuracy

d)

Detection, deletion, and durability