Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Cybersecurity Practice

Total questions: 25

Worksheet time: 25mins

Name
Class
Date
1.

A threat actor sets up a rogue access point (AP) at a local cafe. The rogue AP captures traffic and then forwards the traffic to the cafe AP. Which type of attack does this scenario describe?

a)

Ransomware

b)

DDos

c)

Man-in-the Middle

d)

Reconnaissance

2.

You notice that a new CVE has been shared to an email group that you belong to. What should you do first with the CVE?

a)

Record the CVE as part of the disaster recovery plan

b)

Look up the details of the vulnerability to determine whether it applies to your network

c)

Add the CVE to the firewall rules for your organization

d)

Research measures to prevent the CVE from attacking the network

3.

Which password follows strong password policy guidelines?

a)

Snuffy#

b)

1mpressive1

c)

Mar221984

d)

Wh@tareyouDo1ngtoday4

4.

Your supervisor tells you that you will participate in a CVSS assessment. What will you be doing?

a)

Interviewing users to determine their level of cybersecurity awareness

b)

Analyzing host logs to identify abnormal activities

c)

Evaluating end system security and scoring vulverabilities

d)

Performing penetration tests on internal network devices and systems

5.

How do threat actors launch ransomware attacks on organizations?

a)

They implant malware to collect data from the corporation's financial system

b)

They deface an organization's public facing website

c)

They secretly spy on employees and collect their personal information

d)

They lock data and deny access until they receive money

6.

The company web server collect information through a form. The form is accessed by using port 80. The form content is transferred to an encrypted database for storage. You are investigating a complaint that the form content has been compromised..

What is the cause of the security breach?

a)

The data was transferred to the database using a nonsecure protocol

b)

The database was compromised

c)

The content was accessed using HTTP, which is an unencrypted protocol

d)

The web browser used to access the site wasnot updated to the latest version

7.

Which Windows app is a command-line interface that includes a sophisticated scripting language used to automate Windows tasks?

a)

VMware

b)

Microsoft Management Console

c)

MS-DOS

d)

Powershell

8.

How does sandboxing help with the analysis of malware?

a)

It specifies the applications that are authorized for use on the network

b)

It allows suspicious applications to run in a safe and isolated testing environment

c)

It defines the suspicious ormalicious applications that should be blocked

d)

It restricts traffic from passing from one network to another

9.

Why is it necessary to update firmware to the latest version?

a)

To support the latest operating systems and applications

b)

To patch firmware in the kernel of the operating system

c)

To explore new hardware features

d)

To correct security holes and weaknesses

10.

You are going to perform a penetration test on a company LAN. As part of your preparation, you access the company's websites, view webpage source code, and run Internet searches to uncover domain information. You also use social media to gather details about the company and its employees.

Which type of reconnaissance activities are you performing

a)

Active

b)

Offline

c)

Inactive

d)

Passive

11.

Your home network seems to have slowed down considerably. You look at the home router GUI and notice that an unknown host is attached to the network.

What should you do to prevent this specific host from attaching to the network again?

a)

Change the network SSID

b)

Create an IP access control list (ACL)

c)

Block the host IP address

d)

Implement MAC address filtering

12.

An employee accidently sends an email containing sensitive corporate information to an external email address.

Which type of threat does this scenario describe?

a)

Malware

b)

Insider

c)

Phishing

d)

Logic bomb

13.

What is the main purpose of a disaster recovery plan as compared to a business continuity plan?

a)

Limiting operational downtime

b)

Restoring Data access and an IT infrastructure as quickly as possible

c)

Keeping the business open in some capacity during a disaster

d)

Allowing staff to continue to serve customers throughout a disaster

14.

What is the primary purpose of running a vulnerability scan on your network?

a)

To automatically prioritize security weaknesses for immediate remediation

b)

To determine whether systems are subject to CVE's that could be exploited by adversaries

c)

To identify and document the locations of customer and financial databases

d)

To correlate event logs on multiple servers in order to generate intrusion alerts

15.

Which security assessment of IT systems verifies that PII data is available, accurate, confidential, and accessable only by authorized users?

a)

Cyber Kill Chain

b)

Workflow management

c)

Information assurance

d)

Risk Framing

16.

You need to transfer configuration files to a router across an unsecured network.

Which protocol should you use to encrypt the files in transit?

a)

TFTP

b)

SSH

c)

Telnet

d)

HTTP

17.

Which MacOS security feature encrypts the entire MacOS volume?

a)

XProtect

b)

Gatekeeper

c)

FileVault

d)

System Integrity Protection (SIP)

18.

Which data type is protected through hard disk encryption?

a)

Data in Transit

b)

Data in process

c)

Data at rest

d)

Data in use

19.

Your manager asks you to review the output of some vulnerability scans and report anything that may require escalation. What 2 findings should you report for further investigation as potential security vulnerabilities?

(There are 2 answers here, but you can only choose 1. Make sure that you KNOW the 2 answers)

a)

Encrypted passwords

b)

SSH packets

c)

Disabled firewalls

d)

Open Ports

e)

Closed Ports

20.

You need a software solution that performs the following tasks:

  • Compiles network data

  • Logs information from many sources

  • Provides orchestration in the form of case management

  • Automates incident response workflows

What product should you use?

a)

SOAR

b)

SIEM

c)

CVSS

d)

CVE

21.

A contractor is building a new home for a client. The client decides to install several IoT devices.

What should the client do to ensure that the smart home is less vulnerable to attacks?

a)

Enable the SSID broadcast feature on the wireless router

b)

Connect the IoT devices to different wireless AP's for better protection

c)

Update the firmware on the IoT device regularly

d)

Buy Iot devices with the highest radio frequency so that it is harder to detect

22.

What is the main benefit of using a sandbox environment when analyzing suspicious files?

a)

It increases the speed of malware execution

b)

It prevents the malware from affecting production systems

c)

It allows malware to communicate with external servers

d)

It automatically removes all detected threats

23.

After receiving a report about a new vulnerability affecting your operating system, what should you do first?

a)

Disable all network connections

b)

Notify all users to stop using their computers

c)

Check if your systems are running the vulnerable version

d)

Immediately uninstall the affected software

24.

What network security technology passively monitors network traffic and compares the captured packet stream with known malicious signatures?

a)

Proxy Server

b)

IPS

c)

Honeypot

d)

IDS

25.

A remote worker is visiting a branch office to attend face-to-face meetings. The worker tries to associate their company laptop with the branch wireless access point (WAP) but is unable to do so. What is the possible cause?

a)

The WAP is configured for MAC address filtering

b)

The SSID is not broadcasting

c)

The WAP is using open authentication

d)

The IP address of the laptop is not correct