wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CompTIA N+ N10-009 Mock Test 3 Revision

Total questions: 59

Worksheet time: 33mins

Name
Class
Date
1.

Which of the following is NOT one of the three main goals of computer security as remembered by the CIA triad?

a)

Confidentiality

b)

Compliance

c)

Integrity

d)

Availability

2.

What term describes a weakness in a system-like an unlocked door-that could let someone cause harm, whether by accident or on purpose?

a)

Threat

b)

Risk

c)

Vulnerability

d)

Exploit

3.

What is the chance that someone or something might take advantage of that weakness to cause damage?

a)

Vulnerability

b)

Threat

c)

Risk

d)

Attack Vector

4.

The person or thing causing the threat is called a/an:

a)

Attack vector

b)

Vulnerability actor

c)

Risk agent

d)

Threat actor

5.

What is the process of spotting possible problems (like weaknesses or threats), figuring out how serious they are, and deciding how to deal with them?

a)

Security Audit

b)

Posture Assessment

c)

Process Assessment

d)

Risk Management

6.

Improving a system's security is called:

a)

Hardening

b)

Compliance

c)

Assessment

d)

Auditing

7.

Which of the following is any data that can identify a person-like their name, ID number, phone number, or address?

a)

Confidential Information

b)

Personal Information

c)

Sensitive Data

d)

Personally Identifiable Information (PII)

8.

The General Data Protection Regulation (GDPR) is a privacy law from which region?

a)

United States

b)

European Union

c)

Asia

d)

Australia

9.

What is the term for protecting data by making sure only the right people or systems can read it?

a)

Access Control

b)

Encryption

c)

Hashing

d)

Logical Security

10.

Which type of algorithm changes readable text (called plaintext) into unreadable code (called ciphertext), requiring a special key to change it back?

a)

Hash algorithm

b)

Encryption algorithm

c)

Decoding algorithm

d)

Compression algorithm

11.

What is data that is saved and not currently moving anywhere, such as on a hard drive, SSD, USB flash drive, or cloud storage?

a)

Data in use

b)

Data at rest

c)

Data in transit

d)

Data in motion

12.

What is the actual method or code that a hacker uses to take advantage of that weakness?

a)

Vulnerability

b)

Threat

c)

Risk

d)

Exploit

13.

A special kind of weakness that no one (not even the software developer) knows about yet is called a:

a)

Known vulnerability

b)

Zero-day vulnerability

c)

Undetected threat

d)

Hidden exploit

14.

What type of threat comes from someone outside the organization who doesn't have login access?

a)

Internal threat

b)

Accidental threat

c)

Malicious insider

d)

External threat

15.

What is the term for when an attacker pretends to be someone or something else?

a)

Phishing

b)

Spoofing

c)

Malware

d)

Denial of Service

16.

Which type of attack involves an attacker trying to break or block a service so that normal users can't use it, often by overloading the system?

a)

Malware attack

b)

Spoofing attack

c)

Footprinting attack

d)

Denial of Service (DoS) attack

17.

What is a large group of computers that have been secretly taken over by a hacker and controlled from a central point?

a)

Trojan network

b)

Zombie farm

c)

Botnet

d)

Virus collective

18.

Which type of malware attaches itself to files and spreads when the file is opened?

a)

Worm

b)

Trojan

c)

Virus

d)

PUP

19.

What is an attack where a hacker secretly places themselves between two devices (like your computer and a server) during a conversation?

a)

DoS attack

b)

Spoofing attack

c)

On-path attack

d)

VLAN hopping attack

20.

What attack involves sending out fake messages that pretend to come from a trusted device-like the router-to trick other computers into sending their traffic to the hacker's device instead?

a)

MAC spoofing

b)

IP spoofing

c)

DNS spoofing

d)

ARP spoofing (ARP poisoning)

21.

What attack targets a switch by sending a massive amount of fake data using random, made-up MAC addresses to fill up its MAC address table?

a)

MAC flooding

b)

VLAN hopping

c)

ARP poisoning

d)

DNS poisoning

22.

Which type of attack involves a hacker tricking the network into letting their device talk to VLANs they shouldn’t have access to, sometimes by using a double-tagged frame?

a)

ARP spoofing attack

b)

VLAN hopping attack

c)

MAC flooding attack

d)

DNS attack

23.

What is any device or service connected to your network without the IT department’s permission?

a)

Authorized device

b)

Rogue device or service

c)

Managed service

d)

Shadow IT (only if accidental)

24.

What happens when there’s an unauthorized or fake DHCP server on the network?

a)

Rogue DHCP

b)

IP spoofing

c)

DNS poisoning

d)

MAC flooding

25.

What type of attack targets the system that helps devices translate website names (like google.com) into IP addresses they can actually connect to?

a)

ARP attack

b)

DHCP attack

c)

DNS attack

d)

MAC attack

26.

What is the social engineering trick where an attacker pretends to be someone trustworthy-often using fake emails or websites-to fool someone into doing something dangerous, like downloading a virus or giving away their password?

a)

Impersonation

b)

Phishing

c)

Baiting

d)
  • Quid pro quo

27.

Which of the following is an example of an external threat?

a)

A hacker using malware.

b)
A data backup process
c)
A software update that improves security
d)
An internal policy change
28.

What is the primary goal of footprinting and fingerprinting attacks?

a)

To overload the network.

b)

To steal login credentials directly.

c)

To gather information about a network before launching a bigger attack.

d)

To install malware on target systems.

29.

What is it called when attackers register fake websites with names similar to real ones (like [suspicious link removed] instead of google.com)?

a)
Domain Spoofing
b)
Typosquatting
c)
URL Hijacking
d)
Phishing
30.

Which term refers to data that is currently being used by a device, meaning it’s temporarily held in the computer’s memory (RAM or CPU)?

a)

Data in transit

b)

Data in transit

c)

Data in storage

d)

Data in use

31.

Confidentiality means that everyone should be able to see the information.

a)
False
b)
Confidentiality allows public access to data.
c)
Only authorized personnel should see the information.
d)
True
32.

Integrity means the information must stay the way it was meant to be, without unauthorized changes.

a)

False

b)
Integrity means sharing information freely without restrictions.
c)
Integrity is about making information more accessible to everyone.
d)

True

33.

Risk is how likely it is that a threat will actually happen and how bad the damage would be.

a)
Risk is solely determined by past incidents.
b)

True

c)
Risk is the total absence of any threats.
d)

False

34.

Security policies are rules that make sure risks are known and steps (called security controls) are in place to reduce those risks.

a)

True

b)

False

c)
Security policies are only for IT departments.
d)
Security policies eliminate all risks completely.
35.

It is always a good idea to fix every possible security risk regardless of cost.

a)
All security risks should be fixed immediately, regardless of impact.
b)
It's unnecessary to address any security risks.
c)
False
d)
Cost should never be a factor in fixing security risks.
36.

A Mission Essential Function (MEF) is something a business cannot stop doing-even for a short time.

a)
A Mission Essential Function (MEF) is a non-critical business task that can be delayed.
b)
A Mission Essential Function (MEF) is an optional business activity that can be stopped temporarily.
c)

True

d)
A Mission Essential Function (MEF) is a routine task that can be paused without consequences.
37.

Regulatory compliance is about what the law requires, whereas internal audits are about what the company thinks is important.

a)

False

b)
Regulatory compliance is optional; internal audits are mandatory.
c)

True

d)
Regulatory compliance focuses on company culture; internal audits are about legal standards.
38.

Data sovereignty is when a country says that certain data-like personal info-must stay within that country's borders.

a)
Data sovereignty requires all data to be stored in the cloud.
b)

True

c)
Data sovereignty is the principle of global data access.
d)

False

39.

Encryption is a type of physical security.

a)

True

b)
Encryption is a type of software security.
c)
Encryption is a method of physical access control.
d)
False
40.

You can turn a hash back into the original text.

a)
Yes, you can easily reverse a hash.
b)
You can decode a hash back to text.
c)
No, you cannot turn a hash back into the original text.
d)
Hashing is a reversible process.
41.

Data in transit is data that is saved and not currently moving anywhere.

a)
Data in transit is data that has been deleted.
b)
Data in transit is data that is only in the cloud.
c)
Data in transit is data that is actively moving.
d)
Data in transit is data that is stored permanently.
42.

An exploit is like a broken lock, and a vulnerability is the trick someone uses to open that broken lock.

a)
An exploit is a tool used to strengthen security.
b)
A vulnerability is a method to secure a system.
c)
An exploit is a type of vulnerability.
d)

False

43.

Reputational threat intelligence is written information explaining how attacks happen.

a)
Reputational threat intelligence is a method for preventing attacks.
b)
Reputational threat intelligence is a type of software used in cybersecurity.
c)

True

d)

False

44.

Social engineering involves hacking a computer rather than tricking a human.

a)
Hacking a computer is the main goal of social engineering
b)
True
c)
Social engineering is only about physical access
d)
False
45.

A worm requires a user to open a file to spread.

a)

False

b)

True

c)
The worm spreads automatically without user interaction.
d)
The worm spreads by sending emails to users.
46.

Trojans are programs that ask for permission before installing hidden malware.

a)
Trojans are always safe to install.
b)
Trojans only affect mobile devices.
c)
True
d)
False
47.

In MAC spoofing, hackers fake MAC addresses to sneak past security rules.

a)
Hackers use MAC spoofing to improve their internet speed.
b)
MAC addresses are used to identify devices on a network without any manipulation.
c)
MAC spoofing is a method to enhance network security.
d)

Yes, MAC spoofing is a technique used by hackers to fake MAC addresses and bypass security rules.

48.

ARP (Address Resolution Protocol) has strong built-in security checks.

a)
ARP includes encryption features
b)
ARP is highly secure
c)
True
d)
False
49.

If a MAC flooding attack is successful, a switch starts sending traffic out to all ports like a hub.

a)
The switch encrypts all traffic before sending it out.
b)
The switch only forwards traffic to the intended port.
c)

False, the switch drops all incoming traffic completely.

d)

True, the switch behaves like a hub, broadcasting traffic to all ports.

50.

Shadow IT devices are always set up with malicious intent.

a)
Sometimes
b)
False
c)
True
d)
Always
51.

Typosquatting is a common threat in private networks.

a)
Only in email communications
b)
Only in public networks
c)
True
d)
False
52.

DNS client cache poisoning affects only one computer's stored IP addresses.

a)
Only affects the entire network
b)
True
c)
Only affects DNS servers
d)
False
53.

DNS server cache poisoning affects all users who use that server if successful.

a)
True
b)
False
c)
Only affects the server administrator
d)
Only affects some users
54.

The CIA triad stands for (a)   , Integrity, and Availability.

55.

The method a threat actor uses to attack is called the (a)   .

56.

A posture assessment uses the chosen framework to check how advanced or (a)   a company is in applying security policies and tools.

57.

Data locality means that where data is (a)   and processed matters, especially because different countries have different rules about privacy and data protection.

58.

(a)   algorithms turn any size of text into a fixed-length code and are used to check data integrity.

59.

Data in (a)   (also called data in motion) is data that is moving across a network.