wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Cybersecurity Fundamentals Quiz

Total questions: 121

Worksheet time: 1hrs 1mins

Name
Class
Date
1.

What does the CIA triad in cybersecurity stand for?

a)

Central Intelligence Agency

b)

Confidentiality, Integrity, Availability

c)

Computer Information Access

d)

Cybersecurity Implementation Architecture

2.

Which security goal ensures that information is accessible only to authorized users?

a)

Availability

b)

Integrity

c)

Confidentiality

d)

Non-repudiation

3.

A banking system that prevents unauthorized modification of account balances is primarily addressing which security goal?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Authentication

4.

Which of the following is NOT a common threat to availability?

a)

DDoS attacks

b)

Hardware failures

c)

Eavesdropping

d)

Power outages

5.

Digital signatures primarily support which security goal?

a)

Confidentiality

b)

Availability

c)

Non-repudiation

d)

Authorization

6.

An e-commerce website ensuring 99.9% uptime is primarily focusing on which security goal?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Authentication

7.

Which security goal is most directly threatened by a man-in-the-middle attack?

a)

Availability

b)

Integrity

c)

Authorization

d)

Accountability

8.

Hash functions are primarily used to ensure:

a)

Confidentiality

b)

Availability

c)

Integrity

d)

Authentication

9.

Multi-factor authentication primarily supports which security concept?

a)

Confidentiality

b)

Authentication

c)

Availability

d)

Integrity

10.

Social engineering attacks primarily threaten which security goal?

a)

Availability

b)

Integrity

c)

Confidentiality

d)

All of the above

11.

When should security be considered in the system development lifecycle?

a)

Only during the testing phase

b)

After the system is deployed

c)

From the initial design phase

d)

Only when vulnerabilities are discovered

12.

Which phase of the Secure Development Lifecycle (SDLC) involves identifying security risks and vulnerabilities?

a)

Planning

b)

Analysis

c)

Implementation

d)

Maintenance

13.

What is the primary benefit of incorporating security during the design phase rather than after deployment?

a)

Easier to implement

b)

More cost-effective

c)

Better user acceptance

d)

Faster development

14.

Which principle suggests that systems should be secure in their default configuration?

a)

Fail securely

b)

Secure defaults

c)

Complete mediation

d)

Minimize attack surface

15.

Threat modeling is typically performed during which phase?

a)

Implementation

b)

Testing

c)

Design

d)

Maintenance

16.

Which of the following is NOT a phase of the Secure Development Lifecycle?

a)

Planning

b)

Marketing

c)

Analysis

d)

Deployment

17.

The principle of 'minimize attack surface' means:

a)

Reduce physical size of systems

b)

Reduce number of potential entry points

c)

Minimize user interfaces

d)

Reduce system functionality

18.

Security requirements analysis involves:

a)

Identifying what needs protection

b)

Writing code

c)

Testing applications

d)

Deploying systems

19.

Which approach emphasizes that security should not be an afterthought?

a)

Security-first approach

b)

Performance-first approach

c)

Cost-first approach

d)

User-first approach

20.

Risk assessment in secure system design involves:

a)

Evaluating likelihood and impact of threats

b)

Testing system performance

c)

Training users

d)

Installing antivirus software

21.

Which type of threat comes from employees within an organization?

a)

External threat

b)

Internal threat

c)

Environmental threat

d)

Network threat

22.

Nation-state actors are examples of which type of threat?

a)

Internal threats

b)

Environmental threats

c)

External threats

d)

Physical threats

23.

Which attack involves intercepting communications between two parties?

a)

DoS attack

b)

SQL injection

c)

Man-in-the-middle attack

d)

Buffer overflow

24.

Phishing emails are examples of which type of attack?

a)

Network-based attack

b)

Social engineering

c)

Physical attack

d)

Application-based attack

25.

Which attack involves overwhelming a system with traffic to make it unavailable?

a)

SQL injection

b)

Cross-site scripting

c)

Denial of Service (DoS)

d)

Buffer overflow

26.

Natural disasters fall under which threat category?

a)

Internal threats

b)

External threats

c)

Environmental threats

d)

Social threats

27.

The MITRE ATT&CK framework provides:

a)

Antivirus signatures

b)

A matrix of attack techniques

c)

Firewall rules

d)

Encryption algorithms

28.

Shoulder surfing is an example of which type of attack?

a)

Network attack

b)

Application attack

c)

Physical attack

d)

Social engineering

29.

Which of the following is NOT typically considered an internal threat?

a)

Malicious insiders

b)

Accidental insider threats

c)

DDoS attacks

d)

Privileged user abuse

30.

Threat intelligence is best described as:

a)

Software for detecting threats

b)

Evidence-based knowledge about threats

c)

A type of firewall

d)

An encryption method

31.

What is the main advantage of embedding security controls during the design phase?

a)

Cheaper implementation costs

b)

Better integration with system architecture

c)

Reduced security gaps

d)

All of the above

32.

Which architecture pattern follows the principle 'never trust, always verify'?

a)

Layered Security Architecture

b)

Zero Trust Architecture

c)

Service-Oriented Security

d)

Client-Server Architecture

33.

In layered security architecture, which layer handles input validation?

a)

Data layer

b)

Application layer

c)

Presentation layer

d)

Network layer

34.

Single Sign-On (SSO) is an example of which security pattern?

a)

Authorization pattern

b)

Authentication pattern

c)

Data protection pattern

d)

Network security pattern

35.

Role-Based Access Control (RBAC) is an example of which type of pattern?

a)

Authentication pattern

b)

Authorization pattern

c)

Data protection pattern

d)

Communication pattern

36.

Google's BeyondCorp model is an example of:

a)

Traditional perimeter security

b)

Zero trust implementation

c)

Layered security

d)

Security by obscurity

37.

Which security architecture pattern emphasizes reusable security modules?

a)

Layered Security Architecture

b)

Zero Trust Architecture

c)

Service-Oriented Security

d)

Monolithic Security

38.

Micro-segmentation is a key feature of which architecture?

a)

Traditional network architecture

b)

Zero Trust Architecture

c)

Client-server architecture

d)

Peer-to-peer architecture

39.

Data tokenization is an example of which security pattern?

a)

Authentication pattern

b)

Authorization pattern

c)

Data protection pattern

d)

Network security pattern

40.

Proactive security integration means:

a)

Adding security after deployment

b)

Embedding security during design

c)

Focusing only on perimeter security

d)

Using only open-source security tools

41.

The security-usability trade-off refers to:

a)

Choosing between different security vendors

b)

Balancing strong security with user convenience

c)

Selecting encryption algorithms

d)

Deciding on password policies

42.

Which of the following represents a successful balance between security and convenience?

a)

Complex 20-character passwords changed daily

b)

Biometric authentication (Touch ID/Face ID)

c)

Manual approval for every system access

d)

Disabling all remote access

43.

What often happens when security measures are too complex for users?

a)

Users improve their security awareness

b)

Systems become more secure

c)

Users find workarounds or avoid the security measures

d)

Productivity increases

44.

Progressive security (adaptive authentication) means:

a)

Gradually increasing security over time

b)

Adjusting security requirements based on risk context

c)

Using multiple security vendors

d)

Implementing security in phases

45.

Which approach can help reduce the burden of multiple passwords on users?

a)

Writing passwords down

b)

Using simple passwords

c)

Single Sign-On (SSO) systems

d)

Sharing passwords between applications

46.

'Alert fatigue' occurs when:

a)

Security systems fail frequently

b)

Users ignore security warnings due to too many false alarms

c)

Systems run out of memory

d)

Networks become congested

47.

Users ignore security warnings due to too many false alarms.

a)

Users ignore security warnings due to too many false alarms

b)

Systems run out of memory

c)

Networks become congested

48.

Context-aware security controls: Adjust security based on user context and risk.

a)

Ignore user location and behavior

b)

Apply the same security to all situations

c)

Adjust security based on user context and risk

d)

Only work during business hours

49.

Which of the following led to users creating workarounds that reduced security?

a)

Simple password requirements

b)

Overly complex enterprise VPN systems

c)

Biometric authentication

d)

Single sign-on systems

50.

User-centric security design involves: Conducting usability testing for security features.

a)

Ignoring user preferences

b)

Making security as complex as possible

c)

Conducting usability testing for security features

d)

Removing all security controls

51.

Password managers help achieve balance by: Enabling complex passwords with ease of use.

a)

Eliminating the need for passwords

b)

Allowing simple passwords everywhere

c)

Enabling complex passwords with ease of use

d)

Sharing passwords between users

52.

Security requirements engineering is: The process of identifying and managing security requirements throughout SDLC.

a)

Only done after coding is complete

b)

The process of identifying and managing security requirements throughout SDLC

c)

Only concerned with network security

d)

Focused solely on compliance requirements

53.

Which of the following is a functional security requirement?

a)

System performance under attack

b)

Authentication mechanisms

c)

Scalability of security measures

d)

Reliability of security controls

54.

"The system shall encrypt all sensitive data using AES-256 encryption" is an example of: Confidentiality requirement.

a)

Availability requirement

b)

Integrity requirement

c)

Confidentiality requirement

d)

Authentication requirement

55.

Which requirement type focuses on how well security measures perform rather than what they do?

a)

Functional security requirements

b)

Non-functional security requirements

c)

Business requirements

d)

User requirements

56.

Security use cases include: Normal usage and abuse cases.

a)

Only normal usage scenarios

b)

Normal usage and abuse cases

c)

Only attack scenarios

d)

Only compliance requirements

57.

"The system shall maintain 99.9% uptime" is an example of: Availability requirement.

a)

Confidentiality requirement

b)

Integrity requirement

c)

Availability requirement

d)

Authentication requirement

58.

PCI DSS requirements are an example of: Detailed security requirements for specific industries.

a)

Functional requirements only

b)

Non-functional requirements only

c)

Detailed security requirements for specific industries

d)

General software requirements

59.

Abuse cases in security requirements help identify: How the system might be misused.

a)

Normal system usage

b)

How the system might be misused

c)

Performance requirements

d)

User interface design

60.

"Database transactions shall use ACID properties" is an example of: Integrity requirement.

a)

Confidentiality requirement

b)

Integrity requirement

c)

Availability requirement

d)

Authorization requirement

61.

Security acceptance criteria should be: Specific and measurable.

a)

Vague and general

b)

Specific and measurable

c)

Optional for most projects

d)

Only focused on compliance

62.

Security by obscurity means: Relying on secrecy of system design for security.

a)

Using complex passwords

b)

Relying on secrecy of system design for security

c)

Hiding physical servers

d)

Using encryption

63.

According to Kerckhoffs's Principle, a cryptosystem should be secure even if: Everything except the key is public knowledge.

a)

The key is known

b)

Everything except the key is public knowledge

c)

The algorithm is complex

d)

Multiple users access it

64.

Which of the following is an example of security by obscurity? Hiding system version information.

a)

Using AES encryption

b)

Implementing multi-factor authentication

c)

Hiding system version information

d)

Regular security updates

65.

Why does security by obscurity typically fail as a primary security measure? Secrets are difficult to maintain long-term.

a)

It's too expensive to implement

b)

Secrets are difficult to maintain long-term

c)

It requires special hardware

d)

Users don't understand it

66.

The Wired Equivalent Privacy (WEP) protocol failed because: Its proprietary algorithm was easily broken.

a)

It was too complex for users

b)

It was too expensive

c)

Its proprietary algorithm was easily broken

d)

It required special hardware

67.

When might security by obscurity be appropriately used? As an additional layer in defense in depth.

a)

As the primary security mechanism

b)

As an additional layer in defense in depth

c)

Instead of encryption

d)

To replace authentication systems

68.

HTTPS provides strong security by: Using well-known, publicly documented standards with secret keys.

a)

Hiding the encryption algorithm

b)

Using secret protocols

c)

Using well-known, publicly documented standards with secret keys

d)

Obscuring network traffic

69.

Which statement about proprietary encryption algorithms is generally true? They are often weaker than open standards.

a)

They are always more secure than open standards

b)

They are often weaker than open standards

c)

They are easier to implement

d)

They are preferred by security experts

70.

Reverse engineering can defeat security by obscurity because: It can reveal hidden system details.

a)

It's illegal in most countries

b)

It can reveal hidden system details

c)

It requires expensive tools

d)

It's too time-consuming

71.

The best approach to security is: Rely on proven, open security standards with proper key management.

a)

Rely entirely on security by obscurity

b)

Use only open-source solutions

c)

Rely on proven, open security standards with proper key management

d)

Avoid all forms of obscurity

72.

The principle "Keep It Simple" (Economy of Mechanism) suggests that: Security mechanisms should be as simple as possible while meeting requirements.

a)

Security mechanisms should be as complex as possible

b)

Security mechanisms should be as simple as possible while meeting requirements

c)

Only one security control should be used

d)

Security should be ignored to keep systems simple

73.

Fail-safe defaults means: Systems should default to a secure state when they fail.

a)

Systems should never fail

b)

Systems should default to an insecure state when they fail

c)

Systems should default to a secure state when they fail

d)

Systems should shut down completely when they fail

74.

Complete mediation requires that: Every access attempt to every resource must be checked.

a)

Some access attempts are checked

b)

Every access attempt to every resource must be checked

c)

Only the first access attempt is checked

d)

Access checks are optional

75.

The principle of least privilege means: Users should have only the minimum privileges necessary.

a)

Users should have maximum privileges for convenience

b)

Users should have only the minimum privileges necessary

c)

All users should have the same privileges

d)

Privileges should never be granted

76.

Which principle led to the selection of AES through an open competition? Open design.

a)

Fail-safe defaults

b)

Least privilege

c)

Open design

d)

Separation of privilege

77.

Nuclear weapon systems requiring multiple keys exemplify which principle? Separation of privilege.

a)

Least privilege

b)

Separation of privilege

c)

Economy of mechanism

d)

Complete mediation

78.

Psychological acceptability means security mechanisms should be: Easy to use and understand.

a)

Complex and comprehensive

b)

Hidden from users

c)

Easy to use and understand

d)

Available only to experts

79.

Least common mechanism suggests: Minimize shared mechanisms between different users.

a)

All users should share the same security controls

b)

Minimize shared mechanisms between different users

c)

Use only one type of security control

d)

Common mechanisms are always better

80.

A firewall defaulting to block traffic unless explicitly allowed demonstrates: Fail-safe defaults.

a)

Complete mediation

b)

Fail-safe defaults

c)

Least privilege

d)

Open design

81.

Virtualization systems isolating different VMs exemplify which principle? Least common mechanism.

a)

Economy of mechanism

b)

Psychological acceptability

c)

Least common mechanism

d)

Open design

82.

Defense in depth is based on the principle that: Multiple layers of defense provide better protection.

a)

One strong security control is sufficient

b)

Multiple layers of defense provide better protection

c)

Security controls should be complex

d)

Physical security is most important

83.

Which military concept inspired defense in depth? Multiple defensive positions to slow attackers.

a)

Surprise attacks

b)

Multiple defensive positions to slow attackers

c)

Overwhelming force

d)

Quick retreats

84.

Perimeter security typically includes: Firewalls, intrusion detection, and physical security.

a)

Only firewalls

b)

Firewalls, intrusion detection, and physical security

c)

Only antivirus software

d)

Only access controls

85.

Which type of control detects security incidents after they occur?

a)

Preventive controls

b)

Detective controls

c)

Corrective controls

d)

Deterrent controls

86.

Host security controls include:

a)

Network firewalls only

b)

Antivirus, host firewalls, and OS hardening

c)

Physical security only

d)

Database encryption only

87.

A bank implementing physical security, network controls, application security, and data encryption is using:

a)

Single point of failure approach

b)

Defense in depth

c)

Security by obscurity

d)

Minimum security approach

88.

What is a potential challenge of implementing defense in depth?

a)

Improved security

b)

Better compliance

c)

Increased complexity and costs

d)

Reduced attack surface

89.

Complementary controls in defense in depth should be:

a)

Dependent on each other

b)

Independent and non-overlapping

c)

Identical in function

d)

Simple and basic

90.

Data security layer in defense in depth includes:

a)

Only backup systems

b)

Encryption, DLP, and database security

c)

Only access controls

d)

Only network monitoring

91.

The main benefit of defense in depth is:

a)

Reduced costs

b)

Simplified management

c)

Resilience against multiple attack types

d)

Faster system performance

92.

Diversity in defense means:

a)

Using only one type of security control

b)

Using different types of security controls and technologies

c)

Having diverse user groups

d)

Using multiple operating systems

93.

Vendor diversity helps reduce:

a)

System performance

b)

Risk of vendor-specific vulnerabilities

c)

User training needs

d)

System complexity

94.

Using antivirus products from multiple vendors is an example of:

a)

Technology diversity

b)

Vendor diversity

c)

Temporal diversity

d)

Architectural diversity

95.

Rotating security measures over time represents:

a)

Vendor diversity

b)

Technology diversity

c)

Temporal diversity

d)

Architectural diversity

96.

Which benefit does diversity in defense provide?

a)

Reduced security costs

b)

Simplified management

c)

Increased attacker effort required

d)

Faster system response

97.

Financial services using multiple fraud detection systems from different vendors demonstrates:

a)

Poor security planning

b)

Unnecessary redundancy

c)

Effective diversity in defense

d)

Vendor lock-in

98.

A potential drawback of diversity in defense is:

a)

Better security coverage

b)

Reduced vulnerabilities

c)

Increased management complexity

d)

Improved system resilience

99.

Different authentication methods for different access levels represent:

a)

Vendor diversity

b)

Technology diversity

c)

Temporal diversity

d)

Geographic diversity

100.

Critical infrastructure using diverse control systems helps prevent:

a)

System updates

b)

Common vulnerabilities affecting all systems

c)

User access

d)

Network communication

101.

The main rationale for diversity in defense is that:

a)

It's required by regulations

b)

Attacks that defeat one defense may not work against different defenses

c)

It reduces costs

d)

It simplifies security management

102.

The weakest link principle states that:

a)

All security controls are equally important

b)

A system's security is only as strong as its weakest component

c)

Physical security is always the weakest link

d)

Technical controls are weaker than human controls

103.

Which is often considered the weakest link in security systems?

a)

Firewalls

b)

Encryption algorithms

c)

Human factors

d)

Network protocols

104.

The Target data breach (2013) occurred because:

a)

Their firewall failed

b)

Weak vendor management was exploited

c)

Employees were untrained

d)

They used weak encryption

105.

The Equifax data breach (2017) was caused by:

a)

Social engineering

b)

Physical security failure

c)

Unpatched software vulnerability

d)

Weak passwords

106.

Which method helps identify weakest links in security?

a)

User training only

b)

Vulnerability scans and penetration testing

c)

Installing more firewalls

d)

Increasing password complexity

107.

Common technical weakest links include:

a)

Well-configured systems

b)

Updated software

c)

Legacy systems with known vulnerabilities

d)

Strong authentication systems

108.

To strengthen human factors as potential weakest links, organizations should:

a)

Remove all user access

b)

Implement security awareness training

c)

Install more technical controls only

d)

Ignore user behavior

109.

Attackers typically target:

a)

The strongest security controls

b)

The most expensive systems

c)

The path of least resistance

d)

Random system components

110.

Which is NOT typically a procedural weakness?

a)

Inadequate security policies

b)

Poor incident response procedures

c)

Strong encryption algorithms

d)

Insufficient monitoring

111.

Continuous monitoring helps by:

a)

Eliminating all weaknesses

b)

Identifying and addressing weakest links over time

c)

Replacing human oversight

d)

Reducing system complexity

112.

Failsafe stance means systems should:

a)

Never fail under any circumstances

b)

Fail in a secure manner when they malfunction

c)

Shut down completely when problems occur

d)

Continue operating normally despite failures

113.

Fail-secure (fail-closed) systems:

a)

Allow access when they fail

b)

Deny access when they fail

c)

Shut down completely

d)

Ignore security during failures

114.

Fail-safe (fail-open) systems:

a)

Deny access when they fail

b)

Allow access when they fail

c)

Maintain all security controls

d)

Never experience failures

115.

Which type of system would appropriately use fail-open behavior?

a)

Bank vault security systems

b)

Nuclear facility access controls

c)

Hospital emergency room door systems

d)

Military classified data systems

116.

Default deny policies demonstrate which failsafe approach?

a)

Fail-open

b)

Fail-secure

c)

Fail-soft

d)

No failsafe approach

117.

Fire doors that automatically close during emergencies exemplify:

a)

Poor design

b)

Fail-open systems

c)

Failsafe design principles

d)

Fail-soft systems

118.

ATMs that retain cards when fraud is suspected demonstrate:

a)

Fail-open behavior

b)

Fail-secure behavior

c)

System malfunction

d)

Poor user experience design

119.

Graceful degradation (fail-soft) means:

a)

Systems fail completely

b)

Systems continue with reduced functionality

c)

Systems ignore all security

d)

Systems become more vulnerable

120.

Which consideration is important when designing failsafe systems?

a)

Always prioritize security over safety

b)

Always prioritize availability over security

c)

Balance security, safety, and availability based on risk assessment

d)

Ignore user requirements

121.

Nuclear power plants that shut down when safety systems fail demonstrate:

a)

Poor engineering

b)

Fail-open design

c)

Appropriate failsafe design for safety-critical systems

d)

Fail-secure design