Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Pre-test Quiz

Total questions: 15

Worksheet time: 8mins

Name
Class
Date
1.

What is the main purpose of the Vulnerability Assessment (VA) process?

a)

Exploit all target systems

b)

Identify and assess vulnerabilities in the system (Assessment)

c)

Protect systems using antivirus

d)

Hide user activity from logs

2.

What is the main difference between the roles of Red Team and Blue Team in attack simulation scenarios?

a)

Red Team protects the system, Blue Team attacks

b)

Red Team only uses manual tools

c)

Red Team attacks (Attack Simulation), Blue Team defends and detects (Defensive Operation)

d)

Blue Team only works on Linux-based systems

3.

Which of the following is part of the Reconnaissance stage?

a)

DNS Enumeration and Port Scanning

b)

Privilege Escalation

c)

Persistence

d)

Log Analysis

4.

What is XSS (Cross Site Scripting) in the context of Web Application Security?

a)

An attack on the file system

b)

Brute force attack on passwords

c)

An attack that injects malicious scripts into web pages

d)

A technique to bypass firewalls

5.

Which of the following tools is commonly used in the Vulnerability Assessment process?

a)

Nessus, OpenVAS, Nikto

b)

FTK Imager, Velociraptor

c)

Metasploit, Empire

d)

KAPE, Autopsy

6.

In Red Teaming activities, what is meant by Lateral Movement?

a)

Attack on external DNS servers

b)

Movement of access from one host to another within the network (Horizontal Escalation)

c)

Data exfiltration via email

d)

Log deletion to avoid detection

7.

What is the purpose of the Memory Acquisition process in digital forensics by the Blue Team?

a)

To take a snapshot of RAM for forensic analysis (Volatile Artifact Analysis)

b)

To erase all traces of the attack

c)

To detect network traffic

d)

To automatically turn on the firewall

8.

What is the most accurate statement about Atomic Red Team?

a)

Python-based exploit library

b)

Tools for endpoint encryption

c)

Attack simulation scenario library to test Blue Team detection effectiveness

d)

Forensic toolkit for Linux investigations

9.

What is KAPE (Kroll Artifact Parser and Extractor) used for by the Blue Team?

a)

To collect and extract digital artifacts from endpoints for further analysis

b)

To exploit Windows systems

c)

To create reverse shells

d)

To scan internal network ports

10.

The Persistence technique is used by the Red Team to:

a)

Delete system logs

b)

Replace the OS kernel

c)

Ensure access remains after reboot or shutdown (Backdoor Access)

d)

Permanently disable antivirus

11.

What is the role of Velociraptor in the Incident Response process by the Blue Team?

a)

To collect digital artifacts from endpoints in real-time and distributed manner

b)

To perform brute force on internal systems

c)

To insert backdoors into target systems

d)

To automatically configure firewalls and IDS

12.

When the Red Team performs brute force on a Web Application, how can the Blue Team detect it?

a)

By viewing memory dump results

b)

By analyzing HTTP access logs and detecting repeated failed login patterns

c)

By turning on IDS

d)

By viewing the .htaccess file

13.

In the context of Defense Evasion, what is meant by the Living off the Land (LotL) technique?

a)

Attack on kernel files

b)

Abuse of built-in system tools (like powershell.exe, wmic) to avoid detection

c)

Utilization of polymorphic malware

d)

Exploitation of web application logic

14.

When the Blue Team analyzes Persistence, which indicator is relevant to be suspicious?

a)

Number of outgoing ICMP requests

b)

DNS Cache content

c)

Presence of unknown autorun registry or suspicious Scheduled Task (Autorun Artifacts)

d)

Number of connections to port 21

15.

Why is it important to conduct Red Teaming in a Production Environment or a simulation that resembles production?

a)

To blame the IT team if it fails

b)

To test the effectiveness of detection and security response against real scenarios (Realistic Attack Simulation)

c)

To disable antivirus

d)

To reschedule weekly patches