Font size
WorksheetsMix Ques: Cyber Security, Social Engineering & Boolean Logic
Total questions: 112
Worksheet time: 1hrs 24mins
What is social engineering?
A type of computer virus
Manipulating people to obtain confidential information
A method of coding
A security protocol
Why is it important to train employees and students about social engineering?
To help understand how to give information online
To teach them coding skills
To improve customer service
To help them recognise and avoid manipulation tactics
What is the key difference between data and information?
Data is organized, while information is raw.
Data is raw, unprocessed facts, while information is processed and organized
Data is meaningful, while information is irrelevant.
Data and information are the same.
List the types of Social Engineering
What is malware?
A type of computer hardware
A protective software that blocks viruses
Malicious software designed to damage or steal information
A program to speed up your computer
List 3 different types of malware?
Which of these are types of malware?
Virus
Trojan
Firewall
Worm
What does malware do to a computer system?
Enhances system performance
Protects data from loss
Monitors hardware for maintenance
Infects the system to cause harm or steal data
What is a virus?
A software that protects against threats
A software that monitors user activity
A program that encrypts files for ransom
A harmful program that attaches to files and spreads when they are opened
What is a worm?
A type of malware that disguises itself as legitimate software
A malicious program that steals personal information
A program that replicates itself and spreads across networks without user intervention
A type of adware that displays unwanted ads
What is a Trojan?
A program that appears legitimate but harms the system once installed
Malware that replicates itself
A type of ransomware that demands payment
Software that monitors internet traffic
What is ransomware?
A program that collects data about user behaviour
Malware that encrypts files and demands payment to unlock them
Software that improves system performance
A type of adware that shows pop-up ads
What is spyware?
Software that blocks malicious websites
Malware that secretly tracks user activities and collects personal information
A type of antivirus software
A program that creates backups of data
What is adware?
A program that secures network connections
Malware that steals passwords
A type of worm that spreads through email attachments
Software that displays unwanted ads and can track user activity
How does malware commonly spread?
By downloading infected files
By clicking on harmless links
Through secure email attachments
By using trusted USB drives
What is one way malware can be spread through email?
Opening attachments from trusted sources
Ignoring spam messages
Opening email attachments from untrusted sources
Using strong passwords
What is a potential consequence of a malware infection?
Improved system speed
Unauthorised access to systems
Increased data storage
Enhanced security features
What financial risk can malware pose to individuals?
Free access to credit scores
Increased savings
Better investment opportunities
Financial losses and identity theft
How can data theft lead to identity theft?
By improving credit scores
By providing free access to bank accounts
By stealing personal information like National Insurance
By reducing online activity
What is one effective way to protect your computer from malware?
Downloading free software from unknown sources
Ignoring software updates
Using strong, unique passwords
Opening email attachments from strangers
How can regular software updates help protect against malware?
They slow down your computer
They introduce new malware
They require you to pay fees
They patch security vulnerabilities
What role does antivirus software play in malware protection?
It detects, blocks, and removes malware
It speeds up internet connections
It monitors social media activity
It creates backups of your files
How can firewalls help protect against malware?
By monitoring and controlling network traffic
By increasing download speeds
By shutting down your computer
By installing additional software
What is a best practice when it comes to email attachments?
Open all attachments without hesitation
Only open attachments from trusted sources
Download all attachments automatically
Ignore any email with attachments
What is malware?
A type of computer hardware
Harmful software designed to damage or steal information
A program to speed up your computer
A protective software that blocks viruses
Which of the following is NOT a type of malware?
Virus
Worm
Firewall
Trojan
How does malware commonly spread
By downloading infected files
Through regular software updates
By using antivirus software
By opening secure email attachments
What is ransomware?
Software that monitors user activity
Malware that encrypts files and demands payment to unlock them
A type of adware that displays unwanted ads
A program that protects against threats
Which of the following can lead to malware infection?
Clicking on malicious links
Using strong passwords
Updating software regularly
Scanning for viruses
How can regular software updates help protect against malware?
They introduce new malware
They patch security vulnerabilities
They slow down your computer
They require you to pay fees
What are some best practices students should follow to help protect school systems from malware?
What are some common types of cybersecurity threats?
Match the terms:
Virus
Needs user to execute
Worm
A type of malware that spreads through networks
Trojan
A program that pretends to be legitimate software
Spyware
Software that secretly monitors user activity
Ransomware
Malware that encrypts files and demands payment
A (a) is a type of malware that replicates itself and spreads to other files or programs, usually aiming to damage or delete data.
(b) is malware that doesn’t directly harm the system but instead gathers personal information about the user, such as passwords or browsing habits, and sends it to the attacker.
(c) is a type of malware disguised as legitimate software but secretly causes harm, such as deleting files or creating backdoors for attackers to access the system.
(d) is a type of malware that displays unwanted ads and redirects users to unwanted websites, often changing browser settings.
(e) is malware that infects a system, locks it, and demands payment to restore access to the user.
What is the difference between a brute force attack and a denial-of-service (DoS) attack?
What is a brute force attack?
A method to socially engineer victims
A technique used to gain unauthorised access by trying every possible password combination
An attack that uses malware to gain access to systems
A method of preventing unauthorized access to data
Why are weak passwords vulnerable to brute force attacks?
They are too complex to remember
They contain only numbers
They are often short and predictable
They are rarely changed
Why is a brute force attack effective? (Select multiple options)
It systematically tries all possible password combinations.
It can crack weak passwords that lack complexity.
It manipulates system administrators into disabling security features.
It doesn't require any advanced hacking skills to execute.
Which of these is a way to prevent against brute force attacks?
Using short passwords
Allowing unlimited login attempts
Disabling encryption
Enforcing account lockout after several failed attempts
How are passwords cracked?
By guessing based on personal information
Using pre-written scripts or tools to try every possible combination
By asking the system administrator
By writing secure code
Select which of these are the best practices to prevent brute force attacks?
Use multi-factor authentication (MFA)
Set weak passwords for easy recall
Implement CAPTCHAs to block bots
Allow passwords to be reused
Lists ways to protect against Brute
How does multi-factor authentication enhance security?
By requiring additional verification methods beyond just a password
By simplifying the login process
By making passwords more complex
By preventing all types of hacking
Which statement best describes ethical hackers?
They perform hacking without permission
They only work for large corporations
They create malware for financial gain
They use hacking skills to improve security with permission
Explain the role of ethical hackers in improving cybersecurity.
How do they use brute force techniques responsibly?
Discuss the potential consequences of unethical hacking. What impact can brute force attacks have on organizations and individuals?
Match the terms to their definitions
Ethical Hacker
Legally tests security systems
Unethical Hacker
Illegally breaches security
Brute Force Attack
Attempts to guess passwords
Permission
Obtains consent for testing
Social Engineering
Manipulates individuals for information
Ethical Hacker Vs Unethical
Uses brute force techniques to demonstrate vulnerabilities
Conducts penetration testing with permission
Implements security measures to protect systems
Educates organisations about cybersecurity risks
Develops security tools for public use
Adheres to ethical guidelines and legal standards
Accesses systems without permission
Distributes malware to compromise systems
Engages in identity theft
Conducts denial-of-service attacks
Exploits vulnerabilities for financial profit
Manipulates data for malicious purposes
Creates and sells hacking tools on the dark web
What is a DDoS attack?
A method to enhance server performance
An attack that aims to make a service unavailable by overwhelming it with traffic
A type of malware that infects computers
A security protocol for online transactions
What is a common motivation for hacktivism?
Who are script kiddies?
Explain how a DDoS attack can impact a business.
Describe the differences between hacktivism and traditional hacking.
Match the following terms with its definitions
DDoS Attack
A method that disrupts service by overwhelming traffic
Script Kiddies
Individuals who use existing computer scripts or tools to hack into computers.
Hacktivism
Cyber activism that aims to promote political agendas.
Brute Force Attack
An attack that involves trying many passwords until the correct one is found.
Phishing Attack
A fraudulent attempt to obtain sensitive information by disguising as a trustworthy entity.
Which of the following statements about Boolean logic are correct? (Select 3)
Boolean logic has two possible values: True and False
Boolean logic is a type of data
Boolean logic is used for making decisions
Boolean logic can have more than two values
Who invented Boolean logic and in which century was it invented?
George Boole, 1800s
Isaac Newton, 1700s
Alan Turing, 1900s
Charles Babbage, 1800s
Which of the following are Boolean operators?
AND
OR
NOT
ADD
The AND operator returns (a) if both operands are true.
Compare the AND and OR operators in Boolean logic. How do their results differ when evaluating two conditions?
The NOT gate reverses the value: NOT True becomes (a)
How does the use of the AND, OR, and NOT Boolean operators affect search results?
AND narrows results, OR broadens results, NOT excludes certain results.
AND broadens results, OR narrows results, NOT includes all results.
AND excludes results, OR narrows results, NOT broadens results.
AND and OR both exclude results, NOT includes all results.
Evaluate the Boolean expression: False AND NOT True → (a)
Which of the following are uses of Boolean logic?
Writing computer programs
Searching on the internet
Controlling devices and games
All of the above
In the given code example, what two conditions must be true for the message 'You can watch the movie.' to be printed?
The age must be 13 or more and the person must have a ticket.
The age must be less than 13 and the person must have a ticket.
The age must be 13 or more or the person must have a ticket.
The person must have a ticket only.
After learning about Boolean logic, what is one question you still have or something you would like to explore further?
What does the NOT operator do, in Boolean logic?
Which of the following statements best describes the role of Boolean logic in programming?
Boolean logic helps computers make decisions based on true/false values.
Boolean logic is only used for mathematical calculations.
Boolean logic is not important in programming languages.
Boolean logic is used only for storing data.
What is the key difference between data and information?
A) Data is organized, while information is raw.
B) Data is raw, unprocessed facts, while information is processed and organized.
C) Data is meaningful, while information is irrelevant.
D) Data and information are the same.
Which of the following is an example of data?
A) "John lives in London and is 60 years old.
B) "John Smith works in IT."
C) "60," "London," "John Smith."
D) "The temperature is 20°C."
Why is personal data valuable to individuals?
A) It can help track habits and make informed decisions.
B) It is always available for public use.
C) It has no practical use in daily life.
D) It is only valuable to businesses.
What is targeted marketing?
A) Using customer data to offer personalized ads and services.
B) Marketing only through social media.
C) Selling personal data to third parties without consent.
D) Advertising products without using any customer data.
Which of the following is an example of how businesses benefit from data?
A) Data helps businesses understand customer behavior and improve operations.
B) Businesses sell data to customers at a profit.
C) Businesses stop collecting data to avoid privacy issues.
D) Businesses delete all data after a purchase is made.
What is monetisation of data?
A) Encrypting data to make it more secure.
B) Analysing data for research purposes only.
C) Selling or using data to generate income for a company
D) Deleting data after it has been used.
How do companies use data for targeted marketing?
A) By guessing what customers might like.
B) By analyzing customer data to offer personalized ads and products.
C) By randomly assigning ads to users.
D) By ignoring customer preferences.
What is a common risk to data security?
A) Regular data backups
B) Installing antivirus software
C) Using strong passwords
D) Hacking and unauthorized access
How can human error cause data security risks?
A) Employees frequently change their passwords.
B) Personal data is shared with unauthorized individuals by mistake.
C) Data is stored securely in cloud systems.
D) Users report phishing emails.
Which of the following is a potential consequence of a data breach?
A) Stronger encryption standards
B) Increased productivity
C) Improved business reputation
D) Identity theft and financial loss
What happened in the Equifax data breach of 2017?
A) A hacker exploited weak cybersecurity, exposing the personal data of 147 million people.
B) Data was securely encrypted and protected.
C) Equifax successfully prevented all hacking attempts.
D) Equifax hired more cybersecurity professionals after the breach.
Why is encryption important in data security?
A) It organizes data
B) It improves data analysis.
C) It prevents unauthorized access by converting data into a coded format.
D) It deletes irrelevant data
Which of the following is an example of a data breach?
A) A company encrypts all its data.
B) A user installs updates to their operating system.
C) Employees receive regular cybersecurity training.
D) A hacker gains access to a company's customer database.
What is the main purpose of the Data Protection Act 2018?
A) To allow companies to sell personal data freely.
B) To ensure personal data is handled lawfully, fairly, and transparently.
C) To encourage companies to collect as much data as possible.
D) To prevent individuals from accessing their own data.
Which of the following is a key feature of the Data Protection Act 2018?
A) Organisations can process personal data without consent.
B) Individuals have the right to request the deletion of their personal data.
C) There are no restrictions on handling children's data.
D) Data breaches do not need to be reported.
How long do companies have to report a significant data breach under the Data Protection Act 2018?
A) 48 hours
B) 1 week
C) 72 hours
D) 1 month
What extra protection is provided for children's data under the Data Protection Act 2018?
A) Children's data can be collected without consent.
B) Parental or guardian consent is required to process children's data.
C) There are no special protections for children's data.
D) Children's data can be used for any purpose without restrictions.
What does GDPR stand for?
A) General Data Privacy Regulation
B) Global Data Protection Regulation
C) General Data Protection Regulation
D) Government Data Protection Regulation
Who does GDPR apply to?
A) Only companies based in the European Union.
B) Any company that collects personal data from EU citizens, regardless of location.
C) Only government organizations in the EU.
D) Only companies outside the EU.
Which of the following is an example of turning data into information?
A) Recording temperatures: "20°C, 25°C, 22°C"
B) "The average temperature this week is 22°C based on daily readings."
C) Listing customer ages: "35, 42, 29, 50"
D) Collecting phone numbers: "123-456-7890, 234-567-8901"
100
TRUE
"D"
What is a variable?
A storage location of memory which can change
A random area to store things in.
Something that changes
Something that can only store numbers
What is a Constant?
A storage location of memory which does not change
A random area to store things in.
Something that changes
Something that can only store numbers
Which variable uses a integer data type?
password
passwordScore
passwordLength
Which variable uses a string data type?
password
passwordScore
passwordLength
What is the primary purpose of cybersecurity?
To manage software development processes
To protect computers, networks, and data from unauthorised access or damage
To create new hardware for computers
To monitor social media usage of individuals
What is Social Engineering?
A type of computer virus
A method of coding
Manipulating people to obtain confidential information
A security protocol
Which of the following do yis an example of phishing?
Flooding a website with traffic
Sending a fake email to obtain sensitive information
Stealing someone’s login credentials in person
Installing a virus on a computer
Can you spot whether this is a Phishing email. If so, why?
What are the issues you can identify....
This email is what type of attack?
Shouldering
Blagging
Phishing
Hacking
What would be a key indicator of a phishing email?
a new email from a friend arranging a meet
unexpected email with request for information
work email from a client with personal attachments
a email from family with a picture
An attack in which the perpetrator invents a scenario in order to convince the victim to give them data or money, is?
Blagging
Phishing
Cyberbullying
Shouldering
What is one way somebody could protect themselves from shouldering?
share your pin with someone you trust
create a pin that is easy to remember
have a pin that is the same as your friends
be aware of who is around you
Which of the following describe 'Social engineering'? (select 2 answers)
Confusing people so they give-up information
Manipulating/Tricking people to give-up information
Assaulting people so they give up information
Paying people so they give-up goods and services
Which of the following is not a social engineering technique?
Blagging
Hacking
Phishing
Shouldering
Which of the following most closely matches the definition of 'Blagging'?
Sending an e-mail to a user pretending to be someone else
Hacking a person's computer
Tricking a person into revealing some personal information by creating a fake scenario
Observing a legitimate user entering a password
Setting up a fake website that looks like an official website
Which statement best describes the definition of the term ‘social engineering'
The art of hacking a network to access confidential information.
The art of hacking a network to access public information.
The art of manipulating people so they give up confidential information.
The art of manipulating people so they give up public information.
What is encryption?
A process that converts data into a code to prevent unauthorised access
A way to delete files permanently
A method of compressing files
A type of software used for data recovery
Which action helps minimise the risk of social engineering attacks?
Sharing personal information online
Using weak passwords
Reporting suspicious activity
Ignoring security updates
