wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Cybersecurity Scenarios and Tools Quiz

Total questions: 21

Worksheet time: 11mins

Name
Class
Date
1.

You are analyzing a Nessus scan result and discover that port 4444 is open with a netcat listener active. What should you do first?

a)

Block all outbound internet traffic

b)

Investigate for potential backdoor access

c)

Reboot the machine immediately

d)

Disable all user accounts

2.

A security analyst is working for a small business with a Linux-based infrastructure and prefers open-source tools. Which scanner should they choose?

a)

Qualys

b)

Nessus

c)

OpenVAS

d)

Maltego

3.

Your security team wants to assess how employees respond to deceptive emails. Which method should they use?

a)

Vulnerability scan

b)

Packet sniffing

c)

Phishing campaign

d)

Port scanning

4.

An employee reports a suspicious shortened URL. What’s the best immediate step?

a)

Use an un-shortening tool to preview it

b)

Click it from an isolated system

c)

Block the link at the firewall

d)

Report it to the DNS provider

5.

Which nmap scan type is used for stealthy TCP scanning?

a)

-sT

b)

-sS

c)

-sU

d)

-O

6.

A user visits wwwgoogle.com thinking it’s Google. What URL obfuscation technique is being used?

a)

Character Swapping

b)

QR Code

c)

URL Redirect

d)

URL Doppelganger

7.

You want to use nmap to detect the OS, identify logged-in users, and discover vulnerabilities. What should you enable?

a)

Nmap Scripting Engine (NSE)

b)

OS fingerprinting

c)

Packet sniffing

d)

Port scan

8.

You are tasked with assessing a new web application for vulnerabilities. The tool you're using intercepts client-server traffic and allows you to analyze input validation. Which tool are you most likely using?

a)

Burp Suite

b)

Nmap

c)

Nikto

d)

Maltego

9.

A security analyst is scanning a web server using a command-line tool that provides reports on outdated software, insecure configurations, and common vulnerabilities. Which tool is best suited for this task?

a)

Angry IP Scanner

b)

Nikto

c)

OWASP ZAP

d)

Recon-ng

10.

While running a vulnerability scan, you find a critical risk in a system that stores payroll data. According to proper prioritization processes, which factor should weigh most heavily in deciding your next step?

a)

Number of users on the system

b)

Ease of use of the vulnerability scanner

c)

Age of the vulnerability

d)

Asset value of the system

11.

Which of the following best describes a zero-day vulnerability?

a)

A vulnerability discovered by the organization’s red team

b)

A known vulnerability with a publicly available patch

c)

An unpatched vulnerability discovered by attackers before developers

d)

A bug found during normal system operation

12.

You're analyzing a suspicious link embedded in a phishing email. It appears obfuscated and redirects to an unexpected site. What type of indicator is this?

a)

Other indicator of malicious activity

b)

External context indicator

c)

Application-related

d)

Validation false positive

13.

Which vulnerability scanner provides both automated scanning and allows for manual web application testing, and is maintained by OWASP?

a)

OpenVAS

b)

Metasploit

c)

Zed Attack Proxy (ZAP)

d)

Arachni

14.

A vulnerability scan shows a high number of flagged issues, but further analysis shows many of them are not actually exploitable. What process is needed to refine the results?

a)

Obfuscation

b)

Validation

c)

Weaponization

d)

Mapping

15.

A security engineer is reverse engineering a suspicious binary using a tool that allows for instruction-by-instruction analysis. Which tool is being used?

a)

Burp Suite

b)

Metasploit

c)

ZAP

d)

Immunity Debugger

16.

A security analyst is tasked with auditing a cloud environment for misconfigurations. The company uses a multi-cloud deployment, but the analyst needs a tool that can scan across various cloud platforms, not just AWS. Which tool should the analyst use?

a)

Pacu

b)

ScoutSuite

c)

Prowler

d)

Nessus

17.

Which cloud assessment tool is specifically designed for evaluating AWS environments based on AWS security best practices?

a)

Prowler

b)

Pacu

c)

ScoutSuite

d)

Qualys

18.

A penetration tester is hired to perform post-exploitation testing on a client’s AWS cloud environment after a misconfigured IAM role was discovered. Which tool would best support this activity?

a)

Burp Suite

b)

ScoutSuite

c)

Pacu

d)

Wireshark

19.

True or False: Systems running on cloud infrastructure are always more secure than when they run on-premises due to the provider’s responsibility.

a)

True

b)

False

20.

A cloud administrator is interpreting output from a ScoutSuite scan. What type of information should the admin expect to find?

a)

Real-time malware alerts

b)

Firewall port scan results

c)

Exploitation scripts

d)

Misconfigurations in cloud services

21.
a)

Attack

b)

Vulnerability

c)

Threat

d)

Exploit