wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Cybersecurity Threats Quiz

Total questions: 98

Worksheet time: 49mins

Name
Class
Date
1.

A hospital employee receives an email claiming to be from IT, asking them to verify login credentials through a link. What kind of threat does this represent?

a)

System configuration error

b)

Credential stuffing

c)

Phishing attack

d)

Firewall misconfiguration

2.

During a cyber audit, a company finds that many employees use the same password across systems. What vulnerability does this highlight?

a)

Cross-platform integration

b)

Human error

c)

Encryption protocol weakness

d)

Database overflow

3.

A user downloads a free mobile app that silently records keystrokes. What type of malware is this?

a)

Rootkit

b)

Adware

c)

Keylogger

d)

Spyware

4.

After opening a suspicious attachment, an employee finds all files on their PC encrypted, with a ransom note demanding cryptocurrency. What is this attack known as?

a)

Phishing

b)

Trojan

c)

Ransomware

d)

Data interception

5.

A government database is breached through an outdated system that had not been patched in years. What was the most likely root cause?

a)

Insider sabotage

b)

Misconfigured DNS

c)

Unpatched vulnerability

d)

Power outage

6.

A cybercriminal intercepts data sent between two parties without them noticing. What type of attack is this?

a)

Replay attack

b)

DDoS

c)

MITM (Man-in-the-Middle)

d)

Brute-force attack

7.

A disgruntled ex-employee remotely accesses internal systems using valid credentials that were never revoked. Which threat category does this fall under?

a)

Script kiddie

b)

Insider threat

c)

Social engineering

d)

Physical intrusion

8.

Your organization's website goes offline for several hours due to an overwhelming flood of traffic. What type of attack does this suggest?

a)

Malware injection

b)

Denial of Service

c)

Port scanning

d)

ARP poisoning

9.

A hotel's digital key system is locked down by attackers who demand Bitcoin. What element is primarily being exploited?

a)

Power infrastructure

b)

Access control

c)

Guest data logs

d)

Hotel reviews

10.

A hacker uses publicly available information from a company's 'About Us' page to guess employee email addresses and target them. Which phase of an attack is this?

a)

Delivery

b)

Weaponization

c)

Reconnaissance

d)

Exploitation

11.

A user reports a pop-up asking for admin credentials immediately after visiting a compromised website. What is this technique likely targeting?

a)

DNS hijacking

b)

Privilege escalation

c)

Firewall spoofing

d)

Packet duplication

12.

After clicking a deceptive link, a user's browser begins redirecting to unknown search engines and spam websites. What type of malware might be involved?

a)

Botnet

b)

Ransomware

c)

Browser hijacker

d)

Logic bomb

13.

During a cybersecurity awareness training, employees are taught to hover over links in emails before clicking. What is this practice meant to prevent?

a)

SQL Injection

b)

Phishing

c)

DDoS

d)

Wi-Fi sniffing

14.

A manufacturing plant experiences a shutdown after hackers manipulate temperature sensors remotely. What is being targeted here?

a)

File system

b)

IoT infrastructure

c)

Login sessions

d)

Email servers

15.

An organization installs software that monitors network traffic to identify anomalies. What kind of system is this?

a)

Honeypot

b)

Penetration scanner

c)

Intrusion Detection System

d)

Key exchange monitor

16.

A CEO receives a convincing email that appears to be from the CFO requesting a wire transfer. This is an example of:

a)

Technical audit

b)

CEO fraud

c)

Packet sniffing

d)

Data mining

17.

A cybercriminal gains access by guessing a password based on social media clues. What tactic was used?

a)

Credential stuffing

b)

Cross-site scripting

c)

Brute-force guessing

d)

Social engineering

18.

A hacker installs code that remains dormant until triggered by a specific condition. What is this called?

a)

Rootkit

b)

Logic bomb

c)

Spyware

d)

Backdoor

19.

Employees at a company are required to use a second verification method after password entry. This method is used to improve:

a)

Accessibility

b)

Availability

c)

Integrity

d)

Authentication

20.

After a breach, an IT analyst investigates the origin and timeline of access. What activity is this?

a)

Attribution

b)

Data scraping

c)

Firewall routing

d)

API monitoring

21.

A hacker uses a public USB charging station to install malware on connected devices. What kind of attack does this represent?

a)

Supply chain

b)

Juice jacking

c)

Credential poisoning

d)

Packet injection

22.

During penetration testing, testers find a vulnerability in the way user roles are assigned. This is a weakness in:

a)

Network topology

b)

Authorization control

c)

Physical security

d)

Data encryption

23.

A news site is temporarily defaced with a politically charged message. What is the likely motive behind the attack?

a)

Financial extortion

b)

Activism

c)

Intellectual property theft

d)

Cyberespionage

24.

A system starts sending traffic to multiple random IP addresses after a suspicious update. This behavior suggests:

a)

Phishing infection

b)

Adware spread

c)

Botnet recruitment

d)

Keylogging

25.

A user installs a seemingly useful browser extension that silently monitors all inputs. This is a form of:

a)

Keylogging

b)

Fileless malware

c)

Worm

d)

Port scanning

26.

A data center is physically breached and routers are stolen. This incident involves a violation of:

a)

Logical access

b)

User roles

c)

Physical security

d)

Application layer

27.

After a new regulation, organizations are forced to disclose breaches within 72 hours. What type of policy is this?

a)

Compliance-based

b)

Cyberwarfare doctrine

c)

Anti-trust

d)

Licensing

28.

A cybersecurity analyst uses the MITRE ATT&CK framework. What is their main goal?

a)

Build a network topology

b)

Track adversarial behaviors

c)

Optimize router speeds

d)

Generate incident response forms

29.

A hacker gains access through an unsecured third-party vendor account. What kind of vulnerability is this?

a)

Insider-based

b)

Chain-of-trust

c)

Logic flaw

d)

Session timeout

30.

A company implements a security model where access is granted based on job roles. What model is this?

a)

ABAC

b)

DAC

c)

RBAC

d)

MAC

31.

A user receives a phone call from someone claiming to be IT support asking for credentials. What kind of attack is this?

a)

Password spraying

b)

Vishing

c)

Credential harvesting

d)

Watering hole

32.

A team installs decoy systems to lure and study attackers. These systems are known as:

a)

Proxies

b)

IDS

c)

Honeypots

d)

Firewalls

33.

A file is downloaded that appears benign but opens a backdoor when executed. What type of malware is this?

a)

Ransomware

b)

Trojan

c)

Worm

d)

Adware

34.

A hacker bypasses a system's login by exploiting default admin credentials. This is a failure in:

a)

Port forwarding

b)

Patch management

c)

Configuration hygiene

d)

VPN settings

35.

A company uses artificial intelligence to detect threats based on traffic patterns. This is an example of:

a)

Behavioral analytics

b)

Blockchain verification

c)

Semantic filtering

d)

Traditional scanning

36.

A cyberattack shuts down a region's power supply. Which sector is being attacked?

a)

Media

b)

Industrial Control Systems

c)

Finance

d)

Retail

37.

A policymaker argues for stricter encryption rules after a government leak. This is a reaction to issues with:

a)

Confidentiality

b)

System uptime

c)

Advertising

d)

Cloud storage costs

38.

A military organization uses satellites and sensors for early warning cyber threats. This approach is part of:

a)

IoT analytics

b)

Threat intelligence

c)

Data replication

d)

UX telemetry

39.

An attacker copies encrypted data hoping to break it later. This is called:

a)

Side-channel attack

b)

Sniffing

c)

Store-and-decrypt

d)

Data exfiltration

40.

During a conference, a USB drive is distributed containing malware. This is a form of:

a)

Software as a Service

b)

Socially-engineered delivery

c)

Ad injection

d)

Passive threat

41.

A cybercriminal installs software that spreads automatically via email contacts. What type of malware is this?

a)

Virus

b)

Worm

c)

Rootkit

d)

Logic bomb

42.

A company requires encryption of all customer data in storage and transit. This aims to protect:

a)

Authorization

b)

Confidentiality

c)

Redundancy

d)

Availability

43.

An online banking platform uses geolocation to block access from unknown regions. This is a form of:

a)

Data caching

b)

Access control

c)

DDoS prevention

d)

Authentication

44.

A ransomware group avoids detection by using legitimate Windows processes. What is this tactic called?

a)

Obfuscation

b)

Malware chaining

c)

Living off the land

d)

Code injection

45.

An attacker replaces software updates with malicious versions. This is an example of:

a)

Whaling

b)

Drive-by download

c)

Supply chain attack

d)

File injection

46.

A threat actor inserts malicious code into a login page that captures credentials. This attack is known as:

a)

Session hijack

b)

Cross-site scripting

c)

Credential mirroring

d)

Phishing

47.

A company wants to reduce the likelihood of employees falling for scams. What should they prioritize?

a)

Hardware upgrades

b)

Employee awareness training

c)

Open-source contributions

d)

Outsourced risk audit

48.

A hacker waits silently in a network for weeks before launching an attack. This behavior characterizes a:

a)

Flash exploit

b)

Active reconnaissance

c)

Zero-day

d)

APT (Advanced Persistent Threat)

49.

A national cybersecurity law mandates encryption standards for private companies. This is an example of:

a)

Risk acceptance

b)

Regulation

c)

DNS protection

d)

Industry best practice

50.

A threat actor steals information and sells it on the dark web. This threat is mostly motivated by:

a)

Fame

b)

Revenge

c)

Curiosity

d)

Financial gain

51.

What aspect of cybersecurity focuses on preventing data from being accessed by unauthorized individuals?

a)

Port forwarding

b)

Data replication

c)

Confidentiality

d)

Availability

52.

Which of the following is a behavior that improves cybersecurity at the individual level?

a)

Ignoring updates

b)

Reusing old passwords

c)

Using unique and strong passwords

d)

Disabling firewall

53.

What is considered part of the "attack surface" of an organization?

a)

Only physical entry points

b)

Only the website homepage

c)

All potential vulnerabilities in systems and people

d)

Only external attacks

54.

Who is responsible for cybersecurity in an organization?

a)

Only IT professionals

b)

Only upper management

c)

Everyone using the system

d)

Only the government

55.

Which of the following best describes phishing?

a)

A backup technique

b)

A form of file sharing

c)

A deceptive attempt to gain sensitive info

d)

A way to speed up networks

56.

Which tool helps monitor for malicious activity on a network?

a)

Spreadsheet

b)

Intrusion Detection System

c)

Text Editor

d)

Word Processor

57.

What is the role of firewalls in cybersecurity?

a)

Improve loading speed

b)

Translate web pages

c)

Block unauthorized access

d)

Print logs

58.

What is a strong practice for protecting your online accounts?

a)

Sharing passwords with trusted friends

b)

Writing passwords on a sticky note

c)

Enabling two-factor authentication

d)

Using the same password for all accounts

59.

What type of threat often comes through email attachments or suspicious links?

a)

Firmware

b)

Malware

c)

Cloudware

d)

Hyperlinks

60.

What is the purpose of antivirus software?

a)

To build websites

b)

To check grammar

c)

To detect and prevent malicious software

d)

To clean the desktop

61.

What is the simplest reason to keep your software up to date?

a)

To make it look better

b)

To match the latest trends

c)

To fix bugs and close security holes

d)

To reset passwords

62.

Which of the following could be a human factor vulnerability?

a)

High-speed internet

b)

A weak password

c)

A large hard drive

d)

A VPN connection

63.

Which actor is least likely to follow formal rules but may cause significant damage?

a)

IT admin

b)

Hacker

c)

Support staff

d)

HR officer

64.

How might cybercriminals access systems through social means?

a)

Malware updates

b)

Physical lockpicking

c)

Social engineering

d)

Software crashes

65.

What's a potential result of a cyberattack?

a)

Increase in internet speed

b)

Better website traffic

c)

Data loss or theft

d)

Improved graphics

66.

What kind of information is at risk in a cybersecurity breach?

a)

Only graphics and colors

b)

Random generated codes

c)

Sensitive or personal data

d)

Local news articles

67.

Who uses cybersecurity frameworks like NIST?

a)

Only gamers

b)

Policy makers and organizations

c)

Music producers

d)

Graphic designers

68.

What makes cyber threats particularly difficult to manage?

a)

They are limited to hardware

b)

They don't evolve over time

c)

They can come from humans, technology, or both

d)

They're easy to eliminate with a single tool

69.

What is a common reason hackers exploit systems?

a)

To fix them

b)

For educational purposes only

c)

For financial gain or disruption

d)

To learn coding

70.

Which method is commonly used to trick people into revealing confidential information?

a)

Fragmentation

b)

Network throttling

c)

Phishing

d)

Clustering

71.

What term refers to a weakness in a system that can be exploited by a threat actor?

a)

Patch

b)

Firewall

c)

Vulnerability

d)

Node

72.

What describes the act of identifying and evaluating cybersecurity threats before they happen?

a)

Debugging

b)

Forecasting

c)

Risk Management

d)

Monitoring

73.

Which actor group typically works for a government and engages in cyber operations?

a)

Freelancers

b)

Nation-state actors

c)

Bloggers

d)

Digital marketers

74.

What phase of hacking involves sending the exploit to the victim?

a)

Command & Control

b)

Installation

c)

Delivery

d)

Exploitation

75.

Which of these is a benefit of implementing cybersecurity policies at the national level?

a)

Preventing tax fraud

b)

Regulating internet speed

c)

Protecting critical infrastructure

d)

Managing employment

76.

What is one ethical dilemma faced in cybersecurity governance?

a)

Encouraging user training

b)

Disclosing system updates

c)

Whether to reveal or hide known vulnerabilities

d)

Upgrading device storage

77.

Scenario: A cybersecurity analyst detects unusual outbound traffic. What is the most likely response?

a)

Buy new routers

b)

Turn off Wi-Fi

c)

Investigate potential data exfiltration

d)

Switch browsers

78.

What type of hacker attacks systems to protest political or social causes?

a)

State actor

b)

Hobbyist

c)

Hacktivist

d)

Journalist

79.

What does a holistic cybersecurity approach involve?

a)

Focusing only on antivirus

b)

Addressing tech, human, and organizational risks together

c)

Isolating systems

d)

Avoiding policy making

80.

What's a challenge with attributing a cyberattack?

a)

Attackers are always in the same country

b)

Data is deleted automatically

c)

Use of proxies and fake identities

d)

Attackers use real names

81.

Scenario: A media company experiences a DoS attack. What happens?

a)

System performance improves

b)

Employees receive bonuses

c)

Service becomes unavailable to users

d)

Passwords get changed

82.

What is weaponization in the hacking process?

a)

Changing user credentials

b)

Exploiting software bugs

c)

Creating or customizing tools to exploit a vulnerability

d)

Delivering a phishing email

83.

What's an example of a cascading effect in cybersecurity?

a)

A single computer crashing

b)

One attack triggering failures in connected systems

c)

Turning off Wi-Fi

d)

Changing a password

84.

Why are critical infrastructure sectors high-risk targets?

a)

They have better performance

b)

They use outdated logos

c)

Disruption can have national consequences

d)

They're easily accessible

85.

What tool is used to detect suspicious activity and alert admins?

a)

Microsoft Word

b)

Cloud Backup

c)

Intrusion Detection System

d)

Content Management System

86.

What makes malware-less attacks harder to detect?

a)

They use known viruses

b)

They crash systems

c)

They don't involve traditional malware

d)

They occur on local networks

87.

What describes cyber attacks that manipulate individuals through deception?

a)

Binary exploitation

b)

Network spoofing

c)

Social engineering

d)

Signal jamming

88.

What is the most likely motivation behind ransomware?

a)

Curiosity

b)

Education

c)

Financial gain

d)

Protest

89.

Why should policymakers collaborate internationally?

a)

To increase ad revenue

b)

To improve UX design

c)

To address cross-border cybercrime

d)

To standardize fonts

90.

Which cyber threat involves impersonating trusted contacts to obtain information?

a)

Keylogging

b)

DoS

c)

Spoofing

d)

System crash

91.

What does the term "cybersecurity policy" generally include?

a)

Pricing models

b)

Guidelines and frameworks to secure systems

c)

ISP speed recommendations

d)

UI design patterns

92.

What is the biggest limitation of relying solely on technical defenses?

a)

They're too cheap

b)

They replace human decision-making

c)

They ignore human and organizational factors

d)

They use too much data

93.

Scenario: A hacker uses tools from the dark web to infiltrate a government database without malware. What is this an example of?

a)

Phishing

b)

Spoofing

c)

Malware-less advanced persistent threat

d)

Ransomware

94.

Why is reconnaissance important in the hacking process?

a)

To destroy logs

b)

To infect files

c)

To gather data about a target system

d)

To fake IP addresses

95.

What is one role of national cybersecurity strategies?

a)

Promote local artists

b)

Control web design

c)

Protect infrastructure and ensure cooperation

d)

Monitor YouTube content

96.

What makes cybercrime attractive to organized groups?

a)

Legal immunity

b)

High return and low risk

c)

Minimal tech requirements

d)

Government support

97.

Why is understanding TTPs (Tactics, Techniques, Procedures) important for defense teams?

a)

It helps identify fonts

b)

It allows faster payment

c)

It aids in anticipating and responding to attacks

d)

It boosts software design

98.

How can cybersecurity incidents affect a nation's economy?

a)

They improve market value

b)

They speed up internet

c)

They cause financial disruptions

d)

They enhance tourism