WorksheetsCybersecurity Threats Quiz
Total questions: 98
Worksheet time: 49mins
A hospital employee receives an email claiming to be from IT, asking them to verify login credentials through a link. What kind of threat does this represent?
System configuration error
Credential stuffing
Phishing attack
Firewall misconfiguration
During a cyber audit, a company finds that many employees use the same password across systems. What vulnerability does this highlight?
Cross-platform integration
Human error
Encryption protocol weakness
Database overflow
A user downloads a free mobile app that silently records keystrokes. What type of malware is this?
Rootkit
Adware
Keylogger
Spyware
After opening a suspicious attachment, an employee finds all files on their PC encrypted, with a ransom note demanding cryptocurrency. What is this attack known as?
Phishing
Trojan
Ransomware
Data interception
A government database is breached through an outdated system that had not been patched in years. What was the most likely root cause?
Insider sabotage
Misconfigured DNS
Unpatched vulnerability
Power outage
A cybercriminal intercepts data sent between two parties without them noticing. What type of attack is this?
Replay attack
DDoS
MITM (Man-in-the-Middle)
Brute-force attack
A disgruntled ex-employee remotely accesses internal systems using valid credentials that were never revoked. Which threat category does this fall under?
Script kiddie
Insider threat
Social engineering
Physical intrusion
Your organization's website goes offline for several hours due to an overwhelming flood of traffic. What type of attack does this suggest?
Malware injection
Denial of Service
Port scanning
ARP poisoning
A hotel's digital key system is locked down by attackers who demand Bitcoin. What element is primarily being exploited?
Power infrastructure
Access control
Guest data logs
Hotel reviews
A hacker uses publicly available information from a company's 'About Us' page to guess employee email addresses and target them. Which phase of an attack is this?
Delivery
Weaponization
Reconnaissance
Exploitation
A user reports a pop-up asking for admin credentials immediately after visiting a compromised website. What is this technique likely targeting?
DNS hijacking
Privilege escalation
Firewall spoofing
Packet duplication
After clicking a deceptive link, a user's browser begins redirecting to unknown search engines and spam websites. What type of malware might be involved?
Botnet
Ransomware
Browser hijacker
Logic bomb
During a cybersecurity awareness training, employees are taught to hover over links in emails before clicking. What is this practice meant to prevent?
SQL Injection
Phishing
DDoS
Wi-Fi sniffing
A manufacturing plant experiences a shutdown after hackers manipulate temperature sensors remotely. What is being targeted here?
File system
IoT infrastructure
Login sessions
Email servers
An organization installs software that monitors network traffic to identify anomalies. What kind of system is this?
Honeypot
Penetration scanner
Intrusion Detection System
Key exchange monitor
A CEO receives a convincing email that appears to be from the CFO requesting a wire transfer. This is an example of:
Technical audit
CEO fraud
Packet sniffing
Data mining
A cybercriminal gains access by guessing a password based on social media clues. What tactic was used?
Credential stuffing
Cross-site scripting
Brute-force guessing
Social engineering
A hacker installs code that remains dormant until triggered by a specific condition. What is this called?
Rootkit
Logic bomb
Spyware
Backdoor
Employees at a company are required to use a second verification method after password entry. This method is used to improve:
Accessibility
Availability
Integrity
Authentication
After a breach, an IT analyst investigates the origin and timeline of access. What activity is this?
Attribution
Data scraping
Firewall routing
API monitoring
A hacker uses a public USB charging station to install malware on connected devices. What kind of attack does this represent?
Supply chain
Juice jacking
Credential poisoning
Packet injection
During penetration testing, testers find a vulnerability in the way user roles are assigned. This is a weakness in:
Network topology
Authorization control
Physical security
Data encryption
A news site is temporarily defaced with a politically charged message. What is the likely motive behind the attack?
Financial extortion
Activism
Intellectual property theft
Cyberespionage
A system starts sending traffic to multiple random IP addresses after a suspicious update. This behavior suggests:
Phishing infection
Adware spread
Botnet recruitment
Keylogging
A user installs a seemingly useful browser extension that silently monitors all inputs. This is a form of:
Keylogging
Fileless malware
Worm
Port scanning
A data center is physically breached and routers are stolen. This incident involves a violation of:
Logical access
User roles
Physical security
Application layer
After a new regulation, organizations are forced to disclose breaches within 72 hours. What type of policy is this?
Compliance-based
Cyberwarfare doctrine
Anti-trust
Licensing
A cybersecurity analyst uses the MITRE ATT&CK framework. What is their main goal?
Build a network topology
Track adversarial behaviors
Optimize router speeds
Generate incident response forms
A hacker gains access through an unsecured third-party vendor account. What kind of vulnerability is this?
Insider-based
Chain-of-trust
Logic flaw
Session timeout
A company implements a security model where access is granted based on job roles. What model is this?
ABAC
DAC
RBAC
MAC
A user receives a phone call from someone claiming to be IT support asking for credentials. What kind of attack is this?
Password spraying
Vishing
Credential harvesting
Watering hole
A team installs decoy systems to lure and study attackers. These systems are known as:
Proxies
IDS
Honeypots
Firewalls
A file is downloaded that appears benign but opens a backdoor when executed. What type of malware is this?
Ransomware
Trojan
Worm
Adware
A hacker bypasses a system's login by exploiting default admin credentials. This is a failure in:
Port forwarding
Patch management
Configuration hygiene
VPN settings
A company uses artificial intelligence to detect threats based on traffic patterns. This is an example of:
Behavioral analytics
Blockchain verification
Semantic filtering
Traditional scanning
A cyberattack shuts down a region's power supply. Which sector is being attacked?
Media
Industrial Control Systems
Finance
Retail
A policymaker argues for stricter encryption rules after a government leak. This is a reaction to issues with:
Confidentiality
System uptime
Advertising
Cloud storage costs
A military organization uses satellites and sensors for early warning cyber threats. This approach is part of:
IoT analytics
Threat intelligence
Data replication
UX telemetry
An attacker copies encrypted data hoping to break it later. This is called:
Side-channel attack
Sniffing
Store-and-decrypt
Data exfiltration
During a conference, a USB drive is distributed containing malware. This is a form of:
Software as a Service
Socially-engineered delivery
Ad injection
Passive threat
A cybercriminal installs software that spreads automatically via email contacts. What type of malware is this?
Virus
Worm
Rootkit
Logic bomb
A company requires encryption of all customer data in storage and transit. This aims to protect:
Authorization
Confidentiality
Redundancy
Availability
An online banking platform uses geolocation to block access from unknown regions. This is a form of:
Data caching
Access control
DDoS prevention
Authentication
A ransomware group avoids detection by using legitimate Windows processes. What is this tactic called?
Obfuscation
Malware chaining
Living off the land
Code injection
An attacker replaces software updates with malicious versions. This is an example of:
Whaling
Drive-by download
Supply chain attack
File injection
A threat actor inserts malicious code into a login page that captures credentials. This attack is known as:
Session hijack
Cross-site scripting
Credential mirroring
Phishing
A company wants to reduce the likelihood of employees falling for scams. What should they prioritize?
Hardware upgrades
Employee awareness training
Open-source contributions
Outsourced risk audit
A hacker waits silently in a network for weeks before launching an attack. This behavior characterizes a:
Flash exploit
Active reconnaissance
Zero-day
APT (Advanced Persistent Threat)
A national cybersecurity law mandates encryption standards for private companies. This is an example of:
Risk acceptance
Regulation
DNS protection
Industry best practice
A threat actor steals information and sells it on the dark web. This threat is mostly motivated by:
Fame
Revenge
Curiosity
Financial gain
What aspect of cybersecurity focuses on preventing data from being accessed by unauthorized individuals?
Port forwarding
Data replication
Confidentiality
Availability
Which of the following is a behavior that improves cybersecurity at the individual level?
Ignoring updates
Reusing old passwords
Using unique and strong passwords
Disabling firewall
What is considered part of the "attack surface" of an organization?
Only physical entry points
Only the website homepage
All potential vulnerabilities in systems and people
Only external attacks
Who is responsible for cybersecurity in an organization?
Only IT professionals
Only upper management
Everyone using the system
Only the government
Which of the following best describes phishing?
A backup technique
A form of file sharing
A deceptive attempt to gain sensitive info
A way to speed up networks
Which tool helps monitor for malicious activity on a network?
Spreadsheet
Intrusion Detection System
Text Editor
Word Processor
What is the role of firewalls in cybersecurity?
Improve loading speed
Translate web pages
Block unauthorized access
Print logs
What is a strong practice for protecting your online accounts?
Sharing passwords with trusted friends
Writing passwords on a sticky note
Enabling two-factor authentication
Using the same password for all accounts
What type of threat often comes through email attachments or suspicious links?
Firmware
Malware
Cloudware
Hyperlinks
What is the purpose of antivirus software?
To build websites
To check grammar
To detect and prevent malicious software
To clean the desktop
What is the simplest reason to keep your software up to date?
To make it look better
To match the latest trends
To fix bugs and close security holes
To reset passwords
Which of the following could be a human factor vulnerability?
High-speed internet
A weak password
A large hard drive
A VPN connection
Which actor is least likely to follow formal rules but may cause significant damage?
IT admin
Hacker
Support staff
HR officer
How might cybercriminals access systems through social means?
Malware updates
Physical lockpicking
Social engineering
Software crashes
What's a potential result of a cyberattack?
Increase in internet speed
Better website traffic
Data loss or theft
Improved graphics
What kind of information is at risk in a cybersecurity breach?
Only graphics and colors
Random generated codes
Sensitive or personal data
Local news articles
Who uses cybersecurity frameworks like NIST?
Only gamers
Policy makers and organizations
Music producers
Graphic designers
What makes cyber threats particularly difficult to manage?
They are limited to hardware
They don't evolve over time
They can come from humans, technology, or both
They're easy to eliminate with a single tool
What is a common reason hackers exploit systems?
To fix them
For educational purposes only
For financial gain or disruption
To learn coding
Which method is commonly used to trick people into revealing confidential information?
Fragmentation
Network throttling
Phishing
Clustering
What term refers to a weakness in a system that can be exploited by a threat actor?
Patch
Firewall
Vulnerability
Node
What describes the act of identifying and evaluating cybersecurity threats before they happen?
Debugging
Forecasting
Risk Management
Monitoring
Which actor group typically works for a government and engages in cyber operations?
Freelancers
Nation-state actors
Bloggers
Digital marketers
What phase of hacking involves sending the exploit to the victim?
Command & Control
Installation
Delivery
Exploitation
Which of these is a benefit of implementing cybersecurity policies at the national level?
Preventing tax fraud
Regulating internet speed
Protecting critical infrastructure
Managing employment
What is one ethical dilemma faced in cybersecurity governance?
Encouraging user training
Disclosing system updates
Whether to reveal or hide known vulnerabilities
Upgrading device storage
Scenario: A cybersecurity analyst detects unusual outbound traffic. What is the most likely response?
Buy new routers
Turn off Wi-Fi
Investigate potential data exfiltration
Switch browsers
What type of hacker attacks systems to protest political or social causes?
State actor
Hobbyist
Hacktivist
Journalist
What does a holistic cybersecurity approach involve?
Focusing only on antivirus
Addressing tech, human, and organizational risks together
Isolating systems
Avoiding policy making
What's a challenge with attributing a cyberattack?
Attackers are always in the same country
Data is deleted automatically
Use of proxies and fake identities
Attackers use real names
Scenario: A media company experiences a DoS attack. What happens?
System performance improves
Employees receive bonuses
Service becomes unavailable to users
Passwords get changed
What is weaponization in the hacking process?
Changing user credentials
Exploiting software bugs
Creating or customizing tools to exploit a vulnerability
Delivering a phishing email
What's an example of a cascading effect in cybersecurity?
A single computer crashing
One attack triggering failures in connected systems
Turning off Wi-Fi
Changing a password
Why are critical infrastructure sectors high-risk targets?
They have better performance
They use outdated logos
Disruption can have national consequences
They're easily accessible
What tool is used to detect suspicious activity and alert admins?
Microsoft Word
Cloud Backup
Intrusion Detection System
Content Management System
What makes malware-less attacks harder to detect?
They use known viruses
They crash systems
They don't involve traditional malware
They occur on local networks
What describes cyber attacks that manipulate individuals through deception?
Binary exploitation
Network spoofing
Social engineering
Signal jamming
What is the most likely motivation behind ransomware?
Curiosity
Education
Financial gain
Protest
Why should policymakers collaborate internationally?
To increase ad revenue
To improve UX design
To address cross-border cybercrime
To standardize fonts
Which cyber threat involves impersonating trusted contacts to obtain information?
Keylogging
DoS
Spoofing
System crash
What does the term "cybersecurity policy" generally include?
Pricing models
Guidelines and frameworks to secure systems
ISP speed recommendations
UI design patterns
What is the biggest limitation of relying solely on technical defenses?
They're too cheap
They replace human decision-making
They ignore human and organizational factors
They use too much data
Scenario: A hacker uses tools from the dark web to infiltrate a government database without malware. What is this an example of?
Phishing
Spoofing
Malware-less advanced persistent threat
Ransomware
Why is reconnaissance important in the hacking process?
To destroy logs
To infect files
To gather data about a target system
To fake IP addresses
What is one role of national cybersecurity strategies?
Promote local artists
Control web design
Protect infrastructure and ensure cooperation
Monitor YouTube content
What makes cybercrime attractive to organized groups?
Legal immunity
High return and low risk
Minimal tech requirements
Government support
Why is understanding TTPs (Tactics, Techniques, Procedures) important for defense teams?
It helps identify fonts
It allows faster payment
It aids in anticipating and responding to attacks
It boosts software design
How can cybersecurity incidents affect a nation's economy?
They improve market value
They speed up internet
They cause financial disruptions
They enhance tourism
