Font size
S
M
L
XL
WorksheetsCYBER SECURITY MCQS
Total questions: 120
Worksheet time: 3600secs
Name
Class
Date
1.
Which component of the CIA triad ensures that data is not altered without authorization?
a)
Confidentiality
b)
Integrity
c)
Availability
d)
Authenticity
2.
Which of the following best describes phishing?
a)
A network protocol
b)
Physical theft of a device
c)
Deceptive attempt to obtain sensitive info
d)
Hardware failure
3.
Which is NOT a type of malware?
a)
Trojan
b)
Worm
c)
Firewall
d)
Ransomware
4.
In symmetric encryption the same key is used for:
a)
Hashing and signing
b)
Encryption and decryption
c)
Decryption and compression
d)
Signing and verification
5.
A firewall primarily protects a network by:
a)
Detecting viruses on endpoints
b)
Blocking unauthorized traffic
c)
Increasing bandwidth
d)
Encrypting files
6.
PKI is built around the use of:
a)
Symmetric keys only
b)
Physical tokens
c)
Digital certificates and asymmetric keys
d)
One-time passwords
7.
The primary purpose of a VPN is to:
a)
Speed up internet connection
b)
Provide secure tunnel over public networks
c)
Replace antivirus software
d)
Increase RAM
8.
Two-factor authentication (2FA) requires at least:
a)
Two passwords
b)
Password plus second factor like OTP
c)
Two hardware tokens
d)
Two email addresses
9.
SQL injection targets vulnerabilities in:
a)
Operating systems
b)
Web applications’ database layer
c)
Hardware drivers
d)
Network cables
10.
A DDoS attack aims to:
a)
Steal passwords
b)
Make a service unavailable by overwhelming traffic
c)
Encrypt data
d)
Delete files
11.
Social engineering exploits:
a)
Software bugs
b)
Human psychology
c)
Network latency
d)
Power outages
12.
A vulnerability assessment is best described as:
a)
Writing code
b)
Identifying and ranking security weaknesses
c)
Installing hardware
d)
Creating memes
13.
Ethical hacking is performed by:
a)
Attackers anonymously
b)
Authorized testers to find flaws
c)
Casual gamers
d)
Hardware engineers
14.
SSL/TLS primarily provides:
a)
File compression
b)
Secure encrypted web communication
c)
Spreadsheet editing
d)
Printer sharing
15.
An IDS monitors network traffic for:
a)
Movie streams
b)
Malicious activity patterns
c)
Stock prices
d)
Weather updates
16.
A digital certificate binds a public key to:
a)
A movie file
b)
An identity/organization
c)
An IP address only
d)
A password
17.
Ransomware typically:
a)
Gives free software
b)
Encrypts files and demands payment
c)
Improves system speed
d)
Increases battery life
18.
A zero-day exploit is one that:
a)
Works after 30 days
b)
Targets a previously unknown vulnerability
c)
Runs only on Sundays
d)
Requires user permission
19.
A honeypot is used to:
a)
Cook food
b)
Lure attackers for study
c)
Store backups
d)
Block ads
20.
A brute-force attack involves:
a)
Guessing passwords systematically
b)
Physical force on hardware
c)
Sending flowers
d)
Increasing RAM
21.
A botnet is a collection of:
a)
Routers only
b)
Compromised computers controlled remotely
c)
Printers
d)
USB sticks
22.
A security policy in an organization typically:
a)
Is optional
b)
Defines rules and procedures for protection
c)
Increases internet speed
d)
Reduces screen brightness
23.
Risk assessment in information security involves:
a)
Ignoring threats
b)
Identifying threats and impacts
c)
Deleting emails
d)
Changing wallpapers
24.
Spear phishing is:
a)
A type of fish
b)
Targeted phishing against specific individuals
c)
Physical theft
d)
Hardware upgrade
25.
End-to-end encryption ensures that data is encrypted between:
a)
Router and switch
b)
Sender and intended recipient
c)
Browser and ad network
d)
CPU and RAM
26.
CAPTCHA is used primarily to:
a)
Improve graphics
b)
Distinguish humans from bots
c)
Increase storage
d)
Lower latency
27.
Biometrics in security use:
a)
Paper notes
b)
Unique human traits for authentication
c)
Random numbers
d)
Magnetic fields
28.
The purpose of a digital signature is to:
a)
Decorate documents
b)
Verify authenticity and integrity of data
c)
Increase file size
d)
Speed printing
29.
A honeynet is a network of:
a)
Real production servers
b)
Honeypots acting as decoys
c)
Printers
d)
Smart TVs
30.
Identity theft in cybersecurity involves:
a)
Physical robbery
b)
Unauthorized use of personal info
c)
Buying hardware
d)
Installing games
31.
A rootkit is designed to:
a)
Grow plants
b)
Hide its presence on a system
c)
Improve graphics
d)
Charge batteries
32.
Patch management refers to:
a)
Sewing clothes
b)
Applying updates to fix vulnerabilities
c)
Deleting files
d)
Installing fonts
33.
The principle of least privilege means:
a)
Everyone gets admin rights
b)
Users get minimum access needed
c)
No access at all
d)
Shared passwords
34.
The two-man rule requires:
a)
Two people to approve critical actions
b)
Two computers for each user
c)
Two passwords written down
d)
Two routers
35.
Quantum cryptography leverages:
a)
Wooden sticks
b)
Principles of quantum mechanics for secure keys
c)
Fiber optics only
d)
Bluetooth signals
36.
Which port does HTTPS typically use?
a)
80
b)
443
c)
21
d)
22
37.
Which hashing algorithm is considered broken for security?
a)
SHA-256
b)
MD5
c)
SHA-3
d)
BLAKE2
38.
In asymmetric encryption the private key is used for:
a)
Encryption of data to others
b)
Decryption of data received and signing
c)
Compression
d)
File deletion
39.
A man-in-the-middle attack primarily compromises:
a)
Printer ink
b)
Confidentiality and integrity of data
c)
CPU speed
d)
USB cables
40.
Which type of malware spreads without human intervention?
a)
Trojan
b)
Worm
c)
Adware
d)
Spyware
41.
A proxy firewall operates at which layer of the OSI model?
a)
Physical
b)
Application
c)
Network
d)
Data Link
42.
The principle of non-repudiation ensures that:
a)
Data is always available
b)
Senders cannot deny sending data
c)
Passwords are short
d)
Firewalls are off
43.
Which of the following is a symmetric encryption algorithm?
a)
RSA
b)
AES
c)
ECC
d)
Diffie-Hellman
44.
A rainbow table is used for:
a)
Painting
b)
Cracking password hashes
c)
Storing emails
d)
Streaming video
45.
Which attack exploits session tokens?
a)
Buffer overflow
b)
Session hijacking
c)
Phishing
d)
DDoS
46.
A security token that generates OTPs every 30 seconds is called:
a)
Static token
b)
TOTP token
c)
USB stick
d)
Barcode
47.
Which protocol replaced SSL?
a)
TLS
b)
HTTP
c)
FTP
d)
SNMP
48.
A logic bomb activates:
a)
At a predefined condition
b)
Every second
c)
On Sunday only
d)
When unplugged
49.
Which of the following is NOT a form of biometric authentication?
a)
Fingerprint
b)
Retina scan
c)
Password
d)
Palm vein
50.
The term “blue team†refers to:
a)
Attackers
b)
Defenders
c)
Auditors
d)
Developers
51.
Which tool is commonly used for network sniffing?
a)
Wireshark
b)
Excel
c)
Notepad
d)
Paint
52.
A buffer overflow attack targets:
a)
Printer queue
b)
Memory management weaknesses
c)
Screen brightness
d)
Mouse speed
53.
Which regulation focuses on data protection in the EU?
a)
HIPAA
b)
GDPR
c)
SOX
d)
PCI-DSS
54.
An attack using multiple vectors simultaneously is called:
a)
Single attack
b)
Blended threat
c)
Passive attack
d)
Replay attack
55.
Which of the following ensures data confidentiality?
a)
Hashing
b)
Digital signature
c)
Encryption
d)
Compression
56.
In a PKI who issues digital certificates?
a)
Root CA
b)
Web browser
c)
End user
d)
Router
57.
Which attack exploits XML parsers?
a)
SQL injection
b)
XML injection
c)
Buffer overflow
d)
ARP spoofing
58.
What does the term “air-gapped†mean?
a)
Using Wi-Fi only
b)
Physically isolated from other networks
c)
Using Bluetooth
d)
Cloud storage
59.
Which of the following is a social engineering technique?
a)
Port scanning
b)
Shoulder surfing
c)
Ping sweep
d)
Traceroute
60.
A false positive in an IDS alert means:
a)
Real attack detected
b)
Benign activity flagged as malicious
c)
Missed attack
d)
Hardware failure
61.
Which symmetric key size is considered secure as of 2025?
a)
56-bit
b)
128-bit
c)
40-bit
d)
64-bit
62.
Which attack uses IP spoofing to poison a cache?
a)
DNS cache poisoning
b)
SQL injection
c)
XSS
d)
CSRF
63.
Which of the following is a hardware security module?
a)
HSM
b)
HTML
c)
HTTP
d)
HDLC
64.
The term “black hat†refers to:
a)
Ethical hacker
b)
Malicious hacker
c)
System admin
d)
Auditor
65.
Which protocol is used for secure email transmission?
a)
SMTP
b)
POP3
c)
S/MIME
d)
FTP
66.
A watering hole attack targets:
a)
Coffee shops
b)
Websites frequented by specific users
c)
USB ports
d)
Printers
67.
Which of the following is a web application vulnerability?
a)
Heartbleed
b)
XSS
c)
Meltdown
d)
Spectre
68.
Which control type does encryption belong to?
a)
Administrative
b)
Technical
c)
Physical
d)
Procedural
69.
Which of the following best describes “data at rest†encryption?
a)
Encrypting data on disk
b)
Encrypting network traffic
c)
Encrypting RAM
d)
Encrypting CPU cache
70.
Which of the following is used to verify integrity?
a)
RSA
b)
Digital signature
c)
Hash function
d)
Certificate
71.
Which attack leverages user’s authenticated session?
a)
CSRF
b)
SQL injection
c)
DNS spoofing
d)
ARP poisoning
72.
Which of the following is a key stretching algorithm?
a)
bcrypt
b)
MD5
c)
ROT13
d)
Caesar cipher
73.
A system that lures attackers and records their actions is called:
a)
IDS
b)
IPS
c)
Honeypot
d)
Firewall
74.
Which of the following is NOT a principle of the CIA triad?
a)
Confidentiality
b)
Integrity
c)
Accessibility
d)
Availability
75.
Which attack sends oversized packets to crash a system?
a)
Ping of death
b)
Phishing
c)
Spam
d)
Whaling
76.
Which encryption mode ensures same plaintext yields different ciphertext?
a)
ECB
b)
CBC
c)
CFB
d)
OFB
77.
The term “red team†refers to:
a)
Defenders
b)
Attack simulation group
c)
Auditors
d)
HR team
78.
Which of the following is an open-source intrusion detection system?
a)
Snort
b)
Windows Defender
c)
macOS Firewall
d)
Norton
79.
Which of the following is a key exchange protocol?
a)
IKE
b)
SMTP
c)
FTP
d)
TFTP
80.
Which of the following is a form of multi-factor authentication?
a)
PIN only
b)
Password + fingerprint
c)
Username only
d)
Smartphone alone
81.
Which of the following is a characteristic of asymmetric encryption?
a)
Same key for encryption and decryption
b)
Faster than symmetric
c)
Uses key pairs
d)
Only for hashing
82.
Which attack exploits misconfigured cloud storage?
a)
Cloud misconfiguration
b)
SQL injection
c)
XSS
d)
Buffer overflow
83.
Which of the following is a secure coding practice?
a)
Hard-coding passwords
b)
Input validation
c)
Using HTTP
d)
Ignoring errors
84.
Which of the following is a vulnerability scanner?
a)
Nmap
b)
Nessus
c)
Wireshark
d)
Putty
85.
Which of the following is a secure protocol for file transfer?
a)
FTP
b)
TFTP
c)
SFTP
d)
HTTP
86.
Which of the following is a form of denial-of-service attack?
a)
SYN flood
b)
SQL injection
c)
Phishing
d)
Keylogger
87.
Which of the following is a characteristic of a worm?
a)
Requires host file
b)
Spreads independently
c)
Needs human click
d)
Only infects BIOS
88.
Which of the following is a security principle that limits damage?
a)
Least privilege
b)
Maximum privilege
c)
Shared passwords
d)
Open access
89.
Which of the following is a common password attack technique?
a)
Key stretching
b)
Salting
c)
Dictionary attack
d)
Hashing
90.
Which of the following best describes an insider threat?
a)
Attack from outside hacker
b)
Threat from within organization
c)
Natural disaster
d)
Power outage
91.
Which of the following is a secure hash algorithm?
a)
MD4
b)
SHA-1
c)
SHA-256
d)
RC4
92.
Which of the following is a feature of TLS 1.3?
a)
Slower handshake
b)
Deprecated encryption
c)
Zero Round Trip Time
d)
No forward secrecy
93.
Which of the following is a physical security control?
a)
Firewall
b)
Encryption
c)
Biometric lock
d)
IDS
94.
Which of the following is a method to prevent CSRF?
a)
CAPTCHA
b)
Anti-CSRF tokens
c)
URL encoding
d)
Base64 encoding
95.
Which of the following is a characteristic of ransomware?
a)
Speeds up system
b)
Encrypts files for ransom
c)
Increases storage
d)
Improves battery
96.
Which of the following is used to detect anomalies in network traffic?
a)
IPS
b)
IDS
c)
Firewall
d)
Proxy
97.
Which of the following is a secure key management practice?
a)
Storing keys in plain text
b)
Using HSM
c)
Sharing keys via email
d)
Using short keys
98.
Which of the following is a form of phishing targeting executives?
a)
Spear phishing
b)
Vishing
c)
Whaling
d)
Smishing
99.
Which of the following is a secure authentication protocol?
a)
Kerberos
b)
FTP
c)
HTTP
d)
TFTP
100.
Which of the following is a common vulnerability in IoT devices?
a)
Strong encryption
b)
Default passwords
c)
Regular updates
d)
Long keys
101.
Which of the following is a method to secure APIs?
a)
Rate limiting
b)
Using HTTP
c)
No authentication
d)
Hard-coded keys
102.
Which of the following is a characteristic of a botnet?
a)
Single user control
b)
Centralized or decentralized control
c)
Only attacks printers
d)
Cannot be detected
103.
Which of the following is a security risk of public Wi-Fi?
a)
Man-in-the-middle attacks
b)
Faster speed
c)
Strong encryption
d)
Low latency
104.
Which of the following is a secure backup strategy?
a)
Single copy on same device
b)
3-2-1 rule
c)
No encryption
d)
Public cloud only
105.
Which of the following is a method to prevent XSS?
a)
Input validation
b)
Using HTTP
c)
No encoding
d)
Hard-coded scripts
106.
Which of the following is a characteristic of zero trust architecture?
a)
Trust internal network
b)
Verify every access
c)
Use only passwords
d)
No monitoring
107.
Which of the following is a secure coding standard?
a)
OWASP Top 10
b)
CVE list
c)
NIST CSF
d)
ISO 9001
108.
Which of the following is a security incident response phase?
a)
Planning
b)
Containment
c)
Marketing
d)
Sales
109.
Which of the following is a characteristic of end-to-end encryption?
a)
Encrypted only on server
b)
Encrypted between sender and receiver
c)
Visible to ISP
d)
Stored in plain text
110.
Which of the following is a method to prevent buffer overflow?
a)
Input length checks
b)
Using HTTP
c)
No validation
d)
Short passwords
111.
Which of the following is a secure password storage method?
a)
Plain text
b)
Hashing with salt
c)
Base64 encoding
d)
Reversible encryption
112.
Which of the following is a characteristic of a supply chain attack?
a)
Targets end users only
b)
Compromises third-party software
c)
Only affects hardware
d)
Cannot be prevented
113.
Which of the following is a security benefit of virtualization?
a)
Increased attack surface
b)
Isolation of environments
c)
Shared passwords
d)
No updates needed
114.
Which of the following is a method to secure mobile devices?
a)
Rooting
b)
Jailbreaking
c)
MDM solutions
d)
No screen lock
115.
Which of the following is a characteristic of a Trojan horse?
a)
Self-replicates
b)
Disguised as legitimate software
c)
Infects BIOS
d)
Only affects Linux
116.
Which of the following is a secure communication protocol for IoT?
a)
MQTT over TLS
b)
HTTP
c)
FTP
d)
TFTP
117.
Which of the following is a security control for cloud environments?
a)
CASB
b)
USB lock
c)
Firewall only
d)
Honeypot only
118.
Which of the following is a method to prevent privilege escalation?
a)
Least privilege
b)
Shared accounts
c)
Weak passwords
d)
No logging
119.
Which of the following is a characteristic of a replay attack?
a)
Data is deleted
b)
Old valid transmission is reused
c)
Files are encrypted
d)
Hardware is damaged
120.
Which of the following is a secure method to share sensitive files?
a)
Email attachment
b)
Encrypted file transfer
c)
Public cloud link
d)
Social media
Reset
