wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Paid Class Cybersecurity Quiz

Total questions: 32

Worksheet time: 16mins

Name
Class
Date
1.

What type of malware is specifically designed to replicate itself and spread to other computers?

a)

Trojan Horse

b)

Worm

c)

Ransomware

d)

Virus

2.

A Trojan horse is a type of virus that disguises itself as a legitimate program to gain access to a system.

a)

True

b)

False

3.

Which type of hacker is known for hacking with the intention of highlighting issues for social justice?

a)

Script Kiddie

b)

Cyber Criminal

c)

Grey Hat Hacker

d)

Hacktivist

4.

Which of the following is a type of passive attack?

a)

Denial of Service (DoS)

b)

Evas-dropping

c)

SQL Injection

d)

Man-in-the-Middle (active interception)

5.

Which of the following is an example of an active attack in cybersecurity?

a)

Traffic Analysis

b)

State-Sponsored Hacker

c)

Data Modification

d)

Sniffing

6.

What does it mean to 'Accept' a risk in Cyber Risk management?

a)

To deny that the risk exists

b)

To recognize the risk but decide not to take any action against it

c)

To pass the risk on to another company

d)

To mitigate the risk immediately

7.

What is a common method to transfer cyber risk?

a)

Employee training

b)

Purchasing cyber insurance

c)

Implementing firewalls

d)

Hiring more staff

8.

Which of the following is a component of cyber risk assessment?

a)

Calculating the yearly budget

b)

Assessing the probability and impact of cyber incidents

c)

Employee performance reviews

d)

Checking the stock market

9.

What is the first step in developing a cyber risk management plan?

a)

Implementing security solutions

b)

Identifying and assessing risks

c)

Training employees

d)

Buying insurance

10.

What role does 'risk mitigation' play in cyber risk management?

a)

Refers to transferring all risks to another entity

b)

Involves taking steps to reduce the likelihood or impact of a risk

c)

Is about avoiding any technological upgrades to prevent risks

d)

Deals with eliminating all cyber risks completely

11.

Why is it important to have a cyber incident response plan?

a)

Ensure that incidents are handled consistently and effectively

b)

Comply with local entertainment regulations

c)

Increase the company's stock value

d)

Avoid training employees on security practices

12.

A hospital's patient record system experiences a cyberattack where an attacker deletes all patient data and replaces it with a ransomware note. The hospital has backups, but the data loss caused immediate disruptions to patient care. Which two components of the CIA Triad were most directly impacted by this attack?

a)

Confidentiality and Availability

b)

Integrity and Confidentiality

c)

Integrity and Availability

d)

Confidentiality and Non-repudiation

13.

A company Implements strong encryption for all data transmitted between its branch offices and headquarters. While this significantly improves security, the encryption and decryption processes introduce a slight delay in communication. Which component of the CIA Triad is being prioritized in this scenario, and what potential trade-off is being made?

a)

Prioritizing Confidentiality, with a potential trade-off in Availability.

b)

Prioritizing Integrity, with a potential trade-off in Confidentiality.

c)

Prioritizing Availability, with a potential trade-off in Integrity.

d)

Prioritizing Confidentiality, with a potential trade-off in Integrity.

14.

You are designing a system to store highly sensitive financial records. Choose the best security measure from the options below that primarily addresses the Integrity of the data.

a)

Implementing strong encryption for data at rest.

b)

Ensuring redundant servers and regular backups.

c)

Using digital signatures and hash checks on the data.

d)

Restricting physical access to the servers.

15.

Your organization needs to ensure that users can always access critical business applications, even during hardware failures or power outages. Which security control best supports the Availability component of the CIA Triad in this context?

a)

Implementing multi-factor authentication for all users.

b)

Conducting regular penetration testing.

c)

Deploying redundant power supplies and load balancers.

d)

Encrypting all sensitive data in transit.

16.

You are using the free Wi-Fi at a coffee shop to check your online banking balance. You notice the website's URL is http:// instead of https://. Unbeknownst to you, an attacker on the same network is intercepting all of your communication. What type of attack is most likely taking place, and what is the attacker's primary goal?

a)

A virus attack, aiming to corrupt your files.

b)

A passive, Man-in-the-Middle (MITM) attack, aiming to eavesdrop on your data.

c)

An active, Man-in-the-Middle (MITM) attack, aiming to alter your communication.

d)

A Trojan Horse, aiming to secretly download malicious software.

17.

A company's internal network is infected with a new type of malware that rapidly spreads from one computer to another by exploiting a vulnerability in the operating system's file-sharing service. It duplicates itself, consumes network bandwidth, and leads to a complete system crash. Based on its behavior, which type of malware is described in this case study, and what is its primary characteristic?

a)

Trojan Horse, because it appeared to be a legitimate file.

b)

Spyware, because it was monitoring network traffic.

c)

Virus, because it attached itself to a host program.

d)

Worm, because it self-replicated and spread without human interaction.

18.

A user receives an email that appears to be from their bank, asking them to verify their account information by clicking a link. The user clicks the link, which downloads a file. Later, all of the user's files are encrypted, and a message appears on their screen demanding a ransom payment. From the list of attacks and malware types below, identify the one that best describes the final attack that encrypted the user's files.

a)

Spyware

b)

Ransomware

c)

Trojan Horse

d)

Virus

19.

While using public Wi-Fi at a café, Ali notices his banking app session was hijacked and money was transferred without his consent. What type of attack most likely occurred?

a)

SQL Injection

b)

Man-in-the-Middle (MITM)

c)

Denial of Service (DoS)

d)

Phishing

20.

A company’s systems were infected. The malware spread rapidly, corrupted files, slowed down operations, and sent spam emails from user accounts. The security team suspects multiple types of malicious software were at play. Which combination best fits the scenario?

a)

Virus + Worm + Spyware

b)

Trojan + Backdoor

c)

Adware + Keylogger

d)

Rootkit + Bootkit

21.

If you are the SOC Analyst and find that multiple employees are seeing a screen demanding Bitcoin payment to unlock files: What’s your FIRST response?

a)

Pay the ransom immediately

b)

Disconnect infected machines from the network

c)

Reboot the systems

d)

Ignore the message and continue work

22.

A malicious program attaches itself to Microsoft Word files, and every time the file is shared, the program spreads to the recipient’s computer. What type of malware is this?

a)

Worm

b)

Virus

c)

Trojan

d)

Spyware

23.

Sara downloads a “free antivirus” tool from an unknown website. Instead of protecting her system, it opens a backdoor for hackers. What type of malware is this?

a)

Trojan Horse

b)

Worm

c)

Rootkit

d)

Spyware

24.

You suspect spyware on your system because your keystrokes and browsing activities are being monitored. What is the BEST way to verify and remove it?

a)

Format the system immediately

b)

Run an updated anti-malware scan

c)

Disable firewall temporarily

d)

Share your password with IT support

25.

An attacker intercepts network traffic and reads confidential messages without altering them. What type of attack is this?

a)

Active

b)

Passive

c)

Insider

d)

Replay

26.

During a security workshop, students are asked: “How can we prevent Man-in-the-Middle attacks in web applications?”

a)

Use SSL/TLS encryption (HTTPS)

b)

Disable firewalls

c)

Turn off antivirus

d)

Use only public Wi-Fi

27.

A project manager is presenting a new initiative to the leadership team. A key part of the project relies on a new, unproven technology. The project manager identifies this as a potential risk and creates a contingency plan to use a more established, albeit less efficient, technology if the first one fails. Which risk mitigation strategy is the project manager using?

a)

Risk Avoidance

b)

Risk Acceptance

c)

Risk Transference

d)

Risk Mitigation

28.

Case Study: A large bank is preparing to launch a new mobile application.

The head of security determines that the risk of a cyberattack on the app is high, with a potentially catastrophic financial impact. To address this, the bank purchases a specialized cyber-insurance policy that will

cover up to $50 million in losses from a data breach.

Instruction: Which risk management technique did the bank use to address the potential cyberattack?

a)

A) Risk Avoidance

b)

B) Risk Transference

c)

C) Risk Acceptance

d)

D) Risk Reduction

29.

Activity: You are a security analyst evaluating a critical server.

You identify a specific vulnerability with a medium likelihood of

being exploited and a high impact if it is.

Instruction: Using a standard risk matrix (Likelihood vs. Impact),

how would you prioritize this risk for remediation?

a)

A) Low Priority

b)

B) Medium Priority

c)

C) High Priority

d)

D) The risk should be ignored

30.

A company is planning to migrate its data to the cloud.

The security team is worried about unauthorized access to

sensitive customer data during the migration.

Which type of risk is being considered here?

a)

a) Strategic Risk

b)

b) Operational Risk

c)

c) Security Risk

d)

d) Compliance Risk

31.

Case Study-Based Question (Risk Assessment)

An e-commerce company identified the following risks:

Server downtime (High probability, Medium impact)

Data breach (Medium probability, High impact)

Power outage (Low probability, Low impact)

As a Risk Manager, which risk should be given the highest priority?

a)

a) Server downtime

b)

b) Data breach

c)

c) Power outage

d)

d) All risks equally

32.

You are assigned to develop a risk management plan. What is the FIRST activity you should perform?

a)

a) Buy cyber insurance

b)

b) Identify and categorize potential risks

c)

c) Write a business continuity policy

d)

d) Train employees about risks