NEW
Font size
WorksheetsPaid Class Cybersecurity Quiz
Total questions: 32
Worksheet time: 16mins
What type of malware is specifically designed to replicate itself and spread to other computers?
Trojan Horse
Worm
Ransomware
Virus
A Trojan horse is a type of virus that disguises itself as a legitimate program to gain access to a system.
True
False
Which type of hacker is known for hacking with the intention of highlighting issues for social justice?
Script Kiddie
Cyber Criminal
Grey Hat Hacker
Hacktivist
Which of the following is a type of passive attack?
Denial of Service (DoS)
Evas-dropping
SQL Injection
Man-in-the-Middle (active interception)
Which of the following is an example of an active attack in cybersecurity?
Traffic Analysis
State-Sponsored Hacker
Data Modification
Sniffing
What does it mean to 'Accept' a risk in Cyber Risk management?
To deny that the risk exists
To recognize the risk but decide not to take any action against it
To pass the risk on to another company
To mitigate the risk immediately
What is a common method to transfer cyber risk?
Employee training
Purchasing cyber insurance
Implementing firewalls
Hiring more staff
Which of the following is a component of cyber risk assessment?
Calculating the yearly budget
Assessing the probability and impact of cyber incidents
Employee performance reviews
Checking the stock market
What is the first step in developing a cyber risk management plan?
Implementing security solutions
Identifying and assessing risks
Training employees
Buying insurance
What role does 'risk mitigation' play in cyber risk management?
Refers to transferring all risks to another entity
Involves taking steps to reduce the likelihood or impact of a risk
Is about avoiding any technological upgrades to prevent risks
Deals with eliminating all cyber risks completely
Why is it important to have a cyber incident response plan?
Ensure that incidents are handled consistently and effectively
Comply with local entertainment regulations
Increase the company's stock value
Avoid training employees on security practices
A hospital's patient record system experiences a cyberattack where an attacker deletes all patient data and replaces it with a ransomware note. The hospital has backups, but the data loss caused immediate disruptions to patient care. Which two components of the CIA Triad were most directly impacted by this attack?
Confidentiality and Availability
Integrity and Confidentiality
Integrity and Availability
Confidentiality and Non-repudiation
A company Implements strong encryption for all data transmitted between its branch offices and headquarters. While this significantly improves security, the encryption and decryption processes introduce a slight delay in communication. Which component of the CIA Triad is being prioritized in this scenario, and what potential trade-off is being made?
Prioritizing Confidentiality, with a potential trade-off in Availability.
Prioritizing Integrity, with a potential trade-off in Confidentiality.
Prioritizing Availability, with a potential trade-off in Integrity.
Prioritizing Confidentiality, with a potential trade-off in Integrity.
You are designing a system to store highly sensitive financial records. Choose the best security measure from the options below that primarily addresses the Integrity of the data.
Implementing strong encryption for data at rest.
Ensuring redundant servers and regular backups.
Using digital signatures and hash checks on the data.
Restricting physical access to the servers.
Your organization needs to ensure that users can always access critical business applications, even during hardware failures or power outages. Which security control best supports the Availability component of the CIA Triad in this context?
Implementing multi-factor authentication for all users.
Conducting regular penetration testing.
Deploying redundant power supplies and load balancers.
Encrypting all sensitive data in transit.
You are using the free Wi-Fi at a coffee shop to check your online banking balance. You notice the website's URL is http:// instead of https://. Unbeknownst to you, an attacker on the same network is intercepting all of your communication. What type of attack is most likely taking place, and what is the attacker's primary goal?
A virus attack, aiming to corrupt your files.
A passive, Man-in-the-Middle (MITM) attack, aiming to eavesdrop on your data.
An active, Man-in-the-Middle (MITM) attack, aiming to alter your communication.
A Trojan Horse, aiming to secretly download malicious software.
A company's internal network is infected with a new type of malware that rapidly spreads from one computer to another by exploiting a vulnerability in the operating system's file-sharing service. It duplicates itself, consumes network bandwidth, and leads to a complete system crash. Based on its behavior, which type of malware is described in this case study, and what is its primary characteristic?
Trojan Horse, because it appeared to be a legitimate file.
Spyware, because it was monitoring network traffic.
Virus, because it attached itself to a host program.
Worm, because it self-replicated and spread without human interaction.
A user receives an email that appears to be from their bank, asking them to verify their account information by clicking a link. The user clicks the link, which downloads a file. Later, all of the user's files are encrypted, and a message appears on their screen demanding a ransom payment. From the list of attacks and malware types below, identify the one that best describes the final attack that encrypted the user's files.
Spyware
Ransomware
Trojan Horse
Virus
While using public Wi-Fi at a café, Ali notices his banking app session was hijacked and money was transferred without his consent. What type of attack most likely occurred?
SQL Injection
Man-in-the-Middle (MITM)
Denial of Service (DoS)
Phishing
A company’s systems were infected. The malware spread rapidly, corrupted files, slowed down operations, and sent spam emails from user accounts. The security team suspects multiple types of malicious software were at play. Which combination best fits the scenario?
Virus + Worm + Spyware
Trojan + Backdoor
Adware + Keylogger
Rootkit + Bootkit
If you are the SOC Analyst and find that multiple employees are seeing a screen demanding Bitcoin payment to unlock files: What’s your FIRST response?
Pay the ransom immediately
Disconnect infected machines from the network
Reboot the systems
Ignore the message and continue work
A malicious program attaches itself to Microsoft Word files, and every time the file is shared, the program spreads to the recipient’s computer. What type of malware is this?
Worm
Virus
Trojan
Spyware
Sara downloads a “free antivirus” tool from an unknown website. Instead of protecting her system, it opens a backdoor for hackers. What type of malware is this?
Trojan Horse
Worm
Rootkit
Spyware
You suspect spyware on your system because your keystrokes and browsing activities are being monitored. What is the BEST way to verify and remove it?
Format the system immediately
Run an updated anti-malware scan
Disable firewall temporarily
Share your password with IT support
An attacker intercepts network traffic and reads confidential messages without altering them. What type of attack is this?
Active
Passive
Insider
Replay
During a security workshop, students are asked: “How can we prevent Man-in-the-Middle attacks in web applications?”
Use SSL/TLS encryption (HTTPS)
Disable firewalls
Turn off antivirus
Use only public Wi-Fi
A project manager is presenting a new initiative to the leadership team. A key part of the project relies on a new, unproven technology. The project manager identifies this as a potential risk and creates a contingency plan to use a more established, albeit less efficient, technology if the first one fails. Which risk mitigation strategy is the project manager using?
Risk Avoidance
Risk Acceptance
Risk Transference
Risk Mitigation
Case Study: A large bank is preparing to launch a new mobile application.
The head of security determines that the risk of a cyberattack on the app is high, with a potentially catastrophic financial impact. To address this, the bank purchases a specialized cyber-insurance policy that will
cover up to $50 million in losses from a data breach.
Instruction: Which risk management technique did the bank use to address the potential cyberattack?
A) Risk Avoidance
B) Risk Transference
C) Risk Acceptance
D) Risk Reduction
Activity: You are a security analyst evaluating a critical server.
You identify a specific vulnerability with a medium likelihood of
being exploited and a high impact if it is.
Instruction: Using a standard risk matrix (Likelihood vs. Impact),
how would you prioritize this risk for remediation?
A) Low Priority
B) Medium Priority
C) High Priority
D) The risk should be ignored
A company is planning to migrate its data to the cloud.
The security team is worried about unauthorized access to
sensitive customer data during the migration.
Which type of risk is being considered here?
a) Strategic Risk
b) Operational Risk
c) Security Risk
d) Compliance Risk
Case Study-Based Question (Risk Assessment)
An e-commerce company identified the following risks:
Server downtime (High probability, Medium impact)
Data breach (Medium probability, High impact)
Power outage (Low probability, Low impact)
As a Risk Manager, which risk should be given the highest priority?
a) Server downtime
b) Data breach
c) Power outage
d) All risks equally
You are assigned to develop a risk management plan. What is the FIRST activity you should perform?
a) Buy cyber insurance
b) Identify and categorize potential risks
c) Write a business continuity policy
d) Train employees about risks
