wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CompTIA Security+ Lesson 13 Revision

Total questions: 60

Worksheet time: 30mins

Name
Class
Date
1.

Malware is any software intentionally designed to damage systems or data.

a)

True

b)

False

2.

A ______ virus attaches itself to programs and runs when the program is launched.

a)

file-infecting

b)

memory-resident

c)

boot-sector

d)

macro

3.

Which malware spreads without user action, often across networks?

a)

Worm

b)

Rootkit

c)

Trojan

d)

Spyware

4.

Do rootkits try to hide their presence from detection tools?

a)

Yes, that’s true

b)

No, that’s not true

5.

Which malware pretends to be useful software but has hidden malicious code?

a)

Trojan

b)

Worm

c)

Spyware

6.

Spyware secretly monitors user activity and collects information.

a)

True

b)

False

7.

A ______ virus runs from memory and can infect without host files.

a)

memory-resident

b)

boot-sector

c)

macro

d)

script

8.

Which malware records keystrokes to steal credentials?

a)

Keylogger

b)

Rootkit

c)

Spyware

d)

Adware

9.

Adware displays unwanted ______ to generate revenue.

a)

ads

b)

files

c)

scripts

d)

ports

10.

Does ransomware lock data until payment is made?

a)

Yes, that’s true

b)

No, that’s not true

11.

Crypto-malware encrypts ______ until a ransom is paid.

a)

files

b)

ports

c)

packets

d)

logs

12.

Which malware uses many computers to send traffic at once?

a)

Botnet

b)

Trojan

c)

Spyware

d)

Macro virus

13.

A polymorphic virus changes its ______ to avoid detection.

a)

code

b)

target

c)

password

d)

command

14.

True or False: Fileless malware runs in memory without files.

a)

True

b)

False

15.

Logic bombs trigger when certain ______ are met.

a)

conditions

b)

passwords

c)

servers

d)

policies

16.

Backdoors allow attackers to bypass normal ______.

a)

authentication

b)

firewall

c)

hashing

d)

logging

17.

Mobile malware often spreads via malicious ______.

a)

apps

b)

cables

c)

routers

d)

alerts

18.

Yes or No: Spyware is always installed knowingly by the user.

a)

Yes, that’s true

b)

No, that’s not true

19.

Which malware disables security tools to remain hidden?

a)

Rootkit

b)

Trojan

c)

Adware

d)

Keylogger

20.

Fill in the blank: ______ viruses spread through infected documents with macros.

a)

Macro

b)

Script

c)

Boot-sector

d)

Fileless

21.

A ______ attack overloads a target with traffic to disrupt service.

a)

DoS

b)

SQL injection

c)

Buffer overflow

d)

Phishing

22.

Which is a distributed form of denial-of-service attack?

a)

DDoS

b)

DNS hijacking

c)

Port scanning

d)

IP spoofing

23.

Does phishing trick users into revealing sensitive information through fake emails?

a)

Yes, that’s true

b)

No, that’s not true

24.

Spear phishing targets ______ users with customized messages.

a)

specific

b)

random

c)

unknown

d)

guest

25.

Whaling attacks are aimed at ______.

a)

executives

b)

students

c)

IT staff

d)

vendors

26.

Smishing uses ______ messages for phishing.

a)

SMS

b)

email

c)

DNS

d)

FTP

27.

Pharming redirects users to fake ______.

a)

websites

b)

apps

c)

switches

d)

firewalls

28.

True or False: Vishing is phishing through voice calls.

a)

True

b)

False

29.

An SQL ______ attack manipulates queries to access unauthorized data.

a)

injection

b)

overflow

c)

flooding

d)

hashing

30.

Buffer overflow attacks try to overwrite ______ memory.

a)

system

b)

encrypted

c)

firewall

d)

packet

31.

Which attack uses precomputed hashes to crack passwords?

a)

Rainbow table

b)

SQL injection

c)

Keylogger

d)

DoS

32.

Brute force attacks try all possible ______.

a)

passwords

b)

packets

c)

servers

d)

policies

33.

True or False: Dictionary attacks use common words to guess passwords.

a)

True

b)

False

34.

Privilege escalation gives an attacker higher-level ______.

a)

access

b)

logging

c)

routing

d)

encryption

35.

Fill in the blank: ______ engineering manipulates people to reveal secrets.

a)

Social

b)

Network

c)

File

d)

Memory

36.

Tailgating occurs when someone enters by following an ______ person.

a)

authorized

b)

unknown

c)

blocked

d)

malicious

37.

Does shoulder surfing mean watching someone type a password?

a)

Yes, that’s true

b)

No, that’s not true

38.

True or False: DNS poisoning redirects traffic to malicious sites.

a)

True

b)

False

39.

Man-in-the-middle attacks intercept ______ in transit.

a)

communications

b)

power

c)

storage

d)

policies

40.

ARP spoofing sends false ______ messages on a LAN.

a)

ARP

b)

SMTP

c)

DNS

d)

NTP

41.

Replay attacks capture and resend valid ______.

a)

packets

b)

passwords

c)

servers

d)

hashes

42.

True or False: Downgrade attacks force systems to use weaker security.

a)

True

b)

False

43.

Fill in the blank: Birthday attacks exploit hash ______.

a)

collisions

b)

passwords

c)

packets

d)

encryption

44.

Which attack tries to guess session IDs or tokens?

a)

Session hijacking

b)

Buffer overflow

c)

ARP spoofing

d)

Keylogger

45.

Do pass-the-hash attacks reuse stolen password hashes?

a)

Yes, that’s true

b)

No, that’s not true

46.

Fill in the blank: Cross-site ______ allows attackers to inject malicious scripts.

a)

scripting

b)

routing

c)

logging

d)

signing

47.

Which attack tricks a user’s browser into sending malicious requests?

a)

Cross-site request forgery

b)

Privilege escalation

c)

Ransomware

d)

Sniffing

48.

True or False: Clickjacking hides malicious links under legitimate elements.

a)

True

b)

False

49.

Which attack locks users out of systems until ransom is paid?

a)

Ransomware

b)

Trojan

c)

Adware

d)

Keylogger

50.

Dictionary attacks are a type of ______ attack on passwords.

a)

offline

b)

physical

c)

social

d)

session

51.

Does SQL injection affect the database layer of applications?

a)

Yes, that’s true

b)

No, that’s not true

52.

Fill in the blank: A race ______ occurs when two processes compete for resources.

a)

condition

b)

state

c)

policy

d)

error

53.

Integer overflow exploits errors in handling numeric ______.

a)

values

b)

packets

c)

servers

d)

ports

54.

Which attack relies on exploiting memory allocation issues?

a)

Buffer overflow

b)

Brute force

c)

Whaling

d)

Smishing

55.

True or False: Zero-day attacks target vulnerabilities not yet patched.

a)

True

b)

False

56.

Credential stuffing uses stolen ______ on multiple accounts.

a)

logins

b)

files

c)

routers

d)

apps

57.

Fill in the blank: ______ harvesting collects usernames and passwords in bulk.

a)

Credential

b)

Network

c)

Buffer

d)

Token

58.

Which is a wireless attack exploiting unsecured access points?

a)

Evil twin

b)

Keylogger

c)

Botnet

d)

Macro virus

59.

Yes or No: Rainbow tables are mainly used to secure data.

a)

Yes, that’s true

b)

No, that’s not true

60.

Cryptographic attacks often aim to break data ______.

a)

encryption

b)

routing

c)

storage

d)

policies