wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

AP Cyber- Cisco-Module 1-4

Total questions: 50

Worksheet time: 50mins

Name
Class
Date
1.

What is the path or method used by a threat actor to gain access to a system or network called?

a)

Attack Vectors

b)

Security Patch

c)

Firewall Rule

d)

Encryption Key

2.

Who are individuals or groups who pose a risk to cybersecurity, categorized by their motivations and skills?

a)

Threat Actors

b)

Security Analysts

c)

Network Engineers

d)

System Administrators

3.

Which type of hacker uses their skills for defensive purposes, with permission?

a)

White Hat Hackers

b)

Black Hat Hackers

c)

Grey Hat Hackers

d)

Script Kiddies

4.

Which type of hacker operates without permission but often does not have malicious intent and may expose vulnerabilities to push for a fix?

a)

Gray Hat Hackers

b)

Black Hat Hackers

c)

Script Kiddies

d)

State-sponsored Hackers

5.

Which type of hacker hacks without permission for personal gain, criminal activity, or other harmful purposes?

a)

Black Hat Hackers

b)

White Hat Hackers

c)

Grey Hat Hackers

d)

Script Kiddies

6.

Who are individuals who discover and sell information about zero-day vulnerabilities?

a)

Vulnerability Brokers

b)

Penetration Testers

c)

White Hat Hackers

d)

Security Analysts

7.

Who are individuals or groups motivated by financial gain in the context of hacking?

a)

Cybercriminals

b)

White hat hackers

c)

Hacktivists

d)

Script kiddies

8.

Who are hacking teams sponsored by a government to conduct cyber warfare, espionage, or intelligence gathering?

a)

State-Sponsored Hackers

b)

Script Kiddies

c)

Hacktivists

d)

Cybercriminals

9.

What are technologies and processes used to prevent sensitive data from leaving a company's network called?

a)

Data Loss Prevention (DLP)

b)

Network Address Translation (NAT)

c)

Virtual Private Network (VPN)

d)

Intrusion Detection System (IDS)

10.

What are ways data can be lost, such as physical theft of devices, accidental deletion, malicious insider activity, or external cyberattacks, called?

a)

Common Data Loss Vectors

b)

Data Encryption Methods

c)

Network Protocols

d)

User Authentication Factors

11.

What is the process of identifying, assessing, and mitigating risks to an organization's assets called?

a)

Risk Management

b)

Asset Allocation

c)

Resource Planning

d)

Incident Response

12.

What is the process of identifying and analyzing potential risks called?

a)

Risk Assessment

b)

Risk Ignorance

c)

Risk Elimination

d)

Risk Acceptance

13.

What are measures put in place to reduce risk, such as firewalls, policies, or locks, called?

a)

Security Controls

b)

Threat Vectors

c)

Vulnerabilities

d)

Attack Surfaces

14.

What are forensically identifiable artifacts of a cyberattack, such as malicious file hashes or IP addresses, called?

a)

Indicators of Compromise (IOCs)

b)

Digital Certificates

c)

Access Control Lists (ACLs)

d)

Security Policies

15.

Which U.S. federal agency is involved in cybersecurity and is abbreviated as CISA?

a)

Cybersecurity and Infrastructure Security Agency

b)

Central Intelligence and Security Administration

c)

Civilian Internet Security Agency

d)

Critical Information Systems Authority

16.

Which non-profit organization is focused on promoting cybersecurity awareness and is abbreviated as NCSA?

a)

National Cyber Security Alliance

b)

Network Cyber Safety Association

c)

National Computer Security Agency

d)

National Council for Secure Access

17.

What term describes the path or method used by a threat actor to gain access to a system?

a)

Threat Domain

b)

Cyber Kill Chain

c)

Attack Vector

d)

Vulnerability Broker

18.

An individual who uses their hacking skills with permission to find vulnerabilities in a company's system is a:

a)

Black Hat Hacker

b)

Gray Hat Hacker

c)

White Hat Hacker

d)

Script Kiddie

19.

Which of the following is a primary goal of a state-sponsored hacker?

a)

Financial gain through ransomware

b)

Political or social protest

c)

Espionage or cyber warfare

d)

Selling vulnerabilities for profit

20.

What is the main purpose of Data Loss Prevention (DLP) solutions?

a)

To encrypt all company data

b)

To prevent unauthorized access to a network

c)

To stop sensitive data from leaving the organization

d)

To perform regular backups of critical files

21.

Which of the following is an example of an administrative security control?

a)

A firewall

b)

A security policy

c)

A physical lock on a server room

d)

An intrusion detection system (IDS)

22.

A malicious IP address found in system logs after a network breach is an example of a(n):

a)

Threat Domain

b)

Indicator of Compromise (IOC)

c)

Vulnerability

d)

Exploitation Vector

23.

The phase of the cyber kill chain where the attacker establishes a command-and-control channel is known as:

a)

Delivery

b)

Installation

c)

Command and Control

d)

Exploitation

24.

Which model for intrusion analysis includes the four core elements of Adversary, Capability, Infrastructure, and Victim?

a)

The Cyber Kill Chain

b)

The Diamond Model

c)

The NIST Incident Response Model

d)

The CIA Triad

25.

Which social engineering tactic involves creating a false scenario to gain a victim's trust and information?

a)

Phishing

b)

Baiting

c)

Pretexting

26.

The process of an organization resuming its business operations after a significant disruptive event is called:

a)

Incident Response

b)

Disaster Recovery

c)

Digital Forensics

d)

Risk Assessment

27.

Which phase of reconnaissance involves an attacker using tools to identify open ports and services on a target's network?

a)

Passive Reconnaissance

b)

Active Reconnaissance

c)

Enumeration

d)

Scanning

28.

A type of cyberattack that involves injecting malicious code into an application's database query is known as:

a)

Cross-Site Scripting (XSS)

b)

SQL Injection

c)

Denial of Service (DoS)

d)

Phishing

29.

What is the primary function of digital forensics?

a)

To prevent future cyberattacks

b)

To restore compromised systems

c)

To analyze digital evidence after an incident

d)

To manage an organization's security policies

30.

Which type of threat actor is primarily motivated by a political or social cause?

a)

Cybercriminal

b)

Script Kiddie

c)

Hacktivist

d)

Vulnerability Broker

31.

A rogue access point is a common threat associated with which threat domain?

a)

Application Attacks

b)

Social Engineering

c)

Wireless and Mobile Device Attacks

d)

Insider Threats

32.

The process of identifying, assessing, and mitigating risks to an organization's assets is called:

a)

Security Controls

b)

Incident Response

c)

Risk Management

d)

Disaster Recovery

33.

An organization's formal plan for dealing with a security breach is called a(n):

a)

Disaster Recovery Plan

b)

Risk Management Policy

c)

Incident Response Plan

d)

Security Audit

34.

What is a common data loss vector that involves the physical theft of a device containing sensitive information?

a)

Malware infection

b)

Insider threat

c)

Accidental data deletion

d)

Physical theft

35.

A denial of service (DoS) attack aims to:

a)

Steal sensitive data

b)

Encrypt files and demand a ransom

c)

Make a computer or network resource unavailable to its intended users

d)

Manipulate an individual into revealing confidential information

36.

Which U.S. federal agency is responsible for protecting the nation's critical infrastructure from cyber threats?

a)

CISA

b)

NCSA

c)

FBI

d)

NSA

37.

The term for an individual who uses pre-packaged hacking tools without a deep understanding of what they are doing is:

a)

Cybercriminal

b)

Script Kiddie

c)

Hacktivist

d)

Vulnerability Broker

38.

In the Diamond Model of Intrusion Analysis, which element refers to the tools and exploits used by the attacker?

a)

Infrastructure

b)

Capability

c)

Adversary

d)

Victim

39.

Which of the following is a type of application attack?

a)

Phishing

b)

Social Engineering

c)

SQL Injection

d)

Wireless Eavesdropping

40.

The final phase of the Cyber Kill Chain, where the attacker achieves their ultimate goal, is known as:

a)

Actions on Objectives

b)

Reconnaissance

c)

Delivery

d)

Exploitation

41.

Which of the following is NOT a phase of reconnaissance in the context of a cyberattack?

a)

Passive Reconnaissance

b)

Active Reconnaissance

c)

Data Exfiltration

d)

Scanning

42.

The process of identifying and analyzing potential risks to an organization's assets is known as:

a)

Risk Management

b)

Security Auditing

c)

Risk Assessment

d)

Incident Response

43.

Which type of hacker is a security researcher who discovers a zero-day vulnerability and sells it to a government agency or another party?

a)

Black Hat Hacker

b)

Gray Hat Hacker

c)

White Hat Hacker

d)

Vulnerability Broker

44.

A user receiving a text message that seems to be from their bank asking them to click a link and verify their account information is an example of:

a)

Pretexting

b)

Phishing

c)

Baiting

d)

Social Engineering

45.

The primary purpose of antivirus software is to:

a)

Protect against physical theft

b)

Detect and remove malicious software

c)

Encrypt network traffic

d)

Manage network firewall rules

46.

A company's IT department notices unusual outbound network traffic from a server. Upon investigation, they discover a malware program has been installed and is sending sensitive customer data to an external IP address. The IT team immediately isolates the infected server from the network and begins to analyze the malicious file to understand how it got there. The unusual outbound traffic and the external IP address are examples of:

a)

Social engineering tactics

b)

Application vulnerabilities

c)

Indicators of Compromise (IOCs)

d)

Disaster recovery procedures

47.

A company's IT department notices unusual outbound network traffic from a server. Upon investigation, they discover a malware program has been installed and is sending sensitive customer data to an external IP address. The IT team immediately isolates the infected server from the network and begins to analyze the malicious file to understand how it got there. The action taken by the IT team to disconnect the infected server from the network is part of which phase of the incident response process?

a)

Detection and Analysis

b)

Containment

c)

Eradication

d)

Recovery

48.

Scenario: A company's IT department notices unusual outbound network traffic from a server. Upon investigation, they discover a malware program has been installed and is sending sensitive customer data to an external IP address. The IT team immediately isolates the infected server from the network and begins to analyze the malicious file to understand how it got there. To determine how the malware was installed, the IT team would likely perform a(n):

a)

Risk assessment

b)

Disaster recovery test

49.

This entire scenario, from the initial compromise to the data exfiltration, can be mapped to which model?

a)

The Diamond Model of Intrusion Analysis

b)

The Cyber Kill Chain

c)

The CIA Triad

d)

The Risk Management Framework

50.

The discovery of the malware being installed and sending data out of the network corresponds to which phases of the Cyber Kill Chain?

a)

Reconnaissance and Weaponization

b)

Delivery and Installation

c)

Installation and Actions on Objectives

d)

Command and Control and Delivery