wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

IT3101-IAS-PLE

Total questions: 50

Worksheet time: 25mins

Name
Class
Date
1.

An attacker modifies financial records to insert fraudulent transactions. Which triad(s) were directly violated?

a)

CIA – Availability only

b)

CIA – Confidentiality and Integrity

c)

CIA – Integrity only

d)

DAD – Denial and Disclosure

2.

After a flood destroyed its primary data center, a company relied on its secondary backup facility to restore operations. Which CIA principle was preserved by this action?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Nonrepudiation

3.

An organization sets up security policies requiring all employees to attend annual cybersecurity awareness training. What type of control is this?

a)

Technical Control

b)

Operational Control

c)

Managerial Control

d)

Physical Control

4.

A company applies data masking to display only the last four digits of customer credit card numbers. What is the main objective of this technique?

a)

Prevent unauthorized access to entire data

b)

Destroy unnecessary data

c)

Replace sensitive values with random tokens

d)

Encrypt data in transmission

5.

An attacker intercepts sensitive data being transmitted between a client and a server. Which data state was compromised?

a)

Data in use

b)

Data in transit

c)

Data at rest

d)

Data minimized

6.

A company experiences a ransomware attack. They restore operations by using backup files. Which type of control was applied in the recovery process?

a)

Preventive

b)

Detective

c)

Corrective

d)

Directive

7.

A power outage corrupts some stored customer files, leading to missing information in their records. This is an example of a violation of which principle?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Compliance

8.

Which technique involves partially hiding data, such as showing only the last four digits of a credit card?

a)

Hashing

b)

Masking

c)

Tokenization

d)

Encryption

9.

Which of the following is an operational control?

a)

Access control lists

b)

Biometric locks

c)

Log monitoring

d)

Risk assessment exercises

10.

An organization enforces access restrictions by limiting users to login only from certain countries. What type of restriction is this?

a)

Permission restriction

b)

Role-based restriction

c)

Geographic restriction

d)

Physical restriction

11.

Which of the following describes tokenization?

a)

Using hash values to obscure data

b)

Replacing sensitive values with unique identifiers

c)

Removing all data permanently in the storage

d)

Hiding some fields with “X” or “*”

12.

A DLP (Data Loss Prevention) system that monitors outgoing network traffic for sensitive data is classified as:

a)

Agent-based DLP

b)

Agentles DLP

c)

Masking system

d)

Tokenization tool

13.

A company installs a biometric lock on the data center door. This is an example of what type of control?

a)

Technical control

b)

Operational control

c)

Physical control

d)

Managerial control

14.

Which of the following best describes the main motivation of organized crime as cyber threat actors?

a)

Political influence

b)

Financial gain

c)

Proving technical skills

d)

Revenge

15.

Which threat actor is most likely to carry out a zero-day attack using custom research labs?

a)

Script kiddies attackers

b)

Hacktivists attackers

c)

Nation-state attackers

d)

Insider attackers

16.

Which of the following scenarios best illustrates a hacktivist motivation?

a)

Launching ransomware for quick profit

b)

Defacing a government website to protest policy

c)

Exploiting zero-day vulnerabilities for espionage

d)

Selling stolen credit cards on the dark web

17.

A disgruntled employee steals sensitive data after being denied a promotion. This is an example of:

a)

Competitor attack

b)

Nation-state threat

c)

Insider threat

d)

Shadow IT

18.

Which hacker “hat” type describes someone who identifies vulnerabilities without authorization but later reports them?

a)

White hat

b)

Black hat

c)

Gray hat

d)

Blue hat

19.

An attacker drops infected USB drives in a company’s parking lot. Which threat vector is being exploited?

a)

Cloud computing

b)

Removable devices

c)

Message-based

d)

upply chain

20.

A phishing email that tricks users into entering login details into a fake website is an example of:

a)

Wired network attack

b)

Message-based attack

c)

Shadow IT risk

d)

System misconfiguration

21.

A poorly secured Wi-Fi network allows outsiders to connect from the parking lot. This is an example of:

a)

Wireless network threat

b)

Supply chain vulnerability

c)

Physical network breach

d)

Cloud-based attack

22.

Which of the following best explains why shadow IT is risky?

a)

It always involves malicious insiders activity

b)

It introduces technology outside of official security controls

c)

t is performed by competitors to steal data in an organization

d)

It is required for faster software updates and system performace

23.

A nation-state group that compromises power grid systems during conflict is most likely motivated by:

a)

Service disruption and political gain

b)

Quick financial profit

c)

Demonstrating security network technical skills

d)

Revenge against competitors

24.

A company has strong antivirus protection, but users still report sudden file encryption with ransom notes displayed.
Which security control likely failed, and what alternative mitigation could have minimized the damage?

a)

Firewall filtering – stronger intrusion prevention

b)

Backup strategy – maintaining offline and immutable backups

c)

Patch management – enforcing stricter update schedules

d)

User account control – stricter privilege management

25.

A security analyst detects unusual outbound traffic from multiple systems. The traffic is directed toward known malicious IPs, but no files on the systems match antivirus signatures. Which malware type is most likely responsible?

a)

Worm

b)

Virus

c)

Bloatware

d)

Logic bomb

26.

An employee downloads a “free PDF editor” that later starts enrolling the device into paid subscription services without consent. What best identifies this malware?

a)

Spyware

b)

Keylogger

c)

Trojan

d)

Ransomware

27.

Which malware type poses the greatest threat if a company relies heavily on online transactions but uses strong file backups?

a)

Ransomware

b)

Worms

c)

Spyware

d)

Viruses

28.

A company discovers a malicious script embedded inside payroll software, designed to activate on the last Friday of every month. Which malware type does this represent?

a)

Logic bomb

b)

Worm

c)

Keylogger

d)

Rootkit

29.

Which malware would be most effective for attackers who want long-term, stealthy access to a corporate server without triggering detection?

a)

Ransomware

b)

Worm

c)

Rootkit

d)

Virus

30.

A system administrator observes a suspicious process imitating “explorer.exe” that sends keystroke data to a remote server. Which two malware types could explain this behavior?

a)

Keylogger and Spyware

b)

Virus and Worm

c)

Logic bomb and Trojan

d)

Ransomware and Bloatware

31.

If a worm infection spreads via IoT devices and USB drives, which layered defense strategy would be most effective in prevention?

a)

Stronger user awareness training

b)

Limiting software installation permissions

c)

Network segmentation and patch management

d)

Restoring from backups

32.

A newly hired IT technician claims that pre-installed “manufacturer software” isn’t dangerous because it isn’t malware. From a cybersecurity perspective, why is this reasoning flawed?

a)

Bloatware is legally malware

b)

Bloatware is harmless but consumes resources

c)

Bloatware may be exploited and increase attack surface

d)

Bloatware is always a safe spyware integrates by the manufacturer

33.

Statement A: Ransomware often uses phishing emails as the initial infection vector.
Statement B: The only way to recover from ransomware is by paying the ransom.

a)

Statement A is correct

b)

Statement B is correct

c)

Both statements are correct

d)

Both statements are incorrect

34.

Statement A: Bloatware is intentionally designed to damage a computer system.
Statement B: Bloatware may not be malicious but can consume system resources and increase vulnerabilities.

a)

Statement A is correct

b)

Statement B is correct

c)

Both statements are correct

d)

Both statements are incorrect

35.

Statement A: Viruses need a host file or program to spread.
Statement B: Viruses can remain dormant until triggered by specific conditions.

a)

Statement A is correct

b)

Statement B is correct

c)

Both statements are correct

d)

Both statements are incorrect

36.

Statement A: Threat intelligence feeds can include details such as MAC addresses, file hashes, and URLs.
Statement B: Using only one threat intelligence feed is always sufficient to stay updated on emerging threats.

a)

Statement A is correct

b)

Statement B is correct

c)

Both statements are correct

d)

Both statements are incorrect

37.

Which type of hacker is authorized to test systems?

a)

Black-hat hacker

b)

White-hat hackeR

c)

Gray-hat hacker

d)

Script kiddie

38.

Insiders pose a risk because they:

a)

Have authorized access

b)

Use phishing emails

c)

Exploit software flaws

d)

Hack for fun

39.

Which type of threat actor is motivated by financial gain?

a)

Nation-state

b)

Hacktivist

c)

Cybercriminal

d)

White-hat hacker

40.

Cyberterrorists aim to:

a)

Spread malware for fun

b)

Cause fear and disruption

c)

Test security systems

d)

Monitor browsing

41.

Which of the following reduces the attack surface?

a)

Applying patches

b)

Ignoring updates

c)

Sharing passwords

d)

Disabling firewalls

42.

Clicking a fake login page is an example of:

a)

Social engineering

b)

Hardware attack

c)

Software update

d)

Firewall defense

43.

Email viruses usually spread through:

a)

Attachments

b)

Firewalls

c)

Rootkits

d)

Updates

44.

A simple way to remove bloatware is to:

a)

Uninstall it

b)

Encrypt it

c)

Hide it

d)

Spread it

45.

Adding fraudulent transactions to a financial record is an example of:

a)

Disclosure

b)

Denial

c)

Alteration

d)

Masking

46.

Which term describes stored data on hard drives, tapes, or cloud?

a)

Data in transit

b)

Data at rest

c)

Data in use

d)

Data in motion

47.

Which technique transforms data so the original cannot be retrieved?

a)

Tokenization

b)

Masking

c)

Obfuscation

d)

Hashing

48.

Which technique completely cuts off a system from external networks?

a)

Segmentation

b)

Isolation

c)

Obfuscation

d)

Data minimization

49.

Which triad is most useful in identifying possible threats?

a)

CIA triad

b)

DAD triad

c)

IT governance

d)

NIST framework

50.

Which of the following BEST protects against eavesdropping attacks on transmitted data?

a)

Tokenization

b)

Encryption

c)

Masking

d)

Obfuscation