NEW
Font size
WorksheetsCybersecurity MCQ Quiz
Total questions: 58
Worksheet time: 29mins
Which of the following is self-replicating?
Virus
Worm
Trojan
Spyware
A virus requires __________ to propagate.
User action
Network access
Administrative rights
None of the above
Which malware disguises itself as legitimate software?
Worm
Trojan
Rootkit
Adware
Spyware primarily aims to:
Delete files
Steal sensitive information
Crash the system
Encrypt files
A ransomware attack typically:
Deletes all files
Encrypts files and demands payment
Installs keyloggers
Slows down the network
Which malware type can operate without user interaction?
Virus
Worm
Trojan
Phishing
Rootkits are mainly used to:
Encrypt files
Maintain hidden access
Remove viruses
Scan networks
Which of these is considered malware disguised as software updates?
Adware
Trojan
Worm
Virus
Drive-by downloads require:
User downloading infected files
Visiting a compromised website
Opening email attachments
Installing antivirus
Which of the following is NOT malware?
Worm
Keylogger
Firewall
Trojan
SQL Injection attacks target:
Network devices
Web applications’ databases
Operating system kernel
DNS servers
XSS attacks exploit:
Client-side scripts
Server-side scripts
Network packets
DNS entries
CSRF attacks rely on:
Exploiting user authentication
Stealing network credentials
Infecting routers
Brute-forcing passwords
Phishing attacks aim to:
Encrypt files
Trick users into revealing sensitive info
Install rootkits
Launch DDoS attacks
Social engineering attacks primarily target:
Network protocols
Human behavior
Firewalls
Databases
A Denial-of-Service (DoS) attack’s goal is to:
Steal passwords
Overload systems to make services unavailable
Inject SQL commands
Modify logs
Drive-by download attacks are usually:
Manually initiated by the user
Automatic upon visiting a compromised site
Conducted via email
Only possible via USB
Which tool is commonly used for network scanning?
Nessus
WordPress
Wireshark
Metasploit
Credential harvesting attacks usually target:
Usernames and passwords
System logs
Network packets
Antivirus databases
The best prevention against phishing:
Antivirus
User awareness and training
Firewall
Network segmentation
A zero-day vulnerability means:
The patch is already available
Exploit is known before a patch exists
Vulnerability is harmless
Vulnerability is in deprecated software
Authentication bypass allows:
Users to access resources without proper credentials
Hackers to overload the network
Malware to hide in system
Encryption bypass
Broken access control can lead to:
Privilege escalation
SQL injection
Ransomware attacks
Keylogging
Which of the following is NOT an attack vector?
Web applications
Phishing
Human behavior
Antivirus software
Exploit kits usually contain:
Network scanning tools
Malware that exploits known vulnerabilities
Firewalls
Password managers
An attacker exploiting a system without leaving logs is using:
DoS
Stealth techniques
SQL injection
Phishing
Brute-force attacks involve:
Guessing passwords repeatedly
Exploiting vulnerabilities
Sending phishing emails
Redirecting traffic
Which of the following is a passive attack?
Eavesdropping
DoS
Malware injection
Privilege escalation
Network sniffing tools capture:
User passwords and traffic
Malware signatures
Logs only
Only emails
Security misconfiguration can result in:
Unauthorized access
Data leaks
Malware infections
All of the above
A honeypot is used to:
Detect and study attacks
Encrypt sensitive files
Prevent phishing
Stop ransomware
Which of the following prevents SQL injection?
Input validation
Firewalls only
Antivirus
Patching OS
Using HTTPS prevents:
Malware infection
Traffic sniffing
SQL injection
Phishing attacks
Multi-factor authentication (MFA) helps prevent:
Brute-force attacks
Worm infections
Malware execution
DoS attacks
Security patches are important because they:
Add new features
Fix known vulnerabilities
Remove user data
Improve network speed
Input sanitization helps prevent:
Buffer overflow and injection attacks
Malware execution
DoS attacks
Password theft
Phishing emails often contain:
Malicious links or attachments
Encrypted files
System logs
Network scan reports
Which is an example of a technical attack?
SQL injection
Social engineering
Phishing
Tailgating
Which is an example of a human-based attack?
Phishing
Malware injection
Buffer overflow
Cross-site scripting
A vulnerability scanner detects:
Weaknesses in systems
Malware only
User credentials only
Physical security flaws
The CIA triad stands for:
Confidentiality, Integrity, Availability
Control, Identification, Access
Cybersecurity, Integrity, Authorization
Confidentiality, Information, Access
Penetration testing is done to:
Identify security weaknesses
Encrypt sensitive data
Patch systems
Install antivirus
Which of these is a preventive control?
Firewall
IDS
IPS
Both A & C
IDS (Intrusion Detection System) is primarily:
Preventive
Detective
Corrective
Encryptive
Encryption ensures:
Confidentiality of data
Network scanning
Malware prevention
Privilege escalation
A buffer overflow attack targets:
Memory space of a program
Network bandwidth
File permissions
User credentials
Session hijacking attacks:
Steal active session tokens
Delete malware
Encrypt files
Scan networks
Social engineering exploits:
Technical flaws
Human psychology
Network protocols
Operating system vulnerabilities
Two-factor authentication (2FA) is an example of:
Detective control
Corrective control
Preventive control
Compensating control
The main goal of cybersecurity is to:
Prevent unauthorized access and protect data
Increase network speed
Install more software
Replace hardware
The main purpose of vulnerability assessment is to:
Hack into systems
Identify security weaknesses before attackers do
Encrypt data
Install antivirus
A vulnerability scanner is used to:
Detect network weaknesses and system misconfigurations
Encrypt files
Train users
Block malware
Which of the following is a popular vulnerability scanning tool?
Nessus
Wireshark
Metasploit
Snort
Active vulnerability scanning:
Gathers information without interacting with the target
Interacts with the target to find vulnerabilities
Only checks firewalls
Only analyzes logs
Passive vulnerability scanning:
Crashes the system to detect flaws
Monitors traffic without interacting with the target
Installs malware to find weaknesses
Encrypts sensitive files
Vulnerability assessment differs from penetration testing because:
It only identifies vulnerabilities, not exploits them
It hacks the system
It always bypasses firewalls
It installs malware
Which step comes first in a vulnerability assessment?
Reporting findings
Scanning systems
Planning and defining scope
Exploiting vulnerabilities
CVE in vulnerability management stands for:
Common Vulnerabilities and Exposures
Cybersecurity Vulnerability Exploit
Computer Virus Evaluation
Critical Vulnerability Event
