wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Cybersecurity MCQ Quiz

Total questions: 58

Worksheet time: 29mins

Name
Class
Date
1.

Which of the following is self-replicating?

a)

Virus

b)

Worm

c)

Trojan

d)

Spyware

2.

A virus requires __________ to propagate.

a)

User action

b)

Network access

c)

Administrative rights

d)

None of the above

3.

Which malware disguises itself as legitimate software?

a)

Worm

b)

Trojan

c)

Rootkit

d)

Adware

4.

Spyware primarily aims to:

a)

Delete files

b)

Steal sensitive information

c)

Crash the system

d)

Encrypt files

5.

A ransomware attack typically:

a)

Deletes all files

b)

Encrypts files and demands payment

c)

Installs keyloggers

d)

Slows down the network

6.

Which malware type can operate without user interaction?

a)

Virus

b)

Worm

c)

Trojan

d)

Phishing

7.

Rootkits are mainly used to:

a)

Encrypt files

b)

Maintain hidden access

c)

Remove viruses

d)

Scan networks

8.

Which of these is considered malware disguised as software updates?

a)

Adware

b)

Trojan

c)

Worm

d)

Virus

9.

Drive-by downloads require:

a)

User downloading infected files

b)

Visiting a compromised website

c)

Opening email attachments

d)

Installing antivirus

10.

Which of the following is NOT malware?

a)

Worm

b)

Keylogger

c)

Firewall

d)

Trojan

11.

SQL Injection attacks target:

a)

Network devices

b)

Web applications’ databases

c)

Operating system kernel

d)

DNS servers

12.

XSS attacks exploit:

a)

Client-side scripts

b)

Server-side scripts

c)

Network packets

d)

DNS entries

13.

CSRF attacks rely on:

a)

Exploiting user authentication

b)

Stealing network credentials

c)

Infecting routers

d)

Brute-forcing passwords

14.

Phishing attacks aim to:

a)

Encrypt files

b)

Trick users into revealing sensitive info

c)

Install rootkits

d)

Launch DDoS attacks

15.

Social engineering attacks primarily target:

a)

Network protocols

b)

Human behavior

c)

Firewalls

d)

Databases

16.

A Denial-of-Service (DoS) attack’s goal is to:

a)

Steal passwords

b)

Overload systems to make services unavailable

c)

Inject SQL commands

d)

Modify logs

17.

Drive-by download attacks are usually:

a)

Manually initiated by the user

b)

Automatic upon visiting a compromised site

c)

Conducted via email

d)

Only possible via USB

18.

Which tool is commonly used for network scanning?

a)

Nessus

b)

WordPress

c)

Wireshark

d)

Metasploit

19.

Credential harvesting attacks usually target:

a)

Usernames and passwords

b)

System logs

c)

Network packets

d)

Antivirus databases

20.

The best prevention against phishing:

a)

Antivirus

b)

User awareness and training

c)

Firewall

d)

Network segmentation

21.

A zero-day vulnerability means:

a)

The patch is already available

b)

Exploit is known before a patch exists

c)

Vulnerability is harmless

d)

Vulnerability is in deprecated software

22.

Authentication bypass allows:

a)

Users to access resources without proper credentials

b)

Hackers to overload the network

c)

Malware to hide in system

d)

Encryption bypass

23.

Broken access control can lead to:

a)

Privilege escalation

b)

SQL injection

c)

Ransomware attacks

d)

Keylogging

24.

Which of the following is NOT an attack vector?

a)

Web applications

b)

Phishing

c)

Human behavior

d)

Antivirus software

25.

Exploit kits usually contain:

a)

Network scanning tools

b)

Malware that exploits known vulnerabilities

c)

Firewalls

d)

Password managers

26.

An attacker exploiting a system without leaving logs is using:

a)

DoS

b)

Stealth techniques

c)

SQL injection

d)

Phishing

27.

Brute-force attacks involve:

a)

Guessing passwords repeatedly

b)

Exploiting vulnerabilities

c)

Sending phishing emails

d)

Redirecting traffic

28.

Which of the following is a passive attack?

a)

Eavesdropping

b)

DoS

c)

Malware injection

d)

Privilege escalation

29.

Network sniffing tools capture:

a)

User passwords and traffic

b)

Malware signatures

c)

Logs only

d)

Only emails

30.

Security misconfiguration can result in:

a)

Unauthorized access

b)

Data leaks

c)

Malware infections

d)

All of the above

31.

A honeypot is used to:

a)

Detect and study attacks

b)

Encrypt sensitive files

c)

Prevent phishing

d)

Stop ransomware

32.

Which of the following prevents SQL injection?

a)

Input validation

b)

Firewalls only

c)

Antivirus

d)

Patching OS

33.

Using HTTPS prevents:

a)

Malware infection

b)

Traffic sniffing

c)

SQL injection

d)

Phishing attacks

34.

Multi-factor authentication (MFA) helps prevent:

a)

Brute-force attacks

b)

Worm infections

c)

Malware execution

d)

DoS attacks

35.

Security patches are important because they:

a)

Add new features

b)

Fix known vulnerabilities

c)

Remove user data

d)

Improve network speed

36.

Input sanitization helps prevent:

a)

Buffer overflow and injection attacks

b)

Malware execution

c)

DoS attacks

d)

Password theft

37.

Phishing emails often contain:

a)

Malicious links or attachments

b)

Encrypted files

c)

System logs

d)

Network scan reports

38.

Which is an example of a technical attack?

a)

SQL injection

b)

Social engineering

c)

Phishing

d)

Tailgating

39.

Which is an example of a human-based attack?

a)

Phishing

b)

Malware injection

c)

Buffer overflow

d)

Cross-site scripting

40.

A vulnerability scanner detects:

a)

Weaknesses in systems

b)

Malware only

c)

User credentials only

d)

Physical security flaws

41.

The CIA triad stands for:

a)

Confidentiality, Integrity, Availability

b)

Control, Identification, Access

c)

Cybersecurity, Integrity, Authorization

d)

Confidentiality, Information, Access

42.

Penetration testing is done to:

a)

Identify security weaknesses

b)

Encrypt sensitive data

c)

Patch systems

d)

Install antivirus

43.

Which of these is a preventive control?

a)

Firewall

b)

IDS

c)

IPS

d)

Both A & C

44.

IDS (Intrusion Detection System) is primarily:

a)

Preventive

b)

Detective

c)

Corrective

d)

Encryptive

45.

Encryption ensures:

a)

Confidentiality of data

b)

Network scanning

c)

Malware prevention

d)

Privilege escalation

46.

A buffer overflow attack targets:

a)

Memory space of a program

b)

Network bandwidth

c)

File permissions

d)

User credentials

47.

Session hijacking attacks:

a)

Steal active session tokens

b)

Delete malware

c)

Encrypt files

d)

Scan networks

48.

Social engineering exploits:

a)

Technical flaws

b)

Human psychology

c)

Network protocols

d)

Operating system vulnerabilities

49.

Two-factor authentication (2FA) is an example of:

a)

Detective control

b)

Corrective control

c)

Preventive control

d)

Compensating control

50.

The main goal of cybersecurity is to:

a)

Prevent unauthorized access and protect data

b)

Increase network speed

c)

Install more software

d)

Replace hardware

51.

The main purpose of vulnerability assessment is to:

a)

Hack into systems

b)

Identify security weaknesses before attackers do

c)

Encrypt data

d)

Install antivirus

52.

A vulnerability scanner is used to:

a)

Detect network weaknesses and system misconfigurations

b)

Encrypt files

c)

Train users

d)

Block malware

53.

Which of the following is a popular vulnerability scanning tool?

a)

Nessus

b)

Wireshark

c)

Metasploit

d)

Snort

54.

Active vulnerability scanning:

a)

Gathers information without interacting with the target

b)

Interacts with the target to find vulnerabilities

c)

Only checks firewalls

d)

Only analyzes logs

55.

Passive vulnerability scanning:

a)

Crashes the system to detect flaws

b)

Monitors traffic without interacting with the target

c)

Installs malware to find weaknesses

d)

Encrypts sensitive files

56.

Vulnerability assessment differs from penetration testing because:

a)

It only identifies vulnerabilities, not exploits them

b)

It hacks the system

c)

It always bypasses firewalls

d)

It installs malware

57.

Which step comes first in a vulnerability assessment?

a)

Reporting findings

b)

Scanning systems

c)

Planning and defining scope

d)

Exploiting vulnerabilities

58.

CVE in vulnerability management stands for:

a)

Common Vulnerabilities and Exposures

b)

Cybersecurity Vulnerability Exploit

c)

Computer Virus Evaluation

d)

Critical Vulnerability Event