WorksheetsNetwork Vulnerabilities & Business Impact
Total questions: 40
Worksheet time: 20mins
What type of attack involves intercepting data transmitted between network devices?
Tapping/Eavesdropping
Denial of Service
Phishing
SQL Injection
Which vulnerability affects communication lines according to network security principles?
Crosstalk and radiation
Only software bugs
User passwords only
Firewall settings
In the threat hierarchy, which category includes fire and power failure?
Natural causes
Malicious intent
Directed attacks
Random attacks
What is an example of a "benign intent" human-caused threat?
Human error/misconfiguration
Ransomware attack
Data theft
Impersonation
Which type of loss involves disruption to normal business operations?
Operational loss
Reputational loss
Financial loss
What is the maximum GDPR fine for data protection breaches?
€20 million or 4% of global turnover
€10 million or 2% of global turnover
€5 million or 1% of global turnover
€50 million or 10% of global turnover
What does PCI-DSS stand for?
Payment Card Industry Data Security Standard
Personal Card Information Data Security Standard
Payment Card International Data Security Standard
Protected Card Industry Data Security Standard
How many main requirements does PCI-DSS have?
12
10
15
8
Which type of loss includes damage to an organisation's trustworthiness?
Reputational loss
Operational loss
Financial loss
Legal loss
What is a single point of failure in a network?
A component whose failure would cause entire system failure
A backup system
Multiple redundant connections
A firewall rule
Which type of attack targets specific organisations or individuals?
Directed attacks
Random attacks
Natural disasters
Benign errors
What type of loss includes regulatory fines and litigation costs?
Legal loss
Operational loss
Reputational loss
Financial loss
Level 1 PCI-DSS compliance applies to merchants processing how many transactions annually?
Over 6 million
Over 1 million
Over 100,000
Over 10 million
Which network vulnerability involves unauthorised changes to programmes?
Software modifications
Hardware failure
Natural disasters
Network congestion
What is the typical recovery time for reputation after a major breach?
18–24 months
3–6 months
6–12 months
1–3 months
Which component in a network is vulnerable to radiation attacks?
Processor
Keyboard
Mouse
Monitor
What type of malware encrypts files and demands payment?
Ransomware
Spyware
Adware
Trojan
Network segmentation helps prevent which PCI-DSS violation?
Mixing payment systems with general network traffic
Using strong passwords
Physical security
Employee training
Which type of loss directly affects revenue and includes theft of funds?
Financial loss
Operational loss
Reputational loss
Legal loss
What is an example of a random malicious attack?
Malicious code on a general website
Targeted CEO impersonation
Specific company espionage
Directed phishing campaign
DHCP failure would cause which type of immediate impact?
Devices cannot obtain IP addresses
Files are encrypted
Passwords are stolen
Physical damage occurs
The Computer Misuse Act 1990 addresses which type of loss?
Legal loss
Financial loss only
Reputational loss only
Operational loss only
Which of the following is NOT considered sensitive authentication data under PCI-DSS?
Cardholder name
CVV code
PIN number
Magnetic stripe data
What is the minimum consequence for PCI-DSS non-compliance?
Increased transaction fees
Criminal prosecution
Business closure
Nothing happens
A compromise at a switching centre affects which aspect of a network the most?
All network routing and connectivity
Only wireless connections
Only wired connections
Only internet access
Which threat type includes Advanced Persistent Threats (APTs)?
Directed malicious attacks
Random attacks
Natural causes
Human error
Erosion of customer trust is an example of which type of loss?
Reputational loss
Financial loss
Operational loss
Legal loss
What is a "cascade effect" in security incidents?
One incident triggering multiple types of losses
Only financial impact
Single system failure
Automatic recovery
Wireless access point failure primarily causes?
Service availability issues
Data theft
Regulatory fines
Physical damage
Which document is required for PCI-DSS Level 4 merchants?
Self-Assessment Questionnaire (SAQ)
Full security audit
Government certification
ISO 27001
Tapping into CAT6 cables is what type of vulnerability?
Physical security vulnerability
Software vulnerability
Cloud vulnerability
Wireless vulnerability
How long must businesses retain evidence after a security incident?
As required by legal/regulatory requirements
30 days
1 year exactly
Forever
What type of attack was the WannaCry ransomware?
Random malicious attack
Directed attack
Natural disaster
Benign error
Business interruption insurance covers which type of loss?
Operational and financial loss
Only reputational loss
Only legal loss
Only physical damage
What is the first priority in network risk mitigation?
Network segmentation
Staff training
New computers
Cloud migration
Social engineering primarily exploits which vulnerability?
Human factors
Software bugs
Hardware failures
Network speed
PCI-DSS Level 2 applies to how many annual transactions?
1–6 million
Over 6 million
Under 1 million
Under 20,000
Which type of loss includes increased insurance premiums?
Financial loss
Legal loss only
Reputational loss only
Operational loss only
What does IDS stand for in network security?
Intrusion Detection System
Internal Data Security
Internet Defence System
Integrated Defence Software
Supply chain disruption is primarily which type of loss?
Operational loss
Legal loss
Reputational loss only
Financial loss only
