wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

AP Cybersecurity 2.1 Physical Vulnerabilities and Attacks

Total questions: 28

Worksheet time: 14mins

Name
Class
Date
1.

What is a physical cybersecurity attack?

a)

Hacking someone's social media account

b)

Attempting to guess a password

c)

Gaining unauthorized access through physical means

d)

Creating strong encryption

2.

What is tailgating in cybersecurity?

a)

Following someone on social media

b)

Using someone else’s login credentials

c)

Entering a restricted area by following someone closely

d)

Spying through a camera

3.

What is the danger of leaving a USB device in a public space?

a)

It might get stolen and reused

b)

Someone could load malicious software onto it

c)

It could cause data overload

d)

It might overheat

4.

Which of the following is NOT a physical cybersecurity attack?

a)

A. Dumpster diving

b)

B. Shoulder surfing

c)

C. Phishing email

d)

D. Device theft

5.

What does dumpster diving involve?

a)

Throwing away old electronics

b)

Retrieving sensitive information from discarded materials

c)

Searching through data archives

d)

Exploring old digital files

6.

How can shoulder surfing be prevented?

a)

Disabling Bluetooth

b)

Installing antivirus software

c)

Using a privacy screen

d)

Changing your password frequently

7.

Why is physical security important in cybersecurity?

a)

It protects you from online scams

b)

It ensures faster Wi-Fi access

8.

What should you do if someone asks to use your laptop and you don’t know them?

a)

Let them use it while you watch

b)

Ask for their ID

c)

Politely decline and report it if necessary

d)

Give access only to the browser

9.

What might indicate hardware tampering?

a)

A laptop suddenly runs faster

b)

Cables are more organized

c)

Devices have unexpected parts or loose connections

d)

A screen is brighter than usual

10.

What is an effective defense against device theft?

a)

Turning off Wi-Fi

b)

Carrying your device at all times

c)

Encrypting your emails

d)

Avoiding public places

11.

Which object could improve physical cybersecurity?

a)

Noise-canceling headphones

b)

Laptop lock

c)

USB splitter

d)

Wireless mouse

12.

What does eavesdropping involve?

a)

Tracking GPS location

b)

Listening or watching someone's private information

c)

Reading documents left on desks

d)

Accessing network traffic

13.

What threat do power outages pose to cybersecurity?

a)

Increased system performance

b)

Reduced data storage

c)

Data loss and corruption

d)

Improved system availability

14.

Resilience in security systems is achieved by:

a)

Using a single layer of defense

b)

Building a layered defense

c)

Maximizing system complexity

d)

Reducing the frequency of backups

15.

What is piggybacking, in the context of cybersecurity?

a)

Creating fake invoices to trick employees or vendors

b)

Spreading false narratives about cyber threats

c)

Gaining entry to a restricted area without proper authentication by following an authorized person

d)

Manipulating or creating fake emails that appear to be from a legitimate brand

16.

What is a common tactic used in Piggybacking attacks?

a)

Sending emails with exaggerated threats

b)

Creating fake social media profiles

c)

Demanding immediate action or access by making it appear to be an emergency

d)

Using technical jargon to confuse the target

17.

How can organizations mitigate the risk of tailgating attacks?

a)

A. Establishing clear verification processes for access to restricted areas

b)

B. Allowing employees to hold doors open for everyone

c)

C. Disabling security cameras in entry points

d)

D. Encouraging visitors to bypass security checks

18.

What is the best defense against Piggybacking attacks?

a)

Providing personal information to unknown individuals

b)

Ignoring verification processes to speed up operations

c)

Volunteer information freely to appear cooperative

d)

Checking credentials, calling for proof, and verifying the identity of individuals

19.

Which of the following best describes phishing?

a)

Fishing for compliments on social media

b)

Attempting to gain sensitive information through electronic communication by posing as a trustworthy source

c)

Using real fishing as a metaphor for online security

d)

Sending out random emails without a specific target

20.

Individuals can defend against social engineering attacks by:

a)

Being cautious with sharing personal information

b)

Clicking on all email links

c)

Ignoring security updates

d)

Using the same password everywhere

21.

What is the main reason social engineering attacks succeed?

a)

Lack of security software

b)

Lack of proper computer hardware

c)

Exploitation of human biases and emotions

d)

Lack of encryption on communication channels

22.

What is the purpose of conducting simulated phishing campaigns?

a)

To serve as educational tools for employees

b)

To trick employees into providing sensitive information

c)

To discourage employees from reporting suspicious emails

d)

To avoid addressing social engineering tactics

23.

Looking for a person's information in the trash that can be used to carry out an attack.

a)

Spoofing

b)

Logic Bomb

c)

Dumpster Diving

d)

Black Hat

24.

Launched from several infected host machines looding systems, servers, and/or networks with traffic to overload resources and bandwidth

a)

Trojan

b)

Worms

c)

Denial of Service(DOS)

d)

Zero Day Exploit

25.

Attacker intercepts a two-party transaction, inserting themselves in the middle to steal and manipulate information

a)

RootKits

b)

Zero Day Exploit

c)

DOS

d)

Man In the Middle(MitM)

26.

Which potential threat relates to the mitigation strategy of hardening facilities or having alternate sites?

a)

Natural disaster

b)

Cyber attack

c)

Supply chain disruption

d)

Employee errors

27.

Select the three parts of the CIA triad?

a)

Integrity

b)

Authorization

c)

Intrusion

d)

Confidentiality

e)

Availability

28.

What is card cloning?

a)

Deleting an access card’s data to prevent use

b)

Creating a duplicate of an authorized user’s access card to gain unauthorized entry

c)

Encrypting an access card so only authorized readers can read it

d)

Logging every use of an access card for audit purposes