Font size
WorksheetsCybersecurity Chapter Review
Total questions: 24
Worksheet time: 22mins
Which of the following is the main goal of cybersecurity?
To protect only government networks
To secure physical documents
To protect digital systems, networks, and data from attacks
To develop new hardware components
The “I” in the CIA Triad stands for:
Integrity
Intelligence
Identification
Information
A hacker changing exam grades in a school’s database violates:
Confidentiality
Integrity
Availability
Authorization
Which of the following best describes Authentication?
Recording what users do
Deciding what users can access
Proving who a user is
Encrypting files for storage
A student who can access the teacher’s panel after logging in experiences failure in:
Auditing
Authorization
Authentication
Integrity
Which of the following threat actors is most motivated by financial gain?
Hacktivists
Cybercriminals
State-sponsored groups
Internal employees
A DDoS attack targets which cybersecurity principle of the CIA Triad?
Confidentiality
Integrity
Availability
Authentication
Social Engineering is best described as:
Infecting systems with malware
Tricking people into revealing information
Physically stealing computers
Encrypting files for ransom
Which of the following best explains why IoT devices are risky?
They use complex passwords
They’re disconnected from networks
They often lack security updates and have default passwords
They are only used in offices
Risk occurs when:
A hacker sends an email
A vulnerability exists but isn’t exploited
A threat exploits a vulnerability
A system is completely secure
Which of the following is a Preventive Control?
Restoring backups
Using a firewall
Reviewing logs
Investigating after an incident
Which principle of Zero Trust limits users to only the permissions they need?
Verify every request
Least Privilege Access
Micro-segmentation
Continuous Monitoring
An employee accidentally clicks a phishing link from a known contact. This represents:
Internal threat
External threat
Hybrid of internal and external
Physical threat
The Ukraine Blackout (2015) is an example of:
Physical theft of computers
Cyberattack on critical infrastructure
Insider espionage
Web spoofing attack
The main difference between cybersecurity and information security is that cybersecurity:
Includes physical protection like locks and cameras
Focuses only on digital assets and networks
Doesn’t involve the CIA Triad
Protects paper-based files
The Zero Trust model assumes that every user inside a network is safe.
True
False
Preventive, Detective, and Corrective controls together make a strong defense system.
True
False
Hacktivists attack mainly for financial profit.
True
False
Risk Assessment involves identifying, analyzing, and prioritizing risks.
True
False
Internal threats can be either intentional or accidental.
True
False
Explain the difference between Authentication and Authorization with one real-life example.
Define a Threat, Vulnerability, and Risk, and show how they are related.
List three core strategies of Risk Management and give one example of each.
What are two main reasons IoT devices are considered a security risk?
