wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

T2 - CyberSecurity Threat Landscape

Total questions: 60

Worksheet time: 2hrs 30mins

Name
Class
Date
1.

A company discovers malicious code designed to silently capture keyboard input to steal customer login credentials.

a)

Rootkit

b)

Keylogger

c)

Worm

d)

Logic Bomb

2.

Which threat best describes malware that encrypts user files and demands cryptocurrency payment to restore access?

a)

Ransomware

b)

Trojan Horse

c)

Spyware

d)

Bloatware

3.

A self-replicating program is spreading across the network without user interaction.

a)

Worm

b)

Trojan Horse

c)

Spyware

d)

Logic Bomb

4.

An employee downloads a free “video-player” app that secretly installs a backdoor.

a)

Trojan Horse

b)

Worm

c)

Spyware

d)

Ransomware

5.

During an incident investigation, analysts find malware that replaced system drivers to hide its presence at the kernel level.

a)

Rootkit

b)

Spyware

c)

Logic Bomb

d)

Bloatware

6.

A disgruntled developer embeds code that erases databases if their user account is disabled.

a)

RAT

b)

Logic Bomb

c)

Keylogger

d)

Backdoor

7.

Which of the following is usually unwanted but not directly malicious, often pre-installed trial software that slows devices?

a)

Spyware

b)

Bloatware

c)

Trojan Horse

d)

Rootkit

8.

A cyber-criminal floods a web server with traffic from thousands of compromised IoT devices, causing it to crash.

a)

DoS

b)

DDoS

9.

What distinguishes an Advanced Persistent Threat (APT) from other attacks?

a)

Uses ransomware for quick payout

b)

Stealthy, long-term infiltration often by nation-states

c)

Always relies on insider negligence

d)

Only targets IoT devices

10.

A partner company’s software update is compromised before release and installs malware at customers’ sites.

a)

Insider Threat

b)

Supply-Chain Attack

c)

Trojan Horse

d)

APT

11.

An attacker tricks an employee into revealing VPN credentials via a fake HR-portal email.

a)

Phishing

b)

Keylogging

c)

Logic Bomb

d)

DoS

12.

A CFO receives a spoofed email tailored with their name and internal details, requesting an urgent wire transfer.

a)

Whaling

b)

Spear Phishing

c)

Vishing

d)

Pharming

13.

Which threat actor is MOST commonly linked to espionage against critical infrastructure and usually backed by government resources?

a)

Hacktivist

b)

Nation-State Actor

c)

Organized Crime

d)

Competitor

14.

A group launches cyber-attacks to protest environmental policies.

a)

Hacktivist

b)

Organized Crime

c)

Competitor

d)

Script Kiddie

15.

An entry-level attacker downloads free exploit scripts without understanding the code.

a)

Insider (Negligent)

b)

Script Kiddie

c)

Hacktivist

d)

APT Operative

16.

A data-center technician accidentally leaves default admin passwords on exposed servers, leading to a breach.

a)

Insider (Unintentional)

b)

Competitor

c)

Hacktivist

d)

Terrorist Group

17.

A former employee, angry about being fired, steals proprietary code before departure.

a)

Organized Crime

b)

Insider (Intentional)

c)

Competitor

d)

APT

18.

Which threat actor's main objective is monetary profit through ransomware, fraud, or credential theft?

a)

Organized Crime

b)

Hacktivist

c)

Nation-State

d)

Terrorist Group

19.

A rival manufacturer conducts cyber-espionage to steal product-design blueprints.

a)

Hacktivist

b)

Competitor

c)

Insider (Negligent)

d)

Nation-State

20.

Which actor type is typically motivated by mass disruption, fear, or destruction, sometimes combining cyber and physical tactics?

a)

Organized Crime

b)

Hacktivist

c)

Terrorist Group

d)

Script Kiddie

21.

A covert group compromises a defense contractor’s email for long-term intelligence gathering.

a)

APT sponsored by Nation-State

b)

Organized Crime

c)

Hacktivist

d)

Competitor

22.

Which motivator BEST explains ransomware gangs demanding cryptocurrency from hospitals?

a)

Disruption / Chaos

b)

Financial Gain

c)

Political / Ideological

d)

Notoriety / Fame

23.

A rival nation hacks research labs to steal vaccine formulas.

a)

Espionage / Intelligence Gathering

b)

Disruption / Chaos

c)

Revenge / Grudge

d)

Notoriety / Fame

24.

A hacktivist group defaces a government website to protest a new law.

a)

Financial Gain

b)

Political / Ideological Goals

c)

Revenge

d)

Notoriety / Fame

25.

A disgruntled ex-employee deploys a logic-bomb to delete files on their last day.

a)

Financial Gain

b)

Revenge / Personal Grudge

c)

Espionage

d)

Notoriety / Fame

26.

Which motivator is commonly associated with chaos-driven threat actors whose goal is to destabilize or disrupt services without financial gain?

a)

Notoriety / Fame

b)

Disruption / Chaos

c)

Espionage

d)

Revenge

27.

A contractor introduces malware into a corporate network by plugging in an infected external USB drive.

a)

Cloud Services

b)

Removable Media

c)

Wireless Network

d)

Physical Access

28.

An attacker exploits an insecure API of a cloud-storage provider to access private backups.

a)

Cloud Services

b)

Websites

c)

Email

d)

Social Media

29.

A user is lured to a fake banking site by clicking a link on social media and enters credentials.

a)

Websites

b)

Email

c)

Social Media

d)

Physical Access

30.

An adversary breaks into the server room and installs a rogue device on the internal switch.

a)

Physical Access

b)

Wireless

c)

Email

d)

Supply-Chain

31.

Attackers exploit an outdated plugin on a corporate blog to deploy malicious JavaScript to site visitors.

a)

Websites

b)

Cloud Services

c)

Wireless

d)

Email

32.

Hackers compromise a third-party component used in a company’s online-ordering platform to inject malware during checkout.

a)

Supply-Chain / Third-Party Vendor

b)

Wireless

c)

Cloud Services

d)

Removable Media

33.

A café’s unencrypted public Wi-Fi allows an attacker to intercept session cookies from customers logging into webmail.

a)

Wireless / Wi-Fi

b)

Social Media

c)

Cloud Services

d)

Websites

34.

Which open-framework provides a knowledge base of adversary tactics, techniques, and procedures (TTPs) mapped to attack phases?

a)

MITRE ATT&CK

b)

OWASP

c)

NIST

d)

ISO

35.

A security engineer checks the CVE database to see if a known exploit exists for a newly disclosed software bug.

a)

Patch-management schedules

b)

Unique IDs for public vulnerabilities

c)

Cloud risk-score rankings

d)

Encrypted threat-feed channels

36.

The National Vulnerability Database (NVD) builds upon CVE by adding which key element?

a)

Threat-actor profiles

b)

CVSS metrics and severity data

c)

DNS blacklists

d)

Encrypted file-hash archives

37.

A web-app developer checks the OWASP Top 10 list during code reviews.

a)

Web-application vulnerabilities

b)

Endpoint hardening

c)

ICS / SCADA exploits

d)

Wireless encryption

38.

Which resource enables machine-to-machine sharing of structured threat indicators between trusted partners?

a)

STIX / TAXII

b)

OSINT

c)

IC3

d)

MITRE

39.

Security analysts from multiple hospitals collaborate to share indicators of ransomware campaigns targeting healthcare.

a)

ISAC

b)

OSINT

c)

MITRE ATT&CK

d)

NVD

40.

A company relies on public tweets, blogs, and research forums to monitor new phishing domains.

a)

ISAC

b)

OSINT

c)

Vendor Feed

d)

CVE

41.

Victims of cyber-fraud submit complaints to a federal agency that aggregates incidents for investigation.

a)

FBI IC3

b)

CISA

c)

ISAC

d)

OWASP

42.

A persistent threat actor installs a covert program allowing remote control of a victim’s workstation.

a)

RAT

b)

IDS

c)

SIEM

d)

SOC

43.

Which acronym refers to the triad of fundamental security objectives: protecting data from unauthorized disclosure, unauthorized change, and service disruption?

a)

CIA

b)

ISP

c)

IDS

d)

RAT

44.

An organization deploys an IDS to monitor inbound packets and generate alerts on suspicious patterns but does not block them.

a)

Integrated Defense Suite

b)

Intrusion Detection System

c)

Internal Data Scanner

d)

Internet Domain Shield

45.

Security teams upgrade to an IPS to automatically drop malicious traffic identified in real-time.

a)

Cloud-logging

b)

Automated prevention / blocking

c)

Threat-hunting dashboards

d)

Baseline compliance scans

46.

The enterprise SOC operates 24/7 to triage SIEM alerts and coordinate incident response.

a)

Security Operations Center

b)

Secure Online Console

c)

System Orchestration Control

d)

Security Output Channel

47.

A web server is compromised via a malicious SQL statement embedded in a login field.

a)

XSS

b)

SQLi

c)

RAT

d)

MITRE

48.

A malicious script is injected into a legitimate website’s comment section and executes in visitors’ browsers.

a)

RAT

b)

SQLi

c)

XSS

d)

APT

49.

A university’s network is breached by attackers who publicly leak stolen research to protest animal-testing labs.

a)

Organized Crime

b)

Hacktivist

c)

Nation-State

d)

Insider (Negligent)

50.

An intruder disrupts emergency-dispatch phone services just to cause panic during a local festival—no ransom demanded.

a)

Financial Gain

b)

Revenge / Grudge

c)

Disruption / Chaos

d)

Notoriety / Fame

51.

A new hire connects an infected personal USB to transfer résumé files, which unleashes ransomware onto the HR subnet.

a)

Cloud Service

b)

Removable Media

c)

Physical Access

d)

Wireless / Wi-Fi

52.

A rival start-up pays a contractor to steal design schematics of a new electric-car battery.

a)

Actor: Competitor Motivator: Espionage / Intelligence Gathering

b)

Actor: Hacktivist Motivator: Political / Ideological

c)

Actor: Organized Crime Motivator: Financial Gain

d)

Actor: Insider (Unintentional) Motivator: Notoriety / Fame

53.

A bank’s call-center PC was secretly infected after a customer-service rep clicked a fake email attachment; malware stayed dormant for weeks until triggered to delete logs. What type of malware was used?

a)

Worm

b)

Logic Bomb

c)

Rootkit

d)

Keylogger

54.

Security cameras at a water-treatment plant go offline after highly sophisticated malware—undetected for months—exfiltrates plant-schematic data. What type of actor and threat was involved?

a)

Nation-State APT, Advanced Persistent Threat

b)

Script Kiddie, Trojan

c)

Organized Crime, Ransomware

d)

Hacktivist, DoS

55.

During a high-profile sporting event, attackers spread malicious shortened links on Twitter that redirect users to a credential-harvesting site. What vector was used for the attack?

a)

Social Media

b)

Websites

c)

Cloud Service

d)

Physical Access

56.

A fired IT admin posts VPN passwords to a public forum to “teach the company a lesson.” What type of actor and motivator is involved?

a)

Insider (Intentional), Revenge / Personal Grudge

b)

Hacktivist, Political / Ideological

c)

Organized Crime, Financial Gain

d)

Terrorist Group, Disruption / Chaos

57.

An e-commerce site’s payment form allows attackers to inject a rogue SQL statement that steals customer credit-card data. What type of attack is this?

a)

Type: SQLi Vector: Web Application / Website

b)

Type: RAT Vector: Cloud Service

c)

Type: Worm Vector: Removable Media

d)

Type: DoS Vector: Wireless

58.

Imagine Aria and David have set up a small office network. What is the primary function of a firewall they installed to protect their network?

a)

To increase internet speed.

b)

To serve as a physical barrier against network intrusion.

c)

To monitor and control incoming and outgoing network traffic based on predetermined security rules.

d)

To detect and remove viruses and other malware.

59.

What is the main purpose of a firewall in network security?

a)

To increase the speed of the network

b)

To monitor and control incoming and outgoing network traffic based on predetermined security rules

c)

To serve as a physical barrier against intruders

d)

To manage the data storage on a network

60.

What type of attack involves overwhelming network resources with unwanted traffic?

a)

Phishing attack

b)

Distributed Denial of Service (DDoS) attack

c)

SQL injection

d)

Man-in-the-middle attack