wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Cybersecurity Vocabulary and Definitions

Total questions: 75

Worksheet time: 1hrs 15mins

Name
Class
Date
1.

Fill in the blank: ________ is a cyber-security term that refers to a flaw in a system that can leave it open to attack.

a)

Vulnerability

b)

Encryption

c)

Firewall

d)

Authentication

2.

Fill in the blank: ________ is malware that prevents or limits users from accessing their system, either by locking the system's screen or by locking the user's files unless a ransom is paid.

a)

Ransomware

b)

Adware

c)

Spyware

d)

Rootkit

3.

Fill in the blank: ________ is software that is hidden from the user in order to gather information about internet interaction, keystrokes, passwords, and other valuable data.

a)

Spyware

b)

Adware

c)

Ransomware

d)

Malware

4.

Fill in the blank: ________ is designed to display advertisements on your computer and redirect your search request to advertising websites to collect marketing data about you.

a)

Adware

b)

Spyware

c)

Ransomware

d)

Rootkit

5.

Fill in the blank: ________ is a type of surveillance technology used to monitor and record each keystroke.

a)

Keylogger

b)

Firewall

c)

Antivirus

d)

Router

6.

Fill in the blank: ________ is a collection of tools or programs that enable administrator-level access to computer or computer network.

a)

Rootkit

b)

Firewall

c)

Antivirus

d)

Proxy

7.

Fill in the blank: ________ is a program that claims to free your computer from viruses but instead introduces viruses onto your system.

a)

Trojan horse

b)

Firewall

c)

Antivirus

d)

Cookie

8.

Fill in the blank: ________ is a network attack in which an unauthorized person gains access to network and stays there undetected for a long period of time.

a)

Advanced Persistent Threat (APT)

b)

Denial of Service (DoS)

c)

Phishing Attack

d)

Man-in-the-Middle Attack

9.

Fill in the blank: ________ is the body of technologies, processes, and practices involved in protecting individuals and organizations from cyber crime.

a)

Cyber Security

b)

Data Mining

c)

Cloud Computing

d)

Web Development

10.

Fill in the blank: ________ is any malicious act that attempts to gain access to a computer network without authorization or permission from the owners.

a)

Cyber threat

b)

Data backup

c)

Software update

d)

Network maintenance

11.

Fill in the blank: ________ is a method of bypassing normal authentication and gaining access in OS or application.

a)

Backdoor

b)

Firewall

c)

Patch

d)

Encryption

12.

Fill in the blank: ________ is an attack that intercepts and relays messages between two parties who are communicating directly with each other.

a)

Man-in-the-middle attack

b)

Phishing attack

c)

Denial-of-service attack

d)

Brute force attack

13.

Fill in the blank: ________ is any attack where the attackers attempt to prevent the authorized users from accessing the service.

a)

Denial of service attack

b)

Phishing attack

c)

Man-in-the-middle attack

d)

SQL injection

14.

Fill in the blank: ________ is a very common exploited web application vulnerability that allows malicious hacker to steal and alter data in website’s database.

a)

SQL injection

b)

Cross-site scripting (XSS)

c)

Denial of Service (DoS)

d)

Phishing

15.

Fill in the blank: ________ is a code injection attack that allows an attacker to execute malicious javascript in another user’s browser.

a)

Cross-Site Scripting (XSS)

b)

SQL Injection

c)

Denial of Service (DoS)

d)

Man-in-the-Middle (MitM)

16.

Fill in the blank: ________ is devised to bring real-time, adaptable, risk-aware access control to the enterprise. It represents a fundamental shift in the way access control is managed by introducing environmental conditions and risk levels into the access control decision process.

a)

Risk-adaptive access control (RAdAC)

b)

Role-based access control (RBAC)

c)

Mandatory access control (MAC)

d)

Discretionary access control (DAC)

17.

What is Policy-based Access control (PBAC)?

a)

Emerging model that seeks to help enterprises address the need to implement concrete access controls based on abstract policy and governance requirements. PBAC combines attributes from the resource, the environment, and the requester with information on the particular set of circumstances under which the access request is made. It uses rule sets that specify whether the access is allied under organizational policy for those attributes under those circumstances.

b)

A legacy access control model that only uses user roles to determine access rights, without considering policies or attributes.

c)

A method of access control that grants permissions solely based on the physical location of the user.

d)

A security model that allows unrestricted access to all resources within an organization, regardless of user identity or context.

18.

What is Attribute based access control (ABAC)?

a)

Access control decisions are made based on a set of characteristics, or attributes. Associated with the requester, the environment, and/or the resource itself.

b)

Access control decisions are made solely based on user roles within an organization.

c)

Access control decisions are made based on predefined lists of allowed users.

d)

Access control decisions are made only by the system administrator.

19.

What is Role-based access control (RBAC)?

a)

RBAC determines access based on roles. More than one person can have the same role. RBAC allows for the grouping of individuals into categories of people who fulfill a particular role. One set of access control permissions on a particular resource. The source code tree for a new piece of software can be set once for all members of the software engineering department.

b)

RBAC assigns access based on individual user preferences and personal history.

c)

RBAC provides access only to administrators and denies all other users.

d)

RBAC allows unrestricted access to all resources for every user, regardless of their role.

20.

What is Identity Management?

a)

A broad term to include the use of different products to identify, authenticate, and authorize users through automated means.

b)

A process of managing physical assets in an organization.

c)

A method for encrypting sensitive data in transit.

d)

A system for monitoring network traffic for security threats.

21.

What is Access Control in security engineering?

a)

It is where security engineering meets computer science. Its function is to control which (active) subject have access to a which (passive) object with some specific access operation.

b)

It is a method for encrypting data to prevent unauthorized access.

c)

It is a process of backing up data to ensure data recovery in case of loss.

d)

It is a technique for monitoring network traffic for suspicious activity.

22.

What is Physical Security?

a)

Essential to preventing unauthorized access to sensitive data as well as protecting an organization’s personnel and resources.

b)

A method for encrypting digital files on a computer.

c)

A type of software used to detect viruses.

d)

A process for backing up data to the cloud.

23.

Who are Insider threats?

a)

An insider that is defined as someone with legitimate access to the network.

b)

A person who hacks into the network from outside.

c)

A software that protects the network from viruses.

d)

A device used to store backup data.

24.

What is a Zero-day attack?

a)

A threat aimed at exploiting a software application vulnerability before the application vendor becomes aware of it and before the vulnerability becomes widely known to the internet security community. These attacks are among to mitigate and leave computers and networks extremely vulnerable.

b)

A type of attack that only occurs after a software patch has been released and installed.

c)

An attack that targets outdated hardware components rather than software vulnerabilities.

d)

A threat that is only effective against mobile devices and not computers.

25.

What are Botnets?

a)

Networks of compromised computers used by hackers for malicious purposes, usually criminal in nature.

b)

A type of computer virus that only infects mobile devices.

c)

A security protocol used to protect wireless networks.

d)

A software used for legitimate network management.

26.

What is Removable media in the context of security threats?

a)

The use of removable media on an organization's network poses a significant security threat. Without proper protection, these types of media provide a pathway for malware to move between networks or hosts.

b)

Removable media is a type of software used to encrypt files on a network.

c)

Removable media refers to permanent storage devices that cannot be disconnected from a network.

d)

Removable media is a security protocol used to monitor network traffic.

27.

What is cloud computing in the context of security?

a)

Large amounts of customer data are stored in shared resources, which raises a variety of data encryption and availability issues.

b)

Cloud computing is a method of securing local hard drives from malware.

c)

Cloud computing refers to the use of physical servers only for data storage.

d)

Cloud computing is a way to prevent phishing attacks on email accounts.

28.

What is the Data Protection Act?

a)

The law that protects us against illegal and inappropriate use of our personal information without our consent, and the same applies to us using the information of others.

b)

A law that regulates the use of public parks and recreational areas.

c)

A set of rules for managing internet bandwidth in organizations.

d)

A policy for protecting company property from theft.

29.

What is data protection law?

a)

Data protection law has become not only a vehicle for protecting citizens and consumers, it has become a gateway to trade.

b)

Data protection law is a set of rules for managing financial investments.

c)

Data protection law refers to guidelines for environmental conservation.

d)

Data protection law is a system for regulating international travel.

30.

Data security is commonly referred to as the ________, availability, and integrity of data.

a)

confidentiality

b)

transparency

c)

redundancy

d)

authenticity

31.

Good governance involves clearly defining jobs and responsibilities and evaluating employees according to their ________.

a)

results

b)

attendance

c)

appearance

d)

seniority

32.

Risk management refers to identifying, evaluating, and managing various risks, including legal, financial, and security-related risks. Organizations must employ resources to minimize risks by monitoring and controlling the impact of ________ events.

a)

security

b)

routine

c)

celebratory

d)

predictable

33.

The Committee of Sponsoring Organizations of the Treadway Commission (COSO) framework is a reputable ERM framework businesses across industries use to create a more holistic view of ________.

a)

risk

b)

profit

c)

marketing

d)

technology

34.

The National Institute of Standards and Technology (NIST) Cybersecurity Framework is a repeatable process for managing and improving ________.

a)

cybersecurity

b)

productivity

c)

customer service

d)

financial reporting

35.

The International Organization for Standardization (ISO) offers guidance on various business needs, including information security and ________ management.

a)

risk

b)

inventory

c)

marketing

d)

customer

36.

ISACA is a global professional association that develops frameworks for IT governance and risk management, including the Control Objectives for Information and Related Technologies (COBIT).

a)

True

b)

False

37.

A GRC framework is a model for managing governance and compliance risk in a company. It involves identifying the key policies that can drive the company toward its ________.

a)

goals

b)

losses

c)

competitors

d)

expenses

38.

GRC maturity is the level of integration of governance, risk assessment, and ________ within an organization.

a)

compliance

b)

finance

c)

marketing

d)

operations

39.

Who assesses risks when making strategic decisions?

a)

Senior executives

b)

Junior employees

c)

Interns

d)

Customers

40.

Who helps businesses mitigate legal exposures?

a)

Legal teams

b)

Marketing teams

c)

IT support

d)

Sales representatives

41.

Who supports compliance with regulatory requirements?

a)

Finance managers

b)

Marketing managers

c)

Sales executives

d)

Product designers

42.

Who deals with confidential recruitment information?

a)

HR executives

b)

Marketing managers

c)

IT technicians

d)

Finance analysts

43.

OCEG created an open-source GRC Capability Model integrating risk, governance, audit, ethics/culture, IT, and ________.

a)

compliance

b)

finance

c)

marketing

d)

sales

44.

Compliance refers to an organization's adherence to government regulations, industry standards, and internal ________.

a)

policies

b)

vehicles

c)

colors

d)

holidays

45.

Cyber threat intelligence is an area of cybersecurity that focuses on the collection and analysis of information about current and potential attacks that threaten the safety of an organization or its ________.

a)

assets

b)

employees

c)

software

d)

customers

46.

Fill in the blank: __________ is a high-level assessment of potential threats, identifying who might be interested in attacking the organization or companies in its industry and their motivations. It is presented to executives in the form of whitepapers, reports and presentations to show them how the organization needs to respond.

a)

Strategic threat intelligence

b)

Operational threat intelligence

c)

Technical threat intelligence

d)

Incident response planning

47.

Fill in the blank: __________ relates to how and where the organization may be targeted and focuses on cybercriminals tactics, techniques, and procedures. It is technical and is presented to IT and network professionals, to have them put defenses in place to prevent these types of attacks.

a)

Tactical threat intelligence

b)

Strategic threat intelligence

c)

Operational threat intelligence

d)

Physical security intelligence

48.

Fill in the blank: __________ is information gleaned from active attacks, cyber hotpots (traps to entice hackers to reveal their tactics) and data shared by third parties. It includes highly specific data such as URLs, file names and hashes, domain names, and IP addresses, and should be used to block attacks (if caught early enough), limiting damage and eliminating known threats in the network.

a)

Operational Threat intelligence

b)

Strategic Threat intelligence

c)

Tactical Threat intelligence

d)

Technical Threat intelligence

49.

Fill in the blank: __________ is the process to identify intelligence needs of organization, critical assets, and their vulnerabilities.

a)

Intel planning/strategy

b)

Incident response

c)

Risk acceptance

d)

Asset disposal

50.

Fill in the blank: __________ is the process to identify and collect relevant data for threat analytics.

a)

Data collection and aggregation

b)

Threat mitigation

c)

Incident response

d)

Vulnerability scanning

51.

Fill in the blank: __________ is the process to analyze collected data to develop relevant, timely, and actionable intelligence.

a)

Threat analytics

b)

Data encryption

c)

Network segmentation

d)

Access control

52.

Fill in the blank: __________ is the process to mitigate threats and disseminate intelligence.

a)

Intel usage and dissemination

b)

Threat escalation

c)

Data encryption

d)

Incident reporting

53.

Ransomware locks system down before demanding payment for the user to gain access.

a)

True

b)

False

54.

Fill in the blank: One common type of malware is __________, which can be installed on a system without your knowledge to obtain internet, usage data and other sensitive information.

a)

spyware

b)

adware

c)

ransomware

d)

rootkit

55.

Fill in the blank: __________ is a standardized XML based programming language developed to represent structured cyber threat indicators that can be easily understood by humans and cyber technologies.

a)

Structured threat information expression

b)

Common Vulnerability Scoring System

c)

Open Web Application Security Project

d)

Advanced Persistent Threat Modeling

56.

Fill in the blank: __________ defines set of services and message exchanges that, when implemented, enable sharing of actionable cyber threat information.

a)

Trusted Automated eXchange of indicator information

b)

Simple Mail Transfer Protocol

c)

Domain Name System

d)

File Transfer Protocol

57.

What is the definition of Intelligence in the context of digital forensics? Intelligence - __________ about threats and threat actors that provides sufficient understanding for mitigating a harmful event.

a)

Information

b)

Hardware

c)

Encryption

d)

Authentication

58.

Which organization describes the four phases of the digital evidence forensic process?

a)

A) NIST

b)

B) ISO

c)

C) IEEE

d)

D) STIX

59.

What is the first phase of the digital evidence forensic process according to NIST?

a)

A) Collection

b)

B) Examination

c)

C) Analysis

d)

D) Reporting

60.

Fill in the blank: Collection is the identification of potential sources of forensic data and acquisition, handling, and __________ of that data.

a)

storage

b)

deletion

c)

encryption

d)

transmission

61.

Examination in digital forensics refers to __________ and extracting relevant information from the collected data.

a)

accessing

b)

deleting

c)

encrypting

d)

transmitting

62.

Analysis in digital forensics involves drawing __________ from the data and correlation of data from multiple sources.

a)

conclusions

b)

pictures

c)

guesses

d)

stories

63.

Reporting in digital forensics is about preparing and presenting information that resulted from the __________ phase.

a)

analysis

b)

collection

c)

preservation

d)

identification

64.

Who developed the Cyber Kill Chain?

a)

Lockheed Martin

b)

NIST

c)

Microsoft

d)

Google

65.

What is the first step of the Cyber Kill Chain?

a)

A) Reconnaissance

b)

B) Weaponization

c)

C) Delivery

d)

D) Exploitation

66.

Which CSIRT activity involves training members in how to respond to an incident?

a)

Preparation

b)

Detection

c)

Recovery

d)

Eradication

67.

Which CSIRT activity quickly identifies, analyzes, and validates an incident?

a)

Detection and Analysis

b)

Recovery and Restoration

c)

Post-Incident Review

d)

Containment and Eradication

68.

Which CSIRT activity implements procedures to contain the threat, eradicate the impact on organizational assets, and use backups to restore data and software?

a)

Containment, Eradication, and Recovery

b)

Vulnerability Assessment and Patch Management

c)

Security Policy Development

d)

User Awareness Training

69.

Which CSIRT activity documents how the incident was handled, recommends changes for future response, and specifies how to avoid a reoccurrence?

a)

Post-Incident Activities

b)

Incident Detection

c)

Incident Containment

d)

Incident Identification

70.

The final step of the Cyber Kill Chain that describes the threat actor achieving their original objective.

(a)  

71.

Is when the threat actor performs research, gathers intelligence, and selects targets.

(a)  

72.

uses the information from reconnaissance to develop a weapon against specific targeted systems or individuals in the organization.

(a)  

73.

The weapon is transmitted to the target using a delivery vector. If the weapon is not delivered, the attack will be unsuccessful.

(a)  

74.

The threat actor uses it to break the vulnerability and gain control of the target

(a)  

75.

The threat actor establishes a back door into the system to allow for continued access to the target.

(a)