wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Cybersecurity Quiz

Total questions: 69

Worksheet time: 35mins

Name
Class
Date
1.

Which of the following best describes data integrity?

a)

Ensuring that the data is not modified

b)

Only authorized users can access data

c)

Changing data into something that has no meaning

d)

Ability to ensure identity of sender or receiver

2.

Which of the following is a function of encryption in cybersecurity?

a)

Change the data into something that has no meaning

b)

Ensure the data is not modified

c)

Block any traffic of the rule

d)

Distinguish between human and bot

3.

Which of the following is an example of a symmetric encryption algorithm?

a)

HES, 3DES

b)

RSA, ECC

c)

SHA, MD5

d)

WEP, WPA

4.

What is the main purpose of a firewall in network security?

a)

Block any traffic of the rule

b)

Encrypt data for confidentiality

c)

Authenticate users

d)

Prevent data modification

5.

Which of the following best describes non-repudiation?

a)

Ability of a system to prevent any party from denying he already did

b)

Ensuring only authorized users can access data

c)

Changing data into something meaningless

d)

Blocking unauthorized network traffic

6.

Which protocol is NOT considered a traditional network security protocol?

a)

WEP

b)

SSH

c)

TLS

d)

SSL

7.

Which of the following is a method to distinguish between a human and a bot?

a)

CAPTCHA

b)

Firewall

c)

Antivirus

d)

Checksum

8.

Which mindset assumes that someone wants to break your system and encourages you to study your system to avoid attacks?

a)

Security mindset

b)

Happy-path mindset

c)

Positive mindset

d)

Cyberspace mindset

9.

Why is it not enough to only add security at the edge of the network?

a)

Security should be added in both the border and inside the system

b)

Edge security is always absolute

c)

Only internal threats exist

d)

Firewalls are not effective at the edge

10.

Under what condition can a system be considered practically secure, according to the document?

a)

When the resources required for an attack to succeed are greater than the value of the data being protected

b)

When the system is disconnected from all networks

c)

When only authorized users have access

d)

When a firewall is installed

11.

Which of the following is NOT a method to guarantee a system is completely secure?

a)

Using weak passwords

b)

Backup

c)

Cloud service

d)

Antivirus

12.

What is the main motivation for an attacker to breach a system?

a)

The value of the data being protected

b)

The complexity of the encryption algorithm

c)

The number of users on the system

d)

The type of firewall used

13.

Which of the following is a tool used in vulnerability assessment?

a)

Penetration testing using tool

b)

Data encryption

c)

CAPTCHA

d)

Cloud service

14.

Which type of attacker is known for having a strong understanding of systems and using their skills for criminal purposes?

a)

Black Hat

b)

White Hat

c)

Grey Hat

d)

Script Kiddie

15.

What is the primary motivation of a Grey Hat hacker?

a)

Usually not to cause harm or steal data

b)

To work for the government

c)

To only test their own systems

d)

To always follow ethical guidelines

16.

Which of the following best describes a Script Kiddie?

a)

Does not fully understand the technical background of hacking

b)

Works for the national government

c)

Has strong skills like a Black Hat

d)

Only attacks physical assets

17.

Which of the following is considered a tangible asset?

a)

Physical thing

b)

Business plan

c)

Data record

d)

Copyright

18.

What is the main duty of cybersecurity?

a)

To change and improve organizational culture

b)

To create new software

c)

To increase hardware speed

d)

To reduce employee numbers

19.

Which of the following is an example of a threat?

a)

Someone who intends to cause harm to an asset

b)

A new software update

c)

A backup system

d)

A firewall installation

20.

What is a zero-day attack?

a)

An exploit that is unknown to the world

b)

An attack that happens every day

c)

A physical theft of hardware

d)

A routine system update

21.

Which of the following is NOT a step in countermeasure?

a)

Prevention

b)

Detection

c)

Reaction

d)

Exploitation

22.

What is a vulnerability in the context of cybersecurity?

a)

A weakness that hackers can exploit to gain access to systems

b)

A type of hardware upgrade

c)

A new software feature

d)

A backup procedure

23.

Which of the following is an example of exposure in cybersecurity?

a)

Known vulnerability that is not yet patched

b)

A new antivirus installation

c)

A secure password policy

d)

A regular software update

24.

(DoK Level 2) How can assets be categorized in cybersecurity?

a)

Hardware, Software, Communication lines

b)

Only physical things

c)

Only business plans

d)

Only employee records

25.

(DoK Level 2) What is the difference between an event and an incident in cybersecurity?

a)

An event can be routine and not require action, while an incident negatively affects the IT system and requires action

b)

An event always requires action, while an incident never does

c)

An event is always negative, while an incident is always positive

d)

There is no difference between an event and an incident

26.

(DoK Level 3) If an employee is not well educated about security policies, what could be a potential consequence for the organization?

a)

It might destroy the organization's security

b)

It will increase the organization's profits

c)

It will improve the organization's reputation

d)

It will reduce the need for cybersecurity

27.

(DoK Level 3) Why is it important to implement detection as part of a countermeasure strategy?

a)

So you can detect when, how, and which asset has been damaged

b)

To increase the number of employees

c)

To reduce the cost of hardware

d)

To avoid using any security mechanisms

28.

Which of the following best defines "risk" in the context of network security?

a)

The potential for damage that could occur when vulnerability is exploited

b)

The process of encrypting data during transmission

c)

The method of authenticating users in a network

d)

The act of backing up data to prevent loss

29.

Which of the following is NOT a key component of risk?

a)

Threat agent exploiting vulnerability

b)

Impact if the attacker is successful

c)

Data encryption algorithm

d)

Vulnerability in the system

30.

What is the primary purpose of network security?

a)

Protect data during communication

b)

Increase network speed

c)

Reduce hardware costs

d)

Improve user interface design

31.

Which of the following is an example of a secure communication protocol?

a)

HTTPS

b)

FTP

c)

Telnet

d)

HTTP

32.

Which of the following is NOT one of the five things to ensure during data transmission?

a)

Safe communication

b)

Message secrecy

c)

Authentic identity of participants

d)

Data compression

33.

What does "confidentiality" in the C-T-A triad refer to?

a)

Hiding data from unauthorized access

b)

Ensuring data is always available

c)

Making data readable to everyone

d)

Allowing data to be modified by anyone

34.

Which of the following best describes "integrity" in information security?

a)

Protection from unauthorized access and ensuring data is not altered

b)

Making sure data is always available

c)

Encrypting all data transmissions

d)

Allowing anonymous access to data

35.

What is the main focus of "availability" in the C-T-A triad?

a)

Ensuring data are accessible when needed

b)

Hiding data from unauthorized users

c)

Encrypting data at rest

d)

Preventing data from being modified

36.

Which of the following is a method to support data integrity?

a)

Digital watermarking

b)

Data compression

c)

Data fragmentation

d)

Data mining

37.

If a machine is compromised and able to read private data, which aspect of security is most at risk?

a)

Confidentiality

b)

Availability

c)

Non-repudiation

d)

Anonymity

38.

Why is a checksum value important in data integrity?

a)

It helps detect if data has been changed during transmission

b)

It encrypts the data for secure communication

c)

It compresses the data for faster transfer

d)

It anonymizes the sender of the data

39.

Which of the following is an example of a measure to ensure availability?

a)

Backup and load balancing

b)

Data encryption

c)

User authentication

d)

Message hashing

40.

Which of the following is a main threat to system availability?

a)

Network failure

b)

Unauthorized access

c)

Modification

d)

Masquerading

41.

What is the principle of least privilege in access control?

a)

Having only the permissions needed to do your job

b)

Giving all users administrator rights

c)

Allowing access to all resources

d)

Sharing passwords with colleagues

42.

Which of the following is an example of providing confidentiality for sensitive data?

a)

Using a physical dedicated point-to-point link

b)

Allowing public access to data

c)

Storing passwords in plain text

d)

Disabling encryption

43.

What is the main function of end-to-end encryption (E2EE)?

a)

Encrypting data on the sender's device and only decrypting on the receiver's device

b)

Encrypting data only at intermediate network nodes

c)

Allowing all network devices to read the message content

d)

Storing data in unencrypted form

44.

To keep data at rest confidential, which of the following is NOT required?

a)

Disabling user authentication

b)

Strong encryption

c)

User authentication with name and password

d)

Access control policies

45.

Which of the following is a threat to confidentiality?

a)

Snooping

b)

Modification

c)

Denial of service

d)

Ransomware

46.

Which of the following security attacks is classified as a threat to integrity?

a)

Modification

b)

Denial of service

c)

Snooping

d)

Traffic analysis

47.

Which of the following best describes the three main security goals?

a)

Confidentiality, integrity, and availability

b)

Encryption, authentication, and authorization

c)

Privacy, access, and control

d)

Prevention, detection, and response

48.

Which security service focuses on the person’s attitude and behavior?

a)

Privacy

b)

Confidentiality

c)

Availability

d)

Anonymity

49.

To ensure which security service can we substitute the original names with nicknames?

a)

Confidentiality

b)

Privacy

c)

Anonymity

d)

Availability

50.

Which security service is concerned with the ability to access or not access a specific resource?

a)

Availability

b)

Privacy

c)

Confidentiality

d)

Anonymity

51.

If you don’t want anyone except the one you give permission to access your resource, which security service are you ensuring?

a)

Confidentiality

b)

Privacy

c)

Anonymity

d)

Availability

52.

Which security service ensures that unauthorized persons should not have any access or disclosure of data?

a)

Anonymity

b)

Confidentiality

c)

Privacy

d)

Availability

53.

If all entities in a system are equal and unknown to each other, which security service does this describe?

a)

Privacy

b)

Confidentiality

c)

Anonymity

d)

Availability

54.

Announcing the name of a person who has not participated in any activity is a violation of which security service?

a)

Privacy

b)

Confidentiality

c)

Anonymity

d)

Availability

55.

Having part of the information that identifies a participant is a violation of which security service?

a)

Privacy

b)

Confidentiality

c)

Anonymity

d)

Availability

56.

Announcing the name of the person who has the permission to access specific data is a violation of which security service?

a)

Privacy

b)

Confidentiality

c)

Anonymity

d)

Availability

57.

Having part of your information provided to unauthorized persons is considered a violation of which security service?

a)

Privacy

b)

Confidentiality

c)

Anonymity

d)

Availability

58.

Which security service is addressed by the policy: "Avoid using public WiFi networks"?

a)

Integrity

b)

Availability

c)

Confidentiality

d)

Authentication

59.

Removing duplicate records in a system is a solution mechanism for which aspect of the C-I-A Triad?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Authentication

60.

Blacklisting incoming connections from known IP addresses primarily enhances which security service?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Non-repudiation

61.

Issuing a digital signature is most closely related to which component of the C-I-A Triad?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Authentication

62.

Do not repeat passwords for every site you register in. This policy is mainly concerned with which security service?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Non-repudiation

63.

Shredding or incinerating papers is a solution mechanism for which aspect of security?

a)

Availability

b)

Confidentiality

c)

Integrity

d)

Authentication

64.

Issuing a robot test via CAPTCHA is intended to improve which security service?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Non-repudiation

65.

Adopting cloud computing services is primarily a solution for which part of the C-I-A Triad?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Authentication

66.

Utilizing VPN tunneling is a mechanism to enhance which security service?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Non-repudiation

67.

Fault-tolerant technologies such as RAID that can detect and fix faults are mainly used to ensure which security service?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Authentication

68.

Given a scenario where a company wants to ensure that their data is not altered during transmission, which security service should they focus on?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Authentication

69.

A business wants to make sure their services are always accessible to users, even during a cyber attack. Which part of the C-I-A Triad is most relevant?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Non-repudiation