wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Cybersecurity and Threat Management Quiz

Total questions: 12

Worksheet time: 6mins

Name
Class
Date
1.

A financial firm is implementing a new customer portal that allows clients to upload tax documents. During testing, the security analyst notices files can be intercepted if sent over HTTP. Which security goal is being violated, and what technology should be implemented to correct it?

a)

Integrity – Hashing

b)

Confidentiality – Encryption

c)

Availability – Redundancy

d)

Non-repudiation – Digital signatures

2.

A company recently added motion-activated cameras and badge readers at all entrances. The IT director explains these are meant to discourage intruders before they reach the server room. What type of control and function best describe these new measures?

a)

Managerial – Directive

b)

Operational – Corrective

c)

Physical – Deterrent

d)

Technical – Preventive

3.

After a malware outbreak, the IT team restores servers from clean backups and patches all systems. Which functional control type is the team performing?

a)

Detective

b)

Preventive

c)

Corrective

d)

Directive

4.

During an ongoing phishing campaign, analysts in the Security Operations Center (SOC) detect new malicious domains. They immediately alert developers through the DevSecOps channel so code repositories can block the URLs. Which business units are working together to maintain security resilience in this scenario?

a)

CIRT and Help Desk

b)

SOC and DevSecOps

c)

CIO and Legal Team

d)

CSO and Auditing Department

5.

A mid-level accountant in a company’s finance department begins emailing confidential client data to a competitor. The employee had legitimate access to the files as part of their daily duties. Which type of threat actor does this scenario describe?

a)

Unintentional insider

b)

Malicious insider

c)

External hacktivist

d)

Nation-state actor

6.

A company uses multiple cloud applications and remote access tools for employees. A penetration test shows that default admin passwords and open ports on several cloud servers could be exploited by attackers. Which two components of the organization’s security posture are being described?

a)

Threat vectors and attack surface

b)

Security policies and risk controls

c)

Firewall rules and proxy logs

d)

Compliance gaps and vulnerabilities

7.

A company receives reports that several employees found USB drives in the parking lot labeled “Confidential Salaries.” When inserted, the drives executed malicious scripts that gave attackers remote access to the company network. Which type of attack method was used?

a)

Social engineering using pretexting

b)

Watering hole attack

c)

Lure-based vector (drop attack)

d)

Message-based phishing attack

8.

A threat actor calls a company’s help desk claiming to be a senior executive who urgently needs access to an internal file. The attacker uses a confident tone and insists on bypassing standard verification procedures. Which social engineering techniques are being used in this scenario?

a)

Pretexting and urgency

b)

Whaling and pharming

c)

Baiting and disinformation

d)

Reconnaissance and shoulder surfing

9.

A cybersecurity firm discovers that an attack campaign has been slowly stealing data from government networks for over a year. The malware is custom-built, uses multiple zero-day exploits, and operates through compromised third-party servers. Which type of threat actor is most likely responsible?

a)

Script kiddie

b)

Hacktivist

c)

Nation-state APT

d)

Insider threat

10.

After a ransomware attack, the IT department isolates affected systems and notifies the incident response team. The legal department is also informed to assess regulatory obligations. Which business units are collaborating to address the incident?

a)

Sales and Customer Support

b)

Finance and Marketing

c)

HR and Facilities

d)

IT and Legal

11.

Security analysts discover a sophisticated cyberattack targeting a critical infrastructure provider. The attackers use advanced evasion techniques and have access to significant resources. Which type of threat actor is most likely behind this attack?

a)

Script kiddie

b)

Nation-state APT

c)

Disgruntled employee

d)

Cybercriminal group

12.

A company installs biometric scanners and security guards at the entrance to its data center. These measures are intended to prevent unauthorized physical access. What type of control and function do these measures represent?

a)

Physical – Preventive

b)

Operational – Directive

c)

Technical – Detective

d)

Managerial – Corrective