Font size
WorksheetsCybersecurity Quiz
Total questions: 45
Worksheet time: 45mins
Which of the following best defines a network vulnerability?
A physical lock protecting a server
A weakness in hardware, software, or process that can be exploited
A software license agreement
An internet protocol address
Which act governs data privacy in South Africa?
Cybercrimes Act
Protection of Personal Information (POPI) Act
National Security Act
Privacy Protection Bill
The main goal of a firewall is to:
Store backup data
Prevent unauthorized network access
Encrypt passwords
Manage web applications
Which element of the CIA triad ensures that only authorized users can access data?
Integrity
Availability
Confidentiality
Encryption
Which of the following is NOT a type of malware?
Trojan horse
Worm
Firewall
Virus
A DDoS attack aims to:
Encrypt files
Gain administrator access
Steal data using phishing
Deny service to users by overwhelming a network
The main purpose of a security policy is to:
List computer hardware
Define security rules and user responsibilities
Control website content
Prevent software installation
Which biometric method analyses typing speed and patterns?
Retina scanning
Behavioural biometrics
Fingerprint scanning
Facial recognition
A VPN is primarily used to:
Increase network speed
Replace a firewall
Filter web content
Provide secure remote access
IDS stands for:
Intrusion Detection System
Internet Defence System
Internal Data Security
Information Detection Software
What is the main objective of network risk management?
To remove all risks
To identify, assess, and mitigate vulnerabilities
To collect user data
To improve physical design only
Which of the following is part of physical security?
Firewalls
Access control systems
VPN
Encryption
Which of these policies outlines specific rules for a topic like remote access?
System-specific policy
Issue-specific policy
Program policy
General security guideline
In cybersecurity, the principle of “least privilege” refers to:
Giving users maximum access
Denying all access
Allowing users only the access they need
Enabling public access
Encryption primarily protects:
Data confidentiality
Data availability
User interface design
Server performance
Physical security focuses only on cybersecurity.
TRUE
FALSE
Web content filtering helps reduce malware infections.
TRUE
FALSE
Encryption makes stolen data unreadable without the correct key.
TRUE
FALSE
A firewall allows unrestricted traffic across the network.
TRUE
FALSE
POPIA enforces data confidentiality and privacy.
TRUE
FALSE
IDS actively blocks attacks automatically.
TRUE
FALSE
A network attack is always passive.
TRUE
FALSE
Data backup ensures business continuity after a breach.
TRUE
FALSE
Strong passwords are an example of access control.
TRUE
FALSE
Governance has no link to cybersecurity legislation.
TRUE
FALSE
Which of the following are components of the CIA Triad?
Confidentiality
Identity
Integrity
Availability
Which of the following are types of network security policies defined by NIST?
Issue-specific policy
Program policy
Device-access policy
System-specific policy
Which of the following are examples of physical security controls?
Biometric locks
CCTV monitoring
Encryption software
Firewalls
Which best practices should a firewall administrator implement?
Use least-privilege rules
Update firmware regularly
Disable logging
Restrict admin access
Which of the following help protect data through encryption and backup?
Encrypt data at rest and in transit
Schedule regular automated backups
Store backups on the same system
Keep encryption keys secure
Which of the following can help detect a ransomware attack early?
IDS alerts
Network monitoring tools
Unpatched systems
Employee awareness
Which of the following are examples of user password responsibilities in a security policy?
Change passwords every 60–90 days
Share passwords with trusted coworkers
Use at least 8 characters including symbols
Enable MFA (multi-factor authentication)
Which of the following are causes of repeated login failures?
Brute-force attacks
Weak passwords
MFA enforcement
Credential reuse
Which actions should a network administrator take after detecting a brute-force attempt?
Implement account lockout policy
Block malicious IPs
Disable logging
Review system logs and reset credentials
Which of the following are long-term strategies to prevent cyberattacks?
Regular awareness training
Automated backups
Zero-trust access model
Ignoring system updates
A phishing email can directly install ransomware.
TRUE
FALSE
Network monitoring tools are unnecessary for small organizations.
TRUE
FALSE
Lack of employee training can lead to security breaches.
TRUE
FALSE
Incident response plans should be updated annually.
TRUE
FALSE
Data backups are ineffective against ransomware.
TRUE
FALSE
IDS tools only work after an attack is completed.
TRUE
FALSE
Firewalls can completely prevent phishing.
TRUE
FALSE
Implementing MFA reduces the impact of credential theft.
TRUE
FALSE
A zero-trust model assumes no user or device is trusted by default.
TRUE
FALSE
Outdated software has no impact on network defense.
FALSE
TRUE
