Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

week5

Total questions: 20

Worksheet time: 20mins

Name
Class
Date
1.

A university IT team forgets to update its Windows servers for several months. Hackers exploit an old vulnerability and deploy ransomware. What is the main vulnerability in this case?

a)

Weak passwords

b)

Unpatched operating system

c)

Poor firewall rules

d)

Low storage space

2.

Your company’s email system is attacked through fake invoices sent to employees, leading some to download malware. What type of threat is this?

a)

DDoS attack

b)

Phishing

c)

Password cracking

d)

Keylogging

3.

An employee plugs an unknown USB drive into a company laptop. The device installs hidden malware that spreads to the network. What was the hazard in this situation?

a)

The employee’s curiosity

b)

The antivirus software

c)

Network bandwidth

d)

Cloud storage

4.

A hospital uses outdated legacy software to manage patient records. Attackers exploit a flaw to steal sensitive data. Which CIA principle is most affected?

a)

Availability

b)

Confidentiality

c)

Integrity

d)

None of the above

5.

A web developer leaves default admin credentials (“admin123”) on a live website. Hackers log in and deface the site. What vulnerability was exploited?

a)

SQL Injection

b)

Weak default credentials

c)

Poor encryption

d)

DNS spoofing

6.

A large retailer gives third-party vendors remote access to its network without multi-factor authentication. One vendor is hacked, leading to customer data theft. This scenario describes which real-world breach pattern?

a)

Insider threat

b)

Supply chain attack

c)

DDoS attack

d)

Zero-day exploit

7.

During a DDoS attack, a university’s student portal becomes unreachable. Which element of the CIA triad was most impacted?

a)

Integrity

b)

Availability

c)

Confidentiality

d)

None

8.

You’re connected to free public Wi-Fi at an airport and log into your email without HTTPS. A hacker intercepts your credentials. Which attack occurred?

a)

Brute-force attack

b)

Man-in-the-middle attack

c)

Keylogger infection

d)

Social engineering

9.

A university researcher stores confidential exam papers in a shared Google Drive folder with “Anyone with link can view.” What is the vulnerability?

a)

Cloud misconfiguration

b)

SQL injection

c)

Weak password hashing

d)

Ransomware infection

10.

A small business does not back up its systems. After a ransomware attack, all data is lost permanently. What was the main hazard?

a)

No intrusion detection system

b)

Lack of backup and recovery plan

c)

Weak firewall

d)

Strong passwords

11.

What does a vulnerability refer to in cybersecurity?

a)

The likelihood of an attack

b)

A weakness that can be exploited

c)

A type of malware

d)

The strength of encryption

12.

Which of the following best defines a threat?

a)

A patch that fixes software

b)

Any action or event that could cause harm

c)

A network monitoring tool

d)

A backup system

13.

Which factor does not typically contribute to increased cyber risk?

a)

Unpatched systems

b)

Strong passwords

c)

Poor user awareness

d)

Weak encryption

14.

Which of the following is an example of a technical control?

a)

Security training

b)

Encryption

c)

Security policy

d)

Awareness campaign

15.

What is the main goal of patch management?

a)

Increase system speed

b)

Reduce vulnerabilities

c)

Make software free

d)

Delete malware

16.

Which of these is a human vulnerability?

a)

Weak password practices

b)

Open ports on firewall

c)

Lack of antivirus

d)

Outdated software

17.

What is the primary goal of network segmentation?

a)

To improve internet speed

b)

To isolate systems and limit attack spread

c)

To share all data easily

d)

To increase bandwidth

18.

Which statement about hazards is true?

a)

They directly cause attacks

b)

They increase the likelihood of a threat being successful

c)

They fix vulnerabilities

d)

They are only physical

19.

In the cyber risk formula, Risk = Threat × Vulnerability × Impact, what happens if any term equals zero?

a)

Risk becomes zero

b)

Risk doubles

c)

Threats multiply

d)

Risk increases

20.

Which action best prevents email-based cyber threats?

a)

Ignoring all emails

b)

Using spam filters and user awareness training

c)

Installing more RAM

d)

Sharing credentials over email