Worksheetsweek5
Total questions: 20
Worksheet time: 20mins
A university IT team forgets to update its Windows servers for several months. Hackers exploit an old vulnerability and deploy ransomware. What is the main vulnerability in this case?
Weak passwords
Unpatched operating system
Poor firewall rules
Low storage space
Your company’s email system is attacked through fake invoices sent to employees, leading some to download malware. What type of threat is this?
DDoS attack
Phishing
Password cracking
Keylogging
An employee plugs an unknown USB drive into a company laptop. The device installs hidden malware that spreads to the network. What was the hazard in this situation?
The employee’s curiosity
The antivirus software
Network bandwidth
Cloud storage
A hospital uses outdated legacy software to manage patient records. Attackers exploit a flaw to steal sensitive data. Which CIA principle is most affected?
Availability
Confidentiality
Integrity
None of the above
A web developer leaves default admin credentials (“admin123”) on a live website. Hackers log in and deface the site. What vulnerability was exploited?
SQL Injection
Weak default credentials
Poor encryption
DNS spoofing
A large retailer gives third-party vendors remote access to its network without multi-factor authentication. One vendor is hacked, leading to customer data theft. This scenario describes which real-world breach pattern?
Insider threat
Supply chain attack
DDoS attack
Zero-day exploit
During a DDoS attack, a university’s student portal becomes unreachable. Which element of the CIA triad was most impacted?
Integrity
Availability
Confidentiality
None
You’re connected to free public Wi-Fi at an airport and log into your email without HTTPS. A hacker intercepts your credentials. Which attack occurred?
Brute-force attack
Man-in-the-middle attack
Keylogger infection
Social engineering
A university researcher stores confidential exam papers in a shared Google Drive folder with “Anyone with link can view.” What is the vulnerability?
Cloud misconfiguration
SQL injection
Weak password hashing
Ransomware infection
A small business does not back up its systems. After a ransomware attack, all data is lost permanently. What was the main hazard?
No intrusion detection system
Lack of backup and recovery plan
Weak firewall
Strong passwords
What does a vulnerability refer to in cybersecurity?
The likelihood of an attack
A weakness that can be exploited
A type of malware
The strength of encryption
Which of the following best defines a threat?
A patch that fixes software
Any action or event that could cause harm
A network monitoring tool
A backup system
Which factor does not typically contribute to increased cyber risk?
Unpatched systems
Strong passwords
Poor user awareness
Weak encryption
Which of the following is an example of a technical control?
Security training
Encryption
Security policy
Awareness campaign
What is the main goal of patch management?
Increase system speed
Reduce vulnerabilities
Make software free
Delete malware
Which of these is a human vulnerability?
Weak password practices
Open ports on firewall
Lack of antivirus
Outdated software
What is the primary goal of network segmentation?
To improve internet speed
To isolate systems and limit attack spread
To share all data easily
To increase bandwidth
Which statement about hazards is true?
They directly cause attacks
They increase the likelihood of a threat being successful
They fix vulnerabilities
They are only physical
In the cyber risk formula, Risk = Threat × Vulnerability × Impact, what happens if any term equals zero?
Risk becomes zero
Risk doubles
Threats multiply
Risk increases
Which action best prevents email-based cyber threats?
Ignoring all emails
Using spam filters and user awareness training
Installing more RAM
Sharing credentials over email
