WorksheetsCybersecurity Scenarios and Policies Quiz
Total questions: 25
Worksheet time: 13mins
A security analyst notices PowerShell scripts running in memory that establish outbound connections to unknown IPs, even though no malicious files are saved to disk. Which type of malware is most likely involved?
Trojan
Fileless malware
Rootkit
Boot virus
A user installs a free media player, but the software also installs a browser toolbar and multiple background processes that consume system resources. Which malware category best describes this situation?
Worm
Spyware
Potentially Unwanted Program (PUP)
Backdoor
A technician observes that CPU utilization on a user’s workstation stays above 90% even when idle, and fans are running constantly. What type of malicious activity does this most likely indicate?
Ransomware
Logic bomb
Cryptojacking
Keylogger
An attacker floods local hosts with unsolicited ARP replies that associate the attacker’s MAC address with the default gateway IP. Which type of attack is being performed?
DNS poisoning
ARP poisoning
Man-in-the-browser
Smurf attack
A company’s web server becomes unreachable after a flood of SYN requests from thousands of unique IPs. Investigation shows the attack is being coordinated from multiple compromised hosts. What is this attack type?
Amplified attack
Botnet DDoS
Port scan
Ping of Death
An attacker gains access to a database containing hashed passwords and attempts to derive the original passwords offline using software that tests every possible combination. Which attack method is being used?
Pass-the-hash
Dictionary attack
Brute-force attack
Credential replay
A system administrator detects hidden processes that survive OS reinstallation and cannot be removed by antivirus. Which type of rootkit is likely present?
Boot sector rootkit
Firmware rootkit
Kernel-mode rootkit
Application rootkit
A penetration tester enters ../../../../etc/config into a web application’s URL field and gains access to restricted files. Which vulnerability is being exploited?
Cross-site scripting (XSS)
Directory traversal
Command injection
SQL injection
An attacker manipulates a handshake to force a server to use an older version of TLS with weak ciphers. Which type of cryptographic attack is this?
Collision attack
Replay attack
Downgrade attack
Padding oracle
An attacker captures an NTLM hash from one system and reuses it to authenticate to another system without knowing the password. Which attack type is this?
Pass-the-ticket
Replay attack
Pass-the-hash
Brute-force attack
A user is disciplined for installing torrent software on a company laptop, violating a policy that defines acceptable and unacceptable online behavior. Which policy was violated?
Information Security Policy
Acceptable Use Policy (AUP)
Business Continuity Policy
Change Management Policy
Which of the following best describes the primary goal of an Information Security Policy?
To ensure that employees use systems ethically
To establish technical security controls for all devices
To ensure all IT users follow guidelines protecting organizational data
To assign disaster recovery responsibilities
During a regional flood, an organization activates a plan that allows essential functions to continue from a secondary site. Which policy is being implemented?
Incident Response Policy
Disaster Recovery Policy
Business Continuity and Continuity of Operations Plan (COOP)
Change Management Policy
Which of the following best defines a Disaster Recovery Policy?
Describes how to detect and report security incidents
Defines steps to resume critical operations after an outage
Explains how users can access backup servers
Defines acceptable internet browsing behavior
An organization detects unauthorized access to its HR database. The security team follows predefined steps to contain, analyze, and eradicate the threat. Which policy guided their actions?
Change Management Policy
Incident Response Policy
Business Continuity Policy
Acceptable Use Policy
What is the main purpose of an SDLC Policy?
To ensure all users follow acceptable network behavior
To define disaster recovery procedures
To structure secure and efficient software creation
To regulate payment card data storage
A healthcare organization is fined for failing to protect patient records. Which law was violated?
SOX
GLBA
HIPAA
FISMA
Which statement best describes the goal of regulatory compliance in cybersecurity governance?
To follow internal HR procedures
To meet obligations defined by external laws and regulations
To define acceptable use of company resources
To create encryption standards
A data center plans to upgrade firewall firmware. A team submits a request for approval, tests the update, creates a rollback plan, and schedules the change during off-hours. Which governance process is being demonstrated?
Business Continuity
Incident Response
Change Management
Configuration Management
A U.S.-based online retailer markets to European Union residents and must follow privacy rules requiring explicit consent to process personal data. Which regulation applies?
SOX
GDPR
PCI DSS
FISMA
I lock all your files until you pay for them to be unlocked – if you don’t pay in 24 hours, I will delete them all – What am i?
Spyware
Ransomware
Malware
Virus
I attach myself to documents and files, I disrupt the system. I need a host program to work from the inside - What am i?
A Virus
Trojan Horse
Ransomware
Spyware
I replicate and spread across through devices connected on the network.
A Virus
A worm
A Firewall
Ransomeware
I look like a normal piece of software but secretly I will infect your system – What am i?
Trojan Horse
Virus
Phishing Email
Ransomware
