wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Cybersecurity Scenarios and Policies Quiz

Total questions: 25

Worksheet time: 13mins

Name
Class
Date
1.

A security analyst notices PowerShell scripts running in memory that establish outbound connections to unknown IPs, even though no malicious files are saved to disk. Which type of malware is most likely involved?

a)

Trojan

b)

Fileless malware

c)

Rootkit

d)

Boot virus

2.

A user installs a free media player, but the software also installs a browser toolbar and multiple background processes that consume system resources. Which malware category best describes this situation?

a)

Worm

b)

Spyware

c)

Potentially Unwanted Program (PUP)

d)

Backdoor

3.

A technician observes that CPU utilization on a user’s workstation stays above 90% even when idle, and fans are running constantly. What type of malicious activity does this most likely indicate?

a)

Ransomware

b)

Logic bomb

c)

Cryptojacking

d)

Keylogger

4.

An attacker floods local hosts with unsolicited ARP replies that associate the attacker’s MAC address with the default gateway IP. Which type of attack is being performed?

a)

DNS poisoning

b)

ARP poisoning

c)

Man-in-the-browser

d)

Smurf attack

5.

A company’s web server becomes unreachable after a flood of SYN requests from thousands of unique IPs. Investigation shows the attack is being coordinated from multiple compromised hosts. What is this attack type?

a)

Amplified attack

b)

Botnet DDoS

c)

Port scan

d)

Ping of Death

6.

An attacker gains access to a database containing hashed passwords and attempts to derive the original passwords offline using software that tests every possible combination. Which attack method is being used?

a)

Pass-the-hash

b)

Dictionary attack

c)

Brute-force attack

d)

Credential replay

7.

A system administrator detects hidden processes that survive OS reinstallation and cannot be removed by antivirus. Which type of rootkit is likely present?

a)

Boot sector rootkit

b)

Firmware rootkit

c)

Kernel-mode rootkit

d)

Application rootkit

8.

A penetration tester enters ../../../../etc/config into a web application’s URL field and gains access to restricted files. Which vulnerability is being exploited?

a)

Cross-site scripting (XSS)

b)

Directory traversal

c)

Command injection

d)

SQL injection

9.

An attacker manipulates a handshake to force a server to use an older version of TLS with weak ciphers. Which type of cryptographic attack is this?

a)

Collision attack

b)

Replay attack

c)

Downgrade attack

d)

Padding oracle

10.

An attacker captures an NTLM hash from one system and reuses it to authenticate to another system without knowing the password. Which attack type is this?

a)

Pass-the-ticket

b)

Replay attack

c)

Pass-the-hash

d)

Brute-force attack

11.

A user is disciplined for installing torrent software on a company laptop, violating a policy that defines acceptable and unacceptable online behavior. Which policy was violated?

a)

Information Security Policy

b)

Acceptable Use Policy (AUP)

c)

Business Continuity Policy

d)

Change Management Policy

12.

Which of the following best describes the primary goal of an Information Security Policy?

a)

To ensure that employees use systems ethically

b)

To establish technical security controls for all devices

c)

To ensure all IT users follow guidelines protecting organizational data

d)

To assign disaster recovery responsibilities

13.

During a regional flood, an organization activates a plan that allows essential functions to continue from a secondary site. Which policy is being implemented?

a)

Incident Response Policy

b)

Disaster Recovery Policy

c)

Business Continuity and Continuity of Operations Plan (COOP)

d)

Change Management Policy

14.

Which of the following best defines a Disaster Recovery Policy?

a)

Describes how to detect and report security incidents

b)

Defines steps to resume critical operations after an outage

c)

Explains how users can access backup servers

d)

Defines acceptable internet browsing behavior

15.

An organization detects unauthorized access to its HR database. The security team follows predefined steps to contain, analyze, and eradicate the threat. Which policy guided their actions?

a)

Change Management Policy

b)

Incident Response Policy

c)

Business Continuity Policy

d)

Acceptable Use Policy

16.

What is the main purpose of an SDLC Policy?

a)

To ensure all users follow acceptable network behavior

b)

To define disaster recovery procedures

c)

To structure secure and efficient software creation

d)

To regulate payment card data storage

17.

A healthcare organization is fined for failing to protect patient records. Which law was violated?

a)

SOX

b)

GLBA

c)

HIPAA

d)

FISMA

18.

Which statement best describes the goal of regulatory compliance in cybersecurity governance?

a)

To follow internal HR procedures

b)

To meet obligations defined by external laws and regulations

c)

To define acceptable use of company resources

d)

To create encryption standards

19.

A data center plans to upgrade firewall firmware. A team submits a request for approval, tests the update, creates a rollback plan, and schedules the change during off-hours. Which governance process is being demonstrated?

a)

Business Continuity

b)

Incident Response

c)

Change Management

d)

Configuration Management

20.

A U.S.-based online retailer markets to European Union residents and must follow privacy rules requiring explicit consent to process personal data. Which regulation applies?

a)

SOX

b)

GDPR

c)

PCI DSS

d)

FISMA

21.

I lock all your files until you pay for them to be unlocked – if you don’t pay in 24 hours, I will delete them all – What am i?

a)

Spyware

b)

Ransomware

c)

Malware

d)

Virus

22.

I attach myself to documents and files, I disrupt the system. I need a host program to work from the inside - What am i?

a)

A Virus

b)

Trojan Horse

c)

Ransomware

d)

Spyware

23.

I replicate and spread across through devices connected on the network.

a)

A Virus

b)

A worm

c)

A Firewall

d)

Ransomeware

24.

I look like a normal piece of software but secretly I will infect your system – What am i?

a)

Trojan Horse

b)

Virus

c)

Phishing Email

d)

Ransomware

25.
How does a computer virus infect a pc?
a)
Email attachments
b)
Attached to files on memory sticks
c)
Suspicious web links
d)
All of the above