NEW
Font size
WorksheetsEthical Hacking Quiz (Week 1)
Total questions: 30
Worksheet time: 10mins
What is the primary difference between ethical hacking and malicious hacking?
Ethical hackers use different tools than malicious hackers
Ethical hackers have authorization and work for defensive purposes
Ethical hackers only test web applications
Malicious hackers are more skilled than ethical hackers
According to the 2024-2025 industry statistics, what is the average time to identify a data breach?
90 days
150 days
277 days
365 days
Which of the following is NOT listed as a current threat in the 2025 cybersecurity landscape?
AI-powered phishing
Ransomware attacks
Quantum computing attacks
IoT vulnerabilities
What is the expected global cost of cybercrime by 2025?
$4.45 million
$1.5 trillion
$10.5 trillion
$100 billion
Which Malaysian law addresses unauthorized access to computer systems?
Digital Security Act 2015
Computer Crimes Act 1997
Cyber Protection Act 2010
Information Technology Act 1998
Under Section 3 of the Computer Crimes Act 1997, what is the maximum penalty for unauthorized access?
Up to 3 years imprisonment or RM 25,000 fine
Up to 5 years imprisonment or RM 50,000 fine
Up to 7 years imprisonment or RM 100,000 fine
Up to 10 years imprisonment or RM 150,000 fine
What is the average cost of a data breach according to the course material?
$2.5 million USD
$3.8 million USD
$4.45 million USD
$5.2 million USD
How many unfilled cybersecurity positions are there worldwide according to the lecture?
1.5 million
2.8 million
3.5 million
5 million
Which phase comes immediately after "Intelligence Gathering" in the PTES methodology?
Exploitation
Vulnerability Analysis
Threat Modeling
Post-Exploitation
Which penetration testing methodology is specifically focused on web application security?
PTES
OWASP Testing Guide
NIST SP 800-115
OSSTMM
What does OSSTMM stand for?
Open Source Security Testing Methodology Manual
Organized Security Standards Testing and Methodology Manual
Open Standards Security Testing Method Manual
Operational Security System Testing Methodology Manual
Which methodology is described as government and compliance-focused?
PTES
OWASP
NIST SP 800-115
OSSTMM
In the PTES methodology, what is the first phase?
Intelligence Gathering
Pre-engagement
Reconnaissance
Threat Modeling
Which of the following is NOT a phase in the PTES methodology?
Vulnerability Analysis
Social Engineering
Post-Exploitation
Reporting
In a Black Box penetration test, what level of knowledge does the tester have?
Complete knowledge
Partial knowledge
Zero knowledge
Network-level knowledge only
Which type of penetration test simulates an insider threat?
Black Box
White Box
Grey Box
Red Box
Which type of penetration test is described as providing "a balance between realism and thoroughness"?
Black Box
White Box
Grey Box
Purple Box
Which team role focuses on offensive security and simulating real attackers?
Blue Team
Red Team
Purple Team
Green Team
What is the primary role of the Purple Team?
Offensive security only
Defensive security only
Collaboration and knowledge sharing between Red and Blue teams
Physical security testing
Which type of penetration testing assesses WiFi security and tests WPA2/WPA3 encryption?
Network Penetration Testing
Web Application Penetration Testing
Wireless Network Penetration Testing
Physical Penetration Testing
What is the most critical requirement before conducting any penetration test?
Having the latest security tools
Getting written authorization
Completing security certifications
Understanding all vulnerabilities
Which of the following is NOT part of the Rules of Engagement (ROE)?
Testing timeframe and windows
Target systems and IP ranges
Expected number of vulnerabilities to find
Emergency contact procedures
What is the maximum penalty under the Personal Data Protection Act (PDPA) 2010?
RM 100,000 or 2 years imprisonment
RM 300,000 or 3 years imprisonment
RM 500,000 or 3 years imprisonment
RM 1,000,000 or 5 years imprisonment
According to the Ethical Hacker's Code of Conduct, which principle involves avoiding disrupting systems?
Obtain proper authorization
Maintain confidentiality
Do no harm
Report all findings
What is the approximate salary range for a Penetration Tester in Malaysia according to the course material?
RM 40k - 80k/year
RM 60k - 120k/year
RM 80k - 150k/year
RM 100k - 180k/year
Which certification is NOT mentioned in the course material?
CEH
OSCP
CISSP
GPEN
In the MOVEit Transfer Zero-Day Exploit (2023), what was the attack vector?
Ransomware
SQL injection vulnerability
Phishing email
Buffer overflow
What was the estimated financial impact of the MGM Resorts Ransomware Attack in 2023?
$50 million
$75 million
$100 million
$150 million
In the SolarWinds Supply Chain Attack, what was the name of the backdoor malware inserted into the Orion software?
SUNSPOT
SUNBURST
SOLARFLARE
DARKSIDE
According to current attack trends (2024-2025), how frequently does a ransomware attack occur?
Every 5 seconds
Every 11 seconds
Every 30 seconds
Every minute
