wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Ethical Hacking Quiz (Week 1)

Total questions: 30

Worksheet time: 10mins

Name
Class
Date
1.

What is the primary difference between ethical hacking and malicious hacking?

a)

Ethical hackers use different tools than malicious hackers

b)

Ethical hackers have authorization and work for defensive purposes

c)

Ethical hackers only test web applications

d)

Malicious hackers are more skilled than ethical hackers

2.

According to the 2024-2025 industry statistics, what is the average time to identify a data breach?

a)

90 days

b)

150 days

c)

277 days

d)

365 days

3.

Which of the following is NOT listed as a current threat in the 2025 cybersecurity landscape?

a)

AI-powered phishing

b)

Ransomware attacks

c)

Quantum computing attacks

d)

IoT vulnerabilities

4.

What is the expected global cost of cybercrime by 2025?

a)

$4.45 million

b)

$1.5 trillion

c)

$10.5 trillion

d)

$100 billion

5.

Which Malaysian law addresses unauthorized access to computer systems?

a)

Digital Security Act 2015

b)

Computer Crimes Act 1997

c)

Cyber Protection Act 2010

d)

Information Technology Act 1998

6.

Under Section 3 of the Computer Crimes Act 1997, what is the maximum penalty for unauthorized access?

a)

Up to 3 years imprisonment or RM 25,000 fine

b)

Up to 5 years imprisonment or RM 50,000 fine

c)

Up to 7 years imprisonment or RM 100,000 fine

d)

Up to 10 years imprisonment or RM 150,000 fine

7.

What is the average cost of a data breach according to the course material?

a)

$2.5 million USD

b)

$3.8 million USD

c)

$4.45 million USD

d)

$5.2 million USD

8.

How many unfilled cybersecurity positions are there worldwide according to the lecture?

a)

1.5 million

b)

2.8 million

c)

3.5 million

d)

5 million

9.

Which phase comes immediately after "Intelligence Gathering" in the PTES methodology?

a)

Exploitation

b)

Vulnerability Analysis

c)

Threat Modeling

d)

Post-Exploitation

10.

Which penetration testing methodology is specifically focused on web application security?

a)

PTES

b)

OWASP Testing Guide

c)

NIST SP 800-115

d)

OSSTMM

11.

What does OSSTMM stand for?

a)

Open Source Security Testing Methodology Manual

b)

Organized Security Standards Testing and Methodology Manual

c)

Open Standards Security Testing Method Manual

d)

Operational Security System Testing Methodology Manual

12.

Which methodology is described as government and compliance-focused?

a)

PTES

b)

OWASP

c)

NIST SP 800-115

d)

OSSTMM

13.

In the PTES methodology, what is the first phase?

a)

Intelligence Gathering

b)

Pre-engagement

c)

Reconnaissance

d)

Threat Modeling

14.

Which of the following is NOT a phase in the PTES methodology?

a)

Vulnerability Analysis

b)

Social Engineering

c)

Post-Exploitation

d)

Reporting

15.

In a Black Box penetration test, what level of knowledge does the tester have?

a)

Complete knowledge

b)

Partial knowledge

c)

Zero knowledge

d)

Network-level knowledge only

16.

Which type of penetration test simulates an insider threat?

a)

Black Box

b)

White Box

c)

Grey Box

d)

Red Box

17.

Which type of penetration test is described as providing "a balance between realism and thoroughness"?

a)

Black Box

b)

White Box

c)

Grey Box

d)

Purple Box

18.

Which team role focuses on offensive security and simulating real attackers?

a)

Blue Team

b)

Red Team

c)

Purple Team

d)

Green Team

19.

What is the primary role of the Purple Team?

a)

Offensive security only

b)

Defensive security only

c)

Collaboration and knowledge sharing between Red and Blue teams

d)

Physical security testing

20.

Which type of penetration testing assesses WiFi security and tests WPA2/WPA3 encryption?

a)

Network Penetration Testing

b)

Web Application Penetration Testing

c)

Wireless Network Penetration Testing

d)

Physical Penetration Testing

21.

What is the most critical requirement before conducting any penetration test?

a)

Having the latest security tools

b)

Getting written authorization

c)

Completing security certifications

d)

Understanding all vulnerabilities

22.

Which of the following is NOT part of the Rules of Engagement (ROE)?

a)

Testing timeframe and windows

b)

Target systems and IP ranges

c)

Expected number of vulnerabilities to find

d)

Emergency contact procedures

23.

What is the maximum penalty under the Personal Data Protection Act (PDPA) 2010?

a)

RM 100,000 or 2 years imprisonment

b)

RM 300,000 or 3 years imprisonment

c)

RM 500,000 or 3 years imprisonment

d)

RM 1,000,000 or 5 years imprisonment

24.

According to the Ethical Hacker's Code of Conduct, which principle involves avoiding disrupting systems?

a)

Obtain proper authorization

b)

Maintain confidentiality

c)

Do no harm

d)

Report all findings

25.

What is the approximate salary range for a Penetration Tester in Malaysia according to the course material?

a)

RM 40k - 80k/year

b)

RM 60k - 120k/year

c)

RM 80k - 150k/year

d)

RM 100k - 180k/year

26.

Which certification is NOT mentioned in the course material?

a)

CEH

b)

OSCP

c)

CISSP

d)

GPEN

27.

In the MOVEit Transfer Zero-Day Exploit (2023), what was the attack vector?

a)

Ransomware

b)

SQL injection vulnerability

c)

Phishing email

d)

Buffer overflow

28.

What was the estimated financial impact of the MGM Resorts Ransomware Attack in 2023?

a)

$50 million

b)

$75 million

c)

$100 million

d)

$150 million

29.

In the SolarWinds Supply Chain Attack, what was the name of the backdoor malware inserted into the Orion software?

a)

SUNSPOT

b)

SUNBURST

c)

SOLARFLARE

d)

DARKSIDE

30.

According to current attack trends (2024-2025), how frequently does a ransomware attack occur?

a)

Every 5 seconds

b)

Every 11 seconds

c)

Every 30 seconds

d)

Every minute