wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Network Intrusion Quiz

Total questions: 100

Worksheet time: 50mins

Name
Class
Date
1.

Which of the following best defines a network intrusion in cyber security?

a)

An illegal entrance into a network or domain, either passively or aggressively

b)

A routine update of network resources

c)

The installation of authorized software on a network

d)

The regular monitoring of network traffic

2.

Which of the following is an example of a passive network intrusion?

a)

Gaining access quietly and undetected

b)

Defacing a website with obscene graphics

c)

Launching a DDOS attack

d)

Implanting code to alter public-facing web sites

3.

Which of the following is NOT considered a type of network intrusion?

a)

Routine software updates

b)

Malware such as ransomware

c)

DDOS (Distributed Denial of Service) attacks

d)

Phishing campaigns

4.

What is the main difference between passive and aggressive network intrusions?

a)

Passive intrusions are undetected, while aggressive intrusions are overt and involve changes to network resources

b)

Passive intrusions involve physical access, while aggressive intrusions are only external

c)

Passive intrusions use malware, while aggressive intrusions use phishing

d)

Passive intrusions are legal, while aggressive intrusions are illegal

5.

Which of the following is a strategic way attackers might compromise a network, based on the text?

a)

Implanting carefully developed code to siphon data regularly

b)

Updating the network’s antivirus software

c)

Backing up network data to a secure location

d)

Restricting user access to sensitive folders

6.

Why might an attacker use social engineering techniques such as phishing campaigns?

a)

To deceive consumers with seemingly genuine communication

b)

To physically access restricted machines

c)

To destroy cyber-enabled equipment

d)

To perform routine network maintenance

7.

Which of the following is an example of an employee security breach that is considered an intrusion?

a)

Moving a secure file into a shared folder unintentionally

b)

Installing authorized software updates

c)

Reporting suspicious network activity

d)

Encrypting sensitive data

8.

How can attackers gain physical access to a system, according to the text?

a)

By physically accessing a restricted computer and its hard drive and/or BIOS

b)

By sending phishing emails only

c)

By updating the system’s firewall

d)

By monitoring network traffic legally

9.

Which of the following best describes asymmetric routing in the context of network attacks?

a)

Attackers use several routes to gain access to a targeted device or network.

b)

Attackers overwrite memory buffers to gain access.

c)

Attackers use CGI scripts to relay user requests.

d)

Attackers generate enormous traffic loads to cause congestion.

10.

What is the main function of an Intrusion Detection System (IDS)?

a)

To monitor and report irregularities in network architecture.

b)

To prevent all network attacks automatically.

c)

To encrypt network traffic.

d)

To manage network bandwidth.

11.

Which detection method in IDS matches data activity to a signature or pattern in a database?

a)

Signature-based detection

b)

Behavior-based detection

c)

Heuristic-based detection

d)

Protocol-based detection

12.

How does behavior-based detection differ from signature-based detection in IDS?

a)

It recognizes abnormality and issues alarms, learning what regular behavior looks like.

b)

It matches data activity to a known signature in a database.

c)

It encrypts network traffic to prevent attacks.

d)

It only monitors traffic without reporting irregularities.

13.

Why might signature-based detection fail to identify a new harmful behavior?

a)

The new behavior is not in the signatures database.

b)

The system is offline.

c)

The network is encrypted.

d)

The IDS is positioned inside the real-time communication band.

14.

Worms are considered one of the easiest and most dangerous network penetration tools because:

a)

They are commonly distributed by email attachments or instant messaging and use a considerable amount of network resources.

b)

They require physical access to the network.

c)

They only affect productivity software.

d)

They cannot be detected by any IDS.

15.

What is the role of a SPAN or TAP port in an IDS setup?

a)

To watch the network and examine a copy of inline network packets.

b)

To encrypt all network traffic.

c)

To generate traffic loads for testing.

d)

To overwrite memory buffers.

16.

Which of the following is a potential impact of malformed information packets detected by an IDS?

a)

Severe impact on overall network performance.

b)

Increased network encryption.

c)

Improved bandwidth management.

d)

Enhanced productivity software usage.

17.

Which of the following best describes the primary function of an Intrusion Detection System (IDS) in information security?

a)

To monitor network traffic and detect irregularities or attacks

b)

To create passwords for users

c)

To manage user accounts

d)

To design computer hardware

18.

What is the main benefit of IDS alarms for IT administrators?

a)

They allow rapid troubleshooting and identification of root causes of problems

b)

They automatically fix all network issues

c)

They create new user accounts

d)

They delete suspicious files without review

19.

Which of the following is NOT a type of attack that an IDS is designed to identify?

a)

Privilege escalation

b)

Unauthorized logins

c)

Malware (viruses, trojan horses, worms)

d)

Creating new passwords

20.

What are the main components of an IDS?

a)

Sensors, Console, and Central Engine

b)

Keyboard, Mouse, and Monitor

c)

Firewall, Router, and Switch

d)

Printer, Scanner, and Fax Machine

21.

How does an IDS help administrators after an attack has occurred?

a)

By analyzing access logs and evaluating methods used by hackers

b)

By automatically restoring lost data

c)

By sending emails to all users

d)

By shutting down the entire network

22.

Which statement best explains password management?

a)

It is the practice of creating, storing, managing, and organizing passwords to safeguard against unauthorized access and breach of information

b)

It is the process of deleting old passwords

c)

It is the method of sharing passwords with colleagues

d)

It is the technique of writing passwords on paper

23.

(DoK Level 2) Why is it important for an IDS to analyze network traffic and log files for specific designs?

a)

To identify patterns that may indicate security breaches or attacks

b)

To increase internet speed

c)

To reduce the number of users on the network

d)

To automatically update software

24.

(DoK Level 2) How does password management contribute to information security?

a)

By preventing unauthorized access and breaches through proper handling of passwords

b)

By allowing everyone to use the same password

c)

By making passwords easy to guess

d)

By storing passwords in public folders

25.

(DoK Level 3) Imagine you are an IT administrator. After a cyber attack, what steps would you take using an IDS to investigate and prevent future attacks?

a)

Review IDS logs, analyze attack methods, identify sources, and update security protocols

b)

Ignore the IDS alerts and continue normal operations

c)

Delete all user accounts and start over

d)

Disconnect the network permanently

26.

(DoK Level 3) Given multiple types of malicious behaviors detected by an IDS, how would you prioritize your response as a security manager?

a)

Address the most critical threats first, such as unauthorized access to sensitive information, then handle less severe issues

b)

Respond to threats in alphabetical order

c)

Ignore all alerts and wait for further instructions

d)

Only respond to malware alerts and ignore others

27.

Which of the following is a recommended practice for creating strong passwords?

a)

Use only lowercase letters

b)

Create long, complex, and unique passwords

c)

Use your birthdate as your password

d)

Repeat the same character multiple times

28.

What is the main purpose of multi-factor authentication (MFA)?

a)

To make passwords easier to remember

b)

To add another layer of security beyond just entering a password

c)

To allow access without any password

d)

To use only one form of identity verification

29.

Which of the following is NOT one of the factors used in multi-factor authentication?

a)

Something you know, like a password or pin number

b)

Something you have, like a smartphone or token

c)

Something you are, like fingerprint or face recognition

d)

Something you want, like a preferred username

30.

If you have trouble remembering complex passwords, which strategy is suggested in the material?

a)

Use your name as your password

b)

Use the first characters of a memorable phrase

c)

Write your password on a sticky note

d)

Use only numbers in your password

31.

How does a passphrase differ from a traditional password?

a)

Passphrases are always shorter than passwords

b)

Passphrases use a sentence, series, or combination of words and can contain more characters

c)

Passphrases never include numbers or special characters

d)

Passphrases are less secure than passwords

32.

Which scenario best illustrates the use of two-factor authentication?

a)

Entering only a password to access your email

b)

Scanning your fingerprint to unlock your phone

c)

Entering a password and a code sent to your authenticator app to access a system

d)

Using a password that contains both letters and numbers

33.

Using a combination of uppercase and lowercase letters, numbers, and symbols in a password increases its strength against cyber-attacks because:

a)

It makes the password easier to remember

b)

It increases the number of possible combinations, making it harder for hackers to guess or crack the password

c)

It allows the password to be used on more websites

d)

It makes the password shorter

34.

A company wants to improve its security by implementing multi-factor authentication. What steps should they take to ensure proper verification of user identity?

a)

Require users to enter only their password

b)

Require users to provide two or more forms of authentication, such as something they know, something they have, and something they are

c)

Allow users to choose any single method of authentication

d)

Use only face recognition for all users

35.

Why is it not recommended to use the same password for multiple accounts?

a)

Because it makes it easier for hackers to access all your accounts if one password is stolen.

b)

Because it is too difficult to remember.

c)

Because it is required by most companies.

d)

Because it saves time.

36.

What is the main purpose of a password manager?

a)

To store and create new and unique passwords for different accounts.

b)

To share passwords with friends.

c)

To make passwords shorter.

d)

To delete old passwords automatically.

37.

Which of the following best describes privileged user access?

a)

Granting some employees a higher level of access to data or applications.

b)

Allowing everyone to use the same password.

c)

Sharing passwords with coworkers.

d)

Using only simple passwords for all accounts.

38.

According to the text, what is a recommended characteristic of a master password for a password manager?

a)

It should be long, unique, and extremely difficult to crack.

b)

It should be the same as your email password.

c)

It should be easy to remember and short.

d)

It should be shared with your coworkers.

39.

How does using a password manager contribute to better security in an enterprise environment? (DoK Level 2)

a)

By automating password assistance and resets, and providing robust identity governance.

b)

By making all passwords the same for convenience.

c)

By allowing passwords to be written down on paper.

d)

By disabling password requirements altogether.

40.

Suppose a company does not use a privileged access management platform for sensitive accounts. What potential risk does this pose? (DoK Level 3)

a)

Sensitive information could be more easily compromised if privileged credentials are not securely stored.

b)

Employees will have to remember fewer passwords.

c)

Passwords will automatically become stronger.

d)

The company will save money on security software.

41.

Why is it important to create a strong, long passphrase for your accounts? (DoK Level 2)

a)

It makes it significantly more difficult for hackers to crack and break into systems.

b)

It makes it easier to remember.

c)

It allows you to use the same password everywhere.

d)

It is required by all password managers.

42.

According to the US National Institute of Standards and Technology (NIST), what is a recommended best practice for creating strong passwords?

a)

Use short passwords with only numbers

b)

Create long passphrases that are easy to remember and difficult to crack

c)

Use only uppercase letters in your password

d)

Avoid using any symbols in your password

43.

What is the main purpose of applying password encryption?

a)

To make passwords easier to remember

b)

To provide additional protection for passwords, even if they are stolen

c)

To allow passwords to be shared easily

d)

To remove the need for passwords entirely

44.

Why is two-factor authentication considered more secure than using just a password?

a)

It requires users to change their password every day

b)

It makes passwords visible to attackers

c)

It requires users to confirm their identity with an additional method, making it harder for attackers to gain access

d)

It allows users to use dictionary words in their passwords

45.

Which of the following is an example of an advanced authentication method?

a)

Using a simple password

b)

Biometric verification such as fingerprint or facial recognition

c)

Writing your password on paper

d)

Sharing your password with others

46.

What is a recommended way to test the strength of your password?

a)

Ask a friend to guess it

b)

Use an online password strength testing tool

c)

Use only your birthdate as a password

d)

Never change your password

47.

Why should you avoid using dictionary words in your password?

a)

They are easier to remember

b)

They are less likely to be hacked

c)

They are more likely to be hacked

d)

They make passwords longer

48.

Why is it important to use different passwords for every account?

a)

It makes remembering passwords easier

b)

If one account is breached, other accounts with the same credentials can be compromised

c)

It allows sharing passwords with colleagues

d)

It reduces the need for password managers

49.

Which of the following is a recommended way to secure your mobile phone from hackers?

a)

Use a simple password like "1234"

b)

Avoid using any password

c)

Secure your phone with a strong password, fingerprint, or facial recognition

d)

Share your password with friends

50.

According to recent NIST guidance, when should employees be asked to change their personal passwords?

a)

Every 30 days

b)

Only in case of potential threat or compromise

c)

Every time they log in

d)

Every 180 days

51.

What is a potential negative consequence of frequent mandatory password changes for personal accounts?

a)

Users become more creative with passwords

b)

Users are less likely to write passwords down

c)

Users may write passwords down to keep track of them

d)

Users never forget their passwords

52.

Why should passwords be changed when an employee leaves a business?

a)

To make the new employee feel welcome

b)

To prevent former employees from hacking into business accounts

c)

To comply with government regulations

d)

To avoid password fatigue

53.

What is a best practice for protecting accounts of privileged users?

a)

Use the same password for all privileged accounts

b)

Privileged accounts require special protections, such as privileged access management software

c)

Allow privileged users to share passwords

d)

Avoid using any software for privileged accounts

54.

Strategically, how can a business prevent the risk associated with employees reusing passwords after periodic changes?

a)

Ignore password reuse

b)

Implement strategies to prevent password reuse, as users may find creative ways around periodic changes

c)

Encourage employees to write down passwords

d)

Force password changes every week

55.

Which of the following is a recommended practice to keep your business secure according to the material?

a)

Store vital company security information on the public internet.

b)

Share passwords with colleagues via email.

c)

Keep your business offline and remove permissions when finished with applications.

d)

Use the same password for all accounts.

56.

Why should you avoid storing passwords either digitally or on paper?

a)

Because passwords are too long to remember.

b)

Because they can be stolen by those with malicious motives.

c)

Because it is illegal to store passwords.

d)

Because passwords never change.

57.

Which action can help prevent cybercriminals from stealing your credentials?

a)

Using outdated software.

b)

Ignoring vulnerability management.

c)

Using up-to-date anti-malware and vulnerability management solutions.

d)

Writing passwords on sticky notes.

58.

What is the main advantage of using a password manager?

a)

You only need to remember one master password.

b)

You can share passwords easily with friends.

c)

It makes passwords visible to everyone.

d)

It stores passwords in plain text.

59.

If someone acquires the master password to your password manager, what is the potential risk?

a)

They can only access one account.

b)

They have access to all your stored passwords.

c)

They cannot access any passwords.

d)

They can only change your master password.

60.

How do password managers help when signing up for new websites?

a)

They generate and save strong, unique passwords for you.

b)

They reuse your old passwords.

c)

They delete your account information.

d)

They send your passwords to your email.

61.

Using a password manager with a strong and unique master password can enhance your personal security because:

a)

It makes all your passwords visible to hackers.

b)

It establishes a near-perfect way to protect your personal passwords from improper access, as only you know the master password.

c)

It prevents you from creating new passwords.

d)

It allows you to share passwords with others easily.

62.

A strategy to mitigate weaknesses that might allow intruders to enter or move around your environment is to:

a)

Ignore software updates.

b)

Use up-to-date anti-malware and vulnerability management solutions to harden your systems.

c)

Store passwords on paper.

d)

Share your credentials with coworkers.

63.

Which of the following is a primary function of password managers?

a)

To provide access to all your passwords in an encrypted format

b)

To create new operating systems

c)

To monitor network traffic

d)

To block all internet access

64.

What is the main difference between Personal Password Managers and Privileged Password Managers?

a)

Personal managers are for individual users, while privileged managers are for managing sensitive enterprise credentials

b)

Personal managers are only for mobile devices, while privileged managers are for computers

c)

Privileged managers are free, while personal managers are paid

d)

Personal managers require no encryption, while privileged managers do

65.

Why is encrypted synchronization across devices an important feature of many password managers?

a)

It allows users to access their passwords securely from any device

b)

It increases the speed of the internet connection

c)

It prevents the need for antivirus software

d)

It automatically changes passwords every day

66.

Which of the following is a limitation of password management practices mentioned in the text?

a)

Forgetting the passwords

b)

Too many advertisements

c)

Lack of internet access

d)

High cost of software

67.

Suppose an organization needs to manage access to highly sensitive user accounts and systems. Which type of password manager should they use, and why?

a)

Privileged Password Manager, because it secures and manages privileged credentials for enterprise-wide access

b)

Personal Password Manager, because it is easier to use for individuals

c)

Any password manager, because all have the same features

d)

No password manager, because manual management is safer

68.

Which password in a password manager must be particularly strong and secure due to its protective function?

a)

The master password

b)

The user password

c)

The backup password

d)

The browser password

69.

Why is careless use of the master password in a password manager risky?

a)

It can lead to forgetting other passwords

b)

It allows third parties access to all stored passwords

c)

It makes the database run slower

d)

It increases the number of passwords needed

70.

What should be done if the database of a password manager gets corrupted or deleted?

a)

Ignore the issue

b)

Use a different password manager

c)

Ensure backup copies exist

d)

Change the master password

71.

Which of the following is a disadvantage of storing passwords in most web browsers?

a)

Passwords are always encrypted

b)

Passwords are not always secure

c)

Passwords cannot be accessed by third parties

d)

Passwords are stored in multiple locations

72.

If third parties gain access to the data stored in a password manager, what must be done?

a)

Change only the master password

b)

Exchange all passwords completely

c)

Delete the password manager

d)

Ignore the breach

73.

(DoK Level 2) What is the main reason for taking appropriate security measures for the master password in a password manager?

a)

To make password recovery easier

b)

To prevent unauthorized access to all stored passwords

c)

To reduce the number of passwords needed

d)

To allow sharing passwords with friends

74.

(DoK Level 2) How does the dependence on the database affect the security of a password manager?

a)

It makes passwords easier to remember

b)

It requires reliable database management and protection

c)

It allows passwords to be stored in plain text

d)

It eliminates the need for a master password

75.

(DoK Level 3) Suppose a user loses their master password for a password manager. What steps should they take to maintain security?

a)

Ignore the loss and continue using the manager

b)

Use a simple password for easy recall

c)

Take appropriate security measures, such as resetting the master password and ensuring it is stored securely

d)

Share the master password with trusted friends

76.

(DoK Level 3) Evaluate the risks associated with storing all passwords in a single password manager and suggest a strategy to mitigate these risks.

a)

There are no risks; no strategy is needed

b)

The risk is minimal; use any password manager

c)

If access is gained by third parties, all passwords are compromised; mitigate by regularly updating passwords and using strong master passwords

d)

Only browser-based managers are risky; use only offline managers

77.

Which of the following is a major challenge associated with using a master password in password managers?

a)

The master password can be compromised, giving attackers access to all accounts.

b)

The master password is always unbreakable.

c)

Password managers do not require a master password.

d)

The master password automatically changes every day.

78.

What is a credential stuffing attack as described in the context of password managers?

a)

An attack using stolen email addresses and passwords from third-party breaches to access accounts.

b)

An attack that only targets a single account with a guessed password.

c)

A method of encrypting passwords for extra security.

d)

A way to automatically reset all passwords in a manager.

79.

In 2019, what was discovered about several top password managers?

a)

Security flaws allowed passwords to be exfiltrated from a computer’s memory.

b)

They were immune to all types of hacking attempts.

c)

They could only be accessed with biometric authentication.

d)

They automatically updated passwords every month.

80.

Why does the use of a master password in password managers create a significant security risk? (DoK Level 2)

a)

Because compromising the master password gives access to all stored accounts.

b)

Because it makes passwords easier to remember.

c)

Because it allows for faster login to websites.

d)

Because it prevents password reuse.

81.

Suppose a new bug is found in a password manager that allows attackers to use it as a launchpad for further attacks. What does this imply about the security of password managers? (DoK Level 3)

a)

Password managers can introduce vulnerabilities that may be exploited to compromise not just passwords, but also other systems.

b)

Password managers are always completely secure.

c)

Bugs in password managers only affect the user’s device and not other systems.

d)

Password managers cannot be used to launch attacks on other systems.

82.

Which of the following is a common hacking attack that can compromise access to a password manager?

a)

Man-in-the-middle attack

b)

Brute force attack

c)

Social engineering

d)

Denial of service

83.

What is a major problem with password managers if an attacker gains access?

a)

The attacker can only access one password

b)

The attacker can cover the breadth of your entire online identity

c)

The attacker can only view your email

d)

The attacker cannot change any passwords

84.

Why might someone be permanently locked out of their password manager?

a)

They forget their username

b)

They lose their master password and access to recovery accounts

c)

They change their phone number

d)

They update their browser

85.

How can attackers elevate their attack during the password manager recovery process?

a)

By sending spam emails

b)

By changing the master password after accessing the recovery email

c)

By deleting the account

d)

By installing antivirus software

86.

Why do attackers focus heavily on phishing the master password of a password manager?

a)

Because it is easy to guess

b)

Because it gives access to all stored passwords

c)

Because it is not encrypted

d)

Because it is shared with others

87.

What have attackers developed for accounts with two-factor authentication in password managers?

a)

Ways to circumvent security restrictions

b)

Stronger encryption methods

c)

Password hints

d)

Automatic logout features

88.

Which of the following is a common flaw of human-created passwords mentioned in the text?

a)

They are always encrypted with AES-256

b)

They are easy to guess dictionary words

c)

They are generated by Chrome’s secure password generator

d)

They are never reused across multiple sites

89.

According to research, what percentage of users use Chrome’s secure password generator?

a)

About 10%

b)

About 20%

c)

About 50%

d)

About 80%

90.

What is the main purpose of a “zero-knowledge” system in password managers?

a)

To allow providers to decrypt passwords easily

b)

To encrypt passwords before they leave your device

c)

To store passwords in plain text format

d)

To auto-fill passwords on phishing sites

91.

Why might passwords stored in a password manager still be vulnerable to attacks?

a)

Because password managers never encrypt passwords

b)

Because users may use insecure passwords that are easy to guess or reused

c)

Because password managers always auto-fill on legitimate sites only

d)

Because password managers generate passwords for every account automatically

92.

Evaluate the effectiveness of password managers in protecting user data, considering both their benefits and potential vulnerabilities described in the text.

a)

Password managers are ineffective because they do not encrypt passwords

b)

Password managers offer encryption and convenience, but can be compromised if users use insecure passwords or if the manager itself is breached

c)

Password managers are only useful for generating passwords, not for storing them

d)

Password managers are completely secure and have no vulnerabilities

93.

A few years ago, an attack on which password manager allowed hackers to access and decrypt customer data?

a)

Chrome Password Manager

b)

LastPass

c)

OneLogin

d)

Dashlane

94.

Which of the following best defines malware?

a)

Malware is any piece of software intended to cause harm to your system or network.

b)

Malware is a type of hardware used to protect networks.

c)

Malware is a software that improves computer performance.

d)

Malware is a program designed for entertainment purposes.

95.

What distinguishes malware from normal programs?

a)

Malware can spread itself in the network and remain undetectable.

b)

Malware always improves network security.

c)

Malware is only used for data storage.

d)

Malware is always visible to users.

96.

Who created and released the Melissa virus, and in which year?

a)

David L. Smith, 1999

b)

Bill Gates, 2001

c)

Steve Jobs, 1995

d)

Mark Zuckerberg, 2004

97.

What was the primary method by which the Melissa virus spread?

a)

By embedding a macro virus inside a Word file

b)

By infecting USB drives

c)

By exploiting web browsers

d)

By sending spam emails with attachments

98.

Why was the My Doom malware considered one of the fastest spreading email worms?

a)

It was spread by spammers and contained a text.

b)

It was distributed through social media platforms.

c)

It was installed via physical media.

d)

It required human intervention to spread.

99.

Which companies were notably affected by the My Doom malware?

a)

Google and Microsoft

b)

Apple and Facebook

c)

IBM and Oracle

d)

Amazon and Twitter

100.

What was the main impact of the Stuxnet malware attack in 2010?

a)

Hardware level destruction of a nuclear plant in Iran

b)

Theft of personal passwords

c)

Disruption of banking systems

d)

Spread of ransomware in hospitals