wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

External Threats

Total questions: 81

Worksheet time: 41mins

Name
Class
Date
1.

According to the passage, who are considered a genuine threat to personal and organisation data in the digital world?

a)

Hackers

b)

Teachers

c)

Students

d)

Friends

2.

Fill in the blank: In the digital world, hackers are a genuine threat to ______ and organisation data.

a)

personal

b)

public

c)

shared

d)

temporary

3.

CryptoLocker is:

a)

a type of ransomware malware

b)

an antivirus software

c)

a secure messaging app

d)

a cryptocurrency wallet

4.

Operation Tovar was:

a)

an international law enforcement operation to take down the Gameover Zeus botnet

b)

a military operation in the Middle East

c)

a humanitarian mission in Africa

d)

a space exploration project by NASA

5.

Evgeniy Bogachev was:

a)

a Russian cybercriminal

b)

a famous chess grandmaster

c)

an Olympic gold medalist

d)

a renowned physicist

6.

The reward for capturing Bogachev was:

a)

$3 million

b)

$1 million

c)

$500,000

d)

$10 million

7.

CryptoLocker made how much money?

a)

About $3 million

b)

About $100,000

c)

About $10 million

d)

About $500,000

8.

What type of malware is CryptoLocker?

a)

Virus

b)

Ransomware

c)

Worm

d)

Trojan

9.

What was the name of the operation to capture Evgeniy and the gang of hackers?

a)

Operation Zeus

b)

Operation Tovar

c)

Operation Lockdown

d)

Operation Crypto

10.

How much money did the FBI offer for Evgeniy’s capture?

a)

$1,000,000

b)

$2,000,000

c)

$3,000,000

d)

$5,000,000

11.

CryptoLocker made $__________ in 100 days.

a)

$300,000,000

b)

$3,000,000

c)

$30,000,000

d)

$1,000,000

12.

Describe what a Virus is in the context of network threats and explain how to protect against it.

a)

A virus is a type of malicious software that attaches itself to a legitimate program or file and can replicate itself to spread to other computers. Protection includes using antivirus software, not opening suspicious emails, and keeping software updated.

b)

A virus is a hardware device that prevents unauthorized access to a network. Protection includes installing more hardware devices.

c)

A virus is a type of network cable used to connect computers. Protection includes using shielded cables.

d)

A virus is a legitimate software update that improves computer performance. Protection includes installing all available updates.

13.

Describe what a Worm is in the context of network threats and explain how to protect against it.

a)

A worm is a standalone malware program that replicates itself to spread to other computers, often exploiting vulnerabilities. Protection includes using firewalls, keeping systems updated, and using antivirus software.

b)

A worm is a type of firewall that blocks unauthorized access to a network. Protection includes disabling firewalls and avoiding software updates.

c)

A worm is a security protocol used to encrypt data during transmission. Protection includes using weak passwords and sharing credentials.

d)

A worm is a hardware device that prevents malware infections. Protection includes not using antivirus software and ignoring system updates.

14.

Describe what a Trojan is in the context of network threats and explain how to protect against it.

a)

A Trojan is a type of malware disguised as legitimate software that, once activated, can give attackers access to the infected system. Protection includes not downloading software from untrusted sources and using antivirus software.

b)

A Trojan is a type of firewall that blocks all incoming network traffic. Protection includes disabling your antivirus software.

c)

A Trojan is a legitimate software update that improves system security. Protection includes always installing updates from any source.

d)

A Trojan is a type of hardware device used to secure networks. Protection includes using only wireless connections.

15.

Describe what Ransomware is in the context of network threats and explain how to protect against it.

a)

Ransomware is a type of malware that encrypts a user's files and demands payment for the decryption key. Protection includes regular backups, not clicking on suspicious links, and using security software.

b)

Ransomware is a type of firewall that blocks unauthorized access to a network. Protection includes disabling firewalls and sharing passwords.

c)

Ransomware is a network protocol used to securely transfer files. Protection includes using outdated software and ignoring security updates.

d)

Ransomware is a type of antivirus software that removes all malware automatically. Protection includes never updating the antivirus and clicking on all email attachments.

16.

Describe what Spyware is in the context of network threats and explain how to protect against it.

a)

Spyware is software that secretly monitors and collects user information without their knowledge. Protection includes using antispyware tools and being cautious about what is downloaded and installed.

b)

Spyware is a type of hardware device used to speed up network connections. Protection includes upgrading your network cables.

c)

Spyware is a legitimate software that helps users manage their passwords securely. Protection includes sharing passwords with trusted friends.

d)

Spyware is a virus that only affects mobile devices. Protection includes turning off your phone regularly.

17.

Describe what a Rootkit is in the context of network threats and explain how to protect against it.

a)

A rootkit is a collection of software tools that enable unauthorized access to a computer while hiding its presence. Protection includes using rootkit detection tools and keeping systems updated.

b)

A rootkit is a type of firewall that blocks all incoming network traffic. Protection includes disabling the firewall.

c)

A rootkit is a legitimate software update that improves system performance. Protection includes avoiding software updates.

d)

A rootkit is a type of antivirus program that scans for malware. Protection includes running regular antivirus scans.

18.

Describe what a Botnet is in the context of network threats and explain how to protect against it.

a)

A botnet is a network of infected computers controlled by an attacker, often used to launch attacks. Protection includes using firewalls, antivirus software, and keeping systems updated.

b)

A botnet is a type of firewall that protects computers from malware. Protection includes disabling firewalls and avoiding software updates.

c)

A botnet is a legitimate network used by companies to improve internet speed. Protection includes sharing your network with others.

d)

A botnet is a software tool used to scan for viruses on a computer. Protection includes never using antivirus software.

19.

Describe what a Denial of Service attack is in the context of network threats and explain how to protect against it.

a)

A Denial of Service (DoS) attack is an attempt to make a network or service unavailable by overwhelming it with traffic. Protection includes using firewalls, intrusion detection systems, and load balancers.

b)

A Denial of Service (DoS) attack is a method of encrypting data to prevent unauthorized access. Protection includes using strong passwords and regular software updates.

c)

A Denial of Service (DoS) attack is a way to gain administrative access to a network by exploiting software vulnerabilities. Protection includes disabling unused ports and services.

d)

A Denial of Service (DoS) attack is a technique for intercepting network traffic to steal sensitive information. Protection includes using VPNs and secure communication protocols.

20.

Describe what Social Engineering is in the context of network threats and explain how to protect against it.

a)

Social engineering is the use of deception to manipulate individuals into divulging confidential information. Protection includes user education and awareness, and verifying identities before sharing information.

b)

Social engineering is a type of malware that infects computer systems. Protection includes installing antivirus software and updating operating systems regularly.

c)

Social engineering is a method of encrypting data to prevent unauthorized access. Protection includes using strong encryption algorithms and secure passwords.

d)

Social engineering is a network protocol used to transfer files securely. Protection includes configuring firewalls and monitoring network traffic.

21.

Describe what Pharming is in the context of network threats and explain how to protect against it.

a)

Pharming is a cyberattack intended to redirect a website's traffic to a fraudulent site. Protection includes using secure DNS servers and keeping software updated.

b)

Pharming is a method of encrypting data to prevent unauthorized access. Protection includes using strong passwords and two-factor authentication.

c)

Pharming is a type of malware that locks files and demands ransom. Protection includes regular backups and antivirus software.

d)

Pharming is a technique for intercepting wireless signals. Protection includes using VPNs and strong Wi-Fi passwords.

22.

Describe what Shoulder Surfing is in the context of network threats and explain how to protect against it.

a)

Shoulder surfing is the act of obtaining confidential information by observing someone’s screen or keyboard. Protection includes shielding screens and being aware of surroundings when entering sensitive information.

b)

Shoulder surfing is a type of malware that infects computers through email attachments. Protection includes installing antivirus software and not opening suspicious emails.

c)

Shoulder surfing is a method of intercepting wireless network traffic using specialized equipment. Protection includes using strong encryption on wireless networks.

d)

Shoulder surfing is a technique for bypassing firewalls by tunneling traffic through allowed ports. Protection includes updating firewall rules regularly.

23.

Describe what Man in the Middle Attacks are in the context of network threats and explain how to protect against them.

a)

A Man in the Middle Attack is when an attacker secretly intercepts and possibly alters communication between two parties. Protection includes using encryption and secure communication protocols.

b)

A Man in the Middle Attack is when two users communicate directly without any risk. Protection includes disabling all security protocols.

c)

A Man in the Middle Attack is when a server fails to respond to a client request. Protection includes increasing server bandwidth.

d)

A Man in the Middle Attack is when a user forgets their password. Protection includes resetting the password regularly.

24.

What tool will you use to create a website for new computer users that provides information about different forms of attack and ways to protect themselves?

a)

Google Docs

b)

Google Sites

c)

Microsoft Word

d)

PowerPoint

25.

According to the instructions, what should you use Google for during this project?

a)

Research

b)

Entertainment

c)

Shopping

d)

Social Media

26.

What is the purpose of the website you are creating according to the instructions?

a)

To play games

b)

To provide information about different forms of attack and protection methods for new computer users

c)

To sell products

d)

To share photos

27.

Identify how you can tell this email is phishing.

a)

It contains suspicious links or requests for personal information.

b)

It is sent from a known and trusted sender.

c)

It uses professional language and correct grammar throughout.

d)

It does not ask for any sensitive information.

28.

Read the sample email from 'PayPal Customer Care'. Which feature indicates that this email may not be genuine?

a)

Professional language

b)

Poor spelling

c)

Personalized greeting

d)

Clear instructions

29.

Read the sample email from 'PayPal Customer Care'. What type of salutation is used in the email?

a)

Personalized salutation

b)

Generic salutation

c)

No salutation

d)

Formal salutation

30.

Read the sample email from 'PayPal Customer Care'. Identify the grammatical issue present in the email.

a)

Poor grammar

b)

Incorrect punctuation

c)

Spelling mistake

d)

Incorrect subject-verb agreement

31.

Read the sample email from 'PayPal Customer Care'. What action does the email ask the recipient to complete?

a)

Ignore the email

b)

Complete the attached form

c)

Call customer service

d)

Change password

32.

The security of an organisation can be compromised and improved by:

a)

Implementing strong security policies and addressing vulnerabilities

b)

Ignoring security protocols and updates

c)

Allowing unrestricted access to sensitive data

d)

Neglecting employee training on security measures

33.

External threats to a network and reasons why hackers attack digital systems include:

a)

Gaining unauthorized access, stealing data, and causing disruption

b)

Improving network security and helping users

c)

Reducing network traffic and increasing speed

d)

Providing free software updates to users

34.

The security of an organisation can be compromised and improved in which of the following ways?

a)

By implementing strong security policies and addressing vulnerabilities

b)

By ignoring security updates and using weak passwords

c)

By sharing confidential information publicly

d)

By disabling firewalls and antivirus software

35.

Lesson 1 - 3: External threats to a network and reasons why hackers attack digital systems include:

a)

Malware, phishing, and financial gain

b)

Routine software updates and system maintenance

c)

User collaboration and teamwork

d)

Legal compliance and ethical behavior

36.

Staff within an organisation can pose a threat to digital systems by:

a)

Accidentally leaking sensitive information

b)

Always following security protocols

c)

Never using digital systems

d)

Eliminating all cyber threats

37.

Lesson 5: The consequences of a data breach for an organisation and its stakeholders include:

a)

Financial loss, reputational damage, and legal penalties

b)

Increased profits and market share

c)

Improved customer trust and loyalty

d)

Enhanced data security and privacy

38.

Lesson 6: Access restrictions can help protect digital systems by:

a)

Limiting who can view or change information

b)

Allowing everyone to access all data

c)

Making systems slower and less efficient

d)

Removing all security measures

39.

Lesson 7: Protecting data while it's stored and in transit involves:

a)

Using encryption methods

b)

Ignoring security protocols

c)

Sharing passwords openly

d)

Disabling firewalls

40.

Organisations detect weaknesses in their digital systems by:

a)

conducting security audits and vulnerability assessments.

b)

increasing the number of employees.

c)

upgrading office furniture.

d)

holding more team meetings.

41.

Clear responsibilities and defined rules are essential in a security policy because:

a)

They ensure accountability and consistent enforcement of security measures.

b)

They make the policy more difficult to understand.

c)

They allow for more flexibility in breaking rules.

d)

They reduce the need for employee training.

42.

Lesson 10 (Assessment): After a cyber attack, an organisation should:

a)

Assess the damage, report the incident, and strengthen security measures.

b)

Ignore the incident and continue normal operations.

c)

Delete all data to prevent further attacks.

d)

Blame employees and take no further action.

43.

Lesson 11 (Assessment): Cyber security considerations for an organisation include:

a)

Protecting data, managing access, and ensuring compliance

b)

Increasing physical office space

c)

Hiring only remote employees

d)

Focusing solely on marketing strategies

44.

Which of the following lists two forms of attack that new computer users should be aware of and describes one way to protect against each?

a)

Phishing and malware; use strong passwords and install antivirus software.

b)

Phishing and hardware failure; use backup drives and update hardware.

c)

Malware and slow internet; restart the router and clear cache.

d)

Spam emails and low disk space; delete old files and empty recycle bin.

45.

An important success criteria for your website project is:

a)

Meeting the project objectives

b)

Ignoring user feedback

c)

Delaying the launch date

d)

Overcomplicating the design

46.

It is important to use tailored search terms like 'bitesize' when researching online safety topics because:

a)

they help you find more relevant and specific information.

b)

they make your search results less accurate.

c)

they increase the number of unrelated websites.

d)

they slow down your research process.

47.

Define what a Botnet is.

a)

A Botnet is a network of infected computers controlled by a hacker to perform tasks such as sending spam or launching attacks.

b)

A Botnet is a type of antivirus software used to protect computers from malware.

c)

A Botnet is a secure network used by banks for online transactions.

d)

A Botnet is a programming language used to develop web applications.

48.

Describe a method to protect against Botnets.

a)

Use antivirus software and keep systems updated to prevent botnet infections.

b)

Disable all internet connections permanently.

c)

Share your passwords with friends to avoid botnets.

d)

Ignore software updates and security patches.

49.

Define what a Denial of Service attack is.

a)

A Denial of Service attack is an attempt to make a computer or network resource unavailable to its intended users by overwhelming it with traffic.

b)

A Denial of Service attack is a method to encrypt data for secure communication.

c)

A Denial of Service attack is a process of backing up data to prevent loss.

d)

A Denial of Service attack is a technique to improve network speed by reducing traffic.

50.

Describe a method to protect against Denial of Service attacks.

a)

Use firewalls and intrusion prevention systems to block excessive traffic and prevent Denial of Service attacks.

b)

Increase the number of open ports on the server to allow more connections.

c)

Disable all security software to improve network speed.

d)

Share your network credentials publicly to increase transparency.

51.

Define what Social Engineering is.

a)

Social Engineering is the use of deception to manipulate individuals into divulging confidential or personal information.

b)

Social Engineering is the process of designing social media platforms for better user engagement.

c)

Social Engineering is the study of human behavior in social groups.

d)

Social Engineering is the practice of creating secure computer networks.

52.

Describe a method to protect against Social Engineering.

a)

Educate users about common social engineering tactics and encourage them to verify requests for sensitive information.

b)

Ignore all emails from unknown senders without exception.

c)

Share passwords only with trusted colleagues.

d)

Disable antivirus software to avoid false alarms.

53.

Define what Pharming is.

a)

Pharming is a cyber attack intended to redirect a website's traffic to a fake website without the user's knowledge.

b)

Pharming is a method of encrypting data for secure communication.

c)

Pharming is a process of removing viruses from a computer system.

d)

Pharming is a technique used to speed up internet connections.

54.

Describe a method to protect against Pharming.

a)

Use secure DNS servers and keep software updated to prevent pharming attacks.

b)

Disable your firewall to allow all traffic.

c)

Share your passwords with friends for convenience.

d)

Ignore software updates and security patches.

55.

Define what Shoulder Surfing is.

a)

Shoulder Surfing is the act of obtaining personal information by observing someone’s screen or keyboard.

b)

Shoulder Surfing is a method of securing data by encrypting it.

c)

Shoulder Surfing is a technique used to improve posture while working.

d)

Shoulder Surfing is a way to increase internet speed by using multiple connections.

56.

Describe a method to protect against Shoulder Surfing.

a)

Be aware of your surroundings and use privacy screens to prevent shoulder surfing.

b)

Share your passwords with friends to avoid forgetting them.

c)

Write your passwords on sticky notes and keep them on your monitor.

d)

Disable your computer's firewall for easier access.

57.

Define what a Man in the Middle Attack is.

a)

A Man in the Middle Attack is when a hacker secretly intercepts and relays messages between two parties who believe they are communicating directly with each other.

b)

A Man in the Middle Attack is when a hacker physically steals a device to access information.

c)

A Man in the Middle Attack is when a hacker sends spam emails to multiple users.

d)

A Man in the Middle Attack is when a hacker uses brute force to guess passwords.

58.

Describe a method to protect against Man in the Middle Attacks.

a)

Use encryption such as SSL/TLS to secure communications and prevent man in the middle attacks.

b)

Disable all firewalls to allow open communication.

c)

Share your passwords openly to ensure transparency.

d)

Use public Wi-Fi networks without any security measures.

59.

A small company’s staff try to log in to their payroll system at “payroll.outwood.com” but keep getting redirected to a fake site that captures their usernames and passwords. What is the name of this type of attack?

a)

Phishing

b)

Brute force attack

c)

Denial of Service (DoS)

d)

Man-in-the-middle attack

60.

How can an attacker redirect users to a fake site that captures their usernames and passwords when they try to log in to a payroll system?

a)

By modifying DNS records to point the legitimate domain to a malicious server

b)

By sending users a legitimate login link via email

c)

By installing antivirus software on the users' computers

d)

By updating the payroll system with security patches

61.

Select two different technical measures the company could put in place to prevent this attack.

a)

Implement firewalls and intrusion detection systems

b)

Increase employee salaries and offer more benefits

c)

Host company events and team-building activities

d)

Reduce the number of company meetings

62.

Simply checking for “HTTPS” in the browser’s address bar might not be enough to detect this attack because:

a)

Attackers can use HTTPS with fraudulent certificates.

b)

HTTPS always guarantees the website is safe.

c)

Browsers block all phishing sites automatically with HTTPS.

d)

HTTPS prevents all types of cyber attacks.

63.

The security of an organisation can be compromised and improved in which of the following ways?

a)

By implementing strong access controls and regular security audits

b)

By ignoring security policies and procedures

c)

By sharing passwords among employees

d)

By using outdated software and systems

64.

External threats to a network and reasons why hackers attack digital systems include:

a)

Gaining unauthorized access, stealing data, and causing disruption

b)

Improving network performance and security

c)

Providing free technical support to users

d)

Enhancing user privacy and protection

65.

The security of an organisation can be compromised and improved in which of the following ways?

a)

By implementing strong security policies and addressing vulnerabilities

b)

By ignoring security updates and using weak passwords

c)

By sharing confidential information publicly

d)

By disabling firewalls and antivirus software

66.

Lesson 1 - 3: External threats to a network and reasons why hackers attack digital systems include which of the following?

a)

Malware, phishing, and financial gain

b)

Regular software updates and backups

c)

Physical security measures only

d)

Internal employee collaboration

67.

Lesson 4: Staff within an organisation can pose a threat to digital systems by:

a)

Accidentally leaking sensitive information

b)

Improving system security

c)

Increasing system efficiency

d)

Reducing cyber risks

68.

Lesson 5: The consequences of a data breach for an organisation and its stakeholders include:

a)

Financial loss, reputational damage, legal penalties, and loss of trust

b)

Increased profits and improved public image

c)

Guaranteed immunity from legal action

d)

Automatic increase in customer base

69.

Access restrictions can help protect digital systems by:

a)

Limiting who can view or change information

b)

Allowing everyone to access all data

c)

Making systems slower

d)

Removing all passwords

70.

Lesson 7: Protecting data while it's stored and in transit can be achieved by:

a)

Using encryption methods

b)

Ignoring security protocols

c)

Sharing passwords openly

d)

Disabling firewalls

71.

Organisations detect weaknesses in their digital systems by:

a)

Conducting security audits and vulnerability assessments

b)

Ignoring potential threats

c)

Relying solely on employee intuition

d)

Disabling security features

72.

Lesson 9: Clear responsibilities and defined rules are essential in a security policy because:

a)

They ensure accountability and consistent enforcement of security measures.

b)

They make the policy more difficult to understand.

c)

They allow for more flexibility and less structure.

d)

They reduce the need for employee training.

73.

Lesson 10 (Assessment): After a cyber attack, an organisation should:

a)

Assess the damage, report the incident, and strengthen security measures.

b)

Ignore the incident and continue normal operations.

c)

Delete all data to prevent further attacks.

d)

Blame employees without investigating the cause.

74.

Cyber security considerations for an organisation include:

a)

Protecting sensitive data and systems from unauthorized access

b)

Ignoring software updates and patches

c)

Sharing passwords among employees

d)

Allowing unrestricted access to all users

75.

The UK experiences over 375 cyber attacks every hour. 1 in 5 UK citizens have had an online account hacked. What is a likely reason people hack computers?

a)

To steal personal information or data

b)

To improve internet speed

c)

To create new software

d)

To fix security issues for free

76.

Who is a hacker?

a)

A person who gets access to a computer system without permission

b)

A person who builds computer systems

c)

A person who repairs computers

d)

A person who writes computer programs

77.

Which of the following is something a hacker can do with access to a computer system?

a)

Make the computer run different programs such as a virus or a botnet

b)

Paint the computer

c)

Upgrade the computer hardware

d)

Clean the computer screen

78.

Which of the following is something a hacker can do with access to a computer system?

a)

Steal information

b)

Install games

c)

Change the wallpaper

d)

Increase internet speed

79.

Which of the following is something a hacker can do with access to a computer system?

a)

Damage files by corrupting or deleting them

b)

Print documents

c)

Organize folders

d)

Update software

80.

A hacker who misuses computers is known as a ________ hacker.

a)

black hat

b)

white hat

c)

grey hat

d)

blue hat

81.

A hacker that helps people is known as a ________ hacker.

a)

white hat

b)

black hat

c)

grey hat

d)

blue hat