wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Threat Types and Motivations Worksheet

Total questions: 35

Worksheet time: 18mins

Name
Class
Date
1.

A company discovers a new type of malware targeting its R&D servers. The malware uses zero-day exploits, custom command-and-control channels, and deletes logs after execution. Intelligence analysts believe the group is backed by a foreign government. Which type of threat actor is MOST likely responsible?

a)

Script kiddie

b)

Nation-state actor

c)

Insider with malicious intent

d)

Hacktivist group

2.

A contractor accidentally sends a confidential customer report to the wrong vendor because they misunderstood the new email policy. Which type of insider threat does this scenario represent?

a)

Malicious insider

b)

Unintentional insider

c)

Competitor threat

d)

Hacktivist insider

3.

Organized crime is motivated by which of the following?

a)

Political influence

b)

Chaotic disruption

c)

Criminal profit

d)

Whistleblowing

4.

An attacker calls a help desk pretending to be a new employee who “lost VPN access.” They provide a fake employee ID and use urgency to pressure the technician into resetting the account.

a)

A. Pretexting

b)

B. Watering hole attack

c)

C. Lure-based vector

d)

D. Whaling

5.

A security team wants to evaluate all ways an attacker could exploit vulnerabilities in their environment, including door access, cloud services, and employees. Which concept are they analyzing?

a)

Threat vector

b)

Attack surface

c)

Attack chain

d)

Insider footprint

6.

A user finds a USB drive in the parking lot labeled “Executive Salaries.” When plugged in, a malicious script auto-executes. Which type of vector is being used?

a)

Message-based

b)

Network-based

c)

Lure-based

d)

Supply chain

7.

A CFO receives a fraudulent email that appears to come from the CEO asking for an emergency wire transfer. Which targeted phishing technique is this?

a)

Vishing

b)

Spear phishing

c)

Whaling

d)

Angler phishing

8.

Attackers register the domain “micr0soft-support.com” to make phishing emails look credible. Which technique does this describe?

a)

Pharming

b)

Typosquatting

c)

DNS tunneling

d)

Watering hole attack

9.

A threat group compromises a small third-party vendor that provides HVAC monitoring software to a large corporation. Through the vendor’s remote access, the attackers infiltrate the corporation’s main network. This scenario BEST illustrates which concept?

a)

Insider threat

b)

Watering hole attack

c)

Supply chain attack

d)

Pretexting

10.

A user receives a fraudulent text message claiming their bank account is locked and requesting they click a malicious link. Which type of attack is this?

a)

SMiShing

b)

Vishing

c)

Phishing

d)

Scam

11.

A security team receives an alert about a newly discovered zero-day vulnerability affecting their firewall appliance. They immediately perform a focused evaluation of how this vulnerability might impact them. What type of risk assessment is being conducted?

a)

One-time

b)

Recurring

c)

Ad hoc

d)

Continuous

12.

Which of the following BEST describes the purpose of a risk register?

a)

A list of all security controls an organization uses

b)

A master document used to track risks, data, and comparisons

c)

A table used to assign numerical likelihood and impact values

d)

A document required only for third-party audits

13.

A server valued at $80,000 would lose 25% of its value if a breach occurs. The incident is expected to occur twice per year. What is the Annualized Loss Expectancy (ALE)?

a)

$10,000

b)

$20,000

c)

$40,000

d)

$80,000

14.

An organization wants to measure the level of risk before applying any security controls or mitigation. Which type of risk is this?

a)

Residual risk

b)

Inherent risk

c)

Acceptable risk

d)

Transferable risk

15.

A company determines that the cost of implementing a control is higher than the financial impact of the risk itself. They decide not to implement any mitigation.

a)

Transfer

b)

Avoid

c)

Accept

d)

Mitigate

16.

A database server outage would stop the business from processing orders. Management determines the system must be restored within 6 hours, and workers need 2 additional hours afterward to re-validate data. What is the Work Recovery Time (WRT)?

a)

2 hours

b)

6 hours

c)

8 hours

d)

Unknown without RPO

17.

A company wants to ensure a vendor will meet uptime guarantees for a new SaaS product. Which document should the company review?

a)

Memorandum of Understanding (MOU)

b)

Statement of Work (SOW)

c)

Service-Level Agreement (SLA)

d)

Business Partnership Agreement (BPA)

18.

A company requires an independent organization to verify the accuracy and reliability of security controls implemented by a cloud provider. Which type of assessment is this?

a)

Internal assessment

b)

Attestation

c)

Red team test

d)

Memorandum of Agreement

19.

An organization frequently invests in high-profit, high-risk ventures and prioritizes growth over stability. Which risk appetite category does it MOST likely fall into?

a)

Neutral

b)

Conservative

c)

Expansionary

d)

Operational

20.

A server experiences failures several times per year but is repaired quickly each time. Engineers want to understand how long the server typically stays operational between failures. Which metric provides this information?

a)

Mean Time Between Failures (MTBF)

b)

Mean Time To Repair (MTTR)

c)

Availability Ratio

d)

Failure Rate

21.

A security analyst discovers that attackers gained access to a server and were able to dump the contents of RAM, exposing sensitive customer information. This scenario involves which state of data?

a)

Data in transit

b)

Data at rest

c)

Data in use

d)

Archived data

22.

Which of the following BEST describes the primary function of a Data Loss Prevention (DLP) solution?

a)

Encrypting stored data

b)

Monitoring and preventing unauthorized transmission of sensitive data

c)

Blocking all external network traffic

d)

Providing identity federation services

23.

A developer sends an encrypted file containing client records to the backup team. The file cannot be read without the organization’s decryption tool. This file is considered:

a)

Proprietary data

b)

Human-readable data

c)

Non-human-readable data

d)

Regulated data

24.

A company labels customer Social Security Numbers (SSNs) as information that could cause harm if exposed, influencing hiring decisions or financial outcomes. This classification BEST fits:

a)

Proprietary

b)

Public

c)

Sensitive

d)

Intellectual property

25.

Which of the following restricts processing and storage of data to specific geographic regions?

a)

Data masking

b)

Data minimization

c)

Data sovereignty

d)

Authorization boundaries

26.

Which GDPR role determines why and how personal data is processed?

a)

Data Subject

b)

Data Auditor

c)

Data Processor

d)

Data Controller

27.

A customer contacts an organization and requests that all their personal data be completely removed because they no longer use the company’s services. This request refers to which GDPR principle?

a)

Data minimization

b)

Right to be forgotten

c)

Purpose limitation

d)

Data portability

28.

An attacker compromises an HR database and reads employee tax documents, but does not alter or delete anything. Which statement BEST describes this incident?

a)

Only a cybersecurity incident occurred

b)

A privacy breach occurred

c)

A data breach occurred but not a privacy breach

d)

No breach occurred because data was not modified

29.

An organization installs software that blocks employees from sending confidential engineering documents to personal email addresses. Which type of policy does this MOST likely support?

a)

Acceptable Use Policy

b)

Change Management Policy

c)

Code of Conduct

d)

Data Handling Policy

30.

A company launches a program that includes phishing simulations, job-role-specific training, and continuous updates based on new threat trends. This approach BEST aligns with:

a)

Security Awareness Training

b)

Incident Response Planning

c)

Network Security Protocols

d)

Data Loss Prevention

31.

Which document outlines the specific responsibilities and expectations between two organizations collaborating on a joint project?

a)

Service-Level Agreement (SLA)

b)

Memorandum of Understanding (MOU)

c)

Data Handling Policy

d)

Risk Register

32.

A company wants to reduce the likelihood of employees accidentally sharing sensitive information via instant messaging platforms. Which security control would BEST address this concern?

a)

Data Loss Prevention (DLP)

b)

Network Segmentation

c)

Multi-factor Authentication

d)

Patch Management

33.

After a risk assessment, an organization decides to purchase cyber insurance to cover potential financial losses from data breaches. Which risk management strategy is this?

a)

Avoidance

b)

Acceptance

c)

Mitigation

d)

Transfer

34.

An organization prefers to avoid risks that could disrupt its core business operations, even if it means missing out on potential growth opportunities. Which risk appetite category does this BEST describe?

a)

Expansionary

b)

Conservative

c)

Neutral

d)

Operational

35.

After identifying a risk, a company implements additional firewalls and monitoring tools to reduce the likelihood of a successful cyberattack. Which risk management strategy is being used?

a)

Acceptance

b)

Transfer

c)

Mitigation

d)

Avoidance