WorksheetsThreat Types and Motivations Worksheet
Total questions: 35
Worksheet time: 18mins
A company discovers a new type of malware targeting its R&D servers. The malware uses zero-day exploits, custom command-and-control channels, and deletes logs after execution. Intelligence analysts believe the group is backed by a foreign government. Which type of threat actor is MOST likely responsible?
Script kiddie
Nation-state actor
Insider with malicious intent
Hacktivist group
A contractor accidentally sends a confidential customer report to the wrong vendor because they misunderstood the new email policy. Which type of insider threat does this scenario represent?
Malicious insider
Unintentional insider
Competitor threat
Hacktivist insider
Organized crime is motivated by which of the following?
Political influence
Chaotic disruption
Criminal profit
Whistleblowing
An attacker calls a help desk pretending to be a new employee who “lost VPN access.” They provide a fake employee ID and use urgency to pressure the technician into resetting the account.
A. Pretexting
B. Watering hole attack
C. Lure-based vector
D. Whaling
A security team wants to evaluate all ways an attacker could exploit vulnerabilities in their environment, including door access, cloud services, and employees. Which concept are they analyzing?
Threat vector
Attack surface
Attack chain
Insider footprint
A user finds a USB drive in the parking lot labeled “Executive Salaries.” When plugged in, a malicious script auto-executes. Which type of vector is being used?
Message-based
Network-based
Lure-based
Supply chain
A CFO receives a fraudulent email that appears to come from the CEO asking for an emergency wire transfer. Which targeted phishing technique is this?
Vishing
Spear phishing
Whaling
Angler phishing
Attackers register the domain “micr0soft-support.com” to make phishing emails look credible. Which technique does this describe?
Pharming
Typosquatting
DNS tunneling
Watering hole attack
A threat group compromises a small third-party vendor that provides HVAC monitoring software to a large corporation. Through the vendor’s remote access, the attackers infiltrate the corporation’s main network. This scenario BEST illustrates which concept?
Insider threat
Watering hole attack
Supply chain attack
Pretexting
A user receives a fraudulent text message claiming their bank account is locked and requesting they click a malicious link. Which type of attack is this?
SMiShing
Vishing
Phishing
Scam
A security team receives an alert about a newly discovered zero-day vulnerability affecting their firewall appliance. They immediately perform a focused evaluation of how this vulnerability might impact them. What type of risk assessment is being conducted?
One-time
Recurring
Ad hoc
Continuous
Which of the following BEST describes the purpose of a risk register?
A list of all security controls an organization uses
A master document used to track risks, data, and comparisons
A table used to assign numerical likelihood and impact values
A document required only for third-party audits
A server valued at $80,000 would lose 25% of its value if a breach occurs. The incident is expected to occur twice per year. What is the Annualized Loss Expectancy (ALE)?
$10,000
$20,000
$40,000
$80,000
An organization wants to measure the level of risk before applying any security controls or mitigation. Which type of risk is this?
Residual risk
Inherent risk
Acceptable risk
Transferable risk
A company determines that the cost of implementing a control is higher than the financial impact of the risk itself. They decide not to implement any mitigation.
Transfer
Avoid
Accept
Mitigate
A database server outage would stop the business from processing orders. Management determines the system must be restored within 6 hours, and workers need 2 additional hours afterward to re-validate data. What is the Work Recovery Time (WRT)?
2 hours
6 hours
8 hours
Unknown without RPO
A company wants to ensure a vendor will meet uptime guarantees for a new SaaS product. Which document should the company review?
Memorandum of Understanding (MOU)
Statement of Work (SOW)
Service-Level Agreement (SLA)
Business Partnership Agreement (BPA)
A company requires an independent organization to verify the accuracy and reliability of security controls implemented by a cloud provider. Which type of assessment is this?
Internal assessment
Attestation
Red team test
Memorandum of Agreement
An organization frequently invests in high-profit, high-risk ventures and prioritizes growth over stability. Which risk appetite category does it MOST likely fall into?
Neutral
Conservative
Expansionary
Operational
A server experiences failures several times per year but is repaired quickly each time. Engineers want to understand how long the server typically stays operational between failures. Which metric provides this information?
Mean Time Between Failures (MTBF)
Mean Time To Repair (MTTR)
Availability Ratio
Failure Rate
A security analyst discovers that attackers gained access to a server and were able to dump the contents of RAM, exposing sensitive customer information. This scenario involves which state of data?
Data in transit
Data at rest
Data in use
Archived data
Which of the following BEST describes the primary function of a Data Loss Prevention (DLP) solution?
Encrypting stored data
Monitoring and preventing unauthorized transmission of sensitive data
Blocking all external network traffic
Providing identity federation services
A developer sends an encrypted file containing client records to the backup team. The file cannot be read without the organization’s decryption tool. This file is considered:
Proprietary data
Human-readable data
Non-human-readable data
Regulated data
A company labels customer Social Security Numbers (SSNs) as information that could cause harm if exposed, influencing hiring decisions or financial outcomes. This classification BEST fits:
Proprietary
Public
Sensitive
Intellectual property
Which of the following restricts processing and storage of data to specific geographic regions?
Data masking
Data minimization
Data sovereignty
Authorization boundaries
Which GDPR role determines why and how personal data is processed?
Data Subject
Data Auditor
Data Processor
Data Controller
A customer contacts an organization and requests that all their personal data be completely removed because they no longer use the company’s services. This request refers to which GDPR principle?
Data minimization
Right to be forgotten
Purpose limitation
Data portability
An attacker compromises an HR database and reads employee tax documents, but does not alter or delete anything. Which statement BEST describes this incident?
Only a cybersecurity incident occurred
A privacy breach occurred
A data breach occurred but not a privacy breach
No breach occurred because data was not modified
An organization installs software that blocks employees from sending confidential engineering documents to personal email addresses. Which type of policy does this MOST likely support?
Acceptable Use Policy
Change Management Policy
Code of Conduct
Data Handling Policy
A company launches a program that includes phishing simulations, job-role-specific training, and continuous updates based on new threat trends. This approach BEST aligns with:
Security Awareness Training
Incident Response Planning
Network Security Protocols
Data Loss Prevention
Which document outlines the specific responsibilities and expectations between two organizations collaborating on a joint project?
Service-Level Agreement (SLA)
Memorandum of Understanding (MOU)
Data Handling Policy
Risk Register
A company wants to reduce the likelihood of employees accidentally sharing sensitive information via instant messaging platforms. Which security control would BEST address this concern?
Data Loss Prevention (DLP)
Network Segmentation
Multi-factor Authentication
Patch Management
After a risk assessment, an organization decides to purchase cyber insurance to cover potential financial losses from data breaches. Which risk management strategy is this?
Avoidance
Acceptance
Mitigation
Transfer
An organization prefers to avoid risks that could disrupt its core business operations, even if it means missing out on potential growth opportunities. Which risk appetite category does this BEST describe?
Expansionary
Conservative
Neutral
Operational
After identifying a risk, a company implements additional firewalls and monitoring tools to reduce the likelihood of a successful cyberattack. Which risk management strategy is being used?
Acceptance
Transfer
Mitigation
Avoidance
