NEW
Font size
WorksheetsCybersecurity Quiz
Total questions: 40
Worksheet time: 20mins
What does the term "compliance" refer to in cybersecurity?
Agreeing with hackers
Following established rules and regulations
Ignoring security policies
Deleting all data
Which of the following is NOT a type of malware?
Spyware
Ransomware
Firewall
Worm
What is the primary purpose of a proxy server in a network?
Increase network speed
Act as an intermediary between clients and servers
Encrypt all data automatically
Assign IP addresses
Which protocol is used for secure remote command-line access?
HTTP
Telnet
SSH
FTP
What is a vulnerability in cybersecurity?
A type of encryption algorithm
A weakness in a system that can be exploited
An authorized access attempt
A successful security control
Which of the following is a defense against SQL injection attacks?
Enabling cookies
Using parameterized queries
Disabling JavaScript
Increasing server CPU
What does MFA stand for?
Multi-Factor Access
Multi-Factor Authentication
Multi-Firewall Application
Multi-File Access
Which attack involves overwhelming a service with traffic to make it unavailable?
SQL injection
Phishing
Denial of Service
Social engineering
What is the main goal of a penetration test?
To damage a system
To identify security weaknesses before attackers do
To steal company data
To disable firewalls
Which of the following best describes the principle of least privilege?
Give all users full access
Grant users only the permissions they need for their role
Allow guest access to everything
Eliminate all access controls
What is a zero-day attack?
An attack that happens at midnight
An attack exploiting an unknown vulnerability
An attack that lasts only one day
An attack on domain name servers
Which type of attack impersonates a trusted entity to steal credentials?
Port scanning
Spoofing
Packet sniffing
Fuzzing
What is the primary role of a Network Intrusion Prevention System (NIPS)?
Detect and block malicious traffic
Assign IP addresses
Manage DNS records
Compress network packets
Which standard defines information security management?
ISO 27001
HTTP/2
TCP/IP
SMTP
What is a Man-in-the-Middle (MITM) attack?
Intercepting and potentially altering communication between two parties
Creating multiple user accounts
Overloading a server with requests
Stealing encryption keys
Which port is typically used for HTTPS traffic?
80
21
443
25
What does encryption provide primarily?
Faster network speeds
Confidentiality and protection of data
Permanent backup
User authentication
Which of the following is a best practice for incident response?
Immediately delete all logs
Document and preserve evidence
Ignore the incident
Blame the user
What type of threat actor is motivated by hacktivism?
Cybercriminals
Nation-states
Hacktivists
Script kiddies
Which of the following describes a backdoor in cybersecurity?
An exit strategy
A hidden entry point for unauthorized access
A backup file system
A secondary firewall
What is the purpose of a Web Application Firewall (WAF)?
Manage user passwords
Protect web applications from attacks
Archive old data
Monitor employee emails
Which of the following is NOT a common network protocol?
TCP
UDP
ICMP
FIZZ
What does CVSS stand for?
Cyber Vulnerability Security Score
Common Vulnerability Scoring System
Critical Virus Severity System
Continuous Vulnerability Scan System
Which attack method tries multiple passwords until one works?
Rainbow table attack
Brute-force attack
Dictionary attack
Keylogging
What is a honeypot in cybersecurity?
A type of malware
A decoy system to detect and study attacks
An antivirus software
A password cracking tool
Which of the following is a sign of a strong security culture?
Employees never receive training
Regular security awareness training and incident reporting
All passwords are written on sticky notes
No security policies exist
What is privilege escalation?
Increasing internet speed
Gaining higher access levels than originally authorized
Updating user profiles
Backup restoration
Which protocol is used for domain name resolution?
HTTP
FTP
DNS
SMTP
What does the term "attack surface" refer to?
The physical size of servers
All potential points where an attacker could breach a system
The number of users in a network
Storage capacity
Which of the following is a preventive security control?
Audit logs
Firewalls
System monitoring
Incident reports
What is a rootkit?
A type of flower
Malware that provides administrative access
A networking device
A database management system
Which of the following best describes defense in depth?
Using only one security measure
Multiple layers of security controls
Avoiding all security measures
Trusting all network traffic
What is the primary goal of data classification?
Organize files alphabetically
Delete unnecessary data
Determine appropriate security controls based on sensitivity
Backup all data
Which of the following is an example of a social engineering technique?
Port scanning
Pretexting
SQL injection
Buffer overflow
What is the purpose of network segmentation?
Slow down network traffic
Isolate networks to limit lateral movement
Eliminate the need for firewalls
Remove unnecessary files
Which of the following is NOT a component of the CIA triad?
Confidentiality
Authentication
Integrity
Availability
What is the role of a security information and event management (SIEM) system?
Manage user passwords only
Collect and analyze security logs for threats
Send emails
Design network topologies
Which of the following is a form of cyberattack targeting users via email?
MITM attack
Spear phishing
Port scanning
Packet sniffing
What is the primary benefit of using a VPN?
Increase storage capacity
Encrypt traffic and provide privacy over networks
Delete malware automatically
Manage user passwords
Which of the following is a best practice for password security?
Use birthdate as password
Write passwords on whiteboards
Use unique, complex passwords with regular changes
Share passwords with colleagues
