wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Cybersecurity Quiz

Total questions: 40

Worksheet time: 20mins

Name
Class
Date
1.

What does the term "compliance" refer to in cybersecurity?

a)

Agreeing with hackers

b)

Following established rules and regulations

c)

Ignoring security policies

d)

Deleting all data

2.

Which of the following is NOT a type of malware?

a)

Spyware

b)

Ransomware

c)

Firewall

d)

Worm

3.

What is the primary purpose of a proxy server in a network?

a)

Increase network speed

b)

Act as an intermediary between clients and servers

c)

Encrypt all data automatically

d)

Assign IP addresses

4.

Which protocol is used for secure remote command-line access?

a)

HTTP

b)

Telnet

c)

SSH

d)

FTP

5.

What is a vulnerability in cybersecurity?

a)

A type of encryption algorithm

b)

A weakness in a system that can be exploited

c)

An authorized access attempt

d)

A successful security control

6.

Which of the following is a defense against SQL injection attacks?

a)

Enabling cookies

b)

Using parameterized queries

c)

Disabling JavaScript

d)

Increasing server CPU

7.

What does MFA stand for?

a)

Multi-Factor Access

b)

Multi-Factor Authentication

c)

Multi-Firewall Application

d)

Multi-File Access

8.

Which attack involves overwhelming a service with traffic to make it unavailable?

a)

SQL injection

b)

Phishing

c)

Denial of Service

d)

Social engineering

9.

What is the main goal of a penetration test?

a)

To damage a system

b)

To identify security weaknesses before attackers do

c)

To steal company data

d)

To disable firewalls

10.

Which of the following best describes the principle of least privilege?

a)

Give all users full access

b)

Grant users only the permissions they need for their role

c)

Allow guest access to everything

d)

Eliminate all access controls

11.

What is a zero-day attack?

a)

An attack that happens at midnight

b)

An attack exploiting an unknown vulnerability

c)

An attack that lasts only one day

d)

An attack on domain name servers

12.

Which type of attack impersonates a trusted entity to steal credentials?

a)

Port scanning

b)

Spoofing

c)

Packet sniffing

d)

Fuzzing

13.

What is the primary role of a Network Intrusion Prevention System (NIPS)?

a)

Detect and block malicious traffic

b)

Assign IP addresses

c)

Manage DNS records

d)

Compress network packets

14.

Which standard defines information security management?

a)

ISO 27001

b)

HTTP/2

c)

TCP/IP

d)

SMTP

15.

What is a Man-in-the-Middle (MITM) attack?

a)

Intercepting and potentially altering communication between two parties

b)

Creating multiple user accounts

c)

Overloading a server with requests

d)

Stealing encryption keys

16.

Which port is typically used for HTTPS traffic?

a)

80

b)

21

c)

443

d)

25

17.

What does encryption provide primarily?

a)

Faster network speeds

b)

Confidentiality and protection of data

c)

Permanent backup

d)

User authentication

18.

Which of the following is a best practice for incident response?

a)

Immediately delete all logs

b)

Document and preserve evidence

c)

Ignore the incident

d)

Blame the user

19.

What type of threat actor is motivated by hacktivism?

a)

Cybercriminals

b)

Nation-states

c)

Hacktivists

d)

Script kiddies

20.

Which of the following describes a backdoor in cybersecurity?

a)

An exit strategy

b)

A hidden entry point for unauthorized access

c)

A backup file system

d)

A secondary firewall

21.

What is the purpose of a Web Application Firewall (WAF)?

a)

Manage user passwords

b)

Protect web applications from attacks

c)

Archive old data

d)

Monitor employee emails

22.

Which of the following is NOT a common network protocol?

a)

TCP

b)

UDP

c)

ICMP

d)

FIZZ

23.

What does CVSS stand for?

a)

Cyber Vulnerability Security Score

b)

Common Vulnerability Scoring System

c)

Critical Virus Severity System

d)

Continuous Vulnerability Scan System

24.

Which attack method tries multiple passwords until one works?

a)

Rainbow table attack

b)

Brute-force attack

c)

Dictionary attack

d)

Keylogging

25.

What is a honeypot in cybersecurity?

a)

A type of malware

b)

A decoy system to detect and study attacks

c)

An antivirus software

d)

A password cracking tool

26.

Which of the following is a sign of a strong security culture?

a)

Employees never receive training

b)

Regular security awareness training and incident reporting

c)

All passwords are written on sticky notes

d)

No security policies exist

27.

What is privilege escalation?

a)

Increasing internet speed

b)

Gaining higher access levels than originally authorized

c)

Updating user profiles

d)

Backup restoration

28.

Which protocol is used for domain name resolution?

a)

HTTP

b)

FTP

c)

DNS

d)

SMTP

29.

What does the term "attack surface" refer to?

a)

The physical size of servers

b)

All potential points where an attacker could breach a system

c)

The number of users in a network

d)

Storage capacity

30.

Which of the following is a preventive security control?

a)

Audit logs

b)

Firewalls

c)

System monitoring

d)

Incident reports

31.

What is a rootkit?

a)

A type of flower

b)

Malware that provides administrative access

c)

A networking device

d)

A database management system

32.

Which of the following best describes defense in depth?

a)

Using only one security measure

b)

Multiple layers of security controls

c)

Avoiding all security measures

d)

Trusting all network traffic

33.

What is the primary goal of data classification?

a)

Organize files alphabetically

b)

Delete unnecessary data

c)

Determine appropriate security controls based on sensitivity

d)

Backup all data

34.

Which of the following is an example of a social engineering technique?

a)

Port scanning

b)

Pretexting

c)

SQL injection

d)

Buffer overflow

35.

What is the purpose of network segmentation?

a)

Slow down network traffic

b)

Isolate networks to limit lateral movement

c)

Eliminate the need for firewalls

d)

Remove unnecessary files

36.

Which of the following is NOT a component of the CIA triad?

a)

Confidentiality

b)

Authentication

c)

Integrity

d)

Availability

37.

What is the role of a security information and event management (SIEM) system?

a)

Manage user passwords only

b)

Collect and analyze security logs for threats

c)

Send emails

d)

Design network topologies

38.

Which of the following is a form of cyberattack targeting users via email?

a)

MITM attack

b)

Spear phishing

c)

Port scanning

d)

Packet sniffing

39.

What is the primary benefit of using a VPN?

a)

Increase storage capacity

b)

Encrypt traffic and provide privacy over networks

c)

Delete malware automatically

d)

Manage user passwords

40.

Which of the following is a best practice for password security?

a)

Use birthdate as password

b)

Write passwords on whiteboards

c)

Use unique, complex passwords with regular changes

d)

Share passwords with colleagues