NEW
Font size
WorksheetsCybersecurity Quiz
Total questions: 40
Worksheet time: 20mins
What does BYOD stand for in cybersecurity?
Bring Your Own Device
Business Year of Defense
Backup Your Own Data
Binary Year Oversight Division
Which attack targets the domain name system to redirect traffic?
ARP spoofing
DNS spoofing
ICMP flooding
SYN flooding
What is the primary purpose of a demilitarized zone (DMZ)?
Store customer data
Isolate public-facing services from internal networks
Encrypt all network traffic
Assign IP addresses to devices
Which encryption standard is considered most secure for modern communications?
DES
MD5
AES-256
Base64
What is the purpose of a Security Awareness Training program?
Replace firewalls
Educate employees about security risks and best practices
Eliminate all types of attacks
Disable user access to systems
Which of the following describes a watering hole attack?
Flooding servers with requests
Compromising a website frequently visited by targets
Stealing network credentials
Installing backdoors via email
What does OWASP Top 10 focus on?
Most dangerous operating systems
Most critical web application security risks
Firewall configurations
Password strength algorithms
Which cryptographic method provides both confidentiality and integrity?
Compression
Authenticated encryption
Hashing only
Symmetric keys alone
What is the primary purpose of rate limiting in web applications?
Increase server speed
Prevent brute-force and DoS attacks
Improve user experience
Reduce bandwidth usage
Which type of vulnerability allows code execution through unsanitized input?
Path traversal
Cross-site scripting (XSS)
Cross-site request forgery (CSRF)
Broken authentication
What is credential stuffing?
Storing credentials in a safe
Using multiple passwords for the same account
Testing stolen credentials against multiple accounts
Sharing credentials with trusted colleagues
Which of the following is a symmetric encryption algorithm?
RSA
Diffie-Hellman
Blowfish
ECC
What is the primary goal of access control lists (ACLs)?
Monitor network traffic speed
Define who can access resources
Encrypt all data transfers
Create backup copies
Which attack uses a fake login page to steal credentials?
Keylogger attack
Phishing attack
Man-in-the-middle attack
Packet sniffing
What is the primary function of a certificate authority (CA)?
Generate encryption algorithms
Issue and verify digital certificates
Monitor firewall traffic
Manage user passwords
Which protocol is used for secure email communication?
POP3
SMTP
S/MIME
IMAP
What is the primary purpose of a Web Application Firewall (WAF) rule?
Speed up website performance
Block malicious HTTP requests
Manage user accounts
Archive old data
Which of the following is a corrective security control?
Firewall
Password policy
Incident remediation
Security monitoring
What type of attack involves creating multiple fake access points?
ARP poisoning
Rogue access point attack
Port scanning
DNS tunneling
Which of the following best describes a logic bomb?
An explosive device
Malicious code triggered by a specific condition
A type of firewall rule
An encryption method
What is the primary purpose of multi-tenancy in cloud security?
Share resources while maintaining isolation
Reduce encryption overhead
Increase bandwidth
Eliminate need for firewalls
Which attack occurs when an attacker replaces legitimate software with malicious code?
Man-in-the-middle
Supply chain attack
Brute force
Denial of service
What does GDPR primarily regulate?
Firewall configurations
Personal data protection in the EU
Network protocols
Antivirus software
Which of the following is a passive security control?
Intrusion prevention system
Two-factor authentication
Environmental controls
Antivirus software
What is the primary goal of threat modeling?
Identify potential security threats and vulnerabilities
Increase system performance
Create user accounts
Archive security logs
Which of the following describes a pass-the-hash attack?
Stealing password hashes and using them directly
Guessing a password one character at a time
Intercepting email hashes
Modifying hash functions
What is the primary function of a bastion host?
Store backup data
Act as a single point of entry to a network
Generate encryption keys
Monitor network bandwidth
Which biometric authentication method is least susceptible to spoofing?
Fingerprint
Iris recognition
Facial recognition
Voice recognition
What does the Shodan search engine typically target?
Dark web marketplaces
Internet-connected devices and systems
Email servers
VPN services
Which of the following is NOT a valid reason to perform a vulnerability assessment?
Identify security weaknesses
Improve system performance
Prioritize security improvements
Inform risk management decisions
What is the primary purpose of a bug bounty program?
Prevent all attacks
Incentivize responsible disclosure of vulnerabilities
Replace security testing
Eliminate the need for firewalls
Which of the following best describes a covert channel?
A hidden communication method to bypass security controls
A firewall configuration
A backup network connection
A VPN tunnel
What is the primary goal of application whitelisting?
Allow all software to run
Only permit approved applications to execute
Block antivirus software
Disable security features
Which type of attack attempts to overload system resources?
Phishing
Resource exhaustion
Social engineering
Credential stuffing
What is the primary purpose of a certificate pinning strategy?
Increase encryption speed
Prevent man-in-the-middle attacks using rogue certificates
Reduce certificate validation time
Eliminate the need for CAs
Which of the following is an example of a physical security control?
Firewall rule
Access badge system
Antivirus software
Encryption algorithm
What does CWE stand for in vulnerability classification?
Cyber Weakness Evaluation
Common Weakness Enumeration
Critical Web Error
Cryptographic Weakness Engine
Which attack vector uses memory corruption to gain unauthorized access?
Social engineering
Buffer overflow
Phishing
Shoulder surfing
What is the primary purpose of security hardening?
Increase system speed
Reduce the attack surface by disabling unnecessary services
Create user accounts
Generate security reports
Which of the following is a characteristic of a rootless container?
Runs with full root privileges
Cannot access any files
Runs without root privileges
Requires administrative access
