wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Configuration Vulnerabilities

Total questions: 30

Worksheet time: 15mins

Name
Class
Date
1.

What is the most common cause of configuration vulnerabilities?

a)

Hardware failures

b)

Default settings left unchanged

c)

Network congestion

d)

Power outages

2.

In the MongoDB database exposure case study, what was the primary configuration error?

a)

Outdated software version

b)

Weak encryption protocols

c)

Database bound to all network interfaces with no authentication

d)

Missing firewall rules

3.

Which of the following is NOT a configuration vulnerability?

a)

Overly permissive firewall rules

b)

Unnecessary services enabled

c)

Software bug in the operating system

d)

Disabled security features

4.

What should be the first action when discovering a service using default administrator credentials?

a)

Document it for the next security review

b)

Immediately change the credentials

c)

Disable the service permanently

d)

Monitor the service for suspicious activity

5.

Which tool provides industry-standard secure configuration guidelines?

a)

Google Security Scanner

b)

Norton Antivirus

c)

CIS Benchmarks

d)

Windows Defender

6.

According to the Verizon Data Breach Investigations Report, what percentage of breaches involve weak authentication?

a)

Over 40%

b)

Over 60%

c)

Over 80%

d)

Over 95%

7.

What was the password protecting the SolarWinds update server?

a)

admin123

b)

password

c)

solarwinds123

d)

update2020

8.

What is MFA (Multi-Factor Authentication)?

a)

Using multiple passwords

b)

Requiring two or more authentication factors

c)

Multiple user accounts

d)

Automatic password changes

9.

Which of the following indicates poor session management?

a)

Sessions that timeout after 30 minutes

b)

Encrypted session tokens

c)

Sessions that never expire

d)

Logout functionality

10.

What is the recommended minimum password length according to current best practices?

a)

6 characters

b)

8 characters

c)

10 characters

d)

12 characters

11.

What is a CVE?

a)

Computer Virus Encyclopedia

b)

Common Vulnerabilities and Exposures

c)

Critical Vendor Error

d)

Cyber Verification Examination

12.

Which ransomware exploited the EternalBlue vulnerability in 2017?

a)

CryptoLocker

b)

Petya

c)

WannaCry

d)

Ryuk

13.

How long before the WannaCry attack had Microsoft released a patch for the vulnerability?

a)

Two weeks

b)

One month

c)

Two months

d)

Six months

14.

What is the most critical window for system vulnerability?

a)

Before a vulnerability is discovered

b)

Between vulnerability discovery and disclosure

c)

Between patch release and patch application

d)

After a system is compromised

15.

What does Log4Shell (CVE-2021-44228) affect?

a)

Windows operating systems

b)

Apache Log4j logging library

c)

Cisco routers

d)

Oracle databases

16.

Which protocol should replace HTTP for secure web communications?

a)

FTP

b)

HTTPS

c)

Telnet

d)

SMTP

17.

What is the secure alternative to Telnet?

a)

FTP

b)

HTTP

c)

SSH

d)

SNMP

18.

Why is using HTTP instead of HTTPS a security risk?

a)

It is slower

b)

Data is transmitted in plaintext and can be intercepted

c)

It uses more bandwidth

d)

It requires special software

19.

Which SNMP version includes encryption and authentication?

a)

SNMPv1

b)

SNMPv2

c)

SNMPv3

d)

All versions are equally secure

20.

What tool can be used to analyse network traffic and detect unencrypted protocols?

a)

Microsoft Word

b)

Wireshark

c)

Adobe Reader

d)

Chrome Browser

21.

What percentage of breaches involve social engineering according to Verizon's DBIR?

a)

Over 15%

b)

Over 25%

c)

Over 35%

d)

Over 45%

22.

How did attackers compromise Twitter accounts in the 2020 Bitcoin hack?

a)

SQL injection

b)

DDoS attack

c)

Phone-based social engineering (vishing) targeting employees

d)

Brute force password attack

23.

What is pretexting?

a)

Sending mass phishing emails

b)

Creating a false scenario to extract information

c)

Following someone through a secure door

d)

Installing malware on USB drives

24.

What is tailgating in a security context?

a)

Following vehicles too closely

b)

Monitoring someone's email

c)

Following an authorised person through a secure door without proper authentication

d)

Copying someone's password

25.

Which is a warning sign of a phishing email?

a)

Professional formatting

b)

Urgent language demanding immediate action

c)

Emails from known contacts

d)

Correct spelling and grammar

26.

What is the primary risk of unsecured server rooms?

a)

Increased electricity costs

b)

Direct physical access to servers and potential data theft

c)

Poor ventilation

d)

Difficulty finding equipment

27.

What should be done with old hard drives before disposal?

a)

Delete all files

b)

Format the drive

c)

Physically destroy or use certified data destruction

d)

Remove the power cable

28.

What physical security measure prevents unauthorised network access in public areas?

a)

Painting walls

b)

Port security on network switches to disable unused ports

c)

Installing carpet

d)

Adding more lighting

29.

Why are unattended workstations without screen locks a security risk?

a)

They waste electricity

b)

Anyone can access logged-in systems and data

c)

They slow down the network

d)

They violate building codes

30.

What is the purpose of visitor badges and sign-in procedures?

a)

To make visitors feel welcome

b)

To track who is in the building and restrict unauthorised access

c)

To collect marketing data

d)

To comply with fire regulations only