Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Malware Threats

Total questions: 32

Worksheet time: 16mins

Name
Class
Date
1.

What does malware stand for?

a)

Managed software

b)

Malicious software

c)

Multiple software

d)

Maintenance software

2.

Which type of malware self-replicates and spreads automatically across networks without user interaction?

a)

Virus

b)

Trojan

c)

Worm

d)

Spyware

3.

In the NotPetya ransomware attack (2017), what was the estimated global damage?

a)

£1 billion

b)

£3 billion

c)

£8 billion

d)

£15 billion

4.

What distinguishes a Trojan horse from a virus?

a)

Trojans spread faster

b)

Trojans disguise themselves as legitimate software

c)

Trojans only affect mobile devices

d)

Trojans cannot be detected

5.

Which indicator suggests a ransomware infection?

a)

Slow internet connection

b)

Files encrypted with changed extensions and ransom demand

c)

Excessive pop-up advertisements

d)

Automatic software updates

6.

What does DDoS stand for?

a)

Direct Denial of Service

b)

Distributed Denial of Service

c)

Digital Denial of Software

d)

Dedicated Denial of Systems

7.

In the 2016 Dyn DDoS attack, which botnet was primarily responsible?

a)

Conficker

b)

Zeus

c)

Mirai

d)

Emotet

8.

What is a Man-in-the-Middle (MitM) attack?

a)

An attack that crashes servers

b)

An attack that intercepts communications between two parties

c)

An attack that steals passwords only

d)

An attack that deletes files

9.

Which protocol vulnerability does DNS spoofing exploit?

a)

HTTP

b)

FTP

c)

DNS cache

d)

SMTP

10.

What type of devices were primarily compromised in the Mirai botnet?

a)

Desktop computers

b)

Mobile phones

c)

IoT devices (cameras, routers, DVRs)

d)

Server databases

11.

What does SQL injection allow an attacker to do?

a)

Slow down the website

b)

Manipulate database queries and extract data

c)

Change the website colours

d)

Install browser extensions

12.

Which UK company suffered a SQL injection breach in 2015 affecting 156,959 customers?

a)

BT

b)

Vodafone

c)

TalkTalk

d)

Virgin Media

13.

What does XSS stand for in web security?

a)

Extra Security System

b)

Cross-Site Scripting

c)

Extended Server Security

d)

External System Scan

14.

How much was TalkTalk fined by the ICO for their data breach?

a)

£100,000

b)

£250,000

c)

£400,000

d)

£1,000,000

15.

What is the primary defence against SQL injection attacks?

a)

Using HTTPS

b)

Installing antivirus

c)

Input validation and parameterised queries

d)

Changing passwords regularly

16.

According to IBM's Cost of a Data Breach Report 2024, what is the average cost of a data breach?

a)

£1.5 million

b)

£2.5 million

c)

£3.5 million

d)

£5.5 million

17.

How many people were affected by the Equifax data breach in 2017?

a)

50 million

b)

100 million

c)

147 million

d)

200 million

18.

What vulnerability did attackers exploit in the Equifax breach?

a)

Weak passwords

b)

Unpatched Apache Struts vulnerability (CVE-2017-5638)

c)

Missing firewall

d)

Social engineering

19.

What is data exfiltration?

a)

Backing up data

b)

Encrypting data

c)

Unauthorised transfer of data from systems

d)

Deleting old data

20.

How long before the Equifax breach was the patch for the vulnerability available?

a)

Two weeks

b)

One month

c)

Two months

d)

Six months

21.

Approximately what percentage of data breaches involve insider threats?

a)

10%

b)

20%

c)

30%

d)

40%

22.

Which company experienced insider sabotage in 2018 from a disgruntled employee who modified manufacturing systems?

a)

Apple

b)

Tesla

c)

Ford

d)

Google

23.

What is a negligent insider?

a)

Someone who intentionally steals data

b)

Someone who causes breaches through carelessness or policy violations

c)

A contractor with expired credentials

d)

An external hacker

24.

Which of the following is NOT a warning sign of a malicious insider?

a)

Working unusual hours

b)

Accessing systems outside their job role

c)

Attending security training sessions

d)

Downloading large amounts of data

25.

What motivated the Tesla employee to conduct insider sabotage?

a)

Financial gain from competitors

b)

Upset about not receiving a promotion

c)

Political ideology

d)

Accidental mistake

26.

What does APT stand for?

a)

Automated Password Tool

b)

Advanced Persistent Threat

c)

Application Protection Technology

d)

Active Protocol Testing

27.

Which threat actor was responsible for the SolarWinds supply chain attack?

a)

APT28

b)

Lazarus Group

c)

APT29 (Cozy Bear)

d)

Anonymous

28.

How long did the SolarWinds breach go undetected?

a)

Two weeks

b)

One month

c)

Three months

d)

Nine months

29.

What distinguishes APTs from other cyber threats?

a)

They are always automated

b)

They are sophisticated, persistent, and well-resourced attacks targeting high-value assets

c)

They only affect small businesses

d)

They are easy to detect

30.

What is the typical first phase of an APT attack lifecycle?

a)

Data exfiltration

b)

Lateral movement

c)

Reconnaissance

d)

Installing ransomware

31.

According to the scoring guide, what does a score of 27-30 correct answers indicate?

a)

Satisfactory - Basic knowledge present, more study needed

b)

Outstanding - Excellent understanding of network threats

c)

Good - Solid understanding, review challenging areas

d)

Review required - Revisit course materials and retake assessment

32.

According to the scoring guide, what should a student do if they score below 15 correct answers?

a)

A) Review challenging areas

b)

B) Revisit course materials and retake assessment

c)

C) Strong grasp of key concepts with minor gaps

d)

D) Excellent understanding of network threats