Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CYF MCQ Part 2

Total questions: 139

Worksheet time: 1hrs 10mins

Name
Class
Date
1.

Why is high availability critical for the finance industry?

a)

For customer satisfaction only

b)

Continuous trading, compliance, and customer trust

c)

Only for software updates

d)

It is not critical

2.

Which of the following is a threat to availability?

a)

Unauthorized database access

b)

DoS attacks

c)

Natural disasters like hurricanes

d)

All of the above

3.

Categorizing the impact of a threat helps organizations to:

a)

Increase complexity

b)

Reduce employee workload

c)

Determine the dollar impact of a threat

d)

Avoid redundancy

4.

Asset identification includes which of the following?

a)

Hardware, software, network devices, firmware, libraries

b)

Only software applications

c)

Only operating systems

d)

Only user accounts

5.

Which of the following is the correct order for asset classification?

a)

Identify assets → Assign owner → Determine criteria → Implement schema

b)

Assign owner → Determine criteria → Identify assets → Implement schema

c)

Determine criteria → Implement schema → Assign owner → Identify assets

d)

Implement schema → Identify assets → Assign owner → Determine criteria

6.

Asset standardization helps to:

a)

Increase maintenance cost

b)

Reduce complexity, increase security, and improve maintenance

c)

Increase number of software applications used

d)

Eliminate risk entirely

7.

Quantitative risk analysis involves:

a)

Using opinions and scenarios

b)

Assigning numeric values to risk, such as dollars or percentages

c)

Ignoring asset value

d)

None of the above

8.

Qualitative risk analysis is:

a)

Numeric calculation of losses

b)

Subjective evaluation of likelihood and impact

c)

Always more accurate than quantitative

d)

Only applicable to physical assets

9.

Which of the following is NOT a risk mitigation strategy?

a)

Accept

b)

Reduce

c)

Avoid

d)

Ignore

10.

Defense in depth aims to:

a)

Use a single strong defense

b)

Layer multiple security measures to minimize risk

c)

Avoid using redundancy

d)

Transfer all risks to a third party

11.

Which principle ensures that if one security layer fails, others still protect the system?

a)

Obscurity

b)

Simplicity

c)

Diversity

d)

Limiting

12.

Obscuring information in security means:

a)

Making system details hard to detect by attackers

b)

Using strong passwords only

c)

Eliminating redundancy

d)

Increasing system complexity

13.

Simplicity in security solutions is important because:

a)

Complexity always guarantees security

b)

Complex systems are easy to manage

c)

Simple internal design reduces misconfiguration risk

d)

Simplicity prevents attacks entirely

14.

A single point of failure is:

a)

A backup component

b)

A critical element whose failure halts operations

c)

A type of RAID configuration

d)

A non-critical process

15.

N+1 redundancy ensures:

a)

Only N components are used with no backup

b)

N components plus one backup can take over if one fails

c)

Fault tolerance is ignored

d)

Network loops are created

16.

RAID provides:

a)

Only backup power

b)

Data redundancy and improved performance

c)

User authentication

d)

Firewall protection

17.

Spanning Tree Protocol (STP) prevents:

a)

Loops in networks with redundant paths

b)

Data mirroring

c)

Risk analysis failures

d)

Unauthorized access

18.

Which of the following is a benefit of system resiliency?

a)

Maintains data availability during attacks

b)

Rapid recovery from failures

19.

Router Redundancy: What is considered a single point of failure in a network?

a)

A redundant switch

b)

A router serving as the only default gateway

c)

Multiple load-balanced servers

d)

Multiple network paths

20.

Router Redundancy: First-hop redundancy provides:

a)

Backup power supply

b)

Alternate routing paths at the first-hop router

c)

Firewall protection

d)

End-user device security

21.

Router Redundancy: Which of the following is not a router redundancy protocol?

a)

HSRP

b)

VRRP

c)

GLBP

d)

OSPF

22.

Router Redundancy: In HSRP, the standby router’s main function is:

a)

Forward packets actively

b)

Block redundant paths

c)

Monitor the active router and take over if it fails

d)

Assign IP addresses

23.

Location Redundancy: Synchronous replication requires:

a)

Low bandwidth and high latency

b)

Real-time updates and low latency

c)

Periodic updates

d)

Only a single site

24.

Location Redundancy: Which replication method is most bandwidth-efficient?

a)

Synchronous

b)

Asynchronous

c)

Point-in-time

d)

Real-time

25.

Resiliency: Resiliency in networking is best described as:

a)

Adding multiple firewalls

b)

Maintaining network operation despite failures

c)

Using only one network path

d)

Backing up data once a month

26.

Resiliency: What is the difference between redundancy and resiliency?

a)

Redundancy prevents attacks; resiliency detects them

b)

Redundancy adds backups; resiliency ensures continued operation

c)

Redundancy is cheaper than resiliency

d)

Resiliency is hardware only

27.

Resiliency: Application resilience ensures:

a)

Applications always run on a single server

b)

Applications function even if one component fails

c)

Users can bypass security controls

d)

Only data backups are available

28.

Resiliency: Cisco IOS resilient configuration protects routers by:

a)

Using multiple IP addresses

b)

Maintaining secure copies of the IOS image and running configuration

c)

Encrypting all packets

d)

Blocking unauthorized users

29.

Incident Response: What is the primary role of a CSIRT?

a)

Manage incident response and maintain the response plan

b)

Install antivirus software

c)

Audit annual budgets

d)

Design hardware chipsets

30.

Which is not a stage of incident handling?

a)

Detection & analysis

b)

Containment, eradication & recovery

c)

Post-incident follow-up

d)

Network configuration

31.

Post-incident follow-up is important to:

a)

Increase network speed

b)

Prevent recurrence and improve monitoring

c)

Reduce server memory usage

d)

Upgrade software

32.

NAC ensures that:

a)

Only authorized and compliant devices access the network

b)

All devices can connect

c)

Routers are always online

d)

Firewalls are disabled

33.

Which is a common NAC compliance check?

a)

Firewall logs

b)

Virus updates

c)

VLAN configuration

d)

Physical cable labelling

34.

How does an IPS differ from an IDS?

a)

IPS only monitors traffic; IDS blocks it

b)

IPS operates inline and blocks malicious traffic; IDS monitors passively

c)

IDS detects viruses; IPS detects malware

d)

IDS replaces firewalls; IPS replaces routers

35.

Operating an IDS in promiscuous mode means:

a)

It blocks unauthorized traffic

b)

It monitors a copy of traffic without affecting flow

c)

It changes the source IP of packets

d)

It forwards all traffic to the Internet

36.

Which is not a detection method used by IPS?

a)

Signature-based

b)

Profile-based

c)

Protocol analysis-based

d)

Encryption-based

37.

NetFlow provides:

a)

Firewall rules

b)

Packet flow statistics through a router or switch

c)

Encryption of network traffic

d)

User authentication

38.

IPFIX is based on which NetFlow version?

a)

Version 5

b)

Version 7

c)

Version 9

d)

Version 10

39.

Indicators of a cyberattack include:

a)

User login success

b)

Account lockouts

c)

Printer activity

d)

Power outages

40.

Advanced threat intelligence helps organizations:

a)

Encrypt all data automatically

b)

Detect attacks earlier and respond faster

c)

Eliminate all vulnerabilities

d)

Replace firewalls

41.

Which is a human-caused disaster?

a)

Earthquake

b)

Hurricane

c)

Sabotage

d)

Tsunami

42.

Difference between a DRP and a business continuity plan:

a)

DRP restores systems after disaster; business continuity ensures operations continue

b)

DRP replaces servers; business continuity replaces users

c)

DRP encrypts data; business continuity backs up files

d)

DRP and business continuity are the same

43.

Which is not a disaster recovery control type?

a)

Preventive

b)

Detective

c)

Corrective

d)

Predictive

44.

Why restore mission-critical systems first?

a)

To minimize downtime and maintain essential operations

b)

To reduce electricity costs

c)

To test new software

d)

To upgrade all hardware

45.

A network is only as strong as:

a)

Its firewall

b)

Its antivirus software

c)

Its weakest link

d)

Its bandwidth

46.

Endpoint security includes which of the following?

a)

Workstations only

b)

Servers only

c)

LAN devices, servers, and end systems

d)

Only IP phones

47.

Device hardening involves:

a)

Installing any software

b)

Securing administrative access, maintaining passwords, and implementing secure communications

c)

Using default configurations

d)

Ignoring patches

48.

Which is the first stage of the Kill Chain?

a)

Exploitation

b)

Delivery

c)

Reconnaissance

d)

Installation

49.

Command and Control in the Kill Chain refers to:

a)

Gaining remote access and controlling the target

b)

Creating a malicious payload

c)

Gathering information

d)

Installing software

50.

Which stage involves sending the exploit to the target?

a)

Delivery

b)

Installation

c)

Weaponization

d)

Action

51.

Hardening an OS includes:

a)

Installing unnecessary programs

b)

Removing unnecessary services and applying security patches

c)

Leaving default passwords

d)

Ignoring updates

52.

MBSA (Microsoft Baseline Security Analyzer) is used to:

a)

Scan malware only

b)

Assess missing updates and security misconfigurations

c)

Encrypt files

d)

Backup data

53.

Security patches:

a)

Introduce new vulnerabilities

b)

Fix vulnerabilities and prevent exploits

c)

Only affect hardware

d)

Are optional for security

54.

Spyware protection scans for:

a)

Viruses

b)

Keyloggers

c)

Spam emails

d)

Browser history

55.

True or False: Running multiple antimalware programs simultaneously is recommended.

a)

True

b)

False

56.

Rogue antivirus software usually:

a)

Removes malware

b)

Warns of fake infections and installs malware

c)

Updates patches

d)

Secures VPN connections

57.

A patch differs from a service pack in that:

a)

Patch fixes specific vulnerabilities, service pack combines multiple updates

b)

Patch is optional, service pack is mandatory

c)

Patch encrypts data

d)

Patch clones hard drives

58.

Which is NOT a benefit of automated patch management?

a)

Centralized reporting

b)

Users cannot disable updates

c)

Users manually select updates

d)

Force updates on schedule

59.

A host-based firewall:

a)

Runs on a network switch

b)

Filters traffic to and from the local host

c)

Encrypts email

d)

Tracks GPS

60.

HIDS (Host Intrusion Detection System) can monitor:

a)

Only traffic reaching the host

b)

Entire network traffic

c)

VPN tunnels

d)

Wireless devices only

61.

VPNs are used to:

a)

Encrypt traffic over public networks

b)

Install patches

c)

Backup files

d)

Scan malware

62.

VPN clients:

a)

Encrypt data before sending over the Internet

b)

Monitor host-based activity

c)

Block phishing websites

d)

Run only on mobile phones

63.

Wireless Security: WEP is:

a)

Strong and secure

b)

Obsolete and vulnerable

c)

Mandatory for WPA2

d)

A firewall protocol

64.

Wireless Security: WPA2 uses:

a)

TKIP only

b)

AES encryption

c)

WEP encryption

d)

VPN tunneling

65.

Wireless Security: Mutual authentication prevents:

a)

Malware installation

b)

Rogue access points

c)

OS misconfiguration

d)

Data backup failure

66.

File Access Control: Principle of Least Privilege means:

a)

Give users full access

b)

Limit users to only necessary resources

c)

Deny all access

d)

Ignore permissions

67.

File Access Control: Denying a user permission to a network share:

a)

Can be overridden

b)

Always overrides other permissions

c)

Does nothing

d)

Deletes files

68.

File Access Control: Moving a file to a different volume:

a)

Keeps original permissions

b)

Inherits new permissions

c)

Encrypts the file

d)

Deletes the file

69.

File Encryption: EFS (Encrypting File System) in Windows:

a)

Encrypts entire drives only

b)

Encrypts files/folders for a specific user

c)

Is hardware only

d)

Backups data

70.

File Encryption: BitLocker requires:

a)

Antivirus software

b)

TPM enabled in BIOS

c)

VPN connection

d)

Disk cloning

71.

System and Data Backups: Data backups should:

a)

Be performed regularly and stored offsite

b)

Be ignored

c)

Only include software

d)

Be public

72.

System and Data Backups: Two key considerations for backups are:

a)

Speed and size

b)

Frequency and security

c)

Encryption and WEP

d)

VPN and HIDS

73.

Content Screening and Blocking: Content filtering types include:

a)

Browser-based

b)

Router-based

c)

Cloud-based

d)

All of the above

74.

Disk Cloning and Deep Freeze: Disk cloning is used to:

a)

Encrypt files

b)

Restore a system to a pre-configured state

c)

Block malicious sites

d)

Track GPS

75.

Disk Cloning and Deep Freeze: Deep Freeze:

a)

Protects the system after a restart

b)

Offers real-time protection

c)

Encrypts files

d)

Is a firewall

76.

Physical Security: Cipher locks:

a)

Can restrict access by time

b)

Record door usage

c)

Are programmable

d)

All of the above

77.

Logout Timers: Idle timeout and screen lock prevent:

a)

Data backup errors

b)

Unauthorized access when a user leaves a workstation

c)

Rogue access points

d)

Antivirus failure

78.

GPS Tracking: Tracking a device without consent is:

a)

Legal

b)

Illegal

c)

Recommended

d)

Required

79.

GPS Tracking: Legal GPS tracking examples include:

a)

Locating vehicles or pets with consent

b)

Hacking phones

c)

Unauthorized surveillance

d)

Rogue access points

80.

What is the purpose of Remote Desktop in Windows?

a)

To install Windows updates automatically

b)

To view and control a computer from a remote location

c)

To back up files to the cloud

d)

To monitor network traffic

81.

Which TCP port does Remote Desktop use by default?

a)

22

b)

23

c)

3389

d)

80

82.

Which Windows tool allows a technician to assist a user while the user watches the repair in real-time?

a)

Remote Desktop

b)

Remote Assistance

c)

Task Manager

d)

Device Manager

83.

Which protocol transmits login credentials in plaintext?

a)

Telnet

b)

SSH

c)

SCP

d)

HTTPS

84.

Which protocol encrypts login credentials and data for secure remote management?

a)

Telnet

b)

HTTP

c)

SSH

d)

FTP

85.

What port does SSH use?

a)

22

b)

23

c)

3389

d)

80

86.

What is the purpose of SCP?

a)

To scan for open ports

b)

To monitor system logs

c)

To securely transfer files between remote systems

d)

To manage Active Directory

87.

Why should an administrator disable unused switch ports?

a)

To increase bandwidth

b)

To prevent unauthorized access

c)

To reduce power consumption

d)

To improve routing efficiency

88.

Removing unnecessary services on devices:

a)

Reduces network speed

b)

Improves security

c)

Increases network traffic

d)

Has no effect

89.

Why are privileged accounts a target for cyber criminals?

a)

They are used to store public data

b)

They have elevated access to systems and devices

c)

They have default passwords

d)

They are rarely monitored

90.

Which of the following is a best practice for privileged accounts?

a)

Use shared passwords indefinitely

b)

Grant all users full access

c)

Enforce least privilege and rotate passwords regularly

d)

Disable logging for administrative sessions

91.

Where are account policies automatically applied in a Windows domain?

a)

Local Security Policy

b)

Group Policy on Windows Server

c)

Task Scheduler

d)

Windows Firewall

92.

How often must a user change their password if the policy requires a 90-day rotation?

a)

Every 30 days

b)

Every 60 days

c)

Every 90 days

d)

Every 120 days

93.

What happens if a user enters the wrong password too many times according to account lockout policy?

a)

Account is deleted

b)

Account locks for a configured duration

c)

Password resets automatically

d)

User is granted guest access

94.

What is the purpose of audit logs?

a)

To monitor hardware temperature

b)

To track security events and user activity

c)

To manage power supply

d)

To encrypt passwords

95.

Which of the following is a type of system log?

a)

DHCP log

b)

Operating System log

c)

VLAN log

d)

MAC address log

96.

Which of the following are types of power loss events?

a)

Spike and surge

b)

Fault and blackout

c)

Sag and brownout

d)

Inrush and overload

97.

What device allows a graceful shutdown during power failure?

a)

Firewall

b)

UPS (Uninterruptible Power Supply)

c)

Router

d)

Switch

98.

Why are HVAC systems important in IT facilities?

a)

They provide internet access

b)

They control temperature, humidity, airflow, and air filtering

c)

They manage network protocols

d)

They encrypt sensitive data

99.

One security risk of smart HVAC systems is:

a)

Overheating servers

b)

Unauthorized access by contractors

c)

Power spikes

d)

Packet loss

100.

What is the purpose of hardware monitoring in server farms?

a)

To increase network speed

b)

To monitor CPU, memory, disk, fan, power, and network status

c)

To manage VLANs

d)

To configure firewalls

101.

What is the main difference between a NOC and SOC?

a)

NOC monitors cybersecurity; SOC monitors network performance

b)

NOC monitors network performance; SOC monitors cybersecurity incidents

c)

NOC is physical; SOC is cloud-based

d)

NOC handles hardware; SOC handles software

102.

What is a Red Team exercise?

a)

A firewall configuration process

b)

A simulated cyberattack to test defenses

c)

A DHCP server check

d)

VLAN segmentation

103.

What is port security on a switch used for?

a)

To increase bandwidth

b)

To restrict access to authorized MAC addresses

c)

To encrypt traffic

d)

To assign IP addresses

104.

What is the primary function of VLANs?

a)

To increase network speed

b)

To segment networks logically and protect sensitive data

c)

To assign IP addresses

d)

To filter traffic by protocol

105.

Name one threat to firewalls.

a)

VLAN attacks

b)

Theft, hacking, or attacks on ACLs

c)

DHCP failure

d)

IP address exhaustion

106.

Why change default passwords on network devices?

a)

To improve network speed

b)

To prevent unauthorized access

c)

To reduce electricity consumption

d)

To enable VLANs

107.

Which wireless standard provides the strongest encryption?

a)

WEP

b)

WPA

c)

IEEE 802.11i / WPA2

d)

Open system authentication

108.

Which authentication method allows any device to connect to a wireless network?

a)

WEP

b)

Open system authentication

c)

WPA2

d)

TKIP

109.

True or False: WEP is secure because its encryption key changes for every packet.

a)

True

b)

False

110.

What tool can check for open ports on a device?

a)

Firewall

b)

Port scanner

c)

VLAN

d)

DHCP server

111.

Which protocol automatically assigns IP addresses to devices?

a)

DNS

b)

DHCP

c)

NTP

d)

RIP

112.

Which protocol translates domain names to IP addresses?

a)

DHCP

b)

NTP

c)

DNS

d)

RIP

113.

Why is NTP important for network security?

a)

Encrypts DNS traffic

b)

Synchronizes clocks for logs, digital certificates, and event tracking

c)

Limits network hops

d)

Assigns IP addresses

114.

How many hops does RIP allow at maximum?

a)

10

b)

12

c)

15

d)

20

115.

What does the CIA triad in cybersecurity stand for?

a)

Control, Information, Access

b)

Confidentiality, Integrity, Availability

c)

Cybersecurity, Infrastructure, Access

d)

Confidentiality, Intelligence, Access

116.

Why has increased connectivity led to higher cybersecurity risks?

a)

Devices are cheaper

b)

Users work from home

c)

More devices interconnected increases exposure to theft, fraud, and abuse

d)

Organizations have more servers

117.

Which of the following is NOT a cybersecurity specialist role?

a)

Penetration tester

b)

Security analyst

c)

Network security professional

d)

Graphic designer

118.

Why is understanding cyber law and ethics important for cybersecurity specialists?

a)

To develop software

b)

To guide ethical decisions and ensure compliance

c)

To manage databases

d)

To prevent hardware failures

119.

Why are users often considered the weakest link in cybersecurity?

a)

They have administrative access

b)

Poor user practices can undermine technical controls

c)

They know the network architecture

d)

They always follow policies

120.

Which of the following is a common user-related threat?

a)

Firewall misconfiguration

b)

Data theft

c)

Router vulnerability

d)

Network congestion

121.

Which is a countermeasure to manage user threats?

a)

Enable remote desktop

b)

Security awareness training

c)

Disable antivirus

d)

Increase bandwidth

122.

Which of the following is considered a device in the Device Domain?

a)

Router only

b)

Desktop, laptop, tablet, smartphone

c)

Firewall only

d)

Cloud storage only

123.

A common threat to devices is:

a)

Employee turnover

b)

Malware infection via unauthorized downloads

c)

Compliance violation

d)

Poor website design

124.

Which is a way to protect devices?

a)

Enable screen lockout and passwords

b)

Use outdated software

c)

Share admin credentials

d)

Disable antivirus

125.

What is the LAN Domain?

a)

A collection of cloud services

b)

A network of interconnected devices within an organization

c)

A type of software

d)

A security protocol

126.

Which is a threat to LAN?

a)

Employee training

b)

Network OS vulnerabilities

c)

Disaster recovery plan

d)

Business continuity plan

127.

Which is a countermeasure for LAN threats?

a)

Encrypt wireless networks

b)

Install unauthorized apps

c)

Disable firewalls

d)

Share passwords

128.

What defines the Private Cloud Domain?

a)

Servers accessible to the public

b)

Private servers accessible only to organization members

c)

Cloud services hosted externally

d)

Public Wi-Fi networks

129.

Which is a threat to the Private Cloud?

a)

Unauthorized access

b)

Open-source software

c)

Screen lockout

d)

Antivirus scanning

130.

Which countermeasure helps manage Private Cloud threats?

a)

Intrusion detection and prevention systems (IDS/IPS)

b)

Leaving ports open

c)

Sharing credentials

d)

Disabling monitoring

131.

Which is NOT a cloud service model?

a)

SaaS

b)

PaaS

c)

IaaS

d)

NAS

132.

Which is a threat to the public cloud?

a)

Account hijacking

b)

Antivirus scanning

c)

Password rotation

d)

Hardware updates

133.

Which countermeasure helps secure the public cloud?

a)

Multifactor authentication

b)

Sharing access credentials

134.

Physical Facilities Domain: Which is a threat to physical facilities?

a)

Unauthorized access

b)

Firewall misconfiguration

c)

Malware infection

d)

Software patching

135.

Physical Facilities Domain: Which is a countermeasure for physical facilities?

a)

CCTV and access control

b)

Open network access

c)

Public Wi-Fi sharing

d)

Ignoring visitors

136.

Application Domain: A common threat to applications is:

a)

Unauthorized access to critical systems

b)

Password expiration

c)

Security awareness training

d)

Data backups

137.

Application Domain: Which is a measure to manage application threats?

a)

Software testing before launch

b)

Leaving servers unpatched

c)

Sharing admin credentials

d)

Disabling logging

138.

Miscellaneous: Why is monitoring user behavior important?

a)

To detect abnormal or risky activity

b)

To save electricity

c)

To improve graphics

d)

To share passwords

139.

Miscellaneous: Why is patching and updating software essential?

a)

It fixes vulnerabilities and reduces exploitation risk

b)

It slows down the system

c)

It reduces network speed

d)

It increases storage usage