wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

SAQ practice

Total questions: 150

Worksheet time: 1hrs 18mins

Name
Class
Date
1.

Introduction & Hacker Culture: What was the original meaning of the term “hacker”?

(a)  

2.

Introduction & Hacker Culture: Why is early hacker culture associated with fantasy imagery?

(a)  

3.

Introduction & Hacker Culture: How does Sun Tzu’s philosophy apply to cybersecurity?

(a)  

4.

Cybersecurity Domains: What is a cybersecurity “domain”?

(a)  

5.

Cybersecurity Domains: Which of the following are data‑rich cyber domains?

(a)  

6.

Growth of the Cyber World: What is the main cybersecurity challenge created by IoT devices?

(a)  

7.

Growth of the Cyber World: What does GIS technology allow organizations to do?

a)

Encrypt all emails by default

b)

Map and track environmental and geographical data in real time

c)

Block unauthorized access to mobile apps

d)

Simulate malware outbreaks

8.

Types of Cyber Criminals: Who are “script kiddies”?

a)

Highly trained penetration testers

b)

Low‑skilled attackers who use pre‑made tools or scripts

c)

Senior system administrators

d)

Ethical hackers with certifications

9.

Types of Cyber Criminals: What is the key difference between white‑hat and black‑hat hackers?

a)

White‑hat hackers only use open‑source tools

b)

White‑hat hackers have authorization; black‑hat hackers do not and act illegally

c)

Black‑hat hackers never target networks

d)

White‑hat hackers work remotely while black‑hat hackers work on‑site

10.

Types of Cyber Criminals: What motivates hacktivists?

a)

Quarterly sales goals

b)

Political or social causes

c)

Personal curiosity only

d)

Compliance audits

11.

Cyber Criminal Motivations: Today, what is the primary motivator for most cybercrimes?

a)

Entertainment

b)

Financial gain

c)

Academic research

d)

Reputation among peers only

12.

Cyber Criminal Motivations: Why is stolen medical data valuable to attackers?

a)

It is easy to delete without detection

b)

It contains long‑lasting, sensitive information that can be used for fraud or blackmail

c)

It is always encrypted and useless

d)

Hospitals pay attackers to store records

13.

Becoming a Cybersecurity Specialist: Why is cybersecurity considered a high‑demand field?

a)

There is a global shortage of skilled professionals and increasing digital threats

b)

Most jobs require only entry‑level skills

c)

Cybersecurity work is seasonal

d)

Digital threats are declining

14.

Defense Strategies: What is the purpose of a honeypot?

a)

To store backups securely

b)

To attract attackers and gather intelligence on attack methods

c)

To block all external traffic

d)

To accelerate software development

15.

Defense Strategies: What international standard helps organizations manage cybersecurity?

a)

PCI DSS

b)

ISO 27000 series

c)

IEEE 802.11

d)

HTML5

16.

Threats & Vulnerabilities: Define “threat” in cybersecurity.

a)

A patch that fixes a bug

b)

A potential cause of an unwanted incident, such as an attack

c)

A scheduled maintenance window

d)

A secure communication channel

17.

Threats & Vulnerabilities: Define “vulnerability”.

a)

A security training program

b)

A weakness that can be exploited by a threat actor

c)

A type of antivirus software

d)

A legislative requirement

18.

Personal Data Risks: Give one example each of sensitive data from education, employment, and finance.

a)

Education: grades; Employment: performance evaluations; Finance: bank statements

b)

Education: class schedules; Employment: office layout; Finance: cafeteria menu

c)

Education: campus map; Employment: parking passes; Finance: ATM locations

d)

Education: event flyers; Employment: holiday calendar; Finance: billboard ads

19.

Internet Service Threats: What is DNS spoofing?

a)

Blocking domain names to reduce traffic

b)

Manipulating DNS data to redirect users to malicious sites

c)

Encrypting DNS queries to improve privacy

d)

Creating new top‑level domains

20.

Internet Service Threats: What is packet sniffing used for?

a)

Capturing data packets to steal information such as passwords

b)

Repairing damaged network cables

c)

Generating encryption keys

d)

Allocating IP addresses automatically

21.

Industrial & SCADA Threats: Why are SCADA systems vulnerable to cyberattacks?

a)

They run only on battery power

b)

They were originally designed without cybersecurity in mind and are now connected to IT networks

c)

They use overly complex passwords

d)

They do not control physical processes

22.

Industrial & SCADA Threats: Name a famous cyberattack involving SCADA systems.

a)

WannaCry

b)

Stuxnet

c)

Heartbleed

d)

Conficker

23.

Cybersecurity & Society: What is one challenge governments face in cybersecurity?

a)

Balancing national security needs with citizen privacy rights

b)

Eliminating all malware worldwide

c)

Funding only private companies

d)

Restricting internet access to universities

24.

Internal vs External Threats: Why are internal threats often more dangerous than external threats?

a)

Insiders already have legitimate access to systems and data

b)

External attackers have more resources

c)

Insiders cannot be monitored

d)

External threats never use social engineering

25.

Internal vs External Threats: Give one example of how an internal user can unintentionally cause a breach.

a)

Plugging in an infected USB device

b)

Using a company‑approved password manager

c)

Reading the employee handbook

d)

Attending security awareness training

26.

Mobile & BYOD Risks: Why does BYOD increase security risk?

a)

Organizations have less control over security updates and configurations on personal devices

b)

BYOD guarantees devices are more secure

c)

It limits network connectivity

d)

It eliminates the need for authentication

27.

IoT & Big Data Challenges: What are the “3Vs” of Big Data?

a)

Volume, Velocity, Variety

b)

Vision, Value, Validity

c)

Virtualization, Versioning, Verification

d)

Vulnerability, Visibility, Variance

28.

IoT & Big Data Challenges: Why is Big Data attractive to cybercriminals?

a)

It contains massive amounts of valuable and sensitive information

b)

It is too small to analyze

c)

It is stored only on paper

d)

It never includes personal records

29.

Advanced Cyber Weapons: What is an Advanced Persistent Threat (APT)?

a)

A single short‑term malware infection

b)

A long‑term, stealthy attack where intruders gain continuous access

c)

A hardware malfunction

d)

A network backup process

30.

Advanced Cyber Weapons: What is a selective attack?

a)

An attack that activates only when specific target criteria are met

b)

An attack that randomly targets any device

c)

An attack limited to wireless networks

d)

An attack that only uses phishing emails

31.

Identity & Access: What is a major risk of federated identity systems?

a)

Users must remember more passwords

b)

A compromise of the identity provider can grant widespread access across multiple services

c)

It prevents single sign‑on

d)

It makes auditing impossible

32.

What is the main purpose of the Cybersecurity Cube?

a)

To provide a framework for applying cybersecurity principles across systems and networks

b)

To replace all existing cybersecurity tools with a single platform

c)

To measure network speed and latency

d)

To create backup copies of organizational data

33.

Who developed the Cybersecurity Cube?

a)

John McCumber

b)

Bruce Schneier

c)

Whitfield Diffie

d)

Ron Rivest

34.

Which set lists the three dimensions of the Cybersecurity Cube?

a)

CIA Triad; States of Data; Security Safeguards

b)

Confidentiality; Privacy; Availability

c)

Hardware; Software; People

d)

Threats; Vulnerabilities; Risks

35.

What is confidentiality?

a)

Protection of data from unauthorized access

b)

Ability of a system to remain accessible during failures

c)

Verification that data has not been altered

d)

Tracking and recording user actions

36.

Which method is commonly used to ensure confidentiality?

a)

Encryption

b)

Packet sniffing

c)

Load balancing

d)

Data deduplication

37.

Which are the three types of sensitive information?

a)

Personal, business, classified

b)

Public, archived, compressed

c)

Static, dynamic, streaming

d)

Numeric, textual, graphical

38.

What does authentication verify?

a)

A user's identity

b)

Network uptime

c)

File ownership rights

d)

Data compression ratio

39.

Which is an example of authentication evidence?

a)

Password

b)

Clear-text email

c)

Public Wi‑Fi hotspot

d)

Unencrypted USB drive

40.

What does authorization determine?

a)

What a user is allowed to do on a system

b)

Whether a user is online

c)

How fast a network transmits data

d)

How data is compressed

41.

In the AAA model, what is the purpose of accounting?

a)

To track and record user activity

b)

To encrypt stored passwords

c)

To block malicious traffic

d)

To validate network routes

42.

Which statement best distinguishes confidentiality from privacy?

a)

Confidentiality is the duty to protect data; privacy is the correct use of personal data

b)

Confidentiality is about uptime; privacy is about backups

c)

Confidentiality is user training; privacy is access control

d)

Confidentiality is encryption; privacy is hashing

43.

What does integrity ensure?

a)

That data is accurate, complete, and not tampered with

b)

That data is available to all users at all times

c)

That data is stored redundantly

d)

That data is compressed efficiently

44.

What is hashing used for?

a)

Verifying data integrity by creating a digital fingerprint

b)

Encrypting data so only authorized users can read it

c)

Compressing files to reduce size

d)

Balancing traffic across multiple servers

45.

Which is an example of a hashing algorithm?

a)

SHA-256

b)

AES-256

c)

RSA-2048

d)

TLS 1.3

46.

What is availability?

a)

Ensuring that data and services are accessible to authorized users when needed

b)

Ensuring data remains confidential from unauthorized users

c)

Ensuring data is accurate and unaltered

d)

Ensuring traffic is encrypted end-to-end

47.

What does “Five Nines” uptime represent?

a)

99.999%99.999\% availability

b)

99.9%99.9\% availability

c)

95%95\% availability

d)

90%90\% availability

48.

Which list correctly names the three states of data?

a)

Data at rest, data in transit, data in process

b)

Structured data, semi-structured data, unstructured data

c)

Hot data, warm data, cold data

d)

Primary data, secondary data, tertiary data

49.

What is data at rest?

a)

Stored data on devices or servers

b)

Data currently being transmitted over a network

c)

Data being computed by applications

d)

Data cached in memory only

50.

Which is a challenge associated with data at rest?

a)

Vulnerable endpoints

b)

Packet sniffing

c)

Weak routing protocols

d)

Excessive bandwidth

51.

What is data in transit?

a)

Data being moved across a network or between devices

b)

Data stored on backup tapes

c)

Data processed by an application

d)

Data archived for long-term retention

52.

Which is a major threat to data in transit?

a)

Eavesdropping or packet sniffing

b)

Disk fragmentation

c)

Power over Ethernet failure

d)

Excessive logging

53.

Which security measure protects data in transit?

a)

Encryption (e.g., VPN)

b)

Defragmentation

c)

Load shedding

d)

Open mail relay

54.

What is data in process?

a)

Data being input, computed, or output by applications

b)

Data archived for compliance

c)

Data stored only on removable media

d)

Data queued for printing

55.

Which is a threat to data in process?

a)

Malicious code

b)

Cable attenuation

c)

Dust accumulation

d)

Low screen resolution

56.

Which are the three main categories of cybersecurity safeguards?

a)

Technology, cloud, and human safeguards

b)

Physical, chemical, and biological safeguards

c)

Hardware, software, and firmware safeguards

d)

Policies, audits, and fines

57.

Which is an example of a technology safeguard?

a)

Firewall

b)

Spreadsheet template

c)

Inkjet printer

d)

Public bulletin board

58.

What is SaaS?

a)

Software as a Service—applications hosted by cloud providers

b)

Security as a Standard—government cybersecurity rules

c)

Storage as a System—on‑premises tape libraries

d)

Service and Support—help desk procedures

59.

What is the purpose of cybersecurity training?

a)

To educate users on safe practices and reduce human-related risks

b)

To increase network bandwidth

c)

To eliminate all software vulnerabilities

d)

To enforce legal penalties on attackers

60.

What is an Acceptable Use Policy (AUP)?

a)

A policy defining appropriate and inappropriate use of company systems and networks

b)

A policy that sets hardware warranty terms

c)

A policy that lists public holidays for staff

d)

A policy for printer ink management

61.

What is the purpose of standards in cybersecurity?

a)

To ensure consistency by defining specific rules and configurations

b)

To reduce the need for backups

c)

To prevent any user errors from occurring

d)

To guarantee 100%100\% system uptime

62.

What is the main difference between a virus and a worm?

a)

A virus requires user action to spread; a worm self‑propagates without user action

b)

A virus only targets servers; a worm only targets desktops

c)

A virus is always benign; a worm is always malicious

d)

A virus encrypts data; a worm compresses data

63.

What is the difference between a virus and a worm?

a)

A virus self-replicates without user action, while a worm needs user interaction to spread

b)

A virus requires user action to spread, while a worm self-replicates and spreads automatically

c)

A virus only infects mobile devices, while a worm only targets servers

d)

A virus is harmless, while a worm always encrypts files

64.

Why are Trojans considered dangerous?

a)

They openly announce themselves to users to request permission

b)

They disguise themselves as legitimate software and exploit user privileges to install malware or create backdoors

c)

They only slow down internet speed temporarily

d)

They are limited to sending spam emails

65.

What is the purpose of ransomware?

a)

To monitor user browsing habits

b)

To encrypt or lock a user’s data and demand payment for its release

c)

To improve system performance

d)

To provide remote technical support

66.

How does a rootkit help an attacker?

a)

It optimizes the operating system for faster performance

b)

It hides the attacker’s presence by modifying the operating system, allowing ongoing privileged access without detection

c)

It automatically updates all security patches

d)

It blocks all outbound network traffic

67.

What is spear phishing?

a)

A broad phishing campaign sent to random recipients

b)

A highly targeted phishing attack aimed at specific individuals or organizations

c)

A method of encrypting emails for security

d)

A hardware-based attack on network switches

68.

What is vishing?

a)

Phishing conducted through voice calls or VoIP to trick victims into revealing information

b)

Phishing conducted only via email

c)

Malware that infects video files

d)

A vulnerability in virtual machines

69.

What type of attack involves redirecting a user to a fake website?

a)

Smishing

b)

Pharming

c)

Keylogging

d)

Drive-by download

70.

How is a DoS attack different from a DDoS attack?

a)

A DoS attack uses multiple compromised systems, while a DDoS uses one source

b)

A DoS attack comes from one source, while a DDoS attack originates from multiple compromised systems

c)

A DoS is legal, while a DDoS is illegal

d)

A DoS only affects mobile networks, while a DDoS only affects wired networks

71.

What is a man-in-the-middle attack?

a)

An attack where malware deletes files on a local system

b)

An attack where an unauthorized party intercepts and possibly alters communication between two legitimate parties

c)

An attack that only targets wireless routers by flooding them with traffic

d)

An attack that replaces a user’s keyboard with a malicious device

72.

What is an evil twin?

a)

A legitimate access point with enhanced security

b)

A fake wireless access point set up to mimic a legitimate AP and lure users into connecting

c)

A peer-to-peer connection used for file sharing

d)

A backup device used to improve network redundancy

73.

Name one way to detect or prevent ARP spoofing.

a)

Use static ARP entries

b)

Enable dynamic ARP inspection on network devices

c)

Disable HTTPS in browsers

d)

Switch to WEP encryption on Wi‑Fi

74.

What is a replay attack?

a)

An attack where captured messages are retransmitted to impersonate a user or bypass authentication

b)

An attack that replaces software libraries with malicious versions

c)

An attack that brute-forces passwords using dictionary lists

d)

An attack that scans open ports on a server

75.

What is the function of a backdoor?

a)

It encrypts all user data automatically

b)

It provides attackers unauthorized remote access to a system after initial compromise

c)

It blocks malicious IP addresses by default

d)

It updates antivirus signatures

76.

What makes zero-day attacks particularly dangerous?

a)

They only use outdated malware that is easily detected

b)

They exploit unknown vulnerabilities for which no patches or fixes exist yet

c)

They require physical access to the device

d)

They are limited to social media platforms

77.

What is a rogue access point?

a)

An authorized access point installed by the network team

b)

An unauthorized wireless access point installed without approval, often used for attacks

c)

A device that only provides guest Wi‑Fi

d)

A hardware firewall connected to the router

78.

How can shoulder surfing be prevented?

a)

By shielding screens

b)

By using privacy filters

c)

By being aware of surroundings when entering sensitive information

d)

By sharing passwords with trusted colleagues

79.

What is grayware?

a)

Software that is clearly malicious and encrypts files

b)

Software that is annoying or undesirable and may gather data, but is not clearly malicious

c)

Software that is guaranteed safe and vetted by government agencies

d)

Hardware drivers required for operating system updates

80.

What is the goal of SEO poisoning?

a)

To improve legitimate search rankings for educational websites

b)

To manipulate search engine results to direct users to malicious websites

c)

To block all pop-up advertisements by default

d)

To encrypt search queries for privacy

81.

Why is SMiShing effective?

a)

Because users often trust SMS messages more and tend to click links without verifying the sender

b)

Because SMS messages are always scanned by antivirus software

c)

Because SMS links are blocked by all mobile carriers

d)

Because SMS is only used for internal corporate communication

82.

What is a browser hijacker?

a)

A legitimate browser update that improves performance

b)

Malware that modifies browser settings to redirect users to unsafe or advertising-heavy websites

c)

A plug‑in that removes cookies for privacy

d)

A tool used by administrators to enforce security policies

83.

What is the main goal of cryptography?

a)

To compress data for faster transmission

b)

To protect information by ensuring confidentiality, integrity, authentication, and non‑repudiation

c)

To increase computer graphics performance

d)

To replace passwords with biometrics

84.

What is plaintext?

a)

Encrypted data that is unreadable without a decryption key

b)

The original readable message before encryption

c)

A random key generated during hashing

d)

A message stored only in binary form

85.

What is ciphertext?

a)

Encrypted data that is unreadable without a decryption key

b)

The original readable message before encryption

c)

A public key used to verify signatures

d)

A checksum appended to network packets

86.

What is the difference between cryptography and cryptanalysis?

a)

Cryptography creates secure codes; cryptanalysis attempts to break or defeat them

b)

Cryptography stores passwords; cryptanalysis transmits messages

c)

Cryptography hides images; cryptanalysis compresses files

d)

Cryptography speeds networks; cryptanalysis slows them

87.

Name two historical encryption methods.

a)

Scytale

b)

Caesar Cipher

c)

Vigenère Cipher

d)

Enigma

e)

SHA-256

88.

What is the main weakness of symmetric encryption?

a)

Key distribution — both sender and receiver must share the same secret key

b)

It cannot encrypt large files

c)

It never supports authentication

d)

It requires internet access

89.

What kind of key does asymmetric encryption use for encryption?

a)

The receiver’s public key

b)

The sender’s private key

c)

A shared session key

d)

A one-time pad

90.

What kind of key does asymmetric encryption use for decryption?

a)

The receiver’s private key

b)

The sender’s public key

c)

A symmetric key

d)

A hash value

91.

Why is asymmetric encryption slower than symmetric encryption?

a)

It uses complex mathematical operations and larger key sizes

b)

It transmits data over longer distances

c)

It requires multiple recipients

d)

It relies on physical tokens

92.

Give one example of a symmetric encryption algorithm.

a)

AES

b)

RSA

c)

Diffie–Hellman

d)

ECC

93.

Give one example of an asymmetric encryption algorithm.

a)

RSA

b)

AES

c)

DES

d)

Blowfish

94.

What is the purpose of hybrid cryptography?

a)

To combine asymmetric encryption for secure key exchange with symmetric encryption for fast data transfer

b)

To replace all symmetric ciphers with hashes

c)

To hide messages inside images

d)

To increase compression efficiency

95.

What is steganography?

a)

Hiding secret data inside other data such as an image, audio, or video file

b)

Converting plaintext to ciphertext with a key

c)

Detecting malicious network traffic

d)

Erasing metadata from files

96.

What does a block cipher do?

a)

Encrypts data in fixed-sized blocks

b)

Encrypts only headers of files

c)

Encrypts data one bit at a time

d)

Compresses data before encryption

97.

What does a stream cipher do?

a)

Encrypts data one bit or byte at a time

b)

Encrypts in fixed-size blocks

c)

Stores keys on hardware tokens

d)

Hashes messages for integrity

98.

What are the four steps of access control?

a)

Identification

b)

Authentication

c)

Authorization

d)

Accountability

e)

Confidentiality

99.

Give one example of something you “are” used for authentication.

a)

Biometrics like fingerprints, iris scan, or facial recognition

b)

Passwords remembered by the user

c)

Hardware tokens carried by the user

d)

Security questions answered by the user

100.

What type of access control is used in government or military (Secret/Top Secret labels)?

a)

Mandatory Access Control (MAC)

b)

Discretionary Access Control (DAC)

c)

Role-Based Access Control (RBAC)

d)

Attribute-Based Access Control (ABAC)

101.

What access control model assigns permissions based on job roles?

a)

Role-Based Access Control (RBAC)

b)

Mandatory Access Control (MAC)

c)

Discretionary Access Control (DAC)

d)

Lattice-Based Access Control

102.

What is a common disadvantage of Discretionary Access Control (DAC)?

a)

It is less secure because users can share or change permissions too freely

b)

It never allows file sharing

c)

It requires custom hardware

d)

It cannot be implemented on operating systems

103.

Give one example of a physical access control.

a)

Locks

b)

Passwords

c)

Encryption

d)

Firewall rules

104.

Give one example of a logical access control.

a)

Passwords

b)

Locks

c)

CCTV

d)

Mantraps

105.

Which encryption standard is commonly used for secure web browsing (HTTPS)?

a)

RSA (for key exchange)

b)

AES (for data encryption)

c)

MD5 (for hashing only)

d)

DES (legacy)

106.

What is the purpose of an Access Control List (ACL)?

a)

To define rules that specify which users or devices can access certain resources

b)

To encrypt files using symmetric keys

c)

To compress and archive logs

d)

To assign IP addresses on a network

107.

Why is AES preferred over DES today?

a)

AES uses stronger keys and is more secure than the outdated DES

b)

AES is older and easier to implement

c)

AES avoids using any substitution boxes

d)

AES requires no hardware acceleration

108.

What is data masking?

a)

Replacing sensitive data with a non-sensitive but realistic substitute to protect information

b)

Encrypting data using a public key

c)

Deleting sensitive data permanently

d)

Storing sensitive data in a separate database

109.

Name two reasons why organizations use data masking.

a)

To reduce exposure of sensitive data

b)

To protect data in development and testing environments

c)

To increase network bandwidth

d)

To comply with password reuse policies

110.

List any two data masking techniques.

a)

Substitution

b)

Shuffling

c)

Nulling-out

d)

Mirroring

e)

Watermarking

111.

What is the main purpose of steganography?

a)

To hide the existence of a secret message inside another file

b)

To verify message integrity with hashes

c)

To scramble data for compression

d)

To assign user permissions

112.

What is a stego object?

a)

The output file after embedding hidden data

b)

The unmodified cover file used for hiding

c)

The cryptographic key used for encryption

d)

The detector used to find hidden data

113.

How many bits can typically be hidden in a single RGB pixel using LSB techniques?

a)

Three bits (one per color channel)

b)

One bit total

c)

Six bits (two per channel)

d)

Eight bits total

114.

What is steganalysis?

a)

The process of detecting hidden information inside a file

b)

The process of encrypting a message with a key

c)

The process of masking sensitive fields in a database

d)

The process of compressing images for storage

115.

Give one example of social steganography.

a)

Posting a normal-looking status that secretly signals a meaning to a friend

b)

Using a VPN to encrypt all internet traffic

c)

Compressing files to reduce their size

d)

Sharing a public encryption key on a website

116.

Define cryptography.

a)

The science of encoding and decoding information to ensure confidentiality, integrity, and authentication

b)

The process of compressing data to save storage space

c)

The practice of hiding messages only through imagery

d)

A method of backing up files to protect against loss

117.

What is the difference between plaintext and ciphertext?

a)

Plaintext is readable data; ciphertext is encrypted data

b)

Plaintext is compressed data; ciphertext is expanded data

c)

Plaintext uses a private key; ciphertext uses a public key

d)

Plaintext is binary; ciphertext is hexadecimal

118.

What is a cipher?

a)

An algorithm used to encrypt and decrypt data

b)

A device for physically securing access

c)

A protocol for routing network packets

d)

A checksum used to verify file downloads

119.

Name two classical (historical) ciphers.

a)

Caesar Cipher and Vigenère Cipher

b)

AES and RSA

c)

Blowfish and Twofish

d)

SHA-256 and SHA-512

120.

What key characteristic defines symmetric encryption?

a)

The same key is used for both encryption and decryption

b)

It always uses public and private key pairs

c)

It only encrypts fixed-size blocks

d)

It cannot be implemented in software

121.

Name one symmetric encryption algorithm.

a)

AES

b)

RSA

c)

ECC

d)

ElGamal

122.

Give one disadvantage of symmetric encryption.

a)

Key distribution is difficult because both parties need the same shared key

b)

It cannot encrypt large files

c)

It requires expensive hardware to run

d)

It never achieves confidentiality

123.

What is asymmetric encryption?

a)

A method using two different keys—one public to encrypt and one private to decrypt

b)

A technique that uses a single shared key for both encryption and decryption

c)

A compression method that reduces redundancy

d)

A hashing approach that produces a fixed-length digest

124.

Name one asymmetric encryption algorithm.

a)

RSA

b)

AES

c)

DES

d)

Blowfish

125.

State one advantage of asymmetric encryption.

a)

It allows secure communication without having to share secret keys beforehand

b)

It guarantees zero latency in data transfer

c)

It prevents all forms of data tampering automatically

d)

It requires no computational resources

126.

Why do systems combine symmetric and asymmetric encryption?

a)

To get the speed of symmetric encryption and the secure key exchange of asymmetric encryption

b)

To avoid using any keys at all

c)

To make data readable during transit

d)

To eliminate authentication requirements

127.

What is a block cipher?

a)

A cipher that encrypts fixed-sized blocks of data

b)

A cipher that encrypts one bit at a time

c)

A method of hashing passwords

d)

A protocol for establishing VPN tunnels

128.

What is a stream cipher?

a)

A cipher that encrypts data one bit or one byte at a time

b)

A cipher that encrypts fixed-sized blocks of data

c)

A compression algorithm

d)

A key exchange protocol

129.

What does a VPN do?

a)

It creates an encrypted tunnel over the internet to protect data and hide the user’s IP address

b)

It converts plaintext to ciphertext using public keys

c)

It prevents files from being deleted

d)

It scans systems for malware automatically

130.

Give one common use of a VPN.

a)

Secure browsing on public Wi‑Fi

b)

Defragmenting a hard drive

c)

Compressing multimedia files

d)

Installing operating system updates

131.

List the three categories of access controls.

a)

Physical, Logical, Administrative

b)

Mandatory, Discretionary, Role-Based

c)

Preventive, Detective, Corrective

d)

Public, Private, Hybrid

132.

Give one example of a physical access control.

a)

Locked doors

b)

Password policies

c)

Role assignments in an application

d)

Firewall rules

133.

What is logical access control?

a)

Digital mechanisms that control access, such as passwords or biometrics

b)

Physical barriers like fences

c)

Organizational policies and procedures

d)

Backup schedules for servers

134.

Give an example of administrative access control.

a)

Security policies, procedures, or background checks

b)

Biometric fingerprint scanners

c)

Smart locks on doors

d)

Encryption of hard drives

135.

What is Mandatory Access Control (MAC)?

a)

A strict model where the system, not the user, controls access rights

b)

A model where users assign permissions freely

c)

A role-centric model that groups users by job function

d)

A decentralized approach with no central authority

136.

Which access control model assigns permissions based on job roles?

a)

Role-Based Access Control (RBAC)

b)

Mandatory Access Control (MAC)

c)

Discretionary Access Control (DAC)

d)

Attribute-Based Access Control (ABAC)

137.

Provide one example of rule-based access control.

a)

Allowing access only during office hours or from specific IP addresses

b)

Letting users decide permissions for their own files

c)

Granting access solely by physical badge scans

d)

Encrypting data with a symmetric key

138.

What does data integrity ensure?

a)

That data remains accurate, unchanged, and trustworthy

b)

That data is always encrypted with AES

c)

That data is stored only in the cloud

d)

That data loads faster on networks

139.

Name two methods used to ensure data integrity.

a)

Hashing and digital signatures

b)

Compression and deduplication

c)

VPN tunneling and network address translation

d)

Symmetric encryption and RAID mirroring

140.

What is hashing?

a)

A one-way function that converts data into a fixed-length value called a hash or digest

b)

A reversible encryption method

c)

A protocol for assigning IP addresses

d)

A data compression technique

141.

Why is hashing considered one-way?

a)

Because it cannot be reversed to recover the original data

b)

Because it only works on text files

c)

Because it requires a pair of keys

d)

Because it always produces different outputs

142.

What is a collision in hashing?

a)

When two different inputs produce the same hash value

b)

When the same input yields different output lengths

c)

When a hash matches its original plaintext

d)

When hashing fails due to insufficient memory

143.

Give an example of a hashing algorithm still considered secure.

a)

SHA‑256

b)

MD5

c)

DES

d)

RC4

144.

Why is MD5 no longer recommended for security use?

a)

It is vulnerable to collisions

b)

It cannot run on modern CPUs

c)

It uses too much memory

d)

It only produces very long hashes

145.

What is the purpose of hashing digital forensic images?

a)

To prove the copy is identical to the original (fixity verification)

b)

To encrypt the image for confidentiality

c)

To compress the image to save storage

d)

To remove sensitive information from the image

146.

Why do systems store password hashes instead of plaintext passwords?

a)

To prevent attackers who obtain the database from reading user passwords directly

b)

To ensure passwords are always the same length

c)

To allow users to share passwords safely

d)

To make login processes faster

147.

What happens when a user logs in to a system that uses hashing?

a)

The entered password is hashed and compared with the stored hash

b)

The entered password is encrypted and stored as plaintext

c)

The stored hash is decrypted to reveal the original password

d)

The system sends the password to the server without transformation

148.

What is a dictionary attack?

a)

An attack using a list of common passwords to find a matching hash

b)

An attack that tries all possible character combinations

c)

An attack that intercepts passwords during transmission

d)

An attack that modifies the hashing algorithm

149.

What is a brute-force attack?

a)

Trying all possible combinations until the correct hash is found

b)

Guessing passwords from a list of common phrases

c)

Phishing users to obtain their passwords

d)

Exploiting software vulnerabilities to bypass login

150.

What is a salt?

a)

A random string added to a password before hashing

b)

A secret key used to sign a message

c)

A checksum appended after encryption

d)

A token used to start a session