wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Week 4 Quiz CSF

Total questions: 90

Worksheet time: 50mins

Name
Class
Date
1.

Which principle is NOT part of the CIA triad?

a)

Confidentiality

b)

Integrity

c)

Accessibility

d)

Availability

2.

Malware designed to replicate itself across systems is called:

a)

Trojan

b)

Worm

c)

Spyware

d)

Adware

3.

Which malware disguises itself as legitimate software?

a)

Trojan

b)

Ransomware

c)

Worm

d)

Backdoor

4.

Spyware primarily aims to:

a)

Encrypt files

b)

Steal information

c)

Destroy systems

d)

Scan networks

5.

Adware usually:

a)

Steals banking info

b)

Displays unwanted ads

c)

Installs rootkits

d)

Encrypts data

6.

Ransomware attacks usually involve:

a)

Remote access

b)

Data encryption and payment demand

c)

Network sniffing

d)

Password brute forcing

7.

A hidden method to access a system without authorization is known as:

a)

Zero-day

b)

Backdoor

c)

Patch

d)

Signature

8.

A zero-day vulnerability refers to:

a)

A. A patched bug

b)

B. A known but unfixed bug

c)

C. An unknown vulnerability

d)

D. A malware component

9.

Stuxnet was mainly designed to target:

a)

Personal computers

b)

Nuclear centrifuges

c)

Banking systems

d)

Social media networks

10.

Outsourcing security operations may introduce:

a)

Reduced transparency

b)

No risks at all

c)

Guaranteed protection

d)

Cheaper vulnerabilities

11.

The Target data breach occurred due to compromised:

a)

Administrators

b)

HVAC vendor credentials

c)

Firewall misconfiguration

d)

CEO laptop malware

12.

PCI DSS applies to organizations handling:

a)

Healthcare data

b)

Payment card information

c)

Student records

d)

Government data only

13.

A vulnerability is best defined as:

a)

A threat actor

b)

A weakness in a system

c)

A successful attack

d)

A security policy

14.

Network segmentation helps reduce:

a)

Firewall efficiency

b)

Lateral movement

c)

Authentication time

d)

Password strength

15.

Privilege escalation involves:

a)

Reducing permissions

b)

Gaining higher permission levels

c)

Resetting access logs

d)

Removing administrator rights

16.

Nmap is mainly used for:

a)

Web development

b)

Network scanning

c)

File encryption

d)

Policy writing

17.

An exploit is:

a)

A security patch

b)

Code used to take advantage of a vulnerability

c)

A firewall rule

d)

A backup process

18.

NIST provides:

a)

Legal prosecution tools

b)

Cybersecurity frameworks and standards

c)

Hardware components

19.

ISO 27001 focuses on:

a)

Food safety

b)

Information security management

c)

Physical construction

d)

Financial auditing

20.

GDPR mainly protects:

a)

Payment card industry

b)

EU citizen personal data

c)

Government servers

d)

Police investigative data

21.

An access control policy defines:

a)

Server temperature levels

b)

Who gets access to what resources

c)

Customer billing cycles

d)

Marketing permissions

22.

An incident response policy outlines:

a)

Hiring procedures

b)

Steps to manage security incidents

c)

Website design rules

d)

Employee vacation days

23.

SIEM tools mainly provide:

a)

Software development

b)

Security event monitoring and correlation

c)

HR management

d)

Cloud migration

24.

A threat is:

a)

A. A missing patch

b)

B. A potential cause of an unwanted incident

c)

C. A firewall rule

d)

D. A backup schedule

25.

A risk assessment includes:

a)

Ignoring vulnerabilities

b)

Identifying and prioritizing risks

c)

Eliminating all threats immediately

d)

Only reviewing passwords

26.

Strong passwords must:

a)

Be reused

b)

Be predictable

c)

Be complex and unique

d)

Be short for convenience

27.

Describe Phishing

4 lines
28.

Social engineering via emails

a)

A. Phishing

b)

B. Texting

c)

C. Hardware theft

d)

D. Wireless jamming

29.

A DDoS attack aims to:

a)

Encrypt data

b)

Overload a system or network

c)

Scan open ports

d)

Modify logs

30.

Which is NOT a security control type?

a)

Administrative

b)

Technical

c)

Physical

d)

Imaginative

31.

A firewall works at which level of security?

a)

Administrative

b)

Network

c)

Policy

d)

Human resources

32.

Log analysis helps in:

a)

Cooking

b)

Identifying suspicious activities

c)

Increasing storage speed

d)

Deleting user accounts

33.

A backdoor may be created by:

a)

Attackers

b)

Developers

c)

System misconfigurations

d)

All of the above

34.

Least privilege means:

a)

Maximum access

b)

Minimum necessary access

c)

No password requirements

d)

Unlimited permissions

35.

A patch is intended to:

a)

Add malware

b)

Fix vulnerabilities

c)

Remove users

d)

Expand storage

36.

Encryption ensures:

a)

Speed

b)

Confidentiality

c)

Virus removal

d)

Open access

37.

A vulnerability scanner does:

a)

Active packet injection only

b)

Identifies system weaknesses

c)

Encrypts passwords

d)

Sends phishing emails

38.

An IDS detects:

a)

Network printers

b)

Potential intrusions

c)

Website themes

d)

Camera feeds

39.

Physical security involves:

a)

Locks and surveillance

b)

Password resets

c)

Patching systems

d)

Email filtering

40.

The principle of separation of duties helps prevent:

a)

Efficiency

b)

Single-person abuse of power

c)

Log generation

d)

Encryption

41.

A threat actor is:

a)

A vulnerability

b)

An individual or group causing attacks

c)

A firewall

d)

A risk response strategy

42.

RPO refers to:

a)

Recovery Point Objective

b)

Risk Prevention Order

c)

Remote Patch Operation

d)

Random Policy Outcome

43.

MFA improves security by:

a)

Reducing users

b)

Requiring multiple authentication factors

c)

Lowering encryption

d)

Increasing malware

44.

A policy is:

a)

A rule or guideline

b)

A vulnerability type

c)

A hardware component

d)

A patch update

45.

A zero-day exploit is used:

a)

After a patch is released

b)

Before vulnerability is discovered by the vendor

c)

For backups only

d)

For firewall rules

46.

Data minimization requires:

a)

Collecting as much data as possible

b)

Collecting only needed information

c)

Storing data forever

d)

Sharing data widely

47.

Insider threats come from:

a)

Hackers only

b)

Employees or trusted personnel

c)

Nation-states only

d)

Only external threats

48.

A playbook in incident response is:

a)

A novel

b)

A step-by-step guide for handling incidents

c)

A database server

d)

A policy exception

49.

Botnets are usually controlled by:

a)

Users

b)

Command-and-control servers

c)

Random IPs

d)

System patches

50.

Data integrity ensures data is:

a)

Deleted

b)

Unchanged and accurate

c)

Hidden

d)

Not encrypted

51.

GDPR fines can reach:

a)

$100

b)

Free warnings

c)

Up to 4% of global annual revenue

d)

No penalties

52.

What is the primary goal of a penetration test?

a)

To identify security weaknesses

b)

To monitor network traffic

c)

To fix vulnerabilities

d)

To install security patches

53.

Which of the following is a common method of social engineering?

a)

Firewalls

b)

Data masking

c)

Encryption

d)

Phishing

54.

What is the primary purpose of a firewall?

a)

To encrypt data

b)

To monitor network traffic

c)

To block unauthorized access

d)

To perform backups

55.

Which of the following is a common method for securing data in transit?

a)

Encryption

b)

Data masking

c)

Data archiving

d)

Data replication

56.

Which of the following is a phishing email??

a)

You have won a lottery!! Follow this link to claim it!!

b)

Your bank account has been compromised. Login here to protect yourself.

c)

Help.I am stuck aboard and urgently need money transferred to me to get home.

d)

All of the above. Be careful.

57.

Which of these is an indicator that the website is secure.

a)

Bruce Lee photo

b)

The http://

c)

The https://

d)

The https:\\

58.

What does DDOS stand for?

a)

Denial Data Operation System

b)

Domain Data Overwrite Service

c)

Distributed Domain Or Service

d)

Distributed Denial Of Service

59.

Strategic and tactical capability of the organization to plan for and respond to incidents and business disruptions in order to continue business operations at an acceptable predefined level

a)

Live Drill

b)

Business Continuity

c)

Risk Management

d)

Strategic Planning

60.

Which of these is a sign of malware on your computer?

a)

You receive a fraudulent email

b)

Your browser alerts you it has blocked a pop-up window

c)

Your homepage has changed unexpectedly

d)

Your browser alerts you to update to a newer version

61.

i am a security system that keeps track of filters and outgoing & incoming data through the network

(a)  

62.

Which of these is not a form of phishing?

a)

fake email

b)

fake website link

c)

spam

d)

key logger

63.

What is the primary function of a Security Operations Center (SOC)?

a)

monitor, detect, investigate, and respond to cybersecurity incidents in real-time.

b)

Monitor server performance

c)

Monitor transaction fraud

d)

Monitor network parameter

64.

What is the process of giving individual access to a system or resource?

a)

Auditing

b)

Authorization

c)

Accounting

d)

Authentication

65.

Kim has taken her A-Level exam and is waiting to get her results by email. By accident, Kim’s results are sent to Karen.

a)

C

b)

I

c)

A

d)

None of the above

66.

Mason, Rohan, and Maya are working in a cybersecurity firm. They are using a SIEM system. What would be the purpose of event correlation in their SIEM system?

a)

To help Mason, Rohan, and Maya decide if reported activity is normal or outside of the baseline

b)

To identify vulnerabilities in their system and recommend remediation steps

c)

To gather data from log files, system applications, network appliances, etc., and analyze it

d)

To send customized alerts to Mason, Rohan, and Maya if certain parameters are not within the acceptable range

67.

Is hashing different from encryption?

a)

Yes

b)

No

68.

What do you understand by one-way?

a)

Input can not be recovered from the output

b)

Input can be recovered in only one-direct from the output

c)

Out put can be converted back to the original input if hash key is known

69.

You receive an email with the subject “Immediate Action Required needed on your credit card account.” Why is this suspicious?

a)

Because it is illegal to send credit offers in email

b)

Because your credit card company does not use email

c)

This email is not suspicious

d)

The subject line is demanding immediate action

70.

How can malware be distributed?

a)

Found USB drives

b)

Email attachments

c)

All of these

d)

Browser Plugins

71.

During an ISO 27001 audit exercise at Arjun's company, what is the main focus?

a)

Review and categorize audit findings

b)

Design a new product

c)

Develop a marketing strategy

d)

Train new employees

72.

Anika, Benjamin, and Nora are working in a cybersecurity firm. They are analyzing some data. What information can they get from the network logs they are studying?

a)

The latest news updates

b)

The current weather conditions

c)

The data that's coming into and leaving their network

d)

The menu for the company's cafeteria

73.

Scarlett, William, and Ava are working as IT security analysts in a company. They are asked to review certain logs as part of their job. Which logs fall under the security category that they should review?

a)

Application-security logs

b)

Event-security logs

c)

Security logs for specialty applications

d)

All of the above

74.

TCP Full form

a)

Transmission Control Protocol

b)

Tally Compliant Product

c)

Transcutaneous Cardiac Pacing

d)

None of these

75.

Every device connected to the Internet has at least one IP address

a)

True

b)

False

76.
Which of the following is an internet protocol?
a)
HTTP
b)
HTML
c)
CSS
d)
UTP
77.
Which protocol is used to transfer files from one computer to another?
a)
FTP
b)
DNS
c)
HTML
d)
HTTP
78.

When should the Commission and affected data subjects be notified about a personal data breach?

a)

Within 24 hours

b)

Within 48 hours

c)

Within 72 hours

d)

Within 96 hours

79.

What information should be included in the notification of a personal data breach?

a)

Nature of the breach and measures taken to address it

b)

Personal data possibly involved

c)

Contact details of the personal information controller

d)

All of the above

80.

Which of the following is NOT a type of data breach?

a)

Unauthorized access to data

b)

Data being made unavailable to authorized users

c)

Properly encrypted data being stored securely

d)

Data being altered or deleted without authorization

81.

A computer virus is a program that can copy or______ its code in the system

a)

modify

b)

erase

c)

decode

d)

change

82.

How do you identify a secure website

a)

Check if the web site has a security certificate

b)

Check if the web site content is accurate and valid

c)

Check if the web site is in your browsing history

d)

Check if the web site publisher’s contact information is present

83.

When you delete a post from a social network site or forum it is completely erased.

a)

True

b)

False

84.

Subjects (Users) and sources of access requests are validated through a proper authentication mechanism.

a)

Reliable input

b)

Least privilege

c)

Open Policies

d)

Closed policies

85.

Describe the way in which a subject may access an object

a)

object

b)

access control

c)

subject

d)

object

86.

Name one type of ransomware.

a)

Zepto

b)

CryptoLocker

c)

WannaCry

d)

Locky

87.

How does ransomware typically infect a computer?

a)

Through malicious email attachments, infected websites, or software vulnerabilities.

b)

By downloading pirated software

c)

By connecting to an infected network

d)

By clicking on suspicious links or pop-up ads

88.

What are the types of cloud services?

a)

Public, private and hybrid clouds

b)

Personal area (PAN), Local area (LAN), Campus area networks (CAN)

c)

Infrastructure as a service (IaaS), platform as a service (PaaS), software as a service (SaaS)

d)

Mail server, collaboration server, web server, application server

89.

What is the drawback of cloud computing in education system?

a)

The need for high speed internet access

b)

The management of data and products

c)

The absence of hardware

d)

The wide connection of networks

90.

How can a company stay protected from DDoS attacks?

a)

By limiting user access

b)

By ignoring suspicious activity

c)

By increasing bandwidth

d)

By reducing server capacity