WorksheetsMCQ Set – Cybersecurity Essentials
Total questions: 108
Worksheet time: 54mins
What was the original meaning of “hacker”?
Cybercriminal
Skilled programmer exploring systems
Government spy
Malware developer
Why was early hacker culture linked to fantasy imagery (e.g., wizards)?
Hackers played too many video games
Fantasy themes symbolized mystery and power
It was required by universities
Wizards created early networks
Sun Tzu’s teachings in cybersecurity emphasize:
Punishing attackers
Installing more firewalls
Knowing the enemy
Creating strong passwords
What is a cybersecurity “domain”?
A physical server
An area requiring protection
A programming language
A password vault
Which of the following is a data-rich cyber domain?
Paint software
Calculator apps
Offline games
Which technology increases cyber risk by connecting many devices?
Typewriters
GIS
IoT
Mechanical sensors
GIS is used mainly for:
Tracking geographic data
Encrypting passwords
Testing firewalls
Managing social media
Script kiddies are known for:
Creating new hacking tools
Lacking skills and using existing scripts
Working for the government
Protecting networks legally
Which hacker type is authorized to test systems?
Black hat
White hat
Gray hat
Script kiddie
Hacktivists attack systems mainly for:
Fun
Money
Political or social causes
Hardware theft
What is currently the biggest motivator for cybercrime?
Fame
Friendship
Financial gain
Curiosity
Why is medical data highly valuable to attackers?
It never changes
It is difficult to understand
It can predict future illnesses
It has no legal protection
Cybersecurity jobs are in high demand because:
Companies like hiring interns
Digital threats keep increasing
Computers are no longer used
Cybercrime is disappearing
A honeypot is a:
Backup database
Decoy system to attract attackers
Network encryption tool
Virus removal tool
ISO 27000 is related to:
Web design
Wireless technology
Cybersecurity management standards
Hardware repair
A “threat” in cybersecurity is:
A weak password
A possible cause of an attack
A backup process
A network upgrade
A “vulnerability” is:
A firewall setting
A user account
A weakness exploitable by attackers
A type of social engineering
Which of the following is an example of financial data?
Test scores
Attendance sheets
Bank statements
Medical prescriptions
DNS spoofing is used to:
Slow down internet speed
Redirect users to fake websites
Block all DNS queries
Strengthen password policies
Packet sniffing is performed to:
Increase Wi-Fi range
Capture data packets for analysis
Repair broken packets
Send encrypted emails
SCADA systems are mainly used in:
Social media
Industrial control
Online gaming
Graphic design
Which attack famously targeted SCADA systems?
Malwarebytes
Stuxnet
Zeus
Storm Worm
One challenge governments face in cybersecurity is:
Reducing internet speeds
Limiting cloud storage
Balancing security and privacy
Blocking all foreign websites
Why are internal threats especially dangerous?
Insiders are always hackers
Insiders already have access to systems
Insiders use stronger passwords
Insiders cannot be monitored
An example of an accidental internal threat is:
Launching ransomware
Connecting an infected USB
Selling passwords
Changing firewall rules
BYOD increases security risk because:
Devices are too expensive
Users prefer small screens
Organizations cannot fully control personal devices
Mobile phones cannot run apps
Which of the following is NOT part of Big Data’s “3Vs”?
Volume
Velocity
Variety
Why is Big Data attractive to cybercriminals?
It is always encrypted
It contains large amounts of valuable information
It is unorganized
It has no backup
What is an Advanced Persistent Threat (APT)?
A short-term attack
A long-term, stealthy intrusion
A physical attack on servers
A type of firewall
A major risk of federated identity systems is:
Strong passwords are not allowed
Data cannot be encrypted
One compromised account can unlock many systems
Users must change passwords too often
Which of the following best describes cybersecurity?
Protecting physical equipment from theft
Protecting networked systems and data from digital attacks
Monitoring employee behaviour at work
Installing antivirus software only
What is the primary motivation behind most cybercrimes today?
Curiosity
Fame
Financial gain
Entertainment
Which type of threat actor is typically well-funded and highly skilled?
Script kiddies
Hacktivists
State-sponsored attackers
Insider threats
Which threat actor has legitimate access to systems but misuses it?
Insider
Hacktivist
Criminal group
Script kiddie
Hacktivists usually conduct attacks to:
Earn money
Prove technical skills
Promote political or social causes
Test cybersecurity tools
Which cybersecurity goal focuses on ensuring data is not altered?
Confidentiality
Integrity
Availability
Authentication
A DDoS attack mainly affects which cybersecurity principle?
Availability
Confidentiality
Integrity
Non-repudiation
Which of the following best describes malware?
A secure network protocol
Software designed to cause harm
An encrypted communication channel
A user authentication method
Which expert typically identifies system weaknesses before attackers do?
Malicious hacker
Penetration tester
Script kiddie
Cybercriminal
The primary role of cybersecurity professionals is to:
Develop new applications
Prevent, detect, and respond to cyber threats
Manage internet service providers
Create social media accounts for organisations
What is the main difference between a virus and a worm?
Viruses self-replicate; worms require user action
Worms self-replicate; viruses require user action
Worms are harmless; viruses are harmful
Viruses only infect mobile devices
Which malware disguises itself as a legitimate program?
Worm
Trojan
Rootkit
Logic bomb
What does ransomware typically do?
Steals passwords
Tracks browsing data
Encrypts or locks files until payment is made
Sends spam emails
What makes a rootkit dangerous?
It displays unwanted ads
It destroys hardware
It hides attacker activity in the OS
It spreads through email
Spear phishing is best described as:
Random spam emails
Phishing targeted at specific people or groups
Phishing done through SMS
Phishing done over phone calls
Vishing is phishing done through:
SMS
Voice calls
Search engines
Redirecting a user to a fake website is known as:
Spoofing
Pharming
Pretexting
Tailgating
A DDoS attack is different from a DoS attack because it:
Uses only weak devices
Is easier to block
Comes from multiple compromised systems
Disables firewalls automatically
Which attack involves intercepting communication between two parties?
Replay attack
Phishing
Man-in-the-middle
IP spoofing
An “evil twin” refers to a:
Duplicate user account
Fake wireless access point
Duplicate encryption key
Fake firewall configuration
What does ARP spoofing manipulate?
MAC-to-IP address mapping
DNS queries
Wireless signals
Email headers
A replay attack involves:
Overloading the network
Recording and retransmitting communication
Guessing passwords
Redirecting traffic
What is the purpose of a backdoor?
Improve network performance
Provide hidden access to a system
Block malicious websites
Protect user passwords
Zero-day attacks are dangerous because:
They are used only by beginners
Their effects are easily reversed
They exploit unknown, unpatched vulnerabilities
They only target mobile devices
A rogue access point is:
A secure corporate AP
An outdated wireless device
An unauthorized AP installed without approval
A broken AP that cannot broadcast
Shoulder surfing involves:
Reading someone's screen without permission
Guessing passwords
Following someone into a building
Sending phishing emails
Grayware is best described as:
Clearly malicious software
Software that is annoying but not fully harmful
Hardware-based malware
Anti-virus testing tools
SEO poisoning is used to:
Slow down search engines
Manipulate search results to lead users to malicious sites
Improve website ranking
Encrypt search data
SMiShing is phishing via:
Phone calls
Search engine results
SMS text messages
A browser hijacker typically:
Encrypts files
Redirects a user's browser to unwanted websites
Scans for viruses
Increases browser speed
What is the main goal of cryptography?
To compress data
To ensure data protection and security
To increase system performance
To detect malware
What is plaintext?
Encrypted data
Lost data
Original readable data
Binary code
What is ciphertext?
Data in its original form
Data compressed for storage
Encrypted unreadable data
Data being transmitted
What is cryptanalysis?
The study and practice of breaking or bypassing cryptographic systems
The process of designing encryption algorithms
Encoding data to reduce file size
Managing encryption keys for users
Which of the following is a historical cipher?
AES
Scytale
RSA
ECC
What is the biggest challenge in symmetric encryption?
Slow performance
Key distribution
Weak algorithms
Requires no keys
Asymmetric encryption uses which key for encryption?
Private key
Shared key
Public key
Temporary key
Asymmetric encryption uses which key for decryption?
Recovery key
Private key
Guest key
Public key
Why is asymmetric encryption slower?
It uses smaller key sizes
It requires special hardware
It uses complex mathematical operations
It cannot encrypt large files
Which of the following is a symmetric encryption algorithm?
RSA
AES
Diffie-Hellman
ECC
Which of the following is an asymmetric encryption algorithm?
DES
Blowfish
RSA
3DES
Hybrid cryptography uses:
Only symmetric keys
Only public keys
Both symmetric and asymmetric keys
No keys at all
What is steganography?
Concealing messages inside other data
Compressing large files
Encrypting using two keys
Removing hidden threats
What does a block cipher do?
Encrypts data one bit at a time
Encrypts fixed-size blocks of data
Removes duplicates in data
Converts text into hash values
What does a stream cipher do?
Encrypts blocks of 128 bits
Encrypts data one bit or byte at a time
Detects anomalies in traffic
Stores keys securely
Which is NOT one of the access control steps?
Identification
Encryption
Authorization
Accountability
A fingerprint scan is an example of:
Something you know
Something you do
Something you have
Something you are
Mandatory Access Control (MAC) is commonly used in:
Home networks
Social media apps
Government and military
Gaming systems
Role-Based Access Control (RBAC) assigns permissions based on:
Password strength
Job functions
Network IP
Device type
Which access control model is the least restrictive?
MAC
RBAC
Rule-Based
DAC
Which of the following is a physical access control?
Firewall
Encryption
CCTV camera
Password
Which of the following is a logical access control?
Padlocks
Motion detectors
Biometrics
Security guards
Which encryption standard is used for secure web browsing (HTTPS)?
RSA + AES
DES only
3DES only
Vigenère cipher
What does an Access Control List (ACL) do?
Tracks user passwords
Defines rules for who can access what
Detects malware
Stores encryption keys
AES is preferred over DES because:
AES uses shorter keys
DES is faster
AES is more secure with stronger keys
DES is required by all systems
What is the primary purpose of data masking?
To delete sensitive information permanently
To hide sensitive data with realistic substitutes
To transfer data securely over the internet
To compress data for storage
Which of the following is a data masking technique?
Hashing
Substitution
Compression
Fragmentation
Which masking technique replaces values with NULL?
Shuffling
Substitution
Nulling out
Aggregation
What is steganography used for?
Encrypting messages
Hiding the existence of a message
Data compression
Increasing image resolution
What is the file created after embedding hidden data called?
Cover object
Plain object
Stego object
Encapsulation object
How many bits can be hidden in one RGB pixel using LSB?
1
2
3
8
What is the process of detecting hidden information in a file called?
Steganalysis
Decryption
Encapsulation
Obfuscation
What does cryptography ensure?
Confidentiality, integrity, authentication
Speed, mobility, flexibility
Storage, compression, redundancy
Access, identity, pricing
Plaintext refers to:
Locked data
Encrypted data
Readable data
Compressed data
Which term refers to encrypted, unreadable data?
Plaintext
Ciphertext
Stegotext
Metadata
Which is a classical encryption method?
AES
RSA
Caesar Cipher
SHA-256
What is a key characteristic of symmetric encryption?
Uses two different keys
Uses only a public key
Uses the same key for encryption and decryption
Requires no key at all
Which is a symmetric encryption algorithm?
RSA
AES
ECC
Diffie-Hellman
What is a disadvantage of symmetric encryption?
Limited file size
Key sharing is difficult
Algorithms are too simple
Cannot encrypt large data
Which statement best describes asymmetric encryption?
Uses one shared key
Uses two different keys
Only used for images
Faster than symmetric encryption
Which is an asymmetric algorithm?
AES
DES
Blowfish
RSA
What is an advantage of asymmetric encryption?
Easy key distribution
Faster than symmetric encryption
Requires no keys
Uses block ciphers only
Why combine symmetric and asymmetric encryption?
To increase packet size
For speed and secure key exchange
To reduce hardware use
To remove the need for keys
What defines a block cipher?
Encrypts data one bit at a time
Encrypts data one byte at a time
Encrypts data in fixed-size blocks
Does not require a key
A stream cipher encrypts data:
In large blocks
One bit or byte at a time
Without using a key
Only in wireless networks
What does a VPN provide?
Faster internet speeds
Encrypted tunnel over the internet
Unlimited cloud storage
Website hosting
Which is a common use of VPNs?
Playing offline games
Hardware repair
Secure browsing on public Wi-Fi
Image editing
Which of the following is NOT a category of access control?
Physical
Logical
Administrative
Procedural
