Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

MCQ Set – Cybersecurity Essentials

Total questions: 108

Worksheet time: 54mins

Name
Class
Date
1.

What was the original meaning of “hacker”?

a)

Cybercriminal

b)

Skilled programmer exploring systems

c)

Government spy

d)

Malware developer

2.

Why was early hacker culture linked to fantasy imagery (e.g., wizards)?

a)

Hackers played too many video games

b)

Fantasy themes symbolized mystery and power

c)

It was required by universities

d)

Wizards created early networks

3.

Sun Tzu’s teachings in cybersecurity emphasize:

a)

Punishing attackers

b)

Installing more firewalls

c)

Knowing the enemy

d)

Creating strong passwords

4.

What is a cybersecurity “domain”?

a)

A physical server

b)

An area requiring protection

c)

A programming language

d)

A password vault

5.

Which of the following is a data-rich cyber domain?

a)

Paint software

b)

Google

c)

Calculator apps

d)

Offline games

6.

Which technology increases cyber risk by connecting many devices?

a)

Typewriters

b)

GIS

c)

IoT

d)

Mechanical sensors

7.

GIS is used mainly for:

a)

Tracking geographic data

b)

Encrypting passwords

c)

Testing firewalls

d)

Managing social media

8.

Script kiddies are known for:

a)

Creating new hacking tools

b)

Lacking skills and using existing scripts

c)

Working for the government

d)

Protecting networks legally

9.

Which hacker type is authorized to test systems?

a)

Black hat

b)

White hat

c)

Gray hat

d)

Script kiddie

10.

Hacktivists attack systems mainly for:

a)

Fun

b)

Money

c)

Political or social causes

d)

Hardware theft

11.

What is currently the biggest motivator for cybercrime?

a)

Fame

b)

Friendship

c)

Financial gain

d)

Curiosity

12.

Why is medical data highly valuable to attackers?

a)

It never changes

b)

It is difficult to understand

c)

It can predict future illnesses

d)

It has no legal protection

13.

Cybersecurity jobs are in high demand because:

a)

Companies like hiring interns

b)

Digital threats keep increasing

c)

Computers are no longer used

d)

Cybercrime is disappearing

14.

A honeypot is a:

a)

Backup database

b)

Decoy system to attract attackers

c)

Network encryption tool

d)

Virus removal tool

15.

ISO 27000 is related to:

a)

Web design

b)

Wireless technology

c)

Cybersecurity management standards

d)

Hardware repair

16.

A “threat” in cybersecurity is:

a)

A weak password

b)

A possible cause of an attack

c)

A backup process

d)

A network upgrade

17.

A “vulnerability” is:

a)

A firewall setting

b)

A user account

c)

A weakness exploitable by attackers

d)

A type of social engineering

18.

Which of the following is an example of financial data?

a)

Test scores

b)

Attendance sheets

c)

Bank statements

d)

Medical prescriptions

19.

DNS spoofing is used to:

a)

Slow down internet speed

b)

Redirect users to fake websites

c)

Block all DNS queries

d)

Strengthen password policies

20.

Packet sniffing is performed to:

a)

Increase Wi-Fi range

b)

Capture data packets for analysis

c)

Repair broken packets

d)

Send encrypted emails

21.

SCADA systems are mainly used in:

a)

Social media

b)

Industrial control

c)

Online gaming

d)

Graphic design

22.

Which attack famously targeted SCADA systems?

a)

Malwarebytes

b)

Stuxnet

c)

Zeus

d)

Storm Worm

23.

One challenge governments face in cybersecurity is:

a)

Reducing internet speeds

b)

Limiting cloud storage

c)

Balancing security and privacy

d)

Blocking all foreign websites

24.

Why are internal threats especially dangerous?

a)

Insiders are always hackers

b)

Insiders already have access to systems

c)

Insiders use stronger passwords

d)

Insiders cannot be monitored

25.

An example of an accidental internal threat is:

a)

Launching ransomware

b)

Connecting an infected USB

c)

Selling passwords

d)

Changing firewall rules

26.

BYOD increases security risk because:

a)

Devices are too expensive

b)

Users prefer small screens

c)

Organizations cannot fully control personal devices

d)

Mobile phones cannot run apps

27.

Which of the following is NOT part of Big Data’s “3Vs”?

a)

Volume

b)

Velocity

c)

Variety

28.

Why is Big Data attractive to cybercriminals?

a)

It is always encrypted

b)

It contains large amounts of valuable information

c)

It is unorganized

d)

It has no backup

29.

What is an Advanced Persistent Threat (APT)?

a)

A short-term attack

b)

A long-term, stealthy intrusion

c)

A physical attack on servers

d)

A type of firewall

30.

A major risk of federated identity systems is:

a)

Strong passwords are not allowed

b)

Data cannot be encrypted

c)

One compromised account can unlock many systems

d)

Users must change passwords too often

31.

Which of the following best describes cybersecurity?

a)

Protecting physical equipment from theft

b)

Protecting networked systems and data from digital attacks

c)

Monitoring employee behaviour at work

d)

Installing antivirus software only

32.

What is the primary motivation behind most cybercrimes today?

a)

Curiosity

b)

Fame

c)

Financial gain

d)

Entertainment

33.

Which type of threat actor is typically well-funded and highly skilled?

a)

Script kiddies

b)

Hacktivists

c)

State-sponsored attackers

d)

Insider threats

34.

Which threat actor has legitimate access to systems but misuses it?

a)

Insider

b)

Hacktivist

c)

Criminal group

d)

Script kiddie

35.

Hacktivists usually conduct attacks to:

a)

Earn money

b)

Prove technical skills

c)

Promote political or social causes

d)

Test cybersecurity tools

36.

Which cybersecurity goal focuses on ensuring data is not altered?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Authentication

37.

A DDoS attack mainly affects which cybersecurity principle?

a)

Availability

b)

Confidentiality

c)

Integrity

d)

Non-repudiation

38.

Which of the following best describes malware?

a)

A secure network protocol

b)

Software designed to cause harm

c)

An encrypted communication channel

d)

A user authentication method

39.

Which expert typically identifies system weaknesses before attackers do?

a)

Malicious hacker

b)

Penetration tester

c)

Script kiddie

d)

Cybercriminal

40.

The primary role of cybersecurity professionals is to:

a)

Develop new applications

b)

Prevent, detect, and respond to cyber threats

c)

Manage internet service providers

d)

Create social media accounts for organisations

41.

What is the main difference between a virus and a worm?

a)

Viruses self-replicate; worms require user action

b)

Worms self-replicate; viruses require user action

c)

Worms are harmless; viruses are harmful

d)

Viruses only infect mobile devices

42.

Which malware disguises itself as a legitimate program?

a)

Worm

b)

Trojan

c)

Rootkit

d)

Logic bomb

43.

What does ransomware typically do?

a)

Steals passwords

b)

Tracks browsing data

c)

Encrypts or locks files until payment is made

d)

Sends spam emails

44.

What makes a rootkit dangerous?

a)

It displays unwanted ads

b)

It destroys hardware

c)

It hides attacker activity in the OS

d)

It spreads through email

45.

Spear phishing is best described as:

a)

Random spam emails

b)

Phishing targeted at specific people or groups

c)

Phishing done through SMS

d)

Phishing done over phone calls

46.

Vishing is phishing done through:

a)

SMS

b)

Email

c)

Voice calls

d)

Search engines

47.

Redirecting a user to a fake website is known as:

a)

Spoofing

b)

Pharming

c)

Pretexting

d)

Tailgating

48.

A DDoS attack is different from a DoS attack because it:

a)

Uses only weak devices

b)

Is easier to block

c)

Comes from multiple compromised systems

d)

Disables firewalls automatically

49.

Which attack involves intercepting communication between two parties?

a)

Replay attack

b)

Phishing

c)

Man-in-the-middle

d)

IP spoofing

50.

An “evil twin” refers to a:

a)

Duplicate user account

b)

Fake wireless access point

c)

Duplicate encryption key

d)

Fake firewall configuration

51.

What does ARP spoofing manipulate?

a)

MAC-to-IP address mapping

b)

DNS queries

c)

Wireless signals

d)

Email headers

52.

A replay attack involves:

a)

Overloading the network

b)

Recording and retransmitting communication

c)

Guessing passwords

d)

Redirecting traffic

53.

What is the purpose of a backdoor?

a)

Improve network performance

b)

Provide hidden access to a system

c)

Block malicious websites

d)

Protect user passwords

54.

Zero-day attacks are dangerous because:

a)

They are used only by beginners

b)

Their effects are easily reversed

c)

They exploit unknown, unpatched vulnerabilities

d)

They only target mobile devices

55.

A rogue access point is:

a)

A secure corporate AP

b)

An outdated wireless device

c)

An unauthorized AP installed without approval

d)

A broken AP that cannot broadcast

56.

Shoulder surfing involves:

a)

Reading someone's screen without permission

b)

Guessing passwords

c)

Following someone into a building

d)

Sending phishing emails

57.

Grayware is best described as:

a)

Clearly malicious software

b)

Software that is annoying but not fully harmful

c)

Hardware-based malware

d)

Anti-virus testing tools

58.

SEO poisoning is used to:

a)

Slow down search engines

b)

Manipulate search results to lead users to malicious sites

c)

Improve website ranking

d)

Encrypt search data

59.

SMiShing is phishing via:

a)

Email

b)

Phone calls

c)

Search engine results

d)

SMS text messages

60.

A browser hijacker typically:

a)

Encrypts files

b)

Redirects a user's browser to unwanted websites

c)

Scans for viruses

d)

Increases browser speed

61.

What is the main goal of cryptography?

a)

To compress data

b)

To ensure data protection and security

c)

To increase system performance

d)

To detect malware

62.

What is plaintext?

a)

Encrypted data

b)

Lost data

c)

Original readable data

d)

Binary code

63.

What is ciphertext?

a)

Data in its original form

b)

Data compressed for storage

c)

Encrypted unreadable data

d)

Data being transmitted

64.

What is cryptanalysis?

a)

The study and practice of breaking or bypassing cryptographic systems

b)

The process of designing encryption algorithms

c)

Encoding data to reduce file size

d)

Managing encryption keys for users

65.

Which of the following is a historical cipher?

a)

AES

b)

Scytale

c)

RSA

d)

ECC

66.

What is the biggest challenge in symmetric encryption?

a)

Slow performance

b)

Key distribution

c)

Weak algorithms

d)

Requires no keys

67.

Asymmetric encryption uses which key for encryption?

a)

Private key

b)

Shared key

c)

Public key

d)

Temporary key

68.

Asymmetric encryption uses which key for decryption?

a)

Recovery key

b)

Private key

c)

Guest key

d)

Public key

69.

Why is asymmetric encryption slower?

a)

It uses smaller key sizes

b)

It requires special hardware

c)

It uses complex mathematical operations

d)

It cannot encrypt large files

70.

Which of the following is a symmetric encryption algorithm?

a)

RSA

b)

AES

c)

Diffie-Hellman

d)

ECC

71.

Which of the following is an asymmetric encryption algorithm?

a)

DES

b)

Blowfish

c)

RSA

d)

3DES

72.

Hybrid cryptography uses:

a)

Only symmetric keys

b)

Only public keys

c)

Both symmetric and asymmetric keys

d)

No keys at all

73.

What is steganography?

a)

Concealing messages inside other data

b)

Compressing large files

c)

Encrypting using two keys

d)

Removing hidden threats

74.

What does a block cipher do?

a)

Encrypts data one bit at a time

b)

Encrypts fixed-size blocks of data

c)

Removes duplicates in data

d)

Converts text into hash values

75.

What does a stream cipher do?

a)

Encrypts blocks of 128 bits

b)

Encrypts data one bit or byte at a time

c)

Detects anomalies in traffic

d)

Stores keys securely

76.

Which is NOT one of the access control steps?

a)

Identification

b)

Encryption

c)

Authorization

d)

Accountability

77.

A fingerprint scan is an example of:

a)

Something you know

b)

Something you do

c)

Something you have

d)

Something you are

78.

Mandatory Access Control (MAC) is commonly used in:

a)

Home networks

b)

Social media apps

c)

Government and military

d)

Gaming systems

79.

Role-Based Access Control (RBAC) assigns permissions based on:

a)

Password strength

b)

Job functions

c)

Network IP

d)

Device type

80.

Which access control model is the least restrictive?

a)

MAC

b)

RBAC

c)

Rule-Based

d)

DAC

81.

Which of the following is a physical access control?

a)

Firewall

b)

Encryption

c)

CCTV camera

d)

Password

82.

Which of the following is a logical access control?

a)

Padlocks

b)

Motion detectors

c)

Biometrics

d)

Security guards

83.

Which encryption standard is used for secure web browsing (HTTPS)?

a)

RSA + AES

b)

DES only

c)

3DES only

d)

Vigenère cipher

84.

What does an Access Control List (ACL) do?

a)

Tracks user passwords

b)

Defines rules for who can access what

c)

Detects malware

d)

Stores encryption keys

85.

AES is preferred over DES because:

a)

AES uses shorter keys

b)

DES is faster

c)

AES is more secure with stronger keys

d)

DES is required by all systems

86.

What is the primary purpose of data masking?

a)

To delete sensitive information permanently

b)

To hide sensitive data with realistic substitutes

c)

To transfer data securely over the internet

d)

To compress data for storage

87.

Which of the following is a data masking technique?

a)

Hashing

b)

Substitution

c)

Compression

d)

Fragmentation

88.

Which masking technique replaces values with NULL?

a)

Shuffling

b)

Substitution

c)

Nulling out

d)

Aggregation

89.

What is steganography used for?

a)

Encrypting messages

b)

Hiding the existence of a message

c)

Data compression

d)

Increasing image resolution

90.

What is the file created after embedding hidden data called?

a)

Cover object

b)

Plain object

c)

Stego object

d)

Encapsulation object

91.

How many bits can be hidden in one RGB pixel using LSB?

a)

1

b)

2

c)

3

d)

8

92.

What is the process of detecting hidden information in a file called?

a)

Steganalysis

b)

Decryption

c)

Encapsulation

d)

Obfuscation

93.

What does cryptography ensure?

a)

Confidentiality, integrity, authentication

b)

Speed, mobility, flexibility

c)

Storage, compression, redundancy

d)

Access, identity, pricing

94.

Plaintext refers to:

a)

Locked data

b)

Encrypted data

c)

Readable data

d)

Compressed data

95.

Which term refers to encrypted, unreadable data?

a)

Plaintext

b)

Ciphertext

c)

Stegotext

d)

Metadata

96.

Which is a classical encryption method?

a)

AES

b)

RSA

c)

Caesar Cipher

d)

SHA-256

97.

What is a key characteristic of symmetric encryption?

a)

Uses two different keys

b)

Uses only a public key

c)

Uses the same key for encryption and decryption

d)

Requires no key at all

98.

Which is a symmetric encryption algorithm?

a)

RSA

b)

AES

c)

ECC

d)

Diffie-Hellman

99.

What is a disadvantage of symmetric encryption?

a)

Limited file size

b)

Key sharing is difficult

c)

Algorithms are too simple

d)

Cannot encrypt large data

100.

Which statement best describes asymmetric encryption?

a)

Uses one shared key

b)

Uses two different keys

c)

Only used for images

d)

Faster than symmetric encryption

101.

Which is an asymmetric algorithm?

a)

AES

b)

DES

c)

Blowfish

d)

RSA

102.

What is an advantage of asymmetric encryption?

a)

Easy key distribution

b)

Faster than symmetric encryption

c)

Requires no keys

d)

Uses block ciphers only

103.

Why combine symmetric and asymmetric encryption?

a)

To increase packet size

b)

For speed and secure key exchange

c)

To reduce hardware use

d)

To remove the need for keys

104.

What defines a block cipher?

a)

Encrypts data one bit at a time

b)

Encrypts data one byte at a time

c)

Encrypts data in fixed-size blocks

d)

Does not require a key

105.

A stream cipher encrypts data:

a)

In large blocks

b)

One bit or byte at a time

c)

Without using a key

d)

Only in wireless networks

106.

What does a VPN provide?

a)

Faster internet speeds

b)

Encrypted tunnel over the internet

c)

Unlimited cloud storage

d)

Website hosting

107.

Which is a common use of VPNs?

a)

Playing offline games

b)

Hardware repair

c)

Secure browsing on public Wi-Fi

d)

Image editing

108.

Which of the following is NOT a category of access control?

a)

Physical

b)

Logical

c)

Administrative

d)

 Procedural