wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Cybersecurity Incidents and Statistics Worksheet

Total questions: 25

Worksheet time: 13mins

Name
Class
Date
1.

What is a network threat?

a)

A) A type of computer virus that spreads through email

b)

B) Malicious activities that exploit vulnerabilities in computer networks to gain unauthorised access, disrupt services, or steal information

c)

C) A firewall that protects networks from external attacks

d)

D) Software used to monitor network traffic

2.

According to the Verizon 2025 Data Breach Investigations Report, what percentage of all breaches involved ransomware?

a)

20%

b)

30%

c)

44%

d)

60%

3.

What is the main difference between a virus and other types of malware?

a)

Viruses are less harmful than other malware

b)

Viruses require a host file to attach to and spread, while worms can self-replicate without a host

c)

Viruses only affect mobile devices

d)

There is no difference - they are the same thing

4.

What is the primary goal of a Denial of Service (DoS) attack?

a)

To steal sensitive data from a network

b)

To install ransomware on systems

c)

To overwhelm systems or networks to make them unavailable to legitimate users

d)

To gain administrative access to a server

5.

Which ransomware gang was responsible for the Change Healthcare attack in February 2024?

a)

RansomHub

b)

REvil

c)

BlackCat (ALPHV)

d)

Scattered Spider

6.

What was the estimated total cost of the Change Healthcare ransomware attack in 2024?

a)

$100 million

b)

$500 million

c)

$1.5 billion

d)

$2.87 billion

7.

What method did the Scattered Spider group use to gain initial access to MGM Resorts in September 2023?

a)

SQL injection vulnerability

b)

Exploiting a zero-day vulnerability

c)

Social engineering - calling the IT help desk impersonating an employee

d)

Brute force password attack

8.

How did MGM's response to the ransomware attack differ from Caesars Entertainment?

a)

MGM paid the ransom, Caesars did not

b)

MGM refused to pay the ransom, while Caesars reportedly paid approximately $15 million

c)

Both companies paid the ransom

d)

Both companies refused to pay

9.

According to the Verizon DBIR, what percentage of all breaches involve the human element (social engineering, errors, or credential misuse)?

a)

39%

b)

50%

c)

68%

d)

74%

10.

What percentage of email threats are attributed to phishing?

a)

25.4%

b)

39.6%

c)

50.2%

d)

60.8%

11.

Which of the following is NOT a type of social engineering attack?

a)

Phishing

b)

Vishing

c)

Smishing

d)

Cryptojacking

12.

How did Russian state-sponsored hackers (Midnight Blizzard/APT29) breach Microsoft's corporate systems in January 2024?

a)

Through a zero-day vulnerability

b)

Through a password spray attack on a legacy account without MFA

c)

Through a phishing email to senior leadership

d)

Through stolen employee credentials from the dark web

13.

Which of the following is a common red flag in phishing emails?

a)

Generic greetings like "Dear Valued Customer"

b)

Proper company branding and logos

c)

Requests sent during business hours

d)

Emails with no attachments

14.

According to the Verizon 2025 DBIR, what percentage of breaches were linked to third-party involvement?

a)

10%

b)

15%

c)

20%

d)

30%

15.

What type of vulnerability did the Cl0p ransomware gang exploit in the MOVEit Transfer attack of 2023?

a)

Buffer overflow

b)

Zero-day SQL injection vulnerability

c)

Cross-site scripting (XSS)

d)

Remote code execution

16.

Approximately how many organisations were affected by the MOVEit Transfer attack?

a)

200

b)

500

c)

1,000

d)

2,000

17.

What was the main attack vector used in the May 2024 Snowflake data breach?

a)

Exploited software vulnerability

b)

Compromised credentials from a Snowflake employee account

c)

DDoS attack

d)

Insider threat from a disgruntled employee

18.

In a Defence in Depth strategy, what is the purpose of network segmentation and VLANs?

a)

To improve network speed

b)

To limit lateral movement and contain breaches

c)

To reduce hardware costs

d)

To eliminate the need for firewalls

19.

According to the Verizon DBIR, what percentage of breaches involved stolen credentials (making MFA critically important)?

a)

44%

b)

68%

c)

88%

d)

95%

20.

What is the core principle of Zero Trust Architecture?

a)

Trust all internal network traffic

b)

Only verify users once at initial login

c)

Never trust, always verify - authenticate every access request

d)

Trust employees but not external contractors

21.

According to the report, organisations using AI and automation for security have seen what reduction in average breach costs?

a)

$500,000

b)

$1.25 million

c)

$1.76 million

d)

$2.5 million

22.

What was the total cryptocurrency payment to ransomware attackers in the first half of 2023?

a)

$100 million

b)

$250 million

c)

$449.1 million

d)

$800 million

23.

What is "vishing"?

a)

Video-based phishing attacks

b)

Voice phishing conducted via phone calls

c)

Virtual reality phishing

d)

Virus-based social engineering

24.

Which attack demonstrated how a single widely-used software vulnerability can affect thousands of organisations?

a)

Change Healthcare ransomware

b)

MGM Resorts attack

c)

MOVEit Transfer zero-day exploit

d)

Microsoft corporate breach

25.

Why are insider threats particularly dangerous for organisations?

a)

They are more common than external threats

b)

Insiders have legitimate access and knowledge of systems, making detection difficult

c)

Insider threats always involve physical security breaches

d)

They are impossible to prevent