WorksheetsPractice Test 3
Total questions: 48
Worksheet time: 24mins
A student receives an email claiming their school account will be shut down unless they click a link and enter their password. What threat is this?
DDoS
Phishing
Rootkit
Hardware failure
An administrator notices thousands of requests per second hitting the school’s website, slowing it to a crawl. Which attack is likely happening?
Man-in-the-middle
Brute force
DDoS
Worm infection
A forensic investigator needs to ensure evidence collected from a laptop is admissible in court. What should they do first?
Delete unnecessary files
Create a forensic image of the drive
Upgrade the OS
Install new apps
A student configures a router and needs to prevent unauthorized outside traffic from reaching internal services. What should they use?
Cookies
DNS settings
Access control lists (ACLs)
USB filtering
A teacher complains that their password was stolen even though they never shared it. The logs show suspicious keystrokes were recorded. What malware is responsible?
Spyware
Keylogger
Trojan
Worm
During a network investigation, you find that packets are being intercepted between a user and a website. What type of attack is this?
Port scan
MITM (Man-in-the-Middle)
SQL injection
Smishing
The school introduces fingerprint scanners for computer lab entry. What authentication factor does this represent?
Something you know
Something you have
Something you are
Something you share
A user wants to secure their home Wi-Fi. Which setting should they enable?
Open network
WEP
WPA2 or WPA3
MAC randomization
After a cyberattack, an investigator must verify no data has been tampered with. Which cryptographic tool helps verify file integrity?
Hash values
VPN
Digital certificates
Cookies
A company wants to block certain IP ranges from accessing the network. What should the security team implement?
Cloud storage
Firewall rules
Bluetooth restrictions
Browser extensions
A student exploring network cables accidentally unplugs one device and the whole network collapses. Which device was most likely disconnected?
Access point
Router
Printer
Laptop
During an investigation, logs show repeated failed login attempts over 5 minutes. What attack is occurring?
Brute force
DNS poisoning
ARP spoofing
Cookie manipulation
A hacker controls thousands of infected computers and uses them to attack a target. What is this network of systems called?
Cloud farm
VPN network
Botnet
IoT mesh
You notice the school servers have not been updated for 2 years. Which risk is most likely increased?
Too much storage
Outdated drivers
Known security vulnerabilities
Faster CPU performance
A security engineer wants to ensure only administrators can change system settings. What principle applies?
Open access
Least privilege
Full transparency
Dual control
A forensic examiner must avoid altering timestamps on a seized phone. What should they do?
Power on the device normally
Put it in airplane mode
Use a Faraday bag
Connect it to Wi-Fi
You discover that a coworker uses “School123” as their password for every website. What is the issue?
Too many symbols
Password reuse vulnerability
Excessive length
Biometric bypass
A school wants internet filtering and malware blocking for all student devices. Which device helps most?
Switch
Firewall
Keyboard
UPS battery
An attacker modifies DNS settings so traffic is redirected to a fake banking site. What is this attack?
DoS
DNS poisoning
Bluejacking
Packet fragmentation
A student connects to public Wi‑Fi without encryption. What risk increases?
Improved battery life
Packet sniffing
Faster speed
More reliable DHCP
A system requires a password and a facial scan to log in. Which concept does this represent?
Single‑factor authentication
Hardware‑only security
MFA (Multi‑factor authentication)
Proxy verification
A laptop is infected with ransomware. What is the FIRST action the security team should take?
Pay the ransom
Disconnect the laptop from the network
Delete system files
Reinstall every program
After reviewing logs, a forensic analyst notices unexpected outbound traffic from a server to unknown IP addresses. What might this indicate?
Successful backups
Data exfiltration
System update
Scheduled maintenance
Students report slow internet. The network engineer runs “ping” and gets long response times. What is being tested?
Storage
Website coding
Network latency
CPU temperature
A user tries to access a restricted folder and gets denied even with correct credentials. What is most likely misconfigured?
Firewall
Access control permissions
Wi‑Fi password
Router firmware
A school wants to prevent students from installing unauthorized software. Which method helps most?
Giving everyone admin accounts
Implementing group policy restrictions
Allowing BYOD
Turning off antivirus
A website uses HTTPS instead of HTTP. What benefit does this provide?
Faster load times
Encrypted communication
Fewer CSS errors
Lower DNS usage
The cybersecurity team wants to ensure all user activity is recorded. What should they enable?
Content filters
Password hints
Audit logs
Screensavers
A file found on a suspect's computer has a hash value that does not match the original. What does this indicate?
File is compressed
File has been modified
File version is outdated
File is encrypted
A student notices a Wi‑Fi network named “Free_School_WiFi” which requires no password. What should they suspect?
Official school network
Classroom hotspot
Rogue access point
Personal router
The IT department wants to reduce the attack surface on Windows machines. Which action helps most?
Installing games
Disabling unused services
Lowering screen brightness
Increasing RAM
An examiner must ensure chain of custody is preserved. What must they document?
Evidence creation date
Every person who handled the evidence
The suspect’s password
Time spent analyzing
A server is receiving packets from an IP address that does not exist. What attack might this be?
IP spoofing
Phishing
Social engineering
Dumpster diving
To secure a Linux server, an admin must limit who can execute certain scripts. What command helps with permissions?
ls
chmod
mkdir
cd
During forensics, you must recover deleted files on a Windows drive. Which tool category is needed?
Password managers
File carving tools
Anti‑spyware
VPN
A student sees unexpected Bluetooth connections popping up on their phone. What attack may be happening?
Bluejacking
SQL injection
DoS
SSL stripping
The school blocks social media during class hours. What type of control is this?
Technical (logical) control
Physical control
Administrative control
Detective control
A suspicious USB is found near the staff parking lot. What should the IT team do?
Plug it into a school computer
Give it to students
Analyze it in a sandbox environment
Format it immediately
A cyber risk assessment identifies that outdated switches could fail under heavy traffic, causing downtime. What is this an example of?
Asset duplication
Vulnerability identification
Policy enforcement
Encryption strategy
A student is sending harmful code disguised as homework attachments. What attack technique is being used?
Trojan horse
VPN tunnel
WPA2 cracking
Port mirroring
You find that an attacker gained access because a default router password was never changed. Which concept failed?
Multi-factor authentication
Hardening
Social engineering
Wi-Fi encryption
While analyzing a drive, an investigator spots time gaps in the logs. What might this indicate?
Normal system restarts
Log tampering
Browser updates
Disk fragmentation
The school wants to restrict who can access specific Wi-Fi networks. What should they implement?
SSID broadcasting
VLAN segmentation
Unencrypted guest mode
Stronger DNS caching
After a breach, an investigator isolates the affected machine but wants to monitor ongoing malicious traffic safely. What should they use?
Production network
Airplane mode
Isolated sandbox
Hard reboot
A student shares their account login with a friend. What security principle is violated?
Defense in depth
Non-repudiation
Cryptographic hashing
Data minimization
An attacker physically enters the server room by following someone through a restricted door. What attack is this?
Shoulder surfing
Tailgating
Brute forcing
Smishing
A forensic examiner calculates a hash before and after imaging a drive. The values match. What does this confirm?
Drive is encrypted
No data was altered
Drive is damaged
Logs were cleared
A cybersecurity analyst wants to monitor live network threats and alerts on a dashboard. Which system is needed?
DNS
IDS/IPS
Task Scheduler
Web server
