wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Practice Test 3

Total questions: 48

Worksheet time: 24mins

Name
Class
Date
1.

A student receives an email claiming their school account will be shut down unless they click a link and enter their password. What threat is this?

a)

DDoS

b)

Phishing

c)

Rootkit

d)

Hardware failure

2.

An administrator notices thousands of requests per second hitting the school’s website, slowing it to a crawl. Which attack is likely happening?

a)

Man-in-the-middle

b)

Brute force

c)

DDoS

d)

Worm infection

3.

A forensic investigator needs to ensure evidence collected from a laptop is admissible in court. What should they do first?

a)

Delete unnecessary files

b)

Create a forensic image of the drive

c)

Upgrade the OS

d)

Install new apps

4.

A student configures a router and needs to prevent unauthorized outside traffic from reaching internal services. What should they use?

a)

Cookies

b)

DNS settings

c)

Access control lists (ACLs)

d)

USB filtering

5.

A teacher complains that their password was stolen even though they never shared it. The logs show suspicious keystrokes were recorded. What malware is responsible?

a)

Spyware

b)

Keylogger

c)

Trojan

d)

Worm

6.

During a network investigation, you find that packets are being intercepted between a user and a website. What type of attack is this?

a)

Port scan

b)

MITM (Man-in-the-Middle)

c)

SQL injection

d)

Smishing

7.

The school introduces fingerprint scanners for computer lab entry. What authentication factor does this represent?

a)

Something you know

b)

Something you have

c)

Something you are

d)

Something you share

8.

A user wants to secure their home Wi-Fi. Which setting should they enable?

a)

Open network

b)

WEP

c)

WPA2 or WPA3

d)

MAC randomization

9.

After a cyberattack, an investigator must verify no data has been tampered with. Which cryptographic tool helps verify file integrity?

a)

Hash values

b)

VPN

c)

Digital certificates

d)

Cookies

10.

A company wants to block certain IP ranges from accessing the network. What should the security team implement?

a)

Cloud storage

b)

Firewall rules

c)

Bluetooth restrictions

d)

Browser extensions

11.

A student exploring network cables accidentally unplugs one device and the whole network collapses. Which device was most likely disconnected?

a)

Access point

b)

Router

c)

Printer

d)

Laptop

12.

During an investigation, logs show repeated failed login attempts over 5 minutes. What attack is occurring?

a)

Brute force

b)

DNS poisoning

c)

ARP spoofing

d)

Cookie manipulation

13.

A hacker controls thousands of infected computers and uses them to attack a target. What is this network of systems called?

a)

Cloud farm

b)

VPN network

c)

Botnet

d)

IoT mesh

14.

You notice the school servers have not been updated for 2 years. Which risk is most likely increased?

a)

Too much storage

b)

Outdated drivers

c)

Known security vulnerabilities

d)

Faster CPU performance

15.

A security engineer wants to ensure only administrators can change system settings. What principle applies?

a)

Open access

b)

Least privilege

c)

Full transparency

d)

Dual control

16.

A forensic examiner must avoid altering timestamps on a seized phone. What should they do?

a)

Power on the device normally

b)

Put it in airplane mode

c)

Use a Faraday bag

d)

Connect it to Wi-Fi

17.

You discover that a coworker uses “School123” as their password for every website. What is the issue?

a)

Too many symbols

b)

Password reuse vulnerability

c)

Excessive length

d)

Biometric bypass

18.

A school wants internet filtering and malware blocking for all student devices. Which device helps most?

a)

Switch

b)

Firewall

c)

Keyboard

d)

UPS battery

19.

An attacker modifies DNS settings so traffic is redirected to a fake banking site. What is this attack?

a)

DoS

b)

DNS poisoning

c)

Bluejacking

d)

Packet fragmentation

20.

A student connects to public Wi‑Fi without encryption. What risk increases?

a)

Improved battery life

b)

Packet sniffing

c)

Faster speed

d)

More reliable DHCP

21.

A system requires a password and a facial scan to log in. Which concept does this represent?

a)

Single‑factor authentication

b)

Hardware‑only security

c)

MFA (Multi‑factor authentication)

d)

Proxy verification

22.

A laptop is infected with ransomware. What is the FIRST action the security team should take?

a)

Pay the ransom

b)

Disconnect the laptop from the network

c)

Delete system files

d)

Reinstall every program

23.

After reviewing logs, a forensic analyst notices unexpected outbound traffic from a server to unknown IP addresses. What might this indicate?

a)

Successful backups

b)

Data exfiltration

c)

System update

d)

Scheduled maintenance

24.

Students report slow internet. The network engineer runs “ping” and gets long response times. What is being tested?

a)

Storage

b)

Website coding

c)

Network latency

d)

CPU temperature

25.

A user tries to access a restricted folder and gets denied even with correct credentials. What is most likely misconfigured?

a)

Firewall

b)

Access control permissions

c)

Wi‑Fi password

d)

Router firmware

26.

A school wants to prevent students from installing unauthorized software. Which method helps most?

a)

Giving everyone admin accounts

b)

Implementing group policy restrictions

c)

Allowing BYOD

d)

Turning off antivirus

27.

A website uses HTTPS instead of HTTP. What benefit does this provide?

a)

Faster load times

b)

Encrypted communication

c)

Fewer CSS errors

d)

Lower DNS usage

28.

The cybersecurity team wants to ensure all user activity is recorded. What should they enable?

a)

Content filters

b)

Password hints

c)

Audit logs

d)

Screensavers

29.

A file found on a suspect's computer has a hash value that does not match the original. What does this indicate?

a)

File is compressed

b)

File has been modified

c)

File version is outdated

d)

File is encrypted

30.

A student notices a Wi‑Fi network named “Free_School_WiFi” which requires no password. What should they suspect?

a)

Official school network

b)

Classroom hotspot

c)

Rogue access point

d)

Personal router

31.

The IT department wants to reduce the attack surface on Windows machines. Which action helps most?

a)

Installing games

b)

Disabling unused services

c)

Lowering screen brightness

d)

Increasing RAM

32.

An examiner must ensure chain of custody is preserved. What must they document?

a)

Evidence creation date

b)

Every person who handled the evidence

c)

The suspect’s password

d)

Time spent analyzing

33.

A server is receiving packets from an IP address that does not exist. What attack might this be?

a)

IP spoofing

b)

Phishing

c)

Social engineering

d)

Dumpster diving

34.

To secure a Linux server, an admin must limit who can execute certain scripts. What command helps with permissions?

a)

ls

b)

chmod

c)

mkdir

d)

cd

35.

During forensics, you must recover deleted files on a Windows drive. Which tool category is needed?

a)

Password managers

b)

File carving tools

c)

Anti‑spyware

d)

VPN

36.

A student sees unexpected Bluetooth connections popping up on their phone. What attack may be happening?

a)

Bluejacking

b)

SQL injection

c)

DoS

d)

SSL stripping

37.

The school blocks social media during class hours. What type of control is this?

a)

Technical (logical) control

b)

Physical control

c)

Administrative control

d)

Detective control

38.

A suspicious USB is found near the staff parking lot. What should the IT team do?

a)

Plug it into a school computer

b)

Give it to students

c)

Analyze it in a sandbox environment

d)

Format it immediately

39.

A cyber risk assessment identifies that outdated switches could fail under heavy traffic, causing downtime. What is this an example of?

a)

Asset duplication

b)

Vulnerability identification

c)

Policy enforcement

d)

Encryption strategy

40.

A student is sending harmful code disguised as homework attachments. What attack technique is being used?

a)

Trojan horse

b)

VPN tunnel

c)

WPA2 cracking

d)

Port mirroring

41.

You find that an attacker gained access because a default router password was never changed. Which concept failed?

a)

Multi-factor authentication

b)

Hardening

c)

Social engineering

d)

Wi-Fi encryption

42.

While analyzing a drive, an investigator spots time gaps in the logs. What might this indicate?

a)

Normal system restarts

b)

Log tampering

c)

Browser updates

d)

Disk fragmentation

43.

The school wants to restrict who can access specific Wi-Fi networks. What should they implement?

a)

SSID broadcasting

b)

VLAN segmentation

c)

Unencrypted guest mode

d)

Stronger DNS caching

44.

After a breach, an investigator isolates the affected machine but wants to monitor ongoing malicious traffic safely. What should they use?

a)

Production network

b)

Airplane mode

c)

Isolated sandbox

d)

Hard reboot

45.

A student shares their account login with a friend. What security principle is violated?

a)

Defense in depth

b)

Non-repudiation

c)

Cryptographic hashing

d)

Data minimization

46.

An attacker physically enters the server room by following someone through a restricted door. What attack is this?

a)

Shoulder surfing

b)

Tailgating

c)

Brute forcing

d)

Smishing

47.

A forensic examiner calculates a hash before and after imaging a drive. The values match. What does this confirm?

a)

Drive is encrypted

b)

No data was altered

c)

Drive is damaged

d)

Logs were cleared

48.

A cybersecurity analyst wants to monitor live network threats and alerts on a dashboard. Which system is needed?

a)

DNS

b)

IDS/IPS

c)

Task Scheduler

d)

Web server