wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

What is Cybersecurity?

Total questions: 52

Worksheet time: 26mins

Name
Class
Date
1.

Which statement best defines cybersecurity in an IT context?

a)

Protecting devices from physical damage only

b)

Building faster computers for enterprise use

c)

Protecting systems, networks, and data from unauthorized access

d)

Sharing information freely across connected devices

2.

Which example primarily represents network protection?

a)

Installing antivirus on a laptop

b)

Configuring a firewall for company intranet traffic

c)

Using strong passwords for user accounts

d)

Encrypting stored medical records

3.

If one security element fails, what is the most likely consequence?

a)

Data remains secure but networks fail

b)

Systems improve due to redundancy

c)

Only the failed element is affected

d)

The entire system may be at risk

4.

Which item is categorized as data in cybersecurity?

a)

Smartphones and laptops

b)

Passwords and medical files

c)

Wi‑Fi routers in an office

d)

Company intranet cabling

5.

A helpful analogy compares a firewall to which home security feature?

a)

CCTV watching activity

b)

Open window inviting visitors

c)

Front door lock protecting entry

d)

Guard dog deterring intruders

6.

Which personal risk is commonly triggered by phishing emails?

a)

Improved multi-factor protection

b)

Reduced spam in your inbox

c)

Automatic device encryption

d)

Bank theft from stolen credentials

7.

At the organizational level, which event halted surgeries in UK hospitals?

a)

IoT botnet expansion

b)

Colonial Pipeline outage

c)

Marriott loyalty breach

d)

WannaCry ransomware attack

8.

What was the reported average organizational cost of a data breach?

a)

Nearly $44.5 million

b)

Roughly $45,000

c)

About $4.45 million

d)

Around $445,000

9.

Which impact illustrates national or global disruption from cyberattacks?

a)

Gas shortages across the US

b)

Password reuse on social media

c)

Single hospital surgery delays

d)

A company’s guest record loss

10.

Password reuse across accounts most directly increases the risk of what?

a)

Data deduplication

b)

Hardware failure

c)

Network latency

d)

Account takeovers

11.

Which principle of the CIA Triad focuses on preventing unauthorized data access?

a)

Nonrepudiation of transactions

b)

Integrity of stored records

c)

Availability of online services

d)

Confidentiality of information

12.

Which control best supports confidentiality for messaging apps?

a)

Regular full backups

b)

Anycast DDoS routing

c)

End-to-end encryption

d)

Hash-based checksums

13.

Integrity is primarily concerned with which outcome?

a)

Data remaining accurate and unaltered

b)

Users proving their identities

c)

Systems staying online and responsive

d)

Traffic being blocked from botnets

14.

Which scenario illustrates a failure of integrity?

a)

Encrypted messages cannot be read by outsiders

b)

An employee loses a password

c)

A hacker changes a bank transfer amount

d)

A service goes down for two hours

15.

Availability is best supported by which measures?

a)

Digital signatures and hashes

b)

Strong passwords and MFA

c)

File-level access controls

d)

Backups and DDoS defense

16.

Which real-world event is cited as an availability issue?

a)

2016 Mirai botnet outage

b)

Ransomware encrypts local files

c)

SSL certificate mismatch incident

d)

Zero-day privilege escalation

17.

Which domain focuses on protecting routers, switches, and traffic using controls like firewalls and VPNs?

a)

Data and cloud security compliance

b)

Network security and traffic defenses

c)

Application security and code reviews

d)

Endpoint security for user devices

18.

Which practice best belongs to application security?

a)

Secure coding and regular patching

b)

Encrypting backups in cloud

c)

Installing anti‑virus on laptops

d)

Configuring network intrusion detection

19.

Endpoint security primarily aims to protect which assets?

a)

Laptops, phones, and IoT devices

b)

Databases and cloud storage

c)

Source code and build pipelines

d)

Routers, firewalls, and switches

20.

Which statement describes a key risk from the human element in cybersecurity?

a)

Users click phishing links or use weak passwords

b)

Firewalls eliminate all external threats

c)

Encrypted data always prevents breaches

d)

Unpatched APIs automatically exploit themselves

21.

A company needs GDPR compliance and strong encryption for cloud workloads. Which domain best addresses this need?

a)

Application security testing

b)

Data and cloud security controls

c)

Endpoint security hardening

d)

Network security monitoring

22.

Which action most likely reduces phishing success against employees?

a)

Disabling all mobile device cameras

b)

Using longer firewall rule lists

c)

Adding more network switches to segments

d)

Multi‑factor authentication and awareness training

23.

Which option best defines a cybersecurity threat?

a)

Weakness such as poor passwords or patches

b)

Weapon that leverages a discovered weakness

c)

Safeguard that reduces likelihood and impact

d)

Potential danger from adversaries or disasters

24.

In cybersecurity, what is a vulnerability?

a)

Weakness like unpatched software or unlocked devices

b)

Policy control like MFA or user training

c)

Likelihood multiplied by incident impact

d)

Method used to take advantage of a weakness

25.

Which statement best describes an exploit?

a)

A method or weapon using a vulnerability

b)

A calculation combining likelihood and impact

c)

A safeguard such as encryption or MFA

d)

A potential source of harm to systems

26.

Risk in cybersecurity is commonly understood as:

a)

The controls deployed to prevent attacks

b)

The tools used by attackers to break in

c)

The chance and impact of a security incident

d)

The presence of any system weakness

27.

Which is an example of a control?

a)

Outdated operating system left unpatched

b)

Phishing email crafted to bypass filters

c)

Encryption or training to reduce risk

d)

Hackers planning ransomware campaign

28.

Using the burglar analogy, which mapping is correct?

a)

Control = burglar; Threat = CCTV cameras

b)

Vulnerability = open window; Exploit = burglar climbing

c)

Threat = lock; Control = burglar climbing

d)

Risk = open window; Vulnerability = chance of theft

29.

A company has weak passwords and gets hit by phishing. Which terms match these elements?

a)

Weak passwords = exploit; phishing = control

b)

Weak passwords = vulnerability; phishing = exploit

c)

Weak passwords = control; phishing = threat

d)

Weak passwords = threat; phishing = risk

30.

Which role acts as the first responder by monitoring alerts and logs to quickly handle incidents like a brute-force attack on a VPN?

a)

Security Auditor reviewing policy compliance

b)

SOC Analyst monitoring alerts and responding fast

c)

CISO overseeing strategy and executive communication

d)

Security Engineer responsible for building defenses

31.

A Security Engineer’s primary responsibility is best described as:

a)

Building defenses like MFA, VPNs, and secure cloud

b)

Checking GDPR and HIPAA compliance regularly

c)

Triaging SIEM alerts during live incidents

d)

Leading crisis management and briefing executives

32.

Which role focuses on ensuring an organization meets legal and regulatory requirements such as GDPR and HIPAA?

a)

SOC Analyst investigating real-time threats

b)

Security Auditor conducting compliance checks

c)

Security Engineer implementing technical controls

d)

CISO leading strategy and crisis response

33.

The CISO most accurately serves as:

a)

Hands-on responder to VPN brute-force events

b)

Strategic leader managing security crises and executives

c)

Engineer deploying MFA and cloud infrastructure

d)

Compliance reviewer performing regulatory audits

34.

Which pairing of role and example duty is correct?

a)

CISO — checks operational logs for brute-force attempts

b)

Security Auditor — responds to SIEM alerts immediately

c)

Security Engineer — implements multi-factor authentication

d)

SOC Analyst — designs secure cloud architecture

35.

Which action best aligns with ethical hacking when you discover a vulnerability during authorized testing?

a)

Continue testing to fully exploit the weakness

b)

Immediately cease testing and avoid further interaction

c)

Copy sample user records to prove the issue

d)

Post details online to warn potential victims

36.

What is the primary reason to obtain written permission before testing a system?

a)

It grants admin credentials automatically

b)

It increases payment for bug reports

c)

It ensures legality and defined scope

d)

It improves test accuracy and speed

37.

Which option best describes responsible disclosure?

a)

Demonstrate impact with real stolen data

b)

Report privately through official channels

c)

Publicly share details before any fix

d)

Sell exploit information to third parties

38.

When collecting evidence of a vulnerability, what is the ethical approach to proof?

a)

Document only what's necessary, avoid actual data

b)

Record user sessions to show real impacts

c)

Download full databases for stronger proof

d)

Store credentials to validate access claims

39.

Which behavior violates legal responsibilities in cybersecurity work?

a)

Use security.txt to report issues

b)

Scan random websites without consent

c)

Stay within authorized boundaries

d)

Practice in CTFs and cyber ranges

40.

After privately reporting a vulnerability, what should you do until the issue is fixed?

a)

Share findings publicly to pressure a fix

b)

Keep information confidential and limit details

c)

Test continuously to monitor system changes

d)

Exfiltrate sample data to demonstrate severity

41.

Which hacker type is authorized and focuses on improving security through penetration testing and bug bounties?

a)

Black Hat hackers seeking personal gain

b)

Script Kiddies using tools without knowledge

c)

White Hat hackers with ethical authorization

d)

Grey Hat hackers operating in legal grey areas

42.

Which description best matches Black Hat hackers?

a)

Defenders monitoring systems for threats

b)

Learners experimenting under guidance

c)

Authorized testers who report vulnerabilities

d)

Criminals who run unauthorized attacks

43.

Grey Hat hackers typically:

a)

Work as blue team defensive professionals

b)

Combine offensive and defensive team skills

c)

Deploy ransomware strictly for profit

d)

Act without authorization but not always malicious

44.

Red Hat is best described as:

a)

Users of tools without understanding

b)

Defensive security professionals

c)

Offensive security testers

d)

Beginners learning cybersecurity

45.

Which role aligns with Blue Hat in cybersecurity teams?

a)

Offensive penetration specialists

b)

Defensive security professionals

c)

Combination of red and blue skills

d)

Unauthorized risk-taking operators

46.

Purple Hat practitioners are known for:

a)

Using scripts without understanding

b)

Running bug bounty programs ethically

c)

Combining red and blue team skills

d)

Launching unauthorized attacks for gain

47.

Which statement best characterizes Script Kiddies?

a)

Learners formally trained in basics

b)

Criminals conducting data theft campaigns

c)

Authorized ethical penetration testers

d)

Use tools without understanding them

48.

Which principle of the CIA Triad ensures data is accessible to authorized users when needed?

a)

Integrity ensures accurate, trustworthy data

b)

Confidentiality ensures controlled data access

c)

Accountability ensures traceable user actions

d)

Availability ensures timely, reliable access

49.

Which domains are included in the scope of cybersecurity as commonly defined?

a)

Network, application, endpoint, data, cloud

b)

Hardware, finance, marketing, legal, sales

c)

Planning, budgeting, staffing, training, audits

d)

Servers, laptops, printers, cameras, phones

50.

Match each key term to its best description: Threat, Vulnerability, Exploit, Risk.

a)

Threat: safety control; Vulnerability: patch; Exploit: defense; Risk: zero-impact

b)

Threat: weakness; Vulnerability: attacker; Exploit: consequence; Risk: tool

c)

Threat: potential danger; Vulnerability: weakness; Exploit: method; Risk: likelihood-impact

d)

Threat: policy rule; Vulnerability: compliance; Exploit: audit; Risk: guarantee

51.

Which statement best reflects ethical practice in cybersecurity activities?

a)

Collect data broadly for faster investigations

b)

Get authorization and follow responsible disclosure

c)

Always test systems without telling anyone

d)

Share discovered vulnerabilities on social media

52.

What is a key message about the human element in cybersecurity?

a)

Humans are rarely a security concern

b)

Human actions are the strongest defense only

c)

Humans are both vulnerable and vital to defense

d)

Technology fully replaces human vigilance