NEW
Font size
WorksheetsWhat is Cybersecurity?
Total questions: 52
Worksheet time: 26mins
Which statement best defines cybersecurity in an IT context?
Protecting devices from physical damage only
Building faster computers for enterprise use
Protecting systems, networks, and data from unauthorized access
Sharing information freely across connected devices
Which example primarily represents network protection?
Installing antivirus on a laptop
Configuring a firewall for company intranet traffic
Using strong passwords for user accounts
Encrypting stored medical records
If one security element fails, what is the most likely consequence?
Data remains secure but networks fail
Systems improve due to redundancy
Only the failed element is affected
The entire system may be at risk
Which item is categorized as data in cybersecurity?
Smartphones and laptops
Passwords and medical files
Wi‑Fi routers in an office
Company intranet cabling
A helpful analogy compares a firewall to which home security feature?
CCTV watching activity
Open window inviting visitors
Front door lock protecting entry
Guard dog deterring intruders
Which personal risk is commonly triggered by phishing emails?
Improved multi-factor protection
Reduced spam in your inbox
Automatic device encryption
Bank theft from stolen credentials
At the organizational level, which event halted surgeries in UK hospitals?
IoT botnet expansion
Colonial Pipeline outage
Marriott loyalty breach
WannaCry ransomware attack
What was the reported average organizational cost of a data breach?
Nearly $44.5 million
Roughly $45,000
About $4.45 million
Around $445,000
Which impact illustrates national or global disruption from cyberattacks?
Gas shortages across the US
Password reuse on social media
Single hospital surgery delays
A company’s guest record loss
Password reuse across accounts most directly increases the risk of what?
Data deduplication
Hardware failure
Network latency
Account takeovers
Which principle of the CIA Triad focuses on preventing unauthorized data access?
Nonrepudiation of transactions
Integrity of stored records
Availability of online services
Confidentiality of information
Which control best supports confidentiality for messaging apps?
Regular full backups
Anycast DDoS routing
End-to-end encryption
Hash-based checksums
Integrity is primarily concerned with which outcome?
Data remaining accurate and unaltered
Users proving their identities
Systems staying online and responsive
Traffic being blocked from botnets
Which scenario illustrates a failure of integrity?
Encrypted messages cannot be read by outsiders
An employee loses a password
A hacker changes a bank transfer amount
A service goes down for two hours
Availability is best supported by which measures?
Digital signatures and hashes
Strong passwords and MFA
File-level access controls
Backups and DDoS defense
Which real-world event is cited as an availability issue?
2016 Mirai botnet outage
Ransomware encrypts local files
SSL certificate mismatch incident
Zero-day privilege escalation
Which domain focuses on protecting routers, switches, and traffic using controls like firewalls and VPNs?
Data and cloud security compliance
Network security and traffic defenses
Application security and code reviews
Endpoint security for user devices
Which practice best belongs to application security?
Secure coding and regular patching
Encrypting backups in cloud
Installing anti‑virus on laptops
Configuring network intrusion detection
Endpoint security primarily aims to protect which assets?
Laptops, phones, and IoT devices
Databases and cloud storage
Source code and build pipelines
Routers, firewalls, and switches
Which statement describes a key risk from the human element in cybersecurity?
Users click phishing links or use weak passwords
Firewalls eliminate all external threats
Encrypted data always prevents breaches
Unpatched APIs automatically exploit themselves
A company needs GDPR compliance and strong encryption for cloud workloads. Which domain best addresses this need?
Application security testing
Data and cloud security controls
Endpoint security hardening
Network security monitoring
Which action most likely reduces phishing success against employees?
Disabling all mobile device cameras
Using longer firewall rule lists
Adding more network switches to segments
Multi‑factor authentication and awareness training
Which option best defines a cybersecurity threat?
Weakness such as poor passwords or patches
Weapon that leverages a discovered weakness
Safeguard that reduces likelihood and impact
Potential danger from adversaries or disasters
In cybersecurity, what is a vulnerability?
Weakness like unpatched software or unlocked devices
Policy control like MFA or user training
Likelihood multiplied by incident impact
Method used to take advantage of a weakness
Which statement best describes an exploit?
A method or weapon using a vulnerability
A calculation combining likelihood and impact
A safeguard such as encryption or MFA
A potential source of harm to systems
Risk in cybersecurity is commonly understood as:
The controls deployed to prevent attacks
The tools used by attackers to break in
The chance and impact of a security incident
The presence of any system weakness
Which is an example of a control?
Outdated operating system left unpatched
Phishing email crafted to bypass filters
Encryption or training to reduce risk
Hackers planning ransomware campaign
Using the burglar analogy, which mapping is correct?
Control = burglar; Threat = CCTV cameras
Vulnerability = open window; Exploit = burglar climbing
Threat = lock; Control = burglar climbing
Risk = open window; Vulnerability = chance of theft
A company has weak passwords and gets hit by phishing. Which terms match these elements?
Weak passwords = exploit; phishing = control
Weak passwords = vulnerability; phishing = exploit
Weak passwords = control; phishing = threat
Weak passwords = threat; phishing = risk
Which role acts as the first responder by monitoring alerts and logs to quickly handle incidents like a brute-force attack on a VPN?
Security Auditor reviewing policy compliance
SOC Analyst monitoring alerts and responding fast
CISO overseeing strategy and executive communication
Security Engineer responsible for building defenses
A Security Engineer’s primary responsibility is best described as:
Building defenses like MFA, VPNs, and secure cloud
Checking GDPR and HIPAA compliance regularly
Triaging SIEM alerts during live incidents
Leading crisis management and briefing executives
Which role focuses on ensuring an organization meets legal and regulatory requirements such as GDPR and HIPAA?
SOC Analyst investigating real-time threats
Security Auditor conducting compliance checks
Security Engineer implementing technical controls
CISO leading strategy and crisis response
The CISO most accurately serves as:
Hands-on responder to VPN brute-force events
Strategic leader managing security crises and executives
Engineer deploying MFA and cloud infrastructure
Compliance reviewer performing regulatory audits
Which pairing of role and example duty is correct?
CISO — checks operational logs for brute-force attempts
Security Auditor — responds to SIEM alerts immediately
Security Engineer — implements multi-factor authentication
SOC Analyst — designs secure cloud architecture
Which action best aligns with ethical hacking when you discover a vulnerability during authorized testing?
Continue testing to fully exploit the weakness
Immediately cease testing and avoid further interaction
Copy sample user records to prove the issue
Post details online to warn potential victims
What is the primary reason to obtain written permission before testing a system?
It grants admin credentials automatically
It increases payment for bug reports
It ensures legality and defined scope
It improves test accuracy and speed
Which option best describes responsible disclosure?
Demonstrate impact with real stolen data
Report privately through official channels
Publicly share details before any fix
Sell exploit information to third parties
When collecting evidence of a vulnerability, what is the ethical approach to proof?
Document only what's necessary, avoid actual data
Record user sessions to show real impacts
Download full databases for stronger proof
Store credentials to validate access claims
Which behavior violates legal responsibilities in cybersecurity work?
Use security.txt to report issues
Scan random websites without consent
Stay within authorized boundaries
Practice in CTFs and cyber ranges
After privately reporting a vulnerability, what should you do until the issue is fixed?
Share findings publicly to pressure a fix
Keep information confidential and limit details
Test continuously to monitor system changes
Exfiltrate sample data to demonstrate severity
Which hacker type is authorized and focuses on improving security through penetration testing and bug bounties?
Black Hat hackers seeking personal gain
Script Kiddies using tools without knowledge
White Hat hackers with ethical authorization
Grey Hat hackers operating in legal grey areas
Which description best matches Black Hat hackers?
Defenders monitoring systems for threats
Learners experimenting under guidance
Authorized testers who report vulnerabilities
Criminals who run unauthorized attacks
Grey Hat hackers typically:
Work as blue team defensive professionals
Combine offensive and defensive team skills
Deploy ransomware strictly for profit
Act without authorization but not always malicious
Red Hat is best described as:
Users of tools without understanding
Defensive security professionals
Offensive security testers
Beginners learning cybersecurity
Which role aligns with Blue Hat in cybersecurity teams?
Offensive penetration specialists
Defensive security professionals
Combination of red and blue skills
Unauthorized risk-taking operators
Purple Hat practitioners are known for:
Using scripts without understanding
Running bug bounty programs ethically
Combining red and blue team skills
Launching unauthorized attacks for gain
Which statement best characterizes Script Kiddies?
Learners formally trained in basics
Criminals conducting data theft campaigns
Authorized ethical penetration testers
Use tools without understanding them
Which principle of the CIA Triad ensures data is accessible to authorized users when needed?
Integrity ensures accurate, trustworthy data
Confidentiality ensures controlled data access
Accountability ensures traceable user actions
Availability ensures timely, reliable access
Which domains are included in the scope of cybersecurity as commonly defined?
Network, application, endpoint, data, cloud
Hardware, finance, marketing, legal, sales
Planning, budgeting, staffing, training, audits
Servers, laptops, printers, cameras, phones
Match each key term to its best description: Threat, Vulnerability, Exploit, Risk.
Threat: safety control; Vulnerability: patch; Exploit: defense; Risk: zero-impact
Threat: weakness; Vulnerability: attacker; Exploit: consequence; Risk: tool
Threat: potential danger; Vulnerability: weakness; Exploit: method; Risk: likelihood-impact
Threat: policy rule; Vulnerability: compliance; Exploit: audit; Risk: guarantee
Which statement best reflects ethical practice in cybersecurity activities?
Collect data broadly for faster investigations
Get authorization and follow responsible disclosure
Always test systems without telling anyone
Share discovered vulnerabilities on social media
What is a key message about the human element in cybersecurity?
Humans are rarely a security concern
Human actions are the strongest defense only
Humans are both vulnerable and vital to defense
Technology fully replaces human vigilance
