wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Cybersecurity and Vulnerability Quiz

Total questions: 15

Worksheet time: 8mins

Name
Class
Date
1.

A water treatment facility recently discovered that an attacker gained remote access to a pump control module. The system affected is a Programmable Logic Controller (PLC). Which type of environment has been compromised?

a)

Traditional IT environment

b)

Operational Technology (OT) system

c)

Cloud-managed ICS environment

d)

Data analytics cluster

2.

A hospital is conducting vulnerability scanning on its patient monitoring ICS network. Analysts must avoid interrupting real-time vital-sign equipment. Which type of scanning or operational consideration is MOST critical?

a)

Run automated exploitation scripts

b)

Schedule scans during peak patient hours

c)

Use nonintrusive and low-impact scanning methods

d)

Block all outbound traffic during scans

3.

A vulnerability report lists: Attack Vector: Network (N) Privileges Required: None (N) User Interaction: None (N) Confidentiality Impact: High (H) Given these metrics, which statement is MOST accurate regarding the vulnerability?

a)

It is low risk because it requires physical access

b)

It can be remotely exploited without user interaction

c)

It cannot be exploited unless the attacker has admin privileges

d)

It will always receive an informational score

4.

A regional power grid operator discovers that a SCADA field device is sending inconsistent readings. An analyst suspects tampering. Which statement BEST explains why this situation is critical?

a)

SCADA systems only store logs and are disconnected from operations

b)

SCADA failures can disrupt command and control over critical infrastructure

c)

SCADA devices cannot be remotely accessed

d)

SCADA systems are part of cloud infrastructure

5.

An analyst needs a standardized way to identify misconfigurations and software flaws across multiple vulnerability scanners. Which framework should they rely on?

a)

ISO 27001

b)

SCAP

c)

OWASP

d)

COBIT

6.

An organization is reviewing vulnerabilities in its ICS network. One vulnerability is scored as a 9.8 Critical, but exploitation would require physically accessing a high-security area. What CVSS limitation does this highlight?

a)

Scores cannot exceed 8.0 in OT systems

b)

Temporal metrics overwrite base metrics

c)

CVSS scoring may not reflect practical exploitability

d)

Critical scores always require remote vectors

7.

During a risk review, analysts observe that multiple infrastructure sectors—transportation, power, and communications—could all be affected by a single OT system outage. What concept does this BEST illustrate?

a)

Patch dependency

b)

Infrastructure interdependency

c)

Defense-in-depth strategy

d)

SCADA segmentation

8.

An analyst is reviewing a CVE entry in the National Vulnerability Database. The entry displays both a Base Score and a CVSS Vector String. What is the MAIN purpose of reviewing the vector string?

a)

It lists available patches

b)

It identifies the vulnerability’s exploit kit

c)

It breaks down how the score was calculated

d)

It determines which vendor created the software

9.

A manufacturer discovers a vulnerability that has a Medium base score but becomes High when evaluated for its specific environment. What CVSS metric category explains this change?

a)

Base

b)

Temporal

c)

Environmental

d)

Exploit code maturity

10.

An ICS security analyst is tasked with prioritizing vulnerabilities for remediation. Which factor should be considered to ensure the most critical OT risks are addressed first?

a)

Frequency of vulnerability scanner updates

b)

Number of affected IT users

c)

Vendor patch release date

d)

CVSS Environmental score relevance

11.

During a security assessment, an analyst notes that a vulnerability in a PLC can be exploited remotely with no authentication. Which CVSS metric would MOST influence the severity score in this scenario?

a)

Attack Vector

b)

Exploit Code Maturity

c)

Report Confidence

d)

Remediation Level

12.

An ICS operator notices that a PLC is responding to commands with unexpected delays. What is the MOST likely security concern in this scenario?

a)

PLC delays are always caused by hardware failure

b)

Delayed responses may indicate unauthorized access or manipulation

c)

PLC devices are immune to network-based attacks

d)

ICS networks do not require monitoring for anomalies

13.

A utility company wants to ensure its ICS vulnerability scans do not disrupt critical operations. Which scanning approach should be prioritized?

a)

Use aggressive scanning techniques for faster results

b)

Perform scans during system maintenance windows

c)

Disable all network traffic before scanning

d)

Run scans without considering device sensitivity

14.

Jasmine is responsible for planning vulnerability scans in an ICS environment at her facility. To minimize operational risk, which of the following actions is MOST important for her to consider?

a)

Ignore device manufacturer recommendations

b)

Coordinate scans with system operators and maintenance schedules

c)

Conduct scans during periods of peak activity

d)

Use only default scanning profiles

15.

James is responsible for managing the security of an industrial control system (ICS) at a manufacturing plant. He learns about a vulnerability that requires no user interaction, no privileges, and can be exploited over the network. What does this imply about the potential impact?

a)

It is a low-severity issue

b)

Only administrators are at risk

c)

Physical access is required for exploitation

d)

The vulnerability is likely to be easily exploited remotely