wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Cybersecurity Knowledge Assessment

Total questions: 30

Worksheet time: 15mins

Name
Class
Date
1.

A SOC analyst observes a workstation generating outbound HTTPS traffic to an unfamiliar domain every 300 seconds. The domain resolves to different IP addresses over time, and no user activity aligns with the traffic. What does this behavior MOST likely indicate?

a)

Load-balanced web traffic

b)

Beaconing to a C2 infrastructure

c)

Legitimate cloud API communication

d)

Misconfigured DNS forwarding

2.

An organization is migrating to a zero trust architecture. Which implementation BEST aligns with zero trust principles?

a)

Allowing VPN access to all internal resources

b)

Enforcing MFA only for remote users

c)

Continuous authentication and authorization per session

d)

Deploying perimeter firewalls with IDS

3.

An analyst is validating whether a suspicious email was spoofed. Which TWO controls MOST directly verify sender authenticity?

a)

SPF

b)

DKIM

c)

TLS

d)

HTTPS

4.

Which tool provides the BEST method to safely observe runtime behavior of a suspicious executable?

a)

VirusTotal

b)

Wireshark

c)

Cuckoo Sandbox

d)

WHOIS

5.

Which host-based indicator MOST strongly suggests malware persistence?

a)

High memory utilization

b)

Abnormal DNS queries

c)

Unauthorized scheduled tasks

d)

Increased outbound traffic

6.

Which threat actor is MOST likely to use long-term stealth, custom tooling, and supply-chain compromise?

a)

Script kiddie

b)

Hacktivist

c)

Organized crime

d)

Nation-state APT

7.

Which source represents closed-source threat intelligence?

a)

CERT advisories

b)

Dark web forums

c)

Paid intelligence feeds

d)

Public GitHub repositories

8.

Which scripting language is MOST effective for automating Windows security response actions?

a)

Python

b)

Bash

c)

PowerShell

d)

Ruby

9.

Integrating SIEM, EDR, and threat-intel platforms into a unified dashboard BEST demonstrates:

a)

Defense in depth

b)

Single pane of glass

c)

Network segmentation

d)

Zero trust

10.

Which SOAR capability MOST reduces analyst fatigue during high alert volumes?

a)

Alert dashboards

b)

Threat visualization

c)

Automated response playbooks

d)

Log normalization

11.

Which scanning method provides the MOST comprehensive vulnerability results?

a)

External, non-credentialed

b)

Passive network scanning

c)

Credentialed internal scanning

d)

Web application fuzzing

12.

A security team wants vulnerability insight without impacting production systems. What is the BEST approach?

a)

Active scanning during off-hours

b)

Passive vulnerability scanning

c)

Aggressive fuzz testing

d)

Reverse engineering binaries

13.

A vulnerability has a low attack complexity and requires no privileges. What does this MOST strongly indicate?

a)

High exploitability

b)

Low severity

c)

Internal-only exposure

d)

False positive

14.

Which vulnerability allows attackers to execute database commands via unsanitized input?

a)

Reflected XSS

b)

CSRF

c)

SQL injection

d)

Directory traversal

15.

A Web Application Firewall (WAF) is classified as which control type?

a)

Managerial

b)

Operational

c)

Detective

d)

Technical

16.

Which risk response strategy involves acknowledging risk without remediation?

a)

Mitigate

b)

Transfer

c)

Avoid

d)

Accept

17.

Which tool BEST assesses misconfigurations in AWS environments?

a)

Nessus

b)

Metasploit

c)

Prowler

d)

Nmap

18.

Which practice focuses on identifying and reducing externally exposed assets?

a)

Threat modeling

b)

Attack surface management

c)

Defense in depth

d)

Zero trust

19.

Which secure coding practice MOST effectively prevents SQL injection?

a)

Output encoding

b)

Input length validation

c)

Parameterized queries

d)

Session tokens

20.

Which vulnerability tricks a server into making unauthorized internal requests?

a)

XXE

b)

CSRF

c)

SSRF

d)

RFI

21.

Which framework maps adversary tactics, techniques, and procedures?

a)

Cyber Kill Chain

b)

MITRE ATT&CK

c)

Diamond Model

d)

OSSTMM

22.

What ensures evidence integrity during incident investigations?

a)

Encryption

b)

Chain of custody

c)

Data masking

d)

Obfuscation

23.

Isolating infected systems occurs during which IR phase?

a)

Preparation

b)

Detection

c)

Containment

d)

Recovery

24.

Which post-incident activity determines WHY the incident occurred?

a)

Threat hunting

b)

Root cause analysis

c)

Vulnerability scanning

d)

Asset discovery

25.

Which activity MOST improves organizational readiness for future incidents?

a)

Penetration testing

b)

Tabletop exercises

c)

Threat intelligence sharing

d)

Vulnerability scanning

26.

Which metric measures how quickly incidents are identified?

a)

MTTR

b)

MTTD

c)

SLA

d)

KPI

27.

Which report section is MOST appropriate for executive leadership?

a)

Packet captures

b)

Raw logs

c)

Executive summary

d)

Hash values

28.

Which factor MOST commonly delays remediation efforts?

a)

CVSS calculation

b)

Asset discovery

c)

Legacy systems

d)

Automation

29.

Who MUST be involved when an incident may require public disclosure?

a)

SOC analysts

b)

Legal and public relations

c)

Developers

d)

Network engineers

30.

Which metric BEST helps assess SOC workload trends?

a)

Alert volume

b)

Encryption strength

c)

Patch cadence

d)

Throughput