wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

AP Cybersecurity: Cumulative Review 1.1 - 3.2

Total questions: 62

Worksheet time: 31mins

Name
Class
Date
1.

Which description best matches a low-skill adversary who uses tools created by others and is often motivated by money or recognition?

a)

An attacker who buys exploit kits online and deploys them without understanding how they work

b)

A government-employed cyber operative with advanced tools

c)

An employee abusing legitimate access

d)

An attacker motivated by political or social causes

2.

Which scenario best describes a hacktivist attack?

a)

Defacing a company’s website to raise awareness about an environmental issue

b)

Stealing customer data to sell on underground markets

c)

Launching ransomware purely for financial gain

d)

Testing systems under a government contract

3.

Why are insider adversaries especially dangerous to organizations?

a)

They already have legitimate access and credentials

b)

They only attack physical systems

c)

They rely entirely on automated tools

d)

They cannot be recruited by outsiders

4.

Which attack goal best aligns with cyberterrorism?

a)

Disrupting critical infrastructure like power grids or water treatment facilities

b)

Stealing intellectual property to resell

c)

Gaining social media followers

d)

Testing network defenses for weaknesses

5.

What activity is most commonly associated with transnational criminal organizations?

a)

Deploying ransomware and selling stolen corporate data

b)

Website defacement for awareness

c)

Penetration testing

d)

Espionage for political leverage

6.

Which characteristic best distinguishes state adversaries from other attackers?

a)

They are government-employed and have access to advanced cyber tools

b)

They focus only on small businesses

c)

They lack long-term objectives

d)

They avoid using malware

7.

Why must defenders continually adapt their security strategies?

a)

Adversaries constantly evolve their tactics, techniques, and procedures

b)

Cyber threats remain static

c)

Technology no longer changes

d)

Security controls never become outdated

8.

When does a threat become an actual attack?

a)

When a vulnerability is exploited to cause harm or disruption

b)

When a vulnerability exists

c)

When a threat is identified

d)

When a system is powered on

9.

Which example best illustrates social engineering?

a)

A fake email convincing a user to reset their password

b)

A firewall blocking incoming traffic

c)

Encrypting stored files

d)

Applying software patches

10.

Which tactic involves pretending to be someone with power over the target?

a)

Authority

b)

Scarcity

c)

Familiarity

d)

Consensus

11.

What is eavesdropping in a cyber context?

a)

Secretly capturing and copying digital communications

b)

Deleting stored files

c)

Altering login credentials

d)

Blocking network traffic

12.

What makes an on-path attack especially dangerous?

a)

Both parties believe they are communicating directly with each other

b)

The attack only affects availability

c)

The attacker cannot modify data

d)

The attack only targets wireless networks

13.

Which weakness enables injection attacks?

a)

Failure to validate user input

b)

Strong authentication

c)

Encrypted databases

d)

Network segmentation

14.

What distinguishes a DDoS attack from a DoS attack?

a)

The attack comes from many distributed devices

b)

The attack only targets websites

c)

The attack uses malware exclusively

d)

The attack is always internal

15.

How does credential harvesting work?

a)

Tricking users into entering real credentials on a fake login page

b)

Guessing passwords through brute force

c)

Stealing encrypted password files

d)

Installing keyloggers on servers

16.

What is the primary goal of reconnaissance?

a)

Gathering information about the target using publicly available sources

b)

Destroying data

c)

Installing malware

d)

Disabling defenses

17.

Which activity most often provides initial access?

a)

Social engineering or compromised credentials

b)

Log file deletion

c)

Data exfiltration

d)

Privilege escalation

18.

Why do adversaries establish persistence?

a)

To maintain long-term access without repeating the initial compromise

b)

To immediately destroy systems

c)

To alert defenders

d)

To encrypt backups

19.

What is the purpose of lateral movement?

a)

Accessing systems or accounts with higher privileges

b)

Removing evidence

c)

Blocking network traffic

d)

Collecting OSINT

20.

During which phase do attackers steal or destroy data?

a)

Taking action

b)

Reconnaissance

c)

Initial access

d)

Persistence

21.

Why do attackers attempt to erase logs near the end of an attack?

a)

To evade detection and investigation

b)

To gain initial access

c)

To scan the network

d)

To deploy ransomware

22.

What two factors determine risk during risk analysis?

a)

Likelihood of exploitation and severity of damage

b)

Cost and convenience

c)

Time and effort

d)

Public awareness and legality

23.

Which type of damage affects customer trust?

a)

Reputational damage

b)

Operational damage

c)

Technical damage

d)

Environmental damage

24.

What increases the likelihood that a vulnerability will be exploited?

a)

High target value and low difficulty

b)

Strong encryption

c)

Limited adversary motivation

d)

High detection rates

25.

Why must target value be considered from the attacker’s perspective?

a)

Different adversaries value different outcomes

b)

All attackers seek money

c)

Defenders define value objectively

d)

Value never changes

26.

Why are easy-to-exploit vulnerabilities especially dangerous?

a)

They are more likely to be used by attackers

b)

They require advanced tools

c)

They only affect insiders

d)

They are easier to detect

27.

Why do highly capable adversaries pose greater risk?

a)

They can exploit complex or unknown vulnerabilities

b)

They avoid advanced attacks

c)

They rely on chance

d)

They lack resources

28.

What is qualitative risk analysis?

a)

Describing risk using terms like low, medium, or high

b)

Assigning dollar values to risk

c)

Calculating probabilities mathematically

d)

Measuring system uptime

29.

What defines quantitative risk analysis?

a)

Assigning numerical or monetary values to risk

b)

Using descriptive language

c)

Ignoring impact

d)

Focusing only on likelihood

30.

Which option eliminates the activity causing risk entirely?

a)

Risk avoidance

b)

Risk transfer

c)

Risk mitigation

d)

Risk acceptance

31.

What is an example of risk transference?

a)

Purchasing cyber insurance

b)

Installing a firewall

c)

Accepting downtime

d)

Disabling a system

32.

What does risk mitigation focus on?

a)

Reducing likelihood or impact through controls

b)

Stopping operations entirely

c)

Shifting responsibility

d)

Ignoring threats

33.

What is residual risk?

a)

The remaining risk an organization accepts

b)

The initial risk level

c)

Unidentified threats

d)

Transferred risk

34.

Why is redundancy important to resiliency?

a)

It allows faster recovery after an incident

b)

It eliminates all attacks

c)

It reduces employee training

d)

It prevents insider threats

35.

Which backup site can resume operations almost immediately?

a)

Hot site

b)

Warm site

c)

Cold site

d)

Remote site

36.

How do system backups improve resiliency?

a)

They allow restoration to a pre-attack state

b)

They prevent malware

c)

They block attackers

d)

They encrypt traffic

37.

Why must organizations balance redundancy with cost?

a)

Redundancy increases expenses

b)

Backups eliminate all risks

c)

Employees resist redundancy

d)

Redundancy replaces security

38.

Which principle ensures only authorized access to data?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Accounting

39.

Which principle protects data from unauthorized modification?

a)

Integrity

b)

Confidentiality

c)

Availability

d)

Authorization

40.

What does availability focus on?

a)

Ensuring systems and data are accessible when needed

b)

Preventing impersonation

c)

Tracking user actions

d)

Encrypting communications

41.

What supports non-repudiation?

a)

Logging actions with responsible entities

b)

Password complexity

c)

Firewalls

d)

Redundancy

42.

What is authentication used for?

a)

Verifying identity

b)

Granting permissions

c)

Recording activity

d)

Encrypting data

43.

How does authorization differ from authentication?

a)

Authorization determines access level after identity is verified

b)

Authorization confirms identity

c)

Authentication logs actions

d)

Authentication assigns permissions

44.

What is the purpose of accounting?

a)

Recording and monitoring user actions

b)

Blocking attacks

c)

Encrypting files

d)

Granting access

45.

What best defines defense-in-depth?

a)

Using multiple layered security controls

b)

Relying on a single strong control

c)

Outsourcing all security

d)

Focusing only on prevention

46.

Why is layered defense effective?

a)

One control may stop an attacker if another fails

b)

It eliminates insider threats

c)

It guarantees security

d)

It reduces system cost

47.

Why must organizations consider cost-benefit when choosing controls?

a)

Controls should not cost more than the expected loss

b)

Cheaper controls are always better

c)

All controls must be implemented

d)

Cost does not matter

48.

Which controls are often prioritized first?

a)

High-probability, high-impact risks

b)

Low-impact risks

c)

Unlikely threats

d)

Convenient solutions

49.

Which attack involves following someone into a restricted area without their knowledge?

a)

Tailgating

b)

Piggybacking

c)

Shoulder surfing

d)

Dumpster diving

50.

Which attack relies on social engineering to gain physical access?

a)

Piggybacking

b)

Tailgating

c)

Card cloning

d)

Jamming

51.

What does shoulder surfing involve?

a)

Observing someone enter sensitive information

b)

Copying access cards

c)

Following employees

d)

Searching trash

52.

Why is physical access so dangerous?

a)

It can bypass many technical controls

b)

It only affects availability

c)

It cannot compromise data

d)

It requires advanced skills

53.

What is the goal of an evil-twin attack?

a)

Capturing traffic by impersonating a legitimate wireless network

b)

Blocking wireless signals

c)

Destroying access points

d)

Encrypting traffic

54.

What does a jamming attack target?

a)

Wireless availability

b)

Authentication

c)

Data integrity

d)

User permissions

55.

What enables an ARP poisoning attack?

a)

Sending fake ARP messages to misdirect traffic

b)

Strong encryption

c)

MAC filtering

d)

Firewalls

56.

Why is MAC flooding dangerous?

a)

It forces a switch to broadcast traffic

b)

It disables encryption

c)

It erases logs

d)

It installs malware

57.

What is the purpose of war driving?

a)

Locating and analyzing wireless networks

b)

Breaking encryption

c)

Installing access points

d)

Blocking traffic

58.

Why do organizations disable unnecessary router services like Telnet?

a)

To reduce attack surface

b)

To increase speed

c)

To simplify configuration

d)

To allow remote access

59.

What does port security on switches help prevent?

a)

Unauthorized devices connecting to the network

b)

Phishing attacks

c)

Power outages

d)

DNS poisoning

60.

Why do VPN policies often prohibit split tunneling?

a)

To prevent insecure traffic from bypassing protections

b)

To increase bandwidth

c)

To simplify authentication

d)

To allow personal device access

61.

Why is AES encryption required on secure wireless networks?

a)

It ensures intercepted traffic cannot be read

b)

It increases signal strength

c)

It hides SSIDs

d)

It blocks all attacks

62.

Why should organizations authenticate devices before network access?

a)

To prevent adversaries from joining internal networks

b)

To improve speed

c)

To reduce costs

d)

To enable beacon frames