WorksheetsCybersecurity Quiz
Total questions: 40
Worksheet time: 20mins
What is the primary goal of cybersecurity?
To eliminate all cyber threats
To protect information systems and data
To monitor internet traffic
To prevent hardware failure
Which component of the CIA triad ensures data is accurate and unaltered?
Confidentiality
Integrity
Availability
Authentication
Confidentiality is best described as:
Ensuring systems are always online
Preventing unauthorized access to information
Ensuring data accuracy
Backing up data regularly
Availability in cybersecurity means:
Data is encrypted
Systems are patched
Information is accessible when needed
Users are authenticated
Which of the following is an example of an information asset?
Power cable
Employee database
Air conditioner
Office chair
Who is primarily responsible for an organization’s overall security strategy?
Security Analyst
Security Engineer
IT Support
Chief Information Security Officer (CISO)
Risk management mainly involves:
Buying security tools
Identifying, analyzing, and mitigating risks
Hiring security staff
Blocking all threats
Which document defines high-level security expectations?
Procedure
Standard
Policy
Guideline
ISO/IEC 27001 primarily focuses on:
Network configuration
Information Security Management Systems (ISMS)
Ethical hacking
Software development
Which framework is developed by NIST?
ISO 27001
COBIT
NIST Cybersecurity Framework
ITIL
Ghana’s data protection law focuses mainly on:
Cyber warfare
Data privacy and personal data protection
Software licensing
Intellectual property
Malware is best defined as:
Hardware failure
Malicious software designed to harm systems
Legal software misuse
Network congestion
Phishing attacks mainly attempt to:
Destroy data
Gain unauthorized physical access
Trick users into revealing sensitive information
Scan open ports
An insider threat originates from:
Hackers abroad
Natural disasters
Employees or trusted users
Government agencies
A vulnerability is:
A type of attack
A system weakness that can be exploited
A threat actor
A security policy
Which phase comes first in vulnerability management?
Remediation
Reporting
Identification
Verification
The total points where an attacker can try to enter a system is called:
Threat vector
Attack surface
Risk profile
Control plane
Security policies are an example of:
Technical controls
Physical controls
Administrative controls
Detective controls
Firewalls are considered:
Administrative controls
Technical controls
Physical controls
Corrective controls
CCTV cameras are an example of:
Preventive control
Detective control
Corrective control
Technical control
Defense-in-depth means:
One strong security control
Multiple layers of security controls
Outsourcing security
Only technical security
CIS Controls are best described as:
Legal requirements
Military standards
Best-practice security safeguards
Software tools
AAA stands for:
Authentication, Authorization, Accounting
Access, Audit, Availability
Authentication, Access, Auditing
Authorization, Audit, Access
Which access control model assigns permissions based on job roles?
DAC
MAC
RBAC
ABAC
A fingerprint scanner uses which authentication factor?
Knowledge
Possession
Inherence
Location
A strong password policy helps mainly with:
Availability
Confidentiality
Integrity
Auditing
Which stage removes user access when employment ends?
Provisioning
Authentication
De-provisioning
Authorization
The main purpose of encryption is to ensure:
Integrity
Availability
Confidentiality
Authentication
AES is an example of:
Asymmetric encryption
Symmetric encryption
Hashing algorithm
Digital signature
RSA is classified as:
Symmetric algorithm
Hash function
Asymmetric algorithm
Stream cipher
Hashing is mainly used to:
Encrypt data
Decrypt data
Verify data integrity
Share keys
PKI primarily manages:
Passwords
Firewalls
Digital certificates and keys
Network traffic
Which OSI layer does a firewall primarily operate on?
Physical
Data Link
Network
Application
IDS stands for:
Intrusion Detection System
Internet Defense Service
Internal Data Scanner
Intrusion Defense Software
A VPN mainly provides:
Faster internet
Secure remote communication
Network monitoring
Port scanning
Packet sniffing is used to:
Destroy packets
Capture and analyze network traffic
Block IP addresses
Encrypt data
A Man-in-the-Middle attack aims to:
Shut down servers
Intercept communication between two parties
Delete databases
Scan ports
The main role of a SOC is to:
Develop software
Monitor and respond to security incidents
Train employees
Manage databases
SIEM tools are used for:
Encryption
Log collection and correlation
Access control
Software testing
Patch management helps to:
Increase system speed
Fix known vulnerabilities
Improve user experience
Replace hardware
