wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Cybersecurity Quiz

Total questions: 41

Worksheet time: 21mins

Name
Class
Date
1.

Fill in the blank: Cybersecurity aims to protect networks, devices, people, and data from _____ or unauthorized access.

a)

criminal exploitation

b)

changing business priorities

c)

poor financial management

d)

market shifts

2.

A security professional collaborates with information technology teams to deploy an application that helps identify risks and vulnerabilities. What does this scenario describe?

a)

Upgrading network capacity

b)

Installing detection software

c)

Conducting a security audit

d)

Ethical hacking

3.

Which of the following entities may be an internal threat to an organization? Select three answers.

a)

Trusted partners

b)

Vendors

c)

Customers

d)

Employees

4.

Fill in the blank: Identity theft is the act of stealing _____ to commit fraud while impersonating a victim.

a)

hardware

b)

business records

c)

personal information

d)

trade secrets

5.

What is regulatory compliance?

a)

Sites and services that require complex passwords to access

b)

Threats and risks from employees and external vendors

c)

Laws and guidelines that require implementation of security standards

d)

Expenses and fines associated with vulnerabilities

6.

Which of the following proficiencies are examples of technical skills? Select two answers.

a)

Communicating with employees

b)

Prioritizing collaboration

c)

Automating tasks with programming

d)

Applying computer forensics

7.

Fill in the blank: Security _____ and event management (SIEM) tools enable security professionals to identify and analyze threats, risks, and vulnerabilities.

a)

information

b)

improvement

c)

identity

d)

intelligence

8.

What do security professionals typically do with SIEM tools?

a)

Identify and analyze security threats, risks, and vulnerabilities

b)

Locate and preserve criminal evidence

c)

Identify threat actors and their locations

d)

Educate others about potential security threats, risks, and vulnerabilities

9.

Which of the following threats are examples of malware? Select two answers.

a)

Error messages

b)

Worms

c)

Bugs

d)

Viruses

10.

What historical event used a malware attachment to steal user information and passwords?

a)

Morris worm

b)

LoveLetter attack

c)

Equifax breach

d)

Brain virus

11.

Fill in the blank: Exploiting human error to gain access to private information is an example of _____ engineering.

a)

digital

b)

network

c)

social

d)

communication

12.

A security professional is asked to teach employees how to avoid inadvertently revealing sensitive data. What type of training should they conduct?

a)

Training about security architecture

b)

Training about social engineering

c)

Training about business continuity

d)

Training about network optimization

13.

Which domain involves defining security goals and objectives, risk mitigation, compliance, business continuity, and the law?

a)

Security architecture and engineering

b)

Security and risk management

c)

Security assessment and testing

d)

Identity and access management

14.

A security professional is optimizing data security by ensuring that effective tools, systems, and processes are in place. Which domain does this scenario describe?

a)

Identity and access management

b)

Security architecture and engineering

c)

Security and risk management

d)

Communication and network security

15.

A cybersecurity analyst needs to collect data from multiple places to analyze filtered events and patterns. What type of tool should they use?

a)

network protocol analyzer (packet sniffer)

b)

Playbook

c)

Linux operating system

d)

Security information and event management (SIEM)

16.

Fill in the blank: Security professionals use _____ to help them manage a security incident before, during, and after it has occurred.

a)

charts

b)

playbooks

c)

spreadsheets

d)

programming

17.

A security professional must deactivate user accounts when employees leave the company to remove access to sensitive information and resources. Which domain does this scenario describe?

a)

Security and risk management

b)

Security assessment and testing

c)

Communication and network security

d)

Identity and access management

18.

As a security analyst, you are tasked with auditing your organization's network to identify security related issues. How might a network protocol analyzer (packet sniffer) help you perform this task?

a)

By automating tasks that reduce human error

b)

By removing malware and viruses from the network

c)

By simulating attacks on connected devices

d)

By capturing and analyzing data traffic on the network

19.

Fill in the blank: A security professional has been tasked with implementing strict password policies on workstations to reduce the risk of password theft. This is an example of _____.

a)

hardware changes

b)

security teams

c)

networking regulations

d)

security controls

20.

You are helping your security team consider risk when setting up a new software system. Using the CIA triad, you focus on confidentiality, availability, and what else?

a)

Integrity

b)

Intelligence

c)

Inconsistencies

d)

Information

21.

Fill in the blank: _____ are items perceived as having value to an organization.

a)

Assets

b)

Incidents

c)

Lifecycles

d)

Alerts

22.

Fill in the blank: Some of the most dangerous threat actors are _____ because they often know where to find sensitive information, can access it, and may have malicious intent.

a)

disgruntled employees

b)

past vendors

c)

dissatisfied customers

d)

senior partners

23.

A security professional is updating software on a coworker’s computer and unexpectedly encounters an email containing private information about another employee. The security professional chooses to follow company guidelines regarding privacy protections and does not share the information with coworkers. Which concept does this scenario describe?

a)

Preserving evidence

b)

Business email compromise

c)

Security ethics

d)

Security controls

24.

Fill in the blank: The ethical principle of _____ involves safeguarding an organization’s human resources records that contain personal details about employees.

a)

non-bias

b)

privacy protection

c)

unlimited access

d)

honesty

25.

Which of the following describes a set of rules for data protection that are established and enforced by a governing authority?

a)

Laws

b)

Guidelines

c)

Protections

d)

Restrictions

26.

Fill in the blank: Linux relies on a(n) _____ as the primary user interface.

a)

dashboard

b)

command line

c)

ciphertext

d)

error log

27.

Fill in the blank: A database is a _____ of organized data stored in a computer system.

a)

collection

b)

frame

c)

visualization

d)

model

28.

Fill in the blank: Security _____ refers to an organization’s ability to manage its defense of critical assets and data, as well as its ability to react to change.

a)

governance

b)

posture

c)

architecture

d)

hardening

29.

How does business continuity enable an organization to maintain everyday productivity?

a)

By outlining faults to business policies

b)

By exploiting vulnerabilities

c)

By establishing risk disaster recovery plans

d)

By ensuring return on investment

30.

A security analyst ensures that employees are able to review only the data they need to do their jobs. Which security domain does this scenario relate to?

a)

Security assessment and testing

b)

Identity and access management

c)

Software development security

d)

Communication and network security

31.

Fill in the blank: The software development security domain involves the use of the software development ___, which is an efficient process used by teams to quickly build software products and services.

a)

staging

b)

operations

c)

lifecycle

d)

functionality

32.

A business experiences an attack. As a result, its critical business operations are interrupted and it faces regulatory fines. What type of consequence does this scenario describe?

a)

Reputation

b)

Financial

c)

Practical

d)

Identity

33.

Fill in the blank: In the Risk Management Framework (RMF), the _____ step involves knowing how systems are operating and assessing whether or not those systems support the organization's security goals.

a)

authorize

b)

implement

c)

monitor

d)

categorize

34.

How do organizations use security frameworks to develop an effective security posture?

a)

As a guide to reduce risk and protect data and privacy

b)

As a policy to support employee training initiatives

c)

As a guide to identify threat actor strategies

d)

As a policy to protect against phishing campaigns

35.

Fill in the blank: A security professional uses _____ to verify that an employee has permission to access a resource.

a)

admission

b)

authorization

c)

encryption

d)

integrity

36.

Which of the following is an example of biometrics?

a)

Encryption

b)

Password

c)

Security framework

d)

Fingerprint

37.

You work as a security analyst for a supply chain organization and need to confirm all inventory data is correct, authentic, and reliable. Which core principle of the CIA triad are you using?

a)

Integrity

b)

Availability

c)

Credibility

d)

Confidentiality

38.

A security team has just finished addressing a recent security incident. They now conduct tests to ensure that all of their repairs were successful. Which OWASP principle does this scenario describe?

a)

Fix security issues correctly

b)

Separation of duties

c)

Principle of least privilege

d)

Minimize attack surface area

39.

Fill in the blank: The planning elements of an internal security audit include establishing scope and _____, then conducting a risk assessment.

a)

compliance

b)

goals

c)

controls

d)

limitations

40.

A security analyst performs an internal security audit. They review their company’s existing assets, then evaluate potential risks to those assets. Which aspect of a security audit does this scenario describe?

a)

Communicating results

b)

Completing a controls assessment

c)

Establishing the scope and goals

d)

Assessing compliance

41.

Fill in the blank: To assess the performance of a software application, security professionals use _____, including response time, availability, and failure rate.

a)

metrics

b)

dashboards

c)

logs

d)

SIEM tools