wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

L 1 2 3 4

Total questions: 100

Worksheet time: 50mins

Name
Class
Date
1.

Which type of security control includes alarms, gateways, locks, and guards to detect access to premises and hardware?

a)

Physical control

b)

Technical control

c)

Administrative control

d)

Logical control

2.

What type of security control discourages attackers psychologically, e.g. warning signs or legal penalty?

a)

Deterrent control

b)

Preventive control

c)

Detective control

d)

Corrective control

3.

What term describes the property of a secure network where a sender cannot deny having sent a message?

a)

Non-repudiation

b)

Confidentiality

c)

Integrity

d)

Availability

4.

Which property ensures that systems operate continuously and authorized users can access data?

a)

Availability

b)

Confidentiality

c)

Integrity

d)

Authentication

5.

What does NIST stand for in the context of information security?

a)

National Institute of Standards and Technology

b)

National Information Security Taskforce

c)

Network Institute for Security Technologies

d)

National Internet Security Team

e)

National Institute of Secure Transactions

6.

Which of the ISO standards are about personal data and privacy?

a)

ISO 27701

b)

ISO 9001

c)

ISO 14001

d)

ISO 50001

7.

Which security business function helps resolve tensions between IT and programming divisions in a growing business?

a)

DevSecOps

b)

Penetration Testing

c)

Incident Response

d)

Network Monitoring

8.

Which security business function helps resolve tensions between IT and programming divisions in a growing business (Variant 2)?

a)

DevSecOps

b)

Penetration Testing

c)

Network Monitoring

d)

Incident Response

9.

Who ensures fairness and referees between red and blue team activities?

a)

White cell

b)

Red cell

c)

Blue cell

d)

Green cell

10.

What describes a “script kiddie”?

a)

A user of pre-made tools without deep technical understanding

b)

A professional hacker with advanced skills

c)

A developer who writes original security software

d)

A cybersecurity expert specializing in penetration testing

11.

Which type of malware is self-replicating and spreads across networks without requiring user interaction?

a)

Worm

b)

Trojan Horse

c)

Spyware

d)

Adware

12.

Which risk arises when competitors use cyber espionage?

a)

Theft of intellectual property or disruption or damage to reputation

b)

Increase in employee satisfaction

c)

Improvement in public relations

d)

Reduction in operational costs

13.

Which type of threat intelligence platform is usually subscription-based and closed?

a)

Closed or proprietary threat intelligence platforms

b)

Open-source threat intelligence platforms

c)

Community-driven threat intelligence platforms

d)

Government-sponsored threat intelligence platforms

14.

Which of the following is an example of an attack vector (multiple correct answers)?

a)

Removable media

b)

Direct physical access

c)

Email

15.

What resource level usually enables the most sophisticated threat actors?

a)

Substantial budget and funding (nation states or criminal syndicates)

b)

Limited access to open-source tools

c)

Basic technical skills with minimal funding

d)

Volunteer-based resources

16.

Which statement best describes a vulnerability in the context of security assessments?

a)

A weakness that could be exploited to cause a breach

b)

A tool used to prevent unauthorized access

c)

A method for encrypting sensitive data

d)

A process for monitoring network traffic

17.

Which term describes an unencrypted message?

a)

Plaintext

b)

Ciphertext

c)

Hash

d)

Token

18.

Which hashing algorithm generates a 256-bit digest?

a)

SHA-256

b)

MD5

c)

SHA-1

d)

RIPEMD-160

19.

ROT13 is an example of which type of cipher?

a)

Substitution

b)

Transposition

c)

Stream

d)

Block

20.

Which encryption method uses the same secret key for both encryption and decryption?

a)

Symmetric

b)

Asymmetric

c)

Public Key

d)

Hashing

21.

Which encryption uses a public and private key pair?

a)

Asymmetric

b)

Symmetric

c)

Hashing

d)

Steganography

22.

What cryptographic function is created by combining hashing with private key encryption?

a)

Digital Signature

b)

Symmetric Encryption

c)

Hash Function

d)

Public Key Infrastructure

23.

Which algorithm allows Alice and Bob to derive a shared secret over an insecure channel?

a)

Diffie-Hellman

b)

RSA

c)

SHA-256

d)

AES

24.

Which technique hides information inside images or audio?

a)

Steganography

b)

Cryptography

c)

Watermarking

d)

Compression

25.

Which authority validates digital certificates?

a)

Certificate Authority

b)

Domain Registrar

c)

Internet Service Provider

d)

Web Browser

26.

What are the three components of the CIA triad?

a)

Confidentiality, Integrity, Availability.

b)

Control, Investigation, Authentication.

c)

Confidentiality, Investigation, Authorization.

d)

Control, Integrity, Authentication.

27.

Name two responsibilities of a CISO.

a)

Security strategy and governance; incident response oversight; risk management; policy creation (any two).

b)

Managing company finances; overseeing marketing campaigns; product development; customer service (any two).

c)

Organizing company events; handling payroll; designing office layouts; planning vacations (any two).

d)

Supervising cafeteria staff; maintaining office plants; scheduling janitorial services; ordering office supplies (any two).

28.

Give one example of a technical control and one operational control.

a)

Technical: firewall or encryption. Operational: security awareness training or change-management procedures.

b)

Technical: password reuse. Operational: ignoring security policies.

c)

Technical: using outdated software. Operational: disabling antivirus.

d)

Technical: sharing passwords. Operational: skipping security audits.

29.

What is the difference between preventive and detective controls?

a)

Preventive controls stop attacks before they happen (e.g., access control); detective controls identify or record attacks in progress or after (e.g., IDS, logs).

b)

Preventive controls only monitor attacks, while detective controls block them before they happen.

c)

Preventive controls are used after an attack, while detective controls are used before an attack.

d)

Preventive controls and detective controls serve the same purpose and are interchangeable.

30.

What kind of risks does OWASP focus on?

a)

Web application and API security risks (OWASP Top 10).

b)

Physical security risks in data centers.

c)

Risks related to hardware manufacturing defects.

d)

Financial risks in banking operations.

31.

What is the purpose of CIS Benchmarks?

a)

Provide secure configuration guidance and checklists to harden systems.

b)

Monitor network traffic for suspicious activity.

c)

Develop new operating systems for commercial use.

d)

Create malware detection algorithms.

32.

What is SOC 2 Type II used to demonstrate?

a)

That a service provider not only has controls designed but also operating effectively over time.

b)

That a service provider is compliant with GDPR regulations.

c)

That a service provider has achieved ISO 27001 certification.

d)

That a service provider only has controls designed, not necessarily operating effectively over time.

33.

Name three competencies a security professional should have (from the slides).

a)

Risk assessments/testing; log auditing; business continuity planning (any three).

b)

Graphic design; social media management; event planning.

c)

Sales forecasting; customer service; product development.

d)

Interior decorating; fashion consulting; travel planning.

34.

Which control functional type operates after an attack to restore systems?

a)

Corrective control.

b)

Preventive control.

c)

Detective control.

d)

Compensating control.

35.

Combining frameworks, controls, and regulations is important for an organization because:

a)

it helps ensure comprehensive risk management and compliance.

b)

it increases operational costs without benefits.

c)

it complicates decision-making unnecessarily.

d)

it reduces the need for employee training.

36.

A framework helps an organization's security posture by:

a)

Providing structured guidelines and best practices for security.

b)

Allowing unrestricted access to all systems.

c)

Eliminating the need for security policies.

d)

Guaranteeing complete immunity from cyber threats.

37.

Integrity in information security is defined as:

a)

Ensuring that information is accurate and unaltered.

b)

Preventing unauthorized access to information.

c)

Guaranteeing the availability of information when needed.

d)

Encrypting data to protect its confidentiality.

38.

A SOC is primarily established for which of the following purposes?

a)

To monitor and respond to security threats

b)

To develop software applications

c)

To manage company finances

d)

To oversee employee recruitment

39.

A compensating control is:

a)

A security measure that substitutes for a primary control when it cannot be implemented, such as using CCTV cameras when physical guards are not available.

b)

A control that is always more expensive than the primary control.

c)

A control that eliminates all risks without any exceptions.

d)

A control that is only used in financial audits.

40.

NIST CSF stands for ______ and is useful because ______.

a)

National Institute of Standards and Technology Cybersecurity Framework; it provides guidelines for managing and reducing cybersecurity risk.

b)

National Information Security Taskforce Cybersecurity Formula; it helps in creating passwords.

c)

Network Infrastructure Security Technology Control System; it is used for monitoring network traffic.

d)

National Internet Security Team Cybersecurity Foundation; it is useful for training employees.

41.

Which regulation focuses on protecting personal data of EU residents?

a)

GDPR

b)

HIPAA

c)

FERPA

d)

CCPA

42.

The main goal of security testing is:

a)

to identify vulnerabilities in a system

b)

to improve the user interface

c)

to increase system speed

d)

to reduce development costs

43.

Which of the following lists three types of activities that belong to security testing?

a)

Vulnerability scanning, penetration testing, security auditing

b)

Unit testing, integration testing, system testing

c)

Performance testing, usability testing, reliability testing

d)

Code review, documentation, deployment

44.

The objective of a Vulnerability Assessment is:

a)

To identify and evaluate security weaknesses in a system

b)

To install new software updates

c)

To monitor network traffic continuously

d)

To create user accounts

45.

A pentest differs from a VA in that:

a)

A pentest simulates real-world attacks, while a VA identifies vulnerabilities without exploiting them.

b)

A pentest only scans for vulnerabilities, while a VA exploits them.

c)

A pentest is less thorough than a VA.

d)

A pentest is performed without any tools, while a VA uses automated tools.

46.

The goal of a penetration test is:

a)

to identify and exploit vulnerabilities in a system to assess its security.

b)

to install new software on a system.

c)

to improve system performance.

d)

to backup data regularly.

47.

Describe the analogy of a house and a safe for VA vs Pentest.

a)

VA is like checking if the house is locked; Pentest is like trying to break into the safe.

b)

VA is like building a house; Pentest is like buying a safe.

c)

VA is like painting the house; Pentest is like cleaning the safe.

d)

VA is like owning a house; Pentest is like renting a safe.

48.

A Red Team’s main objective is:

a)

to identify and exploit vulnerabilities in systems to improve security

b)

to monitor network traffic for suspicious activity

c)

to develop security policies and procedures

d)

to provide technical support to end users

49.

TTD and TTM are used for what purpose in Red Team engagements?

a)

Measuring detection and mitigation times

b)

Identifying vulnerabilities in code

c)

Testing network bandwidth

d)

Evaluating employee satisfaction

50.

The Blue Team are responsible for which of the following activities?

a)

Defending systems against cyber attacks

b)

Launching cyber attacks on other organizations

c)

Developing new software applications

d)

Managing company finances

51.

The purpose of a Purple Team is:

a)

To facilitate collaboration between Red and Blue Teams for improved cybersecurity.

b)

To conduct penetration testing independently.

c)

To manage network infrastructure.

d)

To develop security policies without testing.

52.

A Rules of Engagement document is important before a pentest because:

a)

it defines the scope, boundaries, and expectations for the test

b)

it provides a list of vulnerabilities to exploit

c)

it guarantees the success of the pentest

d)

it eliminates the need for any legal agreements

53.

List four common pentesting methodologies.

a)

OWASP, NIST SP 800-115, OSSTMM, PTES.

b)

ISO 27001, COBIT, ITIL, PCI DSS.

c)

Agile, Scrum, Waterfall, DevOps.

d)

GDPR, HIPAA, FERPA, SOX.

54.

According to PTES, what comes after “Exploitation”?

a)

Post-Exploitation, then Reporting.

b)

Reconnaissance, then Scanning.

c)

Vulnerability Assessment, then Exploitation.

d)

Reporting, then Reconnaissance.

55.

What does the OWASP Testing Guide focus on?

a)

Testing web applications and services for security issues using global best practices.

b)

Designing user interfaces for web applications.

c)

Optimizing web applications for performance and speed.

d)

Developing mobile applications using secure coding techniques.

56.

Why must ethical hackers respect the testing scope?

a)

Because testing outside the agreed scope is illegal and unauthorized.

b)

Because it helps hackers gain more access to sensitive data.

c)

Because it allows hackers to bypass security protocols.

d)

Because it makes the hacking process faster.

57.

What is the difference between a threat and a vulnerability?

a)

A threat is a potential attack; a vulnerability is the weakness that the threat can exploit.

b)

A vulnerability is a potential attack; a threat is the weakness that the vulnerability can exploit.

c)

A threat and a vulnerability are the same thing in cybersecurity.

d)

A threat is a security patch; a vulnerability is a type of malware.

58.

What creates a risk in cybersecurity?

a)

When a threat successfully exploits a vulnerability.

b)

When all vulnerabilities are patched.

c)

When there are no threats present.

d)

When security policies are strictly followed.

59.

Name two academic sources for cybersecurity research.

a)

IEEE Xplore and ACM Digital Library (also arXiv).

b)

Reddit and Facebook.

c)

Wikipedia and Quora.

d)

YouTube and Instagram.

60.

What is the purpose of RFCs in cybersecurity?

a)

Define standards and best practices for Internet and security protocols.

b)

Monitor network traffic for malicious activity.

c)

Encrypt data to prevent unauthorized access.

d)

Detect and respond to cyber threats in real time.

61.

Give two well-known cybersecurity conferences.

a)

DEF CON and Black Hat (others: RSA, USENIX).

b)

Comic-Con and E3 (others: PAX, Gamescom).

c)

CES and MWC (others: IFA, Computex).

d)

Sundance and Cannes (others: TIFF, Berlinale).

62.

What does STIX stand for and what does it do?

a)

Structured Threat Information Expression – standard format for sharing threat data.

b)

Secure Threat Intelligence Exchange – protocol for encrypting threat reports.

c)

Systematic Threat Investigation Xchange – tool for analyzing cyber attacks.

d)

Standardized Threat Indicator XML – markup language for malware signatures.

63.

What is TAXII used for?

a)

The protocol for transporting structured threat information (STIX data).

b)

A tool for encrypting email messages.

c)

A method for scanning network vulnerabilities.

d)

A protocol for wireless communication.

64.

Which U.S. government service enables automated cyber threat data sharing?

a)

AIS (Automated Indicator Sharing) by DHS.

b)

USPS (United States Postal Service)

c)

IRS (Internal Revenue Service)

d)

SSA (Social Security Administration)

65.

What does CVE stand for?

a)

Common Vulnerabilities and Exposures.

b)

Certified Vulnerability Expert.

c)

Computer Virus Encyclopedia.

d)

Cybersecurity Vulnerability Evaluation.

66.

Who maintains the NVD?

a)

NIST (National Institute of Standards and Technology).

b)

Microsoft Corporation.

c)

Open Web Application Security Project (OWASP).

d)

Internet Engineering Task Force (IETF).

67.

What is Exploit-DB used for?

a)

It provides public exploits and proof-of-concept code for known vulnerabilities.

b)

It is a database for storing encrypted passwords.

c)

It is a tool for scanning network ports.

d)

It is a platform for sharing open-source software projects.

68.

What kind of data do Threat Maps visualize?

a)

Real-time cyberattacks – their sources, targets, and types.

b)

Historical weather patterns across continents.

c)

Global financial transactions between banks.

d)

Social media trends and user engagement statistics.

69.

Give one example of a well-known cybersecurity blog.

a)

Krebs on Security or Schneier on Security.

b)

TechCrunch

c)

Mashable

d)

Gizmodo

70.

Why are default passwords a vulnerability?

a)

They allow attackers easy access if not changed after installation.

b)

They improve system performance.

c)

They make the system more secure.

d)

They prevent unauthorized updates.

71.

Which database lists default credentials for common devices?

a)

cirt.net/passwords.

b)

exploit-db.com/vulnerabilities.

c)

shodan.io/devices.

d)

nvd.nist.gov/credentials.

72.

What is the difference between a threat and a vulnerability?

a)

A threat is a potential attack; a vulnerability is the weakness that the threat can exploit.

b)

A vulnerability is a potential attack; a threat is the weakness that the vulnerability can exploit.

c)

A threat and a vulnerability are the same thing in cybersecurity.

d)

A threat is always internal; a vulnerability is always external.

73.

What creates a risk in cybersecurity?

a)

When a threat successfully exploits a vulnerability.

b)

When all vulnerabilities are patched.

c)

When security policies are strictly followed.

d)

When there are no threats present.

74.

Name two academic sources for cybersecurity research.

a)

IEEE Xplore and ACM Digital Library (also arXiv).

b)

Wikipedia and Reddit.

c)

YouTube and Facebook.

d)

Quora and Instagram.

75.

What is the purpose of RFCs in cybersecurity?

a)

Define standards and best practices for Internet and security protocols.

b)

Monitor network traffic for malicious activity.

c)

Encrypt data transmissions over the Internet.

d)

Detect and remove malware from computer systems.

76.

Give two well-known cybersecurity conferences.

a)

DEF CON and Black Hat (others: RSA, USENIX).

b)

Comic-Con and E3 (others: PAX, Gamescom).

c)

CES and MWC (others: IFA, Computex).

d)

Sundance and Cannes (others: TIFF, Berlinale).

77.

What does STIX stand for and what does it do?

a)

Structured Threat Information Expression – standard format for sharing threat data.

b)

Secure Transmission Internet Exchange – protocol for secure email.

c)

Systematic Threat Investigation Xchange – tool for malware analysis.

d)

Standardized Technical Information XML – format for software documentation.

78.

What is TAXII used for?

a)

The protocol for transporting structured threat information (STIX data).

b)

A tool for encrypting email messages.

c)

A method for scanning network vulnerabilities.

d)

A protocol for managing user authentication.

79.

Which U.S. government service enables automated cyber threat data sharing?

a)

AIS (Automated Indicator Sharing) by DHS.

b)

USPS (United States Postal Service)

c)

IRS (Internal Revenue Service)

d)

SSA (Social Security Administration)

80.

What does CVE stand for?

a)

Common Vulnerabilities and Exposures.

b)

Certified Vulnerability Expert.

c)

Computer Virus Encyclopedia.

d)

Cybersecurity Vulnerability Evaluation.

81.

Who maintains the NVD?

a)

NIST (National Institute of Standards and Technology).

b)

Microsoft Corporation.

c)

Open Web Application Security Project (OWASP).

d)

Internet Engineering Task Force (IETF).

82.

What is Exploit-DB used for?

a)

It provides public exploits and proof-of-concept code for known vulnerabilities.

b)

It is a database for storing encrypted passwords.

c)

It is a tool for scanning network ports.

d)

It is a platform for sharing open-source software projects.

83.

What kind of data do Threat Maps visualize?

a)

Real-time cyberattacks – their sources, targets, and types.

b)

Weather patterns across the globe.

c)

Stock market trends and financial forecasts.

d)

Global population growth statistics.

84.

Give one example of a well-known cybersecurity blog.

a)

Krebs on Security or Schneier on Security.

b)

TechCrunch

c)

Mashable

d)

Gizmodo

85.

Why are default passwords a vulnerability?

a)

They allow attackers easy access if not changed after installation.

b)

They improve system performance.

c)

They make the system more secure.

d)

They are always unique for each device.

86.

Which database lists default credentials for common devices?

a)

cirt.net/passwords.

b)

exploit-db.com/credentials.

c)

shodan.io/defaults.

d)

securityfocus.com/passwords.

87.

What is the main purpose of encryption?

a)

To protect confidentiality by converting plaintext into unreadable ciphertext.

b)

To increase the speed of data transmission.

c)

To compress data for storage efficiency.

d)

To verify the identity of a sender.

88.

Is hashing reversible?

a)

No – it’s a one-way process for data integrity.

b)

Yes – you can always get the original data back.

c)

Only reversible with a special key.

d)

It depends on the algorithm used.

89.

Difference between symmetric and asymmetric encryption?

a)

Symmetric uses one shared key; asymmetric uses a public/private pair.

b)

Symmetric uses two keys; asymmetric uses one shared key.

c)

Symmetric uses only public keys; asymmetric uses only private keys.

d)

Symmetric and asymmetric encryption are identical.

90.

Give one example of a symmetric and one asymmetric cipher.

a)

AES (symmetric), RSA (asymmetric).

b)

DES (asymmetric), ECC (symmetric).

c)

RSA (symmetric), AES (asymmetric).

d)

Blowfish (asymmetric), Diffie-Hellman (symmetric).

91.

The main problem with symmetric encryption is:

a)

It requires both parties to share and securely manage the same secret key.

b)

It uses very weak algorithms for encryption.

c)

It is only used for encrypting images.

d)

It does not provide any confidentiality.

92.

ECC offers which of the following advantages compared to RSA?

a)

Stronger security with shorter key lengths

b)

Requires longer key lengths for equivalent security

c)

Is less efficient than RSA

d)

Provides no advantage over RSA

93.

A digital signature proves:

a)

the authenticity and integrity of a message

b)

the speed of data transmission

c)

the size of the file

d)

the type of encryption used

94.

Perfect Forward Secrecy (PFS) refers to:

a)

A security feature that ensures session keys cannot be compromised even if the server's private key is exposed.

b)

A method for encrypting data using only symmetric keys.

c)

A protocol for authenticating users without passwords.

d)

A technique for storing passwords securely on a server.

95.

The mode of operation that uses XOR and an IV to link blocks is:

a)

ECB (Electronic Codebook)

b)

CBC (Cipher Block Chaining)

c)

OFB (Output Feedback)

d)

CFB (Cipher Feedback)

96.

Salting is used for:

a)

Enhancing password security by adding random data

b)

Encrypting data with a public key

c)

Compressing files to save space

d)

Improving network speed

97.

A Certificate Authority (CA) is:

a)

an organization that issues digital certificates to verify identities online

b)

a type of encryption algorithm used for secure communication

c)

a protocol for transferring files over the internet

d)

a device used to store cryptographic keys

98.

What is stored in a digital certificate?

a)

The public key and identity information of the certificate holder

b)

Only the private key of the certificate holder

c)

A list of all trusted websites

d)

The password for secure access

99.

OCSP differs from CRL in which of the following ways?

a)

OCSP provides real-time certificate status, while CRL provides periodic lists of revoked certificates.

b)

OCSP and CRL both provide real-time certificate status.

c)

CRL is faster than OCSP in checking certificate status.

d)

OCSP provides a list of revoked certificates, while CRL checks certificate status individually.

100.

Name two cryptographic technologies shaping the future.

a)

Quantum cryptography and blockchain technology

b)

Symmetric encryption and steganography

c)

Classical ciphers and hashing

d)

Password protection and data compression