NEW
Font size
WorksheetsCybersecurity Fundamentals Quiz
Total questions: 40
Worksheet time: 20mins
Which pillar of the CIA Triad ensures that information is correct, authentic, and has not been improperly modified?
Availability
Integrity
Confidentiality
Encryption
What is the primary focus of the 'Availability' element in the CIA Triad?
Preventing unauthorized disclosure of data.
Ensuring only authorized users can modify data.
Ensuring timely and reliable access to data and resources.
Protecting data during transmission.
Which subtopic describes the importance of cybersecurity concerning environmental impact and social accountability?
Key Objectives and Principles
The CIA Triad
Real-world Examples
Cybersecurity and Sustainable Digital Governance (ESG perspective)
Which category broadly defines a path or mechanism by which an attacker can gain unauthorized access to a system?
Key Objectives
Threats and Attack Vectors
Real-world Examples
Sustainable Governance
What concept ensures that data is accessible when needed by authorized users and systems?
Integrity
Confidentiality
Availability
Access Control
Protecting intellectual property and customer data is an essential part of which objective category?
Availability
Confidentiality
Integrity
Sustainability
Which of the following is defined as a primary goal of Cybersecurity for an organization?
Providing unlimited network access.
Avoiding all network downtime.
Protecting Information Systems and Digital Assets.
Maximizing software purchases.
Which objective reflects the requirement for controls that guarantee the reliability and accuracy of data?
Confidentiality
Availability
Integrity
Non-Repudiation
Which attack method involves disrupting legitimate traffic by overwhelming a system or network with excessive requests?
SQL Injection
MitM Attack
Phishing
DoS (Denial of Service)
What is a 'vulnerability' in the context of cybersecurity threats?
A. A specific tool used by attackers.
B. A weakness in a system that can be exploited.
C. An action taken by a malicious user.
D. The damage caused by an attack.
Which common attack method involves intercepting communication between two parties without their knowledge?
DoS Attack
SQL Injection
Man-in-the-Middle (MitM)
Phishing
According to the syllabus, what is often classified as a major vulnerability that attackers exploit?
Outdated hardware
Human Error
Excess network bandwidth
Lack of cloud services
Which attack method targets databases by inserting malicious code into input fields of a web application?
DoS
MitM
Phishing
SQL Injection
Threats are commonly classified based on their source. Which option represents a classification used to categorize the origin of a threat?
Logical vs. Physical
Static vs. Dynamic
Evaluating threat impacts includes considering potential consequences related to which external factor mentioned in Topic 2?
Malware detection rates
Firewall configurations
Society and Environment
Network models
What term describes a piece of software or code designed to take advantage of a vulnerability?
Threat
Mitigation
Exploit
Countermeasure
What term describes the initial phase where malware successfully breaches a system's defenses and becomes resident?
Execution
Infection/Installation
Command and Control
Obfuscation
Which specific type of malware is designed to encrypt a victim's data and demand payment for the decryption key?
Spyware
Trojan Horse
Rootkit
Ransomware
What is the primary difference between Static and Dynamic Malware Analysis?
Static analysis is automated; dynamic analysis is manual.
Static analysis examines code without executing it; dynamic analysis executes code in a controlled environment.
Static analysis uses sandboxing; dynamic analysis uses virtual machines.
Static analysis is faster; dynamic analysis is more cost-effective.
Which common malware delivery method relies on tricking a user into downloading an apparently legitimate file?
Network sniffing
Brute force attack
Infected email attachment
Port scanning
A key technique for malware detection that compares a file's hash against a database of known malicious hashes is known as:
Heuristic analysis
Behavioral analysis
Signature-based detection
Sandboxing
What is a crucial proactive countermeasure against file-encrypting ransomware incidents?
Running dynamic analysis software.
Implementing secure coding practices.
Using biometric authentication.
Implementing robust data backup and recovery planning.
Which phase of the malware lifecycle involves the attacker gaining remote administrative control over the infected device?
Propagation
Execution
Command and Control (C2)
Delivery
Which of the following is defined as a primary element exploited by Social Engineering?
Network Protocols
System Configurations
Encryption Standards
Human Element
Which psychological trigger is often used in phishing emails to make a victim click a link without thinking?
Greed
Urgency/Fear of Loss
Curiosity
Intellectualism
What is the goal of 'Phishing' techniques?
To encrypt system files.
To overwhelm a web server.
To acquire sensitive information (e.g., usernames, passwords) by impersonating a trustworthy entity.
To perform database manipulation.
What specific technique involves an attacker creating a convincing story to obtain information from a victim?
Vishing
Tailgating
Whaling
Pretexting
Which concept requires individuals to consider the consequences of their online actions on others?
Ethical Dilemma
Penetration Testing
Social Responsibility
Network Hardening
What is considered a key practice for identifying and reporting suspicious social engineering attempts?
Immediately deleting the suspicious email.
Only clicking the link if the sender seems familiar.
Sharing the email with colleagues for verification.
Verifying the sender’s identity through an independent, secure channel.
A phishing attack that specifically targets a senior executive (CEO or CFO) is often referred to as:
Phishing
Vishing
Whaling
Baiting
The use of voice communication (phone calls) to trick individuals into divulging PII is classified as what type of Social Engineering?
Spear Phishing
Smishing
Vishing
Hoaxing
Which network security concept acts as a gatekeeper, inspecting traffic passing between two different network segments based on a defined set of rules?
IDS
VPN
Firewall
IPS
What is the primary purpose of Network Hardening practices?
To improve network speed.
To introduce more network protocols.
To enhance security by reducing vulnerabilities.
To ensure compliance with regulatory standards.
Which of the following is a method to reduce the attack surface in network security?
To monitor network protocols.
Eliminate unnecessary services and securing configurations.
To monitor network activities
To monitor IP Addresses
Which of the following is defined as a component that monitors network traffic for suspicious activity but does not actively block or stop the traffic?
IPS (Intrusion Prevention System)
VPN (Virtual Private Network)
Firewall
IDS (Intrusion Detection System)
The use of a VPN (Virtual Private Network) primarily addresses which aspect of network security?
Confidentiality and Integrity (through tunneling and encryption)
Physical Security
Denial of Service prevention
Network Hardening compliance
What concept related to Network Security Fundamentals defines the structured design that separates different types of controls and functions?
Network Protocols
VPN Tunnels
Network Models and Security Layers
Sustainable Practices
Which practice aligns with sustainable network practices?
Maximizing network device power usage.
Running all network protocols simultaneously.
Implementing energy-efficient network equipment and optimizing resource usage.
Disabling security controls to save processing power.
A fundamental step in secure network configuration involves changing:
Default passwords and access credentials.
Network security device colors.
All existing network protocols.
The physical location of the server racks.
Common risks associated with Network Protocols often stem from:
Excess memory usage.
Unencrypted data transmission
High availability rates.
Detailed configuration guides.
