wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Cybersecurity Fundamentals Quiz

Total questions: 40

Worksheet time: 20mins

Name
Class
Date
1.

Which pillar of the CIA Triad ensures that information is correct, authentic, and has not been improperly modified?

a)

Availability

b)

Integrity

c)

Confidentiality

d)

Encryption

2.

What is the primary focus of the 'Availability' element in the CIA Triad?

a)

Preventing unauthorized disclosure of data.

b)

Ensuring only authorized users can modify data.

c)

Ensuring timely and reliable access to data and resources.

d)

Protecting data during transmission.

3.

Which subtopic describes the importance of cybersecurity concerning environmental impact and social accountability?

a)

Key Objectives and Principles

b)

The CIA Triad

c)

Real-world Examples

d)

Cybersecurity and Sustainable Digital Governance (ESG perspective)

4.

Which category broadly defines a path or mechanism by which an attacker can gain unauthorized access to a system?

a)

Key Objectives

b)

Threats and Attack Vectors

c)

Real-world Examples

d)

Sustainable Governance

5.

What concept ensures that data is accessible when needed by authorized users and systems?

a)

Integrity

b)

Confidentiality

c)

Availability

d)

Access Control

6.

Protecting intellectual property and customer data is an essential part of which objective category?

a)

Availability

b)

Confidentiality

c)

Integrity

d)

Sustainability

7.

Which of the following is defined as a primary goal of Cybersecurity for an organization?

a)

Providing unlimited network access.

b)

Avoiding all network downtime.

c)

Protecting Information Systems and Digital Assets.

d)

Maximizing software purchases.

8.

Which objective reflects the requirement for controls that guarantee the reliability and accuracy of data?

a)

Confidentiality

b)

Availability

c)

Integrity

d)

Non-Repudiation

9.

Which attack method involves disrupting legitimate traffic by overwhelming a system or network with excessive requests?

a)

SQL Injection

b)

MitM Attack

c)

Phishing

d)

DoS (Denial of Service)

10.

What is a 'vulnerability' in the context of cybersecurity threats?

a)

A. A specific tool used by attackers.

b)

B. A weakness in a system that can be exploited.

c)

C. An action taken by a malicious user.

d)

D. The damage caused by an attack.

11.

Which common attack method involves intercepting communication between two parties without their knowledge?

a)

DoS Attack

b)

SQL Injection

c)

Man-in-the-Middle (MitM)

d)

Phishing

12.

According to the syllabus, what is often classified as a major vulnerability that attackers exploit?

a)

Outdated hardware

b)

Human Error

c)

Excess network bandwidth

d)

Lack of cloud services

13.

Which attack method targets databases by inserting malicious code into input fields of a web application?

a)

DoS

b)

MitM

c)

Phishing

d)

SQL Injection

14.

Threats are commonly classified based on their source. Which option represents a classification used to categorize the origin of a threat?

a)

Logical vs. Physical

b)

Static vs. Dynamic

15.

Evaluating threat impacts includes considering potential consequences related to which external factor mentioned in Topic 2?

a)

Malware detection rates

b)

Firewall configurations

c)

Society and Environment

d)

Network models

16.

What term describes a piece of software or code designed to take advantage of a vulnerability?

a)

Threat

b)

Mitigation

c)

Exploit

d)

Countermeasure

17.

What term describes the initial phase where malware successfully breaches a system's defenses and becomes resident?

a)

Execution

b)

Infection/Installation

c)

Command and Control

d)

Obfuscation

18.

Which specific type of malware is designed to encrypt a victim's data and demand payment for the decryption key?

a)

Spyware

b)

Trojan Horse

c)

Rootkit

d)

Ransomware

19.

What is the primary difference between Static and Dynamic Malware Analysis?

a)

Static analysis is automated; dynamic analysis is manual.

b)

Static analysis examines code without executing it; dynamic analysis executes code in a controlled environment.

c)

Static analysis uses sandboxing; dynamic analysis uses virtual machines.

d)

Static analysis is faster; dynamic analysis is more cost-effective.

20.

Which common malware delivery method relies on tricking a user into downloading an apparently legitimate file?

a)

Network sniffing

b)

Brute force attack

c)

Infected email attachment

d)

Port scanning

21.

A key technique for malware detection that compares a file's hash against a database of known malicious hashes is known as:

a)

Heuristic analysis

b)

Behavioral analysis

c)

Signature-based detection

d)

Sandboxing

22.

What is a crucial proactive countermeasure against file-encrypting ransomware incidents?

a)

Running dynamic analysis software.

b)

Implementing secure coding practices.

c)

Using biometric authentication.

d)

Implementing robust data backup and recovery planning.

23.

Which phase of the malware lifecycle involves the attacker gaining remote administrative control over the infected device?

a)

Propagation

b)

Execution

c)

Command and Control (C2)

d)

Delivery

24.

Which of the following is defined as a primary element exploited by Social Engineering?

a)

Network Protocols

b)

System Configurations

c)

Encryption Standards

d)

Human Element

25.

Which psychological trigger is often used in phishing emails to make a victim click a link without thinking?

a)

Greed

b)

Urgency/Fear of Loss

c)

Curiosity

d)

Intellectualism

26.

What is the goal of 'Phishing' techniques?

a)

To encrypt system files.

b)

To overwhelm a web server.

c)

To acquire sensitive information (e.g., usernames, passwords) by impersonating a trustworthy entity.

d)

To perform database manipulation.

27.

What specific technique involves an attacker creating a convincing story to obtain information from a victim?

a)

Vishing

b)

Tailgating

c)

Whaling

d)

Pretexting

28.

Which concept requires individuals to consider the consequences of their online actions on others?

a)

Ethical Dilemma

b)

Penetration Testing

c)

Social Responsibility

d)

Network Hardening

29.

What is considered a key practice for identifying and reporting suspicious social engineering attempts?

a)

Immediately deleting the suspicious email.

b)

Only clicking the link if the sender seems familiar.

c)

Sharing the email with colleagues for verification.

d)

Verifying the sender’s identity through an independent, secure channel.

30.

A phishing attack that specifically targets a senior executive (CEO or CFO) is often referred to as:

a)

Phishing

b)

Vishing

c)

Whaling

d)

Baiting

31.

The use of voice communication (phone calls) to trick individuals into divulging PII is classified as what type of Social Engineering?

a)

Spear Phishing

b)

Smishing

c)

Vishing

d)

Hoaxing

32.

Which network security concept acts as a gatekeeper, inspecting traffic passing between two different network segments based on a defined set of rules?

a)

IDS

b)

VPN

c)

Firewall

d)

IPS

33.

What is the primary purpose of Network Hardening practices?

a)

To improve network speed.

b)

To introduce more network protocols.

c)

To enhance security by reducing vulnerabilities.

d)

To ensure compliance with regulatory standards.

34.

Which of the following is a method to reduce the attack surface in network security?

a)

To monitor network protocols.

b)

Eliminate unnecessary services and securing configurations.

c)

To monitor network activities

d)

To monitor IP Addresses

35.

Which of the following is defined as a component that monitors network traffic for suspicious activity but does not actively block or stop the traffic?

a)

IPS (Intrusion Prevention System)

b)

VPN (Virtual Private Network)

c)

Firewall

d)

IDS (Intrusion Detection System)

36.

The use of a VPN (Virtual Private Network) primarily addresses which aspect of network security?

a)

Confidentiality and Integrity (through tunneling and encryption)

b)

Physical Security

c)

Denial of Service prevention

d)

Network Hardening compliance

37.

What concept related to Network Security Fundamentals defines the structured design that separates different types of controls and functions?

a)

Network Protocols

b)

VPN Tunnels

c)

Network Models and Security Layers

d)

Sustainable Practices

38.

Which practice aligns with sustainable network practices?

a)

Maximizing network device power usage.

b)

Running all network protocols simultaneously.

c)

Implementing energy-efficient network equipment and optimizing resource usage.

d)

Disabling security controls to save processing power.

39.

A fundamental step in secure network configuration involves changing:

a)

Default passwords and access credentials.

b)

Network security device colors.

c)

All existing network protocols.

d)

The physical location of the server racks.

40.

Common risks associated with Network Protocols often stem from:

a)

Excess memory usage.

b)

Unencrypted data transmission

c)

High availability rates.

d)

Detailed configuration guides.