wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

module final quiz

Total questions: 40

Worksheet time: 2hrs 0mins

Name
Class
Date
1.

Emily is responsible for maintaining the company's financial records. She must ensure that no one can change these records without proper authorisation. Which principle of information security is Emily upholding?

a)

Confidentiality

b)

Availability

c)

Integrity

d)

Authentication

2.

Max is sending sensitive information over the internet. What is the primary purpose of using encryption in this situation?

a)

Improve network speed

b)

Prevent unauthorised data access

c)

Detect malware

d)

Block network traffic

3.

Samuel is setting up a website for his business and wants to ensure that all customer data is securely encrypted during transmission. Which protocol should Samuel use to securely encrypt web traffic?

a)

HTTP

b)

FTP

c)

HTTPS

d)

SMTP

4.

James is setting up a new computer system for his company. He discovers that the system has a flaw that could be taken advantage of by hackers. Which term refers to this kind of weakness?

a)

Asset

b)

Hazard

c)

Vulnerability

d)

Control

5.

Max is setting up his new computer and wants to make sure it is protected from harmful software. Which of the following is an example of malware?

a)

Firewall

b)

Virus

c)

VPN

d)

Proxy

6.

Sophia manages a company server that stores customer records. The server is rarely patched, leaving it exposed to potential risks. What does this represent?

a)

Threat

b)

Vulnerability

c)

Impact

d)

Control

7.

During a major online sale, a group of attackers floods an e-commerce website with excessive traffic, causing it to become unavailable to legitimate shoppers. What type of attack is this?

a)

SQL Injection

b)

XSS

c)

DoS

d)

Privilege escalation

8.

Jacob is responsible for maintaining the company’s online services. He needs to ensure that employees can access critical systems and data whenever required, especially during business hours. Which security principle is Jacob focusing on?

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Non-repudiation

9.

Anaya receives an unexpected email attachment. When she opens it, malicious software is installed on her computer. What type of threat is this?

a)

Physical threat

b)

Malware infection

c)

Network failure

d)

Hardware fault

10.

James is responsible for ensuring the security of his company's information. He implements policies and organizes staff training sessions to educate employees about security procedures. Which control type is James using?

a)

Physical

b)

Technical

c)

Administrative

d)

Logical

11.

Samuel tries to log into a website and enters ' OR 1=1; in the username field. The website grants him access without needing a valid password. What type of attack has occurred?

a)

XSS

b)

SQL Injection

c)

DoS

d)

Password spraying

12.

Kiara posts a comment on a popular website. Soon after, she and other users start seeing unexpected pop-ups whenever they visit the page with her comment. Investigation reveals that malicious JavaScript was injected and stored with the comment. What is the attack type?

a)

Reflected XSS

b)

Stored XSS

c)

SQL Injection

d)

Buffer overflow

13.

George connects to an unsecured Wi-Fi network at a coffee shop. An attacker intercepts the communication between George and the website he is visiting. Which attack is this?

a)

DoS

b)

Man-in-the-middle

c)

Malware injection

d)

Brute force

14.

Benjamin, a security analyst at a company, notices repeated failed login attempts from one IP address targeting many employee accounts. What attack is likely occurring?

a)

SQL Injection

b)

Brute force

c)

XSS

d)

Packet sniffing

15.

William manages a company website that suddenly slows down after receiving traffic from thousands of different IPs. What is the most likely cause?

a)

Hardware failure

b)

Insider misuse

c)

Distributed DoS

d)

Malware outbreak

16.

Ava is developing a web application, and the database account used by her application has full administrative privileges. Why is this risky?

a)

It improves performance

b)

It violates least privilege

c)

It prevents SQL Injection

d)

It improves availability

17.

James is configuring a company's firewall, which currently allows all outbound traffic by default. What is the main security concern in this situation?

a)

Reduced availability

b)

Increased latency

c)

Data exfiltration risk

d)

Packet loss

18.

Matilda manages a company network and notices that their IDS reports unusual traffic patterns but does not take any action to block them. What is the primary function of the IDS in this situation?

a)

Prevention

b)

Detection

c)

Encryption

d)

Authentication

19.

Amelia works at a company that does not have an incident response plan. One day, the company experiences a cyber attack, and Amelia and her colleagues are unsure what steps to take. Which control is missing?

a)

Technical

b)

Physical

c)

Administrative

d)

Environmental

20.

After users submit forms on a company's website, repeated database syntax errors appear in the system logs. What should Isabella investigate first?

a)

Network cables

b)

Input validation

c)

Physical access logs

d)

Power supply

21.

Emily visits a website where an attacker has injected JavaScript that steals her session cookies and sends them to an external server. What security impact does this have?

a)

Availability only

b)

Confidentiality only

c)

Integrity only

d)

Confidentiality and integrity

22.

Arjun manages the security for a company and decides to use CCTV cameras, firewalls, and strict security policies together to protect the organization. What security approach is Arjun using?

a)

Single control strategy

b)

Risk transfer

c)

Layered security

d)

Threat elimination

23.

Priya is responsible for ensuring that all company computers receive updates to fix known vulnerabilities. Which policy should she follow?

a)

Acceptable use policy

b)

Password policy

c)

Patch management policy

d)

Data classification policy

24.

Freya is part of a SOC team that uses CVE reports to decide which systems need updates first. What is Freya's team using?

a)

Encryption standards

b)

Cyber Threat Intelligence

c)

Firewall rules

d)

Authentication logs

25.

Samuel is setting up a cybersecurity defense system for his company. He wants to use a CTI source that focuses specifically on attacker tactics and techniques. Which CTI source should Samuel choose?

a)

CVE

b)

ENISA

c)

MITRE ATT&CK

d)

ISO 27001

26.

Oscar is shopping online and enters his card details on a payment page. Unbeknownst to him, a third-party JavaScript file on the page has been modified to steal his card information. Which real incident does this resemble?

a)

WannaCry

b)

British Airways breach

c)

Stuxnet

d)

Heartbleed

27.

Amelia is developing a web application that loads scripts from third-party sources. She is concerned about the risk of script injection attacks. Which control would most effectively reduce this risk?

a)

Strong passwords

b)

Content Security Policy

c)

CCTV

d)

Disk encryption

28.

Emily manages a company server that runs outdated software with known vulnerabilities. One day, the system is compromised. What failure caused this?

a)

Weak encryption

b)

Poor patch management

c)

Insider threat

d)

Network congestion

29.

Arthur is responsible for monitoring the company's network for potential security threats. Which element would best help Arthur identify early signs of a security breach?

a)

Encryption keys

b)

Indicators of compromise

c)

Physical locks

d)

Backup tapes

30.

Thomas manages the IT infrastructure of a company. One day, the company's website becomes completely inaccessible to users due to a cyber attack. Which type of attack is most likely responsible for directly targeting the availability principle of CIA?

a)

XSS

b)

SQL Injection

c)

DoS

d)

Session hijacking

31.

Florence works at a company that reviews logs daily to identify abnormal behaviour. What security goal does this support?

a)

Prevention only

b)

Detection

c)

Encryption

d)

Authentication

32.

During a cyberattack on a company's network, which factor most affects the network's performance?

a)

Number of users

b)

Bandwidth consumption

c)

File permissions

d)

Password complexity

33.

Rosie notices that a malware program is spreading across multiple computers in her office network without anyone clicking on suspicious links or opening infected files. Which type of malware is this?

a)

Virus

b)

Worm

c)

Trojan

d)

Spyware

34.

Harry manages a company's computer network. To ensure accountability, he wants to keep a record of all system activities. Which security practice should Harry implement?

a)

Encryption

b)

Logging

c)

Authentication

d)

Authorization

35.

Daniel is hired by a company to legally attempt to exploit vulnerabilities in their systems with permission. What activity is Daniel performing?

a)

Hacking

b)

Malware development

c)

Penetration testing

d)

Cyber espionage

36.

Ava works at a company and needs to access certain files on the company server. Which control directly limits what resources Ava can access?

a)

Authentication

b)

Authorization

c)

Encryption

d)

Logging

37.

Kiara works for an organisation that regularly analyses attack trends to adjust its security strategy. What is this an example of?

a)

Risk avoidance

b)

Physical security planning

c)

Incident recovery

d)

Threat intelligence analysis

38.

Henry is responsible for managing the security of his company's network. Despite having access to advanced malware detection tools and strong encryption, he often overlooks basic security practices like regularly updating passwords and patching software. Which security failure most commonly leads to large-scale breaches?

a)

Advanced malware

b)

Poor basic security practices

c)

Strong encryption

d)

Excessive monitoring

39.

Priya is setting up security measures for her company's network. She wants to make sure that if one security control fails, others are still in place to protect the system. Which approach should Priya use to ensure no single security control is relied upon?

a)

Risk acceptance

b)

Threat elimination

c)

Defence in layers

d)

Asset disposal

40.

Noah is tasked with reviewing the security of a company's IT system. After his analysis, he recommends implementing tighter ACLs, improving monitoring, and ensuring regular patching. What learning outcome is demonstrated?

a)

Identifying assets only

b)

Performing encryption

c)

Installing hardware

d)

Analysing and improving a security profile