Worksheetsmodule final quiz
Total questions: 40
Worksheet time: 2hrs 0mins
Emily is responsible for maintaining the company's financial records. She must ensure that no one can change these records without proper authorisation. Which principle of information security is Emily upholding?
Confidentiality
Availability
Integrity
Authentication
Max is sending sensitive information over the internet. What is the primary purpose of using encryption in this situation?
Improve network speed
Prevent unauthorised data access
Detect malware
Block network traffic
Samuel is setting up a website for his business and wants to ensure that all customer data is securely encrypted during transmission. Which protocol should Samuel use to securely encrypt web traffic?
HTTP
FTP
HTTPS
SMTP
James is setting up a new computer system for his company. He discovers that the system has a flaw that could be taken advantage of by hackers. Which term refers to this kind of weakness?
Asset
Hazard
Vulnerability
Control
Max is setting up his new computer and wants to make sure it is protected from harmful software. Which of the following is an example of malware?
Firewall
Virus
VPN
Proxy
Sophia manages a company server that stores customer records. The server is rarely patched, leaving it exposed to potential risks. What does this represent?
Threat
Vulnerability
Impact
Control
During a major online sale, a group of attackers floods an e-commerce website with excessive traffic, causing it to become unavailable to legitimate shoppers. What type of attack is this?
SQL Injection
XSS
DoS
Privilege escalation
Jacob is responsible for maintaining the company’s online services. He needs to ensure that employees can access critical systems and data whenever required, especially during business hours. Which security principle is Jacob focusing on?
Confidentiality
Integrity
Availability
Non-repudiation
Anaya receives an unexpected email attachment. When she opens it, malicious software is installed on her computer. What type of threat is this?
Physical threat
Malware infection
Network failure
Hardware fault
James is responsible for ensuring the security of his company's information. He implements policies and organizes staff training sessions to educate employees about security procedures. Which control type is James using?
Physical
Technical
Administrative
Logical
Samuel tries to log into a website and enters ' OR 1=1; in the username field. The website grants him access without needing a valid password. What type of attack has occurred?
XSS
SQL Injection
DoS
Password spraying
Kiara posts a comment on a popular website. Soon after, she and other users start seeing unexpected pop-ups whenever they visit the page with her comment. Investigation reveals that malicious JavaScript was injected and stored with the comment. What is the attack type?
Reflected XSS
Stored XSS
SQL Injection
Buffer overflow
George connects to an unsecured Wi-Fi network at a coffee shop. An attacker intercepts the communication between George and the website he is visiting. Which attack is this?
DoS
Man-in-the-middle
Malware injection
Brute force
Benjamin, a security analyst at a company, notices repeated failed login attempts from one IP address targeting many employee accounts. What attack is likely occurring?
SQL Injection
Brute force
XSS
Packet sniffing
William manages a company website that suddenly slows down after receiving traffic from thousands of different IPs. What is the most likely cause?
Hardware failure
Insider misuse
Distributed DoS
Malware outbreak
Ava is developing a web application, and the database account used by her application has full administrative privileges. Why is this risky?
It improves performance
It violates least privilege
It prevents SQL Injection
It improves availability
James is configuring a company's firewall, which currently allows all outbound traffic by default. What is the main security concern in this situation?
Reduced availability
Increased latency
Data exfiltration risk
Packet loss
Matilda manages a company network and notices that their IDS reports unusual traffic patterns but does not take any action to block them. What is the primary function of the IDS in this situation?
Prevention
Detection
Encryption
Authentication
Amelia works at a company that does not have an incident response plan. One day, the company experiences a cyber attack, and Amelia and her colleagues are unsure what steps to take. Which control is missing?
Technical
Physical
Administrative
Environmental
After users submit forms on a company's website, repeated database syntax errors appear in the system logs. What should Isabella investigate first?
Network cables
Input validation
Physical access logs
Power supply
Emily visits a website where an attacker has injected JavaScript that steals her session cookies and sends them to an external server. What security impact does this have?
Availability only
Confidentiality only
Integrity only
Confidentiality and integrity
Arjun manages the security for a company and decides to use CCTV cameras, firewalls, and strict security policies together to protect the organization. What security approach is Arjun using?
Single control strategy
Risk transfer
Layered security
Threat elimination
Priya is responsible for ensuring that all company computers receive updates to fix known vulnerabilities. Which policy should she follow?
Acceptable use policy
Password policy
Patch management policy
Data classification policy
Freya is part of a SOC team that uses CVE reports to decide which systems need updates first. What is Freya's team using?
Encryption standards
Cyber Threat Intelligence
Firewall rules
Authentication logs
Samuel is setting up a cybersecurity defense system for his company. He wants to use a CTI source that focuses specifically on attacker tactics and techniques. Which CTI source should Samuel choose?
CVE
ENISA
MITRE ATT&CK
ISO 27001
Oscar is shopping online and enters his card details on a payment page. Unbeknownst to him, a third-party JavaScript file on the page has been modified to steal his card information. Which real incident does this resemble?
WannaCry
British Airways breach
Stuxnet
Heartbleed
Amelia is developing a web application that loads scripts from third-party sources. She is concerned about the risk of script injection attacks. Which control would most effectively reduce this risk?
Strong passwords
Content Security Policy
CCTV
Disk encryption
Emily manages a company server that runs outdated software with known vulnerabilities. One day, the system is compromised. What failure caused this?
Weak encryption
Poor patch management
Insider threat
Network congestion
Arthur is responsible for monitoring the company's network for potential security threats. Which element would best help Arthur identify early signs of a security breach?
Encryption keys
Indicators of compromise
Physical locks
Backup tapes
Thomas manages the IT infrastructure of a company. One day, the company's website becomes completely inaccessible to users due to a cyber attack. Which type of attack is most likely responsible for directly targeting the availability principle of CIA?
XSS
SQL Injection
DoS
Session hijacking
Florence works at a company that reviews logs daily to identify abnormal behaviour. What security goal does this support?
Prevention only
Detection
Encryption
Authentication
During a cyberattack on a company's network, which factor most affects the network's performance?
Number of users
Bandwidth consumption
File permissions
Password complexity
Rosie notices that a malware program is spreading across multiple computers in her office network without anyone clicking on suspicious links or opening infected files. Which type of malware is this?
Virus
Worm
Trojan
Spyware
Harry manages a company's computer network. To ensure accountability, he wants to keep a record of all system activities. Which security practice should Harry implement?
Encryption
Logging
Authentication
Authorization
Daniel is hired by a company to legally attempt to exploit vulnerabilities in their systems with permission. What activity is Daniel performing?
Hacking
Malware development
Penetration testing
Cyber espionage
Ava works at a company and needs to access certain files on the company server. Which control directly limits what resources Ava can access?
Authentication
Authorization
Encryption
Logging
Kiara works for an organisation that regularly analyses attack trends to adjust its security strategy. What is this an example of?
Risk avoidance
Physical security planning
Incident recovery
Threat intelligence analysis
Henry is responsible for managing the security of his company's network. Despite having access to advanced malware detection tools and strong encryption, he often overlooks basic security practices like regularly updating passwords and patching software. Which security failure most commonly leads to large-scale breaches?
Advanced malware
Poor basic security practices
Strong encryption
Excessive monitoring
Priya is setting up security measures for her company's network. She wants to make sure that if one security control fails, others are still in place to protect the system. Which approach should Priya use to ensure no single security control is relied upon?
Risk acceptance
Threat elimination
Defence in layers
Asset disposal
Noah is tasked with reviewing the security of a company's IT system. After his analysis, he recommends implementing tighter ACLs, improving monitoring, and ensuring regular patching. What learning outcome is demonstrated?
Identifying assets only
Performing encryption
Installing hardware
Analysing and improving a security profile
