wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Unit 11 35 topic KnowitallNinja

Total questions: 120

Worksheet time: 3600secs

Name
Class
Date
1.
Which of the following is an example of an internal threat?
a)
A disgruntled employee deleting important files
b)
An external hacker performing a DDoS attack
c)
A phishing email from an unknown source
d)
Malware downloaded from the internet
2.
What is the main risk associated with poor staff training in cyber security?
a)
Staff may accidentally introduce vulnerabilities through unsafe practices
b)
Staff salaries will increase
c)
The company will need more computers
d)
Internet speeds will decrease
3.
Which scenario represents an internal threat caused by weak cyber security measures?
a)
Network servers left in an unlocked room allowing unauthorized physical access
b)
A virus downloaded from an email by an external hacker
c)
A DDOS attack from overseas
d)
SQL injection from an external website
4.
What is a common consequence of inadequate access controls?
a)
Unauthorized users gaining access to sensitive data
b)
Faster network speeds
c)
Better system performance
d)
Lower electricity costs
5.
Which of these is an example of poor cyber security practice by staff?
a)
Viewing untrustworthy websites that may contain malware
b)
Regularly updating passwords
c)
Reporting suspicious emails
d)
Using multi-factor authentication
6.
What is phishing?
a)
A social engineering attack using deceptive emails to steal sensitive information
b)
A type of firewall configuration
c)
A method of encrypting data
d)
A legitimate email from your bank
7.
What is a Denial of Service (DoS) attack?
a)
An attack that overwhelms a system with traffic to make it unavailable
b)
An attack that steals data from a database
c)
An attack that encrypts files for ransom
d)
An attack that installs antivirus software
8.
What is SQL injection?
a)
Inserting malicious SQL code into input fields to manipulate databases
b)
A method of backing up databases
c)
A way to speed up database queries
d)
Installing SQL server software
9.
What is the purpose of a brute force attack?
a)
To systematically try all possible password combinations until finding the correct one
b)
To physically damage computer hardware
c)
To send spam emails
d)
To create backup copies of files
10.
What makes zero-day exploits particularly dangerous?
a)
They target previously unknown vulnerabilities with no available patches
b)
They only work on zero-budget systems
c)
They happen at midnight
d)
They delete all files immediately
11.
Which of the following is a network vulnerability?
a)
Unsecured open ports on a network
b)
Strong encryption protocols
c)
Up-to-date antivirus software
d)
Regular security training
12.
What risk does using infected external storage devices pose?
a)
They can introduce malware into the network when connected
b)
They make computers run faster
c)
They improve network security
d)
They automatically backup all data
13.
What is a rogue access point?
a)
An unauthorized wireless access point installed on a network
b)
A legitimate company router
c)
A type of antivirus software
d)
A network monitoring tool
14.
Why are default passwords on network devices dangerous?
a)
They are publicly known and make devices easy targets for attackers
b)
They are too complex to remember
c)
They change automatically
d)
They provide better security
15.
What vulnerability does misconfigured firewall rules create?
a)
Unauthorized traffic may be allowed through the network
b)
Computers will run slower
c)
Printers won't work properly
d)
Email will be encrypted
16.
What is an organizational vulnerability?
a)
Weaknesses arising from inadequate processes and policies
b)
Hardware failures in servers
c)
Software bugs in applications
d)
Network connection speeds
17.
Why are overly broad file permissions a security risk?
a)
They allow users to access files they shouldn't have access to
b)
They make files load faster
c)
They improve system performance
d)
They automatically backup files
18.
What problem does a weak password policy create?
a)
Users create easily guessable passwords that are vulnerable to attacks
b)
Passwords become too complex
c)
Systems run slower
d)
Network speeds decrease
19.
What risk does poor change management create?
a)
Unauthorized or poorly tested changes can introduce new vulnerabilities
b)
Changes happen too quickly
c)
Systems become more secure
d)
Users are always notified
20.
Why is lack of security awareness training a vulnerability?
a)
Staff don't recognize or respond appropriately to security threats
b)
Training costs too much money
c)
Staff become too security conscious
d)
Systems become too complex
21.
What is a software vulnerability?
a)
A flaw in program code that can be exploited by attackers
b)
A feature that improves performance
c)
A type of antivirus
d)
A backup system
22.
Why is using pirated or illegal software dangerous?
a)
It often contains malware and won't receive security updates
b)
It's always faster than legitimate software
c)
It has better features
d)
It costs more money
23.
What is buffer overflow?
a)
When a program writes data beyond allocated memory, potentially allowing code execution
b)
When a hard drive becomes full
c)
When too many programs are running
d)
When the internet connection is slow
24.
What makes unpatched software a security risk?
a)
Known vulnerabilities remain unfixed and can be exploited
b)
It runs faster than patched software
c)
It uses less memory
d)
It has more features
25.
What is a logic bomb in software?
a)
Malicious code that executes when specific conditions are met
b)
A type of database optimization
c)
A security enhancement feature
d)
A backup mechanism
26.
What makes outdated operating systems vulnerable?
a)
They no longer receive security updates and patches
b)
They run too fast
c)
They use less electricity
d)
They have more features
27.
What OS vulnerability does poor maintenance create?
a)
Unpatched systems with known security flaws
b)
Systems that run too efficiently
c)
Faster boot times
d)
Better graphics performance
28.
Why is running unnecessary services on an OS a security risk?
a)
Each service is a potential attack vector that increases the attack surface
b)
Services make computers run faster
c)
They improve user experience
d)
They reduce system costs
29.
What is the risk of using default OS configurations?
a)
Default settings often prioritize convenience over security
b)
Systems become too secure
c)
Performance is maximized
d)
Users are restricted
30.
What makes kernel vulnerabilities particularly serious?
a)
The kernel has the highest system privileges and exploits can compromise the entire system
b)
Kernels are easy to replace
c)
They only affect one application
d)
They're impossible to detect
31.
What is the main security challenge with mobile device updates?
a)
Manufacturers often delay updates, leaving devices exposed to known vulnerabilities
b)
Updates happen too frequently
c)
Updates are too large
d)
Updates cost money
32.
Why are mobile apps from unofficial stores risky?
a)
They may contain malware and haven't been vetted by official security processes
b)
They're more expensive
c)
They use more battery
d)
They have fewer features
33.
What security risk do mobile devices face due to portability?
a)
Increased risk of theft or loss, potentially exposing data
b)
They get better signal strength
c)
They charge faster
d)
They have longer battery life
34.
Why is jailbreaking or rooting mobile devices dangerous?
a)
It removes built-in security protections and allows unrestricted access
b)
It improves device performance
c)
It extends battery life
d)
It's officially supported
35.
What risk do BYOD (Bring Your Own Device) policies create?
a)
Personal devices may have inadequate security or contain malware
b)
Companies save money on devices
c)
Employees are happier
d)
Network speeds increase
36.
What is a physical vulnerability in IT security?
a)
Security weaknesses related to physical access to hardware and facilities
b)
Software coding errors
c)
Network configuration issues
d)
Email phishing attempts
37.
Why is equipment theft a serious security concern?
a)
Stolen devices may contain sensitive data and provide access to systems
b)
It only costs the replacement value
c)
Data is always backed up
d)
Insurance covers everything
38.
What is social engineering?
a)
Manipulating people into divulging confidential information or performing actions
b)
Designing social media platforms
c)
Building construction techniques
d)
Engineering software applications
39.
What is tailgating in physical security?
a)
Following authorized personnel through secure doors without proper credentials
b)
Driving too closely behind other vehicles
c)
Following someone on social media
d)
A type of network attack
40.
Why should server rooms have restricted access?
a)
To prevent physical tampering, theft, or unauthorized configuration changes
b)
To reduce electricity costs
c)
To improve cooling efficiency
d)
To make cleaning easier
41.
What is a process vulnerability?
a)
Weaknesses in organizational procedures that can be exploited
b)
CPU manufacturing defects
c)
RAM memory errors
d)
Hard drive failures
42.
How can social engineering lead to data leaks?
a)
Attackers trick employees into revealing sensitive information or credentials
b)
Data automatically uploads to the internet
c)
Encryption fails spontaneously
d)
Backups are created too frequently
43.
Why is sharing security credentials dangerous?
a)
It prevents proper attribution of actions and compromises accountability
b)
It makes systems run faster
c)
It simplifies user management
d)
It reduces password complexity requirements
44.
What risk does poor incident reporting create?
a)
Security incidents may not be properly addressed or learned from
b)
Too many reports are generated
c)
Response times improve
d)
Costs decrease
45.
Why should data classification processes exist?
a)
To ensure appropriate protection measures are applied based on data sensitivity
b)
To make data harder to find
c)
To slow down data access
d)
To increase storage costs
46.
What security challenge do IoT devices present?
a)
They often have weak security, default passwords, and rarely receive updates
b)
They use too much bandwidth
c)
They're too expensive
d)
They require constant monitoring
47.
What risk does storing data in the cloud present?
a)
Data is stored on third-party servers with potential jurisdiction and access issues
b)
Cloud storage is always free
c)
Data loads faster locally
d)
Backups are unnecessary
48.
Why are smart home devices security concerns for remote workers?
a)
They may provide entry points to home networks used for corporate access
b)
They consume too much electricity
c)
They require expensive subscriptions
d)
They're difficult to set up
49.
What is the risk of inadequate cloud access controls?
a)
Unauthorized users may access, modify, or delete cloud-stored data
b)
Cloud services become cheaper
c)
Data synchronizes faster
d)
Storage space increases
50.
Why is vendor lock-in a cloud security concern?
a)
Difficulty migrating data if security issues arise or the provider fails
b)
Providers offer too many features
c)
Services are too reliable
d)
Costs decrease over time
51.
What is the purpose of site security locks?
a)
To control physical access to facilities and IT infrastructure
b)
To make buildings look more professional
c)
To reduce insurance costs only
d)
To comply with building codes
52.
What advantage do biometric access controls offer?
a)
They use unique physical characteristics that cannot be easily shared or stolen
b)
They're the cheapest security solution
c)
They work without electricity
d)
They never require maintenance
53.
What is the primary function of CCTV in physical security?
a)
To monitor and record activities for deterrence and investigation purposes
b)
To entertain security guards
c)
To replace all other security measures
d)
To increase electricity costs
54.
Why should network cabling be physically protected?
a)
To prevent unauthorized physical access for eavesdropping or network taps
b)
To improve signal quality only
c)
To reduce cable costs
d)
To meet aesthetic standards
55.
What is the purpose of a full backup?
a)
To create a complete copy of all data for recovery purposes
b)
To delete old files
c)
To speed up computers
d)
To compress data only
56.
What is the primary function of antivirus software?
a)
To detect, prevent, and remove malicious software from systems
b)
To speed up computer performance
c)
To manage network traffic
d)
To create backups
57.
How does a firewall protect a network?
a)
By filtering incoming and outgoing traffic based on predefined security rules
b)
By accelerating internet speeds
c)
By backing up data automatically
d)
By encrypting all files
58.
What is packet filtering in firewall operations?
a)
Examining individual packets and comparing them against security rules
b)
Physically filtering network cables
c)
Organizing files on hard drives
d)
Compressing data for transmission
59.
What is an application firewall?
a)
A firewall that controls input/output of specific applications
b)
Software for creating applications
c)
A tool for designing user interfaces
d)
A database management system
60.
Why must firewalls be regularly updated?
a)
To receive new security rules for emerging threats and vulnerabilities
b)
To use more system resources
c)
To slow down network traffic
d)
To increase costs
61.
What is the purpose of user authentication?
a)
To verify a user's identity before granting system access
b)
To create user accounts
c)
To delete old passwords
d)
To format hard drives
62.
What are the three factors of authentication?
a)
Something you know, something you have, something you are
b)
Username, password, email
c)
Hardware, software, network
d)
Input, processing, output
63.
What is multi-factor authentication (MFA)?
a)
Using two or more different types of authentication factors to verify identity
b)
Using multiple passwords
c)
Having multiple user accounts
d)
Logging in multiple times
64.
What makes passwords alone a weak authentication method?
a)
They can be guessed, stolen, or cracked through various attacks
b)
They're too complex to remember
c)
They change too frequently
d)
They cost money to create
65.
What is the principle of least privilege in access control?
a)
Users should only have the minimum access rights needed to perform their job
b)
Users should have administrator access by default
c)
Everyone should have the same access level
d)
Access should never be restricted
66.
What is encryption?
a)
Converting data into coded form that can only be read with the correct key
b)
Compressing files to save space
c)
Backing up data to the cloud
d)
Deleting sensitive information
67.
What is the difference between symmetric and asymmetric encryption?
a)
Symmetric uses one key for encryption and decryption; asymmetric uses a key pair
b)
Symmetric is always slower
c)
Asymmetric only works on text files
d)
They're the same thing
68.
Why should data be encrypted in transit?
a)
To protect it from interception and eavesdropping during transmission
b)
To make it transmit faster
c)
To reduce bandwidth usage
d)
To comply with shipping regulations
69.
What is the purpose of encrypting data at rest?
a)
To protect stored data from unauthorized access if storage media is compromised
b)
To reduce storage space requirements
c)
To improve file access speeds
d)
To organize files better
70.
What is a cryptographic key?
a)
A piece of information used by an encryption algorithm to transform data
b)
A physical key for locking servers
c)
A keyboard shortcut
d)
A type of network cable
71.
What is MAC address filtering?
a)
Restricting network access based on device hardware addresses
b)
Filtering emails from Mac computers
c)
A type of email spam filter
d)
Filtering based on IP addresses only
72.
What is network cloaking?
a)
Hiding a wireless network's SSID to make it less visible
b)
Using black network cables
c)
Encrypting all network traffic
d)
Shutting down the network
73.
What is WPA2 encryption?
a)
A security protocol for encrypting wireless network communications
b)
A type of password manager
c)
A web browser
d)
A file compression format
74.
What is trusted computing?
a)
Technology ensuring hardware has built-in security features via TPM chips
b)
Trusting all computers on a network
c)
Using only one computer brand
d)
Sharing passwords between users
75.
What is the purpose of access control authorization?
a)
Determining what resources authenticated users are permitted to access
b)
Creating user accounts
c)
Installing software updates
d)
Backing up data
76.
What is a LAN (Local Area Network)?
a)
A network covering a small geographical area like a building or campus
b)
A network spanning an entire country
c)
The global internet
d)
A personal device network
77.
What distinguishes a WAN from a LAN?
a)
WANs cover large geographical areas, often connecting multiple LANs
b)
WANs are always wireless
c)
WANs are faster than LANs
d)
WANs are cheaper to implement
78.
What is an intranet?
a)
A private network using internet protocols accessible only to organization members
b)
Another name for the internet
c)
A type of external website
d)
A public social network
79.
What is the difference between intranet and extranet?
a)
Extranets extend intranet access to selected external users like partners or customers
b)
Extranets are public while intranets are private
c)
Intranets use wireless while extranets use cables
d)
There is no difference
80.
What is cloud computing?
a)
Storing data and running applications on internet-accessible servers rather than local devices
b)
Using weather prediction software
c)
Storing files in the sky
d)
A type of wireless network
81.
What is the primary function of a network switch?
a)
To connect devices and forward data to specific destinations within a network
b)
To connect to the internet
c)
To filter malicious traffic
d)
To encrypt all data
82.
What is a router's primary function?
a)
To connect different networks and direct traffic between them
b)
To store files
c)
To scan for viruses
d)
To print documents
83.
What is a wireless access point?
a)
A device that creates wireless networks and connects wireless devices to wired networks
b)
A physical door entry system
c)
A type of firewall
d)
A backup storage device
84.
What is a network interface card (NIC)?
a)
Hardware that connects a device to a network
b)
A type of security camera
c)
Software for browsing the internet
d)
A storage device
85.
What is the purpose of a network cable?
a)
To provide physical connection for data transmission between devices
b)
To supply power only
c)
To hang decorations
d)
To measure distances
86.
What is risk assessment in cyber security?
a)
The process of identifying, analyzing, and evaluating security threats and vulnerabilities
b)
Installing antivirus software
c)
Creating user accounts
d)
Buying new computers
87.
What three categories are used to assess threat likelihood?
a)
Unlikely, Likely, Very Likely
b)
Low, Medium, High
c)
Yes, No, Maybe
d)
Good, Bad, Terrible
88.
What three levels are used to assess threat impact?
a)
Minor, Moderate, Major
b)
Small, Medium, Large
c)
Low, Mid, High
d)
Easy, Medium, Hard
89.
What is a risk severity matrix used for?
a)
To combine likelihood and impact to determine overall risk level
b)
To create employee schedules
c)
To organize files
d)
To design networks
90.
What should be included when documenting a risk assessment?
a)
Threat title, probability, impact level, risk severity, and detailed explanation
b)
Only the threat name
c)
Just the solution
d)
Employee names only
91.
What is the purpose of a cyber security plan?
a)
To document how an organization will prevent and respond to cyber threats
b)
To list employee names
c)
To describe building layouts
d)
To plan holiday schedules
92.
What should a cyber security plan include about protection measures?
a)
The risks addressed, actions to be taken, and reasons for implementation
b)
Only the cost of measures
c)
Just product brand names
d)
Employee vacation days
93.
What are the four categories of protection measures in a security plan?
a)
Hardware, Software, Physical, and Alternative risk management
b)
Fast, Slow, Medium, and Stop
c)
Internal, External, Hybrid, and Cloud
d)
Red, Blue, Green, and Yellow
94.
What is risk transfer in security planning?
a)
Shifting security responsibility to a third party, often through insurance or outsourcing
b)
Moving data between servers
c)
Transferring employees between departments
d)
Copying files to USB drives
95.
What is an acceptable use policy (AUP)?
a)
A policy defining appropriate and prohibited uses of organizational IT resources
b)
A document about office furniture
c)
A guide to using coffee machines
d)
A parking permit application
96.
What is a CSIRT?
a)
Computer Security Incident Response Team - specialists who handle security incidents
b)
Computer Support Information Resources Team
c)
Customer Service Internet Response Team
d)
Corporate Systems Installation Research Team
97.
What is the first step when a security incident is detected?
a)
Report it immediately to the CSIRT team leader per incident reporting procedures
b)
Delete all files
c)
Restart the computer
d)
Ignore it and hope it goes away
98.
What does 'containing damage' mean in incident response?
a)
Taking immediate actions to prevent the incident from spreading or worsening
b)
Physically putting computers in containers
c)
Compressing files to save space
d)
Creating backups of all data
99.
Why must evidence be protected during incident response?
a)
To preserve it for forensic analysis and potential legal prosecution
b)
To save storage space
c)
To improve system performance
d)
To reduce electricity costs
100.
What should be done after recovering from a security incident?
a)
Review the incident documentation and response to identify improvements
b)
Delete all records of the incident
c)
Pretend it never happened
d)
Blame specific employees
101.
What is a disaster recovery policy?
a)
A plan defining processes to recover business operations after a major disruptive event
b)
A fire escape plan
c)
A weather forecast system
d)
An employee wellness program
102.
What is RTO (Recovery Time Objective)?
a)
The maximum acceptable time to restore a system after an incident
b)
The time it takes to create backups
c)
Regular office hours
d)
The age of computer systems
103.
What is RPO (Recovery Point Objective)?
a)
The maximum acceptable amount of data loss measured in time
b)
The location where backups are stored
c)
The type of recovery software used
d)
The number of recovery attempts allowed
104.
What is a critical system in disaster recovery planning?
a)
A system essential for business operations whose failure causes significant damage
b)
Any computer in the organization
c)
The newest equipment
d)
The most expensive hardware
105.
What should disaster recovery procedures include?
a)
Step-by-step instructions for restoring each critical system
b)
General suggestions only
c)
Motivational quotes
d)
Company history
106.
What is the Data Protection Act?
a)
Legislation governing how personal data must be collected, stored, and processed
b)
A law about building security
c)
Regulations for power companies
d)
Rules for data compression
107.
What is the Computer Misuse Act?
a)
Legislation making unauthorized access to computer systems a criminal offense
b)
A law about computer repairs
c)
Regulations for software licenses
d)
Rules for computer disposal
108.
Why must organizations have a data protection policy?
a)
To ensure legal compliance and define how personal data is handled appropriately
b)
To reduce electricity costs
c)
To improve marketing
d)
To organize office space
109.
What legal obligation exists regarding data breaches?
a)
Organizations must report significant breaches to regulators and affected individuals
b)
Breaches should never be disclosed
c)
Only report if convenient
d)
Wait several years before reporting
110.
What is intellectual property in cyber security context?
a)
Legal rights over creations like software, designs, and proprietary information
b)
Smart people working in IT
c)
Physical property owned by the company
d)
Employee benefits packages
111.
What is digital forensics?
a)
The process of collecting, preserving, and analyzing digital evidence from incidents
b)
Cleaning computer keyboards
c)
Installing new software
d)
Creating backups
112.
Why must forensic evidence follow chain of custody?
a)
To prove evidence hasn't been tampered with and is admissible in court
b)
To organize files alphabetically
c)
To reduce storage costs
d)
To improve performance
113.
What is network forensics?
a)
Analyzing network traffic and logs to understand security incidents and attacker behavior
b)
Installing network cables
c)
Configuring routers
d)
Measuring bandwidth
114.
What is desktop forensics?
a)
Examining computers and storage devices to recover evidence and understand incidents
b)
Cleaning computer desktops
c)
Organizing desktop icons
d)
Choosing monitor backgrounds
115.
What should external service provider agreements include?
a)
Security requirements, responsibilities, service levels, and dispute resolution
b)
Only pricing information
c)
Marketing materials
d)
Company logos
116.
What is data loss in the context of cyber security threats?
a)
Permanent deletion or destruction of important information
b)
Misplacing a USB drive temporarily
c)
Slow data transfer speeds
d)
Data compression
117.
What is data theft?
a)
Unauthorized copying or exfiltration of sensitive information
b)
Legitimate data transfer
c)
Creating data backups
d)
Data analysis
118.
What is identity theft in cyber security?
a)
Using stolen personal information to impersonate someone for fraudulent purposes
b)
Forgetting your username
c)
Changing your password
d)
Creating a new account
119.
What operational disruption can cyber attacks cause?
a)
Preventing normal business operations and causing downtime
b)
Improving efficiency
c)
Faster processing speeds
d)
Better customer service
120.
What reputational damage can result from security incidents?
a)
Loss of customer trust, negative publicity, and damage to brand image
b)
Improved market share
c)
Better employee morale
d)
Increased sales