wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

The Cybersecurity Intelligence Framework Overview

Total questions: 57

Worksheet time: 40mins

Name
Class
Date
1.

Which domain focuses on understanding adversaries and their potential impact?

a)

Incident Response and Forensics

b)

Protective Architecture and Controls

c)

Vulnerability and Risk Management

d)

Threat Intelligence and Impact Analysis

2.

Which domains in the diagram primarily focus on strengthening defenses rather than studying attackers? Select all that apply.

a)

Vulnerability and Risk Management

b)

Protective Architecture and Controls

c)

Threat Intelligence and Impact Analysis

d)

Incident Response and Forensics

3.

What is the main purpose of Incident Response and Forensics?

a)

Understanding how to fight back and learn

b)

Understanding your own weaknesses

c)

Understanding your defenses

d)

Understanding the enemy and the stakes

4.

Which scenario best describes a phishing attack in an enterprise environment?

a)

An email spoofing a bank requests a password reset

b)

A worm auto-replicates across internal subnets

c)

A DoS flood makes the website unavailable

d)

An insider copies files to a personal USB drive

5.

What distinguishes ransomware from general malware?

a)

Encrypts victim data and demands payment

b)

Self-replicates without user interaction

c)

Only disables service through traffic floods

d)

Primarily exfiltrates credentials and tokens

6.

Which attack primarily aims to overwhelm a service and block legitimate access?

a)

Phishing lures tricking users into disclosure

b)

Ransomware encrypting operational datasets

c)

Insider misuse of authorized permissions

d)

Denial of Service flooding traffic volumes

7.

Select ALL incidents that involve unauthorised access to sensitive information.

a)

Insider misuse to read HR files

b)

DoS traffic exhaustion of endpoints

c)

Phishing capture of login passwords

d)

Data breach of financial records

8.

Which business impact best matches a prolonged outage of an online store due to a DoS attack?

a)

Operational loss through service disruption

b)

Reputation loss from customer opinions

c)

Intellectual property loss of designs

d)

Financial loss from regulatory fines

9.

A company pays compensation after customer data theft. Which loss category is the most direct?

a)

Reputation loss from churn risk

b)

Operational loss reducing capacity

c)

Financial loss from payout costs

d)

Intellectual property loss exposure

10.

Which examples best illustrate reputation loss for an organisation?

a)

Manufacturing output decline from downtime

b)

Legal fees paid after compliance audit

c)

Customer churn after repeated outages

d)

Lowered trust over stolen personal data

11.

Competitors gain advantage through stolen trade secrets. What type of loss is this?

a)

Reputation decline without theft

b)

Financial expense increase only

c)

Operational capability reduction

d)

Intellectual property loss impact

12.

What is the core purpose of a Threat Intelligence Report?

a)

Deliver penetration test tool binaries

b)

Archive last year’s incident tickets only

c)

Offer static compliance policy templates

d)

Provide timely updates on changing threats

13.

Which items are commonly included in a Threat Intelligence Report? Select ALL that apply.

a)

Analysis of recently breached vulnerabilities

b)

Updates on new malware and phishing tactics

c)

Inventory of internal printers by location

d)

Information on threat actors and their methods

14.

Why is relying on last month’s threats insufficient for defenders?

a)

Threats evolve, requiring current awareness

b)

Vendors instantly patch every vulnerability

c)

Old threats are legally prohibited to study

d)

Networks auto-block all past attack types

15.

Which strategic question can a Threat Intelligence Report help decision-makers answer?

a)

Where should defensive efforts be focused next quarter?

b)

How is printer toner consumption calculated?

c)

Which employee has perfect attendance?

d)

What color theme suits the website UI?

16.

Which statement best defines a system vulnerability in IT?

a)

Any hardware failure without security impact

b)

A weakness, error, or flaw that can be exploited

c)

A rare issue with no practical risk

d)

A misconfiguration that cannot be exploited

17.

Which items are part of the internal attack surface in an organisation?

a)

Employee usage processes and credential handling

b)

Cloud accounts and insecure IoT devices

c)

Printer paper quality and office layouts

d)

Network configurations and external storage devices

18.

What is a common organisational vulnerability?

a)

Mandatory multi-factor authentication everywhere

b)

Poorly managed file permissions and privileges

c)

Strong password policies with regular audits

d)

Strict least-privilege enforcement across all roles

19.

Which example describes a software-related weakness?

a)

Updated drivers from trusted OEM vendors

b)

Encrypted backups stored offsite regularly

c)

Locked server rooms with CCTV monitoring

d)

Unpatched systems with known vulnerabilities

20.

Which scenario illustrates an operating system vulnerability?

a)

Running the latest LTS release with auto-updates

b)

Deploying the current OS patched within 24 hours

c)

Enforcing kernel lockdown and secure boot

d)

Using unsupported OS versions without critical updates

21.

Which mobile device risk is commonly highlighted?

a)

Elimination of vulnerabilities through monthly resets

b)

Guaranteed carrier-level encryption by default

c)

Reliance on OEMs causing delayed security updates

d)

Immediate OEM patch delivery for every model

22.

Which physical risk increases exposure to data loss?

a)

Locked cabinets and asset tracking tags

b)

Theft of equipment or loss of sensitive USB devices

c)

Biometric access control with visitor logs

d)

Secure courier handling for hardware returns

23.

Risk Severity is defined by which formula?

a)

Impact of Loss divided by Recovery Time

b)

Probability of Occurrence multiplied by Impact of Loss

c)

Threat Likelihood minus Asset Value

d)

Vulnerability Count plus Control Strength

24.

Match the probability descriptions to their labels.

a)

Very Likely: approximately once or more per day

b)

Likely: approximately every week or month

c)

Unlikely: approximately every year

25.

Which impact definition aligns with 'Major'?

a)

Minimal operational or financial disruption

b)

Significant disruption, financial loss, reputational damage

c)

Minor inconvenience with reversible outcomes

d)

Catastrophic loss threatening business viability

26.

What is the primary purpose of a Vulnerability Assessment Report?

a)

To document incident response post-breach only

b)

To identify, classify, and prioritize vulnerabilities

c)

To inventory hardware without security context

d)

To train users without technical findings

27.

Which tool-output pairing is correct for assessing weaknesses?

a)

Port scanners identify open and exploitable ports

b)

Website vulnerability scanners test for SQLi and XSS

c)

Password audits evaluate strength and access controls

d)

Vulnerability scanners measure network bandwidth usage

28.

Which framework often guides web application testing?

a)

IEEE 802.11 wireless standards

b)

OWASP Top 10 covering common threats

c)

ITIL service lifecycle processes

d)

NIST SP 800-171 baseline mappings

29.

Which strategic document logs each vulnerability, including its severity and tracks remediation?

a)

Asset Inventory Sheet

b)

Incident Postmortem Report

c)

Change Management Request form

d)

Risk Register used as master action plan

30.

Which layer focuses on securing the asset itself through encryption and robust backup procedures?

a)

Physical security foundation elements

b)

Network perimeter segmentation rules

c)

Data protection for encryption and backups

d)

System endpoint hardening steps

31.

Which controls are typically part of physical security in a layered framework?

a)

Biometric or card entry systems

b)

Site security locks and CCTV

c)

Packet filtering firewalls

d)

Protected cabling and cabinets

32.

Which principle should guide authentication and access control configurations?

a)

Defense in depth everywhere

b)

Zero trust for external users

c)

Principle of least privilege

d)

Encrypt everything by default

33.

Which items best represent system/host security activities?

a)

Anti-virus with signature and heuristics

b)

MAC address filtering

c)

Regular patching schedules

d)

Operating system hardening

34.

Which firewall technique inspects each packet against a predefined ruleset?

a)

Packet filtering and inspection

b)

Network address translation process

c)

Application layer awareness filter

d)

Stateful deep packet offloading

35.

What is the role of Network Address Translation (NAT) in security?

a)

Encrypts wireless traffic end-to-end

b)

Hides internal device addresses

c)

Blocks all inbound connections

d)

Enforces certificate pinning

36.

Which statements about symmetric and asymmetric encryption are correct?

a)

Symmetric uses the same key for both directions

b)

Asymmetric encrypts with the public key and decrypts with the private key

c)

Symmetric is commonly used for full disk encryption

d)

Asymmetric is preferred for hashing user passwords

37.

Which use case aligns with asymmetric encryption for protecting data in transit?

a)

DRM for licensed media files

b)

Incremental backup routines

c)

HTTPS with TLS securing web traffic

d)

Full file and folder encryption

38.

Which authentication method uses encrypted tickets and never transmits passwords over the network?

a)

SAML assertions

b)

RADIUS server

c)

OAuth 2.0 tokens

d)

Kerberos protocol

39.

What is the main purpose of architecture reviews and control audits?

a)

Provide long-term data archival only

b)

Generate vendor marketing materials

c)

Replace the need for firewalls entirely

d)

Verify controls are designed and operating

40.

Which statements accurately describe key report types in control audits?

a)

Internal control audit logs summarize routine monitoring of controls

b)

TOR reports focus on anonymizing web traffic for users

c)

Third-party design reviews identify flaws before implementation

d)

Penetration test reports assess real-world defenses via simulated attacks

41.

During identification, which activity best indicates a possible security incident?

a)

Restoring services from backups

b)

Monitoring unusual network traffic

c)

Writing recommendations for management

d)

Patching vulnerable applications

42.

Which actions belong to the containment phase?

a)

Define roles and responsibilities

b)

Remove malware remnants

c)

Quarantine affected systems

d)

Disconnect compromised devices

43.

Eradication primarily involves which set of tasks?

a)

Quarantining devices for isolation

b)

Updating controls and removing malware

c)

Imaging drives to preserve evidence

d)

Restoring services to normal state

44.

Recovery is best described as:

a)

Analyzing logs for attacker paths

b)

Returning systems to normal operations

c)

Documenting a detailed incident timeline

d)

Agreeing on packet capture methodology

45.

In the lessons learned phase, which outcome is most appropriate?

a)

Isolation of compromised endpoints

b)

Live capture of volatile memory data

c)

Formal post-incident analysis for improvements

d)

Immediate malware eradication steps

46.

Desktop forensics prioritises which first step to preserve evidence integrity?

a)

Confiscation of devices

b)

Scan routers and firewalls

c)

Review business impact

d)

Push synthetic test traffic

47.

Why is system imaging critical in desktop forensics?

a)

It pushes test traffic to detect issues

b)

It creates a bit-for-bit copy for analysis

c)

It restores affected systems from backups

d)

It updates controls to prevent recurrence

48.

Which risk is unique to live forensics on running systems?

a)

Accidentally blocking network access

b)

Overlooking the root cause in reporting

c)

Changing or corrupting volatile evidence

d)

Missing logs from core switches

49.

Network forensics commonly uses which pair of tool approaches?

a)

Device confiscation procedures

b)

Drive imaging of endpoints

c)

Active tests that push traffic

d)

Passive monitoring, such as packet sniffers

50.

What is the primary purpose of a post-incident forensic report?

a)

Provide a definitive account from detection to resolution

b)

Restore services to normal operations quickly

c)

Perform packet sniffing across live traffic

d)

Capture only volatile memory from endpoints

51.

Which contents should a thorough post-incident report include? Select all that apply.

a)

Scope and Impact assessment

b)

Response Actions Taken summary

c)

Root Cause Analysis details

d)

Live memory dump methodology

52.

Which sequence best represents the continuous improvement cycle shown in the diagram for moving from reactive to proactive security?

a)

Incident Response → Protective Controls → Vulnerability Management → Threat Intelligence

b)

Threat Intelligence → Vulnerability Management → Protective Controls → Incident Response

c)

Vulnerability Management → Threat Intelligence → Incident Response → Protective Controls

d)

Protective Controls → Incident Response → Threat Intelligence → Vulnerability Management

53.

In the diagram, which activities directly support a proactive, intelligence-led resilience posture? Select all that apply.

a)

Control audits validating safeguards

b)

Vulnerability assessments across critical assets

c)

Post-incident reports only after breaches

d)

Threat reports that inform emerging risks

54.

What is the primary role of security reports in the depicted framework?

a)

Static documentation of past incidents

b)

Endpoints concluding the security process

c)

Catalysts that fuel continuous improvement

d)

Compliance artifacts for annual audits

55.

Which action is most appropriate during the containment phase of incident response?

a)

Conducting a post-incident review

b)

Publishing a public statement about the incident

c)

Isolating impacted systems from the network

d)

Erasing all affected data immediately

56.

What is the primary risk when using outdated software versions in an enterprise?

a)

Reduced hardware compatibility

b)

Increased vulnerability to exploits

c)

Higher licensing costs

d)

Slower user interface performance

57.

Which method best helps prevent unauthorized access to sensitive data?

a)

Allowing shared passwords for convenience

b)

Implementing least privilege access controls

c)

Disabling all encryption protocols

d)

Using default system configurations