wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CyberSecurity Fundamentals (PT1)

Total questions: 93

Worksheet time: 3600secs

Name
Class
Date
1.

A healthcare organization experiences a cyber incident where patient records are accessed by unauthorized users through a compromised web portal. The attackers did not modify or delete any data, but sensitive medical information was exposed. Which CIA principle is MOST affected?

a)

Integrity

b)

Availability

c)

Confidentiality

d)

Authentication

2.

An attacker exploits a previously unknown vulnerability in a company’s VPN system before the vendor releases any patch. The attack spreads silently and installs backdoors across multiple servers. This attack best describes:

a)

Insider threat

b)

Script kiddie activity

c)

Zero-day exploitation

d)

Social engineering

3.

A finance company’s website suddenly displays political messages protesting government policies. No data is stolen, but the attack damages public trust. The attackers are MOST likely:

a)

Cybercriminals

b)

Insiders

c)

Hacktivists

d)

Script kiddies

4.

Employees receive a phone call from someone claiming to be from IT support, asking them to reset their passwords urgently due to a “security breach.” This is an example of:

a)

Phishing

b)

Pretexting

c)

Vishing

d)

Quid pro quo

5.

An organization detects malware that constantly changes its code structure while keeping the same malicious behavior, making signature-based detection ineffective. This malware is classified as:

a)

Trojan

b)

Rootkit

c)

Polymorphic malware

d)

Worm

6.

A university’s research data is encrypted, and attackers demand payment in cryptocurrency. The data is still intact but inaccessible. Which CIA element is MOST affected?

a)

Integrity

b)

Confidentiality

c)

Availability

d)

Authentication

7.

A malicious program disguises itself as a free productivity tool. Once installed, it opens a hidden backdoor for attackers. This malware is a:

a)

Worm

b)

Virus

c)

Trojan

d)

Wiper

8.

A government agency discovers that sensitive files were completely erased with no possibility of recovery after a cyberattack. This attack most likely involved:

a)

Ransomware

b)

Rootkit

c)

Wiper malware

d)

Spyware

9.

A system becomes part of a botnet and begins communicating with an external server to receive instructions for future attacks. Which stage of the cyber attack lifecycle is this?

a)

Infection

b)

Persistence

c)

Command & Control

d)

Exfiltration

10.

After rebooting an infected system, the malware automatically reappears without user interaction. Which attack phase does this demonstrate?

a)

Infection

b)

Communication

c)

Persistence

d)

Cleanup

11.

A company deploys a system that monitors network traffic and alerts administrators when suspicious activity is detected, but it does not block traffic automatically. This system is a:

a)

Firewall

b)

IPS

c)

IDS

d)

VPN

12.

Another system actively blocks malicious traffic in real time without human intervention. This is an example of:

a)

IDS

b)

IPS

c)

Antivirus

d)

Proxy

13.

An attacker sends an email pretending to be HR, offering a “salary bonus” if the employee provides login credentials. This attack method is:

a)

Vishing

b)

Impersonation

c)

Phishing

d)

Pretexting

14.

A cybercriminal offers free “technical support” in exchange for system access. This is best described as:

a)

Pretexting

b)

Quid pro quo

c)

Vishing

d)

Tailgating

15.

A company encrypts customer data so that even if attackers steal it, they cannot read the contents. This primarily protects:

a)

Integrity

b)

Availability

c)

Confidentiality

d)

Performance

16.

Penetration testing differs because it:

a)

Trains employees

b)

Fixes vulnerabilities

c)

Simulates real attacks

d)

Creates malware

17.

A UK business adopts a government-backed framework to improve baseline cybersecurity hygiene. This framework is likely:

a)

ISO 27001

b)

GDPR

c)

UK Cyber Essentials Scheme

d)

NIST

18.

The main goal of the Cyber Essentials Scheme is to:

a)

Stop all hacking

b)

Replace firewalls

c)

Reduce common cyber threats

d)

Train hackers

19.

A company assigns one executive full responsibility for cybersecurity decisions and accountability. This is known as:

a)

Segregation of duties

b)

Least privilege

c)

Single Point of Accountability (SPOA)

d)

Risk transfer

20.

A policy that requires employees to follow documented procedures instead of trusting verbal instructions demonstrates:

a)

Zero trust

b)

Trust but verify

c)

Procedure over trust

d)

Social validation

21.

An attacker gains normal user access, then exploits system flaws to gain admin rights. This is called:

a)

Authentication bypass

b)

Credential stuffing

c)

Privilege escalation

d)

Lateral movement

22.

To reduce privilege escalation risks, organizations should apply:

a)

Open access

b)

Shared passwords

c)

Least privilege principle

d)

Admin-by-default

23.

A company detects suspicious behavior because system logs recorded abnormal login times. Logging primarily supports:

a)

Prevention

b)

Recovery

c)

Detection

d)

Encryption

24.

Monitoring network traffic continuously improves:

a)

Confidentiality

b)

Availability

c)

Visibility

d)

Encryption

25.

An Incident Response Policy defines:

a)

How to design software

b)

Steps to handle cyber incidents

c)

Marketing strategy

d)

Legal contracts

26.

The main purpose of an Incident Response Plan is to:

a)

Prevent attacks

b)

Replace firewalls

c)

Reduce damage and recovery time

d)

Train hackers

27.

A company ensures essential services continue operating during a cyberattack. This is part of:

a)

DRP

b)

BCP

c)

Risk management

d)

Auditing

28.

Restoring systems after a ransomware attack is mainly covered by:

a)

BCP

b)

DRP

c)

IDS

d)

SOP

29.

An attacker uses automated tools downloaded from the internet with little understanding of how they work. This attacker is likely a:

a)

Hacktivist

b)

APT actor

c)

Script kiddie

d)

Insider

30.

A highly funded group silently targets government infrastructure for months. This describes:

a)

Script kiddie

b)

Cybercriminal

c)

Advanced Persistent Threat (APT)

d)

Hacktivist

31.

A multinational company discovers that attackers accessed confidential financial data through a misconfigured cloud storage service. The data was copied but not altered or deleted. The system remained operational throughout the incident. Which security objective failed most directly?

a)

Integrity, because the data structure was exposed

b)

Availability, because services were disrupted

c)

Confidentiality, because unauthorized access occurred

d)

Authentication, because users were not verified

32.

An attacker exploits an unknown flaw in a VPN appliance, installs hidden backdoors, and maintains access for months without detection. No ransom is demanded, and no data is immediately stolen. This attack is best described as:

a)

Financially motivated cybercrime

b)

Opportunistic malware infection

c)

Advanced Persistent Threat (APT) activity

d)

Script kiddie experimentation

33.

A company receives a phone call from someone claiming to be a regulator. The caller threatens legal action unless sensitive compliance documents are emailed immediately. This attack combines:

a)

Phishing and impersonation

b)

Vishing and pretexting

c)

Quid pro quo and tailgating

d)

Malware and spoofing

34.

After a ransomware attack, encrypted files remain intact but inaccessible. Backups were not properly tested, and restoration fails. Which principle is MOST critically impacted in practice?

a)

Integrity, because data trust is lost

b)

Confidentiality, because encryption hides data

c)

Availability, because services and data access are disrupted

d)

Non-repudiation, because proof of actions is lost

35.

A malware sample changes its binary signature every time it spreads, while performing the same malicious actions. Traditional antivirus fails to detect it. This behavior indicates:

a)

Rootkit functionality

b)

Trojan obfuscation

c)

Polymorphic malware design

d)

Worm propagation

36.

An attacker sends a fake "security update" that installs spyware. The file looks legitimate and requires user installation. Which malware category applies?

a)

Worm, because it spreads automatically

b)

Virus, because it modifies files

c)

Trojan, because it disguises itself

d)

Rootkit, because it hides processes

37.

A system becomes part of a botnet and starts receiving encrypted instructions from a remote server. Which stage of the cyber attack lifecycle is this?

a)

Infection

b)

Persistence

c)

Command and Control (C2)

d)

Exfiltration

38.

A hospital’s systems reboot after patching, but malicious software automatically reinstalls itself without user action. This indicates:

a)

Reinfection

b)

Persistence mechanisms

c)

Privilege escalation

d)

Lateral movement

39.

An IDS alerts security staff about unusual traffic but does not stop the attack. A separate system blocks malicious packets in real time. Which statement is correct?

a)

Both systems are IDS

b)

The second system is an IPS

c)

The first system is a firewall

d)

Neither system provides protection

40.

A company encrypts customer data before storing it in the cloud. Attackers later steal the encrypted files. Which security goal was successfully maintained?

a)

Availability

b)

Integrity

c)

Confidentiality

d)

Authentication

41.

A vulnerability assessment report lists weaknesses but does not exploit them. A penetration test actively attacks those weaknesses. Which statement MOST accurate?

a)

VA and PT are identical

b)

VA is more aggressive

c)

PT simulates real-world attacks

d)

VA fixes vulnerabilities

42.

A UK-based SME adopts a government-backed framework to meet baseline cybersecurity requirements. Which framework is this?

a)

ISO 9001

b)

NIST CSF

c)

Cyber Essentials Scheme

d)

PCI DSS

43.

An organization assigns a single executive full responsibility for cybersecurity decisions and accountability. This approach is known as:

a)

Segregation of duties

b)

Zero Trust

c)

Single Point of Accountability (SPOA)

d)

Risk acceptance

44.

An employee follows a documented verification process instead of trusting a verbal request for sensitive data. This demonstrates:

a)

Trust-based security

b)

Zero Trust

c)

Procedure over trust

d)

Role-based access

45.

An attacker gains user access and then exploits system flaws to gain administrator privileges. This is an example of:

a)

Credential harvesting

b)

Lateral movement

c)

Privilege escalation

d)

Session hijacking

46.

A company limits users to only the access required for their job roles. Which principle is being applied?

a)

Separation of duties

b)

Open access

c)

Least privilege

d)

Trust but verify

47.

System logs reveal repeated failed login attempts at unusual hours, helping detect an intrusion. Logging primarily supports:

a)

Prevention

b)

Recovery

c)

Detection

d)

Encryption

48.

Continuous network monitoring improves:

a)

Encryption strength

b)

Data storage

c)

Visibility of threats

d)

User productivity

49.

An Incident Response Policy outlines roles, communication plans, and recovery steps during cyber incidents. Its main purpose is to:

a)

Prevent attacks

b)

Replace firewalls

c)

Reduce impact and response time

d)

Train hackers

50.

A company ensures essential services continue operating during a cyberattack. This is part of:

a)

Disaster Recovery Plan (DRP)

b)

Incident Response Plan (IRP)

c)

Business Continuity Plan (BCP)

d)

Risk Assessment

51.

Restoring systems after ransomware is mainly covered by:

a)

BCP

b)

DRP

c)

IDS

d)

SOP

52.

A highly funded group silently targets government systems for long-term espionage. This describes:

a)

Cybercriminals

b)

Hacktivists

c)

Advanced Persistent Threat (APT)

d)

Script kiddies

53.

A worm spreads across a network without user interaction. Its defining characteristic is:

a)

Disguise

b)

Encryption

c)

Self-propagation

d)

Stealth

54.

A rootkit is dangerous mainly because it:

a)

Encrypts files

b)

Deletes data

c)

Hides malicious activity

d)

Sends spam

55.

A DDoS attack primarily affects:

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Authentication

56.

Website defacement mainly impacts:

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Encryption

57.

Data leakage without modification affects:

a)

Integrity

b)

Availability

c)

Confidentiality

d)

Authentication

58.

Which protocol ensures secure web communication?

a)

FTP

b)

HTTP

c)

HTTPS

d)

SMB

59.

HTTPS security relies on:

a)

UDP

b)

SMB

c)

TLS/SSL

d)

ICMP

60.

Which protocol prioritizes speed over reliability?

a)

TCP

b)

UDP

c)

HTTPS

d)

SMTP

61.

Which protocol is mainly used for Windows file sharing?

a)

FTP

b)

SMB

c)

HTTPS

d)

SMTP

62.

The OSI model has:

a)

5 layers

b)

6 layers

c)

7 layers

d)

8 layers

63.

Encryption mainly occurs at the:

a)

Network layer

b)

Transport layer

c)

Presentation layer

d)

Physical layer

64.

An attacker deletes system logs to hide evidence. This primarily affects:

a)

Availability

b)

Integrity

c)

Confidentiality

d)

Performance

65.

An employee clicks a malicious attachment that installs malware. This stage is:

a)

Persistence

b)

Infection

c)

C2

d)

Cleanup

66.

Malware contacting a remote server for instructions is:

a)

Exfiltration

b)

Command & Control

c)

Persistence

d)

Reconnaissance

67.

A fake software update installs spyware. This is:

a)

Worm

b)

Trojan

c)

Rootkit

d)

Wiper

68.

An attacker convinces a receptionist to let them into a secure building. This is:

a)

Phishing

b)

Vishing

c)

Social engineering

d)

Malware

69.

Which control category includes firewalls and antivirus?

a)

Legal

b)

Procedural

c)

Technical

d)

Administrative

70.

Security policies fall under:

a)

Technical

b)

Administrative

c)

Legal

d)

Physical

71.

Incident response steps are:

a)

Technical controls

b)

Procedural controls

c)

Legal controls

d)

Physical controls

72.

Data protection laws are:

a)

Technical

b)

Procedural

73.

What is a zero-day exploit?

a)

a programming flaw that has not been discovered by the producer

b)

a recurring clock malfunction that resets each day

c)

a program loophole that allows access to source code after installation

d)

the average time a new piece of malware is active before it is discovered

74.

What is stuxnet?

a)

an app

b)

a malware

c)

a worm

d)

a virus

75.

What is the command to get IP Address in Linux System

a)

IPCONFIG

b)

IFCONFIG

c)

GREP

d)

HOPE

76.

TCP Full form

a)

Transmission Control Protocol

b)

Tally Compliant Product

c)

Transcutaneous Cardiac Pacing

d)

None of these

77.

What is the primary purpose of data encryption in backups?

a)

To protect data from unauthorized access

b)

To increase data processing speed

c)

To reduce storage costs

d)

To make data access faster

78.

Which of the following is NOT a task of the Red Team?

a)

Ethical hacking

b)

Social engineering

c)

Digital forensics

d)

Web app scanning

79.

What do biometric authentication systems use to authenticate identity?

a)

Passwords

b)

Physical characteristics

c)

Security questions

d)

PIN codes

80.

What is a brute force attack?

a)

A method of guessing every possible combination to achieve a goal

b)

A type of social engineering attack

c)

A way to encrypt data securely

d)

A method of phishing

81.

What is a common target for brute force attacks?

a)

Passwords or cryptographic keys

b)

Social media posts

c)

Email content

d)

Personal photos

82.

What is a rootkit?

a)

A type of malware that provides administrative access to a computer while concealing its presence.

b)

A type of malware that targets only Linux/Unix systems.

c)

A hardware component used to enhance computer performance.

d)

A software tool used by system administrators to enhance system security.

83.

Why are rootkits difficult to detect?

a)

Because they only target outdated operating systems.

b)

Because they activate after the operating system boots up.

c)

Because they alter system files and data reports to avoid detection.

d)

Because they are only installed on Linux/Unix systems.

84.

Why are rootkits difficult to detect?

a)

Because they only target outdated operating systems.

b)

Because they activate after the operating system boots up.

c)

Because they alter system files and data reports to avoid detection.

d)

Because they are only installed on Linux/Unix systems.

85.

Which function in the NIST CSF involves creating a communication plan for cybersecurity incidents?

a)

Detect

b)

Protect

c)

Respond

d)

Recover

86-90.

Understanding the Cyber Kill Chain

The Cyber Kill Chain is a framework developed to understand and counteract cyber threats. It breaks down the lifecycle of a cyberattack into distinct phases, providing a structured approach to identify and mitigate risks. By analyzing each phase, organizations can implement targeted defenses to disrupt malicious activities. This model is widely used in cybersecurity to enhance threat detection and response strategies.

The phases of the Cyber Kill Chain include reconnaissance, weaponization, delivery, exploitation, installation, command and control, and actions on objectives. Reconnaissance involves gathering information about the target, while weaponization focuses on creating malicious tools. Delivery refers to transmitting the weapon to the victim, and exploitation occurs when the attacker gains access by exploiting vulnerabilities. Installation allows the attacker to establish a foothold, followed by command and control to maintain communication. Finally, actions on objectives involve achieving the attacker's goals, such as data theft or system disruption.

Initial access techniques are critical in the early stages of the Cyber Kill Chain. These techniques include phishing emails, exploiting software vulnerabilities, and using stolen credentials. Phishing emails trick users into revealing sensitive information or clicking on malicious links. Exploiting software vulnerabilities targets weaknesses in applications or systems to gain unauthorized access. Stolen credentials, often obtained through social engineering or data breaches, allow attackers to bypass authentication mechanisms.

Understanding and addressing initial access techniques is essential for preventing cyberattacks. Organizations can implement measures such as employee training, regular software updates, and multi-factor authentication to reduce vulnerabilities. By focusing on the initial phases of the Cyber Kill Chain, cybersecurity teams can proactively defend against threats and minimize the impact of potential attacks. This approach underscores the importance of a comprehensive and layered security strategy in today's digital landscape.

86.

What is the primary purpose of the Cyber Kill Chain framework?

a)

To understand and counteract cyber threats

b)

To develop new software applications

c)

To enhance hardware performance

d)

To create social media strategies

87.

Which phase of the Cyber Kill Chain involves gathering information about the target?

a)

Reconnaissance

b)

Weaponization

c)

Delivery

d)

Exploitation

88.

What is an example of an initial access technique in the Cyber Kill Chain?

a)

Phishing emails

b)

Installing antivirus software

c)

Using firewalls

d)

Encrypting data

89.

How can organizations reduce vulnerabilities in the initial phases of the Cyber Kill Chain?

a)

Employee training and multi-factor authentication

b)

Increasing hardware storage

c)

Developing social media campaigns

d)

Using outdated software

90.

What does the 'actions on objectives' phase of the Cyber Kill Chain involve?

a)

Achieving the attacker's goals

b)

Gathering information about the target

c)

Creating malicious tools

d)

Transmitting the weapon to the victim

91.

Explain the Cyber Kill Chain model in detail.

4 lines
92.

A small company uses:

  • Web server

  • Employee laptops

  • Unsecured Wi-Fi and many other assets.

Perform a risk assessment (Hint: There are 7 steps first being Identifying assets)

4 lines
93.

Explain different risk treatment strategies:

  • Risk avoidance

  • Risk mitigation

  • Risk transfer

  • Risk acceptance

4 lines
94.

What is VPN tunneling?

a)

The process of securing your device's connection with a VPN server

b)

The process of encrypting your data

c)

The process of hiding your IP address

d)

The process of establishing a private network

95.

What does a VPN do to prevent ISP tracking?

a)

Encrypts your internet connection

b)

Hides your IP address

c)

Prevents your ISP from monitoring your online activity

d)

All of the above

96.

What can inadvertently cause a Denial of Service attack, as mentioned in the text?

a)

Improper system load balancing.

b)

Proper security monitoring using IDS/IPS.

c)

Configuring systems to use secure protocols like TCP.

d)

Inadequate bandwidth for the environment.

97.

Which method helps ensure network availability during a DDoS attack?

a)

Single-server hosting

b)

Network redundancy and load balancing

c)

Blocking all incoming traffic

d)

Ignoring the attack