Font size
WorksheetsCyberSecurity Fundamentals (PT1)
Total questions: 93
Worksheet time: 3600secs
A healthcare organization experiences a cyber incident where patient records are accessed by unauthorized users through a compromised web portal. The attackers did not modify or delete any data, but sensitive medical information was exposed. Which CIA principle is MOST affected?
Integrity
Availability
Confidentiality
Authentication
An attacker exploits a previously unknown vulnerability in a company’s VPN system before the vendor releases any patch. The attack spreads silently and installs backdoors across multiple servers. This attack best describes:
Insider threat
Script kiddie activity
Zero-day exploitation
Social engineering
A finance company’s website suddenly displays political messages protesting government policies. No data is stolen, but the attack damages public trust. The attackers are MOST likely:
Cybercriminals
Insiders
Hacktivists
Script kiddies
Employees receive a phone call from someone claiming to be from IT support, asking them to reset their passwords urgently due to a “security breach.” This is an example of:
Phishing
Pretexting
Vishing
Quid pro quo
An organization detects malware that constantly changes its code structure while keeping the same malicious behavior, making signature-based detection ineffective. This malware is classified as:
Trojan
Rootkit
Polymorphic malware
Worm
A university’s research data is encrypted, and attackers demand payment in cryptocurrency. The data is still intact but inaccessible. Which CIA element is MOST affected?
Integrity
Confidentiality
Availability
Authentication
A malicious program disguises itself as a free productivity tool. Once installed, it opens a hidden backdoor for attackers. This malware is a:
Worm
Virus
Trojan
Wiper
A government agency discovers that sensitive files were completely erased with no possibility of recovery after a cyberattack. This attack most likely involved:
Ransomware
Rootkit
Wiper malware
Spyware
A system becomes part of a botnet and begins communicating with an external server to receive instructions for future attacks. Which stage of the cyber attack lifecycle is this?
Infection
Persistence
Command & Control
Exfiltration
After rebooting an infected system, the malware automatically reappears without user interaction. Which attack phase does this demonstrate?
Infection
Communication
Persistence
Cleanup
A company deploys a system that monitors network traffic and alerts administrators when suspicious activity is detected, but it does not block traffic automatically. This system is a:
Firewall
IPS
IDS
VPN
Another system actively blocks malicious traffic in real time without human intervention. This is an example of:
IDS
IPS
Antivirus
Proxy
An attacker sends an email pretending to be HR, offering a “salary bonus” if the employee provides login credentials. This attack method is:
Vishing
Impersonation
Phishing
Pretexting
A cybercriminal offers free “technical support” in exchange for system access. This is best described as:
Pretexting
Quid pro quo
Vishing
Tailgating
A company encrypts customer data so that even if attackers steal it, they cannot read the contents. This primarily protects:
Integrity
Availability
Confidentiality
Performance
Penetration testing differs because it:
Trains employees
Fixes vulnerabilities
Simulates real attacks
Creates malware
A UK business adopts a government-backed framework to improve baseline cybersecurity hygiene. This framework is likely:
ISO 27001
GDPR
UK Cyber Essentials Scheme
NIST
The main goal of the Cyber Essentials Scheme is to:
Stop all hacking
Replace firewalls
Reduce common cyber threats
Train hackers
A company assigns one executive full responsibility for cybersecurity decisions and accountability. This is known as:
Segregation of duties
Least privilege
Single Point of Accountability (SPOA)
Risk transfer
A policy that requires employees to follow documented procedures instead of trusting verbal instructions demonstrates:
Zero trust
Trust but verify
Procedure over trust
Social validation
An attacker gains normal user access, then exploits system flaws to gain admin rights. This is called:
Authentication bypass
Credential stuffing
Privilege escalation
Lateral movement
To reduce privilege escalation risks, organizations should apply:
Open access
Shared passwords
Least privilege principle
Admin-by-default
A company detects suspicious behavior because system logs recorded abnormal login times. Logging primarily supports:
Prevention
Recovery
Detection
Encryption
Monitoring network traffic continuously improves:
Confidentiality
Availability
Visibility
Encryption
An Incident Response Policy defines:
How to design software
Steps to handle cyber incidents
Marketing strategy
Legal contracts
The main purpose of an Incident Response Plan is to:
Prevent attacks
Replace firewalls
Reduce damage and recovery time
Train hackers
A company ensures essential services continue operating during a cyberattack. This is part of:
DRP
BCP
Risk management
Auditing
Restoring systems after a ransomware attack is mainly covered by:
BCP
DRP
IDS
SOP
An attacker uses automated tools downloaded from the internet with little understanding of how they work. This attacker is likely a:
Hacktivist
APT actor
Script kiddie
Insider
A highly funded group silently targets government infrastructure for months. This describes:
Script kiddie
Cybercriminal
Advanced Persistent Threat (APT)
Hacktivist
A multinational company discovers that attackers accessed confidential financial data through a misconfigured cloud storage service. The data was copied but not altered or deleted. The system remained operational throughout the incident. Which security objective failed most directly?
Integrity, because the data structure was exposed
Availability, because services were disrupted
Confidentiality, because unauthorized access occurred
Authentication, because users were not verified
An attacker exploits an unknown flaw in a VPN appliance, installs hidden backdoors, and maintains access for months without detection. No ransom is demanded, and no data is immediately stolen. This attack is best described as:
Financially motivated cybercrime
Opportunistic malware infection
Advanced Persistent Threat (APT) activity
Script kiddie experimentation
A company receives a phone call from someone claiming to be a regulator. The caller threatens legal action unless sensitive compliance documents are emailed immediately. This attack combines:
Phishing and impersonation
Vishing and pretexting
Quid pro quo and tailgating
Malware and spoofing
After a ransomware attack, encrypted files remain intact but inaccessible. Backups were not properly tested, and restoration fails. Which principle is MOST critically impacted in practice?
Integrity, because data trust is lost
Confidentiality, because encryption hides data
Availability, because services and data access are disrupted
Non-repudiation, because proof of actions is lost
A malware sample changes its binary signature every time it spreads, while performing the same malicious actions. Traditional antivirus fails to detect it. This behavior indicates:
Rootkit functionality
Trojan obfuscation
Polymorphic malware design
Worm propagation
An attacker sends a fake "security update" that installs spyware. The file looks legitimate and requires user installation. Which malware category applies?
Worm, because it spreads automatically
Virus, because it modifies files
Trojan, because it disguises itself
Rootkit, because it hides processes
A system becomes part of a botnet and starts receiving encrypted instructions from a remote server. Which stage of the cyber attack lifecycle is this?
Infection
Persistence
Command and Control (C2)
Exfiltration
A hospital’s systems reboot after patching, but malicious software automatically reinstalls itself without user action. This indicates:
Reinfection
Persistence mechanisms
Privilege escalation
Lateral movement
An IDS alerts security staff about unusual traffic but does not stop the attack. A separate system blocks malicious packets in real time. Which statement is correct?
Both systems are IDS
The second system is an IPS
The first system is a firewall
Neither system provides protection
A company encrypts customer data before storing it in the cloud. Attackers later steal the encrypted files. Which security goal was successfully maintained?
Availability
Integrity
Confidentiality
Authentication
A vulnerability assessment report lists weaknesses but does not exploit them. A penetration test actively attacks those weaknesses. Which statement MOST accurate?
VA and PT are identical
VA is more aggressive
PT simulates real-world attacks
VA fixes vulnerabilities
A UK-based SME adopts a government-backed framework to meet baseline cybersecurity requirements. Which framework is this?
ISO 9001
NIST CSF
Cyber Essentials Scheme
PCI DSS
An organization assigns a single executive full responsibility for cybersecurity decisions and accountability. This approach is known as:
Segregation of duties
Zero Trust
Single Point of Accountability (SPOA)
Risk acceptance
An employee follows a documented verification process instead of trusting a verbal request for sensitive data. This demonstrates:
Trust-based security
Zero Trust
Procedure over trust
Role-based access
An attacker gains user access and then exploits system flaws to gain administrator privileges. This is an example of:
Credential harvesting
Lateral movement
Privilege escalation
Session hijacking
A company limits users to only the access required for their job roles. Which principle is being applied?
Separation of duties
Open access
Least privilege
Trust but verify
System logs reveal repeated failed login attempts at unusual hours, helping detect an intrusion. Logging primarily supports:
Prevention
Recovery
Detection
Encryption
Continuous network monitoring improves:
Encryption strength
Data storage
Visibility of threats
User productivity
An Incident Response Policy outlines roles, communication plans, and recovery steps during cyber incidents. Its main purpose is to:
Prevent attacks
Replace firewalls
Reduce impact and response time
Train hackers
A company ensures essential services continue operating during a cyberattack. This is part of:
Disaster Recovery Plan (DRP)
Incident Response Plan (IRP)
Business Continuity Plan (BCP)
Risk Assessment
Restoring systems after ransomware is mainly covered by:
BCP
DRP
IDS
SOP
A highly funded group silently targets government systems for long-term espionage. This describes:
Cybercriminals
Hacktivists
Advanced Persistent Threat (APT)
Script kiddies
A worm spreads across a network without user interaction. Its defining characteristic is:
Disguise
Encryption
Self-propagation
Stealth
A rootkit is dangerous mainly because it:
Encrypts files
Deletes data
Hides malicious activity
Sends spam
A DDoS attack primarily affects:
Confidentiality
Integrity
Availability
Authentication
Website defacement mainly impacts:
Confidentiality
Integrity
Availability
Encryption
Data leakage without modification affects:
Integrity
Availability
Confidentiality
Authentication
Which protocol ensures secure web communication?
FTP
HTTP
HTTPS
SMB
HTTPS security relies on:
UDP
SMB
TLS/SSL
ICMP
Which protocol prioritizes speed over reliability?
TCP
UDP
HTTPS
SMTP
Which protocol is mainly used for Windows file sharing?
FTP
SMB
HTTPS
SMTP
The OSI model has:
5 layers
6 layers
7 layers
8 layers
Encryption mainly occurs at the:
Network layer
Transport layer
Presentation layer
Physical layer
An attacker deletes system logs to hide evidence. This primarily affects:
Availability
Integrity
Confidentiality
Performance
An employee clicks a malicious attachment that installs malware. This stage is:
Persistence
Infection
C2
Cleanup
Malware contacting a remote server for instructions is:
Exfiltration
Command & Control
Persistence
Reconnaissance
A fake software update installs spyware. This is:
Worm
Trojan
Rootkit
Wiper
An attacker convinces a receptionist to let them into a secure building. This is:
Phishing
Vishing
Social engineering
Malware
Which control category includes firewalls and antivirus?
Legal
Procedural
Technical
Administrative
Security policies fall under:
Technical
Administrative
Legal
Physical
Incident response steps are:
Technical controls
Procedural controls
Legal controls
Physical controls
Data protection laws are:
Technical
Procedural
What is a zero-day exploit?
a programming flaw that has not been discovered by the producer
a recurring clock malfunction that resets each day
a program loophole that allows access to source code after installation
the average time a new piece of malware is active before it is discovered
What is stuxnet?
an app
a malware
a worm
a virus
What is the command to get IP Address in Linux System
IPCONFIG
IFCONFIG
GREP
HOPE
TCP Full form
Transmission Control Protocol
Tally Compliant Product
Transcutaneous Cardiac Pacing
None of these
What is the primary purpose of data encryption in backups?
To protect data from unauthorized access
To increase data processing speed
To reduce storage costs
To make data access faster
Which of the following is NOT a task of the Red Team?
Ethical hacking
Social engineering
Digital forensics
Web app scanning
What do biometric authentication systems use to authenticate identity?
Passwords
Physical characteristics
Security questions
PIN codes
What is a brute force attack?
A method of guessing every possible combination to achieve a goal
A type of social engineering attack
A way to encrypt data securely
A method of phishing
What is a common target for brute force attacks?
Passwords or cryptographic keys
Social media posts
Email content
Personal photos
What is a rootkit?
A type of malware that provides administrative access to a computer while concealing its presence.
A type of malware that targets only Linux/Unix systems.
A hardware component used to enhance computer performance.
A software tool used by system administrators to enhance system security.
Why are rootkits difficult to detect?
Because they only target outdated operating systems.
Because they activate after the operating system boots up.
Because they alter system files and data reports to avoid detection.
Because they are only installed on Linux/Unix systems.
Why are rootkits difficult to detect?
Because they only target outdated operating systems.
Because they activate after the operating system boots up.
Because they alter system files and data reports to avoid detection.
Because they are only installed on Linux/Unix systems.
Which function in the NIST CSF involves creating a communication plan for cybersecurity incidents?
Detect
Protect
Respond
Recover
Understanding the Cyber Kill Chain
The Cyber Kill Chain is a framework developed to understand and counteract cyber threats. It breaks down the lifecycle of a cyberattack into distinct phases, providing a structured approach to identify and mitigate risks. By analyzing each phase, organizations can implement targeted defenses to disrupt malicious activities. This model is widely used in cybersecurity to enhance threat detection and response strategies.
The phases of the Cyber Kill Chain include reconnaissance, weaponization, delivery, exploitation, installation, command and control, and actions on objectives. Reconnaissance involves gathering information about the target, while weaponization focuses on creating malicious tools. Delivery refers to transmitting the weapon to the victim, and exploitation occurs when the attacker gains access by exploiting vulnerabilities. Installation allows the attacker to establish a foothold, followed by command and control to maintain communication. Finally, actions on objectives involve achieving the attacker's goals, such as data theft or system disruption.
Initial access techniques are critical in the early stages of the Cyber Kill Chain. These techniques include phishing emails, exploiting software vulnerabilities, and using stolen credentials. Phishing emails trick users into revealing sensitive information or clicking on malicious links. Exploiting software vulnerabilities targets weaknesses in applications or systems to gain unauthorized access. Stolen credentials, often obtained through social engineering or data breaches, allow attackers to bypass authentication mechanisms.
Understanding and addressing initial access techniques is essential for preventing cyberattacks. Organizations can implement measures such as employee training, regular software updates, and multi-factor authentication to reduce vulnerabilities. By focusing on the initial phases of the Cyber Kill Chain, cybersecurity teams can proactively defend against threats and minimize the impact of potential attacks. This approach underscores the importance of a comprehensive and layered security strategy in today's digital landscape.
What is the primary purpose of the Cyber Kill Chain framework?
To understand and counteract cyber threats
To develop new software applications
To enhance hardware performance
To create social media strategies
Which phase of the Cyber Kill Chain involves gathering information about the target?
Reconnaissance
Weaponization
Delivery
Exploitation
What is an example of an initial access technique in the Cyber Kill Chain?
Phishing emails
Installing antivirus software
Using firewalls
Encrypting data
How can organizations reduce vulnerabilities in the initial phases of the Cyber Kill Chain?
Employee training and multi-factor authentication
Increasing hardware storage
Developing social media campaigns
Using outdated software
What does the 'actions on objectives' phase of the Cyber Kill Chain involve?
Achieving the attacker's goals
Gathering information about the target
Creating malicious tools
Transmitting the weapon to the victim
Explain the Cyber Kill Chain model in detail.
A small company uses:
Web server
Employee laptops
Unsecured Wi-Fi and many other assets.
Perform a risk assessment (Hint: There are 7 steps first being Identifying assets)
Explain different risk treatment strategies:
Risk avoidance
Risk mitigation
Risk transfer
Risk acceptance
What is VPN tunneling?
The process of securing your device's connection with a VPN server
The process of encrypting your data
The process of hiding your IP address
The process of establishing a private network
What does a VPN do to prevent ISP tracking?
Encrypts your internet connection
Hides your IP address
Prevents your ISP from monitoring your online activity
All of the above
What can inadvertently cause a Denial of Service attack, as mentioned in the text?
Improper system load balancing.
Proper security monitoring using IDS/IPS.
Configuring systems to use secure protocols like TCP.
Inadequate bandwidth for the environment.
Which method helps ensure network availability during a DDoS attack?
Single-server hosting
Network redundancy and load balancing
Blocking all incoming traffic
Ignoring the attack
