WorksheetsCybersecurity Quiz
Total questions: 40
Worksheet time: 20mins
Which vulnerability occurs when an application trusts client-side access controls?
SQL Injection
Broken Access Control
XSS
CSRF
Sanitizing user input mainly protects against:
DoS
SQL Injection
ARP Poisoning
MAC Flooding
Which HTTP attribute prevents cookies from being accessed via JavaScript?
Secure
Domain
HttpOnly
Path
A web page loads correctly but reveals database errors when special characters are entered. This indicates:
XSS
SQL Injection possibility
CSRF
Buffer Overflow
Which OWASP category includes excessive permissions?
Injection
Broken Authentication
Security Misconfiguration
Broken Access Control
Which attack forces a logged-in user to unknowingly perform an action?
Reflected XSS
Stored XSS
CSRF
Clickjacking
Encoding output is a countermeasure mainly against:
SQL Injection
Command Injection
XSS
Buffer Overflow
Which testing approach simulates real attacker behavior?
Code review
SAST
DAST
Secure design review
Which vulnerability exists when server-side validation is absent?
Client-side bypass
Logic flaw
Input validation failure
Directory traversal
Which HTTP verb is commonly restricted due to file upload risk?
GET
POST
PUT
HEAD
Which scan type sends packets with no TCP flags set?
SYN scan
NULL scan
FIN scan
ACK scan
A firewall allowing traffic based on connection state is:
Packet filter
Application firewall
Stateful firewall
Proxy firewall
Which protocol resolves IP to MAC address?
DNS
RARP
ARP
ICMP
Which attack manipulates ARP cache entries?
DNS spoofing
ARP poisoning
IP spoofing
MAC flooding
Which protocol is used for secure remote login?
Telnet
FTP
SSH
HTTP
Which tool is MOST suitable for packet capture and analysis?
Nmap
Nessus
Wireshark
Burp Suite
Which scanning technique is hardest to trace back to attacker?
SYN scan
FIN scan
IDLE scan
Connect scan
Which port is used by DNS?
21
53
80
443
Which network device separates broadcast domains?
Hub
Switch
Router
Bridge
A packet sent to broadcast address causing replies from multiple hosts indicates:
SYN Flood
Smurf Attack
Teardrop Attack
Replay Attack
Malware disguised as legitimate software is:
Worm
Virus
Trojan
Rootkit
Which malware modifies OS kernel for stealth?
Spyware
Virus
Rootkit
Bot
Which malware spreads without human interaction?
Trojan
Virus
Worm
Backdoor
A reverse shell is preferred by attackers because it:
Requires no listener
Bypasses outbound firewall rules
Encrypts payload automatically
Uses UDP only
Which technique hides data in images?
Encryption
Encoding
Steganography
Obfuscation
Which virus changes its signature on each infection?
Stealth
Multipartite
Polymorphic
Armored
Antivirus signature detection fails MOST against:
Known malware
Encrypted files
Zero-day malware
Email viruses
A botnet mainly consists of:
Firewalls
IDS systems
Compromised hosts
Honeypots
Which attack exhausts system resources?
Phishing
DoS
Sniffing
Spoofing
Which log should be cleared to hide login activity on Windows?
Application log
Security log
System log
Setup log
Which wireless encryption is considered insecure?
WPA2
WPA
WEP
AES
Which wireless attack creates a fake access point?
Sniffing
Rogue AP
Deauthentication
MAC filtering
Which attack uses SMS to trick users?
Phishing
Smishing
Vishing
Spoofing
Risk is BEST defined as:
Threat × Vulnerability
Asset ÷ Threat
Vulnerability × Control
Threat + Asset
Which control aims to discourage attackers?
Preventive
Detective
Deterrent
Corrective
Which principle ensures no single user has complete control?
Least privilege
Default deny
Separation of duties
Defense in depth
IDS differs from IPS because IDS:
Drops packets
Alters traffic
Generates alerts
Blocks IPs
Which security control is applied AFTER an incident?
Preventive
Detective
Corrective
Deterrent
Which authentication factor is a password?
Something you are
Something you have
Something you know
Something you access
Which assessment technique uses scenarios and workshops?
ALE
SLE
OCTAVE
CVSS
