WorksheetsPage 1
Total questions: 120
Worksheet time: 3600secs
Network security refers to:
Protecting hardware only
Protecting data during transmission
Protecting data, devices, and resources in a network
Monitoring user behavior
The main objective of network security is to:
Increase internet speed
Prevent unauthorized access
Reduce bandwidth
Increase server load
Network security is mainly concerned with:
Software installation
Protecting data integrity, confidentiality, and availability
Backup only
Device configuration
Network security ensures:
High profit
Safe and reliable communication
Instant data delivery
More storage
Firewalls, antivirus, and encryption are examples of:
Network security tools
Routing protocols
Web applications
Data compression tools
Network security is mainly needed due to:
Faster computers
Increase in cyber threats and attacks
Low internet speed
Cheap memory devices
Network security protects against:
Viruses and malware
Unauthorized access
Data theft
All of the above
Which factor increases the need for network security?
Decrease in networking
More isolated systems
Growth of internet and online services
Less use of mobile devices
Security helps organizations to:
Slow down network
Lose data
Maintain privacy of information
Allow unauthorized usage
A network without proper security may result in:
Data breaches
Unauthorized modifications
Service disruption
All of these
Confidentiality refers to:
Ensuring data is correct and accurate
Ensuring data is available when needed
Preventing unauthorized access to information
Ensuring fast network speed
Integrity ensures that:
Data is kept secret
Data is not altered or tampered
Data is always available
Data is authenticated
Availability means:
Data is confidential
Data is correct
Data is accessible to authorized users
Data is modified
Which of the following is a threat to availability?
DDoS attack
Encryption
Firewall
Authentication
Authentication means:
Hiding data
Proving identity of a user
Blocking access
Encrypting data
Non-repudiation means:
User cannot deny sending a message
Data is encrypted
Data is compressed
User is anonymous
Which principle ensures that access is given only to authorized users?
Accountability
Confidentiality
Authorization
Integrity
Accountability is achieved through:
Logging and monitoring
Encryption
Compression
Signal modulation
Which principle ensures that users perform only allowed actions?
Authentication
Authorization
Integrity
Availability
Which attack targets confidentiality?
Sniffing
DDoS
Server crash
Hardware failure
Which attack targets integrity?
Data tampering
Password stealing
DNS poisoning
Both A and C
Which attack targets availability?
DDoS
Spoofing
Keylogging
SQL injection
The primary role of encryption is to ensure:
Availability
Integrity
Confidentiality
Accountability
A cyber attack is defined as:
Installation of antivirus
An attempt to damage, steal or gain unauthorized access to data
Running a legal program
Increasing internet speed
Attackers who break into systems without permission are called:
Hacktivists
Black-hat hackers
White-hat hackers
Analysts
Which of the following is a passive attack?
Eavesdropping
Virus infection
SQL injection
DoS attack
Which is an active attack?
Traffic monitoring
Data modification
Encryption
Backup
Active attacks mainly aim to:
Observe data
Steal data silently
Modify, delete, or inject data
Speed up communication
A Denial-of-Service (DoS) attack targets:
Confidentiality
Integrity
Availability
Authentication
Which attack floods a server with fake traffic?
Email spoofing
DDoS attack
Keylogging
Brute force
Which attack tricks users by showing fake websites or messages?
Phishing
Sniffing
Spoofing
DoS
Malware that replicates itself across networks is called:
Worm
Virus
Trojan
Rootkit
Malware hidden within legitimate software is called:
Worm
Trojan horse
Botnet
Sniffer
An attack where an attacker secretly listens to network traffic is:
Phishing
Spoofing
Eavesdropping
DoS
SQL injection exploits vulnerabilities in:
Operating systems
Databases and web applications
Network routers
Browsers only
Brute-force attack is used to:
Steal hardware
Guess passwords
Monitor network
Encrypt data
Ransomware attacks do what?
Encrypt user data and demand payment
Remove malware
Man-in-the-middle attack means:
Two systems communicating normally
An attacker intercepts and modifies communication
Server malfunction
User error
Which of the following is considered a criminal cyber attack?
Unauthorized system access
Sending encrypted data
Backing up files
Installing antivirus
Identity theft is a form of:
Legal activity
Ethical hacking
Cybercrime
Normal operation
Stealing banking credentials is an example of:
Legal attack
Criminal attack
Network upgrade
System testing
Botnets are commonly used for:
File backups
Criminal activities like DDoS attacks
Antivirus programs
Legal auditing
Cyberstalking is considered:
A criminal attack
A passive attack
A legal activity
A network service
A legal attack performed to test systems is called:
Malware attack
Cybercrime
Penetration testing
Phishing
Ethical hackers are also known as:
Black hats
White-hat hackers
Criminals
Rogue agents
Legal attacks require:
No permission
Written authorization
Anonymous identity
Malware usage
The aim of a legal attack is to:
Steal data
Damage the system
Test security strength
Shut down servers
Vulnerability assessment is a:
Criminal activity
Legal security evaluation
Malware infection
Data theft
Which is NOT a legal attack?
Penetration testing
Bug bounty testing
Ethical hacking
Installing spyware without consent
Legal attacks follow which rule?
No rules
Perform secretly
Must follow scope and permission
Use malware only
Passive attacks mainly aim to:
Modify data
Destroy data
Observe or monitor data
Overload the system
Which of the following is a passive attack?
SQL Injection
Eavesdropping
DDoS attack
Data modification
Passive attacks violate which security principle the most?
Integrity
Availability
Confidentiality
Authentication
Traffic analysis is an example of:
Active attack
Passive attack
Both
None
In passive attacks, the attacker:
Interferes with communication
Changes packet contents
Only listens without altering data
Breaks encryption
Active attacks aim to:
Monitor only
Encrypt data
Alter, modify, or inject data
Increase network speed
Which is an example of an active attack?
Traffic analysis
DoS attack
Sniffing
Eavesdropping
Active attacks can violate which of the following?
Confidentiality only
Integrity and availability
Availability only
None
Man-in-the-Middle (MITM) attack is:
Passive
Active
Neither
Legal
Modifying data packets during transmission is:
Passive
Active
Inactive
Secure
Injecting malware into a system is an example of:
Active attack
Passive attack
Legal attack
None
Active attacks are considered more dangerous because:
They are silent
They cause direct damage or disruption
They improve system speed
They cannot be detected
Software supply chain attack targets:
Only hardware
Vendors, developers, and software updates
Network cables
Database only
An attacker who modifies open-source code before distribution is performing:
Active network attack
Software supply chain attack
DoS attack
Legal penetration testing
Which method is commonly used in supply chain attacks?
Using counterfeit hardware
Injecting malicious code into updates
Supply chain attacks are dangerous because:
They do not affect updates
They attack trusted software channels
They can be detected easily
They are limited to hardware
A supply chain attack usually begins at:
End-user device
Software developer, vendor, or third-party provider
Network router
Firewall
Compromising a package manager dependency (e.g., npm, PyPI) is:
Passive attack
Active attack
Supply chain attack
DoS attack
Supply chain attacks mainly violate:
Accountability
Confidentiality, Integrity, and Availability
Availability only
Authentication only
Inserting backdoors in firmware during manufacturing is:
Software supply chain attack
Hardware malfunction
Legal auditing
Passive attack
Cryptography is defined as:
The study of computer hardware
The science of securing information through transformations
The process of deleting data
The study of database systems
The main purpose of cryptography is to ensure:
Data compression
Data backup
Secure communication
Faster transfer
The process of converting plaintext into unreadable ciphertext is:
Decryption
Encryption
Compilation
Hashing
Decryption refers to:
Converting ciphertext back to plaintext
Compressing data
Generating keys
Destroying data
A cryptographic key is used to:
Delete files
Change IP address
Encrypt and decrypt information
Format storage
Which security principle is strongly supported by cryptography?
Availability
Confidentiality
Scalability
Load balancing
Modern cryptography involves:
Only pen-and-paper methods
Mathematical algorithms and keys
Only network routing
Only compression
The output of an encryption algorithm is called:
Plaintext
Ciphertext
Hash value
Packet
Symmetric encryption uses:
One-key for encryption and decryption
Two different keys
No key
Only public key
Symmetric encryption is also known as:
Public key cryptography
Secret key cryptography
No-key cryptography
Cloud encryption
Which of the following is a symmetric algorithm?
RSA
ECC
AES
Diffie-Hellman
Major advantage of symmetric encryption:
High speed and efficiency
No need for keys
Public validation
Easy to break
Major disadvantage of symmetric encryption:
Very slow
Key distribution problem
Needs large bandwidth
Works only on text
Symmetric block ciphers process data in:
Continuous streams
Fixed-size blocks
Random sizes
Only 1-bit at a time
Which of the following is a block cipher?
RC4
AES
ChaCha20
OTP
AES block size is:
64 bits
128 bits
256 bits
32 bits
DES uses a key size of:
32 bits
56 bits
128 bits
256 bits
DES belongs to which type of encryption?
Asymmetric key encryption
Symmetric block cipher
Stream cipher
Hash algorithm
A digest function converts arbitrary input into:
Plaintext
Fixed-size output
Variable-size output
Encrypted text only
Message digests provide:
Confidentiality
Integrity
Confidentiality + Availability
Authentication only
A good hash function must be:
Reversible
One-way
Two-way
Interactive
Digest functions are used mainly in:
Data confidentiality
Password storage and integrity verification
Data compression
Firewall routing
A good digest function must avoid:
Collisions
Fixed length output
Digest functions are:
Encryption algorithms
Non-reversible hash functions
Two-way conversion functions
Used to decrypt messages
Which attack tries to find two different messages with the same hash?
Replay attack
Collision attack
Trojan attack
Brute force
Public key cryptography uses:
One key
Two keys (public + private)
No keys
Same key for both sides
Public key cryptography is also known as:
Symmetric cryptography
Secret-key cryptography
Asymmetric cryptography
Digest cryptography
In public key encryption, the public key is used for:
Decryption
Encryption
Hashing
Signing
The private key must always be:
Publicly available
Stored in the cloud
Kept secret
Shared with everyone
Public key cryptography mainly supports:
Confidentiality
Authentication
Non-repudiation
All of the above
The main mathematical concept behind public key cryptography is:
Easy arithmetic
One-way functions
File compression
Bit flipping
Public key cryptography is slower than symmetric cryptography because:
It uses small keys
It uses complex mathematical operations
It does not use keys
It requires compression
RSA is a(n) _____ encryption algorithm.
Symmetric
Asymmetric
Hashing
Block cipher
RSA security is based on:
Matrix multiplication
Prime factorization problem
Linear algebra
Graph theory
RSA uses two keys known as:
Encryption key and checksum
Public key and private key
Hash key and digest key
Session key and MAC key
In RSA, plaintext is raised to power e and mod n to perform:
Decryption
Encryption
Compression
Hashing
In RSA, decryption is performed using:
Public key
Private key
Hash key
Session key
In RSA, n (the modulus) is generated by:
Adding two primes
XOR of primes
Multiplying two large primes
Dividing two primes
The RSA key pair is generated using:
Two random numbers
Two large prime numbers
One prime and one composite number
Only one prime
Typical RSA key length considered secure today is:
64 bits
128 bits
1024 bits
2048 bits or higher
RSA is preferred for:
Bulk data encryption
Key exchange and digital signatures
Encrypting large files directly
Hashing data
A digital signature provides:
Confidentiality
Integrity
Digital signatures ensure that the message:
Cannot be decrypted
Has not been altered
Is compressed
Contains no malware
Digital signature is created using the sender’s:
Password
Private key
Public key
Hash key
Digital signature verification uses the sender’s:
Private key
Public key
AES key
Session key
A digital signature is basically:
Encrypted plaintext
Encrypted hash value
Encrypted ciphertext
A virus checker
Which algorithm is commonly used for digital signatures?
DES
AES
RSA
RC4
Which security principle is strongest in digital signatures?
Confidentiality
Non-repudiation
Availability
Compression
A digital signature proves:
Sender identity
Data integrity
Non-repudiation
All of the above
Digital signatures require:
Hashing + public key cryptography
Only AES
Only hashing
Only symmetric keys
