WorksheetsOCC Cybersecurity Welcome Test
Total questions: 50
Worksheet time: 25mins
What is the primary purpose of cybersecurity?
Increase system performance
Protect systems, networks, and data
Monitor employees
Develop applications
. Which set represents the CIA Triad?
Control, Integrity, Access
Confidentiality, Integrity, Availability
Compliance, Inspection, Authentication
Confidentiality, Identification, Authorization
What is the main role of a Cybersecurity Analyst?
Writing code
Managing databases
Monitoring and protecting systems from threats
Designing websites
What best describes phishing?
Hardware malfunction
Social engineering attack using deception
Virus scanning technique
Network configuration error
Which control restricts unauthorised network access?
Backup
Firewall
Patch management
Encryption
What is the main purpose of MFA?
Replace passwords
Improve system speed
Add an extra authentication layer
Remove user accounts
Which malware encrypts data and demands payment?
Worm
Trojan
Ransomware
Spyware
Least privilege means:
Full access for all users
Access only required for job roles
No access reviews
Shared accounts
Identify, Protect, Detect, Respond, Recover belongs to:
COBIT
ITIL
ISO 9001
NIST CSF
What does encryption mainly protect?
Availability
Confidentiality
Performance
Storage space
What is a vulnerability?
A threat actor
A system weakness
A security policy
A firewall rule
What is malware?
Legitimate software
Hardware damage
Malicious software
System backup
Which attack floods a system with traffic?
Phishing
Brute force
DoS
SQL Injection
What is patch management?
User training
Updating systems to fix vulnerabilities
Backing up data
Encrypting files
Which device monitors network traffic?
Switch
Router
IDS
Printer
What is authentication?
Granting permissions
Verifying identity
Encrypting data
Backing up files
What is authorisation?
Verifying user identity
Assigning access rights
Monitoring logs
Installing patches
What is a brute-force attack?
Guessing passwords repeatedly
Sending phishing emails
Blocking traffic
Encrypting data
What is data at rest?
Data being transmitted
Stored data
Deleted data
Temporary data
Why are backups important?
Improve speed
Recover data after incidents
Detect threats
Block attacks
Which are cybersecurity threats?
Malware
Phishing
Strong passwords
DoS attacks
Which are examples of malware?
Virus
Worm
Firewall
Trojan
Incident response activities include:
Detection
Containment
Recovery
Software development
Which improve access security?
MFA
Strong passwords
Shared accounts
Least privilege
Which indicate a possible security incident?
Unusual network traffic
Multiple failed logins
Scheduled maintenance
Unexpected data transfers
Social engineering techniques include:
Phishing
Tailgating
Encryption
Pretexting
Which are preventive controls?
Firewalls
Antivirus
Incident reporting
Encryption
Which are detective controls?
IDS
Log monitoring
Firewalls
Security alerts
Which protect data confidentiality?
Encryption
Access control
Backups
Public sharing
Which actions reduce malware infections?
Regular updates
Antivirus software
Disabling security tools
User awareness
Which may indicate insider threats?
Access outside work hours
Unusual data downloads
Strong passwords
Policy violations
Which are examples of authentication factors?
Password
Smart card
Fingerprint
Username
Which activities fall under risk management?
Risk identification
Risk assessment
Risk mitigation
Software coding
Which are network security controls?
Firewalls
IDS/IPS
Password policies
Network segmentation
Which help ensure system availability?
Backups
Redundancy
DoS attacks
Patch management
A threat exploits a vulnerability.
True
False
Encryption protects data confidentiality.
True
False
MFA uses only one authentication factor.
True
False
Social engineering targets human behaviour.
True
False
Firewalls can prevent unauthorised access.
True
False
Antivirus software can detect known malware.
True
False
Log monitoring helps detect suspicious activities.
True
False
Least privilege increases security risks.
True
False
DoS attacks aim to make systems unavailable.
True
False
Patch management reduces vulnerabilities.
True
False
Authentication and authorisation mean the same thing.
True
False
Data in transit refers to stored data.
True
False
Strong passwords reduce the risk of brute-force attacks.
True
False
Insider threats only come from hackers outside the organisation.
True
False
Incident response plans should be tested regularly.
True
False
