ThatQuiz Test Library Take this test now
Cybersecurity - Exam
Contributed by: Porter
  • 1. What does a firewall do in cybersecurity?
A) Takes photographs
B) Records music
C) Monitors and controls incoming and outgoing network traffic
D) Measures temperature
  • 2. What is two-factor authentication in cybersecurity?
A) Writing two passwords
B) Using two different keyboards
C) Typing really fast
D) Verification method using two factors: something you know and something you have
  • 3. What is ransomware in cybersecurity?
A) Software for photo editing
B) Software for word processing
C) Malware that encrypts files and demands payment for decryption
D) Software for data backup
  • 4. What is a good password practice for cybersecurity?
A) Using strong, unique passwords for each account
B) Writing passwords on sticky notes
C) Sharing passwords with friends
D) Reusing the same password
  • 5. Why is regular software patching important for cybersecurity?
A) To organize files
B) To fix security vulnerabilities and bugs
C) To enhance video streaming quality
D) To change desktop backgrounds
  • 6. What is the purpose of SSL certificates in cybersecurity?
A) Secure online communication by encrypting data transmitted between a website and a user
B) Creating music playlists
C) Sorting documents alphabetically
D) Repairing electronic devices
  • 7. What is a vulnerability assessment in cybersecurity?
A) Process of identifying security weaknesses in a system
B) Planning vacations
C) Analyzing weather patterns
D) Finding job opportunities
  • 8. What is a zero-day vulnerability?
A) Software that has zero bugs
B) Countdown to launch new products
C) Security flaw that is unknown to the software vendor
D) Technical support available 24/7
  • 9. Which term is synonymous with computer security?
A) Biometric security
B) Physical security
C) Cybersecurity
D) Network security
  • 10. What does computer security primarily aim to protect against?
A) Network speed optimization
B) Hardware upgrades and software updates
C) User interface design flaws
D) Unauthorized information disclosure, theft, or damage
  • 11. What is an exploitable vulnerability?
A) A vulnerability that enhances security
B) A vulnerability that cannot be discovered
C) A vulnerability without any known exploits
D) A vulnerability with at least one working attack or exploit
  • 12. Who is most likely to be affected by untargeted cyberattacks?
A) Normal internet users
B) Cybersecurity experts exclusively
C) Government agencies only
D) Only large corporations
  • 13. Which type of MITM attack involves hijacking routing protocols?
A) DNS spoofing
B) IP address spoofing
C) WiFi SSID spoofing
D) Message spoofing
  • 14. When did multi-vector polymorphic attacks first surface?
A) 2005
B) 1999
C) 2020
D) 2017
  • 15. Which of the following is NOT a common method used in phishing attacks?
A) Instant messaging
B) Phone call
C) Text message
D) Email spoofing
  • 16. What type of phishing attack uses personal or organization-specific details to appear trustworthy?
A) Vertical escalation
B) Horizontal escalation
C) Spear-phishing
D) Generic phishing
  • 17. What is often used as a starting point in privilege escalation attacks?
A) Social engineering techniques, often phishing
B) Direct hacking of system hardware
C) Exploiting side-channel vulnerabilities
D) Sending ransomware to large networks
  • 18. Which of the following is NOT a form of side-channel attack?
A) Phishing via text message
B) Exploiting electromagnetic radiation from devices
C) Leveraging hardware implementation faults
D) Analyzing residual effects on RAM cells
  • 19. Which type of privilege escalation involves gaining access to higher-level accounts?
A) Phishing
B) Spear-phishing
C) Vertical escalation
D) Horizontal escalation
  • 20. What is an example of tampering involving a physical attack?
A) Cross-site scripting attacks.
B) Evil Maid attacks.
C) SQL injection attacks.
D) Distributed denial-of-service attacks.
  • 21. What percentage of cyber security incidents involved internal actors according to the Verizon Data Breach Investigations Report 2020?
A) 70%
B) 10%
C) 50%
D) 30%
  • 22. Which step in managing information security culture involves setting clear targets and assembling a skilled team?
A) Operative planning
B) Strategic planning
C) Post-evaluation
D) Pre-evaluation
  • 23. How many sections does the UK government's National Cyber Security Centre divide secure cyber design principles into?
A) Five sections.
B) Seven sections.
C) Three sections.
D) Ten sections.
  • 24. What should be the severity of any successful attack on a secure system?
A) Minimal severity.
B) Maximum impact to test defenses.
C) Unlimited access for attackers.
D) Severe enough to cause major disruptions.
  • 25. Which of the following is a preventive measure in computer security?
A) Firewalls.
B) Graphic design software.
C) Data analysis tools.
D) Word processing applications.
  • 26. Which encryption standard is commonly used on USB dongles to enhance security?
A) Data Encryption Standard (DES)
B) Advanced Encryption Standard (AES)
C) RSA
D) Triple DES
  • 27. What do Trusted Platform Modules (TPMs) integrate into devices to enhance security?
A) Drive locks
B) Intrusion detection systems
C) Mobile-enabled access
D) Cryptographic capabilities
  • 28. What is considered the most common hardware threat facing computer networks according to Network World?
A) Trusted Platform Modules
B) Infected USB dongles connected inside a firewall
C) Drive locks
D) Mobile-enabled access devices
  • 29. Which technology allows for hardware-based sandboxing of components in computers?
A) IOMMUs
B) Drive locks
C) TPMs
D) USB dongles
  • 30. Which feature of mobile phones enhances security by providing biometric validation?
A) IOMMUs
B) Drive locks
C) Thumbprint readers
D) TPMs
  • 31. Which certification is popular for secure operating systems?
A) Common Criteria (CC)
B) Lean Manufacturing
C) ISO 9001
D) Six Sigma
  • 32. Which security model uses a list of permissions associated with an object?
A) Role-based access control (RBAC)
B) Mandatory access control (MAC)
C) Capability-based security
D) Access control lists (ACLs)
  • 33. What can capability-based security be implemented at?
A) The hardware level
B) The user interface level
C) The network level
D) The language level
  • 34. Which open-source project is associated with capability-based security?
A) Python
B) C++
C) Java
D) The E language
  • 35. Who coined the term 'cyber hygiene'?
A) Steve Jobs
B) Bill Gates
C) Vint Cerf
D) Tim Berners-Lee
  • 36. Which company pushed out security fixes over the air in 2016?
A) ICV
B) UPS
C) FedEx
D) Tesla
  • 37. In the 2015 test, how far away were hackers able to remotely carjack a vehicle?
A) 15 miles away
B) 10 miles away
C) 20 miles away
D) 5 miles away
  • 38. What is a widely known digitally secure telecommunication device?
A) The SIM (Subscriber Identity Module) card.
B) A smartwatch.
C) A landline telephone.
D) An analog radio.
  • 39. Which organization does the FBI work with to form a multi-agency task force?
A) National White Collar Crime Center (NW3C)
B) Federal Communications Commission
C) Cybersecurity and Infrastructure Security Agency
D) Department of Homeland Security
  • 40. What percentage of security incidents is estimated to involve human error?
A) About 70%
B) Less than 50%
C) Exactly 100%
D) More than 90%
  • 41. What technology allows customers to perform online secure transactions using hand-held card readers?
A) Two-factor authentication via SMS
B) Chip Authentication Program
C) Virtual private networks (VPNs)
D) Biometric authentication systems
  • 42. Who created the first internet computer worm in 1988?
A) Robert Tappan Morris
B) John McAfee
C) Kevin Mitnick
D) Adrian Lamo
  • 43. Who organized the foundational session in computer security at the Spring Joint Computer Conference in April 1967?
A) Markus Hess
B) Bob Thomas
C) Ray Tomlinson
D) Willis Ware
  • 44. What percentage of organizations did not increase security training in 2015?
A) 62%
B) 75%
C) 80%
D) 50%
  • 45. Which website was breached by The Impact Team in July 2015?
A) LinkedIn
B) Ashley Madison
C) Facebook
D) Twitter
  • 46. Which vehicle system was used as an attack vector in simple security risks?
A) A malicious compact disc
B) Cruise control system
C) Bluetooth communication
D) Airbag deployment
  • 47. Which Ukrainian hacker was involved in the Target Corporation breach?
A) Lazarus Group
B) Rescator
C) NotPetya
D) Guccifer
  • 48. Which city in Mexico received the first e-Drivers' licenses using a smart card platform?
A) Puebla
B) Mexico City
C) Monterrey
D) Guadalajara
  • 49. Which agency monitors cyber threats in India?
A) CERT-In
B) Ministry of Electronics and Information Technology
C) Indian Computer Emergency Response Team
D) National Cyber Security Agency
  • 50. What was the name of one of the earliest computer worms created by Bob Thomas?
A) Morris worm
B) Blaster
C) Reaper
D) Creeper
  • 51. Which organization investigated 79 hacking incidents at energy companies in 2014?
A) The Central Intelligence Agency (CIA)
B) The Federal Bureau of Investigation (FBI)
C) The National Security Agency (NSA)
D) The Computer Emergency Readiness Team
  • 52. On what date did the US FDA release its recommendations for maintaining security in Internet-connected medical devices?
A) 15 November 2015
B) 28 December 2016
C) 1 January 2017
D) 30 June 2018
  • 53. When was the National Cyber Security Policy 2013 introduced in India?
A) 1999
B) 2013
C) 2020
D) 2008
  • 54. What was the response of Target and Home Depot to warnings about breaches?
A) They immediately fixed all vulnerabilities
B) They shut down their systems temporarily
C) They upgraded their security software
D) Warnings were ignored
  • 55. Who was an early example of a state-sponsored hacker?
A) A Ukrainian power grid operator
B) An internet activist
C) Clifford Stoll
D) Markus Hess
  • 56. Who is believed to have perpetrated the Office of Personnel Management hack?
A) Chinese hackers
B) Russian hackers
C) Iranian hackers
D) North Korean hackers
  • 57. What method did hackers use to gain access to Rome Laboratory's systems?
A) Trojan horses
B) Phishing emails
C) SQL injection
D) Brute force attacks
  • 58. What book recounts Markus Hess's hacking activities for the KGB?
A) Data and Goliath
B) The Cuckoo's Egg
C) Ghost in the Wires
D) Cybersecurity and Cyberwar: What Everyone Needs to Know
  • 59. Which attack involved spear-phising, destruction of files, and denial-of-service?
A) A ransomware attack on healthcare facilities
B) The 2015 Ukraine power grid hack
C) An attack on a social media platform
D) A bank data breach in 2021
  • 60. What technology is used by FedEx and UPS for tracking shipments?
A) Bluetooth
B) RFID (Radio Frequency Identification)
C) Barcodes
D) GPS
  • 61. Which type of equipment has been successfully attacked in hospitals?
A) Patient transport vehicles
B) Medical training simulators
C) In-hospital diagnostic equipment
D) Hospital cafeteria systems
  • 62. Which company started offering commercial access control systems and computer security software products in the late 1970s?
A) Microsoft
B) IBM
C) Netscape
D) Apple
  • 63. When was the United States Cyber Command created?
A) 2015
B) 2009
C) 2008
D) 2010
  • 64. What is cyber attribution?
A) Finding who perpetrated a cyberattack.
B) Encrypting data for secure transmission.
C) Detecting and eliminating malware.
D) Logging user activity on a network.
  • 65. What is the first key component of a computer security incident response plan?
A) Post incident activity
B) Containment, eradication and recovery
C) Preparation
D) Detection and analysis
  • 66. Who provided documents exposing NSA global surveillance in 2013?
A) Edward Snowden
B) Chelsea Manning
C) Julian Assange
D) Mark Zuckerberg
  • 67. Which Canadian organization is responsible for mitigating threats to Canada's critical infrastructure?
A) European Network and Information Security Agency (ENISA)
B) Forum of Incident Response and Security Teams (FIRST)
C) Council of Europe
D) Canadian Cyber Incident Response Centre (CCIRC)
  • 68. What is digital hygiene analogous to?
A) Personal hygiene
B) Dietary habits
C) Sleep patterns
D) Physical fitness
  • 69. What is one of the main pillars of Canada's cyber security strategy?
A) Coordinating global CSIRTs.
B) Regulating international data protection laws.
C) Securing government systems.
D) Managing European network security.
  • 70. Which type of devices are becoming more common targets for cyberattacks due to their increasing number?
A) Desktop computers
B) Healthcare providers' networks
C) Smartphones and tablets
D) Home automation devices like the Nest thermostat
  • 71. Who wrote the Reaper program to destroy the Creeper worm?
A) Markus Hess
B) Willis Ware
C) Bob Thomas
D) Ray Tomlinson
  • 72. In what year did over a hundred intrusions occur at the Rome Laboratory?
A) 2010
B) 1988
C) 1994
D) 2000
  • 73. In what decade did computer security begin to expand beyond academia due to increased connectivity?
A) 1970s
B) 1990s
C) 2000s
D) 1980s
  • 74. What percentage of organizations reported a 'problematic shortage' of cybersecurity skills in 2016?
A) 35%
B) 46%
C) 50%
D) 28%
  • 75. What is one example of a large corporation that experienced a data breach involving clients' credit card details?
A) Home Depot
B) Sony Pictures
C) Nest
D) HBGary Federal
  • 76. What action did Avid Life Media CEO Noel Biderman take after the Ashley Madison breach?
A) He increased security measures
B) He resigned
C) He took legal action against The Impact Team
D) He denied any wrongdoing
  • 77. Which organization is part of the National Cyber Security Division of the United States Department of Homeland Security?
A) US-CERT
B) CERT/CC
C) NEI
D) NRC
  • 78. How many credit cards were stolen from Target Corporation in 2013?
A) 60 million
B) 25 million
C) 10 million
D) Roughly 40 million
  • 79. What technology are long-distance bus companies switching to?
A) Barter systems
B) E-ticketing transactions
C) Manual ticket sales
D) Paper tickets
  • 80. What was the primary target of the Stuxnet attack in 2010?
A) Israeli government networks
B) U.S. military systems
C) European power grids
D) Iran's nuclear centrifuges
  • 81. Which company was affected by a credit card details breach in early 2007?
A) TJX
B) Target Corporation
C) Home Depot
D) Office of Personnel Management
  • 82. Which technology enables shopping mall kiosks to issue on-the-spot credit cards?
A) Contactless payment systems
B) Blockchain-based transactions
C) QR code scanning
D) Instant Issuance technology
  • 83. Which coalition did Public Safety Canada partner with to launch the Cyber Security Cooperation Program?
A) European Network and Information Security Agency (ENISA)
B) Canadian Cyber Incident Response Centre (CCIRC)
C) STOP.THINK.CONNECT
D) Council of Europe
  • 84. Which of the following is NOT a method used in access authorization?
A) Port scanning.
B) Passwords.
C) Biometric systems.
D) Smart cards.
  • 85. What is a consequence of a simple power outage at an airport?
A) It can cause worldwide repercussions
B) It only affects the local area
C) It has no significant impact
D) It improves airport efficiency
Created with That Quiz — where a math practice test is always one click away.