Each question below shows the correct answer with a full explanation. Use these to build conceptual understanding before attempting a timed quiz.
Introduction to Cyber SecurityEasy
Q1. What is cyber security?
- A.Assembling and configuring enterprise hardware components
- B.Developing and deploying scalable application software
- C.Architecting and building responsive web applications
- D.Protecting computer systems, networks, and data from digital attacks✓ Correct
Explanation
Cyber security is the practice of protecting systems, networks, and programs from digital attacks.
Report an error in this question
Introduction to Cyber SecurityEasy
Q2. Which of the following is a goal of cyber security?
- A.Improving user interface design
- B.Increasing internet speed
- C.Reducing hardware costs
- D.Protecting confidentiality of data✓ Correct
Explanation
One of the primary goals of cyber security is to protect the confidentiality of data from unauthorized access.
Report an error in this question
Introduction to Cyber SecurityEasy
Q3. What does the CIA triad stand for in cyber security?
- A.Computer, Internet, Application
- B.Confidentiality, Integrity, Availability✓ Correct
- C.Central Intelligence Agency
- D.Code, Integration, Authentication
Explanation
The CIA triad stands for Confidentiality, Integrity, and Availability, which are the three main objectives of information security.
Report an error in this question
Introduction to Cyber SecurityEasy
Q4. Which of the following is an example of a cyber threat?
- A.Phishing email✓ Correct
- B.Power outage
- C.Software update
- D.Hardware upgrade
Explanation
A phishing email is a social engineering cyber threat designed to trick users into revealing sensitive information.
Report an error in this question
Introduction to Cyber SecurityEasy
Q5. What is the primary purpose of a firewall?
- A.Reduce file sizes through compression algorithms
- B.Filter incoming and outgoing network traffic✓ Correct
- C.Maintain redundant copies of critical data
- D.Optimize internet speed and network throughput
Explanation
A firewall monitors and filters incoming and outgoing network traffic based on predetermined security rules.
Report an error in this question
Introduction to Cyber SecurityEasy
Q6. Which of the following is considered personal identifiable information (PII)?
- A.Public news article
- B.National ID card number✓ Correct
- C.Weather forecast
- D.Open-source code
Explanation
A National ID card number is PII as it can be used to identify a specific individual.
Report an error in this question
Introduction to Cyber SecurityEasy
Q7. What is a vulnerability in the context of cyber security?
- A.A security tool for scanning and detecting vulnerabilities
- B.A category of self-replicating malicious software
- C.A standard network communication protocol for data transfer
- D.A weakness in a system that can be exploited✓ Correct
Explanation
A vulnerability is a weakness or flaw in a system that could be exploited to compromise security.
Report an error in this question
Introduction to Cyber SecurityEasy
Q8. What is the role of antivirus software?
- A.Detect and remove malicious software✓ Correct
- B.Expand available system memory resources
- C.Organize and catalog system file structures
- D.Schedule and generate automated data backups
Explanation
Antivirus software is designed to detect, prevent, and remove malicious software from computer systems.
Report an error in this question
Introduction to Cyber SecurityEasy
Q9. Which organization is responsible for cyber security standards globally?
- A.ISO (International Organization for Standardization)✓ Correct
- B.UNICEF within enterprise security environments
- C.WHO within enterprise security environments
- D.FIFA within enterprise security environments
Explanation
ISO develops international standards including those for information security management like ISO 27001.
Report an error in this question
Introduction to Cyber SecurityEasy
Q10. What does the term 'threat' mean in cyber security?
- A.A potential cause of an unwanted incident that may harm a system✓ Correct
- B.A routine patch applied to update system software
- C.A high-level language used for development
- D.A hardware component inside wireless networking routers
Explanation
A threat is any potential danger that could exploit a vulnerability to breach security and cause harm.
Report an error in this question
Introduction to Cyber SecurityMedium
Q11. Which of the following best describes 'defense in depth'?
- A.Using only encryption as the single security method
- B.Layering multiple security controls throughout a system✓ Correct
- C.Depending solely on firewalls for perimeter protection
- D.Relying on only one strong security control measure
Explanation
Defense in depth employs multiple layers of security controls so that if one layer fails, others still provide protection.
Report an error in this question
Introduction to Cyber SecurityMedium
Q12. What is the difference between a threat and a risk in cyber security?
- A.A risk is a type of malware designed for compromising system integrity
- B.They are the same thing with no meaningful distinction between them
- C.A threat only applies to hardware targeting enterprise network infrastructure
- D.A threat is a potential danger while risk is the likelihood and impact of that threat✓ Correct
Explanation
A threat is a potential danger, while risk combines the probability of the threat occurring with the potential impact.
Report an error in this question
Introduction to Cyber SecurityMedium
Q13. Which of the following is an example of a physical security control?
- A.Intrusion detection system
- B.Data-at-rest symmetric encryption
- C.Biometric access to server room✓ Correct
- D.Network firewall rule configuration
Explanation
Biometric access control for a server room is a physical security measure that restricts unauthorized physical access.
Report an error in this question
Introduction to Cyber SecurityMedium
Q14. What is the purpose of a security policy in an organization?
- A.To define rules and guidelines for protecting information assets✓ Correct
- B.To minimize infrastructure and hardware expenditures
- C.To expand network bandwidth allocation and throughput
- D.To design and build user-facing application interfaces
Explanation
A security policy establishes the rules, guidelines, and procedures for protecting an organization's information assets.
Report an error in this question
Introduction to Cyber SecurityMedium
Q15. Which cyber security principle states that users should only have the minimum access necessary?
- A.Principle of least privilege✓ Correct
- B.Defense in depth
- C.Security by obscurity
- D.Separation of duties
Explanation
The principle of least privilege states that users should be given only the minimum levels of access needed to perform their job functions.
Report an error in this question
Introduction to Cyber SecurityMedium
Q16. What is social engineering in cyber security?
- A.Manipulating people into revealing confidential information✓ Correct
- B.Engineering software for social platforms
- C.Building social media applications
- D.Designing social networks within enterprise security environments
Explanation
Social engineering is the psychological manipulation of people into performing actions or divulging confidential information.
Report an error in this question
Introduction to Cyber SecurityMedium
Q17. Which of the following is a component of the NIST Cybersecurity Framework?
- A.Identify, Protect, Detect, Respond, Recover✓ Correct
- B.Design, Build, Test, Deploy lifecycle
- C.Input, Process, Output data flow model
- D.Plan, Do, Check, Act continuous cycle
Explanation
The NIST Cybersecurity Framework consists of five core functions: Identify, Protect, Detect, Respond, and Recover.
Report an error in this question
Introduction to Cyber SecurityMedium
Q18. What is the purpose of a risk assessment in cyber security?
- A.To design new websites for enterprise computing environments
- B.To identify, analyze, and evaluate security risks✓ Correct
- C.To install antivirus software and management
- D.To write application code and management
Explanation
A risk assessment identifies potential threats, evaluates vulnerabilities, and helps prioritize mitigation efforts.
Report an error in this question
Introduction to Cyber SecurityMedium
Q19. What does 'non-repudiation' mean in information security?
- A.Ensuring a party cannot deny having performed an action✓ Correct
- B.Denying access to all users regardless of the specific situation or context
- C.Blocking network traffic within enterprise security environments
- D.Encrypting all messages regardless of the specific situation or context
Explanation
Non-repudiation ensures that the sender cannot deny having sent a message, and the recipient cannot deny having received it.
Report an error in this question
Introduction to Cyber SecurityMedium
Q20. Which of the following best describes an 'attack surface'?
- A.The total sum of vulnerabilities accessible to an attacker✓ Correct
- B.A strain of self-replicating malicious software programs
- C.A security certification for mobile network professionals
- D.The physical area of a computer across computing environments
Explanation
An attack surface is the total number of all possible entry points for unauthorized access into any system.
Report an error in this question
Introduction to Cyber SecurityHard
Q21. In the STRIDE threat model, what does the 'E' stand for?
- A.Elevation of Privilege✓ Correct
- B.Exploitation in security contexts
- C.Enumeration in security contexts
- D.Data-at-rest symmetric encryption
Explanation
STRIDE stands for Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege.
Report an error in this question
Introduction to Cyber SecurityHard
Q22. Which is a key difference between ISO 27001 and ISO 27002?
- A.ISO 27001 specifies requirements for an ISMS, ISO 27002 provides implementation guidelines✓ Correct
- B.ISO 27001 is for networks, ISO 27002 is for applications
- C.ISO 27001 is outdated within enterprise security environments
- D.They are identical standards with no meaningful distinction between them
Explanation
ISO 27001 specifies requirements for establishing an ISMS, while ISO 27002 provides best practice guidelines for implementing security controls.
Report an error in this question
Introduction to Cyber SecurityHard
Q23. What is the primary purpose of the MITRE ATT&CK framework?
- A.To design websites for enterprise computing environments
- B.To develop antivirus software across enterprise computing systems
- C.To provide a knowledge base of adversary tactics, techniques, and procedures✓ Correct
- D.To generate comprehensive network topology diagrams
Explanation
MITRE ATT&CK is a globally accessible knowledge base of adversary tactics and techniques based on real-world observations.
Report an error in this question
Introduction to Cyber SecurityHard
Q24. In cyber security, what does APT stand for?
- A.Active Port Tunneling
- B.Application Protocol Transfer
- C.Advanced Persistent Threat✓ Correct
- D.Automated Penetration Testing
Explanation
An Advanced Persistent Threat is a prolonged and targeted cyberattack in which an intruder gains access and remains undetected for an extended period.
Report an error in this question
Introduction to Cyber SecurityHard
Q25. Which best describes the concept of 'zero trust' architecture?
- A.Using zero encryption within enterprise security environments
- B.Trusting all internal network traffic regardless of the specific situation or context
- C.Never trusting any entity by default and always verifying regardless of location✓ Correct
- D.Blocking all external connections regardless of the specific situation or context
Explanation
Zero trust architecture follows the principle of never trust, always verify, requiring authentication and authorization for every access request.
Report an error in this question
Introduction to Cyber SecurityHard
Q26. What is the purpose of a threat intelligence platform (TIP)?
- A.To manage employee records within enterprise computing infrastructure
- B.To create backup systems for enterprise computing environments
- C.To collect, aggregate, and analyze threat data from multiple sources✓ Correct
- D.To design and build user-facing application interfaces
Explanation
A TIP aggregates threat intelligence data from multiple sources to provide actionable information about existing and emerging threats.
Report an error in this question
Introduction to Cyber SecurityHard
Q27. Which regulation specifically addresses data protection for EU citizens?
- A.PCI DSS
- B.SOX
- C.HIPAA
- D.GDPR✓ Correct
Explanation
The General Data Protection Regulation (GDPR) is a comprehensive data protection law for EU citizens.
Report an error in this question
Introduction to Cyber SecurityHard
Q28. What is the 'kill chain' model in cyber security?
- A.A network topology used in enterprise network infrastructure
- B.A method to physically destroy hardware installed within computing infrastructure
- C.A type of encryption algorithm applied to data protection workflows
- D.A framework describing the stages of a cyber attack from reconnaissance to exfiltration✓ Correct
Explanation
The cyber kill chain describes the stages of a cyberattack: Reconnaissance, Weaponization, Delivery, Exploitation, Installation, Command and Control, and Actions on Objectives.
Report an error in this question
Introduction to Cyber SecurityHard
Q29. What is the role of a Security Operations Center (SOC)?
- A.To continuously monitor, detect, analyze, and respond to security incidents✓ Correct
- B.To design network hardware across the enterprise network infrastructure
- C.To develop new software products across enterprise computing systems
- D.To sell security products within enterprise computing infrastructure
Explanation
A SOC is a centralized unit that continuously monitors and improves an organization's security posture while detecting and responding to cybersecurity incidents.
Report an error in this question
Introduction to Cyber SecurityHard
Q30. In Pakistan, which law primarily addresses cybercrime?
- A.Industrial Relations Act in security contexts
- B.Prevention of Electronic Crimes Act (PECA) 2016✓ Correct
- C.Foreign Exchange Act within enterprise security environments
- D.Pakistan Penal Code only in security contexts
Explanation
The Prevention of Electronic Crimes Act (PECA) 2016 is Pakistan's primary legislation dealing with cybercrimes and electronic transactions.
Report an error in this question