HomeSubjectsUniversityBlogAbout

Introduction to Cyber Security

Topic in Cyber Security

210 total MCQsShowing 30 with explanations10 Easy10 Medium10 Hard

About This Topic

Cyber security is the practice of protecting computer systems, networks and data from attacks, damage and unauthorized access. Opening questions build the core vocabulary of asset, threat, vulnerability, exploit and risk, and how risk combines likelihood with impact. You will also classify threat actors, from script kiddies and hacktivists to malicious insiders and nation-state groups, and recognize preventive, detective and corrective controls. Risk treatment choices (accept, avoid, transfer, mitigate) and prioritizing vulnerabilities by severity and exposure appear in scenario form, alongside a first look at encryption and well-known regulations such as the GDPR.

Below are 30 practice questions from a pool of 210 Introduction to Cyber Security MCQs, one of 16 topics in Cyber Security. Each shows the correct answer with an explanation; when you are ready, take a timed quiz to test recall under exam conditions.

Practice Questions

Each question below shows the correct answer with a full explanation. Use these to build conceptual understanding before attempting a timed quiz.

Introduction to Cyber SecurityEasy

Q1. What is cyber security?

  1. A.Assembling and configuring enterprise hardware components
  2. B.Developing and deploying scalable application software
  3. C.Architecting and building responsive web applications
  4. D.Protecting computer systems, networks, and data from digital attacks✓ Correct

Explanation

Cyber security is the practice of protecting systems, networks, and programs from digital attacks.

Report an error in this question

Introduction to Cyber SecurityEasy

Q2. Which of the following is a goal of cyber security?

  1. A.Improving user interface design
  2. B.Increasing internet speed
  3. C.Reducing hardware costs
  4. D.Protecting confidentiality of data✓ Correct

Explanation

One of the primary goals of cyber security is to protect the confidentiality of data from unauthorized access.

Report an error in this question

Introduction to Cyber SecurityEasy

Q3. What does the CIA triad stand for in cyber security?

  1. A.Computer, Internet, Application
  2. B.Confidentiality, Integrity, Availability✓ Correct
  3. C.Central Intelligence Agency
  4. D.Code, Integration, Authentication

Explanation

The CIA triad stands for Confidentiality, Integrity, and Availability, which are the three main objectives of information security.

Report an error in this question

Introduction to Cyber SecurityEasy

Q4. Which of the following is an example of a cyber threat?

  1. A.Phishing email✓ Correct
  2. B.Power outage
  3. C.Software update
  4. D.Hardware upgrade

Explanation

A phishing email is a social engineering cyber threat designed to trick users into revealing sensitive information.

Report an error in this question

Introduction to Cyber SecurityEasy

Q5. What is the primary purpose of a firewall?

  1. A.Reduce file sizes through compression algorithms
  2. B.Filter incoming and outgoing network traffic✓ Correct
  3. C.Maintain redundant copies of critical data
  4. D.Optimize internet speed and network throughput

Explanation

A firewall monitors and filters incoming and outgoing network traffic based on predetermined security rules.

Report an error in this question

Introduction to Cyber SecurityEasy

Q6. Which of the following is considered personal identifiable information (PII)?

  1. A.Public news article
  2. B.National ID card number✓ Correct
  3. C.Weather forecast
  4. D.Open-source code

Explanation

A National ID card number is PII as it can be used to identify a specific individual.

Report an error in this question

Introduction to Cyber SecurityEasy

Q7. What is a vulnerability in the context of cyber security?

  1. A.A security tool for scanning and detecting vulnerabilities
  2. B.A category of self-replicating malicious software
  3. C.A standard network communication protocol for data transfer
  4. D.A weakness in a system that can be exploited✓ Correct

Explanation

A vulnerability is a weakness or flaw in a system that could be exploited to compromise security.

Report an error in this question

Introduction to Cyber SecurityEasy

Q8. What is the role of antivirus software?

  1. A.Detect and remove malicious software✓ Correct
  2. B.Expand available system memory resources
  3. C.Organize and catalog system file structures
  4. D.Schedule and generate automated data backups

Explanation

Antivirus software is designed to detect, prevent, and remove malicious software from computer systems.

Report an error in this question

Introduction to Cyber SecurityEasy

Q9. Which organization is responsible for cyber security standards globally?

  1. A.ISO (International Organization for Standardization)✓ Correct
  2. B.UNICEF within enterprise security environments
  3. C.WHO within enterprise security environments
  4. D.FIFA within enterprise security environments

Explanation

ISO develops international standards including those for information security management like ISO 27001.

Report an error in this question

Introduction to Cyber SecurityEasy

Q10. What does the term 'threat' mean in cyber security?

  1. A.A potential cause of an unwanted incident that may harm a system✓ Correct
  2. B.A routine patch applied to update system software
  3. C.A high-level language used for development
  4. D.A hardware component inside wireless networking routers

Explanation

A threat is any potential danger that could exploit a vulnerability to breach security and cause harm.

Report an error in this question

Introduction to Cyber SecurityMedium

Q11. Which of the following best describes 'defense in depth'?

  1. A.Using only encryption as the single security method
  2. B.Layering multiple security controls throughout a system✓ Correct
  3. C.Depending solely on firewalls for perimeter protection
  4. D.Relying on only one strong security control measure

Explanation

Defense in depth employs multiple layers of security controls so that if one layer fails, others still provide protection.

Report an error in this question

Introduction to Cyber SecurityMedium

Q12. What is the difference between a threat and a risk in cyber security?

  1. A.A risk is a type of malware designed for compromising system integrity
  2. B.They are the same thing with no meaningful distinction between them
  3. C.A threat only applies to hardware targeting enterprise network infrastructure
  4. D.A threat is a potential danger while risk is the likelihood and impact of that threat✓ Correct

Explanation

A threat is a potential danger, while risk combines the probability of the threat occurring with the potential impact.

Report an error in this question

Introduction to Cyber SecurityMedium

Q13. Which of the following is an example of a physical security control?

  1. A.Intrusion detection system
  2. B.Data-at-rest symmetric encryption
  3. C.Biometric access to server room✓ Correct
  4. D.Network firewall rule configuration

Explanation

Biometric access control for a server room is a physical security measure that restricts unauthorized physical access.

Report an error in this question

Introduction to Cyber SecurityMedium

Q14. What is the purpose of a security policy in an organization?

  1. A.To define rules and guidelines for protecting information assets✓ Correct
  2. B.To minimize infrastructure and hardware expenditures
  3. C.To expand network bandwidth allocation and throughput
  4. D.To design and build user-facing application interfaces

Explanation

A security policy establishes the rules, guidelines, and procedures for protecting an organization's information assets.

Report an error in this question

Introduction to Cyber SecurityMedium

Q15. Which cyber security principle states that users should only have the minimum access necessary?

  1. A.Principle of least privilege✓ Correct
  2. B.Defense in depth
  3. C.Security by obscurity
  4. D.Separation of duties

Explanation

The principle of least privilege states that users should be given only the minimum levels of access needed to perform their job functions.

Report an error in this question

Introduction to Cyber SecurityMedium

Q16. What is social engineering in cyber security?

  1. A.Manipulating people into revealing confidential information✓ Correct
  2. B.Engineering software for social platforms
  3. C.Building social media applications
  4. D.Designing social networks within enterprise security environments

Explanation

Social engineering is the psychological manipulation of people into performing actions or divulging confidential information.

Report an error in this question

Introduction to Cyber SecurityMedium

Q17. Which of the following is a component of the NIST Cybersecurity Framework?

  1. A.Identify, Protect, Detect, Respond, Recover✓ Correct
  2. B.Design, Build, Test, Deploy lifecycle
  3. C.Input, Process, Output data flow model
  4. D.Plan, Do, Check, Act continuous cycle

Explanation

The NIST Cybersecurity Framework consists of five core functions: Identify, Protect, Detect, Respond, and Recover.

Report an error in this question

Introduction to Cyber SecurityMedium

Q18. What is the purpose of a risk assessment in cyber security?

  1. A.To design new websites for enterprise computing environments
  2. B.To identify, analyze, and evaluate security risks✓ Correct
  3. C.To install antivirus software and management
  4. D.To write application code and management

Explanation

A risk assessment identifies potential threats, evaluates vulnerabilities, and helps prioritize mitigation efforts.

Report an error in this question

Introduction to Cyber SecurityMedium

Q19. What does 'non-repudiation' mean in information security?

  1. A.Ensuring a party cannot deny having performed an action✓ Correct
  2. B.Denying access to all users regardless of the specific situation or context
  3. C.Blocking network traffic within enterprise security environments
  4. D.Encrypting all messages regardless of the specific situation or context

Explanation

Non-repudiation ensures that the sender cannot deny having sent a message, and the recipient cannot deny having received it.

Report an error in this question

Introduction to Cyber SecurityMedium

Q20. Which of the following best describes an 'attack surface'?

  1. A.The total sum of vulnerabilities accessible to an attacker✓ Correct
  2. B.A strain of self-replicating malicious software programs
  3. C.A security certification for mobile network professionals
  4. D.The physical area of a computer across computing environments

Explanation

An attack surface is the total number of all possible entry points for unauthorized access into any system.

Report an error in this question

Introduction to Cyber SecurityHard

Q21. In the STRIDE threat model, what does the 'E' stand for?

  1. A.Elevation of Privilege✓ Correct
  2. B.Exploitation in security contexts
  3. C.Enumeration in security contexts
  4. D.Data-at-rest symmetric encryption

Explanation

STRIDE stands for Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege.

Report an error in this question

Introduction to Cyber SecurityHard

Q22. Which is a key difference between ISO 27001 and ISO 27002?

  1. A.ISO 27001 specifies requirements for an ISMS, ISO 27002 provides implementation guidelines✓ Correct
  2. B.ISO 27001 is for networks, ISO 27002 is for applications
  3. C.ISO 27001 is outdated within enterprise security environments
  4. D.They are identical standards with no meaningful distinction between them

Explanation

ISO 27001 specifies requirements for establishing an ISMS, while ISO 27002 provides best practice guidelines for implementing security controls.

Report an error in this question

Introduction to Cyber SecurityHard

Q23. What is the primary purpose of the MITRE ATT&CK framework?

  1. A.To design websites for enterprise computing environments
  2. B.To develop antivirus software across enterprise computing systems
  3. C.To provide a knowledge base of adversary tactics, techniques, and procedures✓ Correct
  4. D.To generate comprehensive network topology diagrams

Explanation

MITRE ATT&CK is a globally accessible knowledge base of adversary tactics and techniques based on real-world observations.

Report an error in this question

Introduction to Cyber SecurityHard

Q24. In cyber security, what does APT stand for?

  1. A.Active Port Tunneling
  2. B.Application Protocol Transfer
  3. C.Advanced Persistent Threat✓ Correct
  4. D.Automated Penetration Testing

Explanation

An Advanced Persistent Threat is a prolonged and targeted cyberattack in which an intruder gains access and remains undetected for an extended period.

Report an error in this question

Introduction to Cyber SecurityHard

Q25. Which best describes the concept of 'zero trust' architecture?

  1. A.Using zero encryption within enterprise security environments
  2. B.Trusting all internal network traffic regardless of the specific situation or context
  3. C.Never trusting any entity by default and always verifying regardless of location✓ Correct
  4. D.Blocking all external connections regardless of the specific situation or context

Explanation

Zero trust architecture follows the principle of never trust, always verify, requiring authentication and authorization for every access request.

Report an error in this question

Introduction to Cyber SecurityHard

Q26. What is the purpose of a threat intelligence platform (TIP)?

  1. A.To manage employee records within enterprise computing infrastructure
  2. B.To create backup systems for enterprise computing environments
  3. C.To collect, aggregate, and analyze threat data from multiple sources✓ Correct
  4. D.To design and build user-facing application interfaces

Explanation

A TIP aggregates threat intelligence data from multiple sources to provide actionable information about existing and emerging threats.

Report an error in this question

Introduction to Cyber SecurityHard

Q27. Which regulation specifically addresses data protection for EU citizens?

  1. A.PCI DSS
  2. B.SOX
  3. C.HIPAA
  4. D.GDPR✓ Correct

Explanation

The General Data Protection Regulation (GDPR) is a comprehensive data protection law for EU citizens.

Report an error in this question

Introduction to Cyber SecurityHard

Q28. What is the 'kill chain' model in cyber security?

  1. A.A network topology used in enterprise network infrastructure
  2. B.A method to physically destroy hardware installed within computing infrastructure
  3. C.A type of encryption algorithm applied to data protection workflows
  4. D.A framework describing the stages of a cyber attack from reconnaissance to exfiltration✓ Correct

Explanation

The cyber kill chain describes the stages of a cyberattack: Reconnaissance, Weaponization, Delivery, Exploitation, Installation, Command and Control, and Actions on Objectives.

Report an error in this question

Introduction to Cyber SecurityHard

Q29. What is the role of a Security Operations Center (SOC)?

  1. A.To continuously monitor, detect, analyze, and respond to security incidents✓ Correct
  2. B.To design network hardware across the enterprise network infrastructure
  3. C.To develop new software products across enterprise computing systems
  4. D.To sell security products within enterprise computing infrastructure

Explanation

A SOC is a centralized unit that continuously monitors and improves an organization's security posture while detecting and responding to cybersecurity incidents.

Report an error in this question

Introduction to Cyber SecurityHard

Q30. In Pakistan, which law primarily addresses cybercrime?

  1. A.Industrial Relations Act in security contexts
  2. B.Prevention of Electronic Crimes Act (PECA) 2016✓ Correct
  3. C.Foreign Exchange Act within enterprise security environments
  4. D.Pakistan Penal Code only in security contexts

Explanation

The Prevention of Electronic Crimes Act (PECA) 2016 is Pakistan's primary legislation dealing with cybercrimes and electronic transactions.

Report an error in this question

Ready to test yourself on Introduction to Cyber Security?

Take a timed quiz drawn from 210+ questions on this topic. No signup required — your progress saves in your browser.

Start Introduction to Cyber Security Quiz