1 / 316100%
Cybersecurity threats and mitigation strategies- Midterm Exam
Arizona state university
Subject: ACO 131 - Global Cybersecurity
Instructions:
Answer all questions.
Multiple-choice questions (mcqs) carry 1 mark each.
Short answer questions carry 5 marks each.
Long answer questions carry varying marks as indicated.
Write your answers in a clear and concise manner.
Support your answers with relevant examples where necessary.
Section a: multiple-choice questions (1 mark each)
1. What is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
2. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
3. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
4. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
5. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
6. Which cybersecurity protocol is used to establish a secure connection over the
internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
7. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
8. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
9. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
10. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
Section b: short answer questions (5 marks each)
41. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
42. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
43. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
44. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
45. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
71. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
72. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
73. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
oReputational damage: public trust could erode, leading to customer loss and a
decline in market value.
11. What is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
12. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
13. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
14. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
15. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
16. Which cybersecurity protocol is used to establish a secure connection over the
internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
17. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
18. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
19. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
20. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
42. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
43. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
44. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
45. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
46. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
72. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
73. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
74. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
21. Reputational damage: public trust could erode, leading to customer loss and a decline
in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
22. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
23. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
24. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
25. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
26. Which cybersecurity protocol is used to establish a secure connection over the
internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
27. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
28. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
29. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
30. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
43. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
44. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
45. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
46. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
47. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
73. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
74. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
75. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
31. Reputational damage: public trust could erode, leading to customer loss and a decline
in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
32. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
33. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
34. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
35. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
36. Which cybersecurity protocol is used to establish a secure connection over the
internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
37. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
38. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
39. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
40. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
44. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
45. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
46. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
47. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
48. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
74. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
75. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
76. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
41. Reputational damage: public trust could erode, leading to customer loss and a decline
in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
42. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
43. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
44. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
45. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
46. Which cybersecurity protocol is used to establish a secure connection over the
internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
47. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
48. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
49. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
50. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
45. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
46. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
47. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
48. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
49. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
75. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
76. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
77. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
51. Reputational damage: public trust could erode, leading to customer loss and a decline
in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
52. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
53. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
54. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
55. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
56. Which cybersecurity protocol is used to establish a secure connection over the
internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
57. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
58. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
59. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
60. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
46. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
47. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
48. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
49. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
50. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
76. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
77. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
78. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
61. Reputational damage: public trust could erode, leading to customer loss and a decline
in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
62. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
63. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
64. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
65. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
66. Which cybersecurity protocol is used to establish a secure connection over the
internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
67. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
68. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
69. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
70. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
47. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
48. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
49. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
50. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
51. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
77. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
78. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
79. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
71. Reputational damage: public trust could erode, leading to customer loss and a decline
in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
72. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
73. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
74. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
75. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
76. Which cybersecurity protocol is used to establish a secure connection over the
internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
77. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
78. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
79. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
80. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
48. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
49. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
50. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
51. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
52. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
78. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
79. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
80. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
81. Reputational damage: public trust could erode, leading to customer loss and a decline
in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
82. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
83. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
84. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
85. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
86. Which cybersecurity protocol is used to establish a secure connection over the
internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
87. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
88. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
89. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
90. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
49. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
50. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
51. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
52. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
53. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
79. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
80. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
81. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
91. Reputational damage: public trust could erode, leading to customer loss and a decline
in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
92. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
93. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
94. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
95. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
96. Which cybersecurity protocol is used to establish a secure connection over the
internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
97. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
98. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
99. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
100. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
50. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
51. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
52. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
53. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
54. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
80. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
81. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
82. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
101. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
102. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
103. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
104. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
105. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
106. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
107. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
108. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
109. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
110. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
51. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
52. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
53. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
54. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
55. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
81. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
82. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
83. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
111. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
112. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
113. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
114. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
115. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
116. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
117. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
118. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
119. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
120. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
52. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
53. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
54. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
55. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
56. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
82. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
83. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
84. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
121. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
122. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
123. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
124. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
125. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
126. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
127. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
128. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
129. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
130. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
53. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
54. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
55. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
56. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
57. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
83. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
84. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
85. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
131. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
132. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
133. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
134. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
135. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
136. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
137. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
138. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
139. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
140. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
54. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
55. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
56. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
57. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
58. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
84. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
85. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
86. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
141. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
142. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
143. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
144. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
145. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
146. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
147. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
148. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
149. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
150. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
55. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
56. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
57. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
58. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
59. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
85. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
86. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
87. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
151. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
152. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
153. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
154. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
155. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
156. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
157. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
158. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
159. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
160. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
56. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
57. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
58. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
59. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
60. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
86. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
87. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
88. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
161. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
162. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
163. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
164. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
165. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
166. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
167. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
168. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
169. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
170. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
57. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
58. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
59. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
60. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
61. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
87. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
88. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
89. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
171. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
172. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
173. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
174. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
175. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
176. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
177. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
178. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
179. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
180. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
58. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
59. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
60. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
61. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
62. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
88. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
89. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
90. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
181. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
182. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
183. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
184. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
185. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
186. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
187. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
188. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
189. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
190. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
59. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
60. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
61. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
62. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
63. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
89. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
90. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
91. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
191. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
192. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
193. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
194. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
195. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
196. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
197. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
198. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
199. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
200. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
60. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
61. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
62. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
63. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
64. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
90. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
91. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
92. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
201. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
202. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
203. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
204. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
205. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
206. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
207. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
208. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
209. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
210. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
61. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
62. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
63. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
64. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
65. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
91. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
92. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
93. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
211. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
212. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
213. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
214. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
215. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
216. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
217. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
218. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
219. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
220. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
62. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
63. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
64. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
65. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
66. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
92. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
93. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
94. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
221. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
222. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
223. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
224. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
225. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
226. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
227. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
228. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
229. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
230. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
63. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
64. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
65. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
66. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
67. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
93. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
94. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
95. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
231. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
232. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
233. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
234. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
235. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
236. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
237. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
238. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
239. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
240. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
64. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
65. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
66. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
67. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
68. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
94. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
95. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
96. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
241. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
242. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
243. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
244. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
245. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
246. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
247. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
248. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
249. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
250. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
65. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
66. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
67. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
68. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
69. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
95. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
96. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
97. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
251. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
252. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
253. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
254. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
255. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
256. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
257. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
258. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
259. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
260. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
66. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
67. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
68. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
69. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
70. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
96. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
97. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
98. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
261. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
262. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
263. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
264. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
265. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
266. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
267. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
268. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
269. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
270. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
67. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
68. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
69. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
70. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
71. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
97. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
98. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
99. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
271. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
272. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
273. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
274. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
275. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
276. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
277. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
278. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
279. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
280. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
68. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
69. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
70. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
71. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
72. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
98. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
99. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
100. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
281. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
282. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
283. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
284. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
285. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
286. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
287. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
288. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
289. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
290. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
69. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
70. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
71. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
72. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
73. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
99. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
100. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
101. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
291. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
292. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
293. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
294. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
295. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
296. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
297. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
298. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
299. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
300. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
70. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
71. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
72. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
73. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
74. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
100. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
101. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
102. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
301. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
302. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
303. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
304. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
305. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
306. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
307. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
308. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
309. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
310. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
71. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
72. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
73. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
74. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
75. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
101. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
102. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
103. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
311. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
312. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
313. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
314. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
315. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
316. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
317. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
318. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
319. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
320. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
72. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
73. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
74. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
75. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
76. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
102. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
103. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
104. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
321. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
322. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
323. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
324. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
325. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
326. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
327. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
328. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
329. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
330. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
73. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
74. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
75. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
76. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
77. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
103. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
104. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
105. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
331. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
332. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
333. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
334. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
335. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
336. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
337. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
338. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
339. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
340. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
74. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
75. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
76. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
77. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
78. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
104. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
105. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
106. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
341. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
342. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
343. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
344. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
345. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
346. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
347. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
348. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
349. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
350. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
75. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
76. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
77. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
78. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
79. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
105. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
106. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
107. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
351. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
352. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
353. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
354. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
355. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
356. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
357. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
358. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
359. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
360. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
76. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
77. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
78. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
79. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
80. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
106. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
107. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
108. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
361. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
362. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
363. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
364. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
365. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
366. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
367. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
368. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
369. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
370. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
77. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
78. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
79. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
80. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
81. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
107. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
108. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
109. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
371. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
372. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
373. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
374. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
375. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
376. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
377. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
378. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
379. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
380. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
78. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
79. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
80. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
81. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
82. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
108. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
109. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
110. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
381. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
382. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
383. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
384. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
385. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
386. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
387. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
388. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
389. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
390. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
79. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
80. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
81. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
82. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
83. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
109. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
110. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
111. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
391. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
392. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
393. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
394. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
395. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
396. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
397. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
398. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
399. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
400. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
80. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
81. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
82. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
83. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
84. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
110. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
111. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
112. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
401. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
402. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
403. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
404. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
405. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
406. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
407. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
408. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
409. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
410. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
81. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
82. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
83. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
84. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
85. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
111. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
112. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
113. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
411. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
412. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
413. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
414. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
415. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
416. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
417. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
418. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
419. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
420. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
82. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
83. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
84. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
85. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
86. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
112. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
113. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
114. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
421. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
422. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
423. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
424. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
425. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
426. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
427. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
428. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
429. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
430. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
83. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
84. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
85. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
86. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
87. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
113. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
114. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
115. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
431. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
432. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
433. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
434. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
435. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
436. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
437. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
438. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
439. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
440. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
84. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
85. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
86. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
87. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
88. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
114. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
115. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
116. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
441. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
442. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
443. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
444. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
445. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
446. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
447. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
448. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
449. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
450. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
85. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
86. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
87. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
88. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
89. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
115. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
116. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
117. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
451. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
452. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
453. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
454. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
455. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
456. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
457. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
458. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
459. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
460. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
86. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
87. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
88. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
89. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
90. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
116. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
117. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
118. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
461. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
462. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
463. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
464. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
465. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
466. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
467. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
468. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
469. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
470. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
87. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
88. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
89. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
90. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
91. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
117. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
118. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
119. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
471. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
472. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
473. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
474. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
475. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
476. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
477. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
478. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
479. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
480. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
88. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
89. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
90. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
91. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
92. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
118. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
119. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
120. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
481. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
482. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
483. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
484. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
485. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
486. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
487. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
488. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
489. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
490. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
89. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
90. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
91. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
92. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
93. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
119. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
120. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
121. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
491. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
492. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
493. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
494. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
495. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
496. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
497. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
498. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
499. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
500. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
90. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
91. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
92. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
93. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
94. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
120. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
121. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
122. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
501. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
502. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
503. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
504. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
505. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
506. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
507. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
508. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
509. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
510. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
91. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
92. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
93. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
94. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
95. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
121. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
122. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
123. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
511. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
512. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
513. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
514. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
515. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
516. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
517. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
518. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
519. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
520. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
92. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
93. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
94. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
95. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
96. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
122. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
123. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
124. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
521. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
522. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
523. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
524. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
525. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
526. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
527. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
528. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
529. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
530. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
93. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
94. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
95. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
96. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
97. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
123. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
124. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
125. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
531. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
532. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
533. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
534. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
535. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
536. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
537. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
538. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
539. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
540. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
94. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
95. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
96. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
97. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
98. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
124. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
125. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
126. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
541. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
542. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
543. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
544. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
545. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
546. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
547. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
548. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
549. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
550. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
95. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
96. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
97. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
98. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
99. How do intrusion detection systems (ids) work? What is the difference between
signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
125. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
126. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
127. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
551. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
552. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
553. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
554. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
555. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
556. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
557. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
558. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
559. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
560. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
96. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
97. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
98. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
99. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
100. How do intrusion detection systems (ids) work? What is the difference
between signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
126. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
127. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
128. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
561. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
562. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
563. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
564. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
565. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
566. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
567. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
568. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
569. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
570. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
97. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
98. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
99. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
100. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
101. How do intrusion detection systems (ids) work? What is the difference
between signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
127. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
128. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
129. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
571. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
572. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
573. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
574. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
575. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
576. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
577. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
578. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
579. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
580. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
98. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
99. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
100. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
101. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
102. How do intrusion detection systems (ids) work? What is the difference
between signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
128. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
129. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
130. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
581. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
582. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
583. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
584. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
585. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
586. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
587. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
588. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
589. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
590. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
99. Explain the concept of phishing attacks and how they differ from spear-phishing
attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
100. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
101. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
102. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
103. How do intrusion detection systems (ids) work? What is the difference
between signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
129. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
130. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
131. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
591. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
592. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
593. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
594. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
595. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
596. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
597. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
598. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
599. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
600. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
100. Explain the concept of phishing attacks and how they differ from spear-
phishing attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
101. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
102. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
103. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
104. How do intrusion detection systems (ids) work? What is the difference
between signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
130. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
131. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
132. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
601. Reputational damage: public trust could erode, leading to customer loss and a
decline in market valuewhat is the primary purpose of encryption?
o(a) to increase bandwidth
o(b) to secure data transmission
o(c) to reduce network congestion
o(d) to compress data
answer: (b) to secure data transmission
602. Which of the following best describes a ddos attack?
o(a) denial of service from a single system
o(b) distributing malware via email
o(c) using multiple systems to overload a server
o(d) encrypting sensitive information for ransom
answer: (c) using multiple systems to overload a server
603. What does gdpr stand for?
o(a) general data privacy rights
o(b) general data protection regulation
o(c) global data privacy rules
o(d) general directive on private regulations
answer: (b) general data protection regulation
604. What is the role of a firewall in cybersecurity?
o(a) to prevent unauthorized access
o(b) to monitor network traffic
o(c) to encrypt data
o(d) to store encryption keys
answer: (a) to prevent unauthorized access
605. Which type of malware records the keystrokes of a user?
o(a) ransomware
o(b) keylogger
o(c) spyware
o(d) trojan
answer: (b) keylogger
606. Which cybersecurity protocol is used to establish a secure connection over
the internet?
o(a) https
o(b) ftp
o(c) tcp
o(d) http
answer: (a) https
607. Which of the following is an example of a ransomware attack?
o(a) denying access to a website by overwhelming traffic
o(b) encrypting user data and demanding payment to unlock it
o(c) spamming users with promotional emails
o(d) phishing for login credentials
answer: (b) encrypting user data and demanding payment to unlock it
608. Which tool is commonly used for network packet sniffing?
o(a) wireshark
o(b) bitlocker
o(c) norton antivirus
o(d) snort
answer: (a) wireshark
609. What does an ssl certificate provide?
o(a) malware protection
o(b) data encryption
o(c) secure email communication
o(d) system updates
answer: (b) data encryption
610. Which is a method for defending against brute-force attacks?
o(a) using multi-factor authentication
o(b) sharing passwords
o(c) disabling firewalls
o(d) using default passwords
answer: (a) using multi-factor authentication
(…continue with more mcqs up to question 40)
Section b: short answer questions (5 marks each)
101. Explain the concept of phishing attacks and how they differ from spear-
phishing attacks.
Answer:
phishing attacks involve sending fraudulent communications that appear to come from a
reputable source, typically via email, in order to steal sensitive data like login credentials
or financial information.
Spear-phishing is a more targeted form of phishing, where the attacker customizes the
attack to a specific individual or organization, often using information from social media
or public databases to make the attack more convincing.
102. Discuss the importance of two-factor authentication (2fa) in securing online
accounts.
Answer:
two-factor authentication (2fa) adds an extra layer of security to the login process by
requiring two forms of verification: something the user knows (password) and something
the user has (a code sent to a mobile device). This significantly reduces the likelihood of
unauthorized access, even if a password is compromised.
103. What are advanced persistent threats (apts)? Provide an example of an apt.
Answer:
advanced persistent threats (apts) refer to prolonged and targeted cyberattacks where
an intruder gains unauthorized access to a network and remains undetected for an
extended period. The goal is often to steal data or monitor network activity. An example
of an apt is apt29, a group associated with the russian government, known for attacks
on governmental and financial institutions.
104. Define social engineering in the context of cybersecurity and describe one
method used in social engineering attacks.
Answer:
social engineering is the art of manipulating individuals into divulging confidential
information. A common method is pretexting, where the attacker fabricates a scenario
to gain trust and access to sensitive information, such as posing as a company it support
person.
105. How do intrusion detection systems (ids) work? What is the difference
between signature-based and anomaly-based ids?
Answer:
ids monitors network traffic for suspicious activity and issues alerts when such activity is
detected.
Signature-based ids detects attacks by looking for specific patterns or signatures of
known threats.
Anomaly-based ids detects deviations from normal network behavior, identifying
unusual patterns that might indicate a new or unknown attack.
(…continue with more short answer questions up to question 70)
Section c: long answer questions (10-25 marks each)
131. (10 marks)
explain the concept of zero-day vulnerabilities in cybersecurity. Discuss how zero-
day attacks can be prevented.
Answer:
zero-day vulnerabilities are flaws in software that are exploited by attackers before the
vendor is aware of the flaw or has had time to patch it. These vulnerabilities are
particularly dangerous because there is no fix available at the time of the attack.
Prevention:
oRegular software updates and patching
oEmploying intrusion detection systems (ids)
oBehavioral analysis to detect anomalous activity
oNetwork segmentation to limit attack surfaces
132. (15 marks)
discuss the significance of international cooperation in combating cybercrime.
Include examples of organizations involved in global cybersecurity efforts.
Answer:
international cooperation is critical in fighting cybercrime because many attacks cross
borders. Governments, law enforcement agencies, and global organizations must work
together to address threats that affect multiple nations.
Examples include:
oInterpol's cybercrime directorate which coordinates international cybercrime
investigations.
oEuropol's european cybercrime centre (ec3) assists eu nations in addressing
cyber threats.
oThe united nations works on setting global norms for cybersecurity practices.
133. (20 marks)
case study:
a multinational corporation has suffered a data breach, where attackers accessed
sensitive customer and employee data.
(a) outline the immediate steps the company should take after discovering the
breach. (10 marks)
(b) discuss the potential legal and reputational impacts of this breach. (10 marks)
answer:
(a) immediate steps:
oContain the breach by isolating affected systems.
oNotify regulatory bodies and customers affected by the breach.
oEngage cybersecurity experts to assess the damage and identify vulnerabilities.
oFix vulnerabilities to prevent further exploitation.
(b) legal and reputational impacts:
oLegal impacts: the company could face regulatory fines for violating data
protection laws, such as gdpr or ccpa. They may also face lawsuits from affected
customers or employees.
oReputational damage: public trust could erode, leading to customer loss and a
decline in market value
Students also viewed