CYBER SECURITY – ACADEMIC YEAR
2026/2027 – COMPREHENSIVE
EXAMINATION | VERIFIED QUESTIONS
DOMAIN 1: SECURITY FUNDAMENTALS AND THREAT LANDSCAPE
Question 1. Which of the following best describes the CIA triad in information
security?
A. Confidentiality, Integrity, and Availability
B. Control, Inspection, and Authorization
C. Cryptography, Identification, and Authentication
D. Compliance, Investigation, and Auditing
Rationale: The CIA triad is the foundational model of information security,
representing Confidentiality (protecting data from unauthorized access), Integrity
(ensuring data accuracy and trustworthiness), and Availability (ensuring
authorized users can access resources when needed).
Question 2. A phishing attack is best classified as which type of threat?
A. A physical security breach
B. A social engineering technique that attempts to trick users into revealing
sensitive information
C. A hardware failure
D. A cryptographic weakness
Rationale: Phishing uses deceptive messages, typically via email or messaging, to
manipulate individuals into disclosing credentials, clicking malicious links, or
downloading malware. It exploits human behavior rather than technical
vulnerabilities alone.
Question 3. Which of the following is an example of a vulnerability?
,A. A properly configured firewall
B. An unpatched software application that can be exploited by an attacker
C. A strong password policy
D. Regular security awareness training
Rationale: A vulnerability is a weakness in a system, application, or process that
can be exploited. Unpatched software is a common vulnerability that attackers
target to gain unauthorized access or execute malicious code.
Question 4. The primary difference between a threat and a risk is that:
A. A threat is a potential cause of an unwanted incident, while risk is the
potential for loss when a threat exploits a vulnerability
B. Threats and risks are identical concepts
C. Risks exist only in physical environments
D. Threats can be measured only in monetary terms
Rationale: A threat is anything that can cause harm. Risk combines the likelihood
that a threat will exploit a vulnerability with the potential impact of that
exploitation.
Question 5. Which of the following is an example of a passive attack?
A. Denial-of-service attack
B. Eavesdropping on network traffic
C. SQL injection
D. Ransomware deployment
Rationale: Passive attacks involve monitoring or eavesdropping without modifying
system resources. Active attacks, such as DoS, SQL injection, and ransomware,
involve modifying or disrupting system operations.
Question 6. What is the primary goal of a denial-of-service (DoS) attack?
A. To steal sensitive data
B. To make a system or network resource unavailable to legitimate users
,C. To encrypt files for ransom
D. To gain unauthorized access to a system
Rationale: A DoS attack aims to overwhelm a system or network with traffic or
requests, making it unavailable to legitimate users. It does not typically involve
data theft or encryption.
Question 7. Which of the following best describes malware?
A. Malicious software designed to damage, disrupt, or gain unauthorized
access to a computer system
B. A type of firewall
C. A network protocol
D. A cryptographic algorithm
Rationale: Malware is any software intentionally designed to cause damage,
disrupt operations, or gain unauthorized access to systems. Types include viruses,
worms, trojans, ransomware, and spyware.
Question 8. What is the primary characteristic of a worm?
A. It requires user interaction to spread
B. It self-replicates and spreads across networks without user intervention
C. It only affects standalone computers
D. It is a type of hardware failure
Rationale: A worm is a type of malware that self-replicates and spreads across
networks automatically, without requiring user interaction. This distinguishes it
from a virus, which typically requires a host file or user action.
Question 9. What is the primary characteristic of a trojan horse?
A. It self-replicates automatically
B. It disguises itself as legitimate software to trick users into installing it
C. It only affects mobile devices
D. It is a type of firewall
, Rationale: A trojan horse disguises itself as legitimate or useful software to trick
users into installing it. Once installed, it can perform malicious actions such as
stealing data or providing backdoor access.
Question 10. Which type of malware encrypts a victim's files and demands
payment for the decryption key?
A. Spyware
B. Adware
C. Ransomware
D. Rootkit
Rationale: Ransomware encrypts a victim's files and demands payment (ransom)
in exchange for the decryption key. It is a significant and growing threat to
organizations and individuals.
Question 11. What is the primary purpose of spyware?
A. To display advertisements
B. To secretly collect information about a user's activities
C. To encrypt files for ransom
D. To self-replicate across networks
Rationale: Spyware is designed to secretly collect information about a user's
activities, such as browsing habits, keystrokes, and login credentials, without the
user's knowledge or consent.
Question 12. What is a zero-day vulnerability?
A. A vulnerability that is unknown to the software vendor and has no
available patch
B. A vulnerability that has been patched
C. A vulnerability that only affects zero-day-old software
D. A vulnerability that is not exploitable
2026/2027 – COMPREHENSIVE
EXAMINATION | VERIFIED QUESTIONS
DOMAIN 1: SECURITY FUNDAMENTALS AND THREAT LANDSCAPE
Question 1. Which of the following best describes the CIA triad in information
security?
A. Confidentiality, Integrity, and Availability
B. Control, Inspection, and Authorization
C. Cryptography, Identification, and Authentication
D. Compliance, Investigation, and Auditing
Rationale: The CIA triad is the foundational model of information security,
representing Confidentiality (protecting data from unauthorized access), Integrity
(ensuring data accuracy and trustworthiness), and Availability (ensuring
authorized users can access resources when needed).
Question 2. A phishing attack is best classified as which type of threat?
A. A physical security breach
B. A social engineering technique that attempts to trick users into revealing
sensitive information
C. A hardware failure
D. A cryptographic weakness
Rationale: Phishing uses deceptive messages, typically via email or messaging, to
manipulate individuals into disclosing credentials, clicking malicious links, or
downloading malware. It exploits human behavior rather than technical
vulnerabilities alone.
Question 3. Which of the following is an example of a vulnerability?
,A. A properly configured firewall
B. An unpatched software application that can be exploited by an attacker
C. A strong password policy
D. Regular security awareness training
Rationale: A vulnerability is a weakness in a system, application, or process that
can be exploited. Unpatched software is a common vulnerability that attackers
target to gain unauthorized access or execute malicious code.
Question 4. The primary difference between a threat and a risk is that:
A. A threat is a potential cause of an unwanted incident, while risk is the
potential for loss when a threat exploits a vulnerability
B. Threats and risks are identical concepts
C. Risks exist only in physical environments
D. Threats can be measured only in monetary terms
Rationale: A threat is anything that can cause harm. Risk combines the likelihood
that a threat will exploit a vulnerability with the potential impact of that
exploitation.
Question 5. Which of the following is an example of a passive attack?
A. Denial-of-service attack
B. Eavesdropping on network traffic
C. SQL injection
D. Ransomware deployment
Rationale: Passive attacks involve monitoring or eavesdropping without modifying
system resources. Active attacks, such as DoS, SQL injection, and ransomware,
involve modifying or disrupting system operations.
Question 6. What is the primary goal of a denial-of-service (DoS) attack?
A. To steal sensitive data
B. To make a system or network resource unavailable to legitimate users
,C. To encrypt files for ransom
D. To gain unauthorized access to a system
Rationale: A DoS attack aims to overwhelm a system or network with traffic or
requests, making it unavailable to legitimate users. It does not typically involve
data theft or encryption.
Question 7. Which of the following best describes malware?
A. Malicious software designed to damage, disrupt, or gain unauthorized
access to a computer system
B. A type of firewall
C. A network protocol
D. A cryptographic algorithm
Rationale: Malware is any software intentionally designed to cause damage,
disrupt operations, or gain unauthorized access to systems. Types include viruses,
worms, trojans, ransomware, and spyware.
Question 8. What is the primary characteristic of a worm?
A. It requires user interaction to spread
B. It self-replicates and spreads across networks without user intervention
C. It only affects standalone computers
D. It is a type of hardware failure
Rationale: A worm is a type of malware that self-replicates and spreads across
networks automatically, without requiring user interaction. This distinguishes it
from a virus, which typically requires a host file or user action.
Question 9. What is the primary characteristic of a trojan horse?
A. It self-replicates automatically
B. It disguises itself as legitimate software to trick users into installing it
C. It only affects mobile devices
D. It is a type of firewall
, Rationale: A trojan horse disguises itself as legitimate or useful software to trick
users into installing it. Once installed, it can perform malicious actions such as
stealing data or providing backdoor access.
Question 10. Which type of malware encrypts a victim's files and demands
payment for the decryption key?
A. Spyware
B. Adware
C. Ransomware
D. Rootkit
Rationale: Ransomware encrypts a victim's files and demands payment (ransom)
in exchange for the decryption key. It is a significant and growing threat to
organizations and individuals.
Question 11. What is the primary purpose of spyware?
A. To display advertisements
B. To secretly collect information about a user's activities
C. To encrypt files for ransom
D. To self-replicate across networks
Rationale: Spyware is designed to secretly collect information about a user's
activities, such as browsing habits, keystrokes, and login credentials, without the
user's knowledge or consent.
Question 12. What is a zero-day vulnerability?
A. A vulnerability that is unknown to the software vendor and has no
available patch
B. A vulnerability that has been patched
C. A vulnerability that only affects zero-day-old software
D. A vulnerability that is not exploitable