Cyber Security MCQs

Computer

Cyber Security MCQs

Practice Cyber Security MCQs covering viruses, malware, phishing, hacking, firewall, antivirus and cybersecurity concepts with answers and explanations.

269
Total Questions

Practice Questions

Page 2 of 14
Question #21
Which antivirus analysis protocol examines an unverified application’s structural code commands for suspicious traits or potential threats, even if that specific file hash has never been documented before?
A. Dynamic Cryptographic Hashing
B. Static Signature Masking
C. Heuristic / Behavioral Analysis
D. Database Indexing Lookup

Correct Answer: Option C


Explanation:
Heuristics allow antivirus software to identify zero-day threats by checking logic structures and function signatures for suspicious characteristics rather than relying on static file hash indices.

This question belongs to: Computer Cyber Security
Question #22
What form of social engineering scam utilizes interactive voice response systems or fake telephone calls from threat actors posing as credit card fraud investigators to extract financial metrics?
A. Smishing Scam
B. Vishing (Voice Phishing)
C. Whaling Exploit
D. Pharming Setup

Correct Answer: Option B


Explanation:
Vishing leverages telephone interactions and voice tricks to manipulate victims into providing personal identification records or banking credentials.

This question belongs to: Computer Cyber Security
Question #23
A type of attack where an operator uses automated scripts to cycle through thousands of dictionary words or random password combinations systematically until the correct sequence is verified is a/an:
A. SQL Injection Exploit
B. Eavesdropping Exploit
C. Brute Force Attack
D. Phishing Setup

Correct Answer: Option C


Explanation:
Brute force attacks systematically guess login combinations, trying permutations until a successful authentication match unlocks the targeted account.

This question belongs to: Computer Cyber Security
Question #24
What is the technical security term given to a software flaw or hardware vulnerability that is actively exploited by threat actors before the software vendor has developed a remediation patch?
A. Backdoor Entry
B. Zero-Day Vulnerability
C. Buffer Overflow
D. Logic Bypass flaw

Correct Answer: Option B


Explanation:
A zero-day exploit targets unknown or unpatched software vulnerabilities, giving defense teams zero days of preparation to guard against the threat.

This question belongs to: Computer Cyber Security
Question #25
Which firewall filtering type checks the actual structural state of an active network connection, keeping track of outbound data handshakes to verify that incoming response packets are legitimate parts of an established session?
A. Stateful Inspection Firewall
B. Circuit Level Gateway
C. Stateless Packet Filtering
D. Application Layer Proxy

Correct Answer: Option A


Explanation:
Stateful firewalls track the operational status and context of network connections, validating incoming packets against verified outbound session states.

This question belongs to: Computer Cyber Security
Question #26
What class of hacker operates without malicious intent but may cross legal boundaries to access systems without permission, later disclosing the security flaws to owners or demanding a remediation fee?
A. Grey Hat Hacker
B. White Hat Hacker
C. Black Hat Hacker
D. Script Kiddie

Correct Answer: Option A


Explanation:
Grey hat hackers inhabit an ethical middle ground; they compromise system boundaries without authorization but generally lack malicious intent, aiming instead to report or expose systemic bugs.

This question belongs to: Computer Cyber Security
Question #27
Which malicious software strain automatically floods a user’s computer monitor with pop-up marketing window sequences, often slowing system performance and bundling tracker cookies secretly?
A. Computer Worm
B. Ransomware Core
C. Adware
D. Rootkit Module

Correct Answer: Option C


Explanation:
Adware is code optimized to continuously display advertisement matrices on client screens, often bundled with browser add-ons without transparent consent.

This question belongs to: Computer Cyber Security
Question #28
A complex exploit strategy that compromises the DNS routing directories of a server to automatically redirect users to fake e-commerce sites, even if they typed the correct URL, is known as:
A. Spear Phishing
B. Smishing
C. Vishing
D. Pharming

Correct Answer: Option D


Explanation:
Pharming manipulates DNS servers or host files to transparently reroute traffic to spoofed destinations, harvesting user data even when valid URLs are entered.

This question belongs to: Computer Cyber Security
Question #29
Which cryptographic security technique scrambles plain text records into unreadable strings using mathematical keys, ensuring data remains secure even if intercepted by threat actors?
A. Hashing Allocation
B. De-duplication
C. Encryption
D. Sandboxing Matrix

Correct Answer: Option C


Explanation:
Encryption alters readable data into ciphertext using cryptographic mathematical algorithms, requiring specialized keys to reverse and decode.

This question belongs to: Computer Cyber Security
Question #30
What is the technical term for an intentional, hidden security flaw or operational bypass left behind by software developers or cybercriminals to allow easy administrative access to a system later?
A. Zero-Day Route
B. Trojan Module
C. Logic Loop
D. Backdoor

Correct Answer: Option D


Explanation:
A backdoor bypasses standard authentication protocols, letting insiders or threat actors retain persistent access to targeted operating platforms.

This question belongs to: Computer Cyber Security
Question #31
Which security measure acts as an encrypted network tunnel, obfuscating a client device's physical IP address and wrapping internet traffic in a secure cryptographic layer over public networks?
A. Intrusion Prevention Module
B. Proxy Gateway Server
C. Firewall Layer
D. Virtual Private Network (VPN)

Correct Answer: Option D


Explanation:
VPNs encrypt network data traffic en route between client machines and remote nodes, protecting sessions from snooping on public transport lines.

This question belongs to: Computer Cyber Security
Question #32
What defensive approach involves setting up attractive but completely fake database servers or files to lure hackers away from core production resources and analyze their attack methodologies?
A. Sandboxing
B. Firewall Filtering
C. Honeypot
D. Encryption Vaulting

Correct Answer: Option C


Explanation:
Honeypots are decoy systems designed to attract, deceive, and document the behavior of threat actors targeting organizational networks.

This question belongs to: Computer Cyber Security
Question #33
A destructive form of macro malware explicitly designed to execute malicious code blocks whenever an infected Microsoft Office Word spreadsheet or text document is loaded is classified as a/an:
A. Macro Virus
B. Asynchronous Worm
C. Network Packet Sniffer
D. Boot Sector Threat

Correct Answer: Option A


Explanation:
Macro viruses exploit programming languages embedded inside productivity suite applications, running automated scripts when files are opened.

This question belongs to: Computer Cyber Security
Question #34
Which security parameter evaluates corporate passwords by systematically testing random character hashes to calculate how long they can withstand an automated guessing script?
A. Password Filtering Analyzer
B. Access Control List Validator
C. Password Strength / Complexity Auditor
D. Multi-Factor Registry Check

Correct Answer: Option C


Explanation:
Complexity auditors measure the entropy and structural resilience of user credentials against dictionary or automated guessing patterns.

This question belongs to: Computer Cyber Security
Question #35
What type of attack targets a web application by injecting malicious SQL statements into input forms, allowing the attacker to manipulate the underlying backend database directly?
A. Buffer Overflow Attack
B. Denial of Service (DoS)
C. SQL Injection (SQLi)
D. Cross-Site Scripting (XSS)

Correct Answer: Option C


Explanation:
SQL injection occurs when unvalidated user input is passed directly to a database query engine, enabling threat actors to view, alter, or delete database tables illegally.

This question belongs to: Computer Cyber Security
Question #36
A security policy that assumes no user or device should be trusted by default, requiring continuous verification at every stage of network access, is known as:
A. Defense in Depth
B. Zero Trust Architecture
C. Least Privilege Access
D. Stateful Network Control

Correct Answer: Option B


Explanation:
Zero Trust is an IT security model based on the premise of 'never trust, always verify,' requiring strict identity validation for every person and device trying to access resources on a private network.

This question belongs to: Computer Cyber Security
Question #37
Which technique involves sending fraudulent emails customized for a specific employee within an organization, using personal details to make the message highly convincing?
A. Bulk Spamming
B. Spear Phishing
C. Vishing connection
D. Pharming redirection

Correct Answer: Option B


Explanation:
Spear phishing targets specific individuals or organizations using tailored context and personal details to increase the likelihood of deception.

This question belongs to: Computer Cyber Security
Question #38
What component of an antivirus system isolates infected or highly suspicious files in a protected, inaccessible directory to prevent them from executing or spreading code?
A. Heuristic Analyzer
B. Sandbox Controller
C. Firewall Exclusion List
D. Quarantine Vault

Correct Answer: Option D


Explanation:
Antivirus programs move flagged files into a quarantine vault, isolating them from the rest of the filesystem to neutralize potential threats.

This question belongs to: Computer Cyber Security
Question #39
What type of attack occurs when an unauthorized user intercepts a wireless network session token, allowing them to impersonate a legitimate user without typing a password?
A. SQL Injection Modality
B. Brute Force Guessing
C. Session Hijacking / Cookie Stealing
D. IP Header Spoofing

Correct Answer: Option C


Explanation:
Session hijacking involves stealing active session IDs or web cookies to take over an authenticated user's active session web connection.

This question belongs to: Computer Cyber Security
Question #40
A piece of code that self-replicates by attaching its binary payload to an executable file on a USB flash drive, running whenever the drive is plugged into a new system, is a:
A. Pure Network Daemon
B. Macro Script Module
C. Boot Sector / File Infector Virus
D. Logic Bomb Tracker

Correct Answer: Option C


Explanation:
File infectors and boot sector viruses attach to portable files and storage partitions, copying themselves to new host machines via shared media.

This question belongs to: Computer Cyber Security