Cybersecurity Placement Test

Free assessment — no account required
Answer all questions to the best of your ability. Your result helps estimate your current level and recommend an appropriate learning path.
Question 1 of 40

What is the primary role of an operating system?

Please select an answer before continuing.
Question 2 of 40

What is an IP address primarily used for?

Please select an answer before continuing.
Question 3 of 40

What is the main function of a router?

Please select an answer before continuing.
Question 4 of 40

What does DNS commonly do?

Please select an answer before continuing.
Question 5 of 40

Which statement best describes TCP?

Please select an answer before continuing.
Question 6 of 40

What is a firewall primarily designed to do?

Please select an answer before continuing.
Question 7 of 40

Which term describes software intentionally designed to cause harm, steal information, or perform unauthorized actions?

Please select an answer before continuing.
Question 8 of 40

A message pretending to be from a trusted organization asks you to click a link and enter your password. What type of attack is this most likely?

Please select an answer before continuing.
Question 9 of 40

What is the main security benefit of multi-factor authentication (MFA)?

Please select an answer before continuing.
Question 10 of 40

Which password practice is generally the most secure?

Please select an answer before continuing.
Question 11 of 40

What is the primary purpose of encryption?

Please select an answer before continuing.
Question 12 of 40

Which statement best describes cryptographic hashing?

Please select an answer before continuing.
Question 13 of 40

In cybersecurity, what is a vulnerability?

Please select an answer before continuing.
Question 14 of 40

Why are security patches important?

Please select an answer before continuing.
Question 15 of 40

What does the principle of least privilege mean?

Please select an answer before continuing.
Question 16 of 40

In the CIA security triad, what does confidentiality focus on?

Please select an answer before continuing.
Question 17 of 40

In information security, integrity primarily means:

Please select an answer before continuing.
Question 18 of 40

Why are tested backups important in cybersecurity?

Please select an answer before continuing.
Question 19 of 40

You suspect that a workstation has been compromised. Which action is generally most appropriate?

Please select an answer before continuing.
Question 20 of 40

What is social engineering in cybersecurity?

Please select an answer before continuing.
Question 21 of 40

A host has the address 192.168.10.130/26. Which network address contains this host?

Please select an answer before continuing.
Question 22 of 40

During a normal TCP connection establishment, which sequence represents the three-way handshake?

Please select an answer before continuing.
Question 23 of 40

A browser receives a TLS certificate whose hostname does not match the website being visited. What security property has primarily failed?

Please select an answer before continuing.
Question 24 of 40

A web application safely parameterizes all SQL queries, but places untrusted user input directly into HTML responses without context-appropriate output encoding. Which vulnerability remains most relevant?

Please select an answer before continuing.
Question 25 of 40

A SIEM observes a successful login immediately after hundreds of failed authentication attempts against the same account from one external source. What should an analyst investigate first?

Please select an answer before continuing.
Question 26 of 40

EDR detects a suspicious process spawning PowerShell with an encoded command followed by outbound communication to an unusual host. What is the most appropriate immediate defensive action when organizational procedures allow it?

Please select an answer before continuing.
Question 27 of 40

Why is membership in a highly privileged Active Directory administrative group particularly sensitive?

Please select an answer before continuing.
Question 28 of 40

An attacker compromises a standard user account and then exploits a local misconfiguration to obtain SYSTEM-level privileges. Which stage best describes the second action?

Please select an answer before continuing.
Question 29 of 40

A security analyst observes unusually large numbers of Kerberos service-ticket requests for many service accounts from a single workstation. Which activity should be considered during investigation?

Please select an answer before continuing.
Question 30 of 40

After compromising one workstation, an attacker uses stolen credentials to authenticate to additional internal systems. Which term best describes this behavior?

Please select an answer before continuing.
Question 31 of 40

Two vulnerabilities have similar CVSS scores. One is Internet-exposed, has reliable exploitation observed in the wild, and affects a critical authentication server. The other exists only on an isolated test system. Which should normally receive higher remediation priority?

Please select an answer before continuing.
Question 32 of 40

An internal workstation makes small encrypted outbound connections to the same uncommon external host at highly regular intervals, including when no user is active. Which hypothesis deserves investigation?

Please select an answer before continuing.
Question 33 of 40

A threat hunter has an indicator for one malicious domain but wants to identify related activity even if the adversary changes domains. Which approach is generally more resilient?

Please select an answer before continuing.
Question 34 of 40

During incident response, malware is suspected of injecting code into another running process without leaving a clear executable on disk. Which evidence source is especially valuable?

Please select an answer before continuing.
Question 35 of 40

A cloud workload normally reads objects from one storage bucket. Its identity suddenly receives a broad wildcard permission across multiple services. What is the strongest security concern?

Please select an answer before continuing.
Question 36 of 40

An enterprise root certificate authority private key is confirmed compromised. Why is this a severe incident?

Please select an answer before continuing.
Question 37 of 40

A workstation shows a burst of Kerberos service-ticket requests for privileged service accounts, followed shortly by successful remote logons to several servers using one of those accounts. Which interpretation best connects the evidence?

Please select an answer before continuing.
Question 38 of 40

A compromised endpoint may contain fileless malware, active network sessions, injected processes, and short-lived credentials. The system must eventually be rebuilt. Which evidence collection priority best preserves volatile investigative value?

Please select an answer before continuing.
Question 39 of 40

An adversary frequently changes filenames, hashes, IP addresses, and domains but repeatedly uses the same unusual parent-child process chain and credential-access behavior. Which detection strategy is likely to remain effective longest?

Please select an answer before continuing.
Question 40 of 40

An organization observes a suspicious document spawning a script interpreter, credential-access alerts on the endpoint, unusual privileged authentication to multiple servers, and periodic encrypted outbound connections from those servers. Which response best reflects expert incident handling?

Please select an answer before continuing.
No student account is created and this attempt is not stored in the Moodle gradebook.