Getting your questions ready
Getting your questions ready
Beat the crowd
10 questions No timer
60 free cybersecurity trivia questions with answers. Sixty cybersecurity trivia questions, written for security-awareness sessions, IT team socials and anyone who enjoys the history of hacking. The opening stretch covers the vocabulary every employee is supposed to know: phishing, ransomware, the CIA triad, zero-days, honeypots, multi-factor authentication, air gaps and zero trust. Then it moves through the incidents that made the news, from Creeper and the Morris worm to ILOVEYOU, Stuxnet, WannaCry, Heartbleed, Equifax, SolarWinds, Colonial Pipeline and Log4Shell. The back half is for the people who read the post-mortems: Rejewski and Enigma, Colossus, the first password on CTSS, who really invented RSA, Captain Crunch's whistle, the Selectric bug, DEF CON, Have I Been Pwned, and the films and shows that taught the public what a hacker looks like. Difficulty runs from easy definitions to a few questions only a veteran will get, so mixed groups all have something to play for. Every answer was checked against Wikipedia's articles on the incidents, people and technologies involved, and the sentence that establishes it is shown under each explanation.
30 of 60 questions with answers and explanations. Play the quiz
Q 01What is the fraud of sending messages posing as a trusted sender to trick people into revealing passwords called?
Phishing
Phishing takes its 'ph' spelling from phreaking, the older hobby of hacking phone systems; the word was first recorded in AOHell, a 1995 AOL cracking toolkit.
Q 02Malware that encrypts a victim's files and demands payment for the key is called what?
Ransomware
Ransomware dates to the 1989 AIDS Trojan, which scrambled file names on victims' PCs and demanded $189 be mailed to a post-office box in Panama; its weak symmetric cipher was soon reversed.
Q 03The 'CIA triad' at the heart of information security stands for confidentiality, integrity and what?
Availability
Availability, the third leg of the CIA triad, means legitimate users can reach their data when they need it; the acronym has nothing to do with the US intelligence agency.
Q 04A software flaw exploited by attackers before the vendor even knows it exists is called what?
Zero-day
Zero-day counts the days the vendor has had to fix it, which at the moment of discovery is none.
Q 05In cybersecurity, a decoy system set up to attract attackers and study them is known as what?
Honeypot
A honeypot makes suspicion automatic: no legitimate user has a reason to touch it, so anything that does is an attacker.
Q 06Multi-factor authentication requires how many distinct types of evidence before granting access?
Two or more
Multi-factor authentication demands two or more distinct factor types: something you know (a password), something you have (a phone or key) and something you are (a fingerprint).
Q 07Malware that disguises itself as a normal program to mislead users is named after what?
A wooden horse from Greek myth
Trojan-horse malware is named after the hollow wooden horse of Greek myth that smuggled Greek soldiers inside the walls of Troy; the computing sense dates from the early 1970s.
Q 08Manipulating people psychologically into divulging information or taking unsafe actions is called what?
Social engineering
Social engineering attacks the person rather than the machine; its sub-genres include pretexting (an invented scenario), baiting (a tempting USB stick) and tailgating through a secure door.
Q 09Which networking term, borrowed from building construction, names a system that filters traffic between networks?
Firewall
Firewall originally meant a wall that confines a fire within a row of buildings; the word jumped to networking in the 1980s.
Q 10A computer that is physically isolated from the internet and other unsecured networks is said to be what?
Air-gapped
An air-gapped computer has no network connection at all, so data must move by hand on removable media; an infected USB stick is how Stuxnet crossed the gap into Iran's enrichment plant.
Q 11An analyst at which research firm named the 'never trust, always verify' model 'Zero Trust' in 2010?
Forrester
Forrester analyst John Kindervag coined 'Zero Trust' in a 2010 report; the model gained ground as cloud and mobile use dissolved the old network perimeter.
Q 12What is generally considered the first computer worm, a 1971 program on ARPANET?
Creeper
It printed 'I'M THE CREEPER: CATCH ME IF YOU CAN', and a program called Reaper was written to hunt it down, making Reaper the first antivirus.
Q 13The Morris worm of 2 November 1988 was written by a graduate student at which university?
Cornell
Robert Tappan Morris was a Cornell graduate student who launched the worm from MIT to disguise its origin; his was the first felony conviction under the 1986 Computer Fraud and Abuse Act.
Q 21The May 2017 WannaCry attack spread using EternalBlue, an exploit originally developed by which agency?
NSA
EternalBlue was built by the NSA and leaked by the Shadow Brokers in April 2017, a month before WannaCry; the US and Britain later blamed North Korea for the attack itself.
Q 22WannaCry was halted within hours when researcher Marcus Hutchins did what?
Registered a domain name that acted as a kill switch
The malware checked whether an unregistered web address existed before running; once he bought it, new infections stopped.
Q 23Heartbleed, disclosed in April 2014, was a bug in which widely used cryptography library?
OpenSSL
Q 14What sentence did Robert Tappan Morris receive for releasing the 1988 internet worm?
Three years' probation and a fine
Morris received three years' probation, 400 hours of community service and a $10,050 fine; the appeals court put the clean-up cost per site at anywhere from $200 to over $53,000.
Q 15The ILOVEYOU worm of May 2000 was written by a college dropout from which country?
Philippines
Onel de Guzman, a computer-college dropout from Manila in the Philippines, had all charges dropped because the Philippines had no law against hacking at the time.
Q 16Which 1999 virus spread via infected Word documents emailed to a victim's first 50 contacts?
Melissa
Melissa, released by David L. Smith on 26 March 1999, arrived as a Word attachment innocuously named list.doc and mailed itself to the first 50 addresses in each victim's Outlook address book.
Q 17Elk Cloner, an early 'in the wild' virus written by a 15-year-old around 1982, targeted which computer?
Apple II
Rich Skrenta wrote Elk Cloner for the Apple II as a prank and spread it on game floppies; every 50th boot it displayed a short poem.
Q 18Brain, considered the first virus for the IBM PC, was written in 1986 by two brothers in which city?
Lahore
Basit and Amjad Farooq Alvi ran a computer shop in Lahore, Pakistan, and embedded their names, address and phone numbers in Brain's code; they were reportedly swamped with calls.
Q 19Stuxnet, uncovered in 2010, is believed to have destroyed nuclear centrifuges at which Iranian facility?
Natanz
Stuxnet hijacked the Siemens controllers running Natanz's enrichment centrifuges and reportedly wrecked almost a fifth of Iran's centrifuges by spinning them outside their safe range.
Q 20The joint US-Israeli effort that reportedly built Stuxnet is known by what code name?
Operation Olympic Games
Operation Olympic Games was revealed by New York Times reporter David Sanger in 2012 as a programme begun under George W. Bush and expanded under Barack Obama.
Heartbleed was a missing bounds check in OpenSSL's TLS heartbeat extension (CVE-2014-0160) that let anyone read up to 64 KB of a server's memory per request; it arrived with its own logo.
Q 24The 2017 Equifax breach exposed private records of roughly how many Americans?
About 148 million
An unpatched Apache Struts flaw let attackers in, and the US later indicted members of China's People's Liberation Army.
Q 25The 2020 supply-chain attack on US government agencies came through which SolarWinds product?
Orion
The attackers slipped a backdoor into updates of SolarWinds' Orion network-monitoring platform; fewer than 18,000 of its 33,000 customers installed the tainted build, and the SVR-linked group Cozy Bear was blamed.
Q 26Which group was identified by the FBI as responsible for the May 2021 Colonial Pipeline extortion attack?
DarkSide
The FBI named the DarkSide ransomware gang on 10 May 2021; Colonial paid 75 bitcoin, about $4.4 million, within hours, and panic buying then emptied filling stations across the Southeast.
Q 27The 2013 Yahoo breach, not disclosed until 2016, affected how many user accounts?
All 3 billion
Yahoo revised the 2013 breach in October 2017 to all 3 billion accounts, three times the 1 billion first admitted; a separate 2014 intrusion hit 500 million, and Verizon cut its purchase price by $350 million.
Q 28The 'Guardians of Peace' hackers leaked Sony Pictures data in 2014 demanding it pull which film?
The Interview
The Interview, a comedy starring Seth Rogen and James Franco as a TV host and producer recruited to assassinate Kim Jong Un, was pulled from wide release before a limited Christmas Day opening in 2014.
Q 29Log4Shell, the critical December 2021 flaw, hit Log4j, a logging library for which language?
Java
Log4j is the Apache logging library for Java; the flaw had lurked since a 2013 JNDI lookup feature, was reported by Alibaba Cloud's Chen Zhaojun, and got its 'Log4Shell' name from the LunaSec team.
Q 30NSO Group, developer of the Pegasus phone spyware, is based in which country?
Israel
NSO Group is headquartered in Herzliya, Israel, and every foreign sale of Pegasus needs an export licence from the Israeli defence ministry; the US Commerce Department blacklisted the firm in November 2021.