Technology · BUILDER · Hard

Cybersecurity Quiz

Phishing, ransomware, WannaCry, Stuxnet and Kevin Mitnick: 15 questions on staying safe online.

15questions
0correct
0answered
YOUR PROGRESS0 correct · 0 / 15 answered

    TechnologyQuestion 1 of 15

    In a web address beginning with https, what does the final letter s stand for?

    Got a hunch? Pick the answer that feels right.

    The answer, explained

    Secure

    HTTPS stands for Hypertext Transfer Protocol Secure: the connection is encrypted with TLS so that anyone intercepting traffic between your browser and the website cannot read passwords or card numbers.

    WORTH KNOWING

    Google Chrome began labelling plain http sites as Not Secure in 2018, a nudge that pushed most of the web to adopt encryption.

    What is the term for fraudulent emails or messages that pose as a trusted organisation to trick you into handing over passwords or card details?

    Got a hunch? Pick the answer that feels right.

    The answer, explained

    Phishing

    Phishing attacks imitate banks, delivery firms or colleagues to lure victims onto fake login pages, and they remain the most common starting point for breaches because they exploit people rather than software.

    WORTH KNOWING

    Targeted phishing aimed at a specific person is called spear phishing, and when the target is a senior executive it is known as whaling.

    Which kind of malware encrypts a victim's files and demands payment, usually in cryptocurrency, to unlock them?

    Got a hunch? Pick the answer that feels right.

    The answer, explained

    Ransomware

    Ransomware scrambles data and displays a ransom note, and modern gangs often also steal copies of the files and threaten to publish them, a tactic known as double extortion.

    WORTH KNOWING

    The first known ransomware, the 1989 AIDS Trojan, spread on floppy disks and demanded that $189 be posted to a PO box in Panama.

    Logging in with a password plus a one-time code sent to your phone is an example of which security practice?

    Got a hunch? Pick the answer that feels right.

    The answer, explained

    Two-factor authentication

    Two-factor authentication combines something you know, the password, with something you have, such as your phone or a hardware key, so a stolen password alone is not enough to get in.

    WORTH KNOWING

    Authenticator apps and passkeys are considered safer than SMS codes, because text messages can be intercepted through SIM swap fraud.

    What does VPN stand for?

    Got a hunch? Pick the answer that feels right.

    The answer, explained

    Virtual Private Network

    A Virtual Private Network creates an encrypted tunnel between your device and a remote server, hiding your traffic from the local network and making it appear to come from the server's location.

    WORTH KNOWING

    VPNs were originally built so remote employees could reach company networks securely, long before they became a consumer tool for streaming and privacy.

    The WannaCry ransomware outbreak of May 2017 famously disrupted hospitals belonging to which organisation?

    Got a hunch? Pick the answer that feels right.

    The answer, explained

    NHS

    WannaCry infected an estimated 70,000 NHS devices across England and Scotland in a single day, forcing hospitals to cancel appointments and divert ambulances, at a cost later put at around £92 million.

    WORTH KNOWING

    Researcher Marcus Hutchins stopped the spread by registering an unregistered domain name he found in the code, an accidental kill switch.

    The Stuxnet worm, discovered in 2010, was designed to sabotage uranium enrichment centrifuges in which country?

    Got a hunch? Pick the answer that feels right.

    The answer, explained

    Iran

    Stuxnet targeted Siemens industrial controllers at Iran's Natanz facility, secretly speeding centrifuges up and slowing them down until they broke, while feeding normal readings to operators.

    WORTH KNOWING

    No government has claimed it, but it is widely reported to have been a joint US and Israeli operation code-named Olympic Games.

    In a DDoS attack, what does the acronym DDoS stand for?

    Got a hunch? Pick the answer that feels right.

    The answer, explained

    Distributed Denial of Service

    A Distributed Denial of Service attack floods a website or server with traffic from many compromised machines at once, overwhelming it so that legitimate users cannot get through.

    WORTH KNOWING

    Attackers often rent botnets of hijacked devices by the hour, which is why DDoS attacks are frequently used for extortion against online businesses.

    Which 1988 worm, written by a Cornell graduate student, became the first malware to spread widely across the internet?

    Got a hunch? Pick the answer that feels right.

    The answer, explained

    Morris worm

    Robert Tappan Morris released his worm from MIT on 2 November 1988, and a coding error made it reinfect machines repeatedly, crippling an estimated 6,000 of the roughly 60,000 computers then online.

    WORTH KNOWING

    Morris became the first person convicted under the US Computer Fraud and Abuse Act and later co-founded the startup accelerator Y Combinator.

    Which credit reporting agency suffered a 2017 breach that exposed personal data of about 147 million Americans?

    Got a hunch? Pick the answer that feels right.

    The answer, explained

    Equifax

    Attackers got into Equifax through an unpatched Apache Struts flaw on its dispute website and went undetected for 76 days, taking names, Social Security numbers, birth dates and addresses.

    WORTH KNOWING

    Equifax agreed in 2019 to a settlement of at least $575 million with US regulators, including a fund to compensate affected consumers.

    What is a zero-day vulnerability?

    Got a hunch? Pick the answer that feels right.

    The answer, explained

    A flaw the vendor has had no time to patch

    A zero-day is a security hole that attackers discover or exploit before the software maker knows about it, so defenders have had zero days to prepare a fix, which makes such flaws extremely valuable.

    WORTH KNOWING

    Brokers and governments pay large sums for zero-days, and Stuxnet used four of them at once, an unprecedented number at the time.

    Heartbleed, the 2014 bug that let attackers read a server's memory, was a flaw in which widely used encryption library?

    Got a hunch? Pick the answer that feels right.

    The answer, explained

    OpenSSL

    Heartbleed was a missing bounds check in OpenSSL's heartbeat extension that let anyone pull 64 kilobytes of memory per request from a vulnerable server, potentially exposing private keys and passwords.

    WORTH KNOWING

    It was among the first vulnerabilities to get its own name, logo and website, a branding approach researchers have used for major bugs ever since.

    The Mirai botnet that knocked Twitter, Netflix and Reddit offline for hours in October 2016 was built mainly from which kind of hijacked devices?

    Got a hunch? Pick the answer that feels right.

    The answer, explained

    Internet-connected cameras and routers

    Mirai scanned the internet for cameras, routers and digital video recorders still using factory default passwords, enrolled hundreds of thousands of them and aimed their traffic at the DNS provider Dyn.

    WORTH KNOWING

    Its three authors were American college-age students who had originally built the botnet to attack rival Minecraft server hosts.

    Which hacker, arrested by the FBI in 1995 after a years-long manhunt, later became a security consultant and wrote The Art of Deception?

    Got a hunch? Pick the answer that feels right.

    The answer, explained

    Kevin Mitnick

    Kevin Mitnick was caught in Raleigh, North Carolina, in February 1995 after breaking into dozens of corporate networks, spent five years in custody and then reinvented himself as a consultant and speaker.

    WORTH KNOWING

    While awaiting trial he was held in solitary confinement for months, partly because a prosecutor claimed he could start a nuclear war by whistling into a phone.

    The Log4Shell flaw of December 2021, rated the maximum 10 out of 10 for severity, affected a logging library used by programs written in which language?

    Got a hunch? Pick the answer that feels right.

    The answer, explained

    Java

    Log4j is an Apache logging library used across countless Java applications, and Log4Shell let attackers run code remotely simply by getting a specially crafted string logged, such as a chat message in Minecraft.

    WORTH KNOWING

    The bug was first reported privately to Apache by Chen Zhaojun of Alibaba Cloud's security team on 24 November 2021, two weeks before it became public.

    No rush. You've got this. Keys 1 to 4 pick an answer, Enter moves on.

    About the Cybersecurity Quiz

    Cybersecurity is the one tech topic that touches everybody. The WannaCry outbreak of 2017 shut down hospital wards across Britain in a single afternoon, the Equifax breach exposed the details of 147 million Americans, and a worm written by a graduate student in 1988 knocked out a tenth of the early internet.

    These 15 questions mix the basics everyone should know, such as what https, VPN and two-factor authentication actually mean, with the famous incidents security professionals still talk about: Stuxnet, Heartbleed, Mirai, Log4Shell and the manhunt for Kevin Mitnick. Beginners should handle the first half comfortably, and the second half will sort the casual browsers from the people who read breach reports for fun.

    You will find 15 multiple choice questions here, each with four options. Difficulty: Hard. Most people finish in about 6 minutes, and every answer comes with a short explanation and one extra fact worth keeping.

    How to play

    Read the question and pick one of the four answers. The correct answer is revealed straight away with a short explanation, then press Next question to keep going. At the end you get your score out of 15 and a full review of your round. Play again any time and the questions arrive in a fresh order. There is no timer and no account.

    Good to know before you play

    What are the most common types of cyber attack?

    Phishing emails, ransomware, credential stuffing with reused passwords, and distributed denial of service attacks are among the most common. Most breaches begin with a person being tricked rather than software being broken.

    What is the biggest data breach in history?

    By number of records, the Yahoo breaches disclosed in 2016 affected all three billion of its accounts. The 2017 Equifax breach is often considered the most serious because of the sensitive financial data exposed.

    How can I protect myself online?

    Use a password manager with a unique password for every site, turn on two-factor authentication, install software updates promptly and treat unexpected links and attachments with suspicion.

    Share this quiz

    Challenge a friend and compare scores.

    Answer key: all 15 questions with explanations
    1. In a web address beginning with https, what does the final letter s stand for?
      Secure HTTPS stands for Hypertext Transfer Protocol Secure: the connection is encrypted with TLS so that anyone intercepting traffic between your browser and the website cannot read passwords or card numbers. Google Chrome began labelling plain http sites as Not Secure in 2018, a nudge that pushed most of the web to adopt encryption.
    2. What is the term for fraudulent emails or messages that pose as a trusted organisation to trick you into handing over passwords or card details?
      Phishing Phishing attacks imitate banks, delivery firms or colleagues to lure victims onto fake login pages, and they remain the most common starting point for breaches because they exploit people rather than software. Targeted phishing aimed at a specific person is called spear phishing, and when the target is a senior executive it is known as whaling.
    3. Which kind of malware encrypts a victim's files and demands payment, usually in cryptocurrency, to unlock them?
      Ransomware Ransomware scrambles data and displays a ransom note, and modern gangs often also steal copies of the files and threaten to publish them, a tactic known as double extortion. The first known ransomware, the 1989 AIDS Trojan, spread on floppy disks and demanded that $189 be posted to a PO box in Panama.
    4. Logging in with a password plus a one-time code sent to your phone is an example of which security practice?
      Two-factor authentication Two-factor authentication combines something you know, the password, with something you have, such as your phone or a hardware key, so a stolen password alone is not enough to get in. Authenticator apps and passkeys are considered safer than SMS codes, because text messages can be intercepted through SIM swap fraud.
    5. What does VPN stand for?
      Virtual Private Network A Virtual Private Network creates an encrypted tunnel between your device and a remote server, hiding your traffic from the local network and making it appear to come from the server's location. VPNs were originally built so remote employees could reach company networks securely, long before they became a consumer tool for streaming and privacy.
    6. The WannaCry ransomware outbreak of May 2017 famously disrupted hospitals belonging to which organisation?
      NHS WannaCry infected an estimated 70,000 NHS devices across England and Scotland in a single day, forcing hospitals to cancel appointments and divert ambulances, at a cost later put at around £92 million. Researcher Marcus Hutchins stopped the spread by registering an unregistered domain name he found in the code, an accidental kill switch.
    7. The Stuxnet worm, discovered in 2010, was designed to sabotage uranium enrichment centrifuges in which country?
      Iran Stuxnet targeted Siemens industrial controllers at Iran's Natanz facility, secretly speeding centrifuges up and slowing them down until they broke, while feeding normal readings to operators. No government has claimed it, but it is widely reported to have been a joint US and Israeli operation code-named Olympic Games.
    8. In a DDoS attack, what does the acronym DDoS stand for?
      Distributed Denial of Service A Distributed Denial of Service attack floods a website or server with traffic from many compromised machines at once, overwhelming it so that legitimate users cannot get through. Attackers often rent botnets of hijacked devices by the hour, which is why DDoS attacks are frequently used for extortion against online businesses.
    9. Which 1988 worm, written by a Cornell graduate student, became the first malware to spread widely across the internet?
      Morris worm Robert Tappan Morris released his worm from MIT on 2 November 1988, and a coding error made it reinfect machines repeatedly, crippling an estimated 6,000 of the roughly 60,000 computers then online. Morris became the first person convicted under the US Computer Fraud and Abuse Act and later co-founded the startup accelerator Y Combinator.
    10. Which credit reporting agency suffered a 2017 breach that exposed personal data of about 147 million Americans?
      Equifax Attackers got into Equifax through an unpatched Apache Struts flaw on its dispute website and went undetected for 76 days, taking names, Social Security numbers, birth dates and addresses. Equifax agreed in 2019 to a settlement of at least $575 million with US regulators, including a fund to compensate affected consumers.
    11. What is a zero-day vulnerability?
      A flaw the vendor has had no time to patch A zero-day is a security hole that attackers discover or exploit before the software maker knows about it, so defenders have had zero days to prepare a fix, which makes such flaws extremely valuable. Brokers and governments pay large sums for zero-days, and Stuxnet used four of them at once, an unprecedented number at the time.
    12. Heartbleed, the 2014 bug that let attackers read a server's memory, was a flaw in which widely used encryption library?
      OpenSSL Heartbleed was a missing bounds check in OpenSSL's heartbeat extension that let anyone pull 64 kilobytes of memory per request from a vulnerable server, potentially exposing private keys and passwords. It was among the first vulnerabilities to get its own name, logo and website, a branding approach researchers have used for major bugs ever since.
    13. The Mirai botnet that knocked Twitter, Netflix and Reddit offline for hours in October 2016 was built mainly from which kind of hijacked devices?
      Internet-connected cameras and routers Mirai scanned the internet for cameras, routers and digital video recorders still using factory default passwords, enrolled hundreds of thousands of them and aimed their traffic at the DNS provider Dyn. Its three authors were American college-age students who had originally built the botnet to attack rival Minecraft server hosts.
    14. Which hacker, arrested by the FBI in 1995 after a years-long manhunt, later became a security consultant and wrote The Art of Deception?
      Kevin Mitnick Kevin Mitnick was caught in Raleigh, North Carolina, in February 1995 after breaking into dozens of corporate networks, spent five years in custody and then reinvented himself as a consultant and speaker. While awaiting trial he was held in solitary confinement for months, partly because a prosecutor claimed he could start a nuclear war by whistling into a phone.
    15. The Log4Shell flaw of December 2021, rated the maximum 10 out of 10 for severity, affected a logging library used by programs written in which language?
      Java Log4j is an Apache logging library used across countless Java applications, and Log4Shell let attackers run code remotely simply by getting a specially crafted string logged, such as a chat message in Minecraft. The bug was first reported privately to Apache by Chen Zhaojun of Alibaba Cloud's security team on 24 November 2021, two weeks before it became public.

    Browse other categories

    Every category has its own quizzes, each with instant explanations.