60 free cybersecurity trivia questions with answers. Sixty cybersecurity trivia questions, written for security-awareness sessions, IT team socials and anyone who enjoys the history of hacking. The opening stretch covers the vocabulary every employee is supposed to know: phishing, ransomware, the CIA triad, zero-days, honeypots, multi-factor authentication, air gaps and zero trust. Then it moves through the incidents that made the news, from Creeper and the Morris worm to ILOVEYOU, Stuxnet, WannaCry, Heartbleed, Equifax, SolarWinds, Colonial Pipeline and Log4Shell. The back half is for the people who read the post-mortems: Rejewski and Enigma, Colossus, the first password on CTSS, who really invented RSA, Captain Crunch's whistle, the Selectric bug, DEF CON, Have I Been Pwned, and the films and shows that taught the public what a hacker looks like. Difficulty runs from easy definitions to a few questions only a veteran will get, so mixed groups all have something to play for. Every answer was checked against Wikipedia's articles on the incidents, people and technologies involved, and the sentence that establishes it is shown under each explanation.
30 of 60 questions with answers and explanations. Play the quiz
Q 01What is the fraud of sending messages posing as a trusted sender to trick people into revealing passwords called?
Phishing
The spelling nods to 'phreaking', the older hobby of hacking phone systems; the word first appeared in a 1995 AOL cracking toolkit.
Q 02Malware that encrypts a victim's files and demands payment for the key is called what?
Ransomware
The first documented example, the 1989 AIDS Trojan, was so badly designed that victims never actually needed to pay.
Q 03The 'CIA triad' at the heart of information security stands for confidentiality, integrity and what?
Availability
It has nothing to do with the US intelligence agency; the third leg means legitimate users can actually get at their data.
Q 04A vulnerability that is exploited before the software vendor knows it exists is called what?
Zero-day
The name counts the days the vendor has had to fix it, which at the moment of discovery is none.
Q 05A decoy system set up to attract and study attackers is known as what?
Honeypot
Anything that touches it is suspicious by definition, since no legitimate user has a reason to be there.
Q 06Multi-factor authentication requires how many distinct types of evidence before granting access?
Two or more
The classic factors are something you know, something you have and something you are, and a physical key to a lock counts as a possession factor centuries old.
Q 07Malware that disguises itself as a normal program to mislead users is named after what?
A wooden horse from Greek myth
The story of the hollow gift that let soldiers into Troy fit so well that the name has stuck for decades.
Q 08Manipulating people psychologically into divulging information or taking unsafe actions is called what?
Social engineering
Sub-genres include pretexting (an invented scenario), baiting (a tempting USB stick) and tailgating through a secure door.
Q 09Which term borrowed from building construction describes a system that filters traffic between networks?
Firewall
The original meaning was a wall that confines a fire within a row of buildings; it jumped to networking in the 1980s.
Q 10A computer that is physically isolated from the internet and other unsecured networks is said to be what?
Air-gapped
Data still has to move by hand on removable media, and an infected USB stick is exactly how Stuxnet crossed the gap.
Q 11An analyst at which research firm named the 'never trust, always verify' model 'Zero Trust' in 2010?
Forrester
John Kindervag's idea gained ground as cloud and mobile use dissolved the old network perimeter.
Q 12What is generally considered the first computer worm, a 1971 program on ARPANET?
Creeper
It printed 'I'M THE CREEPER: CATCH ME IF YOU CAN', and a program called Reaper was written to hunt it down, making Reaper the first antivirus.
Q 13The Morris worm of 2 November 1988 was written by a graduate student at which university?
Cornell
His father was an NSA cryptographer, and the case produced the first felony conviction under the 1986 Computer Fraud and Abuse Act.
Q 21The May 2017 WannaCry attack spread using EternalBlue, an exploit originally developed by which agency?
NSA
The Shadow Brokers leaked it a month before the attack, and Britain and the US later blamed North Korea for WannaCry itself.
Q 22WannaCry was halted within hours when researcher Marcus Hutchins did what?
Registered a domain name that acted as a kill switch
The malware checked whether an unregistered web address existed before running; once he bought it, new infections stopped.
Q 23Heartbleed, disclosed in April 2014, was a bug in which widely used cryptography library?
OpenSSL
Q 14What sentence did Robert Tappan Morris receive for releasing the 1988 internet worm?
Three years' probation and a fine
He also got 400 hours of community service, and the court of appeals put the clean-up cost per site at anywhere from $200 to $53,000.
Q 15The ILOVEYOU worm of May 2000 was written by a college dropout from which country?
Philippines
Prosecutors dropped all charges against Onel de Guzman because the country had no law against hacking at the time.
Q 16Which 1999 virus spread via infected Word documents emailed to a victim's first 50 contacts?
Melissa
David L. Smith released it on 26 March 1999; the infected attachment was innocuously named list.doc.
Q 17Elk Cloner, an early 'in the wild' virus written by a 15-year-old around 1982, targeted which computer?
Apple II
Rich Skrenta hid it on a game disk as a joke; every 50th boot it displayed a short poem.
Q 18Brain, considered the first virus for the IBM PC, was written in 1986 by two brothers in which city?
Lahore
The Alvi brothers embedded their names, address and phone numbers in the code, and were reportedly swamped with calls.
Q 19Stuxnet, uncovered in 2010, is believed to have destroyed nuclear centrifuges at which Iranian facility?
Natanz
It targeted Siemens programmable logic controllers and reportedly wrecked almost a fifth of Iran's centrifuges by spinning them apart.
Q 20The joint US-Israeli effort that reportedly built Stuxnet is known by what code name?
Operation Olympic Games
Neither government has ever officially admitted responsibility.
A missing bounds check in the TLS heartbeat extension gave the bug its name, and it came with its own logo.
Q 24The 2017 Equifax breach exposed private records of roughly how many Americans?
About 148 million
An unpatched Apache Struts flaw let attackers in, and the US later indicted members of China's People's Liberation Army.
Q 25The 2020 supply-chain attack on US government agencies came through which SolarWinds product?
Orion
Fewer than 18,000 of 33,000 customers installed the tainted update, and the SVR-linked group Cozy Bear was blamed.
Q 26Which group was identified by the FBI as responsible for the May 2021 Colonial Pipeline extortion attack?
DarkSide
The company paid 75 bitcoin, about $4.4 million, within hours; panic buying then emptied filling stations across the Southeast.
Q 27The 2013 Yahoo breach, not disclosed until 2016, affected how many user accounts?
All 3 billion
A separate 2014 intrusion hit another 500 million, and the disclosures knocked hundreds of millions off Verizon's purchase price.
Q 28The 'Guardians of Peace' hackers leaked Sony Pictures data in 2014 demanding it pull which film?
The Interview
The comedy starred Seth Rogen and James Franco as journalists recruited to assassinate Kim Jong Un.
Q 29Log4Shell, the critical December 2021 flaw, hit Log4j, a logging library for which language?
Java
It had gone unnoticed since 2013 and was first reported by a researcher at Alibaba Cloud; the name came from the LunaSec team.
Q 30NSO Group, developer of the Pegasus phone spyware, is based in which country?
Israel
Every foreign sale needs approval from the Israeli defence ministry, yet governments have used it against journalists and activists.