CAF-3 · Chapter 15
Emerging Risks & Strategic Challenges MCQs with Answers
15 multiple-choice questions on Emerging Risks & Strategic Challenges for CAF-3 Data, Systems and Risks. Try each one before revealing the answer and explanation.
Practise this chapter interactivelyQuestion 1
A hospital's patient database is suddenly encrypted, locking doctors out of critical medical records. A message appears on the screen demanding $50,000 in Bitcoin to provide the decryption key. This is a classic example of:
- A) Spyware
- B) Ransomware
- C) Trojan Horse
- D) Worm
Show answer & explanation
Answer: B) Ransomware
Ransomware is a specific type of malware that encrypts an organization's files or systems, demanding a financial payment (ransom) in exchange for the decryption key
Question 2
An employee receives an urgent email appearing to be from the company’s IT department, asking them to click a link and confirm their login credentials immediately or risk losing access. The link directs to a fake, lookalike portal. This attack is known as:
- A) Phishing
- B) Distributed Denial of Service (DDoS)
- C) A Trojan Horse
- D) Man-in-the-middle
Show answer & explanation
Answer: A) Phishing
Phishing attacks use deceptive emails or messages that appear to come from legitimate sources to trick individuals into revealing sensitive information, such as login credentials
Question 3
A user downloads a free PDF converter from an untrusted website. The software works as advertised, but it secretly installs a hidden backdoor allowing hackers to access the user's system remotely. Which type of malware is this?
- A) Worm
- B) Adware
- C) Trojan Horse
- D) Ransomware
Show answer & explanation
Answer: C) Trojan Horse
A Trojan Horse is a type of malware disguised as legitimate, harmless software (like a PDF converter). Once installed, it executes a malicious payload in the background
Question 4
Statistical data shows that human error and manipulation are among the biggest causes of security breaches. Which strategy is most effective in mitigating this specific risk?
- A) Distributing admin passwords to all team members for operational efficiency
- B) Relying entirely on physical hardware firewalls
- C) Implementing ongoing staff education combined with simulated phishing exercises
- D) Avoiding the use of cloud computing entirely
Show answer & explanation
Answer: C) Implementing ongoing staff education combined with simulated phishing exercises
Because human error is a major vulnerability, the most effective defense against social engineering (like phishing) is continuous staff education and running simulated attack exercises. --------------------------------------------------------------------------------
Question 5
When a customer enters their credit card details on an e-commerce website, the URL shows "https://" and a padlock symbol. What does this indicate?
- A) The data is stored permanently on a public blockchain.
- B) The communication is encrypted using SSL/TLS, protecting it against man-in-the-middle attacks.
- C) The website is completely immune to DDoS attacks.
- D) The data is processed using Edge Computing to reduce latency.
Show answer & explanation
Answer: B) The communication is encrypted using SSL/TLS, protecting it against man-in-the-middle attacks.
HTTPS uses SSL/TLS to encrypt all communication between the user's browser and the server, ensuring that data (like credit card numbers) cannot be intercepted in plain text
Question 6
An organization deploys a specialized security tool that continuously analyzes network traffic patterns to flag potential security breaches and anomalous behavior, immediately sending alerts to the IT team. This tool is known as an:
- A) Antivirus scanner
- B) Intrusion Detection System (IDS)
- C) Uninterruptible Power Supply (UPS)
- D) Virtual Private Network (VPN)
Show answer & explanation
Answer: B) Intrusion Detection System (IDS)
An Intrusion Detection System (IDS) specifically monitors network traffic for anomalous behavior and flags potential breaches to security personnel
Question 7
What is the primary purpose of implementing an automated "Patch Management" system in an organization's cybersecurity strategy?
- A) To automatically pay ransomware demands
- B) To ensure that critical software updates are downloaded and installed swiftly across all devices to protect against newly discovered vulnerabilities
- C) To automatically filter out spam emails
- D) To create physical backups of server hardware
Show answer & explanation
Answer: B) To ensure that critical software updates are downloaded and installed swiftly across all devices to protect against newly discovered vulnerabilities
Patch management ensures that software vulnerabilities are fixed promptly by deploying updates. Automating this process ensures systems are protected against the latest known threats without delay
Question 8
An employee working remotely from a coffee shop uses a public Wi-Fi network to access the company's highly sensitive internal ERP system. To prevent hackers on the same network from intercepting this communication, the employee must use:
- A) A Virtual Private Network (VPN)
- B) A public blockchain ledger
- C) An Intrusion Detection System (IDS)
- D) A relational database
Show answer & explanation
Answer: A) A Virtual Private Network (VPN)
A Virtual Private Network (VPN) creates a secure, encrypted tunnel between the user's device and the corporate network, protecting data from interception on unsecured public networks. --------------------------------------------------------------------------------
Question 9
During a cyberattack, the IT team immediately disconnects the affected servers from the main network to prevent the malware from spreading to other departments. Which phase of the Incident Response capability does this represent?
- A) Post-Incident Analysis
- B) Recovery and Isolation
- C) Vulnerability Scanning
- D) Vendor Lock-in
Show answer & explanation
Answer: B) Recovery and Isolation
Recovery and isolation involve disconnecting or isolating affected systems to contain the threat and prevent malware from spreading, allowing operations to continue safely
Question 10
After successfully recovering from a data breach, the security team holds a meeting to identify weaknesses in their defenses and updates their security policies so the same attack cannot happen again. This crucial step is known as:
- A) Post-Incident Analysis
- B) Disaster Recovery Planning
- C) Data Extraction
- D) Penetration Testing
Show answer & explanation
Answer: A) Post-Incident Analysis
Post-Incident Analysis involves reviewing what went wrong during an attack to identify weaknesses, learn lessons, and improve future incident response plans and defenses
Question 11
Which globally recognized framework is designed to provide structured guidance for organizations to systematically address, manage, and mitigate cybersecurity risks?
- A) SOX (Sarbanes-Oxley Act)
- B) NIST Cybersecurity Framework
- C) IFRS 9
- D) GDPR
Show answer & explanation
Answer: B) NIST Cybersecurity Framework
The NIST Cybersecurity Framework provides a structured, internationally recognized approach for organizations to systematically manage and mitigate cybersecurity risks
Question 12
In the context of Pakistani law, which legislative act provides the primary legal framework to investigate, prosecute, and penalize cybercrimes?
- A) The Electronic Transaction Ordinance, 2002
- A) , 2016
- A) , 2016, provides the legal cover and framework in Pakistan to investigate and penalize cybercrimes. --------------------------------------------------------------------------------
- B) The Sarbanes-Oxley Act
- C) Prevention of Electronic Crimes Act (PEC
- D) Cyber Security Policy of Pakistan
Show answer & explanation
Answer: C) Prevention of Electronic Crimes Act (PEC
The Prevention of Electronic Crimes Act (PEC
Question 13
A manufacturing plant installs thousands of smart sensors on its assembly line equipment to monitor health and efficiency. While productivity improves, the IT team is concerned because each new sensor represents a potential entry point for hackers. This scenario highlights the cybersecurity risks associated with:
- A) Quantum Computing
- B) Internet of Things (IoT)
- C) Public Blockchains
- D) Data Normalization
Show answer & explanation
Answer: B) Internet of Things (IoT)
The widespread deployment of IoT devices expands an organization's "attack surface," introducing numerous new vulnerabilities and entry points that hackers can exploit
Question 14
A successful cyberattack on a financial institution leads to the theft of customer funds, resulting in a massive fine from the central bank and a severe loss of customer trust. These consequences represent:
- A) Financial Loss, Regulatory Penalties, and Reputational Damage
- B) Reputational Damage only
- C) Operational Disruption only
- D) Physical entity failure
Show answer & explanation
Answer: A) Financial Loss, Regulatory Penalties, and Reputational Damage
A successful cyberattack has multifaceted impacts, including direct financial loss (theft), regulatory penalties (fines for non-compliance), and reputational damage (loss of customer trust)
Question 15
According to industry studies, organizations globally are facing a heightened risk of breaches, data loss, and operational disruptions primarily due to a massive shortage of:
- A) Physical hardware servers
- B) Skilled cybersecurity professionals
- C) Cloud storage capacity
- D) Open-source software availability
Show answer & explanation
Answer: B) Skilled cybersecurity professionals
There is a critical global talent gap in the cybersecurity field. The demand for skilled cybersecurity professionals far outpaces the supply, leaving many organizations vulnerable to attacks
