🔐

Cybersecurity & Cryptography MCQ

Test your Cybersecurity & Cryptography knowledge with 100 multiple choice questions covering fundamentals to advanced concepts, with instant feedback and explanations.

100 Questions 40 Beginner 40 Intermediate 20 Advanced
1

What is AES and why is it the standard symmetric cipher?

2

What is the difference between TLS 1.2 and TLS 1.3?

3

What is forward secrecy (Perfect Forward Secrecy)?

4

What is RSA encryption and what are its limitations?

5

What is elliptic curve cryptography (ECC)?

6

What is Diffie-Hellman key exchange?

7

What is a rainbow table attack?

8

What is the purpose of HMAC?

9

What is a certificate authority (CA)?

10

What is certificate revocation and why is it important?

11

What is the OAuth 2.0 authorization framework?

12

What is OpenID Connect?

13

What is a JSON Web Token (JWT)?

14

What is SAML (Security Assertion Markup Language)?

15

What is a WAF (Web Application Firewall)?

16

What is defense in depth?

17

What is the difference between a vulnerability, exploit, and payload?

18

What is privilege escalation?

19

What is a supply chain attack?

20

What is SSRF (Server-Side Request Forgery)?

21

What is path traversal?

22

What is cryptographic agility?

23

What is FIDO2/WebAuthn?

24

What is memory safety and how do it relate to security vulnerabilities?

25

What is the difference between a pentest and a red team engagement?

26

What is SIEM (Security Information and Event Management)?

27

What is the purpose of a nonce in cryptographic protocols?

28

What is the difference between block ciphers and stream ciphers?

29

What is a man-in-the-browser (MitB) attack?

30

What is DNS spoofing (cache poisoning)?

31

What is the purpose of Subresource Integrity (SRI) in web security?

32

What is the purpose of a Content Security Policy (CSP) header?

33

What is credential stuffing and how does it differ from brute forcing?

34

What is the role of a key derivation function (KDF) such as PBKDF2 or Argon2?

35

What is typosquatting in the context of cybersecurity?

36

What is the purpose of network address translation (NAT) from a security perspective?

37

What is the purpose of code signing?

38

What is the difference between vertical and horizontal scaling of security monitoring, in the context of a Security Operations Center (SOC) maturity model?

39

What is an evil twin attack in wireless network security?

40

What is the purpose of DNSSEC (Domain Name System Security Extensions)?