Page 1 of 127
NOCTI Cybersecurity Fundamentals exam question
bank exam QUESTIONS AND CORRECT DETAILED
SOLUTIONS WITH RATIONALES LATEST THIS YEAR
(2026-2027)
A COMPREHENSIVE NOCTI CYBERSECURITY FUNDAMENTALS EXAM QUESTION BANK OF 250
RANDOMIZED, SCENARIO-BASED MULTIPLE-CHOICE QUESTIONS WITH ITALICIZED
RATIONALES. NO SUBTOPICS OR DOMAIN LABELS ARE USED, AND EVERY QUESTION IS EXAM-
RELEVANT TO THE OFFICIAL NOCTI ASSESSMENT .
1. A user receives an email claiming to be from their bank, stating their account has been
locked. The email contains a link to a fake website that looks identical to the bank's real site.
What type of attack is this?
A) Vishing
B) Whaling
C) Phishing
D) Smishing
Answer: C
, Page 2 of 127
Phishing uses deceptive emails to trick users into revealing credentials or clicking malicious links.
Vishing is voice-based, smishing uses SMS, and whaling targets executives .
2. Which type of malware self-replicates across a network without requiring any user
interaction?
A) Trojan Horse
B) Ransomware
C) Worm
D) Rootkit
Answer: C
Worms are distinct because they spread autonomously using network vulnerabilities, without
needing a host program or user action .
3. Which of the following allows a user to access a computer system using credentials such as a
password?
A) Identification
B) Authentication
C) Authorization
D) Accounting
, Page 3 of 127
Answer: B
Authentication verifies a user's identity using credentials (something you know, have, or are).
Identification is claiming identity, authorization grants permissions .
4. Facial recognition is an example of what type of biometric technology?
A) Cognitive
B) Physical
C) Behavioral
D) Identification
Answer: B
Physical biometrics measure physiological characteristics (face, fingerprint, iris). Behavioral
biometrics measure patterns like typing rhythm or gait .
5. An attacker intercepts communication between a client and a server, altering data packets
before they reach their destination. Both parties believe they are communicating directly. What
is this attack called?
A) Replay attack
B) Man-in-the-Middle (MitM)
C) Denial of Service (DoS)
, Page 4 of 127
D) Side-channel attack
Answer: B
In MitM attacks, the attacker secretly relays and potentially alters communications between two
parties who believe they are talking directly to each other .
6. What is the primary goal of a Denial of Service (DoS) attack?
A) To steal confidential data
B) To gain administrative privileges
C) To disrupt the availability of a service
D) To install backdoor software
Answer: C
DoS attacks target the "Availability" pillar of the CIA triad by overwhelming resources so
legitimate users cannot access the service .
7. Which procedure converts plain text into secret symbols or ciphertext?
A) De-encryption
B) Hashing
C) De-hashing
D) Encryption
NOCTI Cybersecurity Fundamentals exam question
bank exam QUESTIONS AND CORRECT DETAILED
SOLUTIONS WITH RATIONALES LATEST THIS YEAR
(2026-2027)
A COMPREHENSIVE NOCTI CYBERSECURITY FUNDAMENTALS EXAM QUESTION BANK OF 250
RANDOMIZED, SCENARIO-BASED MULTIPLE-CHOICE QUESTIONS WITH ITALICIZED
RATIONALES. NO SUBTOPICS OR DOMAIN LABELS ARE USED, AND EVERY QUESTION IS EXAM-
RELEVANT TO THE OFFICIAL NOCTI ASSESSMENT .
1. A user receives an email claiming to be from their bank, stating their account has been
locked. The email contains a link to a fake website that looks identical to the bank's real site.
What type of attack is this?
A) Vishing
B) Whaling
C) Phishing
D) Smishing
Answer: C
, Page 2 of 127
Phishing uses deceptive emails to trick users into revealing credentials or clicking malicious links.
Vishing is voice-based, smishing uses SMS, and whaling targets executives .
2. Which type of malware self-replicates across a network without requiring any user
interaction?
A) Trojan Horse
B) Ransomware
C) Worm
D) Rootkit
Answer: C
Worms are distinct because they spread autonomously using network vulnerabilities, without
needing a host program or user action .
3. Which of the following allows a user to access a computer system using credentials such as a
password?
A) Identification
B) Authentication
C) Authorization
D) Accounting
, Page 3 of 127
Answer: B
Authentication verifies a user's identity using credentials (something you know, have, or are).
Identification is claiming identity, authorization grants permissions .
4. Facial recognition is an example of what type of biometric technology?
A) Cognitive
B) Physical
C) Behavioral
D) Identification
Answer: B
Physical biometrics measure physiological characteristics (face, fingerprint, iris). Behavioral
biometrics measure patterns like typing rhythm or gait .
5. An attacker intercepts communication between a client and a server, altering data packets
before they reach their destination. Both parties believe they are communicating directly. What
is this attack called?
A) Replay attack
B) Man-in-the-Middle (MitM)
C) Denial of Service (DoS)
, Page 4 of 127
D) Side-channel attack
Answer: B
In MitM attacks, the attacker secretly relays and potentially alters communications between two
parties who believe they are talking directly to each other .
6. What is the primary goal of a Denial of Service (DoS) attack?
A) To steal confidential data
B) To gain administrative privileges
C) To disrupt the availability of a service
D) To install backdoor software
Answer: C
DoS attacks target the "Availability" pillar of the CIA triad by overwhelming resources so
legitimate users cannot access the service .
7. Which procedure converts plain text into secret symbols or ciphertext?
A) De-encryption
B) Hashing
C) De-hashing
D) Encryption