WorksheetsApplication/Service Attacks
Total questions: 18
Worksheet time: 9mins
DoS
An attack on a computer or network
device in which multiple computers send data and requests to the device in an attempt
to overwhelm it so that it cannot perform normal operations
An attack using active interception or eavesdropping. It uses a third computer to capture traffic sent between two other systems
An attack from a single source that attempts to disrupt the services provided by the attacked system
An attack that changes the registration of a domain name without permission from the owner
DDoS
An attack from a single source that attempts to disrupt the services provided by the attacked system
An attack that increases the amount of bandwidth sent to a victim
DNS Poisoning-An attack that modifies or corrupts DNS result
The process of gaining elevate rights and permissions. Malware typically uses a variety of techniques to gain elevated privileges
An attack on a computer or network
device in which multiple computers send data and requests to the device in an attempt
to overwhelm it so that it cannot perform normal operations
Man-in-the-middle
An attack using active interception or eavesdropping. It uses a third computer to capture traffic sent between two other systems
An attack that misleads systems about the actual MAC address of a system
A vulnerability or bug that is unknown to trusted sources but can be exploited by attackers
An attack that changes the registration of a domain name without permission from the owner
Buffer overflow
An attack that tricks users into clicking something other than what they think they're clicking
An error that occurs when an application receives more input, or different input, than it expects. It exposes system memory that is normally inaccessible
An attack where the data is captured and replayed. Attackers typically modify data before replaying it
An attack that injects code or commands
Injection
A driver manipulation method. Developers rewrite the code without changing the driver's behavior
The process of gaining elevate rights and permissions. Malware typically uses a variety of techniques to gain elevated privileges
The purchase of a domain name that is close to a legitimate domain name. Attackers often try to trick users who inadvertently use the wrong domain name. Also called typosquatting
An attack that injects code or commands
Cross-Site Scripting (XSS)
A web application attack. XSRF attacks trick users into performing actions on websites, such as making purchases, without their knowledge
A password attack that captures and uses the hash of a password. It attempts to log on as the hash and is commonly associated with the Microsoft NTLM protocol
A web application vulnerability. Attackers embed malicious HTML or JavaScript code into a web site's code, which executes when a user visits the site
An attack from a single source that attempts to disrupt the services provided by the attacked system
Cross-Site Request Forgery
A web application vulnerability. Attackers embed malicious HTML or JavaScript code into a web site's code, which executes when a user visits the site
An attack that changes the source IP address
A web application attack. XSRF attacks trick users into performing actions on websites, such as making purchases, without their knowledge
An attack where the data is captured and replayed. Attackers typically modify data before replaying it
Privilege escalation
The process of gaining elevate rights and permissions. Malware typically uses a variety of techniques to gain elevated privileges
An attack using active interception or eavesdropping. It uses a third computer to capture traffic sent between two other systems
An attack that changes the source MAC address
An attack that infects vulnerable web browsers. It can allow the attacker to capture browser session data, including keystrokes
ARP Poisoning
The process of gaining elevate rights and permissions. Malware typically uses a variety of techniques to gain elevated privileges
An attack that injects code or commands
An attack on a computer or network
device in which multiple computers send data and requests to the device in an attempt
to overwhelm it so that it cannot perform normal operations
An attack that misleads systems about the actual MAC address of a system
Amplification
An attack where the data is captured and replayed. Attackers typically modify data before replaying it
A driver manipulation method. It uses additional code to modify the behavior of a driver
An attack that increases the amount of bandwidth sent to a victim
DNS Poisoning-An attack that modifies or corrupts DNS result
The purchase of a domain name that is close to a legitimate domain name. Attackers often try to trick users who inadvertently use the wrong domain name. Also called typosquatting
Domain Hijacking
An attack that changes the registration of a domain name without permission from the owner
An attack that infects vulnerable web browsers. It can allow the attacker to capture browser session data, including keystrokes
A vulnerability or bug that is unknown to trusted sources but can be exploited by attackers
A driver manipulation method. Developers rewrite the code without changing the driver's behavior
Man-in-the-browser
A vulnerability or bug that is unknown to trusted sources but can be exploited by attackers
An attack using active interception or eavesdropping. It uses a third computer to capture traffic sent between two other systems
An attack that infects vulnerable web browsers. It can allow the attacker to capture browser session data, including keystrokes
An attack from a single source that attempts to disrupt the services provided by the attacked system
Zero Day Exploit
An attack that attempts to impersonate a user by capturing and using a session ID. Session IDs are stored in cookies
An attack that infects vulnerable web browsers. It can allow the attacker to capture browser session data, including keystrokes
An attack that injects code or commands
A vulnerability or bug that is unknown to trusted sources but can be exploited by attackers
Replay
An attack where the data is captured and replayed. Attackers typically modify data before replaying it
An attack using active interception or eavesdropping. It uses a third computer to capture traffic sent between two other systems
An attack that attempts to impersonate a user by capturing and using a session ID. Session IDs are stored in cookies
A web application attack. XSRF attacks trick users into performing actions on websites, such as making purchases, without their knowledge
Pass the Hash
Replaying information already captured, such as security certificate
The process of gaining elevate rights and permissions. Malware typically uses a variety of techniques to gain elevated privileges
A password attack that captures and uses the hash of a password. It attempts to log on as the hash and is commonly associated with the Microsoft NTLM protocol
An attack from a single source that attempts to disrupt the services provided by the attacked system
An attack that tricks users into clicking something other than what they think they're clicking
Click Hijacking
Clickbait
Clickjacking
Klickk
An attack that attempts to impersonate a user by capturing and using a session ID. Session IDs are stored in cookies
URL hijacking
Clickjacking
ID Hijack Attack (IDHA)
Session hijacking
The FitnessGram Pacer Test is a multistage aerobic capacity test that progressively gets more difficult as it continues. The 20 meter pacer test will begin in 30 seconds. The running speed starts slowly, but gets faster each minute after you hear this signal. [beep] A single lap should be completed each time you hear this sound:
[ding]
[beep]
[bang]
[confused screaming]
