Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Application/Service Attacks

Total questions: 18

Worksheet time: 9mins

Name
Class
Date
1.

DoS

a)

An attack on a computer or network

device in which multiple computers send data and requests to the device in an attempt

to overwhelm it so that it cannot perform normal operations

b)

An attack using active interception or eavesdropping. It uses a third computer to capture traffic sent between two other systems

c)

An attack from a single source that attempts to disrupt the services provided by the attacked system

d)

An attack that changes the registration of a domain name without permission from the owner

2.

DDoS

a)

An attack from a single source that attempts to disrupt the services provided by the attacked system

b)

An attack that increases the amount of bandwidth sent to a victim

DNS Poisoning-An attack that modifies or corrupts DNS result

c)

The process of gaining elevate rights and permissions. Malware typically uses a variety of techniques to gain elevated privileges

d)

An attack on a computer or network

device in which multiple computers send data and requests to the device in an attempt

to overwhelm it so that it cannot perform normal operations

3.

Man-in-the-middle

a)

An attack using active interception or eavesdropping. It uses a third computer to capture traffic sent between two other systems

b)

An attack that misleads systems about the actual MAC address of a system

c)

A vulnerability or bug that is unknown to trusted sources but can be exploited by attackers

d)

An attack that changes the registration of a domain name without permission from the owner

4.

Buffer overflow

a)

An attack that tricks users into clicking something other than what they think they're clicking

b)

An error that occurs when an application receives more input, or different input, than it expects. It exposes system memory that is normally inaccessible

c)

An attack where the data is captured and replayed. Attackers typically modify data before replaying it

d)

An attack that injects code or commands

5.

Injection

a)

A driver manipulation method. Developers rewrite the code without changing the driver's behavior

b)

The process of gaining elevate rights and permissions. Malware typically uses a variety of techniques to gain elevated privileges

c)

The purchase of a domain name that is close to a legitimate domain name. Attackers often try to trick users who inadvertently use the wrong domain name. Also called typosquatting

d)

An attack that injects code or commands

6.

Cross-Site Scripting (XSS)

a)

A web application attack. XSRF attacks trick users into performing actions on websites, such as making purchases, without their knowledge

b)

A password attack that captures and uses the hash of a password. It attempts to log on as the hash and is commonly associated with the Microsoft NTLM protocol

c)

A web application vulnerability. Attackers embed malicious HTML or JavaScript code into a web site's code, which executes when a user visits the site

d)

An attack from a single source that attempts to disrupt the services provided by the attacked system

7.

Cross-Site Request Forgery

a)

A web application vulnerability. Attackers embed malicious HTML or JavaScript code into a web site's code, which executes when a user visits the site

b)

An attack that changes the source IP address

c)

A web application attack. XSRF attacks trick users into performing actions on websites, such as making purchases, without their knowledge

d)

An attack where the data is captured and replayed. Attackers typically modify data before replaying it

8.

Privilege escalation

a)

The process of gaining elevate rights and permissions. Malware typically uses a variety of techniques to gain elevated privileges

b)

An attack using active interception or eavesdropping. It uses a third computer to capture traffic sent between two other systems

c)

An attack that changes the source MAC address

d)

An attack that infects vulnerable web browsers. It can allow the attacker to capture browser session data, including keystrokes

9.

ARP Poisoning

a)

The process of gaining elevate rights and permissions. Malware typically uses a variety of techniques to gain elevated privileges

b)

An attack that injects code or commands

c)

An attack on a computer or network

device in which multiple computers send data and requests to the device in an attempt

to overwhelm it so that it cannot perform normal operations

d)

An attack that misleads systems about the actual MAC address of a system

10.

Amplification

a)

An attack where the data is captured and replayed. Attackers typically modify data before replaying it

b)

A driver manipulation method. It uses additional code to modify the behavior of a driver

c)

An attack that increases the amount of bandwidth sent to a victim

DNS Poisoning-An attack that modifies or corrupts DNS result

d)

The purchase of a domain name that is close to a legitimate domain name. Attackers often try to trick users who inadvertently use the wrong domain name. Also called typosquatting

11.

Domain Hijacking

a)

An attack that changes the registration of a domain name without permission from the owner

b)

An attack that infects vulnerable web browsers. It can allow the attacker to capture browser session data, including keystrokes

c)

A vulnerability or bug that is unknown to trusted sources but can be exploited by attackers

d)

A driver manipulation method. Developers rewrite the code without changing the driver's behavior

12.

Man-in-the-browser

a)

A vulnerability or bug that is unknown to trusted sources but can be exploited by attackers

b)

An attack using active interception or eavesdropping. It uses a third computer to capture traffic sent between two other systems

c)

An attack that infects vulnerable web browsers. It can allow the attacker to capture browser session data, including keystrokes

d)

An attack from a single source that attempts to disrupt the services provided by the attacked system

13.

Zero Day Exploit

a)

An attack that attempts to impersonate a user by capturing and using a session ID. Session IDs are stored in cookies

b)

An attack that infects vulnerable web browsers. It can allow the attacker to capture browser session data, including keystrokes

c)

An attack that injects code or commands

d)

A vulnerability or bug that is unknown to trusted sources but can be exploited by attackers

14.

Replay

a)

An attack where the data is captured and replayed. Attackers typically modify data before replaying it

b)

An attack using active interception or eavesdropping. It uses a third computer to capture traffic sent between two other systems

c)

An attack that attempts to impersonate a user by capturing and using a session ID. Session IDs are stored in cookies

d)

A web application attack. XSRF attacks trick users into performing actions on websites, such as making purchases, without their knowledge

15.

Pass the Hash

a)

Replaying information already captured, such as security certificate

b)

The process of gaining elevate rights and permissions. Malware typically uses a variety of techniques to gain elevated privileges

c)

A password attack that captures and uses the hash of a password. It attempts to log on as the hash and is commonly associated with the Microsoft NTLM protocol

d)

An attack from a single source that attempts to disrupt the services provided by the attacked system

16.

An attack that tricks users into clicking something other than what they think they're clicking

a)

Click Hijacking

b)

Clickbait

c)

Clickjacking

d)

Klickk

17.

An attack that attempts to impersonate a user by capturing and using a session ID. Session IDs are stored in cookies

a)

URL hijacking

b)

Clickjacking

c)

ID Hijack Attack (IDHA)

d)

Session hijacking

18.

The FitnessGram Pacer Test is a multistage aerobic capacity test that progressively gets more difficult as it continues. The 20 meter pacer test will begin in 30 seconds. The running speed starts slowly, but gets faster each minute after you hear this signal. [beep] A single lap should be completed each time you hear this sound:

a)

[ding]

b)

[beep]

c)

[bang]

d)

[confused screaming]