WorksheetsBlock 4 Unit 1 Part 5 Review
Total questions: 27
Worksheet time: 14mins
Why might a network have substandard security?
The administrator doesn't have any experience and is trying to mimic his home network.
The security guards are asleep
The network interface card is bad
The router is not configured with 802.1X security
Why would a network be hacked?
Because the network contains information in the form of data that is valuable to the attacker
Because Summers really likes hacking the government
Because networks have a giant "Hack me" .txt file written on them.
Because of some reason
What is a common vulnerability with Wireless networks that results from extended broadcast ranges?
No physical boundaries
Overlooking physical security
Man-in-the-middle attacks
Leaving end-user devices vulnerable
What is overlooking physical security?
Not employing physical security such as guards or mantraps.
Not allowing an attacker in because he is an unwelcome guest
Putting a router in your network where it doesn't belong
Not adding security measures such as encryption in a network
What is Leaving end-user devices vulnerable?
Watching Clarke in his natural habitat, studying.
Allowing virus's to have a pathway into your network through end user devices
Meyers is watching
Connecting users through remote connections to the desktop
What occurs during a Man-in-the-middle attack?
An attacker is able to intercept and view then forward data packets
An attacker is able to destroy files from inside the company
An attacker gains access to the network through the TCP port 3389 RDP
Nothing happens
What are the five distinct classes of network attacks?
Passive
Active
Close-in
Insider
Distribution
What are passive attacks?
Traffic analysis of unprotected or weakly encrypted traffic.
A third party service enabling an attack to happen through reduced security measures
An attempt to break into the network
An insider passively takes information from the company and distributes it to attackers
What is an active attack?
An attempt to break into a protected network or break protection measures.
Includes traffic analysis
Attacker sits in broadcast range to pick up wireless transmissions
Malicious modification of hardware at a factory before distribution.
What is a close-in type of attack
An attacker sits in the range of a wireless network to gain access or information through data emissions
An attempt to break into a network
An attempt to break a security measure
Traffic analysis
What is an insider attack?
When an employee of a company or insider attacks or gains unauthorized access to information or systems
Modification of hardware inside a company before it is released
Malfunction in internal security systems
Traffic analysis
What is a distribution type of attack?
Malicious modification of hardware before it is distributed
Traffic analysis
sitting in close proximity to an access point
Attempting to break into a network
What is the process called that is used to defend against different types of attacks set by IATF?
Defense in Depth
Department of Defense
Defense in Security
Secure Instruction
What is a class of viral software that affects the boot programs run at startup?
Boot sector virus
Macro virus
File-infector virus
Worms
What is a virus that can be executed at any time by the user and is a set of user-generated list of computer instruction.
Macro virus
Boot sector virus
File-infector virus
Worms
What is a file-infector virus? (Pick 2)
Attach themselves to executable files.
Copy themselves into memory when the host file is run
Affects the operating system
Run without the need for a file
What is a worm?
A type of virus that doesn't need a host file
A type of virus that infects only folders
A type of virus that effects boot programs
A type of virus that must be brought into the network by a user
What is a type of malware that disguises itself as a program that hides some other malicious intent?
Trojan horse
Worm
Boot sector virus
Macro virus
What is the purpose of anti-virus?
to harden a security system
for looks
to take up space on you rcomputer
to make sure the ghosts stay away at night (Like Vasallo)
What types of firewalls are there?
Software based
Hardware based
WEP Based
WPA based
Why would you disable unnecessary services?
Because they just keep back doors open on your system
Because there is no point to having them on
Because jackson sucks eggs
Because otherwise it will encrypt the information
What is the newest type of encryption standard?
WEP
WPA
WPA2
WEP2
What is a password policy?
Creating a password
Encrypts the information
Prevents against brute force attacks
Makes a list of all user passwords
this type of hardening prevents brute force attacks.
Password policy
Account lockout policy
Encryption
Disabling Unused accounts
What is disabling unused accounts going to do for YOUR networks?
It can stop an attacker from taking over the account with malicious intent.
Free answer
Free answer
Free answer
Why disable guest accounts?
They serve no purpose on an enterprise network.
They allow users to be productive
They don't need encryption
They don't use encryption
What is a trusted operating system?
An OS that has been thoroughly evaluated, vetted, and ranked into one of the seven EALs.
EAL stands for Evaluation Assurance Level
An operating system that is just like coughlin
Windows
