wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Post-Test Under Cyber Closet Project

Total questions: 25

Worksheet time: 25mins

Name
Class
Date
1.

Why a hacker would use a proxy server?

a)

To create a stronger connection with the target

b)

To create a ghost server on the network

c)

To obtain a remote access connection

d)

To hide malicious activity on the network

2.

Which can be considered as a possible solution for SQL injection vulnerability?

a)

Data Validation

b)

Secure Cookies

c)

Encryption

d)

Comprehensive exception handling

3.

What is the common cause of buffer over flows, cross-site scripting, SQL injection and format string attacks?

a)

Unvalidated input

b)

Lack of authentication

c)

Improper error handing

d)

Insecure configuration management

4.

___________ is a special form of attack using which hackers’ exploit – human psychology.

a)

Cross Site Scripting

b)

Insecure network

c)

Social Engineering

d)

Reverse Engineering

5.

Performing hacking activities with the intent on gaining visibility for an unfair situation is called ________.

a)

Cracking

b)

Analysis

c)

Hacktivism

d)

Exploitation

6.

SQL injection is an attack in which _________ code is inserted into strings that are later passed to an instance of SQL Server.

a)

Malicious

b)

Redundant

c)

Clean

d)

Non malicious

7.

Which database is queried by Whois?

a)

ICANN

b)

ARIN

c)

APNIC

d)

DNS

8.

This attack can be deployed by infusing a malicious code in a website’s comment section. What is “this” attack referred to here?

a)

SQL injection

b)

HTML Injection

c)

Cross Site Scripting (XSS)

d)

Cross Site Request Forgery (XSRF)

9.

Which of the following should be stored in the cookie?

a)

Session ID

b)

Account Privileges

c)

User Name

d)

Password

10.

When there is an excessive amount of data flow, which the system cannot handle, _____ attack takes place.

a)

Database crash attack

b)

DoS (Denial of Service) attack

c)

Data overflow Attack

d)

Buffer overflow Attack

11.

Cross Site Scripting is an attack against

a)

Client (Browser)

b)

Database

c)

Web Application

d)

Web Server

12.

Which of the following is not an appropriate way to compromise web servers?

a)

Misconfiguration in OS

b)

Using network vulnerabilities

c)

Misconfiguration in networks

d)

Bugs in OS which allow commands to run on web servers

13.

As a Security measure what has to be done with Temporary files in a web server?

a)

Should be placed securely in a folder called “temp” in the web root

b)

Can be placed anywhere in the web root as long as there are no links to them

c)

Should be completely removed from the server

d)

Can be placed anywhere after changing the extension

14.

What are Sysinternal Tools?

a)

Troubleshooting Utilities

b)

Advanced Task Manager Tools

c)

Anti-virus tools

d)

Advanced SystemCare

15.

In order for anti-virus programs to be most effective, it is necessary to keep which of the following up to date?

a)

Web Browsers

b)

File Hashes

c)

Antivirus Encryption Keys

d)

Virus Definition Files

16.

What is the ethics behind training how to hack a system?

a)

To think like hackers and know how to defend such attacks

b)

To hack a system without the permission

c)

To hack a network that is vulnerable

d)

To corrupt software or service using malware

17.

Malware is the short form of

a)

Malicious Systems

b)

Maliant Software

c)

Maliant Systems

d)

Malicious Software

18.

Which of the following port is not used by Trojans?

a)

UDP

b)

TCP

c)

SMTP

d)

MP

19.

_____________ is a code injecting method used for attacking the database of a system / website.

a)

HTML injection

b)

SQL Injection

c)

Malicious code injection

d)

XML Injection

20.

DIRB Tool is used to scan website _______________

a)

Vulnerabilities

b)

Content

c)

Both A and B

d)

Open Ports

21.

Which is the most dangerous web application vulnerability according to OWASP?

a)

Security Misconfiguration

b)

Injection

c)

Cross Site Scripting

d)

Sensitive Data Exposure

22.

What are the two primary classifications of Cross-Site Scripting?

a)

Persistent and Non-Persistent

b)

DOM based and Persistent

c)

Traditional and non-persistent

d)

Traditional and DOM based

23.

Suppose you received a mail from HSBC Bank asking you to give your online bank account details. Under which of the spam mail categories does this spam fall?

a)

Chain Mails

b)

Phishing and fraud

c)

Hoaxes

d)

Brand Spoofing

24.

Which of the following is malicious code attack?

a)

Brute Force

b)

DDOS

c)

Virus

d)

Malware

25.

____________________ monitors user activity on Internet and transmit that information in the background to someone else.

a)

Malware

b)

Spyware

c)

Adware

d)

None of these