NEW
Font size
WorksheetsPost-Test Under Cyber Closet Project
Total questions: 25
Worksheet time: 25mins
Why a hacker would use a proxy server?
To create a stronger connection with the target
To create a ghost server on the network
To obtain a remote access connection
To hide malicious activity on the network
Which can be considered as a possible solution for SQL injection vulnerability?
Data Validation
Secure Cookies
Encryption
Comprehensive exception handling
What is the common cause of buffer over flows, cross-site scripting, SQL injection and format string attacks?
Unvalidated input
Lack of authentication
Improper error handing
Insecure configuration management
___________ is a special form of attack using which hackers’ exploit – human psychology.
Cross Site Scripting
Insecure network
Social Engineering
Reverse Engineering
Performing hacking activities with the intent on gaining visibility for an unfair situation is called ________.
Cracking
Analysis
Hacktivism
Exploitation
SQL injection is an attack in which _________ code is inserted into strings that are later passed to an instance of SQL Server.
Malicious
Redundant
Clean
Non malicious
Which database is queried by Whois?
ICANN
ARIN
APNIC
DNS
This attack can be deployed by infusing a malicious code in a website’s comment section. What is “this” attack referred to here?
SQL injection
HTML Injection
Cross Site Scripting (XSS)
Cross Site Request Forgery (XSRF)
Which of the following should be stored in the cookie?
Session ID
Account Privileges
User Name
Password
When there is an excessive amount of data flow, which the system cannot handle, _____ attack takes place.
Database crash attack
DoS (Denial of Service) attack
Data overflow Attack
Buffer overflow Attack
Cross Site Scripting is an attack against
Client (Browser)
Database
Web Application
Web Server
Which of the following is not an appropriate way to compromise web servers?
Misconfiguration in OS
Using network vulnerabilities
Misconfiguration in networks
Bugs in OS which allow commands to run on web servers
As a Security measure what has to be done with Temporary files in a web server?
Should be placed securely in a folder called “temp” in the web root
Can be placed anywhere in the web root as long as there are no links to them
Should be completely removed from the server
Can be placed anywhere after changing the extension
What are Sysinternal Tools?
Troubleshooting Utilities
Advanced Task Manager Tools
Anti-virus tools
Advanced SystemCare
In order for anti-virus programs to be most effective, it is necessary to keep which of the following up to date?
Web Browsers
File Hashes
Antivirus Encryption Keys
Virus Definition Files
What is the ethics behind training how to hack a system?
To think like hackers and know how to defend such attacks
To hack a system without the permission
To hack a network that is vulnerable
To corrupt software or service using malware
Malware is the short form of
Malicious Systems
Maliant Software
Maliant Systems
Malicious Software
Which of the following port is not used by Trojans?
UDP
TCP
SMTP
MP
_____________ is a code injecting method used for attacking the database of a system / website.
HTML injection
SQL Injection
Malicious code injection
XML Injection
DIRB Tool is used to scan website _______________
Vulnerabilities
Content
Both A and B
Open Ports
Which is the most dangerous web application vulnerability according to OWASP?
Security Misconfiguration
Injection
Cross Site Scripting
Sensitive Data Exposure
What are the two primary classifications of Cross-Site Scripting?
Persistent and Non-Persistent
DOM based and Persistent
Traditional and non-persistent
Traditional and DOM based
Suppose you received a mail from HSBC Bank asking you to give your online bank account details. Under which of the spam mail categories does this spam fall?
Chain Mails
Phishing and fraud
Hoaxes
Brand Spoofing
Which of the following is malicious code attack?
Brute Force
DDOS
Virus
Malware
____________________ monitors user activity on Internet and transmit that information in the background to someone else.
Malware
Spyware
Adware
None of these
