Font size
WorksheetsCompTIA Security+ (1.1 to 1.2)
Total questions: 30
Worksheet time: 15mins
What kind of attack can we use with botnets?
ARP poisoning
DOS
Shoulder surfing
DDOS
A password attack that only use a "wordlist" file to attack is called
Bruteforce
Dictionary
Spraying
Rainbow table
We should not use hashing for our password text files
True
False
Once infected, the bot wait for the instruction from where
Network
User
DNS server
C&C server
Trying every possible password combination is called
Tailgating attack
Dictionary attack
Brute force attack
Spraying attack
How many kinds of Logic bombs?
3
2
1
5
In a watering hole attack, which source is used as a hostage by the attackers to attack their target.
Third party network
USB flash drive
A restaurant
Target computers
In Supply Chain attacks, attackers need to attack all parts of the chain to achieve the attack
True
False
The image above is a
Brute froce attack
Dictionary attack
Spraying attack
Hash attack
In which of the following social engineering attack, the attacker threaten the victim to achieve the attack?
Intimidation
Familiarity
Urgency
Social proof
Due to added functionality in its plug, malicious USB cable can be used for:
Capturing keystrokes
Executing malware
Sending and receiving commands
All of the above
Which of the following terms is used to describe the theft of personal data from a payment card?
Identity theft
Skimming
Phishing
Shoulder surfing
Which extra information is added to the fake credit card to look and feel like an authentic one?
CVC
C&C
CFO
C2
Which of the following belongs to HIDs (Human Interface Devices)
Keyboard
Webcam
Headset
All of the above
In the IT field, the practice of making an unauthorized copy of a payment card is referred to as:
Impersonation
Cloning
Replication
Copying
Which of the following security is better in terms of cost and redundancy.
Cloud-based
NAS
On-premise
SAN
Select protective measures against shoulder surfing
Privacy filter
A good display
Wearing a hoodie
Checking around the evironment
How many common social engineering principles do many people know?
5
4
7
6
In which of the following attack, the attacker uses phishing mail to exploit the victim and request payment for goods or services?
Tailgating
Invoice scam
Credential harvesting
Influence campaign
Typosquatting is also called
Tarpitting
Dumpster diving
Domain hijacking
Card cloning
Pharming is the combination of
Whaling and phishing
Phishing and hoaxes
Shoulder surfing and phishing
Phishing and DNS poisoning
Justin is a political backbencher, but he wants to get a higher position. Which attack will he use?
Vishing
Influence campaign
Impersonation
Identity theft
A hoax is a/an
Fileless virus
Fake virus warning
Crypto-malware
Macro virus
Dumpster diving can also be used to find electronics to recycle.
True
False
Which of the following virus type is the most difficult to remove and detect by anti-virus software?
Program virus
Macro Virus
Script-virus
Fileless virus
A virus can replicate itself without human intervention
True
False
Which malware is used by attackers to encrypt all the data inside your computer and ask to pay for the decryption key?
Crypto malware
Wannacry worm
Trojan horse
All of the above
PUPs are essential software and applications that are needed for your device to run smoothly
True
False
Which of the following malware infects the kernel of an operating system to hide from the anti-virus?
Rootkit
Remote Access Trojan
Spyware
Adware
Specially designed anti-virus tools are needed to remove advanced-level rootkits.
True
False
