NEW
Font size
WorksheetsModule 3
Total questions: 15
Worksheet time: 6mins
Which security term is used to describe anything of value to the organization? It includes people, equipment, resources, and data.
Vulnerability
Exploit
Asset
Risk
Which security term is used to describe a weakness in a system, or its design, that could be exploited by a threat?
Mitigation
Risk
Asset
Vulnerability
Which security term is used to describe a potential danger to a company’s assets, data, or network functionality?
Vulnerability
Exploit
Threat
Risk
Which security term is used to describe a mechanism that takes advantage of a vulnerability?
Exploit
Threat
Risk
Mitigation
Which security term is used to describe the counter-measure for a potential threat or risk?
Vulnerability
Exploit
Asset
Mitigation
Which security term is used to describe the likelihood of a threat to exploit the vulnerability of an asset, with the aim of negatively affecting an organization?
Vulnerability
Exploit
Threat
Risk
Which objective of secure communications is achieved by encrypting data?
Integrity
Authentication
Availability
Confidentiality
What type of malware has the primary objective of spreading across the network?
Virus
Trojan horse
Worm
Botnet
Which cyber attack involves a coordinated attack from a botnet of zombie computers?
Address spoofing
DDoS
ICMP redirect
MITM
What specialized network device is responsible for enforcing access control policies between networks?
Firewall
Bridge
IDS
Switch
Which type of hacker is described in the scenario: After hacking into ATM machines remotely using a laptop, I worked with ATM manufacturers to resolve the security vulnerabilities that I discovered.
White Hat
Gray Hat
Black Hat
The IT department is reporting that a company web server is receiving an abnormally high number of web page requests from different locations simultaneously. Which type of security attack is occurring?
phishing
social engineering
spyware
adware
DDoS
For detecting malicious activity, an IPS uses a set of rules called signatures to detect patterns in network traffic.
to detect patterns of malicious traffic by the use of signature files
to filter traffic based on defined rules and connection context
to enforce access control policies based on packet content
to filter traffic based on Layer 7 information
A cleaner attempts to enter a computer lab but is denied entry by the receptionist because there is no scheduled cleaning for that day. What type of attack was just prevented?
phishing
social engineering
Trojan
shoulder surfing
Which type of DNS attack involves the cybercriminal compromising a parent domain and creating multiple subdomains to be used during the attacks?
tunneling
cache poisoning
amplification and reflection
shadowing
