wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Chapter 3 Quiz

Total questions: 20

Worksheet time: 10mins

Name
Class
Date
1.

True or False? A phishing email is a fake or bogus email intended to trick

the recipient into clicking on an embedded link or opening an email

attachment.

a)

True

b)

False

2.

Aditya is the security manager for a mid-sized business. The company

has suffered several serious data losses when laptops were stolen. Aditya

decides to implement full disk encryption on all laptops. What risk

response did Aditya take?

a)

Avoid

b)

Transfer

c)

Accept

d)

Reduce

3.

Purchasing an insurance policy is an example of the ____________ risk

management strategy.

a)

Transfer

b)

Reduce

c)

Accept

d)

Avoid

4.

True or False? In a masquerade attack, one user or computer pretends to

be another user or computer.

a)

True

b)

False

5.

True or False? Anti-malware programs and firewalls cannot detect most

phishing scams because the scams do not contain suspect code.

a)

True

b)

False

6.

In which type of attack does the attacker attempt to take over an existing

connection between two systems?

a)

Session hijacking

b)

Typosquatting

c)

Man-in-the-middle attack

d)

Uniform resource locator (URL) hijacking

7.

True or False? Corrective controls are implemented to address a threat in

place that does not have a straightforward risk-mitigating solution.

a)

True

b)

False

8.

A hacker has stolen logon IDs and passwords. The hacker is now

attempting to gain unauthorized access to a public-facing web application

by using the stolen credentials one by one. What type of attack is taking

place?

a)

Replay attack

b)

Phreaking

c)

Birthday attack

d)

Credential harvesting

9.

Forensics and incident response are examples of __________ controls.

a)

preventive

b)

corrective

c)

detective

d)

deterrent

10.

True or False? Impact refers to the amount of risk or harm caused by a

threat or vulnerability that is exploited by a perpetrator.

a)

True

b)

False

11.

True or False? In a watering-hole attack, a targeted user is lured to a

commonly visited website on which malicious code has been planted.

a)

True

b)

False

12.

True or False? A man-in-the-middle attack takes advantage of the

multihop process used by many types of networks.

a)

True

b)

False

13.

Barry discovers that an attacker is running an access point in a building

adjacent to his company. The access point is broadcasting the security

set identifier (SSID) of an open network owned by the coffee shop in his

lobby. Which type of attack is likely taking place?

a)

Near field communication

b)

Jamming /interference

c)

Bluesnarfing

d)

Evil Twin

14.

True or False? Bluejacking is an attack in which wireless traffic is sniffed

between Bluetooth devices.

a)

True

b)

False

15.

Adam is evaluating the security of a web server before it goes live. He

believes that an issue in the code allows a cross-site scripting attack

against the server. What term describes the issue that Adam discovered?

a)

Impact

b)

Vulnerability

c)

Threat

d)

Risk

16.

Brian notices an attack taking place on his network. When he digs deeper,

he realizes that the attacker has a physical presence on the local network

and is forging Media Access Control (MAC) addresses. Which type of

attack is most likely taking place?

a)

Christmas attack

b)

Address resolution protocol (ARP) poisoning

c)

Internet Protocol (IP) address spoofing

d)

Uniform resource locator (URL) hijacking

17.

True or False? A social engineering consensus tactic relies on the

position that "everyone else has been doing it" as proof that it is okay or

acceptable to do.

a)

True

b)

False

18.

True or False? Preventive controls merely attempt to suggest that a

subject not take a specific action, whereas corrective controls do not allow

the action to occur.

a)

True

b)

False

19.

An attacker attempting to break into a facility pulls the fire alarm to distract

the security guard manning an entry point. Which type of social

engineering attack is the attacker using?

a)

Vishing

b)

Whaling

c)

Urgency

d)

Authority

20.

True or False? A phishing attack "poisons" a domain name on a domain

name server (DNS).

a)

True

b)

False