Worksheets1.3 - Surveying the Cyberspace
Total questions: 15
Worksheet time: 8mins
The use of deception to manipulate individuals into divulging confidential or personal information that may be used for fraudulent purposes.
Man in the middle
Packet sniffing
Social engineering
Malware attacks
An attacker, pretending to be a trusted entity, dupes a victim into opening an email, instant message, or text message. The recipient is then tricked into clicking a malicious link.
Whaling
Fishing attack
Code injection
Phishing attack
A common cyberattack where malicious software executes unauthorized actions on the victim’s system.
Code injection
Malware attacks
Lack of segregation
Default credentials
This attack uses trial-and-error to guess login info, encryption keys, or to find a hidden web page.
Brute force attack
Trial and error attack
Password reuse attack
Encryption attack
Which of these vulnerabilities in a database happens when a user can access the information of another user with the same login credentials?
Default credentials
Unpatched database
Lack of authentication
Lack of segregation
Which of the following vulnerabilities in a database occurs when the developer does not configure a production database after creating it?
Default components and values
Default credentials
Failed configurations
Unpatched database
Users inundated with requirements to supply complex passwords to different systems often resort to reusing the same password across multiple accounts so that they can easily manage their credentials. This leads to which of the following vulnerabilities?
Faulty sessions
Identity theft
Credential reuse
Need a secretary to manage all my passwords
Which of the following might be a good solution to the problem of credential reuse?
Password manager
Requirement of monthly password reset
Setting good minimum standards for passwords
Hacking into people’s accounts to prove a point
A cybersecurity term for when an attacker positions themselves in a conversation between two entities in a network and intercepts messages
Inception
Interception
Man in the middle
Eavesdropping
Which of the following security vulnerabilities can result in credential loss, identity theft, or blackmailing?
Being vulnerable to an attractive person
Hardware theft
Being insecure in formal communications and speaking engagements
Social engineering
Which of the following suggestions would not be good to advise as a cybersecurity professional?
Good password habits like minimum length, symbols, numbers, and using a password manager
Implementing a strong multi factor authentication solution
That a company does not need to spend on security training if their systems are strong enough
To ensure that physical access to servers is protected by multiple layers of physical security
Which of the following actions could you suggest to protect against injection attacks?
To sanitize hands before leaving the bathroom and continuing work
To ensure that all password field contents are hidden in the UI
To remove dangerous characters from the office by calling the police
To implement prepared statements instead of string interpolation for database calls
In the context of cybersecurity, what are sniffing attacks?
When someone gets a bit too close for you to be comfortable
When an attacker uses specialized software to intercept and read data passing through a network
Using a software sniffing tool to analyze faulty coroutines in consumer software
Injecting malware into a victim’s computer to find vulnerabilities on their system
Which of the following suggestions would not be good to advise as a cybersecurity professional?
To expire user cookies and sessions upon logout
To add user details to JSON authentication tokens for easier development
To keep a short expiry time for authentication tokens and cookies
To ensure that all server endpoints are rate limited
Which of the following links is most likely to be a legitimate Google website?
https://au.yahoo.com/
https://transparencyreport.googie.com/
https://unsafe.google.com/
file:///myaccount.google.com/
https://customer.google.one-support.com/
