wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Ransomware 1

Total questions: 29

Worksheet time: 30mins

Name
Class
Date
1.

These two phases of ransomware deployment frequently occur together to prevent mitigation of the malware before it can be initiated (select all that apply):

a)

Reconnaissance

b)

Delivery

c)

Installation

d)

Exploitation

e)

Command & Control (C&C)

2.

In what phase of deployment does ransomware encrypt the impacted systems and exfiltrate data?

a)

Delivery

b)

Installation

c)

Command & Control (C&C)

d)

Actions on Objectives

3.

According to law enforcement agencies, organizations should do which of the following to recover from ransomware events (select all that apply):

a)

Pay ransom to threat actors

b)

Utilize backup or recovery platforms

c)

Work with threat researchers to mitigate the outbreak

d)

Deploy stronger defenses to stop potential external connections into environment

4.

What does SOAR stand for?

a)

Security Orchestration, Automation, and Response

b)

Security Operations, Automations, and Reports

c)

Secret Operations, Automations, and Reports

d)

Secure Organization, Automation, and Response

5.

What is the single best defensive tactic against malware/ransomware in an organization environment?

a)

Strong antivirus/antimalware platform

b)

Next-generation firewalls

c)

Intrusion detection systems

d)

Employee education

6.

What does ransomware use to lock files and prevent the victim from accessing them?

a)

Encryption

b)

Decryption

c)

Manipulation

d)

Illusion

7.

What does TIP stand for?

a)

Transport In Protection

b)

Treat Intelligence Platform

c)

Treat Information Protection

d)

Treat In Protection

8.

Which of the following are potential targets for a ransomware attack? (Select all that applies)

a)

Large organizations

b)

Critical infrastructure

c)

Small businesses

d)

Individuals

9.

What does TTPs stand for?

a)

Tactics, Techniques and Procedures

b)

Techniques, Technology and Procedures

c)

Techniques, Technology and Plans

d)

Tactics, Telecommunication and Preparations

10.

Initial access is often obtained by RansomEXX via a phishing email with an attached file. What file type does the attachment tend to be?

a)

.zip

b)

.pcap

c)

.pdf

d)

.docx

11.

Which of the followings gives the correct order of five most common tactics that are used by every form of malware?

a)

Initial Access

Execution

Lateral Movement

Command and Control

Impact

b)

Initial Access

Execution

Command and Control

Lateral Movement

Impact

c)

Initial Access

Impact

Command and Control

Execution

Lateral Movement

d)

Initial Access

Impact

Command and Control

Lateral Movement

Execution

12.

What does SWG stand for?

a)

Secure Web Gateway

b)

Secret Website Gateway

c)

Secret Web Goals

d)

Secure World Goal

13.

Which of the following common web application vulnerabilities would the exploitation of public-facing applications include?

a)

SQL injection

b)

Buffer overflow attacks

c)

Improper certificate validation

d)

Carriage return line feeds

e)

Cross-site scripting

14.

Which of the following Windows tools can be used as a command and scripting interpreter during a ransomware attack? (Select all that applies)

a)

PowerShell

b)

Media Player

c)

Windows Command Shell

d)

Snipping Tool

15.

What does IDS stand for?

a)

Intrusion Detection System

b)

Innovative Deletion System

c)

Intense Detection System

d)

Intense Detection Solutions

16.

What technique can be used to conceal C&C communications by adding junk protocol traffic or impersonating legitimate protocols?

a)

Data Obfuscation

b)

Encryption

c)

Steganography

d)

DoS

17.

What is the main goal of ransomware affiliates when they encrypt data? (Select all that applies)

a)

To interrupt availability to system and network resources.

b)

To destroy the data.

c)

To steal the data.

d)

To demand ransom for files to be decrypted and released.

18.

What does NGFW stand for?

a)

Next Generation Firewall

b)

Never Generate Failure

c)

Not Generated Firewall

d)

Next Generation Flowers

19.

What do the phishing and malspam methods rely on to begin the attack phase?

a)

Software vulnerabilities.

b)

An out of date operating system.

c)

Human-based user action.

d)

An automated out of office reply.

20.

Which one of these are public-facing services that are often targeted by ransomware threat actors? (Select all that applies)

a)

RDP

b)

VPN

c)

MFA

d)

SMB

21.

What does DLP stand for?

a)

Data Loss Prevention

b)

Date Loss Protection

c)

Developer Loss Protection

d)

Data Learning Protocol

22.

Ryuk ransomware generally consists of two stages. The first stage is the dropper — its role is to drop the ransomware executable. What do threat actors do to make it difficult to detect and investigate the dropper after the incident?

a)

Delete the dropper.

b)

Remove the account used.

c)

Delete the email that the malware arrived in.

d)

Delete the macro enabled document.

23.

Which of the followings are generic tactics employed by ransomware operators when crafting a convincing phishing email? (Select all that applies)

a)

Urgency

b)

Authority

c)

Scarcity

d)

Curiosity

e)

Inconvenience

24.

What does SIEM stand for?

a)

Security Information and Event Management

b)

Securing Illegal Event Managers

c)

Secret Information and Event Management

d)

Secure Organization, Automation, and Response

25.

Which statements are correct?

a)

Patching can be a challenging process.

b)

Patches should be applied as soon as they become available.

c)

If you use properly written software you never need to worry about patching.

d)

Threat actors never scan for vulnerabilities that are more than a few years old.

26.

Which policy follows the principle of "never trust, always verify"?

a)

Zero Trust

b)

MFA

c)

IAM

d)

WannaCry

27.

What does PoLP stand for?

a)

Principle of Least Privilege

b)

Prices of Least Popular

c)

Protocol of Least Private

d)

Power of Low Privilege

28.

Which of the following options are common weaknesses of cloud infrastructure that could be used as part of a ransomware attack? (Select all that applies)

a)

User accounts with unnecessary permissions

b)

Shoulder surfing

c)

Publicly accessible data structures

d)

Use of API keys in publicly available code

e)

Weak passwords on your WiFi infrastructure

29.

How do you feel this week?

a)

b)

c)

d)