Font size
WorksheetsRansomware 1
Total questions: 29
Worksheet time: 30mins
These two phases of ransomware deployment frequently occur together to prevent mitigation of the malware before it can be initiated (select all that apply):
Reconnaissance
Delivery
Installation
Exploitation
Command & Control (C&C)
In what phase of deployment does ransomware encrypt the impacted systems and exfiltrate data?
Delivery
Installation
Command & Control (C&C)
Actions on Objectives
According to law enforcement agencies, organizations should do which of the following to recover from ransomware events (select all that apply):
Pay ransom to threat actors
Utilize backup or recovery platforms
Work with threat researchers to mitigate the outbreak
Deploy stronger defenses to stop potential external connections into environment
What does SOAR stand for?
Security Orchestration, Automation, and Response
Security Operations, Automations, and Reports
Secret Operations, Automations, and Reports
Secure Organization, Automation, and Response
What is the single best defensive tactic against malware/ransomware in an organization environment?
Strong antivirus/antimalware platform
Next-generation firewalls
Intrusion detection systems
Employee education
What does ransomware use to lock files and prevent the victim from accessing them?
Encryption
Decryption
Manipulation
Illusion
What does TIP stand for?
Transport In Protection
Treat Intelligence Platform
Treat Information Protection
Treat In Protection
Which of the following are potential targets for a ransomware attack? (Select all that applies)
Large organizations
Critical infrastructure
Small businesses
Individuals
What does TTPs stand for?
Tactics, Techniques and Procedures
Techniques, Technology and Procedures
Techniques, Technology and Plans
Tactics, Telecommunication and Preparations
Initial access is often obtained by RansomEXX via a phishing email with an attached file. What file type does the attachment tend to be?
.zip
.pcap
.docx
Which of the followings gives the correct order of five most common tactics that are used by every form of malware?
Initial Access
Execution
Lateral Movement
Command and Control
Impact
Initial Access
Execution
Command and Control
Lateral Movement
Impact
Initial Access
Impact
Command and Control
Execution
Lateral Movement
Initial Access
Impact
Command and Control
Lateral Movement
Execution
What does SWG stand for?
Secure Web Gateway
Secret Website Gateway
Secret Web Goals
Secure World Goal
Which of the following common web application vulnerabilities would the exploitation of public-facing applications include?
SQL injection
Buffer overflow attacks
Improper certificate validation
Carriage return line feeds
Cross-site scripting
Which of the following Windows tools can be used as a command and scripting interpreter during a ransomware attack? (Select all that applies)
PowerShell
Media Player
Windows Command Shell
Snipping Tool
What does IDS stand for?
Intrusion Detection System
Innovative Deletion System
Intense Detection System
Intense Detection Solutions
What technique can be used to conceal C&C communications by adding junk protocol traffic or impersonating legitimate protocols?
Data Obfuscation
Encryption
Steganography
DoS
What is the main goal of ransomware affiliates when they encrypt data? (Select all that applies)
To interrupt availability to system and network resources.
To destroy the data.
To steal the data.
To demand ransom for files to be decrypted and released.
What does NGFW stand for?
Next Generation Firewall
Never Generate Failure
Not Generated Firewall
Next Generation Flowers
What do the phishing and malspam methods rely on to begin the attack phase?
Software vulnerabilities.
An out of date operating system.
Human-based user action.
An automated out of office reply.
Which one of these are public-facing services that are often targeted by ransomware threat actors? (Select all that applies)
RDP
VPN
MFA
SMB
What does DLP stand for?
Data Loss Prevention
Date Loss Protection
Developer Loss Protection
Data Learning Protocol
Ryuk ransomware generally consists of two stages. The first stage is the dropper — its role is to drop the ransomware executable. What do threat actors do to make it difficult to detect and investigate the dropper after the incident?
Delete the dropper.
Remove the account used.
Delete the email that the malware arrived in.
Delete the macro enabled document.
Which of the followings are generic tactics employed by ransomware operators when crafting a convincing phishing email? (Select all that applies)
Urgency
Authority
Scarcity
Curiosity
Inconvenience
What does SIEM stand for?
Security Information and Event Management
Securing Illegal Event Managers
Secret Information and Event Management
Secure Organization, Automation, and Response
Which statements are correct?
Patching can be a challenging process.
Patches should be applied as soon as they become available.
If you use properly written software you never need to worry about patching.
Threat actors never scan for vulnerabilities that are more than a few years old.
Which policy follows the principle of "never trust, always verify"?
Zero Trust
MFA
IAM
WannaCry
What does PoLP stand for?
Principle of Least Privilege
Prices of Least Popular
Protocol of Least Private
Power of Low Privilege
Which of the following options are common weaknesses of cloud infrastructure that could be used as part of a ransomware attack? (Select all that applies)
User accounts with unnecessary permissions
Shoulder surfing
Publicly accessible data structures
Use of API keys in publicly available code
Weak passwords on your WiFi infrastructure
How do you feel this week?
