WorksheetsTS Security
Total questions: 20
Worksheet time: 11mins
Which kind of online attack involves pretending to be a legitimate company to get sensitive information?
Impersonating
Spyware
Virus
Phishing
A user was offered a 25% share of this account if she would help the sender transfer it to a bank in the United States.
Eavesdropping
Phishing
Man-in-the-Middle
Piggybacking
Joe, a user, receives an email from a popular video streaming website urging him to renew his membership. The email appears official, but Joe has never had a membership before. When Joe looks closer, he discovers that a hyperlink in the email points to a suspicious URL.
Which of the following security threats does this describe?
Trojan horse
Phishing
Zero-day attack
Man-in-the-middle
What is the best countermeasure against social engineering?
Acceptable use policy
User awareness training
Strong passwords
Access auditing
You are a security consultant and an organization has hired you to review their security measures. They are chiefly concerned that they could become the victim of a social engineering attack.
Which of the following would you MOST likely recommend they do to mitigate the risk?
Implement a border firewall to filter inbound network traffic.
Establish a written security policy.
Teach users how to recognize and respond to social engineering attacks.
Train managers to monitor user activity.
Which of the following is a common form of social engineering attack?
Using a sniffer to capture network traffic.
Hoax virus information emails.
Stealing the key card of an employee and using that to enter a secured building.
Distributing false information about your organization's financial status.
Which of the following is a form of attack that tricks victims into providing confidential information, such as identity information or logon credentials, through emails or Websites that impersonate an online entity that the victim trusts, such as a financial institution or well-known e-commerce site?
Phishing
Fraggle attack
Social engineering
Session hijacking
Dana is an IT administrator who is working on a company-wide initiative to address confidentiality concerns about secure information being revealed to unauthorized individuals.
Which of the following would be topics on the team agenda? (Select two.)
Replay attack
Snooping
Data destruction
Social engineering
Which of the following are examples of social engineering? (Select two.)
Port scanning
Shoulder surfing
Dumpster diving
Brute force password cracking
Maintaining confidentiality in the workplace is important for building and maintaining trust and for ensuring an open and honest communication between customers, clients, and employees. Which of the following threatens data confidentiality?
Replay attacks
Power outages
Man-in-the-Middle attacks
Dumpster diving
You receive a call from a person who identifies himself as a technician at Microsoft. He says your computer is infected and needs to be cleaned. Which of the following is this phone call MOST likely an example of?
Eavesdropping
Snooping
Social engineering
Replay attack
An IT administrator is informed by a security consultant that an attacker is capturing data being transmitted over the company network's wired connections.
Which of the following confidentiality concerns describes the security threat that is happening?
Snooping
Social engineering
Eavesdropping
Pretexting
Social engineering attacks use deception to gain personal and/or private information. Which of the following are examples of social engineering techniques? (Select three.)
Familiarity
Shoulder surfing
Snooping
Dumpster diving
Using an administrator account, a company employee copies the personally identifiable information (PII) for several other employees. Using that information, the employee then opens up several credit card accounts to purchase expensive electronic equipment for personal use.
Which of the following could have helped prevent the employee from opening up the credit card accounts?
Suspicious charges
Identity theft
Identity fraud
Identity checks
Janet is a systems engineer who is helping to design and implement a secure network for a new company. She wants to make sure critical data is protected from unauthorized changes during and after transmission.
Which of the following BEST describes Janet's concerns about making sure the critical data arrives intact and unaltered at its intended location on the network?
Confidentiality concerns
Availability concerns
Integrity concerns
Social engineering concerns
Which of the following are examples of impersonation social engineering tactics? (Select two.)
A hacker gains access to a system to steal or change confidential information.
A hacker uses TCP session hijacking to trick a server. *choose
A hacker intercepts the communication between a client and server.
A hacker pretends to be a member of senior management to gain access to a system.
Which of the following describes a Man-in-the-Middle attack?
A person over the phone convinces an employee to reveal their logon credentials.
An attacker intercepts communications between two network hosts by impersonating each host.
Malicious code is planted on a system where it waits for a triggering event before activating.
An IP packet is constructed which is larger than the valid size.
You recently charged $70 to one of your bank accounts, but the amount now appears as $700. Which of the following may have occurred?
Man-in-the-middle attack
Brute force password attack
Denial-of-service attack
Impersonation
A systems engineer has discovered an attack on the network, which is threatening to shut down a web service by overloading it with bogus requests. The attacker is using bot malware to enlist compromised systems (called zombies) to remotely manipulate them.
Which of the following is the threat being utilized by the attacker?
Replay attack
Distributed denial-of-service attack
Service outage
Data destruction
A systems engineer is maintaining a large network. A critical financial application service is down, and the issue has been escalated to the engineer. They've discovered that the network server hard disk from which the service is running has failed.
Which of the following would help the systems engineer make sure that this is not an issue in the future?
Network redundancy
Data redundancy
Site redundancy
Power redundancy
