wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

TS Security

Total questions: 20

Worksheet time: 11mins

Name
Class
Date
1.

Which kind of online attack involves pretending to be a legitimate company to get sensitive information?

a)

Impersonating

b)

Spyware

c)

Virus

d)

Phishing

2.

A user was offered a 25% share of this account if she would help the sender transfer it to a bank in the United States.

a)

Eavesdropping

b)

Phishing

c)

Man-in-the-Middle

d)

Piggybacking

3.

Joe, a user, receives an email from a popular video streaming website urging him to renew his membership. The email appears official, but Joe has never had a membership before. When Joe looks closer, he discovers that a hyperlink in the email points to a suspicious URL.

Which of the following security threats does this describe?

a)

Trojan horse

b)

Phishing

c)

Zero-day attack

d)

Man-in-the-middle

4.

What is the best countermeasure against social engineering?

a)

Acceptable use policy

b)

User awareness training

c)

Strong passwords

d)

Access auditing

5.

You are a security consultant and an organization has hired you to review their security measures. They are chiefly concerned that they could become the victim of a social engineering attack.

Which of the following would you MOST likely recommend they do to mitigate the risk?

a)

Implement a border firewall to filter inbound network traffic.

b)

Establish a written security policy.

c)

Teach users how to recognize and respond to social engineering attacks.

d)

Train managers to monitor user activity.

6.

Which of the following is a common form of social engineering attack?

a)

Using a sniffer to capture network traffic.

b)

Hoax virus information emails.

c)

Stealing the key card of an employee and using that to enter a secured building.

d)

Distributing false information about your organization's financial status.

7.

Which of the following is a form of attack that tricks victims into providing confidential information, such as identity information or logon credentials, through emails or Websites that impersonate an online entity that the victim trusts, such as a financial institution or well-known e-commerce site?

a)

Phishing

b)

Fraggle attack

c)

Social engineering

d)

Session hijacking

8.

Dana is an IT administrator who is working on a company-wide initiative to address confidentiality concerns about secure information being revealed to unauthorized individuals.

Which of the following would be topics on the team agenda? (Select two.)

a)

Replay attack

b)

Snooping

c)

Data destruction

d)

Social engineering

9.

Which of the following are examples of social engineering? (Select two.)

a)

Port scanning

b)

Shoulder surfing

c)

Dumpster diving

d)

Brute force password cracking

10.

Maintaining confidentiality in the workplace is important for building and maintaining trust and for ensuring an open and honest communication between customers, clients, and employees. Which of the following threatens data confidentiality?

a)

Replay attacks

b)

Power outages

c)

Man-in-the-Middle attacks

d)

Dumpster diving

11.

You receive a call from a person who identifies himself as a technician at Microsoft. He says your computer is infected and needs to be cleaned. Which of the following is this phone call MOST likely an example of?

a)

Eavesdropping

b)

Snooping

c)

Social engineering

d)

Replay attack

12.

An IT administrator is informed by a security consultant that an attacker is capturing data being transmitted over the company network's wired connections.

Which of the following confidentiality concerns describes the security threat that is happening?

a)

Snooping

b)

Social engineering

c)

Eavesdropping

d)

Pretexting

13.

Social engineering attacks use deception to gain personal and/or private information. Which of the following are examples of social engineering techniques? (Select three.)

a)

Familiarity

b)

Shoulder surfing

c)

Snooping

d)

Dumpster diving

14.

Using an administrator account, a company employee copies the personally identifiable information (PII) for several other employees. Using that information, the employee then opens up several credit card accounts to purchase expensive electronic equipment for personal use.

Which of the following could have helped prevent the employee from opening up the credit card accounts?

a)

Suspicious charges

b)

Identity theft

c)

Identity fraud

d)

Identity checks

15.

Janet is a systems engineer who is helping to design and implement a secure network for a new company. She wants to make sure critical data is protected from unauthorized changes during and after transmission.

Which of the following BEST describes Janet's concerns about making sure the critical data arrives intact and unaltered at its intended location on the network?

a)

Confidentiality concerns

b)

Availability concerns

c)

Integrity concerns

d)

Social engineering concerns

16.

Which of the following are examples of impersonation social engineering tactics? (Select two.)

a)

A hacker gains access to a system to steal or change confidential information.

b)

A hacker uses TCP session hijacking to trick a server. *choose

c)

A hacker intercepts the communication between a client and server.

d)

A hacker pretends to be a member of senior management to gain access to a system.

17.

Which of the following describes a Man-in-the-Middle attack?

a)

A person over the phone convinces an employee to reveal their logon credentials.

b)

An attacker intercepts communications between two network hosts by impersonating each host.

c)

Malicious code is planted on a system where it waits for a triggering event before activating.

d)

An IP packet is constructed which is larger than the valid size.

18.

You recently charged $70 to one of your bank accounts, but the amount now appears as $700. Which of the following may have occurred?

a)

Man-in-the-middle attack

b)

Brute force password attack

c)

Denial-of-service attack

d)

Impersonation

19.

A systems engineer has discovered an attack on the network, which is threatening to shut down a web service by overloading it with bogus requests. The attacker is using bot malware to enlist compromised systems (called zombies) to remotely manipulate them.

Which of the following is the threat being utilized by the attacker?

a)

Replay attack

b)

Distributed denial-of-service attack

c)

Service outage

d)

Data destruction

20.

A systems engineer is maintaining a large network. A critical financial application service is down, and the issue has been escalated to the engineer. They've discovered that the network server hard disk from which the service is running has failed.

Which of the following would help the systems engineer make sure that this is not an issue in the future?

a)

Network redundancy

b)

Data redundancy

c)

Site redundancy

d)

Power redundancy