wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Security+ Study Guide-06 Threats, Vulnerabilities & Common Attac

Total questions: 15

Worksheet time: 11mins

Name
Class
Date
1.

A tech company recently discovered an attack on its organization, resulting in a significant data breach of customer data. After investigating the attack, they realized it was very sophisticated and likely originated from a foreign country.

Which of the following identifies the MOST likely threat actor in this attack?

a)

Hacktivist

b)

APT

c)

Competitors

d)

Insiders

2.

An attacker purchased an exploit on the internet. He then used it to modify an item's price in an online shopping cart during checkout.

Which of the following BEST describes this attack?

a)

Insider

b)

Script kiddie

c)

Competitor

d)

Hacktivist

e)

APT

3.

Lisa is a database administrator. She received a phone call from someone identifying himself as a representative from a known hardware vendor. He said he's calling customers to inform them of a problem with database servers they've sold, but he said the problem only affects servers running a specific operating system version. He asks Lisa what operating system version the company is running on their database servers.

Which of the following BEST describes the tactic used by the caller in this scenario?

a)

Pretexting

b)

Tailgating

c)

Pharming

d)

Smishing

4.

An attacker recently attacked a web server hosted by your company. After investigating the attack, security professionals determined that the attacker used a previously unknown application exploit.

Which of the following BEST identifies this attack?

a)

Buffer overflow

b)

Zero-day attack

c)

Man-in-the-browser

d)

Integer overflow

5.

After Bart logged on his computer, he was unable to access any data. Instead, his screen displayed a message indicating that unless he made a payment, his hard drive would be formatted, and he'd permanently lose access to his data.

What does this indicate?

a)

Keylogger

b)

Ransonware

c)

Backdoor

d)

Trojan

6.

Recently, malware on a computer at the Monty Burns Casino destroyed several important files after it detected that Homer was no longer employed at the casino.

Which of the following BEST identifies this walware?

a)

Logic bomb

b)

Rootkit

c)

Backdoor

d)

Spyware

7.

Maggie was on a programming team that developed an application used by your Human Resources department. Personnel use this application to store and manage employee data. Maggie programmed in the ability to access this application with a username and password that only she knows to perform remote maintenance on the application if necessary.

Which of the following does this describe?

a)

Virus

b)

Worm

c)

Backdoor

d)

Trojan

8.

Homer complained of abnormal activity on his workstation. After investigating, an administrator discovered his workstation connects to systems outside the organization's internal network using uncommon ports. The administrator discovered the workstation is also running several hidden processes.

Which of the following choices BEST describes this activity?

a)

Rootkit

b)

Backdoor

c)

Spam

d)

Trojan

9.

Bart downloaded and installed the nmap security scanner from https://passsecurity.com. After completing the install, he noticed that his browser's home page and default search engine was changed.

What is the MOST likely cause of the activity?

a)

PUP

b)

Fileless virus

c)

Worm

d)

Rootkit

10.

Your SIEM system alerted on potential malicious activity from a system in your network. After investigating the alert, you determine it was generated after it detected suspicious activity generated through a PowerShell script. Additionally, you verified that the system is sending traffic to and from an unknown IP address in the Internet.

Which of the following is the BEST description of this threat?

a)

Ransonware

b)

Fileless virus

c)

Command and control

d)

Rootkit

11.

A man in a maintenance uniform walked up to your organization's receptionist desk. He said he was called by the CIO and asked to fix an issue with the phones and needed access to the wiring closet. The receptionist asked the man to show his building access badge, and then she verified that he was on the list of approved personnel to access this secure area.

What type of attack will the checks performed by the receptionist prevent?

a)

Tailgating

b)

Phishing

c)

Impersonation

d)

Whaling

e)

Prepending

12.

An organization's security policy requires employee to place all discarded paper document in containers for temporary storage. These papers are later burned in an incinerator.

Which of the following attacks are these actions MOST likely trying to prevent?

a)

Shoulder surfing

b)

Tailgating

c)

Smishing

d)

Dumpster diving

13.

Lisa is a database administrator and receive a phone call from someone identifying himself as a technician working with a known hardware vendor. He said he's calling customer to inform them of a problem with database servers they've sold, but he said the problem only affects servers running a specific operating system version. He asks Lisa what operating system version the company is running on their database servers.

Which of the following choices is the BEST response from Lisa?

a)

Let the caller know what operating system and versions are running on the database servers to determine if any further actions is needed

b)

Thank the caller and end the call, report the call to her supervisor, and independently check the vendor for issues.

c)

Ask the caller for his phone number so that she can call him back after checking the servers.

d)

Contact law enforcement personnel because this is a pretexting attack.

14.

Homer, the chief financial officer (CFO) of a bank, received an email from Lisa, the company's chief executive officer (CEO). Lisa states she is on vacation and lost her purse, containing all her cash and credit cards. She asks Homer to transfer $5,000 to her account.

Which of the following best identifies this attack?

a)

Phishing

b)

Vishing

c)

Smishing

d)

Whaling

15.

Homer has been looking for the newest version of a popular smartphone. However, he can't find it in stock anywhere. Today, he received an email advertising the smartphone. After clicking the link, his system was infected with malware.

Which of the following principles is the email sender employing?

a)

Authority

b)

Intimidation

c)

Scarcity

d)

Trust