Font size
WorksheetsA+ - 16A - Explain Attacks, Threats, and Vulnerabilities
Total questions: 2
Worksheet time: 16mins
Information security involves controlling access to data, whether in digital or physical formats. The CIA triad, consisting of confidentiality, integrity, and availability, guides secure information practices. Cybersecurity, a subset of information security, focuses on protecting computer systems from attacks. Security policies and controls are implemented to ensure information and systems remain secure, and assessments are conducted to evaluate network security. Vulnerabilities, threats, and risks are key concepts in assessing security.
Configuration baselines are used to minimize vulnerabilities, while security controls like firewalls and antivirus software protect against threats. Software vulnerabilities, especially zero-day vulnerabilities, pose significant risks. Unpatched or end-of-life systems are also vulnerable. Bring Your Own Device (BYOD) policies introduce additional vulnerabilities.
Social engineering techniques, such as impersonation and phishing, exploit human vulnerabilities to gain unauthorized access. Attacks like shoulder surfing and tailgating rely on physical proximity. Cross-site scripting (XSS) and SQL injection are common web application vulnerabilities. Denial of service (DoS) attacks disrupt service availability.
Encryption technologies, including cryptographic hashes and asymmetric encryption, play crucial roles in ensuring data confidentiality and integrity. Digital signatures and key exchange protocols enable secure communication.
What are the three properties of secure information, according to the CIA triad?
Confidentiality, integrity, and authentication
Confidentiality, integrity, and availability
Confidentiality, accessibility, and authenticity
Confidentiality, reliability, and authorization
What term specifically refers to controls that protect against attacks on computer storage and processing systems?
Information security
Cybersecurity
Network security
Data encryption
What is the main purpose of hardening a system?
To make it more user-friendly
To increase its attack surface
To make it more secure
To reduce its accessibility
What is a vulnerability?
A potential threat actor
A security policy
A weakness that could be exploited
A secure configuration
Which type of attack relies on obtaining information about the network and its security controls?
Footprinting
Spoofing
Phishing
Shoulder surfing
What is the purpose of a cryptographic hash?
To encrypt data
To verify data integrity
To generate a digital signature
To exchange encryption keys
What type of encryption uses a single secret key for both encryption and decryption?
Asymmetric encryption
Triple DES
Symmetric encryption
RSA encryption
What is the primary goal of a denial of service (DoS) attack?
To steal data
To gain unauthorized access
To disrupt service availability
To impersonate a trusted user
Which type of attack exploits user input validation vulnerabilities in web applications?
Cross-site scripting (XSS)
Shoulder surfing
Tailgating
SQL injection
What is the main purpose of a digital signature?
To encrypt data
To authenticate the sender
To prevent data tampering
To exchange encryption keys
What is the term used to describe the practice of persuading or intimidating individuals into revealing confidential information or unauthorized access?
Spoofing
Phishing
Social engineering
Footprinting
What is the main purpose of a baseline configuration in information security?
To increase the system's attack surface
To minimize the risk of vulnerabilities
To create a secure backup of data
To allow unrestricted access to all users
Which type of vulnerability allows a threat actor to execute arbitrary code on a system, potentially leading to the installation of malware?
Non-compliant system
Zero-day vulnerability
Spoofing vulnerability
Tailgating vulnerability
What is the primary goal of an evil twin attack?
To harvest authentication information from WiFi users
To intercept network traffic between two hosts
To impersonate a trusted user or computer
To disrupt service availability
Which type of attack involves modifying the HTTP/HTTPS web protocol to insert malicious scripts into web pages?
Cross-site scripting (XSS) attack
SQL injection attack
Denial of service (DoS) attack
Spoofing attack
What is the main drawback of symmetric encryption?
It requires a complex key management system
It is slower compared to asymmetric encryption
It relies on a single secret key for both encryption and decryption
It is vulnerable to brute force attacks
Which type of encryption uses a key pair consisting of a private key and a public key?
Symmetric encryption
Triple DES encryption
Asymmetric encryption
RSA encryption
What is the main goal of a cross-site scripting (XSS) attack?
To gain unauthorized access to a system
To intercept network traffic between two hosts
To impersonate a trusted user or computer
To execute malicious scripts within a web browser
What is the term used to describe a type of attack where a threat actor masquerades as a trusted user or computer?
Spoofing attack
Shoulder surfing attack
Phishing attack
Tailgating attack
What is the main disadvantage of asymmetric encryption compared to symmetric encryption?
Slower encryption and decryption speeds
Inability to encrypt large files
Complexity in key management
Vulnerability to brute force attacks
What is the primary goal of vulnerability scanners in information security?
To exploit weaknesses in the system
To detect and report non-compliant systems
To prevent social engineering attacks
To establish secure communication channels
Which type of attack involves a threat actor intercepting traffic between two hosts or networks covertly?
Denial of service (DoS) attack
Cross-site scripting (XSS) attack
On-path attack
Tailgating attack
How does a threat actor typically exploit a zero-day vulnerability?
By using a well-known attack vector
By exploiting unpatched or legacy systems
By launching a distributed denial of service (DDoS) attack
By exploiting a vulnerability before a patch is available
What term is used to describe a security control that allows employees to use personal mobile devices to access corporate systems and data?
Bring Your Own Device (BYOD)
Social Engineering
Dumpster Diving
Shoulder Surfing
Which of the following is NOT a characteristic of secure information according to the CIA triad?
Availability
Confidentiality
Integrity
Accountability
Which type of attack involves the threat actor learning a password or PIN by watching the user type it?
Dumpster diving
Spoofing
Shoulder surfing
Tailgating
Have you submitted your standup form yet?
Click the link below
Not yet
I have now.
