wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

A+ - 16A - Explain Attacks, Threats, and Vulnerabilities

Total questions: 2

Worksheet time: 16mins

Name
Class
Date
1-26.

Information security involves controlling access to data, whether in digital or physical formats. The CIA triad, consisting of confidentiality, integrity, and availability, guides secure information practices. Cybersecurity, a subset of information security, focuses on protecting computer systems from attacks. Security policies and controls are implemented to ensure information and systems remain secure, and assessments are conducted to evaluate network security. Vulnerabilities, threats, and risks are key concepts in assessing security.

Configuration baselines are used to minimize vulnerabilities, while security controls like firewalls and antivirus software protect against threats. Software vulnerabilities, especially zero-day vulnerabilities, pose significant risks. Unpatched or end-of-life systems are also vulnerable. Bring Your Own Device (BYOD) policies introduce additional vulnerabilities.

Social engineering techniques, such as impersonation and phishing, exploit human vulnerabilities to gain unauthorized access. Attacks like shoulder surfing and tailgating rely on physical proximity. Cross-site scripting (XSS) and SQL injection are common web application vulnerabilities. Denial of service (DoS) attacks disrupt service availability.

Encryption technologies, including cryptographic hashes and asymmetric encryption, play crucial roles in ensuring data confidentiality and integrity. Digital signatures and key exchange protocols enable secure communication.

1.

What are the three properties of secure information, according to the CIA triad?

a)

Confidentiality, integrity, and authentication

b)

Confidentiality, integrity, and availability

c)

Confidentiality, accessibility, and authenticity

d)

Confidentiality, reliability, and authorization

2.

What term specifically refers to controls that protect against attacks on computer storage and processing systems?

a)

Information security

b)

Cybersecurity

c)

Network security

d)

Data encryption

3.

What is the main purpose of hardening a system?

a)

To make it more user-friendly

b)

To increase its attack surface

c)

To make it more secure

d)

To reduce its accessibility

4.

What is a vulnerability?

a)

A potential threat actor

b)

A security policy

c)

A weakness that could be exploited

d)

A secure configuration

5.

Which type of attack relies on obtaining information about the network and its security controls?

a)

Footprinting

b)

Spoofing

c)

Phishing

d)

Shoulder surfing

6.

What is the purpose of a cryptographic hash?

a)

To encrypt data

b)

To verify data integrity

c)

To generate a digital signature

d)

To exchange encryption keys

7.

What type of encryption uses a single secret key for both encryption and decryption?

a)

Asymmetric encryption

b)

Triple DES

c)

Symmetric encryption

d)

RSA encryption

8.

What is the primary goal of a denial of service (DoS) attack?

a)

To steal data

b)

To gain unauthorized access

c)

To disrupt service availability

d)

To impersonate a trusted user

9.

Which type of attack exploits user input validation vulnerabilities in web applications?

a)

Cross-site scripting (XSS)

b)

Shoulder surfing

c)

Tailgating

d)

SQL injection

10.

What is the main purpose of a digital signature?

a)

To encrypt data

b)

To authenticate the sender

c)

To prevent data tampering

d)

To exchange encryption keys

11.

What is the term used to describe the practice of persuading or intimidating individuals into revealing confidential information or unauthorized access?

a)

Spoofing

b)

Phishing

c)

Social engineering

d)

Footprinting

12.

What is the main purpose of a baseline configuration in information security?

a)

To increase the system's attack surface

b)

To minimize the risk of vulnerabilities

c)

To create a secure backup of data

d)

To allow unrestricted access to all users

13.

Which type of vulnerability allows a threat actor to execute arbitrary code on a system, potentially leading to the installation of malware?

a)

Non-compliant system

b)

Zero-day vulnerability

c)

Spoofing vulnerability

d)

Tailgating vulnerability

14.

What is the primary goal of an evil twin attack?

a)

To harvest authentication information from WiFi users

b)

To intercept network traffic between two hosts

c)

To impersonate a trusted user or computer

d)

To disrupt service availability

15.

Which type of attack involves modifying the HTTP/HTTPS web protocol to insert malicious scripts into web pages?

a)

Cross-site scripting (XSS) attack

b)

SQL injection attack

c)

Denial of service (DoS) attack

d)

Spoofing attack

16.

What is the main drawback of symmetric encryption?

a)

It requires a complex key management system

b)

It is slower compared to asymmetric encryption

c)

It relies on a single secret key for both encryption and decryption

d)

It is vulnerable to brute force attacks

17.

Which type of encryption uses a key pair consisting of a private key and a public key?

a)

Symmetric encryption

b)

Triple DES encryption

c)

Asymmetric encryption

d)

RSA encryption

18.

What is the main goal of a cross-site scripting (XSS) attack?

a)

To gain unauthorized access to a system

b)

To intercept network traffic between two hosts

c)

To impersonate a trusted user or computer

d)

To execute malicious scripts within a web browser

19.

What is the term used to describe a type of attack where a threat actor masquerades as a trusted user or computer?

a)

Spoofing attack

b)

Shoulder surfing attack

c)

Phishing attack

d)

Tailgating attack

20.

What is the main disadvantage of asymmetric encryption compared to symmetric encryption?

a)

Slower encryption and decryption speeds

b)

Inability to encrypt large files

c)

Complexity in key management

d)

Vulnerability to brute force attacks

21.

What is the primary goal of vulnerability scanners in information security?

a)

To exploit weaknesses in the system

b)

To detect and report non-compliant systems

c)

To prevent social engineering attacks

d)

To establish secure communication channels

22.

Which type of attack involves a threat actor intercepting traffic between two hosts or networks covertly?

a)

Denial of service (DoS) attack

b)

Cross-site scripting (XSS) attack

c)

On-path attack

d)

Tailgating attack

23.

How does a threat actor typically exploit a zero-day vulnerability?

a)

By using a well-known attack vector

b)

By exploiting unpatched or legacy systems

c)

By launching a distributed denial of service (DDoS) attack

d)

By exploiting a vulnerability before a patch is available

24.

What term is used to describe a security control that allows employees to use personal mobile devices to access corporate systems and data?

a)

Bring Your Own Device (BYOD)

b)

Social Engineering

c)

Dumpster Diving

d)

Shoulder Surfing

25.

Which of the following is NOT a characteristic of secure information according to the CIA triad?

a)

Availability

b)

Confidentiality

c)

Integrity

d)

Accountability

26.

Which type of attack involves the threat actor learning a password or PIN by watching the user type it?

a)

Dumpster diving

b)

Spoofing

c)

Shoulder surfing

d)

Tailgating

27.

Have you submitted your standup form yet?

Click the link below

https://airtable.com/appg2CeX4DA9Y7hDi/shrUyD9aoryvXZgfu

a)

Not yet

b)

I have now.