Font size
WorksheetsCybersecurity Units 2-4 Review
Total questions: 85
Worksheet time: 3hrs 33mins
A set of methods used by cyber criminals to deceive individuals into handing over information that they can use for fraudulent purposes’ is a definition of what?
Impersonatin
Shoulder Surfing
Phishing
Social Engineering
What is one way somebody could protect themselves from shoulder surfing?
share your pin with someone you trust
create a pin that is easy to remember
have a pin that is the same as your friends
be aware of who is around you
While waiting in the lobby of your building for a guest, you notice a man in a red shirt standing close to a locked door with a large box in his hands. He waits for someone else to come along and open the locked door and then proceeds to follow her inside. What type of social engineering attack have you just witnessed?
Impersonation
Phishing
Boxing
Tailgating
A user in your organization contacts you to see if there’s any update to the “account compromise” that happened last week. When you ask him to explain what he means, and the user tells you he received a phone call earlier in the week from your department and was asked to verify his user ID and password. The user says he gave the caller his user ID and password. This user has fallen victim to what specific type of attack?
Spear phishing
Vishing
Phishing
Replication
Coming into your office, you overhear a conversation between two security guards. One guard is telling the other she caught several people digging through the trash behind the building early this morning. The security guard says the people claimed to be looking for aluminum cans, but only had a bag of papers—no cans. What type of attack has this security guard witnessed?
Spear phishing
Pharming
Dumpster diving
Rolling refuse
Which of the following is a type of social engineering attack in which an attacker attempts to obtain sensitive information from a user by masquerading as a trusted entity in an e-mail?
Phishing
Pharming
Spam
Vishing
Which of the following is/are psychological tools used by social engineers to create false trust with a target?
Impersonation
Urgency or scarcity
Authority
All of the above
Your boss thanks you for pictures you sent from the recent company picnic. You ask him what he is talking about, and he says he got an e-mail from you with pictures from the picnic. Knowing you have not sent him that e-mail, what type of attack do you suspect is happening?
Phishing
Spear phishing
Reconnaissance
Impersonation
Lisa received a phone call at work from someone identifying themselves as a person who sells the company hardware regularly. He said he's calling customers to inform them of a problem with database servers they've sold, but he said the problem only affects servers running a specific operating system version. He asks Lisa what OS versions the company is running. Which BEST describes this tactic?
Pretexting
Tailgating
Pharming
Smishing
A man in a maintenance uniform walked up to your organization's receptionist desk. He said he was called by the CIO (Chief Information Officer) and asked to fix an issue with the phones and needed access to the wiring closet. The receptionist asked the man to show his building access badge, and then she verified that he was on the list of approved personnel to access this secure area. What type of attack will the checks the receptionist performed prevent?
Tailgating
Phishing
Impersonation
Whaling
A company's security policy requires employees to place all discarded paper documents in containers for temporary storage. These papers are later burned in an incinerator. Which of the following attacks are these actions MOST likely trying to prevent?
Shoulder surfing
Tailgating
Smishing
Dumpster Diving
Homer, the Chief Financial Officer of a bank, received an email from Lisa, the company's Chief Executive Officer (CEO). Lisa states she is on vacation and that she lost her purse and all her credit cards. She asks Homer to transfer $5,000 to her account. Which of the following best identifies this attack?
Phishing
Vishing
Smishing
Whaling
Homer has been looking for the newest version of a popular smartphone. However, he can't find it in stock anywhere. Today, he received an email advertising the smartphone. After clicking the link, his system was infected with malware. Which of the following principles is the email sender employing?
Authority
Intimidation
Scarcity
Trust
How can we make sure an email is not a phishing scam?
(select all that apply)
Check 'from' address
Hover over links to check URL
Be careful opening attachments
Reply asking for more information
What does OSINT stand for?
Open Source Intelligence
Open Source Interals
Official Secure Information Neutralisation
Official Standard Intelligence Technology
What types of information are hackers looking for when performing an OSINT attack?
(select all that apply)
Addresses
Jobs
Devices used
Family
How funny someone is
Which of these can help protect against OSINT attacks?
Don't post personal information online
Never post fake information
Trust everyone online
Uncheck all privacy options
Scammers may (a) vendors, clients, or executives to (b) into (c) or sharing sensitive (d) .
Phishing is a technique where attackers (a) legitimate entities, such as banks or businesses, to (b) into (c) sensitive (d) like passwords or credit card details.
A data (a) attack is where an attacker (b) all (c) between two parties. To the users, appears as if they are connected directly with each other, while the attacker secretly (d) and controls the information being exchanged.
Phishing attacks often come in the form of (a) emails, but they can also occur via (b) , SMS (smishing) or phone calls. During a cybersecurity workshop, Daniel, Maya, and Abigail learned that by (c) into disclosing confidential information, attackers can (d) access to the university's systems or networks.
deceptive
text messages
tricking employees
gain unauthorised
What is the purpose of a vulnerability assessment?
To identify and mitigate vulnerabilities in a system
To analyze the security of digital products
To reduce the attack surface of a system
To harden a system against cyber attacks
William, a cybersecurity student, is working on a project to analyze vulnerability data. He needs to use a database that is commonly used as an industry repository of vulnerability data. Which database should he use?
Common Vulnerability and Exposure (CVE) database
National Vulnerability Database (NVD)
Microsoft Baseline Security Analyzer (MBSA)
Cybersecurity & Infrastructure Security Agency (CISA)
What is the purpose of system hardening?
To secure user access and backups
To identify and mitigate vulnerabilities
To analyze the security of digital products
To reduce the attack surface of a system
What is the purpose of user access control (UAC) settings?
To restrict user actions and limit vulnerabilities
To secure user access and backups
To analyze the security of digital products
To reduce the attack surface of a system
Abigail received an email warning about the increasing threat of ransomware and data loss. She wants to know, what is the first level of defense she should consider?
Creating system images of her computer
Using sync services like Dropbox or Google Drive
Performing regular software updates
Maintaining regular backups of her data
Charlotte, Anika, and Mason are part of the IT team in a company. They are discussing the best practices for securing user access. Which of the following practices mentioned by them is NOT recommended?
Severely restrict administrative rights
Implement strong password policies
Grant unlimited access to all users
Follow the least privilege principle
What is the purpose of system images?
To restrict user actions and limit vulnerabilities
To secure user access and backups
To analyze the security of digital products
To create backups that include the operating system
What is the primary function of the least privilege principle in system security?
To grant all users unrestricted access
To limit user access based on their role and responsibilities
To ensure regular software updates
To backup important data regularly
Lists directory contents. You will use this to display information about files and
directories.
(a)
Changes the current directory to dir. If you execute it without specifying
a directory, it changes the current directory to your home directory. This is how you
navigate around the system.
(a)
Displays the present working directory name. If you don't know what directory
you are in, it will tell you.
(a)
Concatenates and displays files. This is the command you run to view
the contents of a file.
(a)
Displays arguments to the screen
(a)
Displays the online manual for command.
(a)
How do you change permissions for a file?
chmod
chown
chper
permission
How can you show hidden files?
ls -a
dir
show -h
unhide
A command-line command in Linux that allows to search files for lines containing a match to a given pattern is called:
grep
find
cat
touch
In order to create an empty file one must use (a)
The output of whoami is a:
string
file
directory
username
Display contents of a file hello.txt
(a)
What is ASCII for
a numerical code for letters
A way of checking binary numbers
American writing rules
Chinese letters
Which of the following number systems do we tend to use in computing?
Decimal
Binary
Hexadecimal
Quinary
When viewing data if a 0x comes up we know the next value is represented as (a)
What is 0x110 represented as a decimal?
272
25616
110
284
How many bits are in a byte?
1
2
4
8
The smallest unit of information in a computer
Byte
Bit
Pixel
It's too small I can't see it
The image above most likely represents which type of number system?
Hexadecimal Number
Decimal Number
Octal Number
Binary Number
What is the decimal equivalent of the hexadecimal digit B?
10
11
12
13
Why do we need to encode all data in binary?
Because binary is very small
Because computers only understand binary
Because binary is very fast
Because binary is space efficient
Hexadecimal number system is a base (a) system
What is a potential threat of using USB storage devices?
Introduction of viruses to a system
Increased system performance
Enhanced data security
Improved file transfer speed
William, a cybersecurity student, is working on a project to analyze vulnerability data. He needs to use a database that is commonly used as an industry repository of vulnerability data. Which database should he use?
Common Vulnerability and Exposure (CVE) database
National Vulnerability Database (NVD)
Microsoft Baseline Security Analyzer (MBSA)
Cybersecurity & Infrastructure Security Agency (CISA)
This is to minimize the risk
mitigate
vulnerability
exploit
redundancy
A security flaw, glitch, or weakness found in software code that could be exploited by an attacker
vulnerability
exploit
redundancy
mitigate
specific code or attack technique that uses a vulnerability to carry out an attack or gain unauthorized access
vulnerability
exploit
redundancy
mitigate
a tweak to the OS code that will fix an issue in how it runs or compatibility with devices and applications
Patch / Update
Hotfix
Critical
Security
fix for a bug that is affecting OS functionality
Patch / Update
Hotfix
Critical
Security
By disabling unnecessary services, the performance can be improved significantly, especially on computers with low system resources.
True
False
Common Device Hardening Techniques
Anti-virus Software
Scans for malware and removes it
Encryption
Scrambles the contents of a message or file
Firewalls
Monitors and blocks unwanted data accessing the system
Auto -Installing software Updates
Updates include patches which fixes know vulnerabilities
Blocking USB ports
Stops users transferring malware using a physical medium
Another method of device hardening is (a) user (b) . This involves (c) old user accounts
