WorksheetsCYB125 - Ch3
Total questions: 36
Worksheet time: 21mins
Adam is evaluating the security of a web server before it goes live. He believes that an issue in the code allows a cross-site scripting attack against the server. What term describes the issue that Adam discovered?
Threat
Vulnerability
Risk
Impact
Which term describes an action that can damage or compromise an asset?
Risk
Vulnerability
Countermeasure
Threat
Purchasing an insurance policy is an example of the (a) risk management strategy.
Aditya is the security manager for a mid-sized business. The company has suffered several serious data losses when laptops were stolen. Aditya decides to implement full disk encryption on all laptops. What risk response did Aditya take?
Reduce
Transfer
Accept
Avoid
Residual Risk describes the risk that exists after an organization has performed all planned countermeasures and controls?
True
False
Violet deploys an intrusion prevention system (IPS) on her network as a security control. What type of control has Violet deployed?
Detective
Preventive
Corrective
Deterrent
What is an example of an alteration threat?
Espionage
System or data modification
Intentional information leak
Denial of service
What type of attack against a web application uses a newly discovered vulnerability that is not patchable?
Structured Query Language (SQL) injection
Cross-site scripting (XSS)
Cross-site request forgery (CSRF)
Zero-day attack
Which type of attack involves eavesdropping on transmissions and redirecting them for unauthorized use?
Interception
Interruption
Fabrication
Modification
A hacker has stolen logon IDs and passwords. The hacker is now attempting to gain unauthorized access to a public-facing web application by using the stolen credentials one by one. What type of attack is taking place?
Birthday attack
Replay attack
Phreaking
Credential harvesting
Which attack is typically used specifically against password files that contain cryptographic hashes?
Hijack
Replay
Birthday
Social engineering
Brian notices an attack taking place on his network. When he digs deeper, he realizes that the attacker has a physical presence on the local network and is forging Media Access Control (MAC) addresses. Which type of attack is most likely taking place?
Address resolution protocol (ARP) poisoning
Internet Protocol (IP) address spoofing
Uniform resource locator (URL) hijacking
Christmas attack
In which type of attack does the attacker attempt to take over an existing connection between two systems?
Man-in-the-middle attack
Uniform resource locator (URL) hijacking
Session hijacking
Typosquatting
Which type of attack involves capturing data packets from a network and retransmitting them to produce an unauthorized effect? The receipt of duplicate, authenticated Internet Protocol (IP) packets may disrupt service or produce another undesired consequence.
Replay
Man-in-the-middle
Hijacking
IP spoofing
An attacker attempting to break into a facility pulls the fire alarm to distract the security guard manning an entry point. Which type of social engineering attack is the attacker using?
Vishing
Urgency
Whaling
Authority
Barry discovers that an attacker is running an access point in a building adjacent to his company. The access point is broadcasting the security set identifier (SSID) of an open network owned by the coffee shop in his lobby. Which type of attack is likely taking place?
Evil twin
Near field communication
Bluesnarfing
Jamming/interference
True or False? Not all risks are inherently bad; some risks can lead to positive results.
True
False
True or False? Impact refers to the amount of risk or harm caused by a threat or vulnerability that is exploited by a perpetrator.
True
False
True or False? Safeguards address gaps or weaknesses in the controls that could otherwise lead to a realized threat.
True
False
True or False? Corrective controls are implemented to address a threat in place that does not have a straightforward risk-mitigating solution.
True
False
True or False? Preventive controls merely attempt to suggest that a subject not take a specific action, whereas corrective controls do not allow the action to occur.
True
False
When servers need operating system upgrades or patches, administrators take them offline intentionally so they can perform the necessary work without risking malicious attacks.
True
False
Theft of intellectual property and its release to competitors or to the public can nullify an organization's competitive advantage.
True
False
An alteration threat violates information integrity.
True
False
Transmitting private or sensitive data unencrypted is a risk in both the Local Area Network (LAN) and Wide Area Network (WAN) Domains of a typical IT infrastructure.
True
False
In a browser or uniform resource locator (URL) hijacking attack, users are directed to websites other than what they requested, usually to fake pages that attackers have created.
True
False
Anti-malware programs and firewalls cannot detect most phishing scams because the scams do not contain suspect code.
True
False
A phishing email is a fake or bogus email intended to trick the recipient into clicking on an embedded link or opening an email attachment.
True
False
In a masquerade attack, one user or computer pretends to be another user or computer.
True
False
A dictionary password attack is a type of attack in which one person, program, or computer disguises itself as another person, program, or computer to gain access to some resource.
A man-in-the-middle attack takes advantage of the multihop process used by many types of networks.
True
False
A phishing attack "poisons" a domain name on a domain name server (DNS).
True
False
A smishing attack is a type of phishing attack involving voice communication.
True
False
A social engineering consensus tactic relies on the position that "everyone else has been doing it" as proof that it is okay or acceptable to do.
True
False
Bluejacking is an attack in which wireless traffic is sniffed between Bluetooth devices.
True
False
In a watering-hole attack, a targeted user is lured to a commonly visited website on which malicious code has been planted.
True
False
