Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CYB125 - Ch3

Total questions: 36

Worksheet time: 21mins

Name
Class
Date
1.

Adam is evaluating the security of a web server before it goes live. He believes that an issue in the code allows a cross-site scripting attack against the server. What term describes the issue that Adam discovered?

a)

Threat

b)

Vulnerability

c)

Risk

d)

Impact

2.

Which term describes an action that can damage or compromise an asset?

a)

Risk

b)

Vulnerability

c)

Countermeasure

d)

Threat

3.

Purchasing an insurance policy is an example of the (a)   risk management strategy.

4.

Aditya is the security manager for a mid-sized business. The company has suffered several serious data losses when laptops were stolen. Aditya decides to implement full disk encryption on all laptops. What risk response did Aditya take?

a)

Reduce

b)

Transfer

c)

Accept

d)

Avoid

5.

Residual Risk describes the risk that exists after an organization has performed all planned countermeasures and controls?

a)

True

b)

False

6.

Violet deploys an intrusion prevention system (IPS) on her network as a security control. What type of control has Violet deployed?

a)

Detective

b)

Preventive

c)

Corrective

d)

Deterrent

7.

What is an example of an alteration threat?

a)

Espionage

b)

System or data modification

c)

Intentional information leak

d)

Denial of service

8.

What type of attack against a web application uses a newly discovered vulnerability that is not patchable?

a)

Structured Query Language (SQL) injection

b)

Cross-site scripting (XSS)

c)

Cross-site request forgery (CSRF)

d)

Zero-day attack

9.

Which type of attack involves eavesdropping on transmissions and redirecting them for unauthorized use?

a)

Interception

b)

Interruption

c)

Fabrication

d)

Modification

10.

A hacker has stolen logon IDs and passwords. The hacker is now attempting to gain unauthorized access to a public-facing web application by using the stolen credentials one by one. What type of attack is taking place?

a)

Birthday attack

b)

Replay attack

c)

Phreaking

d)

Credential harvesting

11.

Which attack is typically used specifically against password files that contain cryptographic hashes?

a)

Hijack

b)

Replay

c)

Birthday

d)

Social engineering

12.

Brian notices an attack taking place on his network. When he digs deeper, he realizes that the attacker has a physical presence on the local network and is forging Media Access Control (MAC) addresses. Which type of attack is most likely taking place?

a)

Address resolution protocol (ARP) poisoning

b)

Internet Protocol (IP) address spoofing

c)

Uniform resource locator (URL) hijacking

d)

Christmas attack

13.

In which type of attack does the attacker attempt to take over an existing connection between two systems?

a)

Man-in-the-middle attack

b)

Uniform resource locator (URL) hijacking

c)

Session hijacking

d)

Typosquatting

14.

Which type of attack involves capturing data packets from a network and retransmitting them to produce an unauthorized effect? The receipt of duplicate, authenticated Internet Protocol (IP) packets may disrupt service or produce another undesired consequence.

a)

Replay

b)

Man-in-the-middle

c)

Hijacking

d)

IP spoofing

15.

An attacker attempting to break into a facility pulls the fire alarm to distract the security guard manning an entry point. Which type of social engineering attack is the attacker using?

a)

Vishing

b)

Urgency

c)

Whaling

d)

Authority

16.

Barry discovers that an attacker is running an access point in a building adjacent to his company. The access point is broadcasting the security set identifier (SSID) of an open network owned by the coffee shop in his lobby. Which type of attack is likely taking place?

a)

Evil twin

b)

Near field communication

c)

Bluesnarfing

d)

Jamming/interference

17.

True or False? Not all risks are inherently bad; some risks can lead to positive results.

a)

True

b)

False

18.

True or False? Impact refers to the amount of risk or harm caused by a threat or vulnerability that is exploited by a perpetrator.

a)

True

b)

False

19.

True or False? Safeguards address gaps or weaknesses in the controls that could otherwise lead to a realized threat.

a)

True

b)

False

20.

True or False? Corrective controls are implemented to address a threat in place that does not have a straightforward risk-mitigating solution.

a)

True

b)

False

21.

True or False? Preventive controls merely attempt to suggest that a subject not take a specific action, whereas corrective controls do not allow the action to occur.

a)

True

b)

False

22.

When servers need operating system upgrades or patches, administrators take them offline intentionally so they can perform the necessary work without risking malicious attacks.

a)

True

b)

False

23.

Theft of intellectual property and its release to competitors or to the public can nullify an organization's competitive advantage.

a)

True

b)

False

24.

An alteration threat violates information integrity.

a)

True

b)

False

25.

Transmitting private or sensitive data unencrypted is a risk in both the Local Area Network (LAN) and Wide Area Network (WAN) Domains of a typical IT infrastructure.

a)

True

b)

False

26.

In a browser or uniform resource locator (URL) hijacking attack, users are directed to websites other than what they requested, usually to fake pages that attackers have created.

a)

True

b)

False

27.

Anti-malware programs and firewalls cannot detect most phishing scams because the scams do not contain suspect code.

a)

True

b)

False

28.

A phishing email is a fake or bogus email intended to trick the recipient into clicking on an embedded link or opening an email attachment.

a)

True

b)

False

29.

In a masquerade attack, one user or computer pretends to be another user or computer.

a)

True

b)

False

30.

A dictionary password attack is a type of attack in which one person, program, or computer disguises itself as another person, program, or computer to gain access to some resource.

4 lines
31.

A man-in-the-middle attack takes advantage of the multihop process used by many types of networks.

a)

True

b)

False

32.

A phishing attack "poisons" a domain name on a domain name server (DNS).

a)

True

b)

False

33.

A smishing attack is a type of phishing attack involving voice communication.

a)

True

b)

False

34.

A social engineering consensus tactic relies on the position that "everyone else has been doing it" as proof that it is okay or acceptable to do.

a)

True

b)

False

35.

Bluejacking is an attack in which wireless traffic is sniffed between Bluetooth devices.

a)

True

b)

False

36.

In a watering-hole attack, a targeted user is lured to a commonly visited website on which malicious code has been planted.

a)

True

b)

False