NEW
Font size
WorksheetsChapter Eight Practice Quiz - Info Sec
Total questions: 65
Worksheet time: 33mins
What is often referred to as the "weak link" in information security?
Firewalls
Antivirus software
People
Encryption methods
What type of attack relies on manipulating people to gain information or access to facilities?
Phishing
Social engineering
Malware
Denial of Service
Which of the following is NOT a common tactic used in social engineering attacks?
Sending sensitive information via unprotected channels
Handing over passwords
Posting important data in conspicuous places
Using strong encryption methods
What is a social engineering attack where an attacker calls in a panicked voice and asks for sensitive information?
Phishing
Pretexting
Baiting
Tailgating
What are the two primary sources of information to look at when protecting people and commercial organizations?
Human intelligence and open source intelligence
Firewalls and antivirus software
Encryption methods and secure passwords
Physical security and network security
What is Human Intelligence (HUMINT)?
Data gathered from electronic devices
Data gathered by talking to people
Data gathered from social media
Data gathered from job postings
Which of the following is NOT a method to collect HUMINT?
Observing people's schedules
Using torture
Tricking participants with scams
Analyzing job postings
What is Open Source Intelligence (OSINT)?
Information collected from publicly available sources
Information collected from private conversations
Information collected from encrypted databases
Information collected from physical surveillance
Which of the following is a primary source of information for social engineering attacks?
Encrypted emails
Job postings
Private conversations
Physical surveillance
What can attackers use to set up social engineering attacks based on a target's skills or interests?
Résumés
Encrypted emails
Private conversations
Physical surveillance
How can attackers use social media for OSINT?
By hacking into private accounts
By following someone's activities and social contacts
By accessing encrypted databases
By conducting physical surveillance
What example is provided in the text to illustrate how attackers can take advantage of social media tools?
The 2016 US presidential election
The 2020 US presidential election
The 2012 US presidential election
The 2008 US presidential election
How many Facebook ads did the Russian-based company Internet Research Agency purchase to incite tensions during the 2016 US presidential election?
1,500
2,500
3,500
4,500
What type of records can provide a wealth of information about a target, including evidence of mortgages, marriages, divorces, legal proceedings, and parking tickets?
Social media records
Public records
Private records
Financial records
Which search engine is mentioned as an excellent resource for information gathering, particularly when attackers make use of advanced search operators?
Bing
Yahoo
DuckDuckGo
What does the search operator "filetype:pdf" do?
Limits results to a specific site
Finds pages containing a word or words in the URL
Limits results to a specific file type
Finds pages containing a word or words
What is the purpose of the Google Hacking Database mentioned in the text?
To store personal information
To find specific vulnerabilities or security issues
To hack into Google accounts
To create new search engines
What type of data can file metadata reveal?
Only timestamps and file statistics
Only usernames and server names
Timestamps, file statistics, usernames, server names, network file paths, and deleted or updated information
Only network file paths and deleted information
Which tool is mentioned as being able to view and edit EXIF data?
EnCase
Shodan
Maltego
Exiftool
What kind of information might image files produced by devices containing GPS information include?
Only timestamps
Location coordinates
File statistics
Network file paths
What is Shodan primarily used for?
Editing image files
Searching for information saved on internet-connected devices
Recovering deleted files
Viewing EXIF data
Which of the following is a web-based search engine that looks for information saved on internet-connected devices?
EnCase
Exiftool
Shodan
Maltego
What is the purpose of using transforms in intelligence-gathering tools like Maltego?
To discover information related to information that you already have.
To encrypt data for secure communication.
To delete unnecessary data from the database.
To create new data from scratch.
What kind of intelligence is gathered from geographical information, typically from satellites?
Geospatial intelligence (GEOINT)
Signals intelligence (SIGINT)
Technical intelligence (TECHINT)
Financial intelligence (FININT)
Which type of intelligence involves data gathered by intercepting signals between people or systems?
Signals intelligence (SIGINT)
Technical intelligence (TECHINT)
Financial intelligence (FININT)
Cyber intelligence (CYBINT)
What does MASINT stand for?
Measurement and signature intelligence
Military and strategic intelligence
Management and security intelligence
Measurement and security intelligence
Which type of intelligence is often acquired from financial institutions?
Financial intelligence (FININT)
Technical intelligence (TECHINT)
Geospatial intelligence (GEOINT)
Cyber intelligence (CYBINT)
What is the primary focus of technical intelligence (TECHINT)?
Equipment, technology, and weapons
Financial transactions
Geographical information
Social engineering attacks
What is pretexting in the context of social engineering?
Using gathered information to assume a fake identity and convince targets to give up sensitive information.
Sending unsolicited emails to collect personal information.
Creating fake websites to trick users into providing personal information.
Installing malware on a target's system through malicious links.
Which type of interaction requires a heightened level of attention to details such as body language?
Indirect encounters
Face-to-face encounters
Email interactions
Texting
What advantage does pretexting give social engineers?
Ability to create fake websites
Ability to drop names and provide details about the organization
Ability to send unsolicited emails
Ability to install malware on the target's system
What is phishing?
A technique where attackers use gathered information to assume a fake identity.
A technique where attackers use electronic communications to collect personal information or install malware.
A technique where attackers create fake websites to trick users.
A technique where attackers send unsolicited emails to targets.
What do fake sites used in web-based phishing attacks typically resemble?
Government websites
Well-known websites such as banking, social media, or shopping sites
Personal blogs
Educational websites
What has improved security in recent years to render phishing attacks more difficult?
Better antivirus software
Improved browser security and warnings
Increased public awareness
Stricter email regulations
What is spear phishing?
A technique where attackers use gathered information to assume a fake identity.
A technique where attackers use electronic communications to collect personal information or install malware.
A targeted phishing attack against specific companies, organizations, or people.
A technique where attackers create fake websites to trick users.
What is the primary goal of spear phishing attacks?
To trick a small percentage of recipients with poorly constructed emails
To send clean emails containing expected logos and graphics
To steal credentials and log the target into the real site
To send mass emails to a large group of recipients
What is physical tailgating in the context of security?
Sending phishing emails to employees
Following someone through an access control point without proper credentials
Using technical tools to ensure strong passwords
Conducting security training programs
Which of the following is NOT a method used by attackers to aid in tailgating?
Using props
Employing psychology to gain sympathy
Sending clean emails with expected logos
Knowing which equipment to use
What is the purpose of building security awareness with security training programs?
To ensure employees use technical tools for strong passwords
To conduct instructor-led or computer-based lessons followed by quizzes
To allow attackers to play on the sympathies of others
To send clean emails containing expected logos and graphics
What is a challenge mentioned in the text regarding the use of technical tools for passwords?
They are too expensive to implement
They cannot easily control what users choose as passwords
They are not effective in preventing tailgating
They require extensive training programs
What is one harmful behavior related to password usage mentioned in the text?
Using the same password for multiple accounts
Changing passwords frequently
Using passwords with special characters
Writing passwords in a notebook
What should users be suspicious of according to the text?
Emails from known contacts
Unusual requests or emails in their inboxes
Regular system updates
Messages from their IT department
What is one of the best ways to tackle poor password hygiene?
Forcing users to change passwords monthly
Educating users about creating strong passwords
Using biometric authentication
Disabling password requirements
What should users do when faced with even the slightest doubt about an email or request?
Ignore the email or request
Trust the sender immediately
Verify the authenticity of the email or request
Forward the email to all contacts
What is the potential consequence of an attacker compromising a password database?
The attacker gains access to the user's email and decrypted password
The user is forced to change their password
The attacker is blocked from the system
The user receives a warning message
What is a common misconception uneducated users have about connecting to networks in different locations?
They believe all networks are equally secure.
They think connecting to a network in a hotel is safer than at home.
They assume connecting to a network in a conference room at work is the same as connecting to a network in an airport.
They believe connecting to a network in a coffee shop is more secure than at work.
What should users be educated about to protect the enterprise network?
How to connect their iPads to the production network.
How to connect to any available network.
Not allowing foreign devices to connect to the enterprise network.
How to use any network without restrictions.
What is a recommended solution to protect corporate resources on outside networks?
Use any available network without restrictions.
Implement a VPN that allows users to access the corporate network.
Connect to the network at local coffee shops.
Share sensitive data over public networks.
What should users be taught to avoid when dealing with email attachments?
Opening attachments from known contacts.
Opening attachments containing file types like EXE, ZIP, and PDF.
Opening attachments from people they don't know.
Both B and C.
Which of the following is NOT a red flag when surfing the web?
Email attachments from people they don't know.
Web links using shortened URLs such as bttp://bi.ly/.
Web links with names that differ slightly from known ones.
Web links from trusted sources.
What should you do if you expect your users to follow the rules?
Send an email to all users containing a link to a lengthy policy.
Condense the most critical part of your policy into a kind of crib notes or highlights reel.
Ignore the rules and hope users follow them.
Only communicate the rules verbally.
What is a clean desk policy?
A policy that allows employees to leave sensitive information on their desks overnight.
A policy that states sensitive information shouldn't be left unattended on a desk for any significant period of time.
A policy that requires employees to clean their desks every day.
A policy that allows employees to store sensitive information on their desks.
How can you make a training presentation more engaging?
By making the lecture portion longer.
By conducting an interactive quiz show-style game on the material.
By only using posters and newsletters.
By avoiding any form of competition.
What should you do to ensure employees use personal equipment properly in the workplace?
Allow them to use it on the same network as the company's production systems.
Set rules for when and how employees can use personal equipment.
Allow them to use any device without restrictions.
Ignore the use of personal equipment.
What is one way to effectively communicate policies to users?
Send a lengthy email and have them attest to having read it.
Use posters, giveaways, and newsletters to present the information.
Only use verbal communication.
Avoid communicating policies altogether.
Why are people the weak link in a security program?
Because they can be easily replaced
Because they can be targeted by social engineering attacks
Because they are not important in security
Because they are always careless
Define tailgating. Why is it a problem?
It is a type of phishing attack; it can steal data
It is following someone into a restricted area; it can lead to unauthorized access
It is a type of malware; it can damage systems
It is a form of password attack; it can compromise accounts
How can you more effectively reach users in your security awareness and training efforts?
By using technical jargon
By making the information engaging and relevant
By ignoring their feedback
By using complex training materials
Why shouldn't you allow employees to attach personal equipment to your organization's network?
It can slow down the network
It can lead to unauthorized access and security breaches
It can increase electricity usage
It can make the network faster
How might you train users to recognize phishing?
By showing them examples of phishing emails
By ignoring phishing threats
By using only technical controls
By not discussing phishing at all
Why is it important not to use the same password for all your accounts?
It makes it easier to remember passwords
It reduces the risk of multiple accounts being compromised
It makes logging in faster
It is recommended by security experts
What is pretexting?
A type of malware
A social engineering technique where an attacker creates a fabricated scenario to steal information
A method of encrypting data
A way to secure wireless networks
Why might using the wireless network in a hotel with a corporate laptop be dangerous?
It can be slow
It can lead to data breaches and security risks
It can be expensive
It can improve network speed
Why might clicking a shortened URL from a service such as bit.ly be dangerous?
It can lead to unexpected websites and potential security threats
It can make the URL longer
It can improve website loading speed
It can increase internet usage
Why is it important to use strong passwords?
To make them easy to remember
To prevent unauthorized access and enhance security
To make logging in faster
To reduce the need for password changes
