WorksheetsModule 3 Quiz – Network Security
Total questions: 29
Worksheet time: 15mins
1. The IT department is reporting that a company web server is receiving an abnormally high number of web page requests from different locations simultaneously. Which type of security attack is occurring?
spyware
phishing
DDoS
social engineering
adware
2. What causes a buffer overflow?
downloading and installing too many software updates at one time
attempting to write more data to a memory location than that location can hold
sending too much information to two or more interfaces of the same device, thereby causing dropped packets
sending repeated connections such as Telnet to a particular device, thus denying other data sources
launching a security countermeasure to mitigate a Trojan horse
3. Which objective of secure communications is achieved by encrypting data?
authentication
confidentiality
integrity
availability
4. What type of malware has the primary objective of spreading across the network?
virus
botnet
Trojan horse
worm
5. Which algorithm can ensure data confidentiality?
MD5
PKI
AES
RSA
6. What three items are components of the CIA triad? (Choose three.)
scalibility
access
confidentiality
integrity
availability
7. Which cyber attack involves a coordinated attack from a botnet of zombie computers?
address spoofing
ICMP redirect
DDoS
MITM
8. What specialized network device is responsible for enforcing access control policies between networks?
firewall
switch
IDS
bridge
9. To which category of security attacks does man-in-the-middle belong?
DoS
access
reconnaissance
social engineering
10. What is the role of an IPS?
to detect patterns of malicious traffic by the use of signature files
to enforce access control policies based on packet content
to filter traffic based on defined rules and connection context
to filter traffic based on Layer 7 information
11. Which type of DNS attack involves the cybercriminal compromising a parent domain and creating multiple subdomains to be used during the attacks?
tunneling
cache poisoning
amplification and reflection
shadowing
12. Which two types of hackers are typically classified as grey hat hackers? (Choose two.)
script kiddies
cyber criminals
vulnerability brokers
state-sponsored hackers
hacktivists
13. What is a significant characteristic of virus malware?
Virus malware is only distributed over the Internet.
Once installed on a host system, a virus will automatically propagate itself to other systems.
A virus can execute independently of the host system.
A virus is triggered by an event on the host system.
14. A cleaner attempts to enter a computer lab but is denied entry by the receptionist because there is no scheduled cleaning for that day. What type of attack was just prevented?
phishing
shoulder surfing
war driving
social engineering
Trojan
15. Which network security statement is true?
All threats come from external networks.
Internal threats are always accidental.
Internal threats are always intentional.
Internal threats can cause greater damage than external threats.
16. What commonly motivates cybercriminals to attack networks as compared to hacktivists or statesponsored hackers?
Fame seeking
Financial gain
Political reasons
Status among peers
17. Which type of hacker is motivated by protesting political and social issues?
Cybercriminal
Hacktivist
Script kiddie
Vulnerability broker
18. What is Trojan horse malware?
It is malware that can only be distributed over the internet.
It is software that appears useful but includes malicious code.
It is software that causes annoying computer problems
It is the most easily detected form of malware.
19. A user receives a call from someone in IT services, asking her to confirm her username and password for auditing purposes. Which security threat does this represent?
Anonymous keylogging
DDoS
Social engineering
Spam
20. What is a ping sweep?
A DNS query and response protocol
A network scanning technique that involves identifying active IP addresses
A type of packet capturing software
A TCP and UDP port scanner to detect open services
21. How are zombies used in security attacks?
Zombies are infected machines that carry out a DDoS attack.
Zombies are maliciously formed code segments used to replace legitimate applications.
Zombies probe a group of machines for open ports to learn which services are running.
Zombies target specific individuals to gain corporate or personal information.
22. What is used to decrypt data that has been encrypted using an asymmetric encryption algorithm public key?
A different public key
A digital certificate
A private key
DH
23. What are the SHA hash generating algorithms used for?
Authentication
Confidentiality
Integrity
Nonrepudiation
24. Which of the following is true of an IPS?
It can stop malicious packets.
It has no impact on latency.
It is deployed in offline mode.
It is primarily focused on identifying possible incidents.
25. What is the term used to describe unethical criminals who compromise computer and network security for personal gain or for malicious reasons?
Black hat hackers
Hacktivists
Script kiddies
Vulnerability broker
26. What is the term used to describe a potential danger to a company’s assets, data, or network functionality?
Asymmetric encryption algorithm
Exploit
Threat
Vulnerability
27. What term is used to describe a guarantee that a message is not a forgery and does actually come from the person who is supposed to have sent it?
Data nonrepudiation
Exploit
Mitigation
Origin authentication
28. What term is used to describe a mechanism that takes advantage of a vulnerability?
Asymmetric encryption algorithm
Exploit
Threat
Vulnerability
29. Which of the following guarantees that the sender cannot repudiate, or refute, the validity of a message sent?
Data nonrepudiation
Exploit
Mitigation
Origin authentication
