NEW
Font size
WorksheetsEthical Hacking - Social Engineering
Total questions: 66
Worksheet time: 33mins
What is Social Engineering?
The use of technology to improve social interactions
Any action that influences a person to do something that may not be in their best interest
The process of designing social media platforms
A method of constructing social policies
What is the primary goal of Social Engineering?
To enhance user experience on social media
To gain access to restricted computer systems, areas, or sensitive information
To develop new social policies
To improve communication between people
Which of the following is NOT a method used in Social Engineering?
Con-tricks
Manipulation
Deceit
Physical force
What is often the intention behind Social Engineering?
To create new social networks
To steal or commit fraud
To improve public relations
To develop new software
What is phishing?
The act of catching fish in a river
The act of pretending to be a legitimate organization to steal sensitive information
The act of sending legitimate emails to customers
The act of creating a new bank account
Which of the following is NOT a sign of phishing?
Ambiguous Greeting
Poor Spelling/Grammar
Clear and professional language
Tempting offers
Phishing emails often ask for which type of information?
Favorite color
Bank details or usernames and passwords
Movie preferences
Travel history
Which of the following is a common characteristic of phishing emails?
Sense of urgency
Detailed company history
Personal anecdotes
High-quality images
What is a common tactic used in phishing emails to trick recipients?
Offering free software
Providing accurate weather forecasts
Sending ambiguous greetings
Sharing cooking recipes
What is spear phishing?
A phishing attack targeting thousands of random people
A phishing attack targeting a few key individuals
A type of cyber attack that involves physical harm
A method of fishing using a spear
What do cyber criminals do in spear phishing attacks?
Send out mass emails to random people
Conduct reconnaissance to gather information about key individuals
Use physical force to obtain information
Hack into random computers without any specific target
What makes spear phishing attacks seem genuine?
The use of advanced hacking tools
The inclusion of a small nugget of information about the personnel involved
The large number of emails sent out
The use of physical threats
How do spear phishing attacks differ from regular phishing attacks?
They target thousands of random people
They target a few key individuals
They do not involve any preparation
They are less harmful than regular phishing attacks
What is the act of forging an e-mail header so that it appears to originate from someone else called?
Phishing
E-mail Spoofing
Social Engineering
Psychological Manipulation
Which technique involves getting someone to do something they should not by preying on human weaknesses?
Phishing
E-mail Spoofing
Social Engineering
Psychological Manipulation
What is a common technique used in conjunction with e-mail spoofing?
Phishing
Social Engineering
Psychological Manipulation
Hacking
Why are people more likely to open and trust an e-mail that has been spoofed?
Because it looks professional
Because it appears to be sent from someone they know
Because it contains a catchy subject line
Because it is marked as important
What does psychological manipulation often prey on?
Human strengths
Human weaknesses
Human intelligence
Human curiosity
What is tailgating in the context of social engineering?
A method of gaining access to a restricted area by waiting for someone with authorization to open the door and then following them in.
A method of hacking into a computer system remotely.
A technique used to steal someone's identity online.
A way to intercept phone calls and messages.
In which situations is suspicion avoided when using tailgating as a social engineering technique?
When there are crowds of people.
When there are security cameras.
When there are no people around.
When there are security guards present.
Which of the following is NOT a method mentioned for avoiding suspicion while tailgating?
Dressing as delivery staff carrying a heavy-looking box.
Putting on overalls.
Carrying clipboards and pushing trolleys.
Wearing a security uniform.
What is the method called that involves raiding bins to find sensitive information?
Phishing
Dumpster Diving
Watering Hole Attack
Baiting
Which social engineering technique involves observing websites often visited by a victim and infecting those sites with malware?
Phishing
Dumpster Diving
Watering Hole Attack
Pretexting
What type of information might be found through dumpster diving?
Encrypted passwords
Bank statements with sort codes and account numbers
Social media profiles
Encrypted emails
What is a common characteristic of a watering hole attack?
It involves physical theft
It targets websites often visited by a specific group
It requires direct communication with the victim
It uses social media to gather information
What is an insider threat?
A threat that originates from outside the organization.
A threat that originates from someone inside the organization.
A threat that originates from a competitor.
A threat that originates from a natural disaster.
What is an accidental insider threat?
Damage caused by a natural disaster.
Damage caused by a competitor.
Damage caused by an employee accidentally divulging or deleting data.
Damage caused by a cyber attack.
What is a malicious insider threat?
Deliberate actions intended to cause harm or disruption to the company.
Accidental actions that cause harm to the company.
Natural disasters that disrupt company operations.
Competitor actions that harm the company.
Which of the following could be an example of a malicious insider threat?
An employee accidentally deleting important files.
A natural disaster causing damage to company property.
A disgruntled employee who wishes to damage the organization for any reason.
A competitor launching a cyber attack.
What is the primary focus of cyber resilience?
Preventing cyber attacks
Ensuring no security breaches occur
Preparing for and recovering from security breaches
Eliminating all cyber threats
How does cyber resilience differ from preventing a cyber attack?
It assumes no attacks will occur
It focuses on preventing all attacks
It assumes a security breach will happen and prepares for it
It eliminates the need for security measures
What does cyber resilience assume about the individual or organization?
They will never face a security breach
They will suffer a security breach
They are immune to cyber attacks
They do not need to prepare for cyber threats
What is the ultimate goal of cyber resilience?
To prevent all cyber attacks
To ensure no data is ever compromised
To recover quickly from a successful cyber attack
To eliminate the need for cybersecurity
When assessing the potential damage of a cyber attack, which three aspects concerning the compromised data should be considered?
Confidentiality, Integrity, and Availability
Confidentiality, Integrity, and Accessibility
Confidentiality, Information, and Availability
Confidentiality, Information, and Accessibility
What does it mean if the confidentiality of data is compromised?
The data is deleted permanently.
The data is altered or modified.
An attack was able to see the data and perhaps take a copy of it.
The data is made available to everyone.
What does it mean if the integrity of data has been compromised?
The data has been deleted.
The data has been changed in some way.
The data has been encrypted.
The data has been backed up.
What is the consequence of an integrity breach?
The data can no longer be trusted.
The data is permanently lost.
The data is made public.
The data is encrypted.
What does it mean if the availability of data is affected?
The data is deleted.
The data is encrypted.
Legitimate users no longer have access to it.
The data is duplicated.
What type of attack is based on affecting the availability of data?
Phishing attack
Ransomware attack
Man-in-the-middle attack
SQL injection attack
What is a tabletop exercise?
A planned exercise where employees of an organization work through a hypothetical real-world scenario.
A physical exercise to improve employee health.
A training session for new employees.
A meeting to discuss company policies.
What is the purpose of a firewall in a computer system or network?
To act as a filter, analyzing data packets for malicious intent before they are allowed into the network.
To store data securely.
To manage user passwords.
To provide internet access.
What do employees do during a tabletop exercise?
Simulate a security breach and rehearse their response to such an incident.
Perform physical exercises.
Attend a training session on new software.
Discuss their daily tasks.
Why should every computer system and/or network have a firewall?
To protect against malicious data packets.
To increase internet speed.
To store large amounts of data.
To manage employee schedules.
Who is typically in charge of setting up and maintaining access controls within an organization?
Teacher
Student
Network Administrator
Principal
In a school scenario, what type of files would a central file server store?
Only exam papers
All files
Only learning materials
Only sensitive information
What type of access is appropriate for pupils in a school scenario?
Access to exam papers
Access to sensitive information
Access to learning materials
Access to both exam papers and sensitive information
Who will need access to both exam papers and sensitive information in a school scenario?
Pupils
Teachers
Network Administrators
Parents
What is the purpose of Two-Factor Authentication?
To provide an additional layer of security when accessing computer systems.
To make logging in faster.
To store passwords securely.
To allow multiple users to access the same account.
What happens when Two-Factor Authentication is enabled and an attempt is made to log in from an unknown device?
The account is automatically locked.
A special code is sent to the user's mobile device or email.
The user is logged out of all devices.
The password is reset.
What must the user do after receiving the special code in Two-Factor Authentication?
Ignore the code and continue.
Enter the code to log into the application.
Change their password.
Contact customer support.
What is the term used for any type of authentication method that uses a biological characteristic to verify someone's identity?
Password authentication
Token-based authentication
Biometrics
Two-factor authentication
Which of the following is NOT an example of biometric authentication?
Retina scanners
Face recognition
Voiceprint
Password
Which biometric method uses the unique patterns in the eyes to verify identity?
Face recognition
Retina scanners
Voiceprint
Fingerprint
Which biometric method uses the unique features of a person's face to verify identity?
Retina scanners
Face recognition
Voiceprint
Fingerprint
Which biometric method uses the unique characteristics of a person's voice to verify identity?
Retina scanners
Face recognition
Voiceprint
Fingerprint
What is a software patch?
A new version of the software
A fix for a discovered flaw or vulnerability
A backup of the software
A user manual for the software
Why is it important to download and install all security patches as soon as they are released?
To increase the speed of the system
To ensure the system is up to date and protected from the latest threats
To reduce the size of the software
To improve the graphics of the software
Who develops the fix for a discovered flaw or vulnerability in software?
The users
The software manufacturers
The hardware manufacturers
The operating system developers
What do software manufacturers recommend all users do with a software patch?
Ignore it
Download and install it
Delete it
Share it with others
What does a full backup do?
Copies only new data
Copies every item of data
Copies only modified data
Copies only system files
Why is data from a full backup usually stored in a different location?
To save storage space
To make it easier to access
To protect against physical damage
To reduce backup time
What is one example of physical damage that storing data in a different location can protect against?
Data corruption
Fire
Virus attack
Software malfunction
What is a key characteristic of a differential backup?
It saves all data regardless of changes.
It only saves data that has changed since the last full backup.
It requires more storage space than a full backup.
It takes more time than a full backup.
Which type of backup is described as more efficient because it only saves changes since the last backup of any kind?
Full Backup
Differential Backup
Incremental Backup
Redundant Backup
Which type of backup requires less storage space compared to a full backup?
Full Backup
Differential Backup
Incremental Backup
Redundant Backup
What does an incremental backup save?
All data since the last full backup
Only the data that has changed since the last full backup
Only the data that has changed since the last backup of any kind
All data regardless of changes
