NEW
Font size
WorksheetsCybersecurity I - Unit 3 Part 1 Review
Total questions: 75
Worksheet time: 38mins
What is ransomware?
A type of software that speeds up your computer's performance.
Malicious software that encrypts and locks a victim's data and demands a ransom.
Software used to protect against viruses and malware.
A type of file compression software.
What type of data is commonly targeted by ransomware attackers?
Random internet browsing history.
Personal finance data.
Publicly available data.
Unused software applications.
Which term describes a version of ransomware that encrypts files but demands payment in cryptocurrency?
Locker-ransomware.
Scareware.
Cryptomalware.
Doxware.
How did the attackers demand payment from Baltimore City's governmental computer systems in the RobbinHood ransomware attack?
Bank transfer.
Credit card payment.
Cryptocurrency (Bitcoin).
Cash in hand.
What is the best defense against ransomware according to the text?
Paying the ransom.
Ignoring the ransom demands.
Reporting the attack to law enforcement.
Prevention and data backups.
What is scareware?
Software designed to scare away potential hackers.
Software that creates fake antivirus alerts and demands payment.
Software that encrypts files and demands cryptocurrency.
Software that locks a victim out of their computer.
Victims often take which action in response to a ransomware attack?
Report the attack to law enforcement.
Pay the ransom.
Prevent the attack easily.
Ensure data release after payment.
What is the purpose of doxware?
To lock a victim out of their computer.
To scare users into thinking their computer is infected.
To encrypt files and demand payment.
To threaten to release stolen data if a ransom is not paid.
What is one consequence of paying the ransom according to the text?
Access to the files is always restored.
The cybercriminal releases the victim's data publicly.
The cybercriminal never asks for payment again.
The cybercriminal is immediately apprehended by law enforcement.
What is recommended to defend against ransomware attacks?
Pay the ransom to ensure access to data.
Regularly update software and keep backups of data.
Ignore the threat and continue using the computer.
Disconnect from the internet permanently.
Which of the following is a characteristic of computer viruses?
What is the distinguishing feature of crypto-malware?
It utilizes CPU cycles to generate encryption keys
It records user activity without permission
It relies on authorized programs to operate
It makes your device slower and takes up space
What differentiates ransomware from other forms of crypto-malware?
It encrypts information on systems
It holds victim's information for ransom
It creates a denial of service with no promise of returning access
It spreads autonomously without relying on programs
What is the primary characteristic of trojan malware?
It self-replicates
It encrypts information on systems
It utilizes authorized programs to subvert system defenses
It records user keystrokes
What distinguishes worms from viruses?
They attach themselves to system processes
They rely on authorized programs to spread
They can self-replicate without relying on programs
They encrypt information on systems
What is the primary function of spyware?
To self-replicate and spread across systems
To encrypt information on systems
To listen to user activity without permission
To gain administrative credentials on a system
What are bloatware applications primarily used for?
To slow down devices and take up space
To record user keystrokes
To encrypt information on systems
To self-replicate and spread across systems
What is the purpose of a keylogger?
To listen to user activity without permission
To gain administrative credentials on a system
To self-replicate and spread across systems
To record user's keystrokes to glean information
What is the defining characteristic of bots in the context of malware?
They autonomously act on actions typically sent from a Command and Control server
They hold victim's information for ransom
They utilize CPU cycles to generate encryption keys
They spread autonomously without relying on programs
What is the primary function of a rootkit?
To listen to user activity without permission
To self-replicate and spread across systems
To gain administrative credentials on a system
To encrypt information on systems
What is a keylogger?
A hardware device used to encrypt keyboard inputs
A software program that tracks and logs keystrokes on a victim's keyboard
A security measure used to protect against malware attacks
A physical keyboard layout designed to prevent keylogging
Why are keystrokes valuable to attackers?
They contain data such as passwords, usernames, and credit card information.
They provide information about the victim's internet service provider
They are used to track the victim's physical location
They reveal the victim's computer hardware specifications
How do keyloggers capture data other than individual keystrokes?
By intercepting encrypted communication between the keyboard and the computer
By taking screenshots, logging items copied to the clipboard, and capturing instant messages
By physically modifying the victim's keyboard
By encrypting the data, they capture to prevent detection
Why are keyloggers not affected by encryption protection?
Because they intercept keyboard inputs before encryption takes place
Because they are designed to bypass encryption algorithms
Because they only capture unencrypted data
Because they are immune to all security measures
What are some legitimate uses for keyloggers?
Monitoring a child's online activity
Stealing sensitive information from victims
Engaging in cybercriminal activities
Generating revenue through advertising
How did the FBI use a keylogger in an investigation against cybercriminals?
By installing it on a victim's computer
By monitoring online activity of individuals
By capturing the suspects' usernames and passwords
By spreading it through email attachments
How do keyloggers spread?
Through physical modification of computer hardware
Through email attachments, instant messages, text messages, or visiting malicious websites
Through encrypted communication channels
Through authorized software downloads
What is a recommended defense against keyloggers when opening email attachments?
Use caution and avoid opening any attachments
Disable all email communication to prevent keylogger installation
Always open attachments without hesitation
Use caution when opening attachments and consider using one-time passwords and multi-factor authentication
How can password managers help protect against keyloggers?
By disabling all keyboard inputs
By encrypting keyboard inputs before they reach the computer
By not requiring typing the saved password each time for access
By installing additional security measures on the computer
How can alternate keyboard layouts help defend against keyloggers?
By encrypting all keyboard inputs
By preventing keylogger software from capturing keystrokes
By disabling all keyboard inputs
By modifying the physical structure of the keyboard
Which vector exploits vulnerabilities in communication channels like email, text messaging, or social media to deliver content or trick users into revealing sensitive information?
Image-based
File-based
Message-based
Voice call
What precaution should users take to mitigate risks associated with image-based attacks?
Disable image previews in email clients
Download images only from unknown sources
Enable automatic image loading in emails
Share images freely on social media
Which vector leverages malicious code embedded within harmless files to compromise systems or steal data?
Voice call
Removable device
File-based
Vulnerable software
What precaution should individuals take when dealing with unexpected phone calls to mitigate voice call attacks?
Immediately provide personal information
Verify the caller's identity before providing any information
Verify the caller's identity before providing any information
Engage in lengthy conversations to gather more information
Which vector exploits the trust often placed in removable devices to infiltrate systems and compromise data?
Message-based
File-based
Removable device
Network-based
What is a characteristic of client-based vulnerabilities?
They require physical access to exploit
They can be exploited without user interaction
They rely on vulnerabilities within network devices
They require the installation of specific client applications by the user
Which vector targets unsupported systems and applications, making them prime targets for attackers due to unaddressed vulnerabilities?
Network-based
System-based
Vulnerable software
Open ports and services
What precaution can be taken to mitigate wireless network-based attacks?
Enforce multi-factor authentication
Shut down all wired network connections
Use reverse phone lookup tools
Protect network infrastructure from unauthorized access
What are viruses and worms?
Types of harmless software used for system maintenance.
Types of malware characterized by their ability to self-replicate.
Security measures implemented by antivirus software.
Operating system features designed to prevent unauthorized access.
What distinguishes viruses from worms?
Viruses require user interaction to spread, while worms can spread independently.
Viruses attach themselves to system processes, files, or programs, while worms do not.
Viruses only affect local networks, while worms can spread across wide area networks.
Viruses are always harmful, while worms can sometimes be benign.
What is a characteristic of worms in terms of self-replication?
They require user interaction to spread.
They do not need to rely on programs to spread.
They can only spread within a local network.
They can only replicate by infecting other worms.
How can viruses and worms affect a target?
By infecting specific programs on a computer.
By encrypting sensitive data on a local network.
By spreading to the boot sector of the computer.
All of the above.
What is a recommended defense against viruses?
Implementing least privilege and monitoring file modifications.
Utilizing intrusion detection and prevention systems.
Restricting the level of privilege users and processes natively run in.
All of the above.
What is a common defense measure against both viruses and worms?
Regularly updating antivirus software.
Disabling system processes to prevent malware attachment.
Encrypting all files on the computer to prevent unauthorized access.
Ignoring system alerts and error messages.
What is adware?
Software that monitors computer and internet usage.
Software that comes pre-installed on a device by the manufacturer.
Software that installs extra components to deliver additional advertising, often in the form of pop-up ads.
Software that consumes system resources and takes up storage space.
How does adware affect computer performance?
It speeds up computer performance by optimizing system resources.
It slows down computer performance by increasing network traffic.
It has no impact on computer performance.
It improves system functions by providing additional features.
What is a common method of distributing adware?
Pre-installing it on devices by manufacturers.
Bundling it with free software downloads.
Selling it as a standalone product.
Sending it through email attachments.
How is spyware different from adware?
Spyware is used for advertising purposes.
Spyware monitors and collects user information without consent.
Spyware is pre-installed by manufacturers.
Spyware speeds up computer performance.
What type of data does spyware typically monitor?
Website visit history and browsing habits.
System resource usage.
Installed software applications.
Computer hardware specifications.
What is bloatware?
Software that monitors computer and internet usage.
Software that installs extra components to deliver additional advertising.
Software that comes pre-installed on devices by manufacturers and consumes system resources.
Software that speeds up computer performance by optimizing system resources.
Why do manufacturers pre-install bloatware on devices?
To optimize system performance.
To generate additional revenue through partnerships with software developers.
To provide essential features to users.
To enhance security measures.
What is a logic bomb?
A type of malware that encrypts sensitive data on a computer system.
A piece of code that waits for specific conditions to be met before executing.
A hardware device used to trigger system failures.
A security measure designed to prevent unauthorized access to computer networks.
What are triggers in the context of logic bombs?
Hardware components used to activate the logic bomb.
Specific events or conditions that cause the logic bomb to execute.
Encryption keys used to decrypt data encrypted by the logic bomb.
Security measures used to detect and neutralize logic bombs.
What are time bombs?
Logic bombs that detonate after a certain amount of time has passed.
Logic bombs that detonate when triggered by specific events.
Hardware devices used to activate logic bombs.
Encryption keys used to decrypt data encrypted by logic bombs.
Who is likely to install a logic bomb as an insider threat?
A cybersecurity expert hired to protect the company's network.
A disgruntled employee with privileged access to computer systems.
An external hacker attempting to breach the company's security.
A competitor trying to sabotage the company's operations.
Why are logic bombs hard to identify?
They are large and easily detectable by antivirus software.
They are activated randomly without specific triggers.
They are stealthy by nature and remain inactive until triggered.
They only affect outdated computer systems.
What is a recommended defense against logic bombs?
Disabling all antivirus software to prevent detection.
Regularly updating the operating system and patching vulnerabilities.
Ignoring scheduled tasks and system backups.
Using weak passwords to deter logic bomb activation.
What is a rootkit?
A type of malware that provides administrative access to a computer while concealing its presence.
A type of malware that targets only Linux/Unix systems.
A hardware component used to enhance computer performance.
A software tool used by system administrators to enhance system security.
What is the main role of a rootkit?
To enhance computer performance.
To alter system files and conceal its presence to avoid detection.
To provide additional security features to the operating system.
To detect and remove other malware from the computer.
Why are rootkits difficult to detect?
Because they only target outdated operating systems.
Because they activate after the operating system boots up.
Because they alter system files and data reports to avoid detection.
Because they are only installed on Linux/Unix systems.
How do rootkits block some antivirus software?
By encrypting system files.
By activating before the operating system boots up.
By disabling the computer's firewall.
By uninstalling the antivirus software.
What type of rootkit overwrites the firmware of the system's BIOS?
Bootkit
Kernel rootkit
Firmware rootkit
Driver rootkit
What is the purpose of Secure Boot in defending against rootkits?
To prevent unauthorized access to computer hardware.
To detect tampering with boot loaders and key operating system files.
To enhance computer performance.
To encrypt system files and data reports.
Which operating system was targeted by the Machiavelli rootkit?
Linux
Windows
Mac OS X
Android
What is Stuxnet?
The first known rootkit for industrial control systems (ICS).
A hardware component used to enhance computer performance.
A type of malware that targets Linux/Unix systems.
A software tool used by system administrators to enhance system security.
What is a Trojan horse in the context of cybersecurity?
A type of computer virus that spreads rapidly through networks.
Malicious software disguised as harmless or legitimate software.
A security tool used to protect against malware attacks.
A software program designed to enhance computer performance.
What is the significance of the term "Trojan Horse" in cybersecurity?
It refers to a fictional character in Greek mythology.
It symbolizes deceptive tactics used by hackers to gain unauthorized access.
It represents a type of encryption algorithm used in malware.
It signifies a type of computer hardware vulnerability.
How do Trojan horses typically enter a victim's computer?
Through direct hacking into the system's firewall.
By exploiting vulnerabilities in the operating system.
Via email attachments or free downloads.
Through automatic software updates.
What distinguishes a Trojan horse from a computer virus?
A Trojan horse can self-replicate without user assistance.
A Trojan horse is designed to encrypt files on a computer.
A Trojan horse requires user assistance to propagate.
Trojan horses are always detected by antivirus software.
What is a backdoor in the context of cybersecurity?
A type of malware that steals sensitive information.
A means to access a system or data bypassing normal security controls.
A computer program that replicates itself and spreads to other computers.
A hardware device used to block unauthorized network traffic.
What is a Remote Access Trojan (RAT)?
A type of virus that spreads via infected email attachments.
A software program designed to enhance remote network performance.
A Trojan horse with a backdoor allowing for remote control of the infected host.
A security tool used to scan for vulnerabilities in a network.
What is the purpose of a Downloader Trojan?
To perform distributed denial-of-service (DDoS) attacks on networks.
To intercept and send SMS messages from mobile devices.
To remotely control an infected computer's webcam.
To download and install additional malware onto an already infected computer.
How does a Distributed Denial of Service (DDoS) Trojan function?
By encrypting the victim's files and demanding a ransom.
By intercepting and sending SMS messages from infected devices.
By flooding a network with traffic from infected computers to overwhelm and disrupt its normal functioning.
By remotely controlling the infected computer's microphone.
What is a recommended defense against Trojan horse attacks?
Download and run unknown software to test its functionality.
Disable antivirus software to avoid conflicts with legitimate programs.
Regularly update antivirus and security software, and avoid downloading or running unknown or untrusted software.
Share sensitive information via email attachments to trusted contacts.
What can a hacker do once a Remote Access Trojan (RAT) is installed on a victim's computer?
Control the computer remotely and perform various actions such as viewing files and taking screenshots.
. Install antivirus software to protect the computer from future attacks.
Encrypt the computer's files and demand a ransom for decryption.
Redirect the computer's internet traffic to malicious websites.
