Font size
WorksheetsModule 2: Attacks, Concepts, and Techniques
Total questions: 52
Worksheet time: 33mins
(a) is any code that can be used to steal data, bypass access controls, or cause harm to or compromise a system.
_____ monitors your online activity and can log every key you press on your keyboard, as well as capture almost any of your data, including sensitive personal information such as your online banking details.
Backdoor
Worm
Scareware
Spyware
_____ designed to automatically deliver advertisements to a user, most often on a web browser.
Scareware
Adware
Trojan Horse
Virus
____ used to gain unauthorized access by bypassing the normal authentication procedures to access a system.
Rootkit
Ransomware
Backdoor
Trojan Horse
_____ mainly consists of operating system style windows that pop up to warn you that your system is at risk and needs to run a specific program for it to return to normal operation.
Pretexting
Ransomware
Scareware
Adware
____ takes advantage of software vulnerabilities to gain access to resources that normally shouldn’t be accessible (privilege escalation) and modify system files.
Backdoor
Virus
Rootkits
Worm
A computer infected by a ____ has to be wiped and any required software reinstalled.
Spyware
Backdoor
Ransomware
Rootkit
____ when executed, replicates and attaches itself to other executable files, such as a document, by inserting its own code.
Trojan Horse
Worms
Virus
Rootkit
(a) require end-user interaction to initiate activation and can be written to act on a specific date or time.
(a) are designed to modify the operating system to create a backdoor, which attackers can then use to access your computer remotely.
______ carries out malicious operations by masking its true intent. It might appear legitimate but is, in fact, very dangerous.
Virus
Rootkit
Trojan Horse
Worm
_____ do not self-replicate but act as a decoy to sneak malicious software past unsuspecting users.
Trojan Horses
Rootkits
Worms
Viruses
A (a) replicates itself in order to spread from one computer to another and can run but itself.
____ are responsible for some of the most devastating attacks on the Internet.
Viruses
Trojan Horses
Worms
Rootkits
Which is NOT a symptom of a Malware?
Increased CPU Usage
Unknown Processes Running
Modified or Deleted Files
Increased Traffic to Malicious Websites
______ is the manipulation of people into performing actions or divulging confidential information.
Denial-of-Service
On-Path Attacks
Social Engineering
SEO Poisoning
This is when an attacker calls an individual and lies to them in an attempt to gain access to privileged data.
Tailgating
Quid Pro Quo
Pretexting
Rainbow Attack
This is when an attacker quickly follows an authorized person into a secure, physical location.
On-Path Attacks
Pretexting
Quid Pro Quo
Tailgating
This is when an attacker requests personal information from a person in exchange for something, like a free gift.
Ransomware
Pretexting
Quid Pro Quo
Advanced Persistent Threats
A ___ attack results in some sort of interruption of network service to users, devices or applications.
Distributed Denial-of-Service
Man-in-the-Middle
Denial-of-Service
Man-in-the-Mobile
A type of DoS attack where a network, host, or application is sent an enormous amount of data at a rate which it cannot handle.
Man-in-the-Mobile
Man-in-the-Middle
Overwhelming quantity of traffic
Maliciously formatted packets
A type of DoS attack where an attacker forwards packets containing errors that cannot be identified by an application.
Overwhelming quantity of traffice
Advanced Persistent Threats
Maliciously formatted packets
SEO Poisoning
This is where an attacker builds a network (botnet) of infected hosts called zombies, which are controlled by handler systems.
DoS
SEO Poisoning
DDos
Botnet
A ______ is a group of bots, connected through the Internet, that can be controlled by a malicious individual or group.
DDoS
Traffic Interception
Botnet
DoS
The cloud-based Cisco (a) service pushes down updated filters to the firewall that match the traffic from new known botnets.
(a) attackers intercept or modify communications between two devices, such as a web browser and a web server, either to collect information from or to impersonate one of the devices.
An on-path attack where cybercriminals takes control of a device without the user's knowledge.
Man-in-the-Mobile
Man-in-the-Movie
Man-in-the-Middle
Man-in-the-Manger
____ is a type of attack used to take control over a user's mobile device.
Mobile-in-the-Man
Men-in-the-Man
Man-in-the-Microchip
Man-in-the-Mobile
This is used to increase traffic to malicious sites that host malware or attempt social engineering.
(a)
____ attempts to gain access to a system by ‘spraying’ a few commonly used passwords across a large number of accounts.
Password Praying
Password passwording
Password Spraying
Password Dumping
This technique allows the perpetrator to remain undetected as they avoid frequent account lockouts.
Password Spraying
Brute-force Attacks
Dictionary Attacks
Traffic Interception
A hacker systematically tries every word in a dictionary or a list of commonly used words as a password in an attempt to break into a password-protected account.
Rainbow Attacks
Password Spraying
Dictionary Attack
Brute-force attacks
The simplest and most commonly used way of gaining access to a password-protected site.
Dictionary attacks
Password spraying
Rainbow attacks
Brute-force attacks
An attacker uses all possible combinations of letters, numbers and symbols in the password space until they get it right.
Password spraying
Brute-force attacks
Rainbow attacks
Dictionary attacks
An attacker finds a match from a dictionary of precomputed hashes, then they identify the password used to create the hash.
Traffic interception
Rainbow attacks
Brute-force attacks
Dictionary attacks
Plain text or unencrypted passwords can be easily read by other humans and machines by intercepting communications.
Brute-force attacks
Dictionary attacks
Password spraying
Traffic Interception
A multi-phase, long term, stealthy and advanced operation against a specific target.
SEO Poisoning
Botnet
Advanced Persistent Threats
Distributed DoS
This type of infiltration is usually well-funded and typically targets organizations or nations for business or political reasons.
Advanced Persistent Threats
Botnet
Distributed DoS
SEO Poisoning
(a) are any kind of software or hardware defect.
A program written to take advantage of a known vulnerability is referred to as an ____
Worm
Malware
Virus
Exploit
_____ are specific to device models and are not generally exploited through random compromising attempts.
Software Vulnerabilities
Structural Vulnerabilities
Hardware Vulnerabilities
Logical Vulnerabilities
The (a) vulnerability exploitations are referred to as side-channel attacks (information is gained from the implementation of a computer system).
(a) are usually introduced by errors in the operating system or application code.
The _____ vulnerability allowed attackers to gain control of enterprise-grade routers, such as the legacy Cisco ISR routers, from which they could monitor all network communications and infect other network devices.
Meltdown
Spectre
SYNful Knock
Code Red worm
A vulnerability occurs when data is written beyond the limits of a buffer.
Race conditions
Access control problems
Buffer overflow
Non-validated input
Incoming data could have malicious content, designed to force the program to behave in an unintended way.
Access control problems
Non-validated input
Buffer overflow
Race conditions
Developers should stick to using security techniques and libraries that have already been created, tested and verified and should not attempt to create their own security algorithms.
Non-validated input
Buffer overflow
Race conditions
Weaknesses in Security Practices
Many security vulnerabilities are created by the improper use of access controls.
Non-validated input
Race conditions
Access Control Problems
Buffer Overflow
(a) is digital money that can be used to buy goods and services, using strong encryption techniques to secure online transactions.
Cryptocurrency owners keep their money in encrypted, virtual ‘ (a) .’
When a transaction takes place between the owners of two digital wallets, the details are recorded in a decentralized, electronic ledger or (a) system.
(a) is an emerging threat that hides on a user’s computer, mobile phone, tablet, laptop or server, using that machine’s resources to 'mine’ cryptocurrencies without the user's consent or knowledge.
