wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Module 2: Attacks, Concepts, and Techniques

Total questions: 52

Worksheet time: 33mins

Name
Class
Date
1.

(a)   is any code that can be used to steal data, bypass access controls, or cause harm to or compromise a system.

2.

_____ monitors your online activity and can log every key you press on your keyboard, as well as capture almost any of your data, including sensitive personal information such as your online banking details.

a)

Backdoor

b)

Worm

c)

Scareware

d)

Spyware

3.

_____ designed to automatically deliver advertisements to a user, most often on a web browser.

a)

Scareware

b)

Adware

c)

Trojan Horse

d)

Virus

4.

____ used to gain unauthorized access by bypassing the normal authentication procedures to access a system.

a)

Rootkit

b)

Ransomware

c)

Backdoor

d)

Trojan Horse

5.

_____ mainly consists of operating system style windows that pop up to warn you that your system is at risk and needs to run a specific program for it to return to normal operation.

a)

Pretexting

b)

Ransomware

c)

Scareware

d)

Adware

6.

____ takes advantage of software vulnerabilities to gain access to resources that normally shouldn’t be accessible (privilege escalation) and modify system files.

a)

Backdoor

b)

Virus

c)

Rootkits

d)

Worm

7.

A computer infected by a ____ has to be wiped and any required software reinstalled.

a)

Spyware

b)

Backdoor

c)

Ransomware

d)

Rootkit

8.

____ when executed, replicates and attaches itself to other executable files, such as a document, by inserting its own code.

a)

Trojan Horse

b)

Worms

c)

Virus

d)

Rootkit

9.

(a)   require end-user interaction to initiate activation and can be written to act on a specific date or time.

10.

(a)   are designed to modify the operating system to create a backdoor, which attackers can then use to access your computer remotely.

11.

______ carries out malicious operations by masking its true intent. It might appear legitimate but is, in fact, very dangerous.

a)

Virus

b)

Rootkit

c)

Trojan Horse

d)

Worm

12.

_____ do not self-replicate but act as a decoy to sneak malicious software past unsuspecting users.

a)

Trojan Horses

b)

Rootkits

c)

Worms

d)

Viruses

13.

A (a)   replicates itself in order to spread from one computer to another and can run but itself.

14.

____ are responsible for some of the most devastating attacks on the Internet.

a)

Viruses

b)

Trojan Horses

c)

Worms

d)

Rootkits

15.

Which is NOT a symptom of a Malware?

a)

Increased CPU Usage

b)

Unknown Processes Running

c)

Modified or Deleted Files

d)

Increased Traffic to Malicious Websites

16.

______ is the manipulation of people into performing actions or divulging confidential information.

a)

Denial-of-Service

b)

On-Path Attacks

c)

Social Engineering

d)

SEO Poisoning

17.

This is when an attacker calls an individual and lies to them in an attempt to gain access to privileged data.

a)

Tailgating

b)

Quid Pro Quo

c)

Pretexting

d)

Rainbow Attack

18.

This is when an attacker quickly follows an authorized person into a secure, physical location.

a)

On-Path Attacks

b)

Pretexting

c)

Quid Pro Quo

d)

Tailgating

19.

This is when an attacker requests personal information from a person in exchange for something, like a free gift.

a)

Ransomware

b)

Pretexting

c)

Quid Pro Quo

d)

Advanced Persistent Threats

20.

A ___ attack results in some sort of interruption of network service to users, devices or applications.

a)

Distributed Denial-of-Service

b)

Man-in-the-Middle

c)

Denial-of-Service

d)

Man-in-the-Mobile

21.

A type of DoS attack where a network, host, or application is sent an enormous amount of data at a rate which it cannot handle.

a)

Man-in-the-Mobile

b)

Man-in-the-Middle

c)

Overwhelming quantity of traffic

d)

Maliciously formatted packets

22.

A type of DoS attack where an attacker forwards packets containing errors that cannot be identified by an application.

a)

Overwhelming quantity of traffice

b)

Advanced Persistent Threats

c)

Maliciously formatted packets

d)

SEO Poisoning

23.

This is where an attacker builds a network (botnet) of infected hosts called zombies, which are controlled by handler systems.

a)

DoS

b)

SEO Poisoning

c)

DDos

d)

Botnet

24.

A ______ is a group of bots, connected through the Internet, that can be controlled by a malicious individual or group.

a)

DDoS

b)

Traffic Interception

c)

Botnet

d)

DoS

25.

The cloud-based Cisco (a)   service pushes down updated filters to the firewall that match the traffic from new known botnets.

26.

(a)   attackers intercept or modify communications between two devices, such as a web browser and a web server, either to collect information from or to impersonate one of the devices.

27.

An on-path attack where cybercriminals takes control of a device without the user's knowledge.

a)

Man-in-the-Mobile

b)

Man-in-the-Movie

c)

Man-in-the-Middle

d)

Man-in-the-Manger

28.

____ is a type of attack used to take control over a user's mobile device.

a)

Mobile-in-the-Man

b)

Men-in-the-Man

c)

Man-in-the-Microchip

d)

Man-in-the-Mobile

29.

This is used to increase traffic to malicious sites that host malware or attempt social engineering.

(a)  

30.

____ attempts to gain access to a system by ‘spraying’ a few commonly used passwords across a large number of accounts.

a)

Password Praying

b)

Password passwording

c)

Password Spraying

d)

Password Dumping

31.

This technique allows the perpetrator to remain undetected as they avoid frequent account lockouts.

a)

Password Spraying

b)

Brute-force Attacks

c)

Dictionary Attacks

d)

Traffic Interception

32.

A hacker systematically tries every word in a dictionary or a list of commonly used words as a password in an attempt to break into a password-protected account.

a)

Rainbow Attacks

b)

Password Spraying

c)

Dictionary Attack

d)

Brute-force attacks

33.

The simplest and most commonly used way of gaining access to a password-protected site.

a)

Dictionary attacks

b)

Password spraying

c)

Rainbow attacks

d)

Brute-force attacks

34.

An attacker uses all possible combinations of letters, numbers and symbols in the password space until they get it right.

a)

Password spraying

b)

Brute-force attacks

c)

Rainbow attacks

d)

Dictionary attacks

35.

An attacker finds a match from a dictionary of precomputed hashes, then they identify the password used to create the hash.

a)

Traffic interception

b)

Rainbow attacks

c)

Brute-force attacks

d)

Dictionary attacks

36.

Plain text or unencrypted passwords can be easily read by other humans and machines by intercepting communications.

a)

Brute-force attacks

b)

Dictionary attacks

c)

Password spraying

d)

Traffic Interception

37.

A multi-phase, long term, stealthy and advanced operation against a specific target.

a)

SEO Poisoning

b)

Botnet

c)

Advanced Persistent Threats

d)

Distributed DoS

38.

This type of infiltration is usually well-funded and typically targets organizations or nations for business or political reasons.

a)

Advanced Persistent Threats

b)

Botnet

c)

Distributed DoS

d)

SEO Poisoning

39.

(a)   are any kind of software or hardware defect.

40.

A program written to take advantage of a known vulnerability is referred to as an ____

a)

Worm

b)

Malware

c)

Virus

d)

Exploit

41.

_____ are specific to device models and are not generally exploited through random compromising attempts.

a)

Software Vulnerabilities

b)

Structural Vulnerabilities

c)

Hardware Vulnerabilities

d)

Logical Vulnerabilities

42.

The (a)   vulnerability exploitations are referred to as side-channel attacks (information is gained from the implementation of a computer system).

43.

(a)   are usually introduced by errors in the operating system or application code.

44.

The _____ vulnerability allowed attackers to gain control of enterprise-grade routers, such as the legacy Cisco ISR routers, from which they could monitor all network communications and infect other network devices.

a)

Meltdown

b)

Spectre

c)

SYNful Knock

d)

Code Red worm

45.

A vulnerability occurs when data is written beyond the limits of a buffer.

a)

Race conditions

b)

Access control problems

c)

Buffer overflow

d)

Non-validated input

46.

Incoming data could have malicious content, designed to force the program to behave in an unintended way.

a)

Access control problems

b)

Non-validated input

c)

Buffer overflow

d)

Race conditions

47.

Developers should stick to using security techniques and libraries that have already been created, tested and verified and should not attempt to create their own security algorithms.

a)

Non-validated input

b)

Buffer overflow

c)

Race conditions

d)

Weaknesses in Security Practices

48.

Many security vulnerabilities are created by the improper use of access controls.

a)

Non-validated input

b)

Race conditions

c)

Access Control Problems

d)

Buffer Overflow

49.

(a)   is digital money that can be used to buy goods and services, using strong encryption techniques to secure online transactions.

50.

Cryptocurrency owners keep their money in encrypted, virtual ‘ (a)   .’

51.

When a transaction takes place between the owners of two digital wallets, the details are recorded in a decentralized, electronic ledger or (a)   system.

52.

(a)   is an emerging threat that hides on a user’s computer, mobile phone, tablet, laptop or server, using that machine’s resources to 'mine’ cryptocurrencies without the user's consent or knowledge.