Font size
WorksheetsATTACK CONCEPTS AND TECHNIQUES!
Total questions: 35
Worksheet time: 19mins
During a class project, Abigail received a suspicious email claiming to be from the school's IT department, asking her to confirm her login credentials for a system upgrade. What is a tactic that manipulates individuals into divulging confidential information through deceptive means?
Botnet
On-Path Attacks
Distributed DoS
Denial of Service
Social Engineering
What is the process of applying patches and updates to software to fix vulnerabilities?
Software Updates
Malware Removal
System Restoration
Data Backup
What is the unauthorized use of someone’s computer to mine cryptocurrency?
Crypto-jacking
Phishing
Ransomware
Spyware
Malware used to take over and link a large number of computers in order to execute a attack.
Phishing
Zero-Day Exploit
Social Engineering
Backdoor
Botnet
What's a trojan virus?
It tricks people into thinking it's nasty
A virus disguised as a virus
A virus disguised as a gift
A virus disguised as a worm
What's the difference between a worm and a virus?
A virus is green and a worm is brown
A worm can't be caught
A worm needs to be activated by a human
A worm doesn't need to be activated by a human
What is malware?
A computer bug
A computer program
A piece of hardware
An operating system
What do you call the process in which a user is identified via a username and password
Authorization
Authentication
Accounting
Auditing
What is the process of giving individual access to a system or resource?
Auditing
Authorization
Accounting
Authentication
What is the process of identifying an individual?
Authentication
Authorization
Auditing
Accounting
System redundancy, system backups, increased system resiliency, equipment maintenance, up-to-date operating systems and software, and plans in place to recover quickly from unforeseen disasters are methods to ensure
Protection
Integrity
Confidentiality
Availability
Hashing, data validation checks, data consistency checks, and access controls are used to ensure.
Data Transmission
Data Security
Data Integrity
Data Warehouse
Which of the following contains the primary goals and objectives of security?
Social Media
The CIA triad
The Internet
None of the above
According to the CIA triad, which of the following is not considered in the triad?
Confidentiality
Integrity
Availability
Authenticity
John is working on his college applications online, when the admissions website crashes. He is unable to turn in his college application on time.
Which part of the CIA triad has been broken?
C
I
A
None of the above
Kim takes her college admissions test and is waiting to get her results by email. By accident, Kim’s results are sent to Karen.
Which part of the CIA triad has been broken?
C
I
A
None of the above
Alice is buying books from an online retail site, and she finds that she is able to change the price of a book from $20 to $1.
Which part of the CIA triad has been broken?
C
I
A
None of the above
In cybersecurity, what does CIA stand for?
Confidentiality, Integrity, Availability
Central Intelligence Agency
Cybersecurity Investigation Agency
Cybersecurity, Internet, Accessibility
Which of the following should you do to restrict access to your files and devices?
Update your software once a year.
Share passwords only with colleagues you trust.
Have your staff members access information via an open Wi-Fi network.
Use multi-factor authentication.
Backing up important files offline, on an external hard drive or in the cloud, will help protect your business in the event of a cyber attack.
True
False
Which is the best answer for which people in a business should be responsible for cybersecurity?
Business owners. They run the business, so they need to know cybersecurity basics and put them in practice to reduce the risk of cyber attacks.
IT specialists, because they are in the best position to know about and promote cybersecurity within a business.
Managers, because they are responsible for making sure that staff members are following the right practices.
All staff members should know some cybersecurity basics to reduce the risk of cyber attacks.
Which one of these statements is correct?
If you get an email that looks like it's from someone you know, you can click on any links as long as you have a spam blocker and anti-virus protection.
You can trust an email really comes from a client if it uses the client's logo and contains at least one fact about the client that you know to be true.
If you get a message from a colleague who needs your network password, you should never give it out unless the colleague says it's an emergency.
If you get an email from Human Resources asking you to provide personal information right away, you should check it out first to make sure they are who they say are.
An email from your boss asks for the name, addresses, and credit card information of the company's top clients. The email says it's urgent and to please reply right away. You should reply right away.
True
False
You get a text message from a vendor who asks you to click on a link to renew your password so that you can log in to its website. You should:
Reply to the text to confirm that you really need to renew your password.
Pick up the phone and call the vendor, using a phone number you know to be correct, to confirm that the request is real.
Click on the link. If it takes you to the vendor's website, then you'll know it's not a scam.
Email authentication can help protect against phishing attacks.
True
False
If you fall for a phishing scam, what should you do to limit the damage?
Delete the phishing email.
Unplug the computer. This will get rid of any malware.
Change any compromised passwords.
Strong passwords can be difficult to remember. What can you do to avoid forgetting them?
Use mnemonics (acronyms or phrases that are easy for you to remember)
Develop a password strategy
Use password management software with encryption.
All of the above
Cybersecurity involves...
techniques that help in securing various digital components, networks, data, and computer systems from unauthorized digital access.
techniques that don't help in securing various digital components, networks, data, and computer systems from unauthorized digital access.
techniques that help in giving various digital components, networks, data, and computer systems to unauthorized digital access.
techniques that help in getting various digital components, networks, data, and computer systems for an unauthorized use.
One of the most common types of cyber attacks is a malware attack (troyan, adware, and spyware).
True
False
What is a phishing attack?
It is a cyber attack in which the hacker sends fraudulent e-mails which appear to be coming from a illegitimate source.
It is a cyber attack in which the hacker sends trustworthy e-mails which come from a legitimate source.
It is a cyber attack in which the hacker sends fraudulent e-mails which appear to be coming from a legitimate source.
It is a cyber attack in which the hacker doesn't send fraudulent e-mails.
What is the phishing attack used for?
To install a new software to protect data.
To protect data from malware.
To secure sensitive data.
To install malware or to steal sensitive data.
What is the man-in-the- middle attack?
It is when the hacker gains access to the information path between someone's device and the website's server.
It is when the hacker takes over someone's IP address.
It is when the communication line between someone and the website is secretly intercepted.
it is when the hacker protects the someone's information from malware.
The password attack is one of the most difficult ways to attack a system?
True
False
What are some cybersecurity practices?
To Install a firewall and implement honeypots.
To use alphanumeric passwords and antivirus software.
To use alphabetic password.
To accept e-mails from unknown senders.
What does an ethical hacker do?
Tries to a network's vulnerabilities just how a hacker would do.
Identifies vulnerabilities and resolve them for protection against an actual cyber attack.
Gets the company's information to give it to other hackers for future attacks.
Installs malware to get data to sell to others.
