Font size
WorksheetsFINALS
Total questions: 57
Worksheet time: 34mins
Hospital or Healthcare Provider
Low Risk
High Risk
4. University
Low
meduim
high
. Local Gym with Membership Database
Low Risk
high Risk
is an incident where sensitive, confidential, or protected information is accessed, stolen, or exposed without authorization.
(a)
IT security experts hired by organizations to identify security vulnerabilities -
Sometimes called an ethical hacker
(a)
These groups or individuals use their skills to bypass security systems to cause damage, steal data, or compromise privacy.
They’re not concerned with legal restrictions, and are intent on achieving personal gain or executing a personal agenda against an individual or an organization.
(a)
These hackers abide by a code of ethics all their own. Although they might engage in illegal activity, their intent is to educate and assist.
(a)
A weakness of a system, process, or architecture that could lead to compromised information or unauthorized access
(a)
The act of taking advantage of a vulnerability
(a)
When hackers take advantage of a security flaw in software or hardware that the manufacturer or the users don’t know about yet. • Since no one has had time to fix it (hence "zero days"), the attack can happen unexpectedly and cause serious damage before a patch or update is made available to protect against it.
(a)
involves manipulating individuals into divulging confidential or personal information. o Attackers exploit human psychology rather than relying on technical hacking techniques. o Consequences: Compromised personal and institutional security.
(a)
Which type of attack is conducted through SMS messages?
Spear Phising
Smishing
Vishing
Pharming
Which type of malware is designed to spy on the user’s activities?
Adware
Spy ware
Ransomware
Root Kit
Which social engineering attack involves following someone into a restricted area?
Phising
spear phising
Tailgating
Pretexting
What is the purpose of a quid pro quo attack?
To create fake scenarios
To send fraudulent emails
To follow someone into a restricted area
To offer something in exchange for information
Why is it important to back up important data regularly?
A. To increase network speed B. To prevent malware infections C. To mitigate the impact of ransomware attacks D. To reduce the need for antivirus software
A. To increase network speed
B. To prevent malware infections
C. To mitigate the impact of ransomware attacks
D. To reduce the need for antivirus software
Social engineering attack cycle
(a)
Your organization has just approved a special budget for a network security upgrade. Which of the following procedure should you conduct in order to make recommendations for the upgrade priorities?
Data breach
Security audit
Exploitation
Posture assessment
• What is the first step in a MAC address spoofing attack?
a) Changing the MAC address of the attacker's device
b) Scanning the network to identify a trusted device's MAC address
c) Overloading the network with requests
d) Sending phishing emails to users
• How does an attacker change their device’s MAC address in a spoofing attack?
a) By using special software tools
b) By physically altering the network interface card
c) By gaining admin access to the server
d) By encrypting the MAC address
• What is the primary goal of a MAC address spoofing attack?
a) To modify data packets on the network
b) To bypass network filters and gain access to restricted resources
c) To monitor network traffic
d) To steal user credentials
What is the term for the process where an attacker makes their device appear as a trusted one by using its MAC address?
a) Network scanning
b) Packet injection
c) MAC address spoofing
d) Signal jamming
• How does a MAC address spoofing attack typically gain unauthorized access?
a) By cracking the server's password
b) By encrypting network traffic
c) By disrupting server performance
d) By impersonating a trusted device
What does an ICMP flood attack primarily target?
a) The server's authentication mechanisms
b) The server’s ability to handle ping requests
c) The server’s file storage
d) The encryption protocols in place
• Why is an ICMP flood (Ping Flood) attack easy to execute?
a) It uses advanced encryption tools
b) It targets only outdated servers
c) It exploits TCP handshake mechanisms
d) ICMP packets require no authentication
What is the primary impact of a SYN flood attack?
a) It forces the server to reply with ICMP unreachable messages
b) It consumes the server’s memory and resources, leaving it unable to handle legitimate requests
c) It slows down the transmission speed of UDP packets
d) It encrypts all traffic passing through the network
• What distinguishes a DDoS attack from a regular DoS attack?
a) The use of stronger encryption during the attack
b) The ability to target only secure servers
c) The involvement of multiple compromised systems working together
d) The focus on accessing sensitive data rather than disruption
• What are the compromised devices used in a DDoS attack commonly called?
a) Bots or zombies
b) Reflectors
c) Amplifiers
d) Proxies
• Why are DDoS attacks harder to block than regular DoS attacks?
a) They use advanced cryptography to hide their traffic
b) They originate from multiple sources, making it harder to identify malicious traffic
c) They target only high-security servers
d) They require administrator privileges to execute
• Which of the following is NOT a characteristic of a DDoS or DRDoS attack?
a) It can overwhelm the target with a high volume of traffic
b) It often causes extended downtime for the target
c) It directly steals sensitive information from the target
d) It may involve multiple devices acting as bots or reflectors
What is a Friendly DoS attack also known as?
a) A malicious DoS attack
b) A self-inflicted DoS attack
c) A reflector DoS attack
d) An amplified DoS attack
• What does a security risk assessment primarily evaluate?
a) Threats to and vulnerabilities of the network
b) The financial stability of the organization
c) The impact of security breaches on customers
d) The effectiveness of marketing strategies
• How is a business risk assessment different from a security risk assessment?
a) It focuses on evaluating IT vulnerabilities
b) It measures the impact of potential threats on business processes
c) It prioritizes identifying hardware flaws
d) It targets customer feedback on system security
is like a whole fake village instead of just one treasure chest.
(a)
which is a decoy system that is purposely vulnerable and filled with what appears to be sensitive (though false) content, such as financial data.
(a)
• What is the primary purpose of physical security in network security?
A) To monitor network traffic and detect anomalies.
B) To control and restrict access to critical network components
C) To encrypt sensitive data to protect it from unauthorized access.
D) To prevent malware attacks by implementing antivirus software and firewalls.
• What could an intruder potentially do if they gain physical access to a network’s critical components?
A) Hack into the network remotely
B) Send phishing emails to employees
C) Encrypt data on the network
D) Steal devices, damage equipment, or reset devices
Who should have access to secure computer rooms, data rooms, and network closets?
A) Only the janitorial staff
B) Anyone with a keycard
C) Only trusted networking staff
D) Only external contractors
Who should be authorized to access network devices with physical reset buttons?
A) Any employee with network access
B) Only authorized network staff with proper clearance
C) The owner of the company
D) Only the CEO
What could happen if a computer room is left unsecured?
A. An intruder could steal equipment or sabotage software/hardware.
B. The server will automatically shut down to protect itself from unauthorized access.
C. The equipment will become obsolete due to lack of maintenance and updates.
D. A virus will automatically infect the entire network without human intervention.
• Which physical security device requires the entry of a code to open the door?
A) Access badge
B) Cipher lock
C) Motion detector
D) Asset tag
• How can a cipher lock improve security?
A) By monitoring network traffic
B) By requiring a code entry and enabling logs of who enters and exits
C) By encrypting sensitive data
D) By storing backups of login credentials
• What can be used to identify a person and grant access to secured areas?
A) Motion detection sensors
B) CCTV cameras
C) Drop ceilings
D) Access badges or smart cards
What is the best way to ensure a room with a drop ceiling is secure?
A) Use a stronger password for network access.
B) Ensure walls extend all the way up to the true ceiling.
C) Disable access to the network.
D) Use encryption on all files.
• What does an asset tag monitor?
A) The movement and condition of equipment and inventory
B) The temperature and humidity levels within a server room.
C) Network activity, such as data traffic and potential security threats.
D) User access credentials and authentication methods
What is the main purpose of device hardening in network security?
A) To speed up network performance and improve user experience
B) To secure a device from both external tampering and network or software-supported attacks
C) To reduce the cost of devices by removing unnecessary features
D) To make devices more user-friendly and accessible to a wider range of users
What are administrative credentials compared to in network security?
A) A firewall
B) An antivirus program
C) A master key to the system
D) A backup system
• Why is limiting the use of administrative credentials important?
A) To prevent misuse or theft of powerful access
B) To speed up administrative tasks and increase efficiency
C) To save on costs associated with managing multiple user accounts
D) To improve network bandwidth and performance by reducing administrative overhead
• Why should administrative credentials be limited in duration?
A. To reduce the risk of unauthorized access by limiting the time window during which these credentials can be used.
B. To limit the location from where these credentials can be used, reducing the risk of unauthorized access
C. To make it easier to distribute these credentials to multiple users, increasing efficiency and flexibility
D. To ensure that users don't forget their credentials, reducing the need for password resets and improving productivity.
What is one of the key methods for securing devices from vulnerabilities?
A) Ignoring software updates
B) Installing unnecessary applications
C) Applying updates and security patches
D) Using default passwords
• What can administrative credentials allow someone to do?
A) Install software, change security settings, and access all data
B) Browse the internet
C) Access only emails
D) Monitor network traffic
• How is hashing similar to shredding a piece of paper?
A) It makes the data unreadable and irreversible
B) It organizes data into neat, readable sections.
C) It helps to compress data for faster access.
D) It helps to recover the original data.
How does encryption differ from hashing?
A) Hashing can be reversed, while encryption cannot.
B) Encryption makes the data unreadable by anyone.
C) Encryption is only used for passwords.
D) Encryption locks data in a way that it can be unlocked and read later.
What does a "data wipe" involve during asset disposal?
A) Cleaning the device physically.
B) Erasing all sensitive data to ensure it's unrecoverable.
C) Storing the device in a secure location
D) Encrypting the device for future use.
What is the primary goal of an anti-malware policy in a network security framework?
A) To increase network speed and efficiency.
B) To ensure devices are free from malware
C) To store passwords securely and prevent unauthorized access.
D) To limit user access to the internet to minimize security risks.
• What is the primary purpose of a non-disclosure agreement (NDA) in network security?
A) To allow employees to freely share company secrets with external parties.
B) To enable employees to access personal data on the network for non-work-related purposes
C) To prevent unauthorized disclosure of sensitive information by employees or third parties
D) To grant employees administrative privileges to all network resources.
• Which of the following is a key concern addressed by a Bring Your Own Device (BYOD) policy? .
A) Allowing employees to choose their own work hours and schedules
B) Controlling access to corporate resources and data from personal devices
C) Setting up the physical layout of the office space to accommodate remote work.
D) Limiting the use of company-owned devices and promoting the use of personal devices.
