Font size
WorksheetsCybersecurity I - 25-26 Final Exam
Total questions: 71
Worksheet time: 39mins
If an attack on the availability of a server is coming from multiple locations it is likely what type of attack?
DDoS
DoS
MitM
AitM
If a switching loop is causing a broadcast storm condition on a network, what component of the CIA triad is at risk?
Information
Credibility
Confidentiality
Availability
What is the primary difference between DoS and DDoS attacks?
DoS attacks exploit insecure protocols.
DDoS attacks utilize multiple agents to amplify traffic.
DoS attacks utilize multiple agents in order to hide the source code.
DDoS attacks involve flooding a server with SYN packets.
What type of server provides an IP address for a domain name lookup?
DOCSIS
HTTP
DHCP
DNS
What is the name for a threat actor manipulating the records of a DNS server in order to redirect traffic to a malicious location?
DNS poisoning
DNS trafficking
Domain theft
Registration spoofing
How does DNSSEC help prevent DNS poisoning attacks?
By translating between domain names and IP addresses
By securing DNS records with digital signatures
By redirecting users to malicious websites
By checking domain reputations for spam or malicious files
If an end user finds that there are two SSIDs listed for the company WiFi, what type of attack may be taking place?
Evil Twin attack
Rogue WiFi
Starbucks attack
DoS
What type of attack involves attempting to crack passwords by systematically trying all combinations one after the other?
Pass the Hash Attach
Dictionary Attack
Brute-Force Attack
Rainbow Attack
What defense measure can help mitigate the effects of an On-Path/Adversary-in-the-Middle (AiTM) attack on a wireless network?
Using a VPN
Configuring alerts for duplicate MAC addresses
Using up-to-date browsers
Avoiding sites not utilizing HTTPS
Which transport method is best for securing wireless communications?
WPA2
WEP
WEP3
WPA3
What is the difference between an IDS and an IPS?
An IDS will make changes to prevent the attack where an IPS will only sent an alert.
An IPS will make changes to prevent the attack where an IDS will only sent an alert.
An IDS will cause additional latency on the network, an IPS will not.
An IPS is legacy and shouldn't be used.
What are ACLs commonly used for in network security?
Authenticating email senders
Filtering DNS queries
Controlling and filtering network traffic
Providing encryption for email communication
What does a heat map visualize in the context of wireless networking?
Physical obstacles in the environment
Coverage areas and signal strength
Number of connected devices
Encryption protocols used
How does a buffer overflow vulnerability typically manifest in a program?
It is a type of phishing attack that targets email users.
It occurs when a program writes more data to a buffer than it can hold, causing data to overflow into adjacent memory.
It is a method used to optimize the performance of a database.
It happens when an attacker intercepts network traffic to steal sensitive information.
How does an integer overflow attack differ from a buffer overflow attack?
Integer overflow attacks target numerical variables, while buffer overflow attacks target string variables.
Integer overflow attacks involve exceeding the capacity of numerical variables, leading to unintended results.
Buffer overflow attacks exploit the speed of data writing in memory, while integer overflow attacks exploit data validation processes.
Integer overflow attacks involve manipulating cookies, while buffer overflow attacks involve hijacking URLs.
How can a race condition lead to unexpected behavior in a program?
By allowing unauthorized access to system resources.
By causing multiple threads to access shared data simultaneously without proper synchronization.
By introducing syntax errors in the code.
By corrupting the file system during a software update.
What is a replay attack?
A method to guess passwords by asking the user directly
Injecting malicious code into an application
Capturing and reusing network packets to gain unauthorized access
Exploiting vulnerabilities in the directory structure of a website
What is a "pass the hash" attack?
Guessing passwords by hashing them
Sending hashed passwords to a server for authentication
Intercepting password hashes and using them to gain access
Storing password hashes securely
What is a key difference between Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) attacks?
XSS targets the user's browser, while CSRF targets the user's session.
XSS requires user interaction, while CSRF does not.
XSS involves executing scripts in the user's browser, while CSRF tricks the user into submitting a request.
XSS is a server-side vulnerability, while CSRF is a client-side vulnerability.
What is one defense against SQL Injection attacks?
Use input validation on submitted queries.
Limit input data to less than 10 characters.
What does code signing ensure regarding software code?
It guarantees the code's performance
It confirms the code's integrity and authenticity
It determines the code's compatibility with different platforms
It enhances the code's readability
How does monitoring contribute to cybersecurity?
By increasing system downtime
By reducing the need for security measures
By analyzing logs and detecting suspicious activities
By decreasing system performance
Placing "No Trespassing" signs are a useful deterrent, but what drawback is there to using them?
It deters everybody.
It provides clear instructions for authorized personnel.
Threat actors anticipate that it is secured for a reason.
It eliminates the need for security guards.
How does an access badge contribute to physical security?
By eliminating blind spots in video surveillance.
By providing weight sensors for hardware detection.
By distinguishing personnel and correlating logs between physical and digital worlds.
By providing access to restricted areas without authentication.
What is one method to prevent theft of information through dumpster diving?
Putting documents in sealed envelopes
Locking an account after a defined number of incorrect attempts will help deter which type of attack?
Brute-Force
DDoS
MitM
Tailgating
What is an example of an environmental attack?
Disabling the HVAC system.
Manipulating computer hardware components.
Intercepting communication by tapping into undersea network cables.
Breaking into a remote location data center.
Which deployment model allows employees to use their personal devices for work purposes?
Bring Your Own Device
Corporate-Owned, Personally Enabled
Choose Your Own Device
Company-Owned Device
What is the term used to describe the installation of applications on a mobile device from unofficial sources?
Rooting
Jailbreaking
Side-loading
Misconfiguration
What is the process called when users remove software restrictions on their mobile devices to gain elevated privileges?
Rooting
Jailbreaking
Side-loading
Misconfiguration
What is a characteristic of zero-day vulnerabilities?
Known to the software or hardware vendor
Limited time window between discovery and patch release
Existence of pre-existing security measures or signatures
Exploited by attackers using traditional security mechanisms
What threat is there from using systems after end-of-life?
(a)
What is a characteristic of VM escape vulnerability?
Unauthorized access to the host system from a virtual machine
Insecure handling of virtualized resources
Weaknesses in virtualization technologies
Loss of visibility in cloud infrastructure
Which type of vulnerability occurs when a user or process gains unauthorized access to higher-level privileges?
Privilege Escalation
Denial-of-Service (DoS) Attack
Buffer Overflow
SQL Injection
SQL stands for:
Secure Query Language
Structured Query Language
Server Query Language
System Query Language
What is the primary purpose of Group Policy in operating system security?
Monitoring user behavior
Providing encryption for data transfers
Enforcing security settings and configurations
Detecting changes to files and file systems
What is a good defense against ransomware attacks?
Paying the ransom.
Ignoring the ransom demands.
Reporting the attack to law enforcement.
Prevention and data backups.
What is the primary characteristic of trojan malware?
It self-replicates
It encrypts information on systems
It utilizes authorized programs to subvert system defenses
It records user keystrokes
What distinguishes worms from viruses?
Worms attach themselves to system processes
Worms rely on authorized programs to spread
Worms can self-replicate without relying on programs
Worms encrypt information on systems
If your computer is activated from a Command and Control server to be part of an attack, it is considered part of a ____________?
bot-net
data swarm
broadcast storm
intelligence leak
Why are keyloggers not affected by encryption protection?
Because they intercept keyboard inputs before encryption takes place
Because they are designed to bypass encryption algorithms
Because they only capture unencrypted data
Because they are immune to all security measures
How can password managers help protect against keyloggers?
By disabling all keyboard inputs
By encrypting keyboard inputs before they reach the computer
By not requiring typing the saved password each time for access
By installing additional security measures on the computer
What is a recommended defense against viruses?
Implementing least privilege and monitoring file modifications.
Utilizing intrusion detection and prevention systems.
Restricting the level of privilege users and processes natively run in.
All of the above.
What is a common defense measure against both viruses and worms?
Regularly updating antivirus software.
Disabling system processes to prevent malware attachment.
Encrypting all files on the computer to prevent unauthorized access.
Ignoring system alerts and error messages.
How does adware affect computer performance?
It speeds up computer performance by optimizing system resources.
It slows down computer performance by increasing network traffic.
It has no impact on computer performance.
It improves system functions by providing additional features.
What type of data does spyware typically monitor?
Website visit history and browsing habits.
System resource usage.
Installed software applications.
Computer hardware specifications.
What is a logic bomb?
A type of malware that encrypts sensitive data on a computer system.
A piece of code that waits for specific conditions to be met before executing.
A hardware device used to trigger system failures.
A security measure designed to prevent unauthorized access to computer networks.
Who is likely to install a logic bomb as an insider threat?
A cybersecurity expert hired to protect the company's network.
A disgruntled employee with privileged access to computer systems.
An external hacker attempting to breach the company's security.
A competitor trying to sabotage the company's operations.
Why are rootkits difficult to detect?
Because they only target outdated operating systems.
Because they activate after the operating system boots up.
Because they alter system files and data reports to avoid detection.
Because they are only installed on Linux/Unix systems.
What is the purpose of Secure Boot in defending against rootkits?
To prevent unauthorized access to computer hardware.
To detect tampering with boot loaders and key operating system files.
To enhance computer performance.
To encrypt system files and data reports.
What is a backdoor in the context of cybersecurity?
A type of malware that steals sensitive information.
A means to access a system or data bypassing normal security controls.
A computer program that replicates itself and spreads to other computers.
A hardware device used to block unauthorized network traffic.
What can a hacker do once a Remote Access Trojan (RAT) is installed on a victim's computer?
Control the computer remotely and perform various actions such as viewing files and taking screenshots.
. Install antivirus software to protect the computer from future attacks.
Encrypt the computer's files and demand a ransom for decryption.
Redirect the computer's internet traffic to malicious websites.
How can organizations foster a culture of security consciousness among employees?
By neglecting security training
By discouraging reporting of security incidents
By promoting continuous education and clear policies
By avoiding monitoring security logs
How do phishing emails typically create urgency?
By offering rewards or prizes
By threatening consequences or demanding immediate action
By providing helpful information
By requesting feedback
What should you do if you receive a suspicious email?
Click on the links to verify their legitimacy
Download any attachments to inspect them
Reply to the sender requesting more information
Forward the email to your organization's IT or security team
How can organizations mitigate the risk of tailgating attacks?
Establishing clear verification processes for access to restricted areas
Implementing strong email security measures
Encouraging employees to forward suspicious emails to IT support
Conducting employee training on recognizing phishing attempts
What is spear phishing?
Phishing attempt directed at a specific target using personal information
Phishing attempt directed at a large number of random individuals
Phishing attempt using cloned email addresses
Phishing attempt conducted through text messages
What is whaling in the context of phishing?
Phishing attempt directed at high-profile targets like CEOs
Phishing attempt directed at low-profile individuals
Phishing attempt using cloned email addresses
Phishing attempt through voice messages
What is the principle of scarcity in social engineering?
The fear of consequences
The desire to be exclusive
The tendency to follow the crowd
The exploitation of a bias of relationship
What is the main reason social engineering attacks succeed?
Lack of security software
Lack of proper training for employees
Exploitation of human biases and emotions
Lack of encryption on communication channels
Why is password complexity important?
It simplifies the authentication process
It reduces the likelihood of successful brute-force attacks
It increases the risk of unauthorized access
It encourages password reuse
What is the primary motivation for hacktivist groups?
Philosophical/political beliefs
Political, commercial, or economic messages
Financial gain
Seeking revenge
How do Rainbow Tables aid in password cracking?
They generate random passwords for dictionary attacks
They use brute force to crack passwords
They precalculate a series of hashes using known algorithms
They encrypt passwords for secure storage
What does the CIA Triad stand for?
(a)
Which principle of the CIA Triad ensures that information remains accurate and complete, and hasn’t been tampered with or modified in any unauthorized way?
Confidentiality
Integrity
Availability
Authentication
What is the purpose of the CIA Triad in information security?
To authenticate users accessing the system
To provide a framework for developing and implementing security controls
To ensure data is encrypted
To monitor network traffic
What principle of the CIA Triad ensures that authorized users have timely and reliable access to information and systems when needed?
Confidentiality
Integrity
Availability
Authorization
What does the AAA framework stand for in the context of network security?
Authentication, Authorization, Accounting
Access, Authorization, Authentication
Authorization, Authentication, Availability
Authentication, Authorization, Auditing
Which of the following statements about MFA is true?
A. MFA does not add any additional layers of verification beyond passwords.
B. MFA mitigates the impact of credential theft by relying solely on passwords.
C. MFA enhances security by requiring multiple forms of identification.
D. MFA is not required by regulatory standards or compliance frameworks.
What is a common example of something you know for authentication?
Smart Card
Biometrics
Password
Keyboard Layout
What are three basic things you should always do to secure a PC?
