NEW
Font size
WorksheetsSecurity
Total questions: 20
Worksheet time: 20mins
Which type of denial-of-service (DoS) attack occurs when a name server receives malicious or misleading data that incorrectly maps host names and IP addresses?
Spam
DNS poisoning
SYN flood
ARP poisoning
While using the internet, you type the URL of one of your favorite sites in the browser. Instead of going to the correct site, the browser displays a completely different website. When you use the IP address of the web server, the correct site is displayed.
Which type of attack has likely occurred?
Spoofing
Hijacking
Man-in-the-middle
DNS poisoning
An attacker uses an exploit to push a modified hosts file to client systems. This hosts file redirects traffic from legitimate tax preparation sites to malicious sites to gather personal and financial information.
Which kind of exploit has been used in this scenario?
Domain name kiting
Man-in-the-middle
DNS poisoning
Reconnaissance
An attacker sets up 100 drone computers that flood a DNS server with invalid requests. This is an example of which kind of attack?
Replay
Backdoor
Spamming
DDoS
Which of the following is the BEST definition of the term hacker?
A general term used to describe any individual who uses their technical knowledge to gain unauthorized access to an organization.
A threat actor whose main goal is financial gain.
The most organized, well-funded, and dangerous type of threat actor.
Any individual whose attacks are politically motivated.
A threat actor who lacks skills and sophistication but wants to impress their friends or garner attention.
Which of the following is the correct definition of a threat?
Any potential danger to the confidentiality, integrity, or availability of information or systems
Instance of exposure to losses from an attacker
The likelihood of an attack taking advantage of a vulnerability
Absence or weakness of a safeguard that could be exploited
Which of the following BEST describes a cyber terrorist?
Desires some kind of financial reward or revenge
Exploits internal vulnerabilities to steal information
Disrupts network-dependent institutions
Downloads and runs attacks available on the internet
An employee stealing company data could be an example of which kind of threat actor?
Insider
Nation state
Competitor
Hacktivist
Script kiddie
The IT manager in your organization proposes taking steps to deflect a potential threat actor. The proposal includes the following:
Create and follow onboarding and off-boarding procedures.
Employ the principal of least privilege.
Have appropriate physical security controls in place.
Which type of threat actor do these steps guard against?
Script kiddie
Hacktivist
Insider
Competitor
A script kiddie is a threat actor who lacks knowledge and sophistication. Script kiddie attacks often seek to exploit well-known vulnerabilities in systems.
What is the BEST defense against script kiddie attacks?
Build a comprehensive security approach that uses all aspects of threat prevention and protection.
Implement email filtering systems.
Properly secure and store data backups.
Have appropriate physical security controls in place.
Keep systems up to date and use standard security practices.
Which of the following BEST describes an inside attacker?
A good guy who tries to help a company see their vulnerabilities.
An attacker with lots of resources and money at their disposal.
An unintentional threat actor. This is the most common threat.
An agent who uses their technical knowledge to bypass security.
Which of the following best describes a script kiddie?
A hacker willing to take more risks because the payoff is a lot higher
A hacker whose main purpose is to draw attention to their political views
A hacker who uses scripts written by much more talented individuals
A hacker who helps companies see the vulnerabilities in their security infrastructure
Which of the following is the single greatest threat to network security?
Employees
Weak passwords
Email phishing
Unsecure physical access to network resources
Which of the following could an employee also be known as?
Cybercriminal
Exploit
Internal threat
Script kiddie
What is the storage location called that holds all the development source files that version control systems use?
Memory management
Stored procedures
Normalization
Repository
Which of the following includes all hardware and software necessary to secure data, such as firewalls and antivirus software?
Policies
Assets
Users and administrators
Physical security
In your role as a security analyst, you need to stay up to date on the latest threats. You are currently reviewing the latest real-time updates on cyberthreats from across the world.
Which of the following resources are you MOST likely using?
Threat hunting
Threat feeds
Intelligence fusion
Advisories and bulletins
Which of the following is an example of a vulnerability?
Virus infection
Denial-of-service attack
Unauthorized access to confidential resources
Misconfigured server
A wireless access point configured to use Wired Equivalent Privacy (WEP) is an example of which kind of vulnerability?
Unpatched software
Default settings
Weak security configurations
Zero-day exploit
Every ACME computer comes with the same account created at the factory. Which kind of vulnerability is this?
Backdoor
Misconfigurations
Default accounts and passwords
Weak passwords
