wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

SD_Ch20

Total questions: 30

Worksheet time: 18mins

Name
Class
Date
1.

Which of the following is not a technology-based attack?

a)

DoS

b)

Rogue

c)

DHCP

d)

Shoulder surfing

e)

Malware

2.

A command-and-control server is a part of which of the following attacks?

a)

DDoS

b)

Password attacks

c)

Shoulder surfing

d)

Malware

3.

Which attack involves the attacker impersonating both sides of a conversation between two hosts?

a)

On-path attack

b)

Deauthentication

c)

DoS

d)

Spoofing

4.

Which type of attack will attempt to configure hosts with a malicious default gateway?

a)

DoS

b)

VLAN hopping

c)

Deauthentication

d)

Rogue DHCP

5.

In which of the following does the attacker (and his bots) send a UDP packet to vulnerable NTP servers that requests that a large amount of data (megabytes worth of traffic) be sent to the DDoS's target IP address?

a)

Distributed

b)

NTP amplification

c)

Reflective

d)

DNS amplification

6.

Which of the following was previously known as a man-in-the-middle attack?

a)

VLAN hopping

b)

On-path attack

c)

DoS attack

d)

Deauthentication attack

7.

Double tagging is a part of which of the following attacks?

a)

VLAN hopping

b)

On-path attack

c)

DDoS

d)

Malware

8.

Which of the following is the process of adopting another system's MAC address for the purpose of receiving data meant for that system?

a)

Rogue DHCP

b)

ARP spoofing

c)

IP spoofing

d)

DNS spoofing

9.

Which of the following is connected to your wired infrastructure without your knowledge?

a)

Rogue AP

b)

Command-and-control server

c)

Malware

d)

Botnet

10.

Which of the following uses the same SSID as your AP?

a)

Rogue AP

b)

Rogue DHCP

c)

Evil twin

d)

DNS poisoning

11.

What attack vector can be used for an on-path attack?

a)

DHCP

b)

DNS

c)

Wireless

d)

All of the above

12.

Which attack can be used on a native VLAN?

a)

Double tagging

b)

VLAN traversal

c)

Trunk popping

d)

Denial of service

13.

Which form of social engineering is nothing more than looking over someone's shoulder while they enter or view sensitive information?

a)

Shoulder surfing

b)

Phishing

c)

Tailgating

d)

Whaling

14.

You need to protect your users from Trojans, viruses, and phishing emails. What should you implement?

a)

Multi Factor authentication

b)

Software firewalls

c)

Antimalware

d)

Antivirus

15.

What can you use to protect against spoofing of internal IP addresses on the perimeter of your network?

a)

Access control lists

b)

Intrusion detection systems

c)

Transport Layer Security

d)

Host intrusion detection systems

16.

You are implementing a public guest wireless network and require that users accept an acceptable use policy (AUP). What should you implement to accomplish the goal?

a)

ACLs

b)

MAC filtering

c)

Captive portal

d)

802.1X

17.

You are implementing a wireless network and need to make sure that only hosts that have up-to-date antivirus protection can join. Which technology should you implement?

a)

NAC

b)

802.1X

c)

EAP-TLS

d)

ACLs

18.

Which statement is correct about applying ACLs to an interface?

a)

An access control list can be applied in only one direction.

b)

An access control list can be applied only to a single protocol.

c)

An access control list can be applied only to a single port.

d)

All of the above.

19.

As part of your training program, you're trying to educate users on the importance of security. You explain to them that not every attack depends on implementing advanced technological methods. Some attacks, you explain, take advantage of human shortcomings to gain access that should otherwise be denied. Which term do you use to describe attacks of this type?

a)

Social engineering

b)

IDS

c)

Perimeter security

d)

Biometrics

20.

You've discovered that credentials to a specific application have been stolen. The application is accessed from only one computer on the network. Which type of attack is this most likely to be?

a)

On-path attack

b)

Zero day

c)

Denial of service (DoS)

d)

ARP spoofing

21.

Which security measure can help prevent unauthorized devices from connecting to your network?

a)

Port mirroring

b)

DHCP snooping

c)

Network segmentation

d)

MAC filtering

22.

What type of attack involves sending a large number of requests to a server to overwhelm it and make it unavailable to legitimate users?

a)

Phishing

b)

Denial of Service (DoS)

c)

Cross-Site Scripting (XSS)

d)

SQL Injection

23.

Which of the following is a method to ensure data integrity during transmission?

a)

Encryption

b)

Hashing

c)

Redundancy

d)

Compression

24.

Match the networking terms

a)

Disruption of service by an attacker.

1.

DoS

b)

An indirect DoS attack

2.

Reflective

c)

A DoS attack that is carried out making a small request to a third party

3.

Amplified

d)

An attack in which the threat actor eavesdrops and manipulates the conversation

4.

On Path Attack

e)

A threat actor duplicates an SSID to intercept wireless traffic

5.

Evil Twin

25.

Match the networking terms

a)

Client receives a malicious DNS entry along with their IP and subnet mask

1.

Rogue DHCP

b)

Access to a VLAN is attempted by double tagging the frame

2.

VLAN Hopping

c)

A threat actor sends a malicious reply back for a DNS query

3.

DNS Spoofing

d)

Disruption of service by many attackers

4.

Distributed Denial of Service

e)

Disruption of service because of theft of equipment

5.

Physical DoS

26.

What is a common tactic used in social engineering attacks?

a)

Offering free software updates

b)

Pretending to be a figure of authority to extract personal information

c)

Sending large files to slow down your computer

d)

Promoting physical fitness

27.

Which of these is the best definition of Shoulder Surfing?

a)

Calling someone to create an invented situation that increases the chance they will share sensitive information with you.

b)

Sending an email that pretends to be from a reputable company which usually has a link to click that takes you to a website that looks real but is not.

c)

A cyber attack that redirects a user from a real URL to a website that looks real but is not.

d)

Looking at someone entering their personal data into a system and copying what you see.

28.

A program that is designed to overwhelm email servers and cause DOS

a)

Worm

b)

Trojan

c)

Ransomeware

d)

Spyware

29.

A ​ (a)   is a type of malware that is triggered by running an infected file, whereas a ​ (b)   is able to self-replicate and will often spread automatically through a local network.

Choose from the below words
virus
worm
trojan-horse
hacker
30.

Match the following

a)

Tracks a computer's usage

1.

Spyware

b)

Spreads when a user runs an executable

2.

Virus

c)

Sends copies to itself and other machines

3.

Worm