WorksheetsSD_Ch20
Total questions: 30
Worksheet time: 18mins
Which of the following is not a technology-based attack?
DoS
Rogue
DHCP
Shoulder surfing
Malware
A command-and-control server is a part of which of the following attacks?
DDoS
Password attacks
Shoulder surfing
Malware
Which attack involves the attacker impersonating both sides of a conversation between two hosts?
On-path attack
Deauthentication
DoS
Spoofing
Which type of attack will attempt to configure hosts with a malicious default gateway?
DoS
VLAN hopping
Deauthentication
Rogue DHCP
In which of the following does the attacker (and his bots) send a UDP packet to vulnerable NTP servers that requests that a large amount of data (megabytes worth of traffic) be sent to the DDoS's target IP address?
Distributed
NTP amplification
Reflective
DNS amplification
Which of the following was previously known as a man-in-the-middle attack?
VLAN hopping
On-path attack
DoS attack
Deauthentication attack
Double tagging is a part of which of the following attacks?
VLAN hopping
On-path attack
DDoS
Malware
Which of the following is the process of adopting another system's MAC address for the purpose of receiving data meant for that system?
Rogue DHCP
ARP spoofing
IP spoofing
DNS spoofing
Which of the following is connected to your wired infrastructure without your knowledge?
Rogue AP
Command-and-control server
Malware
Botnet
Which of the following uses the same SSID as your AP?
Rogue AP
Rogue DHCP
Evil twin
DNS poisoning
What attack vector can be used for an on-path attack?
DHCP
DNS
Wireless
All of the above
Which attack can be used on a native VLAN?
Double tagging
VLAN traversal
Trunk popping
Denial of service
Which form of social engineering is nothing more than looking over someone's shoulder while they enter or view sensitive information?
Shoulder surfing
Phishing
Tailgating
Whaling
You need to protect your users from Trojans, viruses, and phishing emails. What should you implement?
Multi Factor authentication
Software firewalls
Antimalware
Antivirus
What can you use to protect against spoofing of internal IP addresses on the perimeter of your network?
Access control lists
Intrusion detection systems
Transport Layer Security
Host intrusion detection systems
You are implementing a public guest wireless network and require that users accept an acceptable use policy (AUP). What should you implement to accomplish the goal?
ACLs
MAC filtering
Captive portal
802.1X
You are implementing a wireless network and need to make sure that only hosts that have up-to-date antivirus protection can join. Which technology should you implement?
NAC
802.1X
EAP-TLS
ACLs
Which statement is correct about applying ACLs to an interface?
An access control list can be applied in only one direction.
An access control list can be applied only to a single protocol.
An access control list can be applied only to a single port.
All of the above.
As part of your training program, you're trying to educate users on the importance of security. You explain to them that not every attack depends on implementing advanced technological methods. Some attacks, you explain, take advantage of human shortcomings to gain access that should otherwise be denied. Which term do you use to describe attacks of this type?
Social engineering
IDS
Perimeter security
Biometrics
You've discovered that credentials to a specific application have been stolen. The application is accessed from only one computer on the network. Which type of attack is this most likely to be?
On-path attack
Zero day
Denial of service (DoS)
ARP spoofing
Which security measure can help prevent unauthorized devices from connecting to your network?
Port mirroring
DHCP snooping
Network segmentation
MAC filtering
What type of attack involves sending a large number of requests to a server to overwhelm it and make it unavailable to legitimate users?
Phishing
Denial of Service (DoS)
Cross-Site Scripting (XSS)
SQL Injection
Which of the following is a method to ensure data integrity during transmission?
Encryption
Hashing
Redundancy
Compression
Match the networking terms
Disruption of service by an attacker.
DoS
An indirect DoS attack
Reflective
A DoS attack that is carried out making a small request to a third party
Amplified
An attack in which the threat actor eavesdrops and manipulates the conversation
On Path Attack
A threat actor duplicates an SSID to intercept wireless traffic
Evil Twin
Match the networking terms
Client receives a malicious DNS entry along with their IP and subnet mask
Rogue DHCP
Access to a VLAN is attempted by double tagging the frame
VLAN Hopping
A threat actor sends a malicious reply back for a DNS query
DNS Spoofing
Disruption of service by many attackers
Distributed Denial of Service
Disruption of service because of theft of equipment
Physical DoS
What is a common tactic used in social engineering attacks?
Offering free software updates
Pretending to be a figure of authority to extract personal information
Sending large files to slow down your computer
Promoting physical fitness
Which of these is the best definition of Shoulder Surfing?
Calling someone to create an invented situation that increases the chance they will share sensitive information with you.
Sending an email that pretends to be from a reputable company which usually has a link to click that takes you to a website that looks real but is not.
A cyber attack that redirects a user from a real URL to a website that looks real but is not.
Looking at someone entering their personal data into a system and copying what you see.
A program that is designed to overwhelm email servers and cause DOS
Worm
Trojan
Ransomeware
Spyware
A (a) is a type of malware that is triggered by running an infected file, whereas a (b) is able to self-replicate and will often spread automatically through a local network.
Match the following
Tracks a computer's usage
Spyware
Spreads when a user runs an executable
Virus
Sends copies to itself and other machines
Worm
