WorksheetsTACN QTANM 1
Total questions: 42
Worksheet time: 21mins
What year did the e-commerce via websites appear?
2003
2005
2004
2006
What is the first step in understanding computer and network security?
Building network security system
Formulate a realistic assessment of the threats
Set the security mode
Evaluate network performance
The first step in understanding computer and network security is ... a realistic assessment of the threats to those systems
constructing
disposed
calculating
to formulate
A number of people who call themselves hackers, though, are not as skilled as they claim to be. They have .... a few buzzwords from the Internet and may be convinced of their own digital supremacy, but they are not able to effect any real compromises to even a moderately secure system
Proved
Ascertained
Evidenced
Demonstrated
Hacking is not the ... you see in movies
dramatic process
mysterious situation
enigmatical situation
interesting process
What is the malware?
an antivirus security software for computer
software which protect computer system
unknown software which steal user information
a generic term for software that has a malicious purpose
Malware is the abbreviation of ...
malicious-logic software
malevolently software
malic software
malevolent-logic software
It includes virus attacks, worms, adware, Trojan horses, and spyware. What is it?
DoS attacks
Symantec
DNS poisoning
Malware
How many identifying types of threats are there?
4
6
7
5
... is a technique for breaching a system’s security by exploiting human nature rather than technology.
Antivirus software
International system
Security system
Social engineering
What is doxing?
is the process of finding personal information about an individual and broadcasting it, often via the Internet
is what translates the domain names you and I understand (like www.ChuckEasttom.com) into IP addresses that computers and routers understand
is actually a much greater problem than many people appreciate. Within an organization, information security is often more lax than it should be
is simply when someone inside your organization either misuses his access to data or accesses data he is not authorized to access
If you enter username 'jdoe' and the password 'password', this code produces this SQL command:
SELECT * FROM tblUsers WHEN USERNAME = 'jdoe' AND PASSWORD = 'password'
SELECT * FROM tblUsers WHEN USERNAME = 'jdoe' OR PASSWORD = 'password'
SELECT * FROM tblUsers WHICH USERNAME = 'jdoe' AND PASSWORD = 'password'
SELECT * FROM tblUsers WHERE USERNAME = 'jdoe' AND PASSWORD = 'password'
This group of attacks includes any attempt to gain unauthorized access to your system. This includes cracking passwords, elevating privileges, breaking into a server…all
the things you probably associate with the term hacking
Security breaches
Session hijacking
DoS attacks
Malware
These are designed to prevent legitimate access to your system
DoS attacks
Malware
Insider threats
Session hijacking
This is any attack that attempts to breach your website
Web attacks
Session hijacking
Insider threats
DNS poisoning
These attacks are rather advanced and involve an attacker attempting to take over a session
DNS poisoning
Web attacks
Insider threats
Session hijacking
These are breaches based on someone who has access to your network misusing his access to steal data or compromise security
Insider threats
Web attacks
DNS poisoning
Malware
This type of attack seeks to compromise a DNS server so that users can be redirected to malicious websites, including phishing websites
DNS poisoning
Web attacks
Malware
DoS attacks
Virus is …
a big program that replicates and hides itself inside other programs, usually without your knowledge
a small program that replicates and hides itself inside other programs, usually without your knowledge
a small, repetitive and easily recognizable program inside other programs, usually without your knowledge
a big, repetitive and easily recognizable program inside other programs, usually without your knowledge
The Trojan horse gets its name from an ancient tale “…”
War horse
Fairy tale
Legend of the horse
The city of Troy
Social engineering is …
a technique for breaching a system’s security by installing malicious code into the system
a technique for breaching a system’s security by stealing access to the device
a technique for breaching a system’s security by exploiting technology rather than human nature
a technique for breaching a system’s security by exploiting human nature rather than technology
This type of attack used to locating vulnerable wireless networks. What is this?
war-driving
war-dialing
war-dying
war-flying
The attacker uses a small private drone equipped with Wi-Fi sniffing and cracking software, flies the drone in the area of interest, and attempts to gain access to wireless networks. What is this type of attack?
war-driving
war-dialing
war-dying
war-flying
A … hacker , upon finding some flaw in a system, will report the flaw to the vendor of that system.
black hat
gray hat
blue hat
white hat
A … hacker is the person normally depicted in the media. Once she gains access to a system, her goal is to cause some type of harm.
gray hat
black hat
blue hat
white hat
A … hacker is normally a law-abiding citizen, but in some cases will venture into illegal activities
gray hat
black hat
blue hat
white hat
The most basic security device is the ...
hub
switch
proxy
firewall
A … is often used with a firewall to hide the internal network’s IP address and present a single IP address (its own) to the outside world.
proxy
router
hub
switch
It is merely the process of determining if the credentials given by a user or another system (such as a username and password) are authorized to access the network resource in question. What is it?
Authentication
Transmission
Auditing
Block
What are three pillars of security in the CIA triangle?
cabbala, identity, and abaci
confidentiality, integrity, and abaci
cabbala, integrity, and availability
confidentiality, integrity, and availability
This is figure of the security approach guide. Fill in the blank.
Layered
Proactive
Perimeter
Passive
This is figure of the security approach guide. Fill in the blank.
Layered
Proactive
Perimeter
Passive
This is figure of the security approach guide. Fill in the blank.
Layered
Proactive
Perimeter
Passive
This is figure of the security approach guide. Fill in the blank.
Layered
Proactive
Perimeter
Passive
One extreme viewpoint about computer security is what?
Microsoft will handle security.
The federal government will handle security.
There are no imminent dangers to your system.
There is no danger if you use Linux.
Before you can build a defense for a network you need what?
Appropriate security clearance
A clear picture of the dangers that are protected against
To complete this textbook
The help of an external consultant
Which of the following is not one of the three major classes of threats?
Attempts to intrude on the system
Online auction fraud
Denial of service attacks
A computer virus
What is a computer virus?
Any program that is downloaded to your system without your permission
Any program that can change your Windows Registry
Any program that causes harm to your system
Any program that self-replicates
What is spyware?
Any software used to gather intelligence
Only software that logs keystrokes
Any software that monitors your system
Only software that monitors what websites you visit
What is a penetration tester?
A person who hacks a system without being caught
A person who hacks a system to test its vulnerabilities
A person who is an amateur hacker
A person who hacks a system by faking a legitimate password
What is the term for hacking a phone system?
Telco-hacking
Hacking
Cracking
Phreaking
When a hacking technique uses persuasion and deception to get a person to provide information to help compromise security, this is referred to as what?
Human intel
Conning
Soft hacking
Social engineering
