Font size
WorksheetsChapter 21: Common Types of Attacks
Total questions: 99
Worksheet time: 50mins
Explain the term (IoT) Internet of Things.
A network of interconnected devices that communicate and exchange data with each other.
A type of internet service provider.
A programming language used for web development.
A social media platform for sharing images.
The (IIoT) Industrial Internet of Things is:
a network of interconnected devices in the industrial sector
a type of internet service for homes
a new programming language
a type of industrial machinery
Describe (SCADA) Supervisory control and data acquisition.
A system used for remote monitoring and control.
A type of database management system.
A programming language for web development.
A method for data encryption.
What does (ICS) Industrial control System refer to?
A system used for controlling industrial processes
A type of computer software
A method of data encryption
A type of industrial machinery
Explain the concept of (OT) operational technology.
Operational technology (OT) refers to hardware and software that detects or causes changes through direct monitoring and control of physical devices, processes, and events.
Operational technology (OT) is a type of technology used primarily in the financial sector for managing transactions.
Operational technology (OT) is a software development methodology focused on operational efficiency.
Operational technology (OT) is a branch of information technology focused on data analysis.
Who is considered a Guest in network security terms?
A user with full access rights
A user with limited access rights
A network administrator
A hacker
What does (BYOD) Bring your own device mean?
A policy allowing employees to bring personal devices to work
A type of device provided by the company
A software used for device management
A security protocol for company devices
Define (DoS) Denial-of-service.
A type of cyber attack that aims to make a machine or network resource unavailable to its intended users.
A method of encrypting data to protect it from unauthorized access.
A protocol for secure communication over a computer network.
A software tool used for network monitoring and analysis.
What is (DDoS) distributed denial-of-service?
A type of cyber attack that aims to make a service unavailable by overwhelming it with traffic.
A method of encrypting data to protect it from unauthorized access.
A software tool used to detect and remove malware from a computer.
A protocol for secure communication over a computer network.
VLAN hopping is a network security vulnerability that allows an attacker to:
Access data on a different VLAN without authorization
Improve network performance
Securely connect to a VLAN
Monitor network traffic
What is (MAC) Media Access Control Flooding?
A technique used to overload a network switch's MAC address table
A method to enhance network security by filtering MAC addresses
A protocol for wireless communication
A type of malware that targets MAC addresses
Describe (ARP) Address Resolution Protocol poisoning.
ARP poisoning is a type of cyber attack where an attacker sends falsified ARP messages over a local area network.
ARP poisoning is a method used to enhance network security by encrypting ARP messages.
ARP poisoning is a technique for improving network speed by optimizing ARP message routing.
ARP poisoning is a protocol used for secure communication between network devices.
ARP spoofing is a technique used to:
Intercept network traffic by associating the attacker's MAC address with the IP address of another host
Encrypt data for secure transmission
Improve network speed by caching IP addresses
Authenticate users on a network
DNS poisoning is a type of attack that involves what?
Altering DNS records to redirect traffic
Encrypting DNS queries for security
Blocking DNS requests from certain IPs
Increasing DNS query speed
Key management involves:
storing and organizing cryptographic keys
managing user access to a network
developing software applications
designing user interfaces
DNS spoofing is a type of cyber attack that involves:
Altering DNS records to redirect traffic
Encrypting DNS queries for security
Blocking DNS requests to prevent access
Monitoring DNS traffic for analysis
What are Rogue devices and services?
Unauthorized devices and services that connect to a network without permission
Devices and services that are officially sanctioned by the network administrator
Devices and services that are used exclusively for gaming purposes
Devices and services that are used for educational purposes
The role of DHCP in network security is to:
Assign IP addresses dynamically to devices on a network, reducing the risk of IP conflicts.
Encrypt data transmitted over the network to prevent unauthorized access.
Monitor network traffic for suspicious activity and block potential threats.
Provide a secure channel for remote access to the network.
An AP in network security is:
Access Point
Application Protocol
Authentication Process
Advanced Protection
Evil twin in the context of network security is:
A type of phishing attack
A rogue Wi-Fi access point
A type of malware
A network firewall
An On-path attack is a type of cyber attack where an attacker secretly intercepts and relays communications between two parties who believe they are directly communicating with each other.
A type of cyber attack where an attacker intercepts and relays communications.
A method of secure communication between two parties.
A legal way to monitor network traffic.
A technique for improving network speed.
Social engineering is a technique used to:
steal personal information through manipulation
improve social skills
engineer social networks
develop social policies
What is Phishing?
A type of fishing technique
A method of secure communication
A cyber attack method to steal sensitive information
A programming language
Dumpster diving in network security involves:
Searching through trash to find sensitive information
Hacking into secure networks
Phishing for user credentials
Installing malware on devices
What is Shoulder surfing?
A technique used to steal someone's personal information by looking over their shoulder.
A method of surfing on the internet using shoulder movements.
A type of surfing sport performed on the shoulders of waves.
A dance move involving shoulder movements.
Explain Tailgating in the context of security.
Tailgating is a method of social engineering where an unauthorized person gains access to a restricted area by following an authorized person.
Tailgating is a technique used in cybersecurity to protect data from unauthorized access.
Tailgating refers to the practice of monitoring network traffic to prevent data breaches.
Tailgating is a method of encrypting sensitive information to ensure privacy.
What is Malware?
A type of software designed to protect computers
A type of software designed to harm or exploit any programmable device or network
A type of hardware used to enhance computer performance
A type of software used for creating documents
Device hardening involves:
Installing antivirus software
Updating device firmware
Disabling unnecessary services
All of the above
Disabling unused ports and services means:
Turning off ports and services that are not in use to enhance security.
Keeping all ports and services active regardless of usage.
Enabling additional ports and services for better performance.
Ignoring unused ports and services.
It is important to change default passwords because:
they are easy to guess and can lead to unauthorized access.
they are difficult to remember.
they are unique to each device.
they improve the speed of the device.
What is (NAC) Network access control?
A security solution to control access to a network
A type of network protocol
A hardware device for network management
A software application for data analysis
Port security is a feature used to:
Control access to a network by limiting the number of MAC addresses allowed on a port
Encrypt data transmitted over a network
Monitor network traffic for suspicious activity
Provide wireless connectivity to devices
What is 802.1X in network security?
A network protocol for secure communication
A standard for network access control
A type of firewall
A wireless communication protocol
MAC filtering is a security access control method that allows or denies network access based on the MAC address of a device. Which of the following best describes MAC filtering?
A method to control access to a network based on the MAC address of a device.
A technique to filter emails based on their content.
A process to enhance the speed of a network by prioritizing certain devices.
A method to encrypt data before transmission over a network.
What are Security rules?
Security rules are guidelines to protect data and resources.
Security rules are a type of software.
Security rules are irrelevant in modern technology.
Security rules are only applicable to physical security.
Explain (ACL) Access control list.
An ACL is a set of rules that control network traffic and limit access to resources.
An ACL is a type of encryption algorithm used to secure data.
An ACL is a protocol for transferring files over the internet.
An ACL is a software application for managing databases.
What is (URL) Uniform Resource Locator filtering?
A method to block access to certain websites based on their URLs
A technique to enhance website loading speed
A process to encrypt URL data for security
A way to categorize websites based on content
Content filtering is a technique used to:
Block or allow access to specific content based on predefined criteria
Enhance the speed of internet connection
Monitor user activity without restrictions
Provide unlimited access to all online content
What are Zones: Trusted vs. untrusted?
Zones are network segments that are either trusted or untrusted based on security policies.
Zones are geographical areas with different time zones.
Zones refer to different climate regions in the world.
Zones are sections of a hard drive used for data storage.
A Screened subnet is a network security architecture that involves:
A single firewall protecting the entire network
Multiple firewalls with a DMZ between them
A network without any firewalls
A network with only internal firewalls
What is a Botnet in the context of network attacks?
A network of private computers infected with malicious software and controlled as a group without the owners' knowledge
A type of firewall used to protect against network attacks
A software tool used by network administrators to monitor traffic
A secure network protocol for encrypting data
Explain the MITM attack as shown in the diagram.
A type of attack where the attacker secretly intercepts and relays communications between two parties.
A method of encrypting data to prevent unauthorized access.
A protocol for secure communication over a computer network.
A technique for improving network performance by caching data.
DNS Spoofing is a type of cyber attack. How does it work according to the diagram?
By redirecting traffic to a malicious server
By encrypting DNS queries
By blocking DNS requests
By speeding up DNS resolution
Describe IP Spoofing based on the information provided.
IP Spoofing is a technique used to gain unauthorized access to computers by tricking the system into believing that the messages are coming from a trusted source.
IP Spoofing is a method of encrypting data to ensure secure communication over the internet.
IP Spoofing is a process of compressing data to save bandwidth during transmission.
IP Spoofing is a technique used to improve the speed of data transmission over networks.
DDoS stands for Distributed Denial of Service. How is it depicted in the diagram?
A single computer attacking a server
Multiple computers attacking a server
A server attacking multiple computers
A single computer defending against an attack
What are Rootkits and how do they function as per the diagram?
Rootkits are software tools that allow unauthorized access to a computer system.
Rootkits are hardware devices used to enhance computer performance.
Rootkits are antivirus programs designed to protect against malware.
Rootkits are network protocols used for secure communication.
What are technology-based attacks in cybersecurity?
Phishing, malware, and ransomware
Social engineering and insider threats
Physical theft and natural disasters
Regulatory compliance and audits
Network attacks can be prevented by:
Using strong passwords and firewalls
Ignoring software updates
Sharing passwords openly
Disabling antivirus software
Explain the concept of rogue devices and services in cybersecurity.
Rogue devices and services are unauthorized and potentially harmful devices or services connected to a network.
Rogue devices and services are authorized and secure devices connected to a network.
Rogue devices and services are devices that enhance network security.
Rogue devices and services are devices that are always visible and easily detectable.
Password attacks can be mitigated by:
Using strong, unique passwords and enabling two-factor authentication
Sharing passwords with trusted friends
Writing passwords on a sticky note
Using the same password for all accounts
Malware threats and their impact on cybersecurity can be described as:
A type of software designed to protect systems from cyber attacks.
A type of software that disrupts, damages, or gains unauthorized access to a computer system.
A method of encrypting data to secure it from unauthorized access.
A legal framework for managing digital rights and copyrights.
What are human and environmental threats in the context of cybersecurity?
Human threats include insider threats and social engineering, while environmental threats include natural disasters and power failures.
Human threats include natural disasters and power failures, while environmental threats include insider threats and social engineering.
Human threats and environmental threats are the same in the context of cybersecurity.
There are no human or environmental threats in the context of cybersecurity.
What are hardening security measures and why are they important?
Hardening security measures are techniques to enhance system security and they are important to protect against vulnerabilities.
Hardening security measures are methods to increase system speed and they are important for performance optimization.
Hardening security measures are strategies to improve user interface and they are important for user satisfaction.
Hardening security measures are tools to expand storage capacity and they are important for data management.
What is network access control and filtering in cybersecurity?
A method to monitor and control incoming and outgoing network traffic
A technique to enhance the speed of a network
A process to install antivirus software
A way to design network architecture
Explain network segmentation and enforcement in cybersecurity.
Network segmentation divides a network into smaller parts to improve security, while enforcement ensures policies are followed.
Network segmentation is about connecting all devices, and enforcement is about monitoring traffic.
Network segmentation and enforcement are methods to increase network speed.
Network segmentation and enforcement are unrelated concepts in cybersecurity.
Secure communication and infrastructure in cybersecurity refers to:
The use of encryption and secure protocols to protect data during transmission and storage.
The physical security measures to protect hardware from theft.
The use of antivirus software to protect against malware.
The implementation of firewalls to block unauthorized access.
Describe physical security measures in the context of cybersecurity.
Physical security measures include firewalls and antivirus software.
Physical security measures involve encryption and secure passwords.
Physical security measures include surveillance cameras and access control systems.
Physical security measures are about data backup and recovery.
What is industrial security and segmentation in cybersecurity?
Industrial security and segmentation are methods to protect industrial systems from cyber threats by dividing networks into segments.
Industrial security and segmentation refer to the physical security measures in factories.
Industrial security and segmentation are unrelated to cybersecurity.
Industrial security and segmentation are methods to enhance the speed of industrial networks.
Explain the concept of trusted vs. untrusted zones in cybersecurity.
Trusted zones are areas within a network that are considered secure, while untrusted zones are areas that are not considered secure.
Trusted zones are areas outside a network that are considered secure, while untrusted zones are areas within a network that are not considered secure.
Trusted zones and untrusted zones are both considered secure areas within a network.
Trusted zones and untrusted zones are both considered insecure areas outside a network.
Which of the following is a best practice for cybersecurity preventive measures?
Regularly updating software and systems
Ignoring software updates
Using the same password for all accounts
Sharing passwords with others
What is a Technology-Based Attack?
A type of attack that uses technology to exploit vulnerabilities.
A physical attack on technological devices.
An attack that does not involve any technology.
A type of attack that only targets software.
A Denial-of-Service (DoS) attack is:
a type of cyber attack where the attacker seeks to make a machine or network resource unavailable to its intended users by temporarily or indefinitely disrupting services of a host connected to the Internet.
a method of encrypting data to protect it from unauthorized access.
a technique used to improve the speed and efficiency of a computer network.
a process of backing up data to prevent loss in case of hardware failure.
Which of the following is a characteristic of a Denial-of-Service (DoS) attack?
It uses multiple computers to attack.
It overloads resources like CPU and memory.
It is a type of phishing attack.
It encrypts data on the server.
The difference between a DoS and a DDoS attack is:
A DoS attack is from a single source, while a DDoS attack is from multiple sources.
A DoS attack is more powerful than a DDoS attack.
A DoS attack targets multiple systems, while a DDoS attack targets a single system.
There is no difference between a DoS and a DDoS attack.
What is a Reflective Attack?
An attack that uses open services to disguise the attacker's identity.
An attack that directly targets the victim's server.
An attack that uses malware to infect the victim's system.
An attack that encrypts the victim's data.
Describe the process of a Reflective Attack.
A Reflective Attack involves sending a request to a server that appears to come from a trusted source.
A Reflective Attack is a type of cyber attack where the attacker sends a request to a third-party server, which then reflects the request back to the target.
A Reflective Attack is a method of encrypting data to prevent unauthorized access.
A Reflective Attack is a technique used to improve the performance of a network by caching responses.
What is an Amplified Attack?
A) A type of DoS attack that uses small requests to generate large responses.
B) A type of attack that encrypts data.
C) A type of attack that uses phishing techniques.
D) A type of attack that uses social engineering.
Explain the process of an Amplified Attack.
An attack that increases the volume of traffic using reflection techniques.
A method to reduce network congestion.
A process to enhance data encryption.
A strategy to improve server performance.
What type of attack is depicted in the first diagram?
Reflection attack
Amplification attack
Phishing attack
Man-in-the-middle attack
An amplification attack works by exploiting vulnerabilities in network protocols to increase the volume of traffic sent to a target. Which of the following best describes this process?
The attacker sends a small request to a server, which then sends a much larger response to the target.
The attacker directly sends a large volume of traffic to the target.
The attacker uses malware to take control of the target's system.
The attacker encrypts the traffic to make it untraceable.
What is a Friendly DoS Attack?
A type of cyber attack that is unintentional and caused by legitimate users.
A deliberate attempt to disrupt a network by overwhelming it with traffic.
A security measure to prevent unauthorized access to a network.
A software tool used to enhance network performance.
Which of the following is an example of a Friendly DoS Attack?
Unplugging cables to disrupt connections.
A flash sale on an e-commerce site causing server crashes due to high traffic.
Cutting fiber optic lines to isolate networks.
Overheating network hardware to cause failures.
What is a Physical DoS Attack?
A type of cyber attack that targets physical infrastructure to disrupt services.
A method of enhancing physical security measures.
A strategy for improving network performance.
A technique for optimizing data storage.
Which of the following actions can cause a Physical DoS Attack?
High demand for services.
Unpatched software causing infinite loops.
Overheating network hardware to cause failures.
Large file downloads overwhelming bandwidth.
What does a Permanent Denial-of-Service (PDoS) attack do to devices?
It temporarily disrupts device services.
It permanently damages the device hardware.
It encrypts device data for ransom.
It slows down the device's network connection.
What type of malware is used by attackers to overwrite device firmware permanently?
Ransomware
Adware
Firmware rootkit
Spyware
In the example provided, what does an attacker do to IoT devices?
Gain unauthorized access
Improve security
Monitor performance
Update firmware
Which of the following is a method to prevent DoS and DDoS attacks?
Use Firewalls & Intrusion Prevention Systems (IPS)
Disable Rate Limiting
Ignore Load Balancers
Avoid DDoS Mitigation Services
Which service can be used for DDoS mitigation?
Cloudflare
AWS Shield
Both A and B
None of the above
Why is it important to keep systems updated in the context of preventing DoS and DDoS attacks?
To ensure compatibility with new software
To improve system performance
To patch security vulnerabilities
To enhance user experience
Which of the following is an example of a network attack?
Data Theft
VLAN Hopping
Service Disruption
Identity Fraud
What occurs during an On Path Attack (Man-in-the-Middle)?
Data is encrypted end-to-end
The attacker intercepts and possibly alters the communication between two parties
The attacker gains physical access to the device
The attacker uses social engineering to gain information
Which of the following is a process involved in an On Path Attack?
A) Attacker inserts themselves between two communicating hosts.
B) Attacker sends a direct message to the user.
C) Attacker encrypts the communication.
D) Attacker deletes all data.
Wi-Fi Eavesdropping in the context of On Path Attack is:
A method of intercepting data over a wireless network.
A technique to improve Wi-Fi signal strength.
A way to connect multiple devices to a single network.
A process to enhance internet speed.
Which of the following is a common On Path Attack method?
SSL Stripping
Data Encryption
Direct Messaging
Data Deletion
Fill in the blank: DNS Poisoning is a cyberattack where attackers manipulate the DNS cache to redirect traffic to ________ sites.
malicious
legitimate
secure
trusted
List the process steps involved in DNS Spoofing.
Reconnaissance, Crafting Malicious Response, Injecting Malicious Response, Redirecting Traffic
Crafting Malicious Response, Injecting Malicious Response, Redirecting Traffic, Reconnaissance
Injecting Malicious Response, Redirecting Traffic, Reconnaissance, Crafting Malicious Response
Redirecting Traffic, Reconnaissance, Crafting Malicious Response, Injecting Malicious Response
Which of the following is a type of DNS attack?
DNS Cache Poisoning
Pharming
Rogue DNS Server
All of the above
Explain the example given for DNS Spoofing involving a fake PayPal login page.
A fake PayPal login page is created to steal user credentials.
DNS Spoofing redirects users to a legitimate PayPal page.
Users are warned about DNS Spoofing through email alerts.
DNS Spoofing is used to enhance PayPal security.
A VLAN Hopping Attack is:
a method to bypass network security by exploiting VLAN tagging and trunking.
a technique to enhance network performance by optimizing VLAN configurations.
a strategy to improve wireless network coverage by using VLANs.
a process to secure VLANs by implementing strict access controls.
Which of the following is a method of VLAN Hopping?
Port Mirroring
Switch Spoofing
MAC Flooding
ARP Spoofing
An attacker exploits what in a VLAN Hopping Attack?
VLAN tagging
MAC address spoofing
IP address spoofing
Port mirroring
In the context of VLAN Hopping, what does Double Tagging involve?
A method where an attacker adds an additional VLAN tag to packets.
A technique to encrypt VLAN traffic.
A process to merge two VLANs into one.
A strategy to prevent VLAN hopping.
ARP Spoofing is:
A technique used to intercept network traffic by sending fake ARP messages.
A method to enhance network security by encrypting ARP messages.
A protocol used to assign IP addresses to devices on a network.
A tool for monitoring network performance.
Which of the following is a consequence of ARP Spoofing?
Data Interception
Improved Network Speed
Enhanced Security
None of the above
In the process of ARP Spoofing, what does the attacker do with the victim's traffic?
Reroutes it through themselves
Deletes it
Encrypts it
Ignores it
Explain how an attacker uses ARP Spoofing on a public Wi-Fi network.
By sending fake ARP messages to associate their MAC address with the IP address of another device
By encrypting all data packets on the network
By physically tampering with the network hardware
By using a VPN to mask their IP address
Which of the following devices is not a part of the Internet of Things?
A watch that allows you to measure and track your activity through a mobile app
A security system that lets you remotely monitor your home
A physical combination padlock for your gym locker
A car with a built-in navigation system
A computing concept that describes the network of physical devices and everyday devices (including refrigerators, thermostats, streetlights, and environmental tracking systems) that communicate with the internet.
Internet of Things (IoT)
Virtual Network
Augmented Reality (AR)
World Wide Web
