Font size
WorksheetsEHE Module 03: Information Security Threats
Total questions: 93
Worksheet time: 47mins
What is a threat in the context of information security?
A potential occurrence of an undesirable event that can damage and disrupt an organization
A harmless event that has no impact on an organization
A beneficial event that improves organizational security
A routine event that occurs daily in an organization
Which of the following is an example of a cyber threat?
An attacker stealing sensitive data of an organization
A natural disaster causing a power failure
An unskilled administrator making a mistake
A disgruntled employee leaving the company
What type of threat source is a flood considered?
Natural
Unintentional
Intentional
Internal
Which of the following is an example of an intentional internal threat?
A fired employee
A flood
An unskilled administrator
A hacker
What is malware?
Malicious software that damages or disables computer systems
A harmless software used for entertainment
A beneficial software that enhances system performance
A routine software update
What is one of the effects of malware on computer systems?
Increase system speed
Improve hardware performance
Slow down systems and degrade performance
Enhance data security
Which of the following is a ways malware can enter a system?
Through antivirus software
Instant Messenger applications
Via secure websites
Through email
What is Black hat SEO used for in the context of malware distribution?
To improve website design
To increase website traffic
To rank malware pages highly in search results
To enhance user experience
What is the purpose of a Crypter in malware components?
To download other malware
To protect malware from reverse engineering
To inject code into other processes
To exploit system vulnerabilities
Which component of malware is responsible for concealing its code and intended purpose?
Downloader
Injector
Obfuscator
Exploit
What is a Packer in the context of malware?
A program that allows all files to bundle together into a single executable file via compression to bypass security software detection
A piece of software that allows control over a computer system after it has been exploited
A command that defines malware’s basic functionalities such as stealing data and creating backdoors
A type of malware that records keystrokes
Which of the following is NOT a type of malware?
Trojans
Viruses
Firewalls
Ransomware
What is a Trojan?
A program that allows control over a computer system after it has been exploited
A program in which the malicious or harmful code is contained inside an apparently harmless program or data
A command that defines malware’s basic functionalities such as stealing data
A type of malware that records keystrokes
Which of the following is an indication of a Trojan attack?
The computer screen blinks, flips upside-down, or is inverted
The computer runs faster than usual
The computer automatically updates its software
The computer's battery life improves
How do hackers use Trojans?
To improve the computer's performance
To delete or replace critical operating system files
To install antivirus software
To enhance the computer's graphics
Which of the following is a type of Trojan?
Remote Access Trojans
Antivirus Trojans
Firewall Trojans
Security Trojans
What is a Trojan Horse construction kit used for?
To help attackers construct Trojan horses of their choice
To protect computers from viruses
To create antivirus software
To enhance computer performance
What is a virus?
A self-replicating program that produces its own copy by attaching itself to another program
A program that speeds up computer processes
A software that enhances graphics
A tool for data recovery
What is the Theef RAT Trojan?
A Remote Access Trojan written in Delphi
A type of antivirus software
A tool for data encryption
A program for system optimization
What is the first stage in the virus lifecycle?
Design
Replication
Launch
Detection
Which of the following actions can lead to a computer getting infected by a virus?
Opening infected e-mail attachments
Using a password manager
Installing a firewall
Updating antivirus software regularly
What type of virus is known for changing its code to avoid detection?
Polymorphic Virus
Boot Sector Virus
Macro Virus
Email Virus
Which virus type is specifically designed to affect the boot sector of a computer?
System or Boot Sector Virus
Macro Virus
Encryption Virus
Web Scripting Virus
Which of the following is a type of malware that restricts access to a computer system's files and demands a ransom?
Ransomware
Spyware
Adware
Trojan Horse
What is the primary method of attack used by the Dharma ransomware?
Email campaigns with ransom notes
Social media phishing
Direct download from websites
USB drive infections
What is a characteristic of computer worms?
They require human interaction to spread.
They independently replicate and spread across network connections.
They are used to enhance computer performance.
They are harmless and do not affect system resources.
How does a worm differ from a virus?
A worm replicates on its own, while a virus attaches itself to other programs.
A worm attaches itself to other programs, while a virus replicates on its own.
A worm does not use memory, while a virus does.
A worm cannot spread through networks, while a virus can.
What is the function of a rootkit?
To hide the presence of malicious activities and grant full access to the server.
To enhance the security of the target system.
To prevent the execution of malicious functions.
To detect and remove malware from the system.
Which of the following is an open-source tool used to create worms?
Internet Worm Maker Thing
Batch Worm Generator
C++ Worm Generator
Rootkit Installer
What is a potential risk of installing Potentially Unwanted Applications (PUAs)?
They may pose severe risks to the security and privacy of data.
They enhance system performance.
They provide additional security features.
They are always beneficial for system updates.
What is one of the objectives of a rootkit?
To root the host system and gain remote backdoor access.
To improve system performance.
To enhance antivirus software.
To provide system updates.
What is a characteristic of Adware?
Consumes additional bandwidth and exhausts CPU resources
Hides its process files to avoid detection
Monitors keystrokes on a keyboard
Changes firewall settings
Which of the following is NOT a type of PUA?
Adware
Spyware
Cryptomining
Dialers
What does adware do?
Displays annoying pop-ups
Tracks cookies for marketing purposes
Monitors keystrokes on a keyboard
Causes frequent system lag
What is one way Spyware propagate?
Through drive-by download
By tracking cookies
By consuming additional bandwidth
By monitoring keystrokes
What is one of the functions of a keylogger?
Record every keystroke typed on the user’s keyboard
Increase the speed of the computer
Protect against malware
Improve internet connectivity
What is a botnet?
A collection of compromised computers connected to perform a distributed task
A type of antivirus software
A secure network for data transfer
A tool for enhancing computer graphics
Why do attackers use botnets?
To perform DDoS attacks
To enhance computer graphics
To improve system performance
To secure online transactions
What is fileless malware known for?
Infecting legitimate software without leaving a trace on the disk
Being easily detectable by antivirus software
Improving system performance
Enhancing internet speed
Where does fileless malware typically reside?
In the system’s RAM
On the hard drive
In the cloud
On external storage devices
Which of the following is a fileless propagation technique?
Phishing emails
Installing antivirus software
Regular data backups
Using an infected bootable system disk
What is a recommended countermeasure against Trojans?
Avoid opening email attachments from unknown senders
Use more than one file-type extension
Do not perform regular data backups
Accept programs transferred by instant messaging
Which action should be taken to prevent virus infections?
Regularly update antivirus software
Avoid using firewalls
Open files with multiple extensions
Disable pop-up blockers
What should be done to maintain local workstation file integrity?
Use checksums, auditing, and port scanning
Disable antivirus software
Accept all email attachments
Avoid using firewalls
Which of the following is a recommended remediation for rootkits?
Reinstall OS/applications from a trusted source after backing up critical data
Download files from untrusted sources
Disable all antivirus software
Ignore system updates
What is a key practice to prevent spyware installation on your computer?
Set Internet security settings to low
Open emails from unknown senders
Enable a firewall
Disable antivirus software
Why is it important to regularly update antivirus and anti-spyware software?
To increase system speed
To protect against known new threats
To avoid using any computer system
To disable unnecessary applications
What should you do to enhance the security of your system against rootkits?
Install network and host-based firewalls
Open all unused ports
Log into accounts with administrative privileges
Disable all security features
Which of the following actions can help prevent spyware from being installed on your system?
Regularly update virus definition files
Set Internet security settings to low
Open attachments from unknown senders
Ignore firewall settings
What should you do before downloading any software to ensure safety?
Download from any website
Read the license agreement and privacy statements
Ignore security warnings
Download immediately without checking
Why should you avoid using administrative mode unnecessarily?
It slows down the computer
You may execute malicious programs
It increases internet speed
It improves software performance
What is a recommended practice to prevent automatic installation of PUAs?
Use the express method during setup
Uncheck unnecessary options during setup
Always choose the recommended method
Install all available options
Which of the following is a keylogger countermeasure?
Use pop-up blockers
Download more software
Disable antivirus
Open all emails
Which software should be installed to protect against keylogging?
Antivirus software
Firewall software
Port scanning software
Email client software
What is a recommended practice to avoid phishing emails?
Regularly update your browser
User training to recognize phishing emails and delete them
Use a virtual keyboard
Install a host-based IDS
What tool can be used to enter passwords securely to avoid keyloggers?
On-screen keyboard
Physical keyboard
Voice recognition software
Handwriting recognition
What is the purpose of using a VPN according to the document?
To increase internet speed
To enable an additional layer of protection through encryption
To block unwanted ads
To monitor system performance
Which of the following is a fileless malware countermeasure?
Enable macros in MS Office documents
Disable PowerShell and WMI when not in use
Install more RAM
Use a faster internet connection
What is the purpose of using User Behavior Analytics (UBA) solutions in cybersecurity?
To detect threats hidden within your data
To improve network speed
To enhance user interface design
To increase storage capacity
What is a common reason behind the existence of vulnerabilities in a system?
Insecure or poor design of the network and application
High-quality software development
Advanced encryption techniques
Regular system updates
What is a characteristic of next-generation antivirus (NGAV) software?
Employs advanced technology such as ML and AI
Uses outdated virus definitions
Relies solely on user input
Operates without internet connectivity
What should be done to applications that are not important?
Uninstall them
Update them regularly
Increase their permissions
Encrypt their data
Which of the following is a common network device vulnerability?
Lack of password protection
Correct folder permissions
Properly authenticated external systems
Secure routing protocols
What is a potential risk of using default passwords on network devices?
Increased security
Enhanced performance
Vulnerability to unauthorized access
Improved user experience
Which protocol is inherently insecure?
HTTP
HTTPS
SSH
SFTP
What can result from misconfiguring internet services like IIS and Apache?
Improved network speed
Exposed Security vulnerabilities
Enhanced data encryption
Reduced network traffic
What is a challenge in implementing and enforcing unwritten security policies?
Lack of awareness
Lack of continuity
Identity theft
Data exfiltration
What impact can vulnerabilities have on a company's reputation?
Increase in sales
Reputational damage
Improved security
Enhanced customer trust
What is the purpose of vulnerability research?
To increase network speed
To discover vulnerabilities and design flaws
To enhance user interface design
To improve software aesthetics
Why might vulnerabilities lead to legal consequences for an organization?
Due to increased profits
Due to compromised customer data
Due to improved security measures
Due to enhanced customer service
What is the primary purpose of a vulnerability assessment?
To identify and classify security vulnerabilities
To install new security software
To update operating systems
To create new user accounts
Which of the following is a limitation of vulnerability-scanning software?
It can detect all vulnerabilities at any time
It does not need regular updates
It is limited in detecting vulnerabilities at a given point in time
It measures the strength of security controls
What type of information can be obtained from vulnerability scanning?
The color of the computer case
The OS version running on devices
The brand of the computer
The number of users logged in
What is the main difference between active and passive vulnerability scanning?
Active scanning involves direct interaction with the target network, while passive scanning does not.
Active scanning is faster than passive scanning.
Passive scanning provides more detailed results than active scanning.
Passive scanning requires more resources than active scanning.
Which system provides a publicly available and free-to-use list of standardized identifiers for common software vulnerabilities?
Common Vulnerability Scoring System (CVSS)
Common Vulnerabilities and Exposures (CVE)
National Vulnerability Database (NVD)
Common Weakness Enumeration (CWE)
What is the purpose of the Common Vulnerability Scoring System (CVSS)?
To provide a list of software vulnerabilities and exposures.
To automate vulnerability management and compliance.
To communicate the characteristics and impacts of IT vulnerabilities.
To categorize software vulnerabilities and weaknesses.
Which type of vulnerability assessment uses a network scanner to find hosts, services, and vulnerabilities?
Active Assessment
External Assessment
Host-based Assessment
Passive Assessment
What is the primary focus of an Application Assessment?
Testing databases for vulnerabilities
Analyzing web infrastructure for misconfigurations
Sniffing network traffic for active systems
Scanning internal infrastructure for exploits
Which type of assessment involves sniffing network traffic to discover active systems and vulnerabilities?
Internal Assessment
Passive Assessment
Network-based Assessment
Database Assessment
What does a Network-based Assessment determine?
Vulnerabilities in wireless networks
Possible network security attacks
Credentials of all machines in the network
Misconfigurations in web infrastructure
Which assessment focuses on testing databases like MYSQL and ORACLE for vulnerabilities?
Application Assessment
Database Assessment
Wireless Network Assessment
Credentialed Assessment
What is the purpose of a Credentialed Assessment?
To assess the network by obtaining credentials of all machines
To assess distributed organization assets
To assess the network without acquiring any credentials
To employ various vulnerability assessment tools
Which tool is mentioned as a cloud-based service offering global visibility into IT system vulnerabilities?
Nessus
Qualys
GFI LanGuard
Oracle
Which tool offers a comprehensive, open source and powerful vulnerability scanning and vulnerability management solution?
OpenVAS
GFI LanGuard
Nessus Professional
Nikto
What is the primary function of GFI LanGuard?
Monitors network traffic
Scans, detects, assesses, and rectifies security vulnerabilities
Provides firewall protection
Encrypts data
Which of the following is NOT a vulnerability assessment tool mentioned in the document?
Nessus Professional
Qualys FreeScan
Core Impact
Wireshark
What is the first step in vulnerability exploitation according to the document?
Develop the exploit
Identify the vulnerability
Gain remote access
Generate and deliver the payload
Which website is a resource for identifying vulnerabilities to include expolit code?
exploit-db.com
tenable.com
beyondtrust.com
coresecurity.com
What is the primary purpose of a firewall in network security?
To enhance computer graphics
To block unauthorized access while permitting outward communication
To increase internet speed
To store backup data
Which of the following is a common method used by phishing attacks?
Regularly updating software
Sending emails that appear to be from legitimate sources
Installing antivirus software
Using a secure password manager
What is the role of an Intrusion Detection System (IDS)?
To manage network traffic efficiently
To enhance system performance
To detect and alert on potential security breaches
To prevent unauthorized access to a network
What is the best way to handle pop-ups that claim your computer is infected and you need to download software to fix it?
Click on the pop-up and follow the instructions
Close the pop-up and run a scan with legitimate antivirus software
Call the phone number provided in the pop-up for help
Download the software; it might be helpful
What is a common sign that your computer might be infected with maleware?
Your computer runs faster than usual
You can't find any files on your desktop anymore
You computer runs slower and addition programs run at startup
Your computer tells you it's secure
