wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

AP CK CyberSecurity Unit 4

Total questions: 10

Worksheet time: 5mins

Name
Class
Date
1.

What security tool is being used to protect this network?

  • Collects data streams from multiple sources

  • Analyzes the data to detect patterns that may indicate a cyber attack

  • Raises an alert if a potential attack is detected

  • Security analysts investigate the alert to determine whether it represents a true threat

What security tool is being used to protect this network?

a)

Network intrusion prevention system (NIPS)

b)

Next-generation firewall (NGFW)

c)

Web application firewall (WAF)

d)

Security incident and event management (SIEM)

2.

Which of the following methods is used to detect cyber attacks that are known and have been previously recorded?

a)

Anomaly-based detection

b)

Signature-based detection

c)

Baselining detection

d)

Hybrid detection

3.

During the reconnaissance phase of a cyber attack, an adversary was able to learn the following about a target:

A social media website revealed the target’s employer

The employer’s website revealed the office address

A public records website revealed the target’s home address

Which of the following resources did the adversary use to obtain this information?

a)

Phishing

b)

APT

c)

Wiretapping

d)

OSINT

4.

Which of the following is an example of shoulder surfing?

a)

An adversary uses software that tracks all the keys a target presses on their keyboard

b)

An adversary sets up a fake Wi-Fi hotspot to collect login credentials when users connect

c)

An adversary steals a laptop that is left unattended in a coffee shop

d)

An adversary watches a target enter their phone’s passcode

5.

Which of the following can be added to a password to prevent users with the same passwords from having the same password hash?

a)

A second hashing algorithm

b)

A token

c)

A key derivation function

d)

A salt

6.

A system administrator is reviewing the following authentication log. What might the anomaly on line 9 indicate?

a)

The user’s password has been compromised

b)

The system’s clock has reset on the network

c)

The user logged in during a maintenance window

d)

The user has accessed a restricted area

7.

Which of the following explains how a SQL injection attack can exploit an application?

a)

It places SQL commands into a user-input field in an application with the intent to either return more information than it should or modify the data on the database

b)

It places malicious JavaScript code into a SQL user-input field to steal user session cookies with the intent to use these cookies to gain authentication to the application

c)

It uses the user-input field of the application to bypass user authentication requirements for the application to gain access to the application

d)

It uses a user-input field in an application to send an overwhelming amount of data to the application in hopes to cause a denial of service attack on the application

8.

Review the following log.

The log file shows evidence of which of the following types of application attacks?

a)

Buffer overflow

b)

SQL injection

c)

Cross-site scripting

d)

On-path

9.

Which of the following describes an ARP poisoning attack?

a)

An adversary uses ARP to monitor a network by capturing and logging ARP traffic

b)

An adversary attempts to modify the ARP table so they receive traffic intended for a target

c)

An adversary uses an ARP request to verify that the target device is active on the local network

d)

An adversary floods the network with ARP requests to gather IP-to-MAC mappings of the devices on the network

10.

A network administrator reviewing a MAC address table observes a surge of ethernet frames with different MAC addresses. Which type of network attack did the administrator likely observe?

a)

DNS poisoning

b)

MAC spoofing

c)

ARP poisoning

d)

MAC flooding