NEW
Font size
WorksheetsAP CK CyberSecurity Unit 4
Total questions: 10
Worksheet time: 5mins
What security tool is being used to protect this network?
Collects data streams from multiple sources
Analyzes the data to detect patterns that may indicate a cyber attack
Raises an alert if a potential attack is detected
Security analysts investigate the alert to determine whether it represents a true threat
What security tool is being used to protect this network?
Network intrusion prevention system (NIPS)
Next-generation firewall (NGFW)
Web application firewall (WAF)
Security incident and event management (SIEM)
Which of the following methods is used to detect cyber attacks that are known and have been previously recorded?
Anomaly-based detection
Signature-based detection
Baselining detection
Hybrid detection
During the reconnaissance phase of a cyber attack, an adversary was able to learn the following about a target:
A social media website revealed the target’s employer
The employer’s website revealed the office address
A public records website revealed the target’s home address
Which of the following resources did the adversary use to obtain this information?
Phishing
APT
Wiretapping
OSINT
Which of the following is an example of shoulder surfing?
An adversary uses software that tracks all the keys a target presses on their keyboard
An adversary sets up a fake Wi-Fi hotspot to collect login credentials when users connect
An adversary steals a laptop that is left unattended in a coffee shop
An adversary watches a target enter their phone’s passcode
Which of the following can be added to a password to prevent users with the same passwords from having the same password hash?
A second hashing algorithm
A token
A key derivation function
A salt
A system administrator is reviewing the following authentication log. What might the anomaly on line 9 indicate?
The user’s password has been compromised
The system’s clock has reset on the network
The user logged in during a maintenance window
The user has accessed a restricted area
Which of the following explains how a SQL injection attack can exploit an application?
It places SQL commands into a user-input field in an application with the intent to either return more information than it should or modify the data on the database
It places malicious JavaScript code into a SQL user-input field to steal user session cookies with the intent to use these cookies to gain authentication to the application
It uses the user-input field of the application to bypass user authentication requirements for the application to gain access to the application
It uses a user-input field in an application to send an overwhelming amount of data to the application in hopes to cause a denial of service attack on the application
Review the following log.
The log file shows evidence of which of the following types of application attacks?
Buffer overflow
SQL injection
Cross-site scripting
On-path
Which of the following describes an ARP poisoning attack?
An adversary uses ARP to monitor a network by capturing and logging ARP traffic
An adversary attempts to modify the ARP table so they receive traffic intended for a target
An adversary uses an ARP request to verify that the target device is active on the local network
An adversary floods the network with ARP requests to gather IP-to-MAC mappings of the devices on the network
A network administrator reviewing a MAC address table observes a surge of ethernet frames with different MAC addresses. Which type of network attack did the administrator likely observe?
DNS poisoning
MAC spoofing
ARP poisoning
MAC flooding
