WorksheetsCyber Challenge Final Round
Total questions: 30
Worksheet time: 5mins
What is the primary purpose of a "canary" in cybersecurity?
To detect SQL injection attempts
To serve as a decoy for attackers (honeypot)
To monitor memory corruption in stack-based buffer overflows
To encrypt sensitive data in transit
Which of the following is NOT a common use of steganography?
Hiding malware in image files
Concealing data within DNS queries
Encrypting emails with PGP
Embedding secret messages in audio files
In Linux, what does the command chmod 4755 set on a file?
Read, write, execute for owner; read & execute for group/others
Read, write, execute for owner; SUID bit set
Full permissions for owner, read-only for others
SUID bit with execute permissions for all
Which attack exploits the race condition between checking and using a resource?
XSS
TOCTOU
CSRF
ARP poisoning
What does the term "Living Off the Land" (LOTL) refer to in cybersecurity?
Using cloud services for anonymity
Attackers using legitimate system tools for malicious purposes
Harvesting credentials from phishing sites
Exploiting zero-day vulnerabilities
Which Linux command lists all open files and the processes using them?
netstat -tuln
lsof
ps aux
ss -a
What is the main risk of a "Pass-the-Hash" attack?
Brute-forcing password hashes offline
Bypassing authentication using stolen hash values
Exploiting weak hash algorithms like MD5
Intercepting hashes in transit
Which of the following is NOT a valid method to prevent CSRF attacks?
Using SameSite cookies
Implementing CAPTCHAs
Adding CSRF tokens
Disabling JavaScript
What does the Linux command grep -r "password" /etc/ do?
Searches for the word "password" recursively in /etc/
Replaces "password" with "********" in /etc/
Lists all files in /etc/ containing passwords
Encrypts passwords in /etc/shadow
Which cryptographic attack exploits small differences in encryption time?
Birthday attack
Timing attack
Rainbow table attack
Meet-in-the-middle attack
What is the primary purpose of SELinux in Linux?
To block all incoming network traffic
To enforce mandatory access control (MAC) policies
To encrypt filesystem data
To prevent buffer overflow attacks
Which protocol is most vulnerable to "Downgrade Attacks"?
SSH
TLS
IPsec
DNSSEC
What does the Linux command iptables -A INPUT -p tcp --dport 22 -j DROP do?
Allows SSH traffic on port 22
Blocks all incoming SSH connections
Logs SSH connection attempts
Redirects port 22 traffic
Which of the following is NOT a side-channel attack?
Spectre
Meltdown
Heartbleed
Rowhammer
What is the main purpose of a "Nonce" in cryptography?
To ensure data integrity
To prevent replay attacks
To generate random keys
To encrypt large files
Which Linux file contains encrypted password hashes?
/etc/passwd
/etc/shadow
/etc/group
/etc/security
What does the command netcat -lvp 4444 do?
Starts a reverse shell listener
Scans open ports on a remote host
Encrypts traffic on port 4444
Blocks incoming connections on port 4444
Which Linux tool is used for auditing file integrity?
tripwire
snort
nmap
metasploit
What is the purpose of sudo visudo?
To edit the sudoers file safely
To escalate privileges without a password
To disable sudo access for all users
To log all sudo commands
Which Linux command displays kernel-level process activity?
top
htop
dmesg
strace
What attack abuses DNS to redirect traffic to malicious servers?
DNS tunneling
DNS spoofing
DNS amplification
DNSSEC hijacking
Which encryption mode is vulnerable to "Padding Oracle Attacks"?
AES-GCM
RSA-OAEP
CBC
ECDSA
What is the primary risk of "Kerberoasting"?
Exploiting weak Kerberos TGTs
Stealing service account password hashes
Bypassing MFA in Active Directory
Spoofing Kerberos tickets
Which tool is used for network traffic analysis and packet sniffing?
Burp Suite
Wireshark
Nmap
John the Ripper
What does "RAID 1" provide in terms of security?
Data striping for performance
Disk mirroring for redundancy
Parity-based error correction
Encryption at rest
Which vulnerability allows attackers to inject malicious scripts into trusted websites?
CSRF
SSRF
XSS
RCE
What is the main purpose of "Shodan"?
Password cracking
Searching for vulnerable IoT devices
Encrypting network traffic
Detecting malware signatures
Which attack involves forcing a system to downgrade its security protocols?
FREAK attack
BEAST attack
POODLE attack
CRIME attack
What does "ASLR" protect against?
Buffer overflow exploits
Phishing attacks
Man-in-the-middle attacks
SQL injection
Which of the following is NOT a valid OWASP Top 10 vulnerability?
Insecure Deserialization
XML External Entities (XXE)
ARP Spoofing
Broken Access Control
