WorksheetsCybersecurity - Assessment Review - SGM #2
Total questions: 20
Worksheet time: 10mins
Which of the following would pose the greatest threat to a user's personal privacy if it were to be leaked to the public?
The IP address of the user’s computer
The user's browser cookies
The user's email address
The user's public key for encryption
In the context of password generation, for what does the acronym OTP stand?
One-time password
One-time paradox
One-time phishing
None of the above
In 2017, the credit report company Equifax suffered a data breach that exposed the PII of more than 100 million Americans to attackers. The exposed data included names, home addresses, phone numbers, dates of birth, Social Security numbers, and driver's licence numbers.
With access to only that information, which of these actions could not be taken by an attacker?
An attacker could sell the Social Security numbers to another attacker on the Internet
An attacker could send an email to an affected person that contained their PII and a threat to reveal them
An attacker could post the home addresses on a public website
An attacker could steal the identity of one of the affected people
Which of the following could not occur if your computer is connected to the Internet over a rogue access point?
The rogue access point could analyze the types of websites you visit
The rogue access point could modify the contents of your connection to a website
The rogue access point could see what keywords you're searching for on a web search engine
The rogue access point could read the files on your device
Why is a computer virus more dangerous than other types of malware?
A virus can make copies of itself, including copying itself into an existing file
A virus can access the internal system of a computer so that it can change how the operating system works
A virus has access to the user's input devices so that it can see what they type and how they move their mouse cursor
A virus can decrypt any data that has been encrypted on the user's hard drive
Dorothy is a network administrator. Her system has been experimenting with an attack that is using bots to send fake requests to the cloud resources her company uses. This is causing disruption of the availabilities of these resources. How is this attack best described?
PDoS
DDoS
EDoS
DoS
Which of the following best explains how devices and information can be susceptible to unauthorized access if weak passwords are used?
Unauthorized individuals can deny service to a computing system by overwhelming the system with login attempts
Unauthorized individuals can exploit vulnerabilities in compression algorithms to determine a user’s password from their decompressed data
Unauthorized individuals can exploit vulnerabilities in encryption algorithms to determine a user’s password from their encryption key
Unauthorized individuals can use data mining and other techniques to guess a user’s password
It is important that you understand cybersecurity terminology, including terms for different actors in cybersecurity. What is the correct term for a person who uses hacking techniques for illegal activities?
A hacker
A gray hat hacker
A phreaker
A cracker
Which of the following is an example of a strong password?
password123
P@55w0rd!
abc123
qwerty
Which of the following is an example of a social engineering attack?
Running a network vulnerability scan
Installing a software patch
Tricking someone into revealing their password
Configuring a firewall rule
(a) is the term used for a testing environment in a computer system in which new or untested software or coding can be run securely.
Phishing
Sandbox
Engineering
Botnet
What is the name of the process of trying to list all the servers on a network?
Port scanning
Enumeration
Vulnerability scanning
Scouting
Which of the following most accurately defines encryption?
Changing a message so it can only be easily read by the intended recipient
Using complex mathematics to conceal a message
Changing a message using complex algorithms
Applying keys to a message to conceal it
Which of the following scenarios best exemplifies a phishing attack?
A user connects to a public wireless network. An unauthorized individual intercepts data transmitted on the network, looking for private information that can be used to gain access to the user’s accounts.
A user’s e-mail account is overwhelmed with messages containing large attachments, which causes the account to exceed the maximum amount of data allowed and temporarily prevents the user from sending and receiving new messages.
A user receives an e-mail from a sender offering technical help with the user’s computer. The e-mail prompts the user to start a help session by clicking a provided link and entering the username and password associated with the user’s computer.
A user chooses a weak password for an online account. An unauthorized individual successfully guesses the user’s password from a list of common passwords.
The transmission control protocol (TCP) and Internet protocol (IP) are used in Internet communication. Which of the following best describes the purpose of these protocols?
To ensure that communications between devices on the Internet are above a minimum transmission speed
To ensure that private data is inaccessible to unauthorized devices on the Internet
To establish a common standard for sending messages between devices on the Internet
To validate the ownership of encryption keys used in Internet communication
A fraudulent email pretending to be from your bank and asking for your login information is a classic example of what kind of simple cyberattack?
Phishing
Spoofing
DDoS attack
Ransomware
Which of the following is an example of a phishing attack?
Loading malicious software onto a user’s computer in order to secretly gain access to sensitive information
Flooding a user’s computer with e-mail requests in order to cause the computer to crash
Gaining remote access to a user’s computer in order to steal user IDs and passwords
Using fraudulent e-mails in order to trick a user into voluntarily providing sensitive information
Which of the following is a common phishing technique?
Installing antivirus software
Using strong encryption algorithms
Sending deceptive emails to trick users
Conducting regular system backups
What is the purpose of two-factor authentication (2FA)?
To provide additional security by requiring two different passwords
To encrypt sensitive data stored on a computer
To prevent physical theft of devices
To verify a user’s identity using multiple methods
Which of the following actions can help you maintain your digital footprint?
Using privacy settings to limit the audience of your posts and Reviewing posts you are tagged in
Using privacy settings to limit the audience of your posts, Reviewing posts you are tagged in and Goggling yourself on a regular basis
Using privacy settings to limit the audience of your posts, Reviewing posts you are tagged in and Posting long rants when you are angry about school or work
Using privacy settings to limit the audience of your posts, Reviewing posts you are tagged in, Goggling yourself on a regular basis and finally Posting long rants when you are angry about school or work
