WorksheetsKiberbiztonsag alapjai 4
Total questions: 97
Worksheet time: 49mins
What is the main goal of patching in the SDLC?
To add new features
To fix security vulnerabilities
To improve UI
To reduce code size
What is the impact of the Log4Shell vulnerability?
Slower logging
Remote code execution in millions of applications
Memory leaks
SQL injection
What is the CVSS score of the Log4Shell vulnerability?
5.0
7.5
9.0
10.0
What is the main risk of insecure deserialization?
Data loss
Remote code execution
Memory leaks
SQL injection
What is the purpose of monitoring in the SDLC?
To test performance
To detect and respond to security incidents
To encrypt logs
To compile code
What makes mobile devices particularly attractive targets for attackers?
They are rarely used
They store minimal personal data
They contain a wealth of sensitive personal information
They are not connected to the internet
What was the first known mobile malware?
Pegasus
FluBot
Cabir
Zeus
What is a key risk of using public Wi-Fi networks?
Faster speeds
Man-in-the-middle attacks
Better encryption
Reduced latency
What is a “zero-click” exploit, as seen in Pegasus spyware?
Requires user to click a malicious link
Requires physical access to the device
Exploits vulnerabilities without user interaction
Only affects Android devices
What is the main benefit of biometric authentication?
It is always more secure than passwords
It replaces encryption
It offers fast and user-friendly authentication
It stores data in the cloud
What is the purpose of the secure boot process?
To speed up device startup
To encrypt user data
To verify each stage of the boot chain and prevent tampering
To allow app installation
What is a key difference between full disk encryption and file-based encryption?
Full disk encryption is faster
File-based encryption allows more granular access control
File-based encryption is less secure
Full disk encryption uses multiple keys
What is a major limitation of VPNs?
They encrypt all traffic
They prevent fingerprinting
They can be slow and require trust in the provider
They are free and unlimited
What is a common attack on mobile networks like 2G and 3G?
SQL injection
IMSI catching and downgrade attacks
Cross-site scripting
DNS spoofing
What is the main goal of app sandboxing?
To improve app performance
To isolate apps and limit their access to system resources
To allow background services
To enable root access
What is a key security feature of modern Android and iOS systems?
Open bootloaders
Side-loading by default
Runtime permissions and app signing
No encryption
What is a major risk of granting accessibility permissions to apps?
They can access the camera
They can bypass biometric authentication
They can control the device and steal data
They can disable encryption
What is the main purpose of secure enclaves in mobile hardware?
To store photos
To run apps faster
To securely store biometric data and cryptographic keys
To manage network connections
What is a key takeaway from the FluBot malware case?
SMS is a secure communication method
Accessibility permissions are harmless
Malware can spread via contact lists and steal banking data
Android is immune to malware
What is a common feature of secure mobile operating systems like GrapheneOS?
No app permissions
Enhanced privacy and hardened security
No encryption
Unlimited root access
What is the main purpose of app permissions?
To allow all apps to access everything
To restrict app access to sensitive data and features
To improve app speed
To enable background updates
What is a key difference between Android and iOS in terms of app distribution?
Android only allows apps from the Play Store
iOS allows side-loading by default
Android supports side-loading; iOS uses a stricter app review process
iOS has no app sandboxing
What is the main security concern with free VPNs?
They are too fast
They may sell user data
They encrypt too much traffic
They block HTTPS
What is the role of hardware-backed keys in mobile security?
To store passwords in RAM
To enable faster boot times
To securely store cryptographic keys in hardware
To allow app updates
What is the best practice regarding app permissions?
Grant all permissions by default
Disable all permissions
Request only the minimum necessary
What is the best practice regarding app permissions?
Grant all permissions by default
Disable all permissions
Request only the minimum necessary and explain why
Use root access to manage permissions
What is the main security risk of side-loading apps on Android?
Reduced performance
Exposure to unverified and potentially malicious apps
Slower updates
Increased battery usage
What is a key limitation of biometric authentication?
It is always more secure than passwords
It can’t be used on Android
It may lack recovery options if compromised
It stores data in the cloud
What is the function of the “chain of trust” in secure boot?
To allow faster app loading
To verify each boot stage using cryptographic signatures
To encrypt user data
To enable root access
What is the main reason 2G networks are considered insecure?
They use AES encryption
They support VPNs
They lack proper network authentication and use weak ciphers
They are not widely used
What is the purpose of runtime permissions in mobile apps?
To allow apps to run in the background
To request access to sensitive features only when needed
To improve app speed
To bypass encryption
What is a key privacy feature introduced in iOS?
Side-loading
App tracking transparency
Unlimited background access
Root access
What is the main risk of granting apps access to your contact list?
Slower performance
Increased battery usage
Potential for malware to spread via social engineering
Reduced encryption
What is the role of AES-256 in mobile security?
It compresses files
It encrypts data at rest
It speeds up app loading
It disables root access
What is a key difference between 4G and 5G in terms of security?
5G has weaker encryption
4G supports biometric authentication
5G includes enhanced privacy features (depending on provider)
4G is not encrypted
What is the best way to protect your mobile device from malware?
Disable all updates
Use only trusted app stores and review permissions
Enable root access
Use public Wi-Fi without a VPN
What is the primary goal of malware?
To optimize system performance
To update software
To protect user data
To harm or exploit devices or networks
Which of the following is a self-replicating malware that does not require a host file?
Virus
Trojan
Rootkit
Worm
What distinguishes a Trojan from a virus or worm?
It replicates itself
It spreads via networks
It disguises itself as legitimate software
It infects executable files
What is the main function of ransomware?
To delete system files
To spy on users
To display ads
To extort users by encrypting their data
Which malware type is designed to remain hidden and collect information?
Adware
Scareware
Ransomware
Spyware
What is the purpose of scareware?
To encrypt files
To steal credentials
To display ads
To frighten users into taking action
What is a rootkit primarily used for?
Encrypting files
Displaying ads
Establishing remote access
Sending spam
Which malware spreads via social engineering and email attachments, as seen in ILOVEYOU?
RAT
Worm
Virus
Rootkit
What was the main infection method used by the WannaCry ransomware?
Email phishing
USB drives
Exploiting SMB vulnerabilities
Fake antivirus popups
What is the role of antivirus software?
To create malware
To slow down systems
To detect, prevent, and remove malware
To encrypt user data
What is signature-based detection in antivirus software?
Detecting unknown threats
Using AI to detect malware
Matching known malware patterns
Executing malware in a sandbox
What is sandbox execution used for in antivirus tools?
Encrypting files
Running malware in a safe environment
Updating software
Speeding up performance
What is heuristic detection?
Detecting malware based on exact matches
Using AI to create malware
Using generic patterns to detect variants
Encrypting antivirus databases
What is a zero-day exploit?
A known vulnerability
A patched vulnerability
A vulnerability with no known fix
A malware that deletes itself
What is polymorphic malware?
Malware that deletes files
Malware that changes its code on each execution
Malware that only runs once
Malware that targets mobile devices
What is polymorphic malware?
Malware that deletes files
Malware that changes its code on each execution
Malware that only runs once
Malware that targets mobile devices
What is metamorphic malware?
Malware that replicates itself
Malware that encrypts its code
Malware that rewrites its own code to avoid detection
Malware that uses phishing
What is fileless malware?
Malware that infects only USB drives
Malware that operates entirely in memory
Malware that deletes system files
Malware that uses rootkits
What is the purpose of code obfuscation in malware?
To speed up execution
To make analysis harder
To improve compatibility
To reduce file size
What is VirusTotal?
A malware family
A type of ransomware
A free online malware analysis tool
A government agency
What is an APT group?
A type of antivirus
A malware detection tool
A state-sponsored hacking group
A sandbox environment
What is the main limitation of signature-based antivirus detection?
It is too fast
It uses too much memory
It cannot detect unknown threats
It encrypts files
How do malware authors bypass sandbox detection?
By using stronger encryption
By disabling antivirus
By delaying malicious actions
By using phishing emails
What is the difference between polymorphic and metamorphic malware?
Polymorphic malware deletes itself
Metamorphic malware rewrites its own engine
Polymorphic malware is easier to detect
Metamorphic malware uses social engineering
Why is fileless malware harder to detect?
It uses outdated libraries
It runs in safe mode
It never writes to disk
It uses email attachments
What is the role of anomaly detection in antivirus software?
To detect known malware
To scan USB drives
To identify unusual system behavior
To encrypt user data
What is a common social engineering tactic used to bypass antivirus?
Sending encrypted files
Convincing users to disable antivirus
Using polymorphic code
Exploiting SMB vulnerabilities
What is the historical significance of the Creeper worm?
It was the first ransomware
It was the first virus
It was the first worm and led to the first antivirus
It was the first spyware
What is the main goal of scareware?
To encrypt files
To steal passwords
To scare users into installing fake software
To disable antivirus
What is the function of threat intelligence in antivirus systems?
To scan USB drives
To update the operating system
To provide real-time data on emerging threats
To encrypt malware
What is a RAT (Remote Access Trojan) designed to do?
Encrypt files
Display ads
Provide remote control over a system
Scan for vulnerabilities
What is Artificial Intelligence (AI)?
A type of hardware
A programming language
A method for encrypting data
The simulation of human intelligence by machines
What is a Large Language Model (LLM)?
A database of human languages
A type of antivirus
A neural network trained to understand and generate human language
A compiler for machine code
What architecture is commonly used in LLMs?
Convolutional networks
Decision trees
Transformers
Linear regression
What is the purpose of tokenization in LLMs?
To encrypt the input
To split input into smaller units for processing
To compress the output
To translate the input into binary
What is prompt injection?
A method of training AI
A way to speed up inference
A technique to manipulate AI behavior through crafted inputs
A method for compressing prompts
What is a system prompt?
A user command
A type of malware
A background instruction that shapes AI behavior
A debugging tool
What is a user prompt?
A system-level instruction
A training dataset
The input given by the user to the AI
A type of encryption
What is a key defensive use of AI in cybersecurity?
Creating phishing emails
Generating malware
Threat detection and anomaly analysis
Jailbreaking models
What is a key offensive use of AI in cybersecurity?
SIEM augmentation
Secure boot validation
Automated phishing and malware generation
Threat intelligence sharing
What is a major risk of using LLMs in software development?
They are too slow
They require no training
They may introduce security vulnerabilities
They cannot generate code
What is model hallucination?
When a model crashes
When a model generates incorrect or fabricated information
When a model repeats input
When a model fails to tokenize
What is a jailbreaking attack in AI security?
Unlocking a phone
Bypassing safety filters in AI models
Encrypting AI weights
Updating the model
What is model inversion?
Reversing the training process
Reconstructing training data from model weights
Encrypting model outputs
Compressing the model
What is poisoning in AI security?
Injecting malware into AI
Adding falsified data to training sets
Encrypting training data
Disabling AI models
What is the main concern with LLM-generated code?
It is always encrypted
It is too optimized
It may contain vulnerabilities
It cannot be compiled
What is the CASTLE benchmark used for?
Evaluating antivirus software
Testing AI-generated C code for vulnerabilities
Measuring AI speed
Encrypting AI models
What is the main difference between traditional and AI cybersecurity?
AI security focuses on protecting networks
Traditional security uses AI models
AI security focuses on protecting models and data pipelines
Traditional security uses transformers
What is a key risk of overreliance on LLMs in development?
Faster debugging
Reduced memory usage
Reduced critical thinking and unsafe code
Improved documentation
What is the role of adversarial testing in AI security?
Encrypting AI models
Testing AI with malicious inputs to find weaknesses
Speeding up inference
Compressing training data
What is the future of AI in cybersecurity likely to include?
Less automation
Manual code reviews
AI systems attacking and defending against each other
No use in security
What is the main challenge with protecting data in an LLM’s context window?
It is encrypted
It is stored offline
It is difficult to prevent leakage once loaded
It is always deleted
What is a key limitation of LLMs in answering difficult questions?
They are too fast
They hallucinate less
They often overestimate their capabilities
They require no tools
What is the main concern with AI-generated phishing emails?
They are easy to detect
They are poorly written
They are highly personalized and convincing
They are only used in spam
What is the main risk of model theft?
Slower inference
Loss of intellectual property and data leakage
Increased training time
Reduced accuracy
What is the main benefit of using LLMs in security automation?
Slower response time
Manual triaging
Automatic playbook generation and triage
Reduced detection
What is the main concern with explainability in AI?
It improves accuracy
It reduces hallucinations
It makes it hard to understand model decisions
It increases training time
What is the role of embeddings in AI security?
Encrypting data
Representing data in vector space for analysis
Compressing models
Speeding up tokenization
What is the main concern with AI-generated documentation?
It is too detailed
It is always accurate
It may contain hallucinated or incorrect information
It is encrypted
What is the main reason AI is used in fuzzing?
To encrypt inputs
To generate random passwords
To discover vulnerabilities through automated input generation
To compress logs
What is the main concern with using LLMs for secure code generation?
They are too slow
They always use best practices
They may introduce unsafe patterns even without being asked
They require manual compilation
