WorksheetsCybersecurity Practice
Total questions: 25
Worksheet time: 25mins
A threat actor sets up a rogue access point (AP) at a local cafe. The rogue AP captures traffic and then forwards the traffic to the cafe AP. Which type of attack does this scenario describe?
Ransomware
DDos
Man-in-the Middle
Reconnaissance
You notice that a new CVE has been shared to an email group that you belong to. What should you do first with the CVE?
Record the CVE as part of the disaster recovery plan
Look up the details of the vulnerability to determine whether it applies to your network
Add the CVE to the firewall rules for your organization
Research measures to prevent the CVE from attacking the network
Which password follows strong password policy guidelines?
Snuffy#
1mpressive1
Mar221984
Wh@tareyouDo1ngtoday4
Your supervisor tells you that you will participate in a CVSS assessment. What will you be doing?
Interviewing users to determine their level of cybersecurity awareness
Analyzing host logs to identify abnormal activities
Evaluating end system security and scoring vulverabilities
Performing penetration tests on internal network devices and systems
How do threat actors launch ransomware attacks on organizations?
They implant malware to collect data from the corporation's financial system
They deface an organization's public facing website
They secretly spy on employees and collect their personal information
They lock data and deny access until they receive money
The company web server collect information through a form. The form is accessed by using port 80. The form content is transferred to an encrypted database for storage. You are investigating a complaint that the form content has been compromised..
What is the cause of the security breach?
The data was transferred to the database using a nonsecure protocol
The database was compromised
The content was accessed using HTTP, which is an unencrypted protocol
The web browser used to access the site wasnot updated to the latest version
Which Windows app is a command-line interface that includes a sophisticated scripting language used to automate Windows tasks?
VMware
Microsoft Management Console
MS-DOS
Powershell
How does sandboxing help with the analysis of malware?
It specifies the applications that are authorized for use on the network
It allows suspicious applications to run in a safe and isolated testing environment
It defines the suspicious ormalicious applications that should be blocked
It restricts traffic from passing from one network to another
Why is it necessary to update firmware to the latest version?
To support the latest operating systems and applications
To patch firmware in the kernel of the operating system
To explore new hardware features
To correct security holes and weaknesses
You are going to perform a penetration test on a company LAN. As part of your preparation, you access the company's websites, view webpage source code, and run Internet searches to uncover domain information. You also use social media to gather details about the company and its employees.
Which type of reconnaissance activities are you performing
Active
Offline
Inactive
Passive
Your home network seems to have slowed down considerably. You look at the home router GUI and notice that an unknown host is attached to the network.
What should you do to prevent this specific host from attaching to the network again?
Change the network SSID
Create an IP access control list (ACL)
Block the host IP address
Implement MAC address filtering
An employee accidently sends an email containing sensitive corporate information to an external email address.
Which type of threat does this scenario describe?
Malware
Insider
Phishing
Logic bomb
What is the main purpose of a disaster recovery plan as compared to a business continuity plan?
Limiting operational downtime
Restoring Data access and an IT infrastructure as quickly as possible
Keeping the business open in some capacity during a disaster
Allowing staff to continue to serve customers throughout a disaster
What is the primary purpose of running a vulnerability scan on your network?
To automatically prioritize security weaknesses for immediate remediation
To determine whether systems are subject to CVE's that could be exploited by adversaries
To identify and document the locations of customer and financial databases
To correlate event logs on multiple servers in order to generate intrusion alerts
Which security assessment of IT systems verifies that PII data is available, accurate, confidential, and accessable only by authorized users?
Cyber Kill Chain
Workflow management
Information assurance
Risk Framing
You need to transfer configuration files to a router across an unsecured network.
Which protocol should you use to encrypt the files in transit?
TFTP
SSH
Telnet
HTTP
Which MacOS security feature encrypts the entire MacOS volume?
XProtect
Gatekeeper
FileVault
System Integrity Protection (SIP)
Which data type is protected through hard disk encryption?
Data in Transit
Data in process
Data at rest
Data in use
Your manager asks you to review the output of some vulnerability scans and report anything that may require escalation. What 2 findings should you report for further investigation as potential security vulnerabilities?
(There are 2 answers here, but you can only choose 1. Make sure that you KNOW the 2 answers)
Encrypted passwords
SSH packets
Disabled firewalls
Open Ports
Closed Ports
You need a software solution that performs the following tasks:
Compiles network data
Logs information from many sources
Provides orchestration in the form of case management
Automates incident response workflows
What product should you use?
SOAR
SIEM
CVSS
CVE
A contractor is building a new home for a client. The client decides to install several IoT devices.
What should the client do to ensure that the smart home is less vulnerable to attacks?
Enable the SSID broadcast feature on the wireless router
Connect the IoT devices to different wireless AP's for better protection
Update the firmware on the IoT device regularly
Buy Iot devices with the highest radio frequency so that it is harder to detect
What is the main benefit of using a sandbox environment when analyzing suspicious files?
It increases the speed of malware execution
It prevents the malware from affecting production systems
It allows malware to communicate with external servers
It automatically removes all detected threats
After receiving a report about a new vulnerability affecting your operating system, what should you do first?
Disable all network connections
Notify all users to stop using their computers
Check if your systems are running the vulnerable version
Immediately uninstall the affected software
What network security technology passively monitors network traffic and compares the captured packet stream with known malicious signatures?
Proxy Server
IPS
Honeypot
IDS
A remote worker is visiting a branch office to attend face-to-face meetings. The worker tries to associate their company laptop with the branch wireless access point (WAP) but is unable to do so. What is the possible cause?
The WAP is configured for MAC address filtering
The SSID is not broadcasting
The WAP is using open authentication
The IP address of the laptop is not correct
