WorksheetsPre-test Quiz
Total questions: 15
Worksheet time: 8mins
What is the main purpose of the Vulnerability Assessment (VA) process?
Exploit all target systems
Identify and assess vulnerabilities in the system (Assessment)
Protect systems using antivirus
Hide user activity from logs
What is the main difference between the roles of Red Team and Blue Team in attack simulation scenarios?
Red Team protects the system, Blue Team attacks
Red Team only uses manual tools
Red Team attacks (Attack Simulation), Blue Team defends and detects (Defensive Operation)
Blue Team only works on Linux-based systems
Which of the following is part of the Reconnaissance stage?
DNS Enumeration and Port Scanning
Privilege Escalation
Persistence
Log Analysis
What is XSS (Cross Site Scripting) in the context of Web Application Security?
An attack on the file system
Brute force attack on passwords
An attack that injects malicious scripts into web pages
A technique to bypass firewalls
Which of the following tools is commonly used in the Vulnerability Assessment process?
Nessus, OpenVAS, Nikto
FTK Imager, Velociraptor
Metasploit, Empire
KAPE, Autopsy
In Red Teaming activities, what is meant by Lateral Movement?
Attack on external DNS servers
Movement of access from one host to another within the network (Horizontal Escalation)
Data exfiltration via email
Log deletion to avoid detection
What is the purpose of the Memory Acquisition process in digital forensics by the Blue Team?
To take a snapshot of RAM for forensic analysis (Volatile Artifact Analysis)
To erase all traces of the attack
To detect network traffic
To automatically turn on the firewall
What is the most accurate statement about Atomic Red Team?
Python-based exploit library
Tools for endpoint encryption
Attack simulation scenario library to test Blue Team detection effectiveness
Forensic toolkit for Linux investigations
What is KAPE (Kroll Artifact Parser and Extractor) used for by the Blue Team?
To collect and extract digital artifacts from endpoints for further analysis
To exploit Windows systems
To create reverse shells
To scan internal network ports
The Persistence technique is used by the Red Team to:
Delete system logs
Replace the OS kernel
Ensure access remains after reboot or shutdown (Backdoor Access)
Permanently disable antivirus
What is the role of Velociraptor in the Incident Response process by the Blue Team?
To collect digital artifacts from endpoints in real-time and distributed manner
To perform brute force on internal systems
To insert backdoors into target systems
To automatically configure firewalls and IDS
When the Red Team performs brute force on a Web Application, how can the Blue Team detect it?
By viewing memory dump results
By analyzing HTTP access logs and detecting repeated failed login patterns
By turning on IDS
By viewing the .htaccess file
In the context of Defense Evasion, what is meant by the Living off the Land (LotL) technique?
Attack on kernel files
Abuse of built-in system tools (like powershell.exe, wmic) to avoid detection
Utilization of polymorphic malware
Exploitation of web application logic
When the Blue Team analyzes Persistence, which indicator is relevant to be suspicious?
Number of outgoing ICMP requests
DNS Cache content
Presence of unknown autorun registry or suspicious Scheduled Task (Autorun Artifacts)
Number of connections to port 21
Why is it important to conduct Red Teaming in a Production Environment or a simulation that resembles production?
To blame the IT team if it fails
To test the effectiveness of detection and security response against real scenarios (Realistic Attack Simulation)
To disable antivirus
To reschedule weekly patches
