WorksheetsCompTIA Security+ Lesson 13 Revision
Total questions: 60
Worksheet time: 30mins
Malware is any software intentionally designed to damage systems or data.
True
False
A ______ virus attaches itself to programs and runs when the program is launched.
file-infecting
memory-resident
boot-sector
macro
Which malware spreads without user action, often across networks?
Worm
Rootkit
Trojan
Spyware
Do rootkits try to hide their presence from detection tools?
Yes, that’s true
No, that’s not true
Which malware pretends to be useful software but has hidden malicious code?
Trojan
Worm
Spyware
Spyware secretly monitors user activity and collects information.
True
False
A ______ virus runs from memory and can infect without host files.
memory-resident
boot-sector
macro
script
Which malware records keystrokes to steal credentials?
Keylogger
Rootkit
Spyware
Adware
Adware displays unwanted ______ to generate revenue.
ads
files
scripts
ports
Does ransomware lock data until payment is made?
Yes, that’s true
No, that’s not true
Crypto-malware encrypts ______ until a ransom is paid.
files
ports
packets
logs
Which malware uses many computers to send traffic at once?
Botnet
Trojan
Spyware
Macro virus
A polymorphic virus changes its ______ to avoid detection.
code
target
password
command
True or False: Fileless malware runs in memory without files.
True
False
Logic bombs trigger when certain ______ are met.
conditions
passwords
servers
policies
Backdoors allow attackers to bypass normal ______.
authentication
firewall
hashing
logging
Mobile malware often spreads via malicious ______.
apps
cables
routers
alerts
Yes or No: Spyware is always installed knowingly by the user.
Yes, that’s true
No, that’s not true
Which malware disables security tools to remain hidden?
Rootkit
Trojan
Adware
Keylogger
Fill in the blank: ______ viruses spread through infected documents with macros.
Macro
Script
Boot-sector
Fileless
A ______ attack overloads a target with traffic to disrupt service.
DoS
SQL injection
Buffer overflow
Phishing
Which is a distributed form of denial-of-service attack?
DDoS
DNS hijacking
Port scanning
IP spoofing
Does phishing trick users into revealing sensitive information through fake emails?
Yes, that’s true
No, that’s not true
Spear phishing targets ______ users with customized messages.
specific
random
unknown
guest
Whaling attacks are aimed at ______.
executives
students
IT staff
vendors
Smishing uses ______ messages for phishing.
SMS
DNS
FTP
Pharming redirects users to fake ______.
websites
apps
switches
firewalls
True or False: Vishing is phishing through voice calls.
True
False
An SQL ______ attack manipulates queries to access unauthorized data.
injection
overflow
flooding
hashing
Buffer overflow attacks try to overwrite ______ memory.
system
encrypted
firewall
packet
Which attack uses precomputed hashes to crack passwords?
Rainbow table
SQL injection
Keylogger
DoS
Brute force attacks try all possible ______.
passwords
packets
servers
policies
True or False: Dictionary attacks use common words to guess passwords.
True
False
Privilege escalation gives an attacker higher-level ______.
access
logging
routing
encryption
Fill in the blank: ______ engineering manipulates people to reveal secrets.
Social
Network
File
Memory
Tailgating occurs when someone enters by following an ______ person.
authorized
unknown
blocked
malicious
Does shoulder surfing mean watching someone type a password?
Yes, that’s true
No, that’s not true
True or False: DNS poisoning redirects traffic to malicious sites.
True
False
Man-in-the-middle attacks intercept ______ in transit.
communications
power
storage
policies
ARP spoofing sends false ______ messages on a LAN.
ARP
SMTP
DNS
NTP
Replay attacks capture and resend valid ______.
packets
passwords
servers
hashes
True or False: Downgrade attacks force systems to use weaker security.
True
False
Fill in the blank: Birthday attacks exploit hash ______.
collisions
passwords
packets
encryption
Which attack tries to guess session IDs or tokens?
Session hijacking
Buffer overflow
ARP spoofing
Keylogger
Do pass-the-hash attacks reuse stolen password hashes?
Yes, that’s true
No, that’s not true
Fill in the blank: Cross-site ______ allows attackers to inject malicious scripts.
scripting
routing
logging
signing
Which attack tricks a user’s browser into sending malicious requests?
Cross-site request forgery
Privilege escalation
Ransomware
Sniffing
True or False: Clickjacking hides malicious links under legitimate elements.
True
False
Which attack locks users out of systems until ransom is paid?
Ransomware
Trojan
Adware
Keylogger
Dictionary attacks are a type of ______ attack on passwords.
offline
physical
social
session
Does SQL injection affect the database layer of applications?
Yes, that’s true
No, that’s not true
Fill in the blank: A race ______ occurs when two processes compete for resources.
condition
state
policy
error
Integer overflow exploits errors in handling numeric ______.
values
packets
servers
ports
Which attack relies on exploiting memory allocation issues?
Buffer overflow
Brute force
Whaling
Smishing
True or False: Zero-day attacks target vulnerabilities not yet patched.
True
False
Credential stuffing uses stolen ______ on multiple accounts.
logins
files
routers
apps
Fill in the blank: ______ harvesting collects usernames and passwords in bulk.
Credential
Network
Buffer
Token
Which is a wireless attack exploiting unsecured access points?
Evil twin
Keylogger
Botnet
Macro virus
Yes or No: Rainbow tables are mainly used to secure data.
Yes, that’s true
No, that’s not true
Cryptographic attacks often aim to break data ______.
encryption
routing
storage
policies
