Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Information Assurance & Security (Cybersec)

Total questions: 141

Worksheet time: 1hrs 11mins

Name
Class
Date
1.

It is the state of the well-being of information and infrastructure in which the possibility of

theft, tampering, or disruption of information and services is kept low or tolerable.

a)

Information Security

b)

Security Policy

c)

Security, Functionality, Usability

d)

Security Challenges

2.

It is the protection or safeguarding of information systems that use, store, and transmit information from unauthorized access, disclosure, alteration, and destruction.

a)

Information Security

b)

Security Policy

c)

Security, Functionality, Usability

d)

Security Challenges

3.

It is a specification of how objects in a security domain are allowed to interact.

a)

Information Security

b)

Security Policy

c)

Security, Functionality, Usability

d)

Security Challenges

4.

Which of the following is NOT under the Need for Security

a)

A greater focus on ease of use with the evolution of technology

b)

Routine tasks rely on the use of computers for accessing, providing, or storing information

c)

Increased network environment and network-based applications

d)

The increased complexity of computer infrastructure administration and management creates a direct impact of security breach on the corporate asset base and goodwill

e)

Technological evolution has eliminated the need for cybersecurity in modern corporate systems.

5.

Elements of Information Security


The assurance that the information is accessible only to authorized people. It occur due to improper data handling or a hacking attempt.

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Authenticity

e)

Non-repudiation

6.

Elements of Information Security


The trustworthiness of data or resources in the prevention of improper and

unauthorized changes – the assurance that information is sufficiently accurate for its purpose.

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Authenticity

e)

Non-repudiation

7.

Elements of Information Security


The assurance that the systems responsible for delivering, storing, and processing

information are accessible when required by authorized users.

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Authenticity

e)

Non-repudiation

8.

Elements of Information Security


The characteristic of communication, documents, or any data that ensures the quality of being genuine or uncorrupted. Controls such as biometrics, smart cards, and digital certificates ensure the authenticity of data, transactions, communications, and documents.

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Authenticity

e)

Non-repudiation

9.

Elements of Information Security


A guarantee that the sender of a message cannot later deny having sent the message and that the recipient cannot deny having received the message. Individuals and organizations use digital signatures to avoid this.

a)

Confidentiality

b)

Integrity

c)

Availability

d)

Authenticity

e)

Non-repudiation

10.

The restrictions imposed on accessing the components of the system.

a)

Security

b)

Functionality

c)

Usability

d)

Availability

11.

The set of features provided by the system.

a)

Security

b)

Functionality

c)

Usability

d)

Availability

12.

The GUI components were used to design the system for ease of use.

a)

Security

b)

Functionality

c)

Usability

d)

Availability

13.

Security Challenges


Which is NOT a part of security challenges

a)

Compliance with government laws and regulations

b)

Lack of qualified and skilled cybersecurity professionals

c)

Difficulty in centralizing security in a distributed computing environment

d)

Difficulty in overseeing end-to-end processes due to complex IT infrastructure

e)

Complete elimination of cybersecurity risks due to advanced technologies

14.

Security Challenges


Which is NOT a part of security challenges

a)

Weak links in supply-chain management

b)

Increase in cybersecurity risks, such as data loss, unpatched vulnerabilities, and errors due to the usage of shadow IT

c)

Shortage of research visibility and training for IT employees

d)

Universal standardization of IT practices across all industries

15.

Security Challenges


Which of the following are a part of security challenges? (4)

a)

Fragmented and complex privacy and data protection regulations

b)

Use of serverless architecture and applications that rely on third-party cloud providers

c)

Compliance issues and issues with data removal and retrieval due to the implementation of Bring Your Own Device (BYOD) policies in companies

d)

Relocation of sensitive data from legacy data centers to the cloud without proper configuration

e)

Cloud migration guarantees automatic compliance with all global data protection laws

16.

It originates from the notion that a target system stores or processes something valuable, which leads to the threat of an attack on the system.

a)

Motive

b)

Goals

c)

Objectives

d)

Vulnerability

17.

Motive (Goal) + Method + Vulnerability = ?

a)

Attack

b)

Method

c)

Objectives

d)

Vulnerability

18.

Classification of Attacks


The intercepting and monitoring of network traffic and data flow on the target network and not tampering with the data. Attackers perform reconnaissance, or the initial phase where attackers gather information about a target system, network, or organization, on network activities using sniffers.

a)

Passive Attacks

b)

Active Attacks

c)

Close-in Attacks

d)

Insider Attacks

e)

Distribution Attacks

19.

Classification of Attacks


These attacks are difficult to detect as the attacker has no active interaction with the target system or network. It also capture the data or files being transmitted in the network without the consent of the user.

a)

Passive Attacks

b)

Active Attacks

c)

Close-in Attacks

d)

Insider Attacks

e)

Distribution Attacks

20.

Classification of Attacks


The tampering of the data in transit or disrupting communication or services between the systems to bypass or break into secured systems.

a)

Passive Attacks

b)

Active Attacks

c)

Close-in Attacks

d)

Insider Attacks

e)

Distribution Attacks

21.

Classification of Attacks


Attacks launch attacks on the target system or network by sending traffic actively that can be

detected.

a)

Passive Attacks

b)

Active Attacks

c)

Close-in Attacks

d)

Insider Attacks

e)

Distribution Attacks

22.

Classification of Attacks


These are performed when the attacker is in close physical proximity to the target system or network. The main goal of performing this type of attack is to gather or modify information or disrupt its access.

a)

Passive Attacks

b)

Active Attacks

c)

Close-in Attacks

d)

Insider Attacks

e)

Distribution Attacks

23.

Classification of Attacks


These are performed by trusted persons who have physical access to the critical assets of the target. They use privileged access to violate rules or intentionally causes a threat to the organization’s information or information systems.

a)

Passive Attacks

b)

Active Attacks

c)

Close-in Attacks

d)

Insider Attacks

e)

Distribution Attacks

24.

Classification of Attacks


Occur when attackers tamper with hardware or software before installation. They tamper with the hardware or software at its source or when it is in transit.

a)

Passive Attacks

b)

Active Attacks

c)

Close-in Attacks

d)

Insider Attacks

e)

Distribution Attacks

25.

Information Security Attack Vector


It refers to the on-demand delivery of IT capabilities in which IT infrastructure and applications are provided to subscribers as a metered service over a network. Clients can store sensitive information in the cloud.

a)

Cloud Computing Threats

b)

Advance Persistent Threats (APT)

c)

Virus and Worms

d)

Ransomware

26.

Information Security Attack Vector


An attack that focuses on stealing information from the victim machine without its user being aware of it. These attacks are generally targeted at large companies and government networks.

a)

Cloud Computing Threats

b)

Advance Persistent Threats (APT)

c)

Virus and Worms

d)

Ransomware

27.

Information Security Attack Vector


These are the most prevalent networking threats and are capable of infecting a network within seconds.

a)

Cloud Computing Threats

b)

Advance Persistent Threats (APT)

c)

Virus and Worms

d)

Ransomware

28.

Information Security Attack Vector


A malware that restricts access to the computer system’s files and folders and demands an online ransom payment to the malware creator(s) in order to remove the restrictions.

a)

Cloud Computing Threats

b)

Advance Persistent Threats (APT)

c)

Virus and Worms

d)

Ransomware

29.

Information Security Attack Vector


It is a self-replicating program that produces a copy of itself by attaching to another computer program, boot sector, or document.

a)

Mobile Threats

b)

Botnet

c)

Virus

d)

Worms

30.

Information Security Attack Vector


It is a malicious program that replicates, executes, and spreads across network connections.

a)

Mobile Threats

b)

Botnet

c)

Virus

d)

Worms

31.

Information Security Attack Vector


Users may download malware-infested applications (APKs) onto their smartphones, which can damage other applications and data or reveal sensitive information to attackers.

a)

Mobile Threats

b)

Botnet

c)

Phishing

d)

Web Application Threats

32.

Information Security Attack Vector


A huge network of compromised systems used by attackers to perform Denial-of-Service attacks.

a)

Mobile Threats

b)

Botnet

c)

Phishing

d)

Web Application Threats

33.

Information Security Attack Vector


The practice of sending an illegitimate email falsely claiming to be from a legitimate site in an attempt to acquire a user’s personal or account information.

a)

Internet of Things (IoT) Threats

b)

Botnet

c)

Phishing

d)

Web Application Threats

34.

Information Security Attack Vector


Attacks such as SQL injection and cross-site scripting have made web applications a favorable target for attackers to steal credentials, set up phishing sites, or acquire private information.

a)

Internet of Things (IoT) Threats

b)

Botnet

c)

Phishing

d)

Web Application Threats

35.

Information Security Attack Vector


These are devices connected to the Internet have little or no security, which makes them vulnerable to various types of attacks.

a)

Internet of Things (IoT) Threats

b)

Botnet

c)

Phishing

d)

Web Application Threats

36.

Information Security Laws and Regulations


This is a proprietary information security standard for organizations that handle cardholder information for the major debit, credit, prepaid, e-purse, ATM, and POS cards.

a)

Payment Card Industry Data Security Standard (PCI DSS)

b)

ISO/IEC 27001:2013

c)

Health Insurance Portability and Accountability Act (HIPAA)

d)

Sarbanes-Oxley (SOX) Act

37.

Information Security Laws and Regulations


This specifies the requirements for establishing, implementing, maintaining, and continually improving an information security management system within the context of an organization.

a)

Payment Card Industry Data Security Standard (PCI DSS)

b)

ISO/IEC 27001:2013

c)

Health Insurance Portability and Accountability Act (HIPAA)

d)

Sarbanes-Oxley (SOX) Act

38.

Information Security Laws and Regulations


It provides federal protections for the individually identifiable health information held by covered entities and their business associates and gives patients an array of rights to that information.

a)

Payment Card Industry Data Security Standard (PCI DSS)

b)

ISO/IEC 27001:2013

c)

Health Insurance Portability and Accountability Act (HIPAA)

d)

Sarbanes-Oxley (SOX) Act

39.

Information Security Laws and Regulations


It aims to protect the public and investors by increasing the accuracy and reliability of corporate disclosures.

a)

Payment Card Industry Data Security Standard (PCI DSS)

b)

ISO/IEC 27001:2013

c)

Health Insurance Portability and Accountability Act (HIPAA)

d)

Sarbanes-Oxley (SOX) Act

40.

Information Security Laws and Regulations


An American copyright law that implements two (2) 1996 treaties from the World Intellectual Property Organization (WIPO): the WIPO Copyright Treaty and the WIPO Performances and Phonograms Treaty.

a)

The Digital Millennium Copyright Act (DMCA)

b)

General Data Protection Regulation (GDPR):

c)

The Federal Information Security Management Act (FISMA):

d)

Data Protection Act 2018 (DPA)

41.

Information Security Laws and Regulations


It provides a comprehensive framework for ensuring the effectiveness of information security controls over information resources that support federal operations and assets.

a)

The Digital Millennium Copyright Act (DMCA)

b)

General Data Protection Regulation (GDPR):

c)

The Federal Information Security Management Act (FISMA):

d)

Data Protection Act 2018 (DPA)

42.

Information Security Laws and Regulations


It is one of the most stringent privacy and security laws globally.

a)

The Digital Millennium Copyright Act (DMCA)

b)

General Data Protection Regulation (GDPR):

c)

The Federal Information Security Management Act (FISMA):

d)

Data Protection Act 2018 (DPA)

43.

Information Security Laws and Regulations


It sets out the framework for data protection law in the UK.

a)

The Digital Millennium Copyright Act (DMCA)

b)

General Data Protection Regulation (GDPR):

c)

The Federal Information Security Management Act (FISMA):

d)

Data Protection Act 2018 (DPA)

44.

Information Security Laws and Regulations


Transactions are electronic exchanges involving the transfer of information between two parties for specific purposes.

a)

Electronic Transactions and Code Set Standards

b)

Privacy Rule

c)

Security Rule

d)

Employer Identifier Standard

45.

Information Security Laws and Regulations


Establishes national standards to protect people’s medical records and other personal health information and applies to health plans, health care clearinghouses, and health care providers that conduct health care transactions electronically.

a)

Electronic Transactions and Code Set Standards

b)

Privacy Rule

c)

Security Rule

d)

Employer Identifier Standard

46.

Information Security Laws and Regulations


Establishes national standards to protect individuals’ electronic personal health information that is created, received, used, or maintained by a covered entity.

a)

National Provider Identifier (NPI) Standard

b)

Enforcement Rule

c)

Security Rule

d)

Employer Identifier Standard

47.

Information Security Laws and Regulations


Requires that each employer have a standard national number that identifies them on standard transactions.

a)

National Provider Identifier (NPI) Standard

b)

Enforcement Rule

c)

Security Rule

d)

Employer Identifier Standard

48.

Information Security Laws and Regulations


It is a unique identification number assigned to covered health care providers.

a)

National Provider Identifier (NPI) Standard

b)

Enforcement Rule

c)

Security Rule

d)

Employer Identifier Standard

49.

Information Security Laws and Regulations


Contains provisions relating to compliance and investigation, as well as the imposition of civil monetary penalties for violations of the HIPAA Administrative Simplification Rules and procedures for hearings.

a)

National Provider Identifier (NPI) Standard

b)

Enforcement Rule

c)

Security Rule

d)

Employer Identifier Standard

50.

Information Security Laws and Regulations


Processing must be lawful, fair, and transparent to the data subject.

a)

Lawfulness, fairness, and transparency

b)

Purpose limitation

c)

Data minimization

d)

Accuracy

51.

Information Security Laws and Regulations


You must process data for legitimate purposes specified explicitly to the data subject when you collect it.

a)

Lawfulness, fairness, and transparency

b)

Purpose limitation

c)

Data minimization

d)

Accuracy

52.

Information Security Laws and Regulations


You should collect and process only as much data as necessary for the purposes specified.

a)

Lawfulness, fairness, and transparency

b)

Purpose limitation

c)

Data minimization

d)

Accuracy

53.

Information Security Laws and Regulations


You must keep personal data accurate and up to date.

a)

Lawfulness, fairness, and transparency

b)

Purpose limitation

c)

Data minimization

d)

Accuracy

54.

Information Security Laws and Regulations


You may only store personally identifying data for as long as necessary for the specified purpose.

a)

Storage limitation

b)

Integrity and confidentiality

c)

Accountability

d)

Purpose limitation

55.

Information Security Laws and Regulations


Processing must be done in such a way as to ensure appropriate security, integrity, and confidentiality (e.g., by using encryption).

a)

Storage limitation

b)

Integrity and confidentiality

c)

Accountability

d)

Purpose limitation

56.

Information Security Laws and Regulations


The data controller is responsible for demonstrating GDPR compliance with all of these principles.

a)

Storage limitation

b)

Integrity and confidentiality

c)

Accountability

d)

Purpose limitation

57.

It is an efficient and effective way of illustrating how an adversary can attack the target organization.

a)

Cyber Kill Chain

b)

Reconnaissance

c)

Indicators of Compromise

d)

Tactics, Techniques, and Procedures

58.

This model helps organizations understand the various possible threats at every stage of an attack and the necessary countermeasures to defend against such attacks.

a)

Cyber Kill Chain

b)

Reconnaissance

c)

Indicators of Compromise

d)

Tactics, Techniques, and Procedures

59.

It performed to collect as much information about the target as possible to probe for weak points before actually attacking.

a)

Reconnaissance

b)

Weaponization

c)

Delivery

d)

Exploitation

60.

They look for information such as publicly available information on the Internet, network information, system information, and organizational information of the target.

a)

Reconnaissance

b)

Weaponization

c)

Delivery

d)

Exploitation

61.

Analyzes the data collected in the previous stage to identify the vulnerabilities and techniques that can be exploited and gain unauthorized access to the target organization.

a)

Reconnaissance

b)

Weaponization

c)

Delivery

d)

Exploitation

62.

It is a key stage that measures the effectiveness of the defense strategies implemented by the target organization based on whether the intrusion attempt of the adversary is blocked or not.

a)

Reconnaissance

b)

Weaponization

c)

Delivery

d)

Exploitation

63.

After the weapon is transmitted to the intended victim, it triggers the adversary’s malicious code to exploit a vulnerability in the operating system, application, or server on a target system.

a)

Reconnaissance

b)

Weaponization

c)

Delivery

d)

Exploitation

64.

The adversary downloads and installs more malicious software on the target system to maintain access to the target network for an extended period.

a)

Installation

b)

Command and Control

c)

Actions and Objectives

d)

Exploitation

65.

The adversary creates a channel, which establishes two-way communication between the victim’s system and the adversary-controlled server to communicate and pass data back and forth.

a)

Installation

b)

Command and Control

c)

Actions and Objectives

d)

Exploitation

66.

The adversary controls the victim’s system from a remote location and finally accomplishes their intended goals.

a)

Installation

b)

Command and Control

c)

Actions and Objectives

d)

Exploitation

67.

It is defined as a guideline that describes the way an attacker performs their attack from beginning to end.

a)

Tactics

b)

Techniques

c)

Procedure

d)

Protection

68.

It is defined as the technical methods used by an attacker to achieve intermediate results during their attack.

a)

Tactics

b)

Techniques

c)

Procedure

d)

Protection

69.

It is defined as the organizational approach followed by the threat actors to launch their attack.

a)

Tactics

b)

Techniques

c)

Procedure

d)

Protection

70.

Describe the way the threat actor operates during different phases of an attack.

a)

Tactics

b)

Techniques

c)

Procedure

d)

Protection

71.

Used in the early stages of an attack must be analyzed properly.

a)

Tactics

b)

Techniques

c)

Procedure

d)

Protection

72.

To launch an attack successfully, threat actors use several techniques during their execution.

a)

Tactics

b)

Techniques

c)

Procedure

d)

Protection

73.

Involve a sequence of actions performed by the threat actors to execute different steps of an attack life cycle.

a)

Tactics

b)

Techniques

c)

Procedure

d)

Protection

74.

These are the clues, artifacts, and pieces of forensic data that are found on a network or operating system of an organization that indicate a potential intrusion or malicious activity in the organization’s infrastructure.

a)

Cyber Kill Chain

b)

Reconnaissance

c)

Indicators of Compromise

d)

Tactics, Techniques, and Procedures

75.

It act as a good source of information about threats that serve as data points in the intelligence process.

a)

Cyber Kill Chain

b)

Reconnaissance

c)

Indicators of Compromise

d)

Tactics, Techniques, and Procedures

76.

Attackers usually prefer e-mail services to send malicious data to the target organization or individual.

a)

E-mail Indicators

b)

Network Indicators

c)

Host-Based Indicators

d)

Behavioral Indicators

77.

E-mail address, e-mail subject, and attachments or links.

a)

E-mail Indicators

b)

Network Indicators

c)

Host-Based Indicators

d)

Behavioral Indicators

78.

Useful for command and control, malware delivery, and identifying details about the operating system, browser type, and other computer-specific information.

a)

E-mail Indicators

b)

Network Indicators

c)

Host-Based Indicators

d)

Behavioral Indicators

79.

URLs, domain names, and IP addresses.

a)

E-mail Indicators

b)

Network Indicators

c)

Host-Based Indicators

d)

Behavioral Indicators

80.

Found by performing an analysis of the infected system within the organizational network.

a)

E-mail Indicators

b)

Network Indicators

c)

Host-Based Indicators

d)

Behavioral Indicators

81.

Filenames, file hashes, registry keys, DLLs, and mutex.

a)

E-mail Indicators

b)

Network Indicators

c)

Host-Based Indicators

d)

Behavioral Indicators

82.

Used to identify specific behavior related to malicious activities, such as code injection into the memory or running the scripts of an application.

a)

E-mail Indicators

b)

Network Indicators

c)

Host-Based Indicators

d)

Behavioral Indicators

83.

Executing a PowerShell script and remote command execution.

a)

E-mail Indicators

b)

Network Indicators

c)

Host-Based Indicators

d)

Behavioral Indicators

84.

In the field of computer security, it refers to exploiting system vulnerabilities and compromising security controls to gain unauthorized or inappropriate access to system resources.

a)

Hacking

b)

Hacker

c)

Programmer

d)

Ethical Hacker

85.

A person who breaks into a system or network without authorization to destroy, steal sensitive data, or perform malicious attacks.

a)

Hacking

b)

Hacker

c)

Programmer

d)

Ethical Hacker

86.

Individuals who use their extraordinary computing skills for illegal or malicious purposes.

a)

Black Hats

b)

White Hats / Penetration Testers

c)

Gray Hats

d)

Suicide Hackers

87.

Also known are Crackers.

a)

Black Hats

b)

White Hats / Penetration Testers

c)

Gray Hats

d)

Suicide Hackers

88.

Are individuals who use their hacking skills for defensive purposes. They have permission from the system owner.

a)

Black Hats

b)

White Hats / Penetration Testers

c)

Gray Hats

d)

Suicide Hackers

89.

Individuals who work both offensively and defensively at various times.

a)

Black Hats

b)

White Hats / Penetration Testers

c)

Gray Hats

d)

Suicide Hackers

90.

Individuals who aim to bring down critical infrastructure for a ‘cause’ and are not worried about facing jail terms or any other kind of punishment.

a)

Black Hats

b)

White Hats / Penetration Testers

c)

Gray Hats

d)

Suicide Hackers

91.

Unskilled hackers who compromise systems by running scripts, tools, and software developed by real hackers.

a)

Script Kiddies

b)

Cyber Terrorist

c)

State-Sponsored Hackers

d)

Hacktivist: Hacktivism

92.

Individuals with a wide range of skills who are motivated by religious or political beliefs to create the fear of large-scale disruption of computer networks.

a)

Script Kiddies

b)

Cyber Terrorist

c)

State-Sponsored Hackers

d)

Hacktivist: Hacktivism

93.

Skilled individuals having expertise in hacking and are employed by the government to penetrate, gain top-secret information from, and damage the information systems of other government or military organizations.

a)

Script Kiddies

b)

Cyber Terrorist

c)

State-Sponsored Hackers

d)

Hacktivist: Hacktivism

94.

It is a form of activism in which hackers break into government or corporate computer systems as an act of protest.

a)

Script Kiddies

b)

Cyber Terrorist

c)

State-Sponsored Hackers

d)

Hacktivist: Hacktivism

95.

A consortium of skilled hackers having their own resources and funding.

a)

Hacker Teams

b)

Industrial Spies

c)

Insiders

d)

Criminal Syndicates

96.

Individuals who perform corporate espionage by illegally spying on competitor organizations.

a)

Hacker Teams

b)

Industrial Spies

c)

Insiders

d)

Criminal Syndicates

97.

Any employee (trusted person) who has access to critical assets of an organization.

a)

Hacker Teams

b)

Industrial Spies

c)

Insiders

d)

Criminal Syndicates

98.

Groups of individuals or communities that are involved in organized, planned, and prolonged criminal activities.

a)

Hacker Teams

b)

Industrial Spies

c)

Insiders

d)

Criminal Syndicates

99.

A group of hackers working together in criminal activities.

a)

Hacker Teams

b)

Industrial Spies

c)

Organized Hackers

d)

Criminal Syndicates

100.

Hacking Cycle Phase 1

a)

Reconnaissance

b)

Scanning

c)

Gaining Access

d)

Maintaining Access

e)

Clearing Tracks

101.

Hacking Cycle Phase 2

a)

Reconnaissance

b)

Scanning

c)

Gaining Access

d)

Maintaining Access

e)

Clearing Tracks

102.

Hacking Cycle Phase 3

a)

Reconnaissance

b)

Scanning

c)

Gaining Access

d)

Maintaining Access

e)

Clearing Tracks

103.

Hacking Cycle Phase 4

a)

Reconnaissance

b)

Scanning

c)

Gaining Access

d)

Maintaining Access

e)

Clearing Tracks

104.

Hacking Cycle Phase 5

a)

Reconnaissance

b)

Scanning

c)

Gaining Access

d)

Maintaining Access

e)

Clearing Tracks

105.

It is the preparatory phase in which an attacker gathers as much information as possible about the target prior to launching the attack.

a)

Reconnaissance

b)

Scanning

c)

Gaining Access

d)

Maintaining Access

106.

A reconnaissance technique that looks through an organization’s trash for any discarded sensitive information.

a)

Dumpster Diving

b)

Active Reconnaissance

c)

Passive Reconnaissance

d)

Trash Diving

107.

Involve direct interactions with the target system by using tools to detect open ports, accessible hosts, router locations, network mapping, details of operating systems, and applications.

a)

Dumpster Diving

b)

Active Reconnaissance

c)

Passive Reconnaissance

d)

Trash Diving

108.

They do not interact with the target directly.

a)

Dumpster Diving

b)

Active Reconnaissance

c)

Passive Reconnaissance

d)

Trash Diving

109.

It is the phase immediately preceding the attack. Here, the attacker uses the details gathered during reconnaissance to scan the network for specific information.

a)

Reconnaissance

b)

Scanning

c)

Gaining Access

d)

Maintaining Access

110.

Detect listening ports to find information about the nature of services running on the target machine.

a)

Port Scanner

b)

Vulnerability Scanner

c)

E-mail Scanner

d)

Hardware Scanner

111.

The most commonly used tool, which can search for thousands of known vulnerabilities on a target network.

a)

Port Scanner

b)

Vulnerability Scanner

c)

E-mail Scanner

d)

Hardware Scanner

112.

This is the phase in which real hacking occurs. Attackers use vulnerabilities identified during the

reconnaissance and scanning phases to gain access to the target system and network.

a)

Reconnaissance

b)

Scanning

c)

Gaining Access

d)

Maintaining Access

113.

Refers to the point where the attacker obtains access to the operating system or applications on the computer or network.

a)

Reconnaissance

b)

Scanning

c)

Gaining Access

d)

Maintaining Access

114.

Technique to exploit the system by pretending to be a legitimate user or a different system, attackers can send a data packet containing a bug to the target system to exploit a vulnerability.

a)

Spoofing

b)

Packet Flooding

c)

Smurf Attacks

d)

Shrek Attacks

115.

Attempt to cause users on a network to flood each other with data, making it appear as if everyone is attacking each other, and leaving the hacker anonymous.

a)

Spoofing

b)

Packet Flooding

c)

Smurf Attacks

d)

Shrek Attacks

116.

Breaks the availability of essential services. Sends an overwhelming volume of data packets are sent to a targeted server or network system

a)

Spoofing

b)

Packet Flooding

c)

Smurf Attacks

d)

Shrek Attacks

117.

The phase when the attacker tries to retain their ownership of the system.

a)

Reconnaissance

b)

Scanning

c)

Gaining Access

d)

Maintaining Access

118.

It refers to the activities carried out by an attacker to hide malicious acts.

a)

Reconnaissance

b)

Clearing Tracks

c)

Gaining Access

d)

Maintaining Access

119.

It is the process of hiding data in other data, for instance, in image and sound files.

a)

Steganography

b)

Tunneling

c)

Pipette

d)

Burette

120.

Takes advantage of the transmission protocol by carrying one protocol over another.

a)

Steganography

b)

Tunneling

c)

Pipette

d)

Burette

121.

Refers to a person who enjoys learning the details of computer systems and stretching their capabilities.

a)

Hacker

b)

Hack

c)

Cracker / Attacker

d)

Ethical Hacker

122.

Describes the rapid development of new programs or the reverse engineering of existing software to make it better or more efficient in new and innovative ways.

a)

Hacker

b)

Hack

c)

Cracker / Attacker

d)

Ethical Hacker

123.

Refer to persons who employ their hacking skills for offensive purposes.

a)

Hacker

b)

Hack

c)

Cracker / Attacker

d)

Ethical Hacker

124.

Refers to security professionals who employ their hacking skills for defensive purposes.

a)

Hacker

b)

Hack

c)

Cracker / Attacker

d)

Ethical Hacker

125.

It is the use of advanced Google search operators for creating complex search queries to extract sensitive or hidden information.

a)

Google Hacking

b)

Advanced Google Hacking

c)

Chrome Hacking

d)

Chromium Hacking

126.

It is the art of creating complex search engine queries. Queries can retrieve valuable data about a target company from Google search results.

a)

Google Hacking

b)

Advanced Google Hacking

c)

Chrome Hacking

d)

Chromium Hacking

127.

This operator restricts search results to the specified site or domain.

a)

site

b)

allinurl

c)

inurl

d)

allintitle

128.

This operator restricts results to only the pages containing all the query terms specified in the

URL.

a)

site

b)

allinurl

c)

inurl

d)

allintitle

129.

This operator restricts the results to only the pages containing the specified word in the URL.

a)

site

b)

allinurl

c)

inurl

d)

allintitle

130.

This operator restricts results to only the pages containing all the query terms specified in

the title.

a)

site

b)

allinurl

c)

inurl

d)

allintitle

131.

This operator restricts results to only the pages containing the specified term in the title.

a)

intitle

b)

inanchor

c)

allinanchor

d)

cache

132.

This operator restricts results to only the pages containing the query terms specified in the

anchor text on links to the page.

a)

intitle

b)

inanchor

c)

allinanchor

d)

cache

133.

This operator restricts results to only the pages containing all query terms specified in the

anchor text on links to the pages.

a)

intitle

b)

inanchor

c)

allinanchor

d)

cache

134.

This operator displays Google's cached version of a web page instead of the current version of

the web page.

a)

intitle

b)

inanchor

c)

allinanchor

d)

cache

135.

This operator searches websites or pages that contain links to the specified website or page.

a)

link

b)

related

c)

info

d)

location

136.

This operator displays websites that are similar or related to the URL specified.

a)

link

b)

related

c)

info

d)

location

137.

This operator finds information for the specified web page.

a)

link

b)

related

c)

info

d)

location

138.

This operator finds information for a specific location.

a)

link

b)

related

c)

info

d)

location

139.

This operator allows you to search for results based on a file extension.

a)

Filetype

b)

related

c)

info

d)

location

140.

It automatically extracts specific information from web pages.

a)

Web Data Extractor

b)

Whois Lookup

c)

ICMP Traceroute

d)

TCP Traceroute

141.

The services perform a lookup by entering the target's domain or IP address.

a)

Web Data Extractor

b)

Whois Lookup

c)

ICMP Traceroute

d)

TCP Traceroute