NEW
Font size
WorksheetsAP Cyber- Cisco-Module 1-4
Total questions: 50
Worksheet time: 50mins
What is the path or method used by a threat actor to gain access to a system or network called?
Attack Vectors
Security Patch
Firewall Rule
Encryption Key
Who are individuals or groups who pose a risk to cybersecurity, categorized by their motivations and skills?
Threat Actors
Security Analysts
Network Engineers
System Administrators
Which type of hacker uses their skills for defensive purposes, with permission?
White Hat Hackers
Black Hat Hackers
Grey Hat Hackers
Script Kiddies
Which type of hacker operates without permission but often does not have malicious intent and may expose vulnerabilities to push for a fix?
Gray Hat Hackers
Black Hat Hackers
Script Kiddies
State-sponsored Hackers
Which type of hacker hacks without permission for personal gain, criminal activity, or other harmful purposes?
Black Hat Hackers
White Hat Hackers
Grey Hat Hackers
Script Kiddies
Who are individuals who discover and sell information about zero-day vulnerabilities?
Vulnerability Brokers
Penetration Testers
White Hat Hackers
Security Analysts
Who are individuals or groups motivated by financial gain in the context of hacking?
Cybercriminals
White hat hackers
Hacktivists
Script kiddies
Who are hacking teams sponsored by a government to conduct cyber warfare, espionage, or intelligence gathering?
State-Sponsored Hackers
Script Kiddies
Hacktivists
Cybercriminals
What are technologies and processes used to prevent sensitive data from leaving a company's network called?
Data Loss Prevention (DLP)
Network Address Translation (NAT)
Virtual Private Network (VPN)
Intrusion Detection System (IDS)
What are ways data can be lost, such as physical theft of devices, accidental deletion, malicious insider activity, or external cyberattacks, called?
Common Data Loss Vectors
Data Encryption Methods
Network Protocols
User Authentication Factors
What is the process of identifying, assessing, and mitigating risks to an organization's assets called?
Risk Management
Asset Allocation
Resource Planning
Incident Response
What is the process of identifying and analyzing potential risks called?
Risk Assessment
Risk Ignorance
Risk Elimination
Risk Acceptance
What are measures put in place to reduce risk, such as firewalls, policies, or locks, called?
Security Controls
Threat Vectors
Vulnerabilities
Attack Surfaces
What are forensically identifiable artifacts of a cyberattack, such as malicious file hashes or IP addresses, called?
Indicators of Compromise (IOCs)
Digital Certificates
Access Control Lists (ACLs)
Security Policies
Which U.S. federal agency is involved in cybersecurity and is abbreviated as CISA?
Cybersecurity and Infrastructure Security Agency
Central Intelligence and Security Administration
Civilian Internet Security Agency
Critical Information Systems Authority
Which non-profit organization is focused on promoting cybersecurity awareness and is abbreviated as NCSA?
National Cyber Security Alliance
Network Cyber Safety Association
National Computer Security Agency
National Council for Secure Access
What term describes the path or method used by a threat actor to gain access to a system?
Threat Domain
Cyber Kill Chain
Attack Vector
Vulnerability Broker
An individual who uses their hacking skills with permission to find vulnerabilities in a company's system is a:
Black Hat Hacker
Gray Hat Hacker
White Hat Hacker
Script Kiddie
Which of the following is a primary goal of a state-sponsored hacker?
Financial gain through ransomware
Political or social protest
Espionage or cyber warfare
Selling vulnerabilities for profit
What is the main purpose of Data Loss Prevention (DLP) solutions?
To encrypt all company data
To prevent unauthorized access to a network
To stop sensitive data from leaving the organization
To perform regular backups of critical files
Which of the following is an example of an administrative security control?
A firewall
A security policy
A physical lock on a server room
An intrusion detection system (IDS)
A malicious IP address found in system logs after a network breach is an example of a(n):
Threat Domain
Indicator of Compromise (IOC)
Vulnerability
Exploitation Vector
The phase of the cyber kill chain where the attacker establishes a command-and-control channel is known as:
Delivery
Installation
Command and Control
Exploitation
Which model for intrusion analysis includes the four core elements of Adversary, Capability, Infrastructure, and Victim?
The Cyber Kill Chain
The Diamond Model
The NIST Incident Response Model
The CIA Triad
Which social engineering tactic involves creating a false scenario to gain a victim's trust and information?
Phishing
Baiting
Pretexting
The process of an organization resuming its business operations after a significant disruptive event is called:
Incident Response
Disaster Recovery
Digital Forensics
Risk Assessment
Which phase of reconnaissance involves an attacker using tools to identify open ports and services on a target's network?
Passive Reconnaissance
Active Reconnaissance
Enumeration
Scanning
A type of cyberattack that involves injecting malicious code into an application's database query is known as:
Cross-Site Scripting (XSS)
SQL Injection
Denial of Service (DoS)
Phishing
What is the primary function of digital forensics?
To prevent future cyberattacks
To restore compromised systems
To analyze digital evidence after an incident
To manage an organization's security policies
Which type of threat actor is primarily motivated by a political or social cause?
Cybercriminal
Script Kiddie
Hacktivist
Vulnerability Broker
A rogue access point is a common threat associated with which threat domain?
Application Attacks
Social Engineering
Wireless and Mobile Device Attacks
Insider Threats
The process of identifying, assessing, and mitigating risks to an organization's assets is called:
Security Controls
Incident Response
Risk Management
Disaster Recovery
An organization's formal plan for dealing with a security breach is called a(n):
Disaster Recovery Plan
Risk Management Policy
Incident Response Plan
Security Audit
What is a common data loss vector that involves the physical theft of a device containing sensitive information?
Malware infection
Insider threat
Accidental data deletion
Physical theft
A denial of service (DoS) attack aims to:
Steal sensitive data
Encrypt files and demand a ransom
Make a computer or network resource unavailable to its intended users
Manipulate an individual into revealing confidential information
Which U.S. federal agency is responsible for protecting the nation's critical infrastructure from cyber threats?
CISA
NCSA
FBI
NSA
The term for an individual who uses pre-packaged hacking tools without a deep understanding of what they are doing is:
Cybercriminal
Script Kiddie
Hacktivist
Vulnerability Broker
In the Diamond Model of Intrusion Analysis, which element refers to the tools and exploits used by the attacker?
Infrastructure
Capability
Adversary
Victim
Which of the following is a type of application attack?
Phishing
Social Engineering
SQL Injection
Wireless Eavesdropping
The final phase of the Cyber Kill Chain, where the attacker achieves their ultimate goal, is known as:
Actions on Objectives
Reconnaissance
Delivery
Exploitation
Which of the following is NOT a phase of reconnaissance in the context of a cyberattack?
Passive Reconnaissance
Active Reconnaissance
Data Exfiltration
Scanning
The process of identifying and analyzing potential risks to an organization's assets is known as:
Risk Management
Security Auditing
Risk Assessment
Incident Response
Which type of hacker is a security researcher who discovers a zero-day vulnerability and sells it to a government agency or another party?
Black Hat Hacker
Gray Hat Hacker
White Hat Hacker
Vulnerability Broker
A user receiving a text message that seems to be from their bank asking them to click a link and verify their account information is an example of:
Pretexting
Phishing
Baiting
Social Engineering
The primary purpose of antivirus software is to:
Protect against physical theft
Detect and remove malicious software
Encrypt network traffic
Manage network firewall rules
A company's IT department notices unusual outbound network traffic from a server. Upon investigation, they discover a malware program has been installed and is sending sensitive customer data to an external IP address. The IT team immediately isolates the infected server from the network and begins to analyze the malicious file to understand how it got there. The unusual outbound traffic and the external IP address are examples of:
Social engineering tactics
Application vulnerabilities
Indicators of Compromise (IOCs)
Disaster recovery procedures
A company's IT department notices unusual outbound network traffic from a server. Upon investigation, they discover a malware program has been installed and is sending sensitive customer data to an external IP address. The IT team immediately isolates the infected server from the network and begins to analyze the malicious file to understand how it got there. The action taken by the IT team to disconnect the infected server from the network is part of which phase of the incident response process?
Detection and Analysis
Containment
Eradication
Recovery
Scenario: A company's IT department notices unusual outbound network traffic from a server. Upon investigation, they discover a malware program has been installed and is sending sensitive customer data to an external IP address. The IT team immediately isolates the infected server from the network and begins to analyze the malicious file to understand how it got there. To determine how the malware was installed, the IT team would likely perform a(n):
Risk assessment
Disaster recovery test
This entire scenario, from the initial compromise to the data exfiltration, can be mapped to which model?
The Diamond Model of Intrusion Analysis
The Cyber Kill Chain
The CIA Triad
The Risk Management Framework
The discovery of the malware being installed and sending data out of the network corresponds to which phases of the Cyber Kill Chain?
Reconnaissance and Weaponization
Delivery and Installation
Installation and Actions on Objectives
Command and Control and Delivery
