wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CompTIA Security+ (SYO-701) Obj 2

Total questions: 117

Worksheet time: 59mins

Name
Class
Date
1.
Which of the following attackers is MOST likely driven by a desire to expose unethical practices within a corporation, even if it means acting in an unethical way themselves?
a)
Organized crime
b)
State-sponsored actor
c)
Hacktivist
d)
White hat hacker
2.
Which of the following BEST describes a threat actor whose primary motivation is to obtain unauthorized access to credit card data?
a)
War
b)
Financial gain
c)
Chaos
d)
Ethical belief
3.
What is the primary difference between an insider threat and a shadow IT threat actor?
a)
Level of access
b)
Malicious intent
c)
Resources/funding
d)
Level of sophistication/capability
4.
What is a similarity between data exfiltration and espionage as motivations for threat actors?
a)
Service disruption
b)
Financial gain
c)
Obtaining sensitive/confidential information
d)
Philosophical/political beliefs
5.
Which of the following motivations is common among Hacktivists?
a)
Political beliefs
b)
Espionage
c)
Service disruption
d)
Data exfiltration
6.
A former technician of Dion Innovations who was recently laid off launches a series of distributed denial of service (DDoS) attacks against the company's main website. Many believe the attacks are a direct response to the technician's termination. What is the likely motivation behind these attacks?
a)
Blackmail
b)
Revenge
c)
Espionage
d)
Financial gain
7.
Sterling, an animal rights activist, infiltrates the network of a company that sells fur coats, blocking customers from accessing the website. His goal is to prevent customers from buying fur coats. What type of act does this example best represent?
a)
Data exfiltration
b)
Service disruption
c)
Espionage
d)
Creating disorder/chaos
8.
Which of the following motivations is MOST likely to drive a nation-state threat actor to launch an attack?
a)
Financial Gain
b)
Political beliefs
c)
Service disruption
d)
Espionage
9.
Which of the following BEST describes an individual who doesn't have authorized access but attempts to breach security using malware or social engineering?
a)
External threat actor
b)
Business partner
c)
Contractor
d)
Insider threat
10.
What is the main danger that comes from Shadow IT?
a)
A larger attack surface
b)
A large scale service disruption
c)
Data losses
d)
Financial losses
11.
Which attribute of a threat actor refers to their ability to develop unique exploit techniques and tools?
a)
Funding
b)
Sophistication
c)
Capability
d)
Resources
12.
Which of the following types of threat actors is most likely to have authorized access to the systems they attack?
a)
Hacktivist
b)
Unskilled Attackers
c)
Insider threat
d)
Organized crime organizations
13.
A hacktivist group targets a government website, flooding it with traffic to take it offline. They claim responsibility for the attack, stating that their goal is to protest the government's new policies that they view as oppressive and harmful to civil liberties. What is the primary motivation for this attack?
a)
Blackmail
b)
Financial Gain
c)
Service Disruption
d)
Philosophical Beliefs
14.
Which group is MOST likely to possess the funding and resources to recruit top talent, including skilled strategists, designers, coders, and hackers?
a)
An open-source development community
b)
A security researcher
c)
An independent black hat hacker
d)
A criminal syndicate
15.
Who, among the following, operates without any prior permissions and may launch attacks from remote locations?
a)
Business partner
b)
External threat actor
c)
Cybercriminal
d)
Internal threat actor
16.
What type of threat actor is motivated by political beliefs and often targets organizations they disagree with?
a)
Insider Threats
b)
Unskilled Attackers
c)
Nation-state Actors
d)
Hacktivists
17.
Sarah was passed over for a promotion again. She has been working hard on a new device because her boss promised her a promotion and a raise. What is the point of her hard work if she isn't going to be rewarded? She takes all of the data about the new device and puts it on the internet. She hopes that someone will produce the new device before her company can and her company will lose all of the money they have invested in research and development. What is her primary motivation for conducting this data exfiltration?
a)
Revenge
b)
Ethical Considerations
c)
Blackmail
d)
Financial Gain
18.
Which of the following threat actors is MOST likely to have the budget and means to develop unique exploits in both software and hardware?
a)
Phishing scammer
b)
Nation-state actor
c)
Distributed denial-of-service (DDoS) Attacker
d)
Ransomware gang
19.
Which of the following motivations refers to the act of stealing information from a system or network?
a)
Ethical motivations
b)
Service disruption
c)
Disruption/chaos
d)
Data exfiltration
20.
You are a security analyst at Dion Training and you discover that an unauthorized device has been connected to the company’s network. As you investigate, you discover that the device was added so the employee could play video games during her breaks. What type of threat actor are you dealing with?
a)
Unskilled Actor
b)
Insider Threat
c)
Shadow IT
d)
Nation-state Actor
21.
Who among the following represents the pinnacle of capability, potentially leveraging both digital and non-digital means to achieve their objectives?
a)
State-sponsored Advanced Persistent Threat
b)
Troll
c)
Grey hat hacker
d)
Whistleblower
22.
Which term relates to the complexity of a threat actor's methods and operations?
a)
Sophistication
b)
Funding
c)
Capability
d)
Resources
23.
What is the name of the attack vector that involves sending fraudulent emails to trick recipients into revealing sensitive information or clicking malicious links?
a)
Phishing
b)
Vishing
c)
Smishing
d)
Misinformation
24.
Which of the following is a type of unsecure wireless network that uses short-range radio waves to connect devices without encryption or authentication?
a)
Cellular
b)
Ethernet
c)
Bluetooth
d)
Wi-Fi
25.
Jason receives an email at his Kelly Innovations LLC account. The email seems to be from Reed, a coworker, and states that Reed urgently needs to see the invoice for a recent project. However, Reed specifies he needs it within the next 10 minutes as he is in a meeting with Sasha and top executives. Jason quickly sends over the invoice without double-checking with Reed. Which type of attack best describes this situation?
a)
Whaling
b)
Cloning
c)
Brute-force attack
d)
Pretexting
26.
Which of the following terms refers to a major program executed by powerful entities to shift public opinion?
a)
Influence campaign
b)
Soft power
c)
Digital diplomacy
d)
Digital espionage
27.
An attacker sets up a rogue access point mimicking a legitimate one at a local cafe. Unsuspecting customers connect to this access point, enabling the attacker to intercept their data. Which of the following BEST describes this threat vector?
a)
Supply chain
b)
Phishing
c)
Default credentials
d)
Wireless network
28.
Which of the following threat vectors primarily involves malicious software or data being transferred or executed from documents, executables, or other common file types?
a)
Email
b)
Business email compromise
c)
Voice call
d)
File-based
29.
Which of the following is the BEST type of backup that allows for the rapid redeployment of an OS without requiring reinstallation of third-party software, patches, and configurations?
a)
Differential backup
b)
File-level backup
c)
Image backup
d)
Incremental backup
30.
You are working remotely and you need to access your company’s network resources. You connect to a public Wi-Fi hotspot at a nearby coffee shop and use a VPN client to establish a secure connection. However, you notice that the VPN client is outdated. What type of vulnerability are you exposing yourself to?
a)
Open service ports
b)
Unsecure networks
c)
Default credentials
d)
Vulnerable software
31.
Which of the following techniques allows an attacker to eavesdrop on a wired network by connecting their device directly to the network cables?
a)
Port Mirroring
b)
Wiretapping
c)
On-path attack
d)
Packet Sniffing
32.
What is the term for a type of open service port that is commonly used for remote access servers and can be used to perform on-path attacks on a Windows computer, but not on computers using other operating systems?
a)
RDP
b)
VNC
c)
SSH
d)
Telnet
33.
Which of the following is a social engineering attack that involves using logos of a real organization to deceive users into trusting a fake website?
a)
Watering hole
b)
Brand impersonation
c)
Pretexting
d)
Misinformation/disinformation
34.
Which of the following is a social engineering technique where an attacker pretends to be someone else, often to gain unauthorized access to systems or information?
a)
Impersonation
b)
Vulnerability Assessment
c)
Reconnaissance
d)
Spoofing
35.
Which of the following is a type of human vector attack that involves creating a fake website address or domain name that resembles a legitimate one, but with slight spelling or punctuation differences?
a)
Business email compromise
b)
Pretexting
c)
Impersonation
d)
Typosquatting
36.
You receive a text message from your bank asking you to verify your account details by clicking on a link. The message looks legitimate, but you are suspicious. What kind of threat vector was used in this attack?
a)
File-based
b)
IM
c)
SMS
d)
Voice call
37.
Which threat vector utilizes malicious attachments or hyperlinks within communications, requiring the attacker to convince the recipient to engage with the content for successful exploitation?
a)
Wireless networks
b)
Supply chain
c)
Email
d)
Database manipulation
38.
You are working on a project with a vendor who provides you with a software application that runs on your computer. The vendor says that the software is secure and does not currently require any updates or patches. He assures you that when updates and patches are available they will be automatically downloaded from the vendor's server and installed on your computer. What type of attack vector is this an example of?
a)
Unsupported systems and applications
b)
Client-based software
c)
Agentless software
d)
Image-based software
39.
Which threat vector focuses on exploiting vulnerabilities in third-party vendors to gain unauthorized access to a primary target's network or data?
a)
Ransomware
b)
Phishing attack
c)
Distributed denial of service (DDoS)
d)
Supply chain attack
40.
You receive an email from your bank asking you to verify your account details by clicking on a link. The email looks legitimate, but you are suspicious. What kind of threat vector was used for this attack?
a)
File-based
b)
Message-based
c)
Agentless
d)
Image-based
41.
Which of the following email security techniques specifically utilizes email certificates to authenticate and safeguard email content?
a)
TLS
b)
SPF
c)
DMARC
d)
S/MIME
42.
An attacker uses a phone call to impersonates a bank representative in order to gather sensitive customer information. Which of the following threat vectors does this describe?
a)
File-based
b)
Spear Phishing
c)
Phishing
d)
Vishing
43.
A tech company discovers that the firmware in some of their devices contains a hidden backdoor. Upon investigation, it's determined that the compromised firmware came from an overseas supplier they contracted with. The backdoor gave attackers remote access to devices without user knowledge. What type of attack vector has the company fallen victim to?
a)
On-path attack
b)
Bluesnarfing
c)
Drive-by download
d)
Supply chain
44.
Which threat vector involves an attacker targeting high-ranking officials or departments within an organization, typically to fraudulently redirect financial transactions or obtain sensitive data?
a)
Voice call
b)
Watering hole
c)
Impersonation
d)
Business email compromise
45.
Which of the following threat vectors is associated with the risks stemming from not changing pre-set login information on systems, potentially allowing easy unauthorized access?
a)
Phishing
b)
Default credentials
c)
Managed service providers
d)
Business email compromise
46.
Which of the following terms refers to a strategy combining espionage, disinformation, hacking, and the use of diplomatic assets often executed by state actors?
a)
Soft power
b)
Cyber diplomacy
c)
Hybrid warfare
d)
Counterintelligence operations
47.
Which of the following is a type of message-based attack that involves sending fraudulent voice calls to trick recipients into revealing sensitive information or performing certain actions?
a)
Smishing
b)
Phishing
c)
Vishing
d)
IM
48.
Which of the following scenarios MOST exemplify a business email compromise?
a)
A CEO's request to finance to wire money urgently.
b)
Receiving spam email about a lottery win.
c)
Spotting a pop-up on a website asking for credit card details.
d)
An email from a coworker asking to review an attached invoice.
49.
You receive a text message from your bank asking you to confirm your account details and PIN by clicking on a link. The message looks legitimate, but you are suspicious. What type of attack might this be an example of?
a)
Typo squatting
b)
Phishing
c)
Smishing
d)
Vishing
50.
An application creates a temporary file to save a value for later use. A malicious actor deletes this file after its creation but before its subsequent use by the application. What type of vulnerability is being exploited in this situation?
a)
Time-of-use (TOU)
b)
Memory leaks
c)
Memory injection
d)
Race conditions
51.
What is the name of the web-based attack that involves entering malicious code into user input fields that are executed by a database server?
a)
Cross-site scripting (XSS)
b)
Structured Query Language injection
c)
Directory traversal
d)
Cross-site request forgery (CSRF)
52.
Which of the following hardware vulnerability involves the ability to modify the software that controls the functionality of a device?
a)
End-of-life vulnerability
b)
Legacy vulnerability
c)
Firmware vulnerability
d)
Side loading
53.
Jason is working on a legacy application that processes user inputs. He notices that unchecked user inputs can be used to manipulate memory locations directly, leading to potential memory injection attacks. To counter this vulnerability, what should Jason prioritize?
a)
Enable firewalls and intrusion detection systems.
b)
Upgrade to the latest version of the application.
c)
Use a different programming language.
d)
Implement stringent input validation and sanitation.
54.
A company’s systems were compromised, and sensitive data was stolen. After investigating, it was found that the breach occurred through a Trojan installed on an employee’s mobile phone. The employee had bypassed the Mobile Device Management (MDM) security controls to install an unauthorized game, which either introduced the Trojan or allowed attackers to exploit the phone's weakened security. Which of the following is the MOST probable cause of this vulnerability?
a)
Buffer overflow on the mobile device
b)
Insecure network configuration
c)
Misconfiguration of security settings
d)
SQL injection in the mobile app
55.
Which of the following are hardware issues that result from products that are no longer being made or supported, but are still usable?
a)
Hardware tampering
b)
Hardware cloning
c)
Legacy vulnerability
d)
End-of-life vulnerability
56.
Which of the following vulnerabilities is unique to cloud computing environments, posing risks related to unauthorized access and data manipulation?
a)
Side loading
b)
Buffer overflow
c)
Cross-site scripting (XSS)
d)
Insecure Interfaces and APIs
57.
Which of the following is an attack where a process verifies the state or value of a resource before using it, but another process has changed it in between?
a)
Virtual machine (VM) escape
b)
Buffer overflow
c)
TOCTOU
d)
Memory Injection
58.
Which of the following is a hardware vulnerability that relates to using devices or components that are no longer supported by the manufacturer, possibly leading to unpatched security risks?
a)
Firmware vulnerability
b)
Legacy vulnerability
c)
Supply Chain vulnerability
d)
End-of-life vulnerability
59.
Elvi downloads an app from a website not associated with Apple on his new iPhone. The app offered free games and wallpapers. He installs the app on his mobile device and grants it all the permissions it requests. He notices that the app does not work as advertised, and instead displays ads and pop-ups on his device. He also notices that his device performance and battery life have degraded significantly. What is the most likely cause of Elvi's problems?
a)
Malicious update
b)
Side loading
c)
Jailbreaking
d)
End of Life vulnerability
60.
Kelsi is browsing an online shopping website that sells various products. She adds some items to her shopping cart and proceeds to checkout. She enters her credit card information, double checks that the credit card information is correct, then clicks on the confirm button. She then receives an email from her bank that informs that her credit card has been charged, but the amount she is charged is more than she expected. She checks her online banking account and sees that there are several transactions that she did not authorize. What type of web-based vulnerability has she likely encountered?
a)
Buffer overflow
b)
Malicious update
c)
Structured Query Language injection (SQLi)
d)
Cross-site scripting (XSS)
61.
Which of the following refers to a vulnerability in software that is unknown to the vendor and often exploited by malicious actors before a patch is released?
a)
Supply chain disruption
b)
Hardware incompatibility
c)
Zero-day
d)
Service disruption
62.
Fedson is an ethical hacker. He has been hired by Gregory's Games to conduct a review of their security. The vulnerability scan of the system found that the company is using a very old piece of software that is no longer supported by the manufacturer. Which type of vulnerability has Fedson found?
a)
Firmware vulnerability
b)
Hardware tampering
c)
End-of-life
d)
Hardware cloning
63.
Which of the following practices is MOST effective in mitigating software supply chain vulnerabilities?
a)
Use encrypted communication for all internal chats.
b)
Limit the number of hardware vendors for an organization.
c)
Maintain a log of all physical accesses to server rooms.
d)
Regular security test of third-party software products.
64.
Which of the following is a common consequence of a Cross-site scripting (XSS) attack?
a)
Denial of service for legitimate users
b)
Theft of user session data
c)
Alteration of database record
d)
Execution of unauthorized commands on the server
65.
Which of the following web-based attacks involves inserting malicious scripts into web pages that can be executed by the browser of unsuspecting users?
a)
Virtual machine (VM) escape
b)
Cross-site scripting (XSS)
c)
SQL Injection
d)
Firmware vulnerability
66.
Dion Training Solutions, a software-as-a-service company, began facing latency issues and, in some cases, outages. The IT team found that a massive amount of traffic was flooding in, but the peculiarity was that the incoming data appeared to be responses to requests that the company never made. These responses came from a wide range of IP addresses scattered globally. Which of the following types of malicious activities is BEST described in this scenario?
a)
Amplified DDoS attack
b)
SQL injection
c)
Reflected DDoS attack
d)
Phishing campaign
67.
Recently, Antatack, a martial arts company, has had a data breech. Barzan, a security analyst, was hired to investigate. He found a rogue WAP near the building. The attacker used the WAP to gain information about Anatack's clients. Which of the following network attacks is BEST demonstrated by this finding?
a)
Amplified
b)
Reflected
c)
Wireless
d)
On-Path
68.
While analyzing network traffic at Dion Training Solutions, Carlos, a security analyst, discovered a specific workstation repeatedly sending HTTPS requests to unfamiliar IP addresses. These requests contained encoded data that matched sensitive company information. Carlos also noted the workstation downloading unknown executables from various domains. Which of the following terms BEST describes the primary malicious activity of extracting sensitive information that Carlos detected?
a)
Malware Propagation
b)
Network Reconnaissance
c)
Data Exfiltration
d)
C2 Communication
69.
While browsing the company portal of Dion Training Solutions, Tina, an employee, attempted to access a link to a third-party site she frequently uses for market research. Instead of reaching the site, she received a message stating that access to this URL was denied due to policy violations. Which of the following terms BEST describes the action experienced by Tina?
a)
Content filtering
b)
Malicious URL
c)
Firewall rejection
d)
Blocked content
70.
While conducting a routine system audit at Kelly Innovations LLC, Enrique, a senior IT administrator, stumbled upon a startling discovery. He found that Jamario, a junior database analyst whose responsibilities typically revolved around running simple queries and generating weekly reports, suddenly had permissions to modify core database structures, including adding and removing tables. Further analysis revealed that these permissions weren't granted through the company's formal access control procedure. Enrique suspected an external intervention that could have allowed Jamario's account to bypass the standard role-based permissions. This is an example of:
a)
SQL injection
b)
Privilege escalation
c)
Session hijacking
d)
Access control list tampering
71.
Enrique was validating the integrity of files in the company's database when he came across two distinct files that, surprisingly, had the same cryptographic hash value. Understanding the implications, Enrique immediately escalated the situation, realizing this could be a potential vulnerability in the hashing algorithm in use. Which of the following BEST describes the anomaly Enrique found in Kelly Innovations LLC's file signatures?
a)
Brute force attack
b)
Time memory trade-off
c)
Hash extension attack
d)
Cryptographic collision
72.
John, a senior executive at Dion Training Solutions, accessed his corporate email from New York at 10:00 AM. The logs also showed a login attempt to the same account from Tokyo at 10:15 AM, and then another one from Paris at 10:30 AM. The IT team at Dion Training Solutions grew concerned about this activity. Which of the following statements BEST describes the activity related to John's account?
a)
Legitimate use of a VPN.
b)
Multi-factor authentication failure.
c)
Detection of impossible travel.
d)
Scheduled system maintenance.
73.
Hani, a security analyst, is investigating a malware incident and discovers that the malware had been placed on the computers weeks ago. At midnight, it triggered a virus that spread across four servers and throughout the organization. The CEO found a message from a former employee stating that he had left a "surprise" for the company. Which type of malware is MOST likely responsible for this incident?
a)
Ransomware
b)
Trojan
c)
Logic bomb
d)
Worm
74.
Jasmine, the manager of a local bank, was puzzled. Every Monday morning, she would find her safe's electronic keypad non-responsive, showing a "maximum attempts reached" error message. However, security footage did not show anyone physically attempting to open the safe over the weekend. Which of the following types of malicious activities is BEST described in this scenario?
a)
Brute force
b)
RFID cloning
c)
Phishing
d)
Environmental attack
75.
Cerys is investigating an incident. She found a hidden program that monitors the network traffic and captures sensitive information. Which of the following types of malware is MOST likely involved in this incident?
a)
Spyware
b)
Ransomware
c)
Trojan
d)
Worm
76.
At a high-security research facility, employees have been noticing some oddities. Every morning for a week, when the first employee arrives, they find the main entrance door slightly ajar, though nothing inside seems to be stolen or disturbed. The facility uses a high-tech access card system for entry, and logs show different authorized personnel supposedly accessing the building multiple times during the night. However, those employees claim they were at home during those hours. What type of malicious activity is MOST likely responsible for these oddities?
a)
RFID cloning
b)
Malware
c)
Environmental attack
d)
Brute force
77.
Manar is reviewing logs and finds that many logon attempts were made using common words followed by numbers or symbols. Each password is attempted on the 20 computers in the accounting department. He suspects that these passwords were generated by an automated tool. Which of the following password attacks is BEST illustrated by this finding?
a)
Downgrade
b)
Birthday
c)
Spraying
d)
Brute force
78.
Lucas, an executive at Kelly Innovations LLC, started observing some unusual behaviors on his office computer. The system sometimes seemed to be running tasks he hadn't initiated. Lucas asked the IT department to check the machine for signs of malware. IT couldn't find any suspicious files or traditional malware footprints on the system. However, they noticed unauthorized changes in the system's registry values and detected activity suggesting the use of PowerShell scripts to execute tasks. Further, these scripts were leveraging legitimate system scripting tools for scanning and configuration activities. Which type of malware is Lucas's computer MOST likely compromised with?
a)
Bloatware
b)
Fileless Malware
c)
Spyware
d)
Worm
79.
The IT team at Dion Training Solutions noticed that one of their servers was suddenly using 95% of its processing power. This was highly unusual as the typical utilization was around 40%. Upon investigation, they found a process they didn't recognize consuming a large portion of the resources. Which of the following statements describes the MOST likely situation faced by the Dion Training Solutions IT team?
a)
User-initiated large data transfer.
b)
Scheduled backup activity.
c)
Hardware malfunction.
d)
Malicious activity.
80.
An attacker tries to gain access to an account by rapidly guessing commonly used passwords across multiple accounts, hoping to find one that works. This technique avoids triggering account lockouts by using different usernames with each attempt. What type of attack is this?
a)
Password spraying
b)
Rainbow table attack
c)
Brute force attack
d)
Dictionary attack
81.
While monitoring the company's encrypted data transmissions, Jamario noticed that certain data streams, which usually employed robust encryption protocols, were now using older, less-secure encryption standards. He recognized this could make the data more vulnerable to unauthorized decryption. Which of the following BEST captures the type of attack Jamario discovered affecting Kelly Innovations LLC's encrypted transmissions?
a)
Key exchange attack
b)
Cryptographic downgrade
c)
Cipher Block Chaining (CBC) Attack
d)
Data obfuscation
82.
Maria, a cybersecurity analyst, is examining logs from a server with crucial financial data. She spots a few anomalies: a two-hour log gap without planned maintenance, a spike in outbound traffic to an unknown IP just before this gap, multiple failed logins from a foreign IP using valid usernames, and a higher CPU usage during the log gap despite no recorded actions. Which of these observations should Maria be MOST concerned with?
a)
Multiple failed login attempts from a foreign IP.
b)
The increase in CPU usage during the missing log period.
c)
The sudden two-hour gap in the logs.
d)
The spike in outbound traffic to the unfamiliar IP address.
83.
A security analyst is investigating a malware incident and finds that the malware has compromised an account and is using it simultaneously with the legitimate user, creating multiple sessions from different locations or devices. Which of the following indicators of malicious activity is BEST demonstrated by this finding?
a)
Impossible travel
b)
Concurrent session usage
c)
Blocked content
d)
Resource consumption
84.
Kelly Innovations LLC is hosting an offsite meeting at a hotel. Benjamin is trying to access the hotel's Wi-Fi network. Upon connecting, he's not required to input any credentials but is redirected to a splash page when he launches his browser. This page requests his room number and last name. Benjamin is aware of potential threats on open networks and wants to ensure his communications remain confidential. Given this situation, what should Benjamin do to ensure secure communication over the open Wi-Fi?
a)
Connect without hesitation because the splash page uses HTTPS.
b)
Use Wi-Fi Enhanced Open because it uses the Dragonfly handshake.
c)
Establish a VPN connection after associating with the open hotspot.
d)
Transfer confidential files over email since the splash page is secure.
85.
Kelly Innovations LLC, an e-commerce website, experienced a sudden spike in its incoming traffic. The website's logs showed that thousands of requests were being sent per second, originating from just a handful of IP addresses. However, upon further analysis, it was revealed that the request packets contained IP addresses that were not part of the originating addresses. The server quickly became overloaded, preventing access to legitimate users. Which of the following types of malicious activities is BEST described in this scenario?
a)
Reflected DDoS attack
b)
Amplified DDoS attack
c)
Brute force attack
d)
Malware infection
86.
Langa, a security analyst, is investigating a malware incident and finds that the malware has installed a deeply hidden program that allows an attacker to remotely execute commands on the system without detection. Further investigation reveals that the attacker has gained local administrator privileges, and the program is designed to remain concealed within the operating system. Which of the following types of malware is MOST likely involved in this incident?
a)
Rootkit
b)
Worm
c)
Ransomware
d)
Trojan
87.
Sam, a security engineer, is testing the security of a web application and finds that it is vulnerable to a type of attack that involves sending more data than expected to a function, causing it to overwrite adjacent memory locations and execute arbitrary code. Which of the following application attacks is BEST described by this vulnerability?
a)
Replay
b)
Privilege escalation
c)
Injection
d)
Buffer overflow
88.
Martin recently noticed something odd about his personal laptop. He had just typed out a lengthy password for a new online service he was signing up for. Later that day, while he was checking his email, he found a suspicious message seemingly containing the exact same password he had typed earlier, with a message that read, "Is this your password?". Troubled, he delved into his computer's activities but couldn't find any unusual software running. Which of the following types of malware is MOST likely responsible for capturing and transmitting Martin's password?
a)
Worm
b)
Adware
c)
Trojan
d)
Keylogger
89.
Jamario, while analyzing the network logs at BetaLabs, observed multiple requests originating from a single IP address targeting the company's login portal. These requests used different alphanumeric combinations in rapid succession. Furthermore, Jamario's review of the server health metrics revealed periods of intense processing demand during these login attempts. Which of the following activities is MOST likely causing the observations made by Jamario?
a)
Password spraying
b)
Brute force attack
c)
Phishing attack
d)
Replay attack
90.
Shekhar, a security researcher, discovers that two different hashing algorithms produce the same output for the same input. Which of the following cryptographic attacks is BEST illustrated by this finding?
a)
Brute force
b)
Spraying
c)
Collision
d)
Downgrade
91.
The IT team at Dion Training Solutions noticed multiple access attempts for certain services on their server. They had set up firewall rules to prevent access to the services for security purposes. The attempts seemed to come from a variety of IP addresses in rapid succession. Which of the following statements BEST describes the activity occurring in this scenario?
a)
Traffic redirection efforts.
b)
Port scanning activity.
c)
Distributed Denial of Service (DDoS) attack.
d)
Attempted access to blocked ports.
92.
Recently, Kelly Innovations LLC launched a new web application for its clients. Jake noticed that several users reported unexpected changes to their account settings even though they hadn't made any modifications. Emily, analyzing the logs, discovered that many of the affected users were previously on various unrelated external sites just before the unexpected changes occurred. The logs show a valid session cookie for each affected user, but there was no direct user action triggering the change. Which of the following BEST describes the attack that the users of Kelly Innovations LLC's web application might be experiencing?
a)
Cross-site request forgery
b)
Unsecured network sniffing
c)
Session hijacking
d)
Session token prediction
93.
During a routine audit, Enrique, a cybersecurity specialist at Kelly Innovations LLC, noticed that a specific software module was crashing unexpectedly. While inspecting further, he discovered multiple requests that contained exceedingly long strings of characters without any discernible patterns. These strings, when processed, seemed to disrupt the normal execution of the application and caused unexpected behavior. Which of the following BEST defines the type of attack Enrique observed on Kelly Innovations LLC's software application?
a)
Buffer overflow
b)
Parameter tampering
c)
Denial of service (DoS)
d)
Cross-site scripting (XSS)
94.
Upon returning from vacation, Vanessa noticed that her workstation seemed slower than usual. Not only were applications lagging, but there were also instances when scripts would momentarily appear and vanish from her screen. Concerned, she ran her antivirus software, but it didn't detect any malicious files. Puzzled, she decided to consult her company's cybersecurity team. They initiated a deep dive and found that the system was running a series of unusual command line tasks, and there was evidence of unauthorized WMI queries. They also observed that some of the tasks appeared to be initiated by a host process, yet no associated files were detected on the disk. Which of the following types of malware is MOST likely responsible for the oddities on Vanessa's workstation?
a)
Adware
b)
Rootkit
c)
Fileless Malware
d)
Ransomware
95.
Dini is investigating a malware incident. The attacker seems to have information about everything that has been typed on the terminal and has used that information to figure out users' PINs. Which of the following types of malware is MOST likely involved in this incident?
a)
Trojan
b)
Ransomware
c)
Worm
d)
Keylogger
96.
Enrique, the IT head at Dion Consultants, received frantic calls from multiple departments. Users reported that their crucial files were encrypted and they were seeing a countdown timer. The message accompanying the timer indicated that unless a certain amount in cryptocurrency was transferred to a specific address before the countdown ended, the decryption key would be destroyed permanently. Which form of malware has MOST likely targeted Dion Consultants?
a)
Rootkit
b)
Adware
c)
Screen-locking ransomware
d)
Crypto-malware ransomware
97.
One evening, Megan, a database administrator for Kelly Innovations LLC, was alerted to suspicious activity on the company's website. She noticed an unusually high volume of search inquiries, but instead of typical search terms, these entries contained characters such as '=', '%20', and 'OR'. Megan also observed that right after these odd search queries, the server logs displayed unscheduled database retrievals that exposed employee details. Which of the following BEST identifies the type of attack Megan witnessed on Kelly Innovations LLC's website?
a)
Buffer overflow
b)
SQL injection
c)
Cross-site scripting (XSS)
d)
Parameter tampering
98.
Dion Training has recently implemented a new web portal for their customers. During a routine security review, the IT team notices that some suspicious activities have been logged. An unknown user attempted to access the system with a strange pattern: when requesting a particular user file, instead of the usual URL structure ( /users/[username]/profile ) the system registered requests like ( /users/../admin/config ). Within a short span of time, several such patterns were identified, each trying to reach different sensitive files and directories. Given this information, which of the following types of attack is the user MOST likely attempting?
a)
Attempting to inject malicious scripts into the system.
b)
Attempting to escalate their privileges on the system.
c)
Attempting to exploit a buffer overflow vulnerability.
d)
Attempting to access files outside of intended directories.
99.
Ahmed works in the IT department of a healthcare organization. One morning, he opens an email attachment labeled 'urgent patient records.' Shortly after, his files become inaccessible, and a message appears demanding payment in cryptocurrency to restore access. As Ahmed's computer is connected to the network, the malicious software quickly spreads, affecting other systems across the organization. What type of malware has MOST likely infected Ahmed’s system?
a)
Ransomware
b)
Worm
c)
Adware
d)
Spyware
100.
Barzun, a security engineer, is testing new software and discovers a vulnerability that allows users to easily gain root-level access on devices running the software. Which of the following types of application attacks BEST describes this issue?
a)
Replay
b)
Privilege escalation
c)
Buffer overflow
d)
Injection
101.
Which of the following mitigation techniques inspects and controls incoming and outgoing network traffic on a per-application basis?
a)
Data Loss prevention
b)
Intrustion Detection System
c)
Network Segmentation
d)
Host-based Firewall
102.
Which of the following mitigation techniques can help prevent users from making changes to the security features of devices by applying predefined security standards?
a)
Configuration enforcement
b)
Least Privilege
c)
Encryption
d)
Patching
103.
Which of the following mitigation techniques can help enforce compliance with security standards and policies on a system or network by designating programs that are allowed to run and blocking all other programs from being run?
a)
Application allow list
b)
Least Privilege
c)
Patching
d)
Configuration Enforcement
104.
Which of the following mitigation techniques can help reduce the exposure of systems to potential attacks by turning off unneeded or unwanted network communication channels?
a)
Changing Default Passwords
b)
Removing unnecessary software
c)
Disabling ports and protocols
d)
Patching
105.
You are a network engineer for a large hospital that has a complex network with many applications and many employees. You are most concerned with protecting the privacy of patients, so you will need to prevent unauthorized people from seeing data. Which of the following mitigation techniques can help you achieve this goal?
a)
Monitoring
b)
Least Privilege
c)
Isolation
d)
Application allow list
106.
Which of the following ports should be disabled or carefully monitored to prevent unauthorized Voice over IP (VoIP) signaling, which can be an avenue for toll fraud or unauthorized call control?
a)
Port 139
b)
Port 161
c)
Port 110
d)
Port 5060
107.
Which of the following ports, if left open and unmonitored, might allow database queries from unauthorized external sources?
a)
Port 21
b)
Port 443
c)
Port 53
d)
Port 1433
108.
Sofia, an HR manager, requests access to the company's payroll system to view employee records. The IT team grants her permission to view the data but restricts her from modifying any records or accessing other sensitive system areas. What principle is being applied in this case?
a)
Job rotation
b)
Discretionary access control
c)
Separation of duties
d)
Least privilege
109.
Which of the following mitigation techniques can help detect and respond to potential threats or incidents on a system by collecting data about the activities occurring on the system?
a)
Monitoring
b)
Encryption
c)
Isolation
d)
Permissions
110.
Which of the following mitigation technique is BEST for preventing data breaches from devices that are no longer in use?
a)
Patching
b)
Encryption
c)
Decommissioning
d)
Isolation
111.
Which mitigation technique involves shutting off specific entry and exit points in a system to prevent potential vulnerabilities or unauthorized access?
a)
Segmentation
b)
Monitoring
c)
Encryption
d)
Disabling ports
112.
Which of the following mitigation techniques involves using mathematical algorithms to transform data into an unreadable format?
a)
Encryption
b)
Patching
c)
Segmentation
d)
Isolation
113.
Disabling which of the following ports can help prevent the exposure of a commonly used mail transport service, thus reducing the likelihood of mail relay attacks?
a)
Port 22
b)
Port 80
c)
Port 25
d)
Port 3389
114.
Which of the following hardening techniques is MOST effective in preventing easy cracking of passwords through the use dictionaries?
a)
Default password changes
b)
Installation of endpoint protection
c)
Disabling ports and protocols
d)
Device Isolation
115.
Which of the following hardening techniques can help prevent buffer overflow attacks on a system or device by using software that can detect and prevent any attempts to write data beyond the allocated memory space of a program?
a)
Removal of unnecessary software
b)
Isolation
c)
Disabling ports and protocols
d)
Host-based intrusion prevention system (HIPS)
116.
Which mitigation technique is most effective in ensuring that different network components are isolated to prevent potential breaches from spreading?
a)
VPN (Virtual Private Network)
b)
Antivirus software
c)
Data encryption
d)
Network segmentation
117.
Which mitigation technique involves the use of tools like Nagios or Splunk to continuously observe and check the operation of a system or network?
a)
Patching
b)
Monitoring
c)
Segmentation
d)
Hardening techniques