wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

cyber midterm

Total questions: 54

Worksheet time: 27mins

Name
Class
Date
1.

the potential occurrence of an undesirable event that can eventually damage and disrupt the operational and functional activities of an organization.

a)

cyber threats

b)

threat

c)

Threat Sources

d)

compromised system

2.

Attackers use ___ to infiltrate and steal data such as personal information, financial information, and login credentials

a)

cyber threats

b)

threat

c)

Threat Sources

d)

compromised system

3.

They can also use a ____ to perform malicious activities and launch further attacks.

a)

cyber threats

b)

threat

c)

Threat Sources

d)

compromised system

4.

Threats to data assets can cause:

a)

Cyber sabotage

b)

Fires

c)

Power failures

d)

Shut down

5.

___ as fires, floods, power failures, lightning, meteors, and earthquakes are potential threats to the assets of an organization. For example, these may cause severe physical damage to computer systems.

a)

Structured External Threats

b)

  Intentional Threats

c)

Unintentional Threats

d)

Natural Threats

6.

These threats are performed by insiders within the organization, such as disgruntled or negligent employees, and harm the organization intentionally or unintentionally. Most of these attacks are performed by privileged users of the network.

a)

Unstructured External Threats

b)

Internal Threats

c)

External Threats

d)

Structured External Threats

7.

____ are performed by exploiting vulnerabilities that already exist in a network, without the assistance of insider employees. Therefore, the potential to perform an external attack depends on the severity of the identified network weaknesses. Attackers may perform such attacks for financial gain, to damage the reputation of the target organization, or simply for the sake of curiosity.

a)

Unstructured External Threats

b)

Internal Threats

c)

External Threats

d)

Structured External Threats

8.

Implemented by technically skilled attackers, using various tools to gain access to a network to disrupt services. The motivation behind such attacks includes criminal bribes, racism, politics, terrorism, etc. Examples include distributed ICMP floods, spoofing, and simultaneously executing attacks from multiple sources. Tracking and identifying an attacker executing such an attack can be challenging.

a)

Unstructured External Threats

b)

Internal Threats

c)

External Threats

d)

Structured External Threats

9.

Implemented by unskilled attackers, typically script kiddies who may be aspiring hackers, to access networks. Most of these attacks are performed primarily out of curiosity, rather than with criminal intentions.

a)

Unstructured External Threats

b)

Internal Threats

c)

External Threats

d)

Structured External Threats

10.

Threats that exist due to the potential for ___l errors occurring within the organization. Examples include insider-originating security breaches, negligence, operator errors, unskilled administrators, lazy or untrained employees, and accidents.

a)

Structured External Threats

b)

Unintentional Threats

c)

Unstructured External Threats

d)

Natural Threats

11.

A ____ is a piece of malicious software that is designed to perform activities as intended by the attacker, without user consent. This may be in the form of executable code, active content, scripts, or other kinds of software

a)

Trojan

b)

Malware

c)

Virus

d)

Computer Worms

12.

A program in which malicious or harmful code is contained inside a harmless program or data, which can later gain control and cause damage, such as ruining the file allocation table on a hard disk.

a)

Malware

b)

Virus

c)

Trojan

d)

Computer Worms

13.

A self-replicating program that produces its code by attaching copies of itself to other executable code and operates without the knowledge or consent of the user. Like a biological virus, a computer virus is contagious and can contaminate other files; however, viruses can infect external machines only with the assistance of computer users.

a)

Malware

b)

Virus

c)

Trojan

d)

Computer Worms

14.

Standalone malicious programs that replicate, execute, and spread across network connections independently without human intervention.

a)

Virus

b)

Rootkit

c)

Computer Worms

d)

Trojan

15.

A type of malware that restricts access to the infected computer system or critical files and documents stored on it, and then demands an online ransom payment to the malware creator(s) to remove user restrictions. It is a type of crypto-malware that might encrypt files stored on the system’s hard disk or merely lock the system and display messages meant to trick the user into paying the ransom.

a)

Ransomware

b)

Rootkit

c)

Spyware

d)

Keylogger

16.

  Software programs designed to gain access to a computer without being detected. They are malware that help attackers gain unauthorized access to a remote system and perform malicious activities. The goal of a rootkit is to gain root privileges on a system.

a)

Rootkit

b)

PUAs or Grayware

c)

Spyware

d)

Keylogger

17.

A stealthy computer monitoring software that allows secret recording of all user activities on a target computer. It automatically delivers logs to the remote attacker using the Internet (via email, FTP, command and control through encrypted traffic, HTTP, DNS, etc.).

a)

Rootkit

b)

PUAs or Grayware

c)

Spyware

d)

Keylogger

18.

Potentially unwanted applications or programs (PUAs or PUPs, respectively), also known as grayware/junkware, are potentially harmful applications that may pose severe risks to the security and privacy of data stored in the system where they are installed.

a)

Botnets

b)

PUAs or Grayware

c)

Fileless Malware

d)

Keylogger

19.

A software programs or hardware device that record the keys struck on the computer keyboard (also called keystroke logging) of an individual computer user or a network of computers

a)

Botnets

b)

PUAs or Grayware

c)

Fileless Malware

d)

Keylogger

20.

A collection of compromised computers connected to the Internet to perform a distributed task

a)

Botnets

b)

PUAs or Grayware

c)

Fileless Malware

d)

Keylogger

21.

  Also called ____, it infects legitimate software, applications, and other protocols existing in the system to perform various malicious activities. This type of malware leverages existing vulnerabilities to infect the system. It generally resides in the system’s RAM. It injects malicious code into running processes.

a)

Botnets

b)

PUAs or Grayware

c)

Fileless Malware

d)

Keylogger

22.

It refers to a weakness in the design or implementation of a system that can be exploited to compromise the security of the system. It is frequently a security loophole that enables an attacker to enter the system by bypassing user authentication.

a)

Default Installations

b)

Application

c)

Vulnerability

d)

Keylogger

23.

This is the most common vulnerability and is mainly caused by human error, which allows attackers to gain unauthorized access to the system. It may happen intentionally or unintentionally and affect web servers, application platforms, databases, and networks.

a)

Default Installations

b)

Buffer Overflows

c)

Vulnerability

d)

Misconfiguration

24.

These are usually user-friendly, especially when the device is being used for the first time, when the primary concern is the usability of the device rather than the device’s security. In some cases, infected devices may not contain any valuable information, but are connected to networks or systems that have confidential information that would result in a data breach.

a)

Default Installations

b)

Buffer Overflows

c)

Vulnerability

d)

Misconfiguration

25.

These are common software vulnerabilities that happen due to coding errors that allow attackers to gain access to the target system.

a)

Default Installations

b)

Buffer Overflows

c)

Unpatched Servers

d)

Design Flaws

26.

An essential component of the infrastructure of any organization. There are several cases where organizations run unpatched and misconfigured servers that compromise the security and integrity of the data in their systems.

a)

Default Installations

b)

Buffer Overflows

c)

Unpatched Servers

d)

Design Flaws

27.

Vulnerabilities due to design flaws are universal to all operating devices and systems. Design vulnerabilities, such as incorrect encryption or poor validation of data, are logical flaws in the functionality of the system that attackers exploit to bypass the detection mechanism and acquire access to a secure system.

a)

Default Installations

b)

Operating System Flaws

c)

Unpatched Servers

d)

Design Flaws

28.

Due to vulnerabilities in the operating systems, applications such as trojans, worms, and viruses pose threats. These attacks use malicious code, script, or unwanted software, which results in the loss of sensitive information and control of computer operations

a)

Application Flaws

b)

Operating System Flaws

c)

Open Services

d)

Design Flaws

29.

These are vulnerabilities in applications that attackers exploit. Applications should be secured using the validation and authorization of the user. ____ have security threats such as data tampering and unauthorized access to configuration stores.

a)

Application Flaws

b)

Operating System Flaws

c)

Open Services

d)

Design Flaws

30.

: Open ports and services may lead to the loss of data or DoS attacks and allow attackers to perform further attacks on other connected devices.

a)

Application Flaws

b)

Operating System Flaws

c)

Open Services

d)

Default Passwords

31.

Manufacturers provide users with default passwords to access the device during its initial setup, which users must change for future use

a)

Legacy Platform Vulnerabilities:

b)

Operating System Flaws

c)

Zero-Day Vulnerabilities

d)

Default Passwords

32.

Unknown vulnerabilities in software/hardware that are exposed but not yet patched. The attackers exploit these before being acknowledged and patched by the software developers or security analysts. ___ vulnerabilities are one of the major cyber threats that continuously expose vulnerable systems until they are repaired.

a)

Legacy Platform Vulnerabilities:

b)

Operating System Flaws

c)

Zero-Day Vulnerabilities

d)

Default Passwords

33.

These are exposed from old or familiar code. However, they could cause costly data breaches for organizations. Using these outdated codes, attackers can easily discover zero-day vulnerabilities in the system or software that are not yet patched.

a)

Legacy Platform Vulnerabilities:

b)

Vulnerability Assessment

c)

Zero-Day Vulnerabilities

d)

Default Passwords

34.

The attacker interacts directly with the target network to find vulnerabilities. Active scanning helps in simulating an attack on the target network to uncover vulnerabilities that the attacker can exploit. For example, an attacker sends probes and specially crafted requests to the target host in the network to identify vulnerabilities

a)

Passive Assessment

b)

Active Assessment

c)

Active Scanning

d)

Passive Scanning

35.

The attacker tries to find vulnerabilities without directly interacting with the target network. The attacker identifies vulnerabilities via information exposed by systems during normal communications. For example, an attacker guesses the operating system information, applications, and application and service versions by observing the TCP connection setup and teardown.

a)

Passive Assessment

b)

Active Assessment

c)

Active Scanning

d)

Passive Scanning

36.

A type of vulnerability assessment that uses network scanners to identify the hosts, services, and vulnerabilities present in a network. ___ scanners can reduce the intrusiveness of the checks they perform.

a)

Active Assessment

b)

Internal Assessment

c)

Passive Assessment

d)

External Assessment

37.

____ sniff the traffic present on the network to identify the active systems, network services, applications, and vulnerabilities. This is also provide a list of the users who are currently accessing the network.

a)

Active Assessment

b)

Internal Assessment

c)

Passive Assessment

d)

External Assessment

38.

____ examines the network from a hacker’s point of view to identify exploits and vulnerabilities accessible to the outside world. These types of assessments use external devices such as firewalls, routers, and servers. This is also estimates the threat of network security attacks from outside the organization. It determines the level of security of the external network and firewall

a)

Active Assessment

b)

Internal Assessment

c)

Passive Assessment

d)

External Assessment

39.

·         This involves scrutinizing the internal network to find exploits and vulnerabilities.

a)

Network-based Assessment

b)

Internal Assessment

c)

Passive Assessment

d)

Host-based Assessment

40.

A type of security check that involves conducting a configuration-level check to identify system configurations, user directories, file systems, registry settings, and other parameters to evaluate the possibility of compromise. These assessments check the security of a particular network or server.

a)

Network-based Assessment

b)

Internal Assessment

c)

Passive Assessment

d)

Host-based Assessment

41.

This determines the possible network security attacks that may occur on an organization’s system. These assessments discover network resources and map the ports and services running to various areas of the network.

a)

Network-based Assessment

b)

Application Assessment

c)

Passive Assessment

d)

Host-based Assessment

42.

Focuses on transactional web applications, traditional client-server applications, and hybrid systems. It analyzes all elements of an application infrastructure, including deployment and communication with the client and server. This type of assessment tests the web server infrastructure for any misconfiguration, outdated content, or known vulnerabilities. Security professionals use both commercial and open-source tools to perform such assessments.

a)

Network-based Assessment

b)

Application Assessment

c)

Wireless Network Assessment

d)

Database Assessment

43.

This is any assessment focused on testing the databases for the presence of any misconfiguration or known vulnerabilities. These assessments mainly concentrate on testing various database technologies like MYSQL, MSSQL, ORACLE, and POSTGRESQL to identify data exposure or injection-type vulnerabilities

a)

Network-based Assessment

b)

Distributed Assessment

c)

Wireless Network Assessment

d)

Database Assessment

44.

Determines the vulnerabilities in an organization’s ____. In the past, ____ used weak and defective data encryption mechanisms. Now, standards have evolved, but many networks still use weak and outdated security mechanisms and are open to attack.

a)

Network-based Assessment

b)

Distributed Assessment

c)

Wireless Network Assessment

d)

Database Assessment

45.

This type of assessment, employed by organizations that possess assets like servers and clients at different locations, involves simultaneously assessing the distributed organization assets, such as client and server applications, using appropriate synchronization techniques.

a)

Credentialed Assessment

b)

Distributed Assessment

c)

Wireless Network Assessment

d)

Non-credentialed Assessment, or unauthenticated assessment

46.

This type of assessment is challenging since it is highly unclear who owns particular assets in large enterprises, and even when the security professional identifies the actual owners of the assets, accessing the credentials of these assets is highly tricky since the asset owners generally do not share such confidential information.

a)

Credentialed Assessment

b)

Distributed Assessment

c)

Wireless Network Assessment

d)

Non-credentialed Assessment, or unauthenticated assessment

47.

This assessment is also incapable of detecting the vulnerabilities that are potentially covered by firewalls. It is prone to false-positive outputs and is not reliably effective as compared to credential-based assessment.

a)

Credentialed Assessment

b)

Distributed Assessment

c)

Wireless Network Assessment

d)

Non-credentialed Assessment, or unauthenticated assessment

48.

After performing footprinting and network scanning and obtaining crucial information, if the security professional performs manual research for exploring the vulnerabilities or weaknesses, they manually rank the vulnerabilities and score them by referring to vulnerability scoring standards like CVSS (Common Vulnerability Scoring System) and vulnerability databases like CVE (Common Vulnerabilities and Exposures) and CWE (Common Weakness Enumeration). Such assessments are considered to be ___

a)

Credentialed Assessment

b)

Distributed Assessment

c)

Manual Assessment

d)

Automated Assessment

49.

An assessment where a security professional uses vulnerability assessment tools such as Nessus, Qualys, or GFI LanGuard to perform a vulnerability assessment of the target is called an automated assessment. Unlike manual assessments, the security professional does not perform footprinting and network scanning.

a)

Credentialed Assessment

b)

Distributed Assessment

c)

Manual Assessment

d)

Automated Assessment

50.

: This phase is very crucial in ___ management. In this step, the security analyst performs a ____ on the network to identify the known ___ in the organization’s infrastructure.

a)

Vulnerability Scan

b)

Verification

c)

Remediation

d)

Risk Assessment

e)

Monitor

51.

In this phase, all serious uncertainties that are associated with the system are assessed and prioritized, and remediation is planned to permanently eliminate system flaws. The risk assessment summarizes the vulnerability and risk level identified for each of the selected assets. It determines whether the risk level for a particular asset is high, moderate, or low.

a)

Vulnerability Scan

b)

Verification

c)

Remediation

d)

Risk Assessment

e)

Monitor

52.

The process of applying fixes to vulnerable systems in order to reduce the impact and severity of vulnerabilities. This phase is initiated after the successful implementation of the baseline and assessment steps.

a)

Vulnerability Scan

b)

Verification

c)

Remediation

d)

Risk Assessment

e)

Monitor

53.

In this phase, the security team performs a re-scan of systems to assess if the required remediation is complete and whether the individual fixes have been applied to the impacted assets.

a)

Vulnerability Scan

b)

Verification

c)

Remediation

d)

Risk Assessment

e)

Monitor

54.

Organizations need to perform regular ___ to maintain system security. They use tools such as IDS/IPS and firewalls. Continuous ___ identifies potential threats and any new vulnerabilities that have evolved.

a)

Vulnerability Scan

b)

Verification

c)

Remediation

d)

Risk Assessment

e)

Monitor