Worksheetscyber midterm
Total questions: 54
Worksheet time: 27mins
the potential occurrence of an undesirable event that can eventually damage and disrupt the operational and functional activities of an organization.
cyber threats
threat
Threat Sources
compromised system
Attackers use ___ to infiltrate and steal data such as personal information, financial information, and login credentials
cyber threats
threat
Threat Sources
compromised system
They can also use a ____ to perform malicious activities and launch further attacks.
cyber threats
threat
Threat Sources
compromised system
Threats to data assets can cause:
Cyber sabotage
Fires
Power failures
Shut down
___ as fires, floods, power failures, lightning, meteors, and earthquakes are potential threats to the assets of an organization. For example, these may cause severe physical damage to computer systems.
Structured External Threats
Intentional Threats
Unintentional Threats
Natural Threats
These threats are performed by insiders within the organization, such as disgruntled or negligent employees, and harm the organization intentionally or unintentionally. Most of these attacks are performed by privileged users of the network.
Unstructured External Threats
Internal Threats
External Threats
Structured External Threats
____ are performed by exploiting vulnerabilities that already exist in a network, without the assistance of insider employees. Therefore, the potential to perform an external attack depends on the severity of the identified network weaknesses. Attackers may perform such attacks for financial gain, to damage the reputation of the target organization, or simply for the sake of curiosity.
Unstructured External Threats
Internal Threats
External Threats
Structured External Threats
Implemented by technically skilled attackers, using various tools to gain access to a network to disrupt services. The motivation behind such attacks includes criminal bribes, racism, politics, terrorism, etc. Examples include distributed ICMP floods, spoofing, and simultaneously executing attacks from multiple sources. Tracking and identifying an attacker executing such an attack can be challenging.
Unstructured External Threats
Internal Threats
External Threats
Structured External Threats
Implemented by unskilled attackers, typically script kiddies who may be aspiring hackers, to access networks. Most of these attacks are performed primarily out of curiosity, rather than with criminal intentions.
Unstructured External Threats
Internal Threats
External Threats
Structured External Threats
Threats that exist due to the potential for ___l errors occurring within the organization. Examples include insider-originating security breaches, negligence, operator errors, unskilled administrators, lazy or untrained employees, and accidents.
Structured External Threats
Unintentional Threats
Unstructured External Threats
Natural Threats
A ____ is a piece of malicious software that is designed to perform activities as intended by the attacker, without user consent. This may be in the form of executable code, active content, scripts, or other kinds of software
Trojan
Malware
Virus
Computer Worms
A program in which malicious or harmful code is contained inside a harmless program or data, which can later gain control and cause damage, such as ruining the file allocation table on a hard disk.
Malware
Virus
Trojan
Computer Worms
A self-replicating program that produces its code by attaching copies of itself to other executable code and operates without the knowledge or consent of the user. Like a biological virus, a computer virus is contagious and can contaminate other files; however, viruses can infect external machines only with the assistance of computer users.
Malware
Virus
Trojan
Computer Worms
Standalone malicious programs that replicate, execute, and spread across network connections independently without human intervention.
Virus
Rootkit
Computer Worms
Trojan
A type of malware that restricts access to the infected computer system or critical files and documents stored on it, and then demands an online ransom payment to the malware creator(s) to remove user restrictions. It is a type of crypto-malware that might encrypt files stored on the system’s hard disk or merely lock the system and display messages meant to trick the user into paying the ransom.
Ransomware
Rootkit
Spyware
Keylogger
Software programs designed to gain access to a computer without being detected. They are malware that help attackers gain unauthorized access to a remote system and perform malicious activities. The goal of a rootkit is to gain root privileges on a system.
Rootkit
PUAs or Grayware
Spyware
Keylogger
A stealthy computer monitoring software that allows secret recording of all user activities on a target computer. It automatically delivers logs to the remote attacker using the Internet (via email, FTP, command and control through encrypted traffic, HTTP, DNS, etc.).
Rootkit
PUAs or Grayware
Spyware
Keylogger
Potentially unwanted applications or programs (PUAs or PUPs, respectively), also known as grayware/junkware, are potentially harmful applications that may pose severe risks to the security and privacy of data stored in the system where they are installed.
Botnets
PUAs or Grayware
Fileless Malware
Keylogger
A software programs or hardware device that record the keys struck on the computer keyboard (also called keystroke logging) of an individual computer user or a network of computers
Botnets
PUAs or Grayware
Fileless Malware
Keylogger
A collection of compromised computers connected to the Internet to perform a distributed task
Botnets
PUAs or Grayware
Fileless Malware
Keylogger
Also called ____, it infects legitimate software, applications, and other protocols existing in the system to perform various malicious activities. This type of malware leverages existing vulnerabilities to infect the system. It generally resides in the system’s RAM. It injects malicious code into running processes.
Botnets
PUAs or Grayware
Fileless Malware
Keylogger
It refers to a weakness in the design or implementation of a system that can be exploited to compromise the security of the system. It is frequently a security loophole that enables an attacker to enter the system by bypassing user authentication.
Default Installations
Application
Vulnerability
Keylogger
This is the most common vulnerability and is mainly caused by human error, which allows attackers to gain unauthorized access to the system. It may happen intentionally or unintentionally and affect web servers, application platforms, databases, and networks.
Default Installations
Buffer Overflows
Vulnerability
Misconfiguration
These are usually user-friendly, especially when the device is being used for the first time, when the primary concern is the usability of the device rather than the device’s security. In some cases, infected devices may not contain any valuable information, but are connected to networks or systems that have confidential information that would result in a data breach.
Default Installations
Buffer Overflows
Vulnerability
Misconfiguration
These are common software vulnerabilities that happen due to coding errors that allow attackers to gain access to the target system.
Default Installations
Buffer Overflows
Unpatched Servers
Design Flaws
An essential component of the infrastructure of any organization. There are several cases where organizations run unpatched and misconfigured servers that compromise the security and integrity of the data in their systems.
Default Installations
Buffer Overflows
Unpatched Servers
Design Flaws
Vulnerabilities due to design flaws are universal to all operating devices and systems. Design vulnerabilities, such as incorrect encryption or poor validation of data, are logical flaws in the functionality of the system that attackers exploit to bypass the detection mechanism and acquire access to a secure system.
Default Installations
Operating System Flaws
Unpatched Servers
Design Flaws
Due to vulnerabilities in the operating systems, applications such as trojans, worms, and viruses pose threats. These attacks use malicious code, script, or unwanted software, which results in the loss of sensitive information and control of computer operations
Application Flaws
Operating System Flaws
Open Services
Design Flaws
These are vulnerabilities in applications that attackers exploit. Applications should be secured using the validation and authorization of the user. ____ have security threats such as data tampering and unauthorized access to configuration stores.
Application Flaws
Operating System Flaws
Open Services
Design Flaws
: Open ports and services may lead to the loss of data or DoS attacks and allow attackers to perform further attacks on other connected devices.
Application Flaws
Operating System Flaws
Open Services
Default Passwords
Manufacturers provide users with default passwords to access the device during its initial setup, which users must change for future use
Legacy Platform Vulnerabilities:
Operating System Flaws
Zero-Day Vulnerabilities
Default Passwords
Unknown vulnerabilities in software/hardware that are exposed but not yet patched. The attackers exploit these before being acknowledged and patched by the software developers or security analysts. ___ vulnerabilities are one of the major cyber threats that continuously expose vulnerable systems until they are repaired.
Legacy Platform Vulnerabilities:
Operating System Flaws
Zero-Day Vulnerabilities
Default Passwords
These are exposed from old or familiar code. However, they could cause costly data breaches for organizations. Using these outdated codes, attackers can easily discover zero-day vulnerabilities in the system or software that are not yet patched.
Legacy Platform Vulnerabilities:
Vulnerability Assessment
Zero-Day Vulnerabilities
Default Passwords
The attacker interacts directly with the target network to find vulnerabilities. Active scanning helps in simulating an attack on the target network to uncover vulnerabilities that the attacker can exploit. For example, an attacker sends probes and specially crafted requests to the target host in the network to identify vulnerabilities
Passive Assessment
Active Assessment
Active Scanning
Passive Scanning
The attacker tries to find vulnerabilities without directly interacting with the target network. The attacker identifies vulnerabilities via information exposed by systems during normal communications. For example, an attacker guesses the operating system information, applications, and application and service versions by observing the TCP connection setup and teardown.
Passive Assessment
Active Assessment
Active Scanning
Passive Scanning
A type of vulnerability assessment that uses network scanners to identify the hosts, services, and vulnerabilities present in a network. ___ scanners can reduce the intrusiveness of the checks they perform.
Active Assessment
Internal Assessment
Passive Assessment
External Assessment
____ sniff the traffic present on the network to identify the active systems, network services, applications, and vulnerabilities. This is also provide a list of the users who are currently accessing the network.
Active Assessment
Internal Assessment
Passive Assessment
External Assessment
____ examines the network from a hacker’s point of view to identify exploits and vulnerabilities accessible to the outside world. These types of assessments use external devices such as firewalls, routers, and servers. This is also estimates the threat of network security attacks from outside the organization. It determines the level of security of the external network and firewall
Active Assessment
Internal Assessment
Passive Assessment
External Assessment
· This involves scrutinizing the internal network to find exploits and vulnerabilities.
Network-based Assessment
Internal Assessment
Passive Assessment
Host-based Assessment
A type of security check that involves conducting a configuration-level check to identify system configurations, user directories, file systems, registry settings, and other parameters to evaluate the possibility of compromise. These assessments check the security of a particular network or server.
Network-based Assessment
Internal Assessment
Passive Assessment
Host-based Assessment
This determines the possible network security attacks that may occur on an organization’s system. These assessments discover network resources and map the ports and services running to various areas of the network.
Network-based Assessment
Application Assessment
Passive Assessment
Host-based Assessment
Focuses on transactional web applications, traditional client-server applications, and hybrid systems. It analyzes all elements of an application infrastructure, including deployment and communication with the client and server. This type of assessment tests the web server infrastructure for any misconfiguration, outdated content, or known vulnerabilities. Security professionals use both commercial and open-source tools to perform such assessments.
Network-based Assessment
Application Assessment
Wireless Network Assessment
Database Assessment
This is any assessment focused on testing the databases for the presence of any misconfiguration or known vulnerabilities. These assessments mainly concentrate on testing various database technologies like MYSQL, MSSQL, ORACLE, and POSTGRESQL to identify data exposure or injection-type vulnerabilities
Network-based Assessment
Distributed Assessment
Wireless Network Assessment
Database Assessment
Determines the vulnerabilities in an organization’s ____. In the past, ____ used weak and defective data encryption mechanisms. Now, standards have evolved, but many networks still use weak and outdated security mechanisms and are open to attack.
Network-based Assessment
Distributed Assessment
Wireless Network Assessment
Database Assessment
This type of assessment, employed by organizations that possess assets like servers and clients at different locations, involves simultaneously assessing the distributed organization assets, such as client and server applications, using appropriate synchronization techniques.
Credentialed Assessment
Distributed Assessment
Wireless Network Assessment
Non-credentialed Assessment, or unauthenticated assessment
This type of assessment is challenging since it is highly unclear who owns particular assets in large enterprises, and even when the security professional identifies the actual owners of the assets, accessing the credentials of these assets is highly tricky since the asset owners generally do not share such confidential information.
Credentialed Assessment
Distributed Assessment
Wireless Network Assessment
Non-credentialed Assessment, or unauthenticated assessment
This assessment is also incapable of detecting the vulnerabilities that are potentially covered by firewalls. It is prone to false-positive outputs and is not reliably effective as compared to credential-based assessment.
Credentialed Assessment
Distributed Assessment
Wireless Network Assessment
Non-credentialed Assessment, or unauthenticated assessment
After performing footprinting and network scanning and obtaining crucial information, if the security professional performs manual research for exploring the vulnerabilities or weaknesses, they manually rank the vulnerabilities and score them by referring to vulnerability scoring standards like CVSS (Common Vulnerability Scoring System) and vulnerability databases like CVE (Common Vulnerabilities and Exposures) and CWE (Common Weakness Enumeration). Such assessments are considered to be ___
Credentialed Assessment
Distributed Assessment
Manual Assessment
Automated Assessment
An assessment where a security professional uses vulnerability assessment tools such as Nessus, Qualys, or GFI LanGuard to perform a vulnerability assessment of the target is called an automated assessment. Unlike manual assessments, the security professional does not perform footprinting and network scanning.
Credentialed Assessment
Distributed Assessment
Manual Assessment
Automated Assessment
: This phase is very crucial in ___ management. In this step, the security analyst performs a ____ on the network to identify the known ___ in the organization’s infrastructure.
Vulnerability Scan
Verification
Remediation
Risk Assessment
Monitor
In this phase, all serious uncertainties that are associated with the system are assessed and prioritized, and remediation is planned to permanently eliminate system flaws. The risk assessment summarizes the vulnerability and risk level identified for each of the selected assets. It determines whether the risk level for a particular asset is high, moderate, or low.
Vulnerability Scan
Verification
Remediation
Risk Assessment
Monitor
The process of applying fixes to vulnerable systems in order to reduce the impact and severity of vulnerabilities. This phase is initiated after the successful implementation of the baseline and assessment steps.
Vulnerability Scan
Verification
Remediation
Risk Assessment
Monitor
In this phase, the security team performs a re-scan of systems to assess if the required remediation is complete and whether the individual fixes have been applied to the impacted assets.
Vulnerability Scan
Verification
Remediation
Risk Assessment
Monitor
Organizations need to perform regular ___ to maintain system security. They use tools such as IDS/IPS and firewalls. Continuous ___ identifies potential threats and any new vulnerabilities that have evolved.
Vulnerability Scan
Verification
Remediation
Risk Assessment
Monitor
