Font size
WorksheetsAP Cybersecurity 2.1 Physical Vulnerabilities and Attacks
Total questions: 28
Worksheet time: 14mins
What is a physical cybersecurity attack?
Hacking someone's social media account
Attempting to guess a password
Gaining unauthorized access through physical means
Creating strong encryption
What is tailgating in cybersecurity?
Following someone on social media
Using someone else’s login credentials
Entering a restricted area by following someone closely
Spying through a camera
What is the danger of leaving a USB device in a public space?
It might get stolen and reused
Someone could load malicious software onto it
It could cause data overload
It might overheat
Which of the following is NOT a physical cybersecurity attack?
A. Dumpster diving
B. Shoulder surfing
C. Phishing email
D. Device theft
What does dumpster diving involve?
Throwing away old electronics
Retrieving sensitive information from discarded materials
Searching through data archives
Exploring old digital files
How can shoulder surfing be prevented?
Disabling Bluetooth
Installing antivirus software
Using a privacy screen
Changing your password frequently
Why is physical security important in cybersecurity?
It protects you from online scams
It ensures faster Wi-Fi access
What should you do if someone asks to use your laptop and you don’t know them?
Let them use it while you watch
Ask for their ID
Politely decline and report it if necessary
Give access only to the browser
What might indicate hardware tampering?
A laptop suddenly runs faster
Cables are more organized
Devices have unexpected parts or loose connections
A screen is brighter than usual
What is an effective defense against device theft?
Turning off Wi-Fi
Carrying your device at all times
Encrypting your emails
Avoiding public places
Which object could improve physical cybersecurity?
Noise-canceling headphones
Laptop lock
USB splitter
Wireless mouse
What does eavesdropping involve?
Tracking GPS location
Listening or watching someone's private information
Reading documents left on desks
Accessing network traffic
What threat do power outages pose to cybersecurity?
Increased system performance
Reduced data storage
Data loss and corruption
Improved system availability
Resilience in security systems is achieved by:
Using a single layer of defense
Building a layered defense
Maximizing system complexity
Reducing the frequency of backups
What is piggybacking, in the context of cybersecurity?
Creating fake invoices to trick employees or vendors
Spreading false narratives about cyber threats
Gaining entry to a restricted area without proper authentication by following an authorized person
Manipulating or creating fake emails that appear to be from a legitimate brand
What is a common tactic used in Piggybacking attacks?
Sending emails with exaggerated threats
Creating fake social media profiles
Demanding immediate action or access by making it appear to be an emergency
Using technical jargon to confuse the target
How can organizations mitigate the risk of tailgating attacks?
A. Establishing clear verification processes for access to restricted areas
B. Allowing employees to hold doors open for everyone
C. Disabling security cameras in entry points
D. Encouraging visitors to bypass security checks
What is the best defense against Piggybacking attacks?
Providing personal information to unknown individuals
Ignoring verification processes to speed up operations
Volunteer information freely to appear cooperative
Checking credentials, calling for proof, and verifying the identity of individuals
Which of the following best describes phishing?
Fishing for compliments on social media
Attempting to gain sensitive information through electronic communication by posing as a trustworthy source
Using real fishing as a metaphor for online security
Sending out random emails without a specific target
Individuals can defend against social engineering attacks by:
Being cautious with sharing personal information
Clicking on all email links
Ignoring security updates
Using the same password everywhere
What is the main reason social engineering attacks succeed?
Lack of security software
Lack of proper computer hardware
Exploitation of human biases and emotions
Lack of encryption on communication channels
What is the purpose of conducting simulated phishing campaigns?
To serve as educational tools for employees
To trick employees into providing sensitive information
To discourage employees from reporting suspicious emails
To avoid addressing social engineering tactics
Looking for a person's information in the trash that can be used to carry out an attack.
Spoofing
Logic Bomb
Dumpster Diving
Black Hat
Launched from several infected host machines looding systems, servers, and/or networks with traffic to overload resources and bandwidth
Trojan
Worms
Denial of Service(DOS)
Zero Day Exploit
Attacker intercepts a two-party transaction, inserting themselves in the middle to steal and manipulate information
RootKits
Zero Day Exploit
DOS
Man In the Middle(MitM)
Which potential threat relates to the mitigation strategy of hardening facilities or having alternate sites?
Natural disaster
Cyber attack
Supply chain disruption
Employee errors
Select the three parts of the CIA triad?
Integrity
Authorization
Intrusion
Confidentiality
Availability
What is card cloning?
Deleting an access card’s data to prevent use
Creating a duplicate of an authorized user’s access card to gain unauthorized entry
Encrypting an access card so only authorized readers can read it
Logging every use of an access card for audit purposes
