WorksheetsT2 - CyberSecurity Threat Landscape
Total questions: 60
Worksheet time: 2hrs 30mins
A company discovers malicious code designed to silently capture keyboard input to steal customer login credentials.
Rootkit
Keylogger
Worm
Logic Bomb
Which threat best describes malware that encrypts user files and demands cryptocurrency payment to restore access?
Ransomware
Trojan Horse
Spyware
Bloatware
A self-replicating program is spreading across the network without user interaction.
Worm
Trojan Horse
Spyware
Logic Bomb
An employee downloads a free “video-player” app that secretly installs a backdoor.
Trojan Horse
Worm
Spyware
Ransomware
During an incident investigation, analysts find malware that replaced system drivers to hide its presence at the kernel level.
Rootkit
Spyware
Logic Bomb
Bloatware
A disgruntled developer embeds code that erases databases if their user account is disabled.
RAT
Logic Bomb
Keylogger
Backdoor
Which of the following is usually unwanted but not directly malicious, often pre-installed trial software that slows devices?
Spyware
Bloatware
Trojan Horse
Rootkit
A cyber-criminal floods a web server with traffic from thousands of compromised IoT devices, causing it to crash.
DoS
DDoS
What distinguishes an Advanced Persistent Threat (APT) from other attacks?
Uses ransomware for quick payout
Stealthy, long-term infiltration often by nation-states
Always relies on insider negligence
Only targets IoT devices
A partner company’s software update is compromised before release and installs malware at customers’ sites.
Insider Threat
Supply-Chain Attack
Trojan Horse
APT
An attacker tricks an employee into revealing VPN credentials via a fake HR-portal email.
Phishing
Keylogging
Logic Bomb
DoS
A CFO receives a spoofed email tailored with their name and internal details, requesting an urgent wire transfer.
Whaling
Spear Phishing
Vishing
Pharming
Which threat actor is MOST commonly linked to espionage against critical infrastructure and usually backed by government resources?
Hacktivist
Nation-State Actor
Organized Crime
Competitor
A group launches cyber-attacks to protest environmental policies.
Hacktivist
Organized Crime
Competitor
Script Kiddie
An entry-level attacker downloads free exploit scripts without understanding the code.
Insider (Negligent)
Script Kiddie
Hacktivist
APT Operative
A data-center technician accidentally leaves default admin passwords on exposed servers, leading to a breach.
Insider (Unintentional)
Competitor
Hacktivist
Terrorist Group
A former employee, angry about being fired, steals proprietary code before departure.
Organized Crime
Insider (Intentional)
Competitor
APT
Which threat actor's main objective is monetary profit through ransomware, fraud, or credential theft?
Organized Crime
Hacktivist
Nation-State
Terrorist Group
A rival manufacturer conducts cyber-espionage to steal product-design blueprints.
Hacktivist
Competitor
Insider (Negligent)
Nation-State
Which actor type is typically motivated by mass disruption, fear, or destruction, sometimes combining cyber and physical tactics?
Organized Crime
Hacktivist
Terrorist Group
Script Kiddie
A covert group compromises a defense contractor’s email for long-term intelligence gathering.
APT sponsored by Nation-State
Organized Crime
Hacktivist
Competitor
Which motivator BEST explains ransomware gangs demanding cryptocurrency from hospitals?
Disruption / Chaos
Financial Gain
Political / Ideological
Notoriety / Fame
A rival nation hacks research labs to steal vaccine formulas.
Espionage / Intelligence Gathering
Disruption / Chaos
Revenge / Grudge
Notoriety / Fame
A hacktivist group defaces a government website to protest a new law.
Financial Gain
Political / Ideological Goals
Revenge
Notoriety / Fame
A disgruntled ex-employee deploys a logic-bomb to delete files on their last day.
Financial Gain
Revenge / Personal Grudge
Espionage
Notoriety / Fame
Which motivator is commonly associated with chaos-driven threat actors whose goal is to destabilize or disrupt services without financial gain?
Notoriety / Fame
Disruption / Chaos
Espionage
Revenge
A contractor introduces malware into a corporate network by plugging in an infected external USB drive.
Cloud Services
Removable Media
Wireless Network
Physical Access
An attacker exploits an insecure API of a cloud-storage provider to access private backups.
Cloud Services
Websites
Social Media
A user is lured to a fake banking site by clicking a link on social media and enters credentials.
Websites
Social Media
Physical Access
An adversary breaks into the server room and installs a rogue device on the internal switch.
Physical Access
Wireless
Supply-Chain
Attackers exploit an outdated plugin on a corporate blog to deploy malicious JavaScript to site visitors.
Websites
Cloud Services
Wireless
Hackers compromise a third-party component used in a company’s online-ordering platform to inject malware during checkout.
Supply-Chain / Third-Party Vendor
Wireless
Cloud Services
Removable Media
A café’s unencrypted public Wi-Fi allows an attacker to intercept session cookies from customers logging into webmail.
Wireless / Wi-Fi
Social Media
Cloud Services
Websites
Which open-framework provides a knowledge base of adversary tactics, techniques, and procedures (TTPs) mapped to attack phases?
MITRE ATT&CK
OWASP
NIST
ISO
A security engineer checks the CVE database to see if a known exploit exists for a newly disclosed software bug.
Patch-management schedules
Unique IDs for public vulnerabilities
Cloud risk-score rankings
Encrypted threat-feed channels
The National Vulnerability Database (NVD) builds upon CVE by adding which key element?
Threat-actor profiles
CVSS metrics and severity data
DNS blacklists
Encrypted file-hash archives
A web-app developer checks the OWASP Top 10 list during code reviews.
Web-application vulnerabilities
Endpoint hardening
ICS / SCADA exploits
Wireless encryption
Which resource enables machine-to-machine sharing of structured threat indicators between trusted partners?
STIX / TAXII
OSINT
IC3
MITRE
Security analysts from multiple hospitals collaborate to share indicators of ransomware campaigns targeting healthcare.
ISAC
OSINT
MITRE ATT&CK
NVD
A company relies on public tweets, blogs, and research forums to monitor new phishing domains.
ISAC
OSINT
Vendor Feed
CVE
Victims of cyber-fraud submit complaints to a federal agency that aggregates incidents for investigation.
FBI IC3
CISA
ISAC
OWASP
A persistent threat actor installs a covert program allowing remote control of a victim’s workstation.
RAT
IDS
SIEM
SOC
Which acronym refers to the triad of fundamental security objectives: protecting data from unauthorized disclosure, unauthorized change, and service disruption?
CIA
ISP
IDS
RAT
An organization deploys an IDS to monitor inbound packets and generate alerts on suspicious patterns but does not block them.
Integrated Defense Suite
Intrusion Detection System
Internal Data Scanner
Internet Domain Shield
Security teams upgrade to an IPS to automatically drop malicious traffic identified in real-time.
Cloud-logging
Automated prevention / blocking
Threat-hunting dashboards
Baseline compliance scans
The enterprise SOC operates 24/7 to triage SIEM alerts and coordinate incident response.
Security Operations Center
Secure Online Console
System Orchestration Control
Security Output Channel
A web server is compromised via a malicious SQL statement embedded in a login field.
XSS
SQLi
RAT
MITRE
A malicious script is injected into a legitimate website’s comment section and executes in visitors’ browsers.
RAT
SQLi
XSS
APT
A university’s network is breached by attackers who publicly leak stolen research to protest animal-testing labs.
Organized Crime
Hacktivist
Nation-State
Insider (Negligent)
An intruder disrupts emergency-dispatch phone services just to cause panic during a local festival—no ransom demanded.
Financial Gain
Revenge / Grudge
Disruption / Chaos
Notoriety / Fame
A new hire connects an infected personal USB to transfer résumé files, which unleashes ransomware onto the HR subnet.
Cloud Service
Removable Media
Physical Access
Wireless / Wi-Fi
A rival start-up pays a contractor to steal design schematics of a new electric-car battery.
Actor: Competitor Motivator: Espionage / Intelligence Gathering
Actor: Hacktivist Motivator: Political / Ideological
Actor: Organized Crime Motivator: Financial Gain
Actor: Insider (Unintentional) Motivator: Notoriety / Fame
A bank’s call-center PC was secretly infected after a customer-service rep clicked a fake email attachment; malware stayed dormant for weeks until triggered to delete logs. What type of malware was used?
Worm
Logic Bomb
Rootkit
Keylogger
Security cameras at a water-treatment plant go offline after highly sophisticated malware—undetected for months—exfiltrates plant-schematic data. What type of actor and threat was involved?
Nation-State APT, Advanced Persistent Threat
Script Kiddie, Trojan
Organized Crime, Ransomware
Hacktivist, DoS
During a high-profile sporting event, attackers spread malicious shortened links on Twitter that redirect users to a credential-harvesting site. What vector was used for the attack?
Social Media
Websites
Cloud Service
Physical Access
A fired IT admin posts VPN passwords to a public forum to “teach the company a lesson.” What type of actor and motivator is involved?
Insider (Intentional), Revenge / Personal Grudge
Hacktivist, Political / Ideological
Organized Crime, Financial Gain
Terrorist Group, Disruption / Chaos
An e-commerce site’s payment form allows attackers to inject a rogue SQL statement that steals customer credit-card data. What type of attack is this?
Type: SQLi Vector: Web Application / Website
Type: RAT Vector: Cloud Service
Type: Worm Vector: Removable Media
Type: DoS Vector: Wireless
Imagine Aria and David have set up a small office network. What is the primary function of a firewall they installed to protect their network?
To increase internet speed.
To serve as a physical barrier against network intrusion.
To monitor and control incoming and outgoing network traffic based on predetermined security rules.
To detect and remove viruses and other malware.
What is the main purpose of a firewall in network security?
To increase the speed of the network
To monitor and control incoming and outgoing network traffic based on predetermined security rules
To serve as a physical barrier against intruders
To manage the data storage on a network
What type of attack involves overwhelming network resources with unwanted traffic?
Phishing attack
Distributed Denial of Service (DDoS) attack
SQL injection
Man-in-the-middle attack
