WorksheetsConfiguration Vulnerabilities
Total questions: 30
Worksheet time: 15mins
What is the most common cause of configuration vulnerabilities?
Hardware failures
Default settings left unchanged
Network congestion
Power outages
In the MongoDB database exposure case study, what was the primary configuration error?
Outdated software version
Weak encryption protocols
Database bound to all network interfaces with no authentication
Missing firewall rules
Which of the following is NOT a configuration vulnerability?
Overly permissive firewall rules
Unnecessary services enabled
Software bug in the operating system
Disabled security features
What should be the first action when discovering a service using default administrator credentials?
Document it for the next security review
Immediately change the credentials
Disable the service permanently
Monitor the service for suspicious activity
Which tool provides industry-standard secure configuration guidelines?
Google Security Scanner
Norton Antivirus
CIS Benchmarks
Windows Defender
According to the Verizon Data Breach Investigations Report, what percentage of breaches involve weak authentication?
Over 40%
Over 60%
Over 80%
Over 95%
What was the password protecting the SolarWinds update server?
admin123
password
solarwinds123
update2020
What is MFA (Multi-Factor Authentication)?
Using multiple passwords
Requiring two or more authentication factors
Multiple user accounts
Automatic password changes
Which of the following indicates poor session management?
Sessions that timeout after 30 minutes
Encrypted session tokens
Sessions that never expire
Logout functionality
What is the recommended minimum password length according to current best practices?
6 characters
8 characters
10 characters
12 characters
What is a CVE?
Computer Virus Encyclopedia
Common Vulnerabilities and Exposures
Critical Vendor Error
Cyber Verification Examination
Which ransomware exploited the EternalBlue vulnerability in 2017?
CryptoLocker
Petya
WannaCry
Ryuk
How long before the WannaCry attack had Microsoft released a patch for the vulnerability?
Two weeks
One month
Two months
Six months
What is the most critical window for system vulnerability?
Before a vulnerability is discovered
Between vulnerability discovery and disclosure
Between patch release and patch application
After a system is compromised
What does Log4Shell (CVE-2021-44228) affect?
Windows operating systems
Apache Log4j logging library
Cisco routers
Oracle databases
Which protocol should replace HTTP for secure web communications?
FTP
HTTPS
Telnet
SMTP
What is the secure alternative to Telnet?
FTP
HTTP
SSH
SNMP
Why is using HTTP instead of HTTPS a security risk?
It is slower
Data is transmitted in plaintext and can be intercepted
It uses more bandwidth
It requires special software
Which SNMP version includes encryption and authentication?
SNMPv1
SNMPv2
SNMPv3
All versions are equally secure
What tool can be used to analyse network traffic and detect unencrypted protocols?
Microsoft Word
Wireshark
Adobe Reader
Chrome Browser
What percentage of breaches involve social engineering according to Verizon's DBIR?
Over 15%
Over 25%
Over 35%
Over 45%
How did attackers compromise Twitter accounts in the 2020 Bitcoin hack?
SQL injection
DDoS attack
Phone-based social engineering (vishing) targeting employees
Brute force password attack
What is pretexting?
Sending mass phishing emails
Creating a false scenario to extract information
Following someone through a secure door
Installing malware on USB drives
What is tailgating in a security context?
Following vehicles too closely
Monitoring someone's email
Following an authorised person through a secure door without proper authentication
Copying someone's password
Which is a warning sign of a phishing email?
Professional formatting
Urgent language demanding immediate action
Emails from known contacts
Correct spelling and grammar
What is the primary risk of unsecured server rooms?
Increased electricity costs
Direct physical access to servers and potential data theft
Poor ventilation
Difficulty finding equipment
What should be done with old hard drives before disposal?
Delete all files
Format the drive
Physically destroy or use certified data destruction
Remove the power cable
What physical security measure prevents unauthorised network access in public areas?
Painting walls
Port security on network switches to disable unused ports
Installing carpet
Adding more lighting
Why are unattended workstations without screen locks a security risk?
They waste electricity
Anyone can access logged-in systems and data
They slow down the network
They violate building codes
What is the purpose of visitor badges and sign-in procedures?
To make visitors feel welcome
To track who is in the building and restrict unauthorised access
To collect marketing data
To comply with fire regulations only
