WorksheetsMalware Threats
Total questions: 32
Worksheet time: 16mins
What does malware stand for?
Managed software
Malicious software
Multiple software
Maintenance software
Which type of malware self-replicates and spreads automatically across networks without user interaction?
Virus
Trojan
Worm
Spyware
In the NotPetya ransomware attack (2017), what was the estimated global damage?
£1 billion
£3 billion
£8 billion
£15 billion
What distinguishes a Trojan horse from a virus?
Trojans spread faster
Trojans disguise themselves as legitimate software
Trojans only affect mobile devices
Trojans cannot be detected
Which indicator suggests a ransomware infection?
Slow internet connection
Files encrypted with changed extensions and ransom demand
Excessive pop-up advertisements
Automatic software updates
What does DDoS stand for?
Direct Denial of Service
Distributed Denial of Service
Digital Denial of Software
Dedicated Denial of Systems
In the 2016 Dyn DDoS attack, which botnet was primarily responsible?
Conficker
Zeus
Mirai
Emotet
What is a Man-in-the-Middle (MitM) attack?
An attack that crashes servers
An attack that intercepts communications between two parties
An attack that steals passwords only
An attack that deletes files
Which protocol vulnerability does DNS spoofing exploit?
HTTP
FTP
DNS cache
SMTP
What type of devices were primarily compromised in the Mirai botnet?
Desktop computers
Mobile phones
IoT devices (cameras, routers, DVRs)
Server databases
What does SQL injection allow an attacker to do?
Slow down the website
Manipulate database queries and extract data
Change the website colours
Install browser extensions
Which UK company suffered a SQL injection breach in 2015 affecting 156,959 customers?
BT
Vodafone
TalkTalk
Virgin Media
What does XSS stand for in web security?
Extra Security System
Cross-Site Scripting
Extended Server Security
External System Scan
How much was TalkTalk fined by the ICO for their data breach?
£100,000
£250,000
£400,000
£1,000,000
What is the primary defence against SQL injection attacks?
Using HTTPS
Installing antivirus
Input validation and parameterised queries
Changing passwords regularly
According to IBM's Cost of a Data Breach Report 2024, what is the average cost of a data breach?
£1.5 million
£2.5 million
£3.5 million
£5.5 million
How many people were affected by the Equifax data breach in 2017?
50 million
100 million
147 million
200 million
What vulnerability did attackers exploit in the Equifax breach?
Weak passwords
Unpatched Apache Struts vulnerability (CVE-2017-5638)
Missing firewall
Social engineering
What is data exfiltration?
Backing up data
Encrypting data
Unauthorised transfer of data from systems
Deleting old data
How long before the Equifax breach was the patch for the vulnerability available?
Two weeks
One month
Two months
Six months
Approximately what percentage of data breaches involve insider threats?
10%
20%
30%
40%
Which company experienced insider sabotage in 2018 from a disgruntled employee who modified manufacturing systems?
Apple
Tesla
Ford
What is a negligent insider?
Someone who intentionally steals data
Someone who causes breaches through carelessness or policy violations
A contractor with expired credentials
An external hacker
Which of the following is NOT a warning sign of a malicious insider?
Working unusual hours
Accessing systems outside their job role
Attending security training sessions
Downloading large amounts of data
What motivated the Tesla employee to conduct insider sabotage?
Financial gain from competitors
Upset about not receiving a promotion
Political ideology
Accidental mistake
What does APT stand for?
Automated Password Tool
Advanced Persistent Threat
Application Protection Technology
Active Protocol Testing
Which threat actor was responsible for the SolarWinds supply chain attack?
APT28
Lazarus Group
APT29 (Cozy Bear)
Anonymous
How long did the SolarWinds breach go undetected?
Two weeks
One month
Three months
Nine months
What distinguishes APTs from other cyber threats?
They are always automated
They are sophisticated, persistent, and well-resourced attacks targeting high-value assets
They only affect small businesses
They are easy to detect
What is the typical first phase of an APT attack lifecycle?
Data exfiltration
Lateral movement
Reconnaissance
Installing ransomware
According to the scoring guide, what does a score of 27-30 correct answers indicate?
Satisfactory - Basic knowledge present, more study needed
Outstanding - Excellent understanding of network threats
Good - Solid understanding, review challenging areas
Review required - Revisit course materials and retake assessment
According to the scoring guide, what should a student do if they score below 15 correct answers?
A) Review challenging areas
B) Revisit course materials and retake assessment
C) Strong grasp of key concepts with minor gaps
D) Excellent understanding of network threats
