WorksheetsAP Cybersecurity: Cumulative Review 1.1 - 3.2
Total questions: 62
Worksheet time: 31mins
Which description best matches a low-skill adversary who uses tools created by others and is often motivated by money or recognition?
An attacker who buys exploit kits online and deploys them without understanding how they work
A government-employed cyber operative with advanced tools
An employee abusing legitimate access
An attacker motivated by political or social causes
Which scenario best describes a hacktivist attack?
Defacing a company’s website to raise awareness about an environmental issue
Stealing customer data to sell on underground markets
Launching ransomware purely for financial gain
Testing systems under a government contract
Why are insider adversaries especially dangerous to organizations?
They already have legitimate access and credentials
They only attack physical systems
They rely entirely on automated tools
They cannot be recruited by outsiders
Which attack goal best aligns with cyberterrorism?
Disrupting critical infrastructure like power grids or water treatment facilities
Stealing intellectual property to resell
Gaining social media followers
Testing network defenses for weaknesses
What activity is most commonly associated with transnational criminal organizations?
Deploying ransomware and selling stolen corporate data
Website defacement for awareness
Penetration testing
Espionage for political leverage
Which characteristic best distinguishes state adversaries from other attackers?
They are government-employed and have access to advanced cyber tools
They focus only on small businesses
They lack long-term objectives
They avoid using malware
Why must defenders continually adapt their security strategies?
Adversaries constantly evolve their tactics, techniques, and procedures
Cyber threats remain static
Technology no longer changes
Security controls never become outdated
When does a threat become an actual attack?
When a vulnerability is exploited to cause harm or disruption
When a vulnerability exists
When a threat is identified
When a system is powered on
Which example best illustrates social engineering?
A fake email convincing a user to reset their password
A firewall blocking incoming traffic
Encrypting stored files
Applying software patches
Which tactic involves pretending to be someone with power over the target?
Authority
Scarcity
Familiarity
Consensus
What is eavesdropping in a cyber context?
Secretly capturing and copying digital communications
Deleting stored files
Altering login credentials
Blocking network traffic
What makes an on-path attack especially dangerous?
Both parties believe they are communicating directly with each other
The attack only affects availability
The attacker cannot modify data
The attack only targets wireless networks
Which weakness enables injection attacks?
Failure to validate user input
Strong authentication
Encrypted databases
Network segmentation
What distinguishes a DDoS attack from a DoS attack?
The attack comes from many distributed devices
The attack only targets websites
The attack uses malware exclusively
The attack is always internal
How does credential harvesting work?
Tricking users into entering real credentials on a fake login page
Guessing passwords through brute force
Stealing encrypted password files
Installing keyloggers on servers
What is the primary goal of reconnaissance?
Gathering information about the target using publicly available sources
Destroying data
Installing malware
Disabling defenses
Which activity most often provides initial access?
Social engineering or compromised credentials
Log file deletion
Data exfiltration
Privilege escalation
Why do adversaries establish persistence?
To maintain long-term access without repeating the initial compromise
To immediately destroy systems
To alert defenders
To encrypt backups
What is the purpose of lateral movement?
Accessing systems or accounts with higher privileges
Removing evidence
Blocking network traffic
Collecting OSINT
During which phase do attackers steal or destroy data?
Taking action
Reconnaissance
Initial access
Persistence
Why do attackers attempt to erase logs near the end of an attack?
To evade detection and investigation
To gain initial access
To scan the network
To deploy ransomware
What two factors determine risk during risk analysis?
Likelihood of exploitation and severity of damage
Cost and convenience
Time and effort
Public awareness and legality
Which type of damage affects customer trust?
Reputational damage
Operational damage
Technical damage
Environmental damage
What increases the likelihood that a vulnerability will be exploited?
High target value and low difficulty
Strong encryption
Limited adversary motivation
High detection rates
Why must target value be considered from the attacker’s perspective?
Different adversaries value different outcomes
All attackers seek money
Defenders define value objectively
Value never changes
Why are easy-to-exploit vulnerabilities especially dangerous?
They are more likely to be used by attackers
They require advanced tools
They only affect insiders
They are easier to detect
Why do highly capable adversaries pose greater risk?
They can exploit complex or unknown vulnerabilities
They avoid advanced attacks
They rely on chance
They lack resources
What is qualitative risk analysis?
Describing risk using terms like low, medium, or high
Assigning dollar values to risk
Calculating probabilities mathematically
Measuring system uptime
What defines quantitative risk analysis?
Assigning numerical or monetary values to risk
Using descriptive language
Ignoring impact
Focusing only on likelihood
Which option eliminates the activity causing risk entirely?
Risk avoidance
Risk transfer
Risk mitigation
Risk acceptance
What is an example of risk transference?
Purchasing cyber insurance
Installing a firewall
Accepting downtime
Disabling a system
What does risk mitigation focus on?
Reducing likelihood or impact through controls
Stopping operations entirely
Shifting responsibility
Ignoring threats
What is residual risk?
The remaining risk an organization accepts
The initial risk level
Unidentified threats
Transferred risk
Why is redundancy important to resiliency?
It allows faster recovery after an incident
It eliminates all attacks
It reduces employee training
It prevents insider threats
Which backup site can resume operations almost immediately?
Hot site
Warm site
Cold site
Remote site
How do system backups improve resiliency?
They allow restoration to a pre-attack state
They prevent malware
They block attackers
They encrypt traffic
Why must organizations balance redundancy with cost?
Redundancy increases expenses
Backups eliminate all risks
Employees resist redundancy
Redundancy replaces security
Which principle ensures only authorized access to data?
Confidentiality
Integrity
Availability
Accounting
Which principle protects data from unauthorized modification?
Integrity
Confidentiality
Availability
Authorization
What does availability focus on?
Ensuring systems and data are accessible when needed
Preventing impersonation
Tracking user actions
Encrypting communications
What supports non-repudiation?
Logging actions with responsible entities
Password complexity
Firewalls
Redundancy
What is authentication used for?
Verifying identity
Granting permissions
Recording activity
Encrypting data
How does authorization differ from authentication?
Authorization determines access level after identity is verified
Authorization confirms identity
Authentication logs actions
Authentication assigns permissions
What is the purpose of accounting?
Recording and monitoring user actions
Blocking attacks
Encrypting files
Granting access
What best defines defense-in-depth?
Using multiple layered security controls
Relying on a single strong control
Outsourcing all security
Focusing only on prevention
Why is layered defense effective?
One control may stop an attacker if another fails
It eliminates insider threats
It guarantees security
It reduces system cost
Why must organizations consider cost-benefit when choosing controls?
Controls should not cost more than the expected loss
Cheaper controls are always better
All controls must be implemented
Cost does not matter
Which controls are often prioritized first?
High-probability, high-impact risks
Low-impact risks
Unlikely threats
Convenient solutions
Which attack involves following someone into a restricted area without their knowledge?
Tailgating
Piggybacking
Shoulder surfing
Dumpster diving
Which attack relies on social engineering to gain physical access?
Piggybacking
Tailgating
Card cloning
Jamming
What does shoulder surfing involve?
Observing someone enter sensitive information
Copying access cards
Following employees
Searching trash
Why is physical access so dangerous?
It can bypass many technical controls
It only affects availability
It cannot compromise data
It requires advanced skills
What is the goal of an evil-twin attack?
Capturing traffic by impersonating a legitimate wireless network
Blocking wireless signals
Destroying access points
Encrypting traffic
What does a jamming attack target?
Wireless availability
Authentication
Data integrity
User permissions
What enables an ARP poisoning attack?
Sending fake ARP messages to misdirect traffic
Strong encryption
MAC filtering
Firewalls
Why is MAC flooding dangerous?
It forces a switch to broadcast traffic
It disables encryption
It erases logs
It installs malware
What is the purpose of war driving?
Locating and analyzing wireless networks
Breaking encryption
Installing access points
Blocking traffic
Why do organizations disable unnecessary router services like Telnet?
To reduce attack surface
To increase speed
To simplify configuration
To allow remote access
What does port security on switches help prevent?
Unauthorized devices connecting to the network
Phishing attacks
Power outages
DNS poisoning
Why do VPN policies often prohibit split tunneling?
To prevent insecure traffic from bypassing protections
To increase bandwidth
To simplify authentication
To allow personal device access
Why is AES encryption required on secure wireless networks?
It ensures intercepted traffic cannot be read
It increases signal strength
It hides SSIDs
It blocks all attacks
Why should organizations authenticate devices before network access?
To prevent adversaries from joining internal networks
To improve speed
To reduce costs
To enable beacon frames
