wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

CySA+ Ch 2

Total questions: 20

Worksheet time: 10mins

Name
Class
Date
1.

Which of the following is NOT an accepted term to describe those who are responsible for cyberattacks?

a)

Malicious actor

b)

Hacker

c)

Attacker

d)

Threat actor

2.

Which of the following is NOT a target of financial cybercrime?

a)

Nonprofit organizations

b)

Governments

c)

Individual users

d)

Enterprises

3.

Which of the following is the least skilled category of attacker?

a)

Competitors

b)

Organized crime

c)

Script kiddies

d)

Brokers

4.

What are the reasons that organized crime perform cyberattacks?

a)

It is less risky and more rewarding than traditional crimes.

b)

The avenues for the types of crimes committed previously are no longer available.

c)

Performing cyberattacks is a means of "showing off" their capabilities.

d)

The punishment for cyberattacks is less than that for traditional crimes.

5.

Which of the following is NOT true about unintentional insiders?

a)

Carelessness, too much multitasking, and low situational awareness are all reasons for the actions of unintentional insiders.

b)

Careless employees or contractors are rarely the cause of most insider incidents.

c)

Many unintentional insiders have a general disinterest in practicing strong cyber defense.

d)

Unintentional insiders can unwittingly cause harm or create a vulnerability for an external threat actor to then exploit.

6.

Elodie decided to purchase with her own money a new wireless router that she then installed in the company breakroom. What category does her actions fall under?

a)

Shadow IT

b)

Express expenditure

c)

Corporate circumvention

d)

Exploitative actions

7.

Which of the following is NOT a characteristic of hacktivists?

a)

Hacktivists are strongly motivated by philosophical or political beliefs or ideology for the sake of their principles.

b)

Most hacktivists are proud to call themselves "hacktivists."

c)

Attacks by hacktivists are often used to "make a statement."

d)

Today many hacktivists work through disinformation campaigns by spreading fake news and supporting conspiracy theories.

8.

Who are the financiers that support nation-state actors?

a)

Cyber zealots

b)

Hacktivists

c)

Organized crime

d)

Governments

9.

What is the class of attacks that are multiyear intrusion campaigns targeting highly sensitive economic, proprietary, or national security information?

a)

RCE

b)

APT

c)

RCR

d)

ABA

10.

Why are supply-chain attacks difficult to defend against?

a)

Because supply chains are global in scope, each link in the chain is thousands of miles away overseas and is not under any direct and coordinated supervision and monitoring.

b)

Attackers can hide their exploits through firmware patches.

c)

Supply-chain attacks only impact hardware that is difficult to trace.

d)

Supply chains themselves are hidden networks.

11.

Which software supply-chain target infection is considered particularly alarming today?

a)

Corporate database software

b)

Open-source software

c)

OS software

d)

Network software

12.

Which threat actors sell their knowledge of a weakness to other attackers?

a)

APTs

b)

Cyber middlemen

c)

Brokers

d)

Cyberterrorists

13.

Which of the following is a high-level description of a threat actor’s behavior?

a)

PTTs

b)

Procedures

c)

Tactics

d)

Techniques

14.

What tool is used to classify threats comparing the knowledge of the threat actor to security personnel?

a)

Rumsfeld Graph

b)

Johari Window

c)

Fire Chart

d)

Motivation Display

15.

Which attack takes advantage of an authentication token that a website sends to a user’s web browser?

a)

FRFS

b)

SSRF

c)

CSRF

d)

CSCS

16.

Which attack takes advantage of user input and display on a web server?

a)

CSCR

b)

DOM XRS

c)

CSS

d)

XSS

17.

Which type of attack occurs when a threat actor accesses a target device to make changes to it?

a)

XRC

b)

RCE

c)

CED

d)

CRC

18.

Which of the following is NOT a means of how obfuscated links are crafted?

a)

Obfuscate with punycode.

b)

Use the HTML "x href" attribute.

c)

Manipulate the @ symbol.

d)

Use alternative hostname formats.

19.

Which vulnerability manipulates code to point away from an approved file on the web server to the attacker’s own file that has been uploaded to that server?

a)

RFI

b)

LFI

c)

XFI

d)

FFI

20.

Which overflow attack manipulates the area of memory in which local variables are stored that a program uses?

a)

Data overflow

b)

Integer overflow

c)

Heap overflow

d)

Stack overflow