NEW
Font size
WorksheetsCySA+ Ch 2
Total questions: 20
Worksheet time: 10mins
Which of the following is NOT an accepted term to describe those who are responsible for cyberattacks?
Malicious actor
Hacker
Attacker
Threat actor
Which of the following is NOT a target of financial cybercrime?
Nonprofit organizations
Governments
Individual users
Enterprises
Which of the following is the least skilled category of attacker?
Competitors
Organized crime
Script kiddies
Brokers
What are the reasons that organized crime perform cyberattacks?
It is less risky and more rewarding than traditional crimes.
The avenues for the types of crimes committed previously are no longer available.
Performing cyberattacks is a means of "showing off" their capabilities.
The punishment for cyberattacks is less than that for traditional crimes.
Which of the following is NOT true about unintentional insiders?
Carelessness, too much multitasking, and low situational awareness are all reasons for the actions of unintentional insiders.
Careless employees or contractors are rarely the cause of most insider incidents.
Many unintentional insiders have a general disinterest in practicing strong cyber defense.
Unintentional insiders can unwittingly cause harm or create a vulnerability for an external threat actor to then exploit.
Elodie decided to purchase with her own money a new wireless router that she then installed in the company breakroom. What category does her actions fall under?
Shadow IT
Express expenditure
Corporate circumvention
Exploitative actions
Which of the following is NOT a characteristic of hacktivists?
Hacktivists are strongly motivated by philosophical or political beliefs or ideology for the sake of their principles.
Most hacktivists are proud to call themselves "hacktivists."
Attacks by hacktivists are often used to "make a statement."
Today many hacktivists work through disinformation campaigns by spreading fake news and supporting conspiracy theories.
Who are the financiers that support nation-state actors?
Cyber zealots
Hacktivists
Organized crime
Governments
What is the class of attacks that are multiyear intrusion campaigns targeting highly sensitive economic, proprietary, or national security information?
RCE
APT
RCR
ABA
Why are supply-chain attacks difficult to defend against?
Because supply chains are global in scope, each link in the chain is thousands of miles away overseas and is not under any direct and coordinated supervision and monitoring.
Attackers can hide their exploits through firmware patches.
Supply-chain attacks only impact hardware that is difficult to trace.
Supply chains themselves are hidden networks.
Which software supply-chain target infection is considered particularly alarming today?
Corporate database software
Open-source software
OS software
Network software
Which threat actors sell their knowledge of a weakness to other attackers?
APTs
Cyber middlemen
Brokers
Cyberterrorists
Which of the following is a high-level description of a threat actor’s behavior?
PTTs
Procedures
Tactics
Techniques
What tool is used to classify threats comparing the knowledge of the threat actor to security personnel?
Rumsfeld Graph
Johari Window
Fire Chart
Motivation Display
Which attack takes advantage of an authentication token that a website sends to a user’s web browser?
FRFS
SSRF
CSRF
CSCS
Which attack takes advantage of user input and display on a web server?
CSCR
DOM XRS
CSS
XSS
Which type of attack occurs when a threat actor accesses a target device to make changes to it?
XRC
RCE
CED
CRC
Which of the following is NOT a means of how obfuscated links are crafted?
Obfuscate with punycode.
Use the HTML "x href" attribute.
Manipulate the @ symbol.
Use alternative hostname formats.
Which vulnerability manipulates code to point away from an approved file on the web server to the attacker’s own file that has been uploaded to that server?
RFI
LFI
XFI
FFI
Which overflow attack manipulates the area of memory in which local variables are stored that a program uses?
Data overflow
Integer overflow
Heap overflow
Stack overflow
