WorksheetsCanvas CySA+ ch2
Total questions: 25
Worksheet time: 13mins
The PHP configuration on a web server is set to control the ability to open, include, or use a remote file. Which of the following best describes the security threat that is being mitigated by this action?
RFI
LFI
Remote injection flaw
Remote access control
A government IT security team discovered data has been slowly leaking from their storage servers over the last 12 months. After additional analysis, they unmask the threat actor and accurately label the type of threat in a report. Which of the following information can be expected in the report?
A software supply-chain breach made the leak possible.
A nation-state actor launched an APT attack.
The government agency needs to add a layer of security by adopting TTP protocols.
A group of intentional internal threat hacktivists installed a back door.
A company determines a relatively small but important software module used in an app exhibits an insecure design condition. What should the company do to mitigate this condition?
Rewrite the module with security controls.
Apply a software patch before releasing the app.
Ensure the app is released using an improved implementation.
Minimize or eliminate poor coding practices.
An unethical company is determined to exfiltrate data from a reputable company. The goal is to obtain information that will help them release a competing product with similar features. Which of the following represents the order and steps the unethical company is likely to take to meet their objectives?
Privilege escalation, execute code, RCE, exfiltrate data
RCE, privilege escalation, execute code, exfiltrate data
Privilege escalation, RCE, execute code, exfiltrate data
Execute code, RCE, privilege escalation, exfiltrate data
A security specialist endeavors to prevent recent broken authentication-related events at a branch office. What should the security specialist do to successfully meet this objective? Select two.
Allow brute-force attacks but only as a decoy.
Ensure users have personalized session identifiers.
Implement a strong password policy.
Implement an effective multifactor authentication system.
What benefit do security professionals derive from understanding TTPs?
It is used by security professionals to develop a comprehensive Johari window quickly.
It provides the background information needed to protect all possible attack paths.
It provides the evidence in real-time of an attack that is currently taking place.
It helps them pinpoint the location from where a malicious actor is launching an attack.
A group of threat actors want to disrupt the electric grid to induce disruption and panic among residents of a particular city. Which of the following best characterizes this statement?
It represents a tactic.
It represents a TTP.
It represents a procedure.
It represents a technique.
A threat actor discovers a vulnerability in an app that has never been reported. However, instead of exploiting the weakness, the threat actor offers to sell the information. Why would the threat actor do this?
Because the threat actor is a broker
Because the threat actor is a competitor who wants to keep a low profile
Because the threat actor is a cyberterrorist
Because the threat actor is a zero-day attacker
An insider threat actor has been engaging in unscrupulous cybersecurity activities for some time without being discovered. Which of the following best describes why it is so difficult to unmask an intentional insider threat?
Their login credentials are all valid.
They only attack occasionally.
They know how to cover their tracks.
Security is focused on outsiders.
A company sources products from a variety of vendors to create a complex security system. However, a year after releasing the product, it was recalled because one of its components allows unauthorized surveillance, and patches did not fix the problem. What type of malware is most likely affecting the security system?
Software supply-chain infection
Espionage infection
Hardware supply-chain infection
Supply-chain infection
An attacker successfully launches a buffer overflow attack. Which of the following best represents the resulting effect?
A data overflow condition that affects global variables.
Replacing the existing return address with a new one.
A text overflow condition that affects the code being executed.
Using the stack to dynamically allocate additional memory.
The number of container ships a port is capable of processing has been reduced by 70% due to serious cybersecurity incident. What type of attack was most likely launched and to what type of threat actor is this type of attack often attributed?
Hardware supply-chain infection hacktivist.
Software supply-chain infection cyberterrorists.
Competitive advantages attack, competing entity.
Supply-chain attack, nation-state actors.
An attacker determines permission on a web server are not very secure and proceeds to access unauthorized data, thus, exploiting the vulnerability. What type of attack is the threat actor performing?
Privilege escalation
Directory traversal
Server-side scripting
Remote access attack
Which of the following describes true statements regarding CSRF and SSRF? Select two.
SSRF attacks exploit how a web server receives information from another server.
CSRF involves a request to a website that is not from the authentic user.
A web application accepts input, then immediately displays it back to initiate the attack.
A SSRF attack targets a user while a CSRF attack targets a web server.
They both write data to the Document Object Model on the web server without proper sanitization.
A malicious actor manages to modify data in RAM in an ecommerce platform to induce a credit in their account instead of a charge. What type of attack is most likely to produce this effect?
Numeric overflow
Integer overflow
Stack overflow
Heap overflow
A senior hardware test technician at a company that designs computer hardware engages in shadow IT activities from time to time. Which of the following activities is the technician most likely to perform and/or why does the technician participate in such activities? Select three.
Because the test lab is on a network that is not connected to the main network.
The technician has low situational awareness.
Purposely inject security weaknesses to see if they are discovered during testing.
The technician is not interested in practicing strong cybersecurity defenses.
The company lacks security protocols and does a poor jobs of training its employees.
Which of following best describes the type of threat posed by an individual engaging in shadow IT?
Unintentional insider threat
Intentional insider threat
White hat hacker
Insider threat
A script kiddie finds a document online that includes detailed information on how to penetrate a network to determine if there are computers using older operating systems that can be compromised. What type of information is most likely to be contained in the document?
A procedure
A technique
A tactic
A strategy
A rogue government employee steals a host of numeric attributes from a third-party storage facility that uniquely identifies the persons to whom they correspond. The employee's goal is to benefit financially. If successful, who or what entity will be the most likely victim?
The entity where the victims are employed
The third-party entity where the information was stored
Individual users
The government
An attacker crafts a URL that reads as follows: validdomain.com@3232235777
What is most likely to happen if the URL is entered in the address bar of a web browser? Select two.
The user will access the resource pointed to by 3232235777 at validdomain.com.
3232235777 will be used as the username and validdomain.com will prompt for the password.
validdomain.com will be seen as a username and be discarded.
Entering the URL in a browser will launch an email app allowing the user to send a message.
The request will be sent to 3232235777, the decimal equivalent of the corresponding IPv4 address.
A threat actor launches a zero-day attack against a popular social media app. Upon discovery, a security analyst is asked to categorize the attack using a Johari window. Under which category should this type of attack be placed?
Unknown knowns
Known unknowns
Unknown unknowns
Known knowns
An attacker manages to compromise a network and slowly injects data into the network to make it appear as innocuous data. What type of attack is the threat actor most likely performing?
Data exfiltration
Data spoofing
Data poisoning
Data infiltration
Data adulteration
An individual is probing for weaknesses and successfully finds one. The individual then proceeds to provide the information to the organization. Which of the following best describes this type of individual?
Intentional insider threat
Insider threat
Individual hacker
White hat hacker
Black hat hacker
A developer is using an API to create an app that pulls data from an insurance portal. However, in the effort, a particular type of data that was readily available is suddenly no longer available. Which of the following statements most closely represents what could have happened?
A cryptographic failure is preventing proper authentication.
The portal had a broken access control condition that was fixed.
The POST command issued is not properly structured.
A security breach has created a buffer overflow condition.
A group of threat actors is planning to launch a denial-of-service attack against a state government website because they are opposed to a ruling issued by the state's supreme court. Which of the following is most likely to launch the attack?
Cyberterrorist brokers
Hacktivists
Nation-state actors
Organized crime members
