NEW
Font size
WorksheetsNetwork Security Quiz
Total questions: 40
Worksheet time: 20mins
Wireshark primarily operates at which OSI layer
Application layer
Data Link layer
Transport layer
Session layer
Which protocol is MOST vulnerable to packet sniffing
HTTPS
SSH
FTP
SFTP
What is the main purpose of ARP poisoning
Denial of Service
Man-in-the-Middle attack
Port scanning
Password cracking
Which HTTP method is mainly abused for unauthorized data modification
GET
POST
HEAD
OPTIONS
Which OWASP Top 10 (2021) category includes SQL Injection
Broken Access Control
Injection
Security Misconfiguration
Cryptographic Failures
What does XSS primarily target
Database
Server OS
User’s browser
Network device
Stored XSS differs from reflected XSS because it is
Executed only once
Stored on server permanently
Client-side only
Network based
What is the primary goal of threat modeling
Patch vulnerabilities
Rank threats by risk
Detect malware
Encrypt data
Which tool acts as an intercepting proxy
Wireshark
Burp Suite
Nessus
Metasploit
Which type of scan does not complete TCP handshake
TCP connect scan
SYN scan
UDP scan
Ping scan
Which TCP flags are set in an XMAS scan
SYN, ACK
FIN only
FIN, PSH, URG
ACK only
Idle scan requires a zombie host with
High traffic
Predictable IPID
Closed ports
No firewall
Banner grabbing mainly helps identify
Open ports
Service versions
Exploit code
Passwords
Which protocol is used for DNS zone transfer
HTTP
FTP
DNS AXFR
SNMP
MAC flooding targets which table
Routing table
ARP cache
CAM table
NAT table
Which malware spreads without user interaction
Trojan
Virus
Worm
Rootkit
A Trojan is best described as
Self-replicating malware
Kernel-level malware
Malicious software disguised as legitimate
Network-only attack
Polymorphic malware changes its
Functionality
Target OS
Signature
Payload size
Which tool is used for system file integrity verification
Nessus
Tripwire
Wireshark
Nmap
Smurf attack abuses
TCP handshake
ICMP broadcast
DNS recursion
UDP flooding
SYN flood attack exhausts
Bandwidth
CPU
Half-open connections
Disk space
Session hijacking is easiest when
HTTPS is used
Session IDs are predictable
IDS is enabled
Firewall is present
Which wireless protocol is weakest
WPA2
WPA
WEP
802.1X
Deauthentication attack operates at
Layer 1
Layer 2
Layer 3
Layer 7
Evil Twin attack involves
Fake client
Fake access point
Fake DNS server
Fake IP address
IDS differs from IPS because IDS
Blocks traffic
Drops packets
Generates alerts
Modifies payload
Signature-based IDS fails mainly against
Known attacks
Brute force
Zero-day attacks
Port scans
Application proxy firewall works at
Layer 3
Layer 4
Layer 5
Layer 7
Honeypots are primarily used to
Block attackers
Replace firewall
Observe attacker behavior
Encrypt traffic
The major legal concern with honeypots is
Malware hosting
Entrapment
Packet loss
IDS bypass
Android app sandboxing is enforced by
Dalvik VM
Google Play
Linux kernel UID model
Application signature
ADB is mainly used for
Packet sniffing
Device debugging
Malware creation
Network scanning
MobSF supports
Static analysis only
Dynamic analysis only
Both static and dynamic analysis
Network scanning
Which phase of ethical hacking defines scope and permission
Reconnaissance
Scanning
Planning
Exploitation
Penetration testing differs from vulnerability scanning because it
Uses tools
Is automated
Actively exploits vulnerabilities
Generates reports
Google dorking is mainly used for
Exploitation
OSINT gathering
Password cracking
Network scanning
Which command performs host discovery only in Nmap
nmap -sS
nmap -A
nmap -sn
nmap -p 80
True Positive means
Attack exists but not detected
No attack but detected
Attack exists and detected
No attack and not detected
False Positive means
Attack exists and missed
No attack but detected
Attack exists and detected
No attack and not detected
The MOST common real-world attack vector is
Zero-day exploit
Buffer overflow
Social engineering
SQL injection
