NEW
Font size
WorksheetsL6 CSO Cyber Threats
Total questions: 67
Worksheet time: 34mins
The 2017 WannaCry outbreak primarily exploited which vulnerability?
SQL Injection
SMBv1 EternalBlue exploit
Weak RDP passwords
DNS cache poisoning
Which malware technique allows malicious code to remain dormant until a specific condition is met?
Polymorphism
Logic bomb
Rootkit injection
Fileless execution
Emotet is best classified as which type of malware?
Ransomware only
Trojan horse
Spyware
Adware
Fileless malware commonly abuses which Windows feature?
Windows Defender
PowerShell
NTFS journaling
Task Scheduler GUI
Which malware persistence mechanism modifies the Master Boot Record?
Macro virus
Bootkit
Logic bomb
Worm
The primary purpose of the NotPetya attack was:
Financial extortion
Cryptocurrency mining
Destructive data wiping
Credential harvesting
Which malware technique encrypts its payload differently each time?
Steganography
Polymorphism
Packing
Obfuscation
A trojan disguised as a software update installing a RAT is an example of:
Worm propagation
Supply chain malware
Privilege escalation
Credential stuffing
Which ransomware strain is known for double extortion?
Zeus
LockBit
Conficker
Stuxnet
Malware that spreads without user interaction is known as:
Trojan
Rootkit
Worm
Spyware
A targeted phishing email pretending to be from a company's CEO requesting an urgent wire transfer is known as:
Smishing
Vishing
Whaling
Pretexting
An attacker calls an employee pretending to be IT support to reset their MFA token. This is an example of:
Baiting
Vishing
Tailgating
Watering hole attack
Which social engineering attack relies on curiosity, such as leaving infected USB drives in a car park?
Pretexting
Baiting
Phishing
Shoulder surfing
In the 2020 Twitter breach, attackers primarily used:
SQL injection
Zero-day exploits
Phone-based social engineering
Brute-force attacks
Creating a fake scenario to manipulate a victim into disclosing information is known as:
Spoofing
Pretexting
Pharming
Dumpster diving
A QR code on a restaurant table leading to a fake payment website is an example of:
Smishing
Quishing
Vishing
Pharming
Which psychological principle is most often exploited in “urgent action required” phishing emails?
Reciprocity
Authority
Scarcity
Fear
A fake LinkedIn recruiter sending a malicious document to a developer is commonly associated with:
Credential stuffing
Spear phishing
Malvertising
Drive-by downloads
An attacker following an employee through a secure door without authentication is known as:
Piggybacking
Spoofing
Shoulder surfing
Eavesdropping
MFA fatigue attacks attempt to:
Bypass encryption
Overwhelm users with repeated authentication requests
Steal session cookies
Exploit password reuse
ARP spoofing allows an attacker to:
Hijack DNS queries
Perform man-in-the-middle attacks
Crash routing tables
Bypass firewalls
Which attack was used in the Mirai botnet to compromise IoT devices?
Zero-day exploits
Default credentials
SQL injection
Phishing
DNS amplification attacks exploit:
Weak encryption
Recursive DNS resolvers
Browser vulnerabilities
HTTP headers
A rogue Wi-Fi access point mimicking a legitimate network is known as:
Evil twin attack
Bluejacking
Wardriving
Jamming
Which tool is commonly used for password spraying in enterprise environments?
Nmap
Hydra
Wireshark
Metasploit
What is the primary goal of a man-in-the-middle attack?
Destroy data
Intercept or alter communications
Overload servers
Encrypt user files
Which network attack exploits improperly segmented VLANs?
VLAN hopping
ARP flooding
DNS poisoning
Packet injection
SQL injection exploits which application weakness?
Poor authentication
Unsanitised user input
Weak encryption
Insecure cookies
Cross-Site Scripting (XSS) primarily targets:
Web servers
Databases
End users' browsers
Firewalls
A web attack that forces a logged-in user to perform unwanted actions is:
CSRF
XSS
SSRF
LFI
Which attack allows access to internal cloud metadata services such as AWS IAM credentials?
SQL injection
SSRF
RCE
IDOR
Insecure Direct Object Reference (IDOR) vulnerabilities often lead to:
Privilege escalation
Broken access control
Malware infection
Network sniffing
Stuxnet specifically targeted which type of system?
Web servers
Banking platforms
Industrial control systems (ICS)
Cloud infrastructure
Which IoT weakness is most commonly exploited in smart home devices?
Buffer overflow
Hardcoded credentials
Kernel exploits
Heap spraying
An attack that sends malformed Modbus packets to disrupt industrial processes is an example of:
IT malware
OT protocol abuse
Cloud misconfiguration
Web injection
Misconfigured S3 buckets primarily lead to:
Ransomware
Data exposure
DDoS attacks
Privilege escalation
Which cloud attack involves abusing excessive permissions assigned to service accounts?
IAM privilege escalation
Container escape
Side-channel attack
Cryptojacking
Cryptojacking in cloud environments often results in:
Data deletion
Increased cloud billing
Service outages
Credential theft
A Kubernetes pod escaping its container is an example of:
Lateral movement
Container breakout
API abuse
SSRF
Which attack exploits insecure CI/CD pipelines?
Supply chain attack
DNS poisoning
Credential stuffing
SQL injection
Exposed cloud API keys in GitHub repositories often lead to:
Web defacement
Cloud resource abuse
Malware injection
Network sniffing
Which web attack reads server-side files such as '/etc/passwd'?
XSS
LFI
CSRF
SSRF
OT environments are particularly vulnerable because they often:
Use outdated, unpatched systems
Lack internet connectivity
Use encrypted protocols only
Employ zero-trust architecture
A watering hole attack targets:
Random victims
High-traffic public websites
Specific groups frequently visiting a site
Cloud infrastructure
Which attack abuses OAuth misconfiguration to access user data?
Token replay
Authorization code interception
Broken authentication
Clickjacking
What is the primary risk of exposed Docker APIs?
Web defacement
Remote code execution
SQL injection
DDoS
Cloud "shadow IT" primarily increases the risk of:
Physical theft
Unmonitored data leakage
Network congestion
Malware signatures
Multiple servers are encrypted rapidly using SMB exploits on unpatched systems.
Password spraying
SMB worm propagation
Phishing
DNS poisoning
A fake supplier email requests updated bank details.
Generic phishing
Whaling
Spear phishing / BEC
Pretexting via SMS
PowerShell commands run without files being written to disk.
Polymorphic malware
Bootkit
Fileless malware
Rootkit
AWS keys leaked to GitHub result in unexpected EC2 usage.
Cloud ransomware
Cryptojacking using stolen keys
Container escape
SSRF
Multiple MFA prompts overwhelm a user.
Credential stuffing
MFA fatigue attack
SIM swapping
Pass-the-hash
URL parameter manipulation reveals other users' data.
SQL injection
Broken authentication
IDOR
XSS
Malware targets Siemens PLCs via USB drives.
WannaCry
Mirai
Stuxnet
NotPetya
A rogue Wi-Fi access point mimics the corporate network.
DNS poisoning
Evil twin attack
Wardriving
Bluejacking
Internal services accessed via web server requests.
CSRF
SSRF
XSS
SQL injection
One password attempt across many accounts.
Brute force
Credential stuffing
Password spraying
Dictionary attack
Malformed Modbus packets disrupt industrial devices.
DDoS
OT protocol abuse
Malware injection
Cloud attack
PHP shell uploaded via image upload form.
CSRF
Unrestricted file upload
Reflected XSS
SQL injection
Helpdesk reset via fake new starter call.
Phishing
Pretexting
Tailgating
Baiting
Legitimate software update installs a backdoor.
Watering hole
Zero-day
Supply chain attack
Drive-by download
Small DNS request causes large response flood.
SYN flood
DNS amplification
ARP spoofing
BGP hijacking
Attacker escapes a Docker container.
Lateral movement
Privilege escalation
Container breakout
Kernel poisoning
Session cookies stolen via injected JavaScript.
CSRF
Stored XSS
SQL injection
IDOR
CCTV cameras form a botnet.
Kernel exploits
Default credentials
Phishing
SQL injection
Cloud role has excessive permissions.
Lack of encryption
Excessive IAM permissions
Poor segmentation
Missing MFA
Staff infected after visiting a trusted forum.
Malvertising
Watering hole attack
Drive-by phishing
Credential stuffing
