1/45
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
An attacker uses a list of 1 million common passwords to crack a user's account. What type of attack is this?
Dictionary attack
A hacker attempts every possible password combination until the correct one is found. What attack is this?
Brute-force attack
An attacker tries the password "Winter2025!" against every user account in a company. What attack is this?
Password spraying
An attacker uses usernames and passwords leaked from another website to log into company accounts. What attack is this?
Credential stuffing
Which attack uses precomputed password hashes to crack passwords?
Rainbow table attack
An attacker creates a fake Wi-Fi network using the same SSID as a legitimate company network. What attack is this?
Evil Twin
An employee secretly installs their own wireless access point on the corporate network. What is this called?
Rogue Access Point
Which attack changes the source IP address to impersonate another device?
IP spoofing
A user is redirected to fake banking websites even when entering the correct URL. What attack is MOST likely?
DNS poisoning
An attacker intercepts communication between two systems without either party knowing. What attack is this?
Man-in-the-Middle (MitM)
Which attack involves secretly capturing wireless traffic between a victim and an access point?
Packet sniffing
An attacker sends fraudulent emails requesting login credentials. What attack is this?
Phishing
Which social engineering attack uses text messages?
Smishing
Which social engineering attack uses phone calls?
Vishing
Which phishing attack specifically targets one individual?
Spear phishing
Which phishing attack specifically targets executives?
Whaling
Which attack involves following an authorized employee through a secure door?
Tailgating
An attacker watches a user type their password. What attack is this?
Shoulder surfing
An attacker searches company rubbish bins for sensitive information. What attack is this?
Dumpster diving
Which attack tricks users into revealing confidential information by pretending to be someone trustworthy?
Social engineering
An attacker floods a web server with traffic until legitimate users cannot access it. What attack is this?
DDoS
Which attack originates from many compromised computers simultaneously?
DDoS
Malicious software encrypts a company's files and demands payment. What type of malware is this?
Ransomware
Which malware disguises itself as legitimate software?
Trojan
Which malware spreads automatically without user interaction?
Worm
Which malware requires a host file to spread?
Virus
Which malware secretly records user activity such as passwords and browsing history?
Spyware
Which malware displays unwanted advertisements?
Adware
Which malware hides itself by modifying the operating system?
Rootkit
A company receives a USB drive in the mail labeled "Employee Salaries." An employee plugs it into their computer. What attack does this demonstrate?
Baiting
An attacker offers a free USB charger that secretly steals data. What social engineering attack is this?
Baiting
An attacker invents a believable story to convince an employee to reveal confidential information. What attack is this?
Pretexting
An attacker repeatedly sends MFA approval requests hoping the victim accepts one. What attack is this?
MFA fatigue
Which attack attempts to exploit trust by pretending to be a coworker or manager?
Impersonation
An attacker captures data traveling across an unsecured network. What technique is this?
Packet sniffing
A hacker inserts malicious SQL commands into a login form to access a database. What attack is this?
SQL Injection
A malicious script executes in another user's web browser after visiting a compromised website. What attack is this?
Cross-Site Scripting (XSS)
Which attack modifies website content displayed to users by injecting scripts into webpages?
XSS
An attacker gains access to a user's active authenticated web session. What attack is this?
Session hijacking
Which attack intercepts authentication cookies to impersonate a logged-in user?
Session hijacking
A criminal records every key pressed on a victim's keyboard. What malware is this?
Keylogger
Which malware is specifically designed to secretly capture usernames and passwords?
Keylogger
A user installs what appears to be a legitimate PDF reader, but it secretly installs malware. What type of malware is this?
Trojan
Which attack is MOST likely if multiple users report connecting to Wi-Fi with the company's SSID but traffic is being intercepted?
Evil Twin
Which attack is MOST likely if hundreds of login attempts are made using one password against many usernames?
Password spraying
Which attack is MOST likely if a login page receives every possible password combination for a single account?
Brute-force attack