Security Attacks (core 2)

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/45

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 5:10 AM on 7/27/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

46 Terms

1
New cards

An attacker uses a list of 1 million common passwords to crack a user's account. What type of attack is this?

Dictionary attack

2
New cards

A hacker attempts every possible password combination until the correct one is found. What attack is this?

Brute-force attack

3
New cards

An attacker tries the password "Winter2025!" against every user account in a company. What attack is this?

Password spraying

4
New cards

An attacker uses usernames and passwords leaked from another website to log into company accounts. What attack is this?

Credential stuffing

5
New cards

Which attack uses precomputed password hashes to crack passwords?

Rainbow table attack

6
New cards

An attacker creates a fake Wi-Fi network using the same SSID as a legitimate company network. What attack is this?

Evil Twin

7
New cards

An employee secretly installs their own wireless access point on the corporate network. What is this called?

Rogue Access Point

8
New cards

Which attack changes the source IP address to impersonate another device?

IP spoofing

9
New cards

A user is redirected to fake banking websites even when entering the correct URL. What attack is MOST likely?

DNS poisoning

10
New cards

An attacker intercepts communication between two systems without either party knowing. What attack is this?

Man-in-the-Middle (MitM)

11
New cards

Which attack involves secretly capturing wireless traffic between a victim and an access point?

Packet sniffing

12
New cards

An attacker sends fraudulent emails requesting login credentials. What attack is this?

Phishing

13
New cards

Which social engineering attack uses text messages?

Smishing

14
New cards

Which social engineering attack uses phone calls?

Vishing

15
New cards

Which phishing attack specifically targets one individual?

Spear phishing

16
New cards

Which phishing attack specifically targets executives?

Whaling

17
New cards

Which attack involves following an authorized employee through a secure door?

Tailgating

18
New cards

An attacker watches a user type their password. What attack is this?

Shoulder surfing

19
New cards

An attacker searches company rubbish bins for sensitive information. What attack is this?

Dumpster diving

20
New cards

Which attack tricks users into revealing confidential information by pretending to be someone trustworthy?

Social engineering

21
New cards

An attacker floods a web server with traffic until legitimate users cannot access it. What attack is this?

DDoS

22
New cards

Which attack originates from many compromised computers simultaneously?

DDoS

23
New cards

Malicious software encrypts a company's files and demands payment. What type of malware is this?

Ransomware

24
New cards

Which malware disguises itself as legitimate software?

Trojan

25
New cards

Which malware spreads automatically without user interaction?

Worm

26
New cards

Which malware requires a host file to spread?

Virus

27
New cards

Which malware secretly records user activity such as passwords and browsing history?

Spyware

28
New cards

Which malware displays unwanted advertisements?

Adware

29
New cards

Which malware hides itself by modifying the operating system?

Rootkit

30
New cards

A company receives a USB drive in the mail labeled "Employee Salaries." An employee plugs it into their computer. What attack does this demonstrate?

Baiting

31
New cards

An attacker offers a free USB charger that secretly steals data. What social engineering attack is this?

Baiting

32
New cards

An attacker invents a believable story to convince an employee to reveal confidential information. What attack is this?

Pretexting

33
New cards

An attacker repeatedly sends MFA approval requests hoping the victim accepts one. What attack is this?

MFA fatigue

34
New cards

Which attack attempts to exploit trust by pretending to be a coworker or manager?

Impersonation

35
New cards

An attacker captures data traveling across an unsecured network. What technique is this?

Packet sniffing

36
New cards

A hacker inserts malicious SQL commands into a login form to access a database. What attack is this?

SQL Injection

37
New cards

A malicious script executes in another user's web browser after visiting a compromised website. What attack is this?

Cross-Site Scripting (XSS)

38
New cards

Which attack modifies website content displayed to users by injecting scripts into webpages?

XSS

39
New cards

An attacker gains access to a user's active authenticated web session. What attack is this?

Session hijacking

40
New cards

Which attack intercepts authentication cookies to impersonate a logged-in user?

Session hijacking

41
New cards

A criminal records every key pressed on a victim's keyboard. What malware is this?

Keylogger

42
New cards

Which malware is specifically designed to secretly capture usernames and passwords?

Keylogger

43
New cards

A user installs what appears to be a legitimate PDF reader, but it secretly installs malware. What type of malware is this?

Trojan

44
New cards

Which attack is MOST likely if multiple users report connecting to Wi-Fi with the company's SSID but traffic is being intercepted?

Evil Twin

45
New cards

Which attack is MOST likely if hundreds of login attempts are made using one password against many usernames?

Password spraying

46
New cards

Which attack is MOST likely if a login page receives every possible password combination for a single account?

Brute-force attack