Threats & Vulnerabilities

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/17

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 1:48 AM on 7/30/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

18 Terms

1
New cards

A Denial-of-Service (DoS) attack is a cyberattack that disrupts access to a website, service, or network by overwhelming it with excessive traffic or malicious requests from a single, compromised source. A more advanced form of DoS attack where multiple compromised systems flood a target with traffic, making it harder to detect and defend against, is referred to as:

DDoS

2
New cards

The term "Evil twin" refers to a rogue WAP set up for eavesdropping or stealing sensitive user data. The evil twin replaces a legitimate AP by advertising its own presence with the same SSID, which causes networked hosts to perceive it as the correct AP to connect to. (T/F)

True

3
New cards

An attack that takes advantage of a previously unknown software vulnerability that the developer has not yet patched is known as:

Zero-day attack

4
New cards

Which term best describes a situation where an attacker falsifies an identifier (email address, IP address, MAC address, caller ID, or website) to appear as a trusted source, with the intent to deceive targets, bypass filters, or redirect traffic for malicious purposes?

Spoofing

5
New cards

Which of the statements listed below describe an on-path attack?

Attackers intercept and modify the packets sent between two communicating devices

Attackers can impersonate one of the communicating parties to alter the communication

Attackers place themselves on the communication route between two devices

6
New cards

Which of the following answers refers to a cyberattack that relies on testing every possible combination of letters, numbers, and symbols to gain unauthorized access to accounts, systems, or encrypted data?

Brute-force attack

7
New cards

Which password attack takes advantage of a predefined list of words?

Dictionary attack

8
New cards

Which term best describes a disgruntled employee abusing legitimate access to a company’s internal resources?

Insider threat

9
New cards

Which of the answers listed below refers to a security vulnerability that allows an attacker to inject malicious code into input fields, such as search bars or login forms, to execute unauthorized commands on a database?

SQL injection

10
New cards

Which of the following answers can be used to describe the characteristics of an XSS attack?

An attacker injects a malicious script into a trusted website

An attack that exploits the trust a user's web browser has in a website

The attacker’s script is executed in the user’s browser

11
New cards

A BEC attack is a targeted subtype of which broader social engineering attack category?

Phishing

12
New cards

Which cyberattack involves impersonating executives, vendors, or trusted partners via email to trick organizations into harmful actions such as making unauthorized wire transfers or disclosing sensitive data?

BEC

13
New cards

Which of the answers listed below refers to a cybersecurity threat in which attackers compromise a trusted third-party vendor, software provider, or service in the distribution pipeline to insert malicious code, hardware, or updates?

Supply chain attack

14
New cards

Network Access Control (NAC) defines a set of rules enforced in a network that clients attempting to access the network must comply with. With NAC, policies can be enforced before or after end-stations gain access to the network. NAC can be implemented as pre-admission NAC, where a host must, for example, be virus-free or have patches applied before it is allowed to connect to the network, and/or post-admission NAC, where a host is granted or denied permissions based on its actions after it has been provided access to the network. (T/F)

True

15
New cards

A network administrator is using an asset inventory report to identify systems running web server software with recently disclosed critical security flaws. This task is an example of managing which type of vulnerability?

Unpatched systems

16
New cards

Which of the following controls are considered basic first-line, active defenses that reduce risk from common vulnerabilities on endpoints?

Host-based firewall

Antivirus software

17
New cards

The most critical security risk posed by an EOL system is that newly discovered vulnerabilities will remain permanently unpatched. (T/F)

True

18
New cards

Which mobile device deployment model allows employees to use their personal mobile devices to access a company's restricted data and applications?

BYOD