1/17
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
A Denial-of-Service (DoS) attack is a cyberattack that disrupts access to a website, service, or network by overwhelming it with excessive traffic or malicious requests from a single, compromised source. A more advanced form of DoS attack where multiple compromised systems flood a target with traffic, making it harder to detect and defend against, is referred to as:
DDoS
The term "Evil twin" refers to a rogue WAP set up for eavesdropping or stealing sensitive user data. The evil twin replaces a legitimate AP by advertising its own presence with the same SSID, which causes networked hosts to perceive it as the correct AP to connect to. (T/F)
True
An attack that takes advantage of a previously unknown software vulnerability that the developer has not yet patched is known as:
Zero-day attack
Which term best describes a situation where an attacker falsifies an identifier (email address, IP address, MAC address, caller ID, or website) to appear as a trusted source, with the intent to deceive targets, bypass filters, or redirect traffic for malicious purposes?
Spoofing
Which of the statements listed below describe an on-path attack?
Attackers intercept and modify the packets sent between two communicating devices
Attackers can impersonate one of the communicating parties to alter the communication
Attackers place themselves on the communication route between two devices
Which of the following answers refers to a cyberattack that relies on testing every possible combination of letters, numbers, and symbols to gain unauthorized access to accounts, systems, or encrypted data?
Brute-force attack
Which password attack takes advantage of a predefined list of words?
Dictionary attack
Which term best describes a disgruntled employee abusing legitimate access to a company’s internal resources?
Insider threat
Which of the answers listed below refers to a security vulnerability that allows an attacker to inject malicious code into input fields, such as search bars or login forms, to execute unauthorized commands on a database?
SQL injection
Which of the following answers can be used to describe the characteristics of an XSS attack?
An attacker injects a malicious script into a trusted website
An attack that exploits the trust a user's web browser has in a website
The attacker’s script is executed in the user’s browser
A BEC attack is a targeted subtype of which broader social engineering attack category?
Phishing
Which cyberattack involves impersonating executives, vendors, or trusted partners via email to trick organizations into harmful actions such as making unauthorized wire transfers or disclosing sensitive data?
BEC
Which of the answers listed below refers to a cybersecurity threat in which attackers compromise a trusted third-party vendor, software provider, or service in the distribution pipeline to insert malicious code, hardware, or updates?
Supply chain attack
Network Access Control (NAC) defines a set of rules enforced in a network that clients attempting to access the network must comply with. With NAC, policies can be enforced before or after end-stations gain access to the network. NAC can be implemented as pre-admission NAC, where a host must, for example, be virus-free or have patches applied before it is allowed to connect to the network, and/or post-admission NAC, where a host is granted or denied permissions based on its actions after it has been provided access to the network. (T/F)
True
A network administrator is using an asset inventory report to identify systems running web server software with recently disclosed critical security flaws. This task is an example of managing which type of vulnerability?
Unpatched systems
Which of the following controls are considered basic first-line, active defenses that reduce risk from common vulnerabilities on endpoints?
Host-based firewall
Antivirus software
The most critical security risk posed by an EOL system is that newly discovered vulnerabilities will remain permanently unpatched. (T/F)
True
Which mobile device deployment model allows employees to use their personal mobile devices to access a company's restricted data and applications?
BYOD