1/176
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What is the main difference between a worm and a virus?
A worm can replicate itself, while a virus requires a host for distribution.
What type of malware monitors your actions?
Spyware
A collection of zombie computers have been set up to collect personal information. What type of
malware do the zombie computers represent?
Botnet
Which is a program that appears to be a legitimate application, utility, game, or screensaver and performs malicious activities surreptitiously?
Trojan horse
Which of the following describes a logic bomb?
A program that performs a malicious activity at a specific time or after a triggering
event.
Which of the following is a characteristic of a virus?
Requires an activation mechanism to run
Which of the following is undetectable software that allows administrator-level access?
Rootkit
Which of the following are characteristics of a rootkit? (Select two.)
Requires administratorlevel privileges for installation.
Hides itself from detection
You have heard about a new malware program that presents itself to users as a virus scanner. When users run the software, it installs itself as a hidden program that has administrator access to various operating system components. The program then tracks system activity and allows an attacker to remotely gain administrator access to the computer.
Which of the following terms best describes this software?
Rootkit
While browsing the internet, you notice that the browser displays ads that are targeted towards recent keyword searches you have performed.
What is this an example of?
Adware
Which of the following best describes spyware?
It monitors the actions you take on your machine and sends the information back to its originating source.
What is the common name for a program that has no useful purpose, but attempts to spread itself to other systems and often damages resources on the systems where it is found?
Virus
What is the primary distinguishing characteristic between a worm and a logic bomb?
Self-replication
What is another name for a logic bomb?
Asynchronous attack
You have installed anti-malware software that checks for viruses in email attachments. You configure the software to quarantine any files with problems.
You receive an email with an important attachment, but the attachment is not there. Instead, you see a message that the file has been quarantined by the anti-malware software.
What has happened to the file?
It has been moved to a secure folder on your computer.
Which of the following measures are you most likely to implement to protect against a worm or Trojan horse?
Anti-virus software
Which of the following statements about the use of antivirus software is correct?
Antivirus software should be configured to download updated virus definition files as soon as they become available.
If your antivirus software does not detect and remove a virus, what should you try first?
Update your virus detection software.
You have installed antivirus software on the computers on your network. You update the
definition and engine files and configure the software to update those files every day.
What else should you do to protect your systems from malware? (Select two.)
Schedule regular full system scans.
Educate users about malware
To tightly control the anti-malware settings on your computer, you elect to update the signature file manually. Even though you vigilantly update the signature file, the machine becomes infected with a new type of malware.
Which of the following actions would best prevent this scenario from occurring again?
Configure the software to automatically download the virus definition files as soon as
they become available
You recently discovered that several key files of your antivirus program have been deleted. You suspect that a virus has deleted the files. Which type of virus deletes key antivirus program files?
Retro
Which type of virus conceals its presence by intercepting system requests and altering service outputs?
Stealth
Which of the following is an example of an internal threat?
A user accidentally deletes the new product designs.
What is the greatest threat to the confidentiality of data in most secure organizations?
USB devices
Which of the following is an example of privilege escalation?
Creeping privileges
Which of the following attacks tricks victims into providing confidential information (such as identity information or login credentials) through emails or websites that impersonate an online entity that the victim trusts?
Phishing
Match the social engineering description on the left with the appropriate attack type on the right.
1.Phishing
2.Whaling
3.Spear phishing
4.Dumpster diving
5.Piggybacking
6.Vishing
1.An attacker pretending to be from a trusted organization sends an email asking users to access a website to verify personal information.
2.An attacker gathers personal information about the target individual, who is a CEO.
3.An attacker gathers personal information about the target individual in an organization.
4.An attacker searches through an organization's trash looking for sensitive information.
5.An attacker enters a secured building by following an authorized employee through a secure
door without providing identification.
6. An attacker uses a telephone to convince target individuals to reveal their credit card information.
Which of the following is a common social engineering attack?
Distributing hoax virus information emails
Which of the following is not a form of social engineering?
Impersonating a user by logging on with stolen credentials
You have just received a genericlooking email that is addressed as coming from the administrator of your company. The email says that, as part of a system upgrade, you are to go to a website and enter your user name and password at a new website so you can manage your email and spam using the new service.
What should you do?
Verify that the email was sent by the administrator and that this new service is
legitimate.
Dumpster diving is a lowtech way to gathering information that may be useful in gaining unauthorized access or as a starting point for more advanced attacks. How can a company reduce the risk associated with dumpster diving?
Establish and enforce a document destruction policy
Which of the following are examples of social engineering? (Select two.)
1. Shoulder surfing
2. Dumpster diving
Which of the following social engineering attacks use Voice over IP (VoIP) to gain sensitive information?
Vishing
A senior executive reports that she received a suspicious email concerning a sensitive internal project that is behind production. The email was sent from someone she doesn't know, and he is asking for immediate clarification on several of the project's details so the project can get back on schedule.
Which type of an attack best describes the scenario?
Whaling
Identify and label the following attacks by dragging the term on the left to the definition on the right. Not all terms are used.
1. Masquerading
2.Whaling
3.Vishing
4.Spear phishing
5. Spim
1.An attacker convinces personnel to grant access to sensitive information or protected systems by pretending to be someone who is authorized and/or requires that access.
2.An attacker pretending to be from a trusted organization sends emails to senior executives and high-profile personnel asking them to verify personal information or send money.
3.Attackers use Voice over IP (VoIP) to pretend to be from a trusted organization and ask victims to verify personal information or send money.
4.Attackers send emails with specific information about the victim (such as which online banks
they use) that ask them to verify personal information or send money.
5.Attackers send unwanted and unsolicited text messages to many people with the intent to sell products or services.
The receptionist received a phone call from an individual claiming to be a partner in a highlevel project and requesting sensitive information. The individual is engaging in which type of social engineering?
Authority
You've just received an email message explaining that a new and serious malicious code threat is ravaging across the internet. The message contains detailed information about the threat, its source code, and the damage it can inflict. The message states that you can easily detect whether or not you have already been a victim of this threat by the presence of three files in the \Windows\System32 folder. As a countermeasure, the message suggests that you delete these three files from your system.
In response to this message, which action should you take first?
Verify the information on wellknown malicious code threat management websites
What is the weakest point in an organization's security infrastructure?
People
Which of the following is the main difference between a DoS attack and a DDoS attack?
The DDoS attack uses zombie computers.
An attacker sets up 100 drone computers that flood a DNS server with invalid requests. This is an
example of which kind of attack?
DDoS
Which of the following are denial of service attacks? (Select two.)
1.Fraggle
2.Fraggle
Which attack form either exploits a software flaw or floods a system with traffic in order to prevent legitimate activities or transactions from occurring?
Denial of service attack
As the victim of a Smurf attack, what protection measure is the most effective during the attack?
Communicate with your upstream provider
You suspect that an Xmas tree attack is occurring on a system. Which of the following could result if you do not stop the attack? (Select two.)
1. The threat agent will obtain information about open ports on the system.
2. The system will be unavailable to respond to legitimate requests.
You need to enumerate the devices on your network and display the network's configuration details.
nmap
An attacker is conducting passive reconnaissance on a targeted company. Which of the following could he be doing?
Browsing the organization's website
Which type of active scan turns off all flags in a TCP header?
Null
Which of the following denial of service (DoS) attacks uses ICMP packets and is only successful if the victim has less bandwidth than the attacker?
Ping flood
In which of the following denial of service (DoS) attacks does the victim's system rebuild invalid
UDP packets, causing the system to crash or reboot?
Teardrop
A SYN packet is received by a server. The SYN packet has the exact same address for both the sender and receiver addresses, which is the address of the server. This is an example of what type of attack?
Land attack
Which of the following is a denial of service attack that:
• Subverts the TCP threeway handshake process by attempting to open numerous sessions on a victim server
• Intentionally fails to complete the session by not sending the final required packet
SYN flood
Which of the following is a form of denial of service attack that uses spoofed ICMP packets to flood a victim with echo requests using a bounce/amplification network?
Smurf
A SYN attack or SYN flood exploits or alters which element of the TCP threeway handshake?
ACK
When a SYN flood is altered so that the SYN packets are spoofed in order to define the source and destination address as a single victim IP address, the attack is now called what?
Land attack
Which of the following best describes the ping of death?
An ICMP packet that is larger than 65,536 bytes
Which of the following is the best countermeasure against maninthemiddle attacks?
IPsec
What is modified in the most common form of spoofing on a typical IP packet?
Source address
Which type of activity changes or falsifies information in order to mislead or redirect traffic?
Spoofing
What is spoofing?
Changing or falsifying information in order to mislead or redirect traffic.
Which type of denial of service (DoS) attack occurs when a name server receives malicious or misleading data that incorrectly maps host names and IP addresses?
DNS poisoning
Which of the following describes a man-in-the-middle attack?
A false server intercepts communications from a client by impersonating the intended
server.
Capturing packets as they travel from one host to another with the intent of altering the contents of the packets is a form of which attack type?
Man-in-the-middle attack
When the TCP/IP session state is manipulated so that a third party is able to insert alternate packets into the communication stream, what type of attack has occurred?
Hijacking
What is the goal of a TCP/IP hijacking attack?
Executing commands or accessing resources on a system the attacker does not
otherwise have authorization to access.
Which of the following is not a protection against session hijacking?
DHCP reservations
Which of the following is the most effective protection against IP packet spoofing on a private network?
Ingress and egress filters
While using the internet, you type the URL of one of your favorite sites in the browser. Instead of going to the correct site, however, the browser displays a completely different website. When you use the IP address of the web server, the correct site is displayed.
Which type of attack has likely occurred?
DNS poisoning
Which of the following attacks tries to associate an incorrect MAC address with a known IP address?
ARP poisoning
What are the most common network traffic packets captured and used in a replay attack?
Authentication
When a malicious user captures authentication traffic and replays it against the network later, what is the security problem you are most concerned about?
An unauthorized user gaining access to sensitive resources
A router on the border of your network detects a packet with a source address that is from an internal client, but the packet was received on the internetfacing interface. This is an example of what form of attack?
Spoofing
An attacker uses an exploit to push a modified hosts file to client systems. This hosts file redirects traffic from legitimate tax preparation sites to malicious sites to gather personal and financial information.
What kind of exploit has been used in this scenario?
(Choose two. Both responses are different names for the same exploit.)
1. DNS poisoning
2. Pharming
Which of the following locations contributes the greatest amount of interference for a wireless access point? (Select two.)
1. Near cordless phones
2. Near backup generators
Your company security policy states that wireless networks are not to be used because of the potential security risk they present to your network.
One day, you find that an employee has connected a wireless access point to the network in his office.
What type of security risk is this?
Rogue access point
Which of the following describes the marks attackers place outside a building to identify an open wireless network?
War chalking
The process of walking around an office building with an 802.11 signal detector is known as what?
War driving
Which of the following best describes Bluesnarfing?
Viewing calendar, emails, and messages on a mobile device without authorization
Which of the following sends unsolicited business cards and messages to a Bluetooth device?
Bluejacking
Which of the following is the best protection to prevent attacks on mobile phones through the Bluetooth protocol?
Disable Bluetooth on the phone
You are troubleshooting a wireless connectivity issue in a small office. You determine that the 2.4 GHz cordless phones used in the office are interfering with the wireless network transmissions.
If the cordless phones are causing the interference, which of the following wireless standards could the network be using? (Select two.)
1. Bluetooth
2. 802.11g
Your organization uses an 802.11g wireless network. Recently, other tenants installed the following equipment in your building:
• A wireless television distribution system running at 2.4 GHz
• A wireless phone system running at 5.8 GHz
• A wireless phone system running at 900 MHz
• An 802.11n wireless network running in the 5 GHz frequency range
Since this equipment was installed, your wireless network has been experiencing significant interference. Which system is to blame?
The wireless TV system
A user calls to report that she is experiencing intermittent problems while accessing the wireless network from her laptop computer. While she normally works from her office, today she is trying to access the wireless network from a conference room across the hall and next to the elevator.
What is the most likely cause of her connectivity problem?
Interference is affecting the wireless signal.
Which of the following best describes an evil twin?
An access point that is configured to mimic a valid access point to obtain logon
credentials and other sensitive information.
Network packet sniffing is often used to gain the information necessary to conduct more specific and detailed attacks. Which of the following is the best defense against packet sniffing?
Encryption
Which of the following common network monitoring or diagnostic activities can be used as a passive malicious attack?
Sniffing
Match the malicious interference type on the right with the appropriate characteristic on the left. Each characteristic can be used once, more than once, or not at all.
1. Spark Jamming
2.Random Noise Jamming
3.Random Pulse Jamming
1.Repeatedly blasts receiving equipment with highintensity, shortduration RF bursts at a rapid pace
2.Produces RF signals using random amplitudes and frequencies
3.Uses radio signal pulses of random amplitude and frequency
An attacker has hidden an NFC reader behind an NFC based kiosk in an airport.
The attacker uses the device to capture NFC data in transit between end user devices and the reader in the kiosk. She then uses that information to masquerade as the original end user device and establish an NFC connection to the kiosk.
What kind of attack has occurred in this scenario?
NFC relay attack
You are implementing a wireless network in a dentist's office. The dentist's practice is small, so you choose to use an inexpensive consumergrade access point.
While reading the documentation, you notice that the access point supports WiFi Protected Setup (WPS) using a PIN. You are concerned about the security implications of this functionality.
What should you do to reduce risk?
Disable WPS in the access point's configuration
You are concerned that wireless access points may have been deployed within your organization without authorization.
What should you do? (Select two. Each response is a complete solution.)
Conduct a site survey
Check the MAC addresses of devices connected to your wired switch
A relatively new employee in the data entry cubical farm was assigned a user account similar to the other data entry employees' accounts. However, audit logs have shown that this user account has been used to change ACLs on several confidential files and has accessed data in restricted areas.
This situation indicates which of the following has occurred?
Privilege escalation
An attacker has obtained the logon credentials for a regular user on your network. Which type of security threat exists if this user account is used to perform administrative functions?
Privilege escalation
You've just deployed a new Cisco router that connects several network segments in your organization.
The router is physically located in a server room that requires an ID card to gain access. You've backed up the router configuration to a remote location in an encrypted file. You access the router configuration interface from your notebook computer by connecting it to the console port on the router. You configured the management interface with a user name of admin and a password of password.
What should you do to increase the security of this device?
Use a stronger administrativepassword.
While developing a network application, a programmer adds functionally that allows her to access
the running program without authentication so she can capture debugging data. The programmer
forgets to remove this functionality prior to finalizing the code and shipping the application.
What type of security weakness does this represent?
Backdoor
Which of the following password attacks uses preconfigured matrices of hashed dictionary words?
Rainbow table
Which of the following is most vulnerable to a brute force attack?
Password authentication
A user named Bob Smith has been assigned a new desktop workstation to complete his daytoday work.
When provisioning Bob's user account in your organization's domain, you assigned an account name of BSmith with an initial password of bw2Fs3d.
On first login, Bob is prompted to change his password, so he changes it to the name of his dog (Fido).
What should you do to increase the security of Bob's account? (Select two.) Configure
Train users not to use passwords that are easy to guess.
Use Group Policy to require strong passwords on user accounts.
Which type of malicious activity can be described as numerous unwanted and unsolicited email messages sent to a wide range of victims?
Spamming
An attacker sends an unwanted and unsolicited email message to multiple recipients with an attachment that contains malware.
What kind of attack has occurred in this scenario?
spam
What is the most common means of virus distribution?
You install a new Linux distribution on a server in your network. The distribution includes an SMTP daemon that is enabled by default when the system boots. The SMTP daemon does not require authentication to send email messages.
Which type of email attack is this server susceptible to?
Open SMTP relay