CompTIA Security+ Domain 1: Threats, Attacks and Vulnerabilities

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/176

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 3:26 AM on 8/12/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

177 Terms

1
New cards

What is the main difference between a worm and a virus?

A worm can replicate itself, while a virus requires a host for distribution.

2
New cards

What type of malware monitors your actions?

Spyware

3
New cards

A collection of zombie computers have been set up to collect personal information. What type of

malware do the zombie computers represent?

Botnet

4
New cards

Which is a program that appears to be a legitimate application, utility, game, or screensaver and performs malicious activities surreptitiously?

Trojan horse

5
New cards

Which of the following describes a logic bomb?

A program that performs a malicious activity at a specific time or after a triggering

event.

6
New cards

Which of the following is a characteristic of a virus?

Requires an activation mechanism to run

7
New cards

Which of the following is undetectable software that allows administrator-level access?

Rootkit

8
New cards

Which of the following are characteristics of a rootkit? (Select two.)

Requires administratorlevel privileges for installation.

Hides itself from detection

9
New cards

You have heard about a new malware program that presents itself to users as a virus scanner. When users run the software, it installs itself as a hidden program that has administrator access to various operating system components. The program then tracks system activity and allows an attacker to remotely gain administrator access to the computer.

Which of the following terms best describes this software?

Rootkit

10
New cards

While browsing the internet, you notice that the browser displays ads that are targeted towards recent keyword searches you have performed.

What is this an example of?

Adware

11
New cards

Which of the following best describes spyware?

It monitors the actions you take on your machine and sends the information back to its originating source.

12
New cards

What is the common name for a program that has no useful purpose, but attempts to spread itself to other systems and often damages resources on the systems where it is found?

Virus

13
New cards

What is the primary distinguishing characteristic between a worm and a logic bomb?

Self-replication

14
New cards

What is another name for a logic bomb?

Asynchronous attack

15
New cards

You have installed anti-malware software that checks for viruses in email attachments. You configure the software to quarantine any files with problems.

You receive an email with an important attachment, but the attachment is not there. Instead, you see a message that the file has been quarantined by the anti-malware software.

What has happened to the file?

It has been moved to a secure folder on your computer.

16
New cards

Which of the following measures are you most likely to implement to protect against a worm or Trojan horse?

Anti-virus software

17
New cards

Which of the following statements about the use of antivirus software is correct?

Antivirus software should be configured to download updated virus definition files as soon as they become available.

18
New cards

If your antivirus software does not detect and remove a virus, what should you try first?

Update your virus detection software.

19
New cards

You have installed antivirus software on the computers on your network. You update the

definition and engine files and configure the software to update those files every day.

What else should you do to protect your systems from malware? (Select two.)

Schedule regular full system scans.

Educate users about malware

20
New cards

To tightly control the anti-malware settings on your computer, you elect to update the signature file manually. Even though you vigilantly update the signature file, the machine becomes infected with a new type of malware.

Which of the following actions would best prevent this scenario from occurring again?

Configure the software to automatically download the virus definition files as soon as

they become available

21
New cards

You recently discovered that several key files of your antivirus program have been deleted. You suspect that a virus has deleted the files. Which type of virus deletes key antivirus program files?

Retro

22
New cards

Which type of virus conceals its presence by intercepting system requests and altering service outputs?

Stealth

23
New cards

Which of the following is an example of an internal threat?

A user accidentally deletes the new product designs.

24
New cards

What is the greatest threat to the confidentiality of data in most secure organizations?

USB devices

25
New cards

Which of the following is an example of privilege escalation?

Creeping privileges

26
New cards

Which of the following attacks tricks victims into providing confidential information (such as identity information or login credentials) through emails or websites that impersonate an online entity that the victim trusts?

Phishing

27
New cards

Match the social engineering description on the left with the appropriate attack type on the right.

1.Phishing

2.Whaling

3.Spear phishing

4.Dumpster diving

5.Piggybacking

6.Vishing

1.An attacker pretending to be from a trusted organization sends an email asking users to access a website to verify personal information.

2.An attacker gathers personal information about the target individual, who is a CEO.

3.An attacker gathers personal information about the target individual in an organization.

4.An attacker searches through an organization's trash looking for sensitive information.

5.An attacker enters a secured building by following an authorized employee through a secure

door without providing identification.

6. An attacker uses a telephone to convince target individuals to reveal their credit card information.

28
New cards

Which of the following is a common social engineering attack?

Distributing hoax virus information emails

29
New cards

Which of the following is not a form of social engineering?

Impersonating a user by logging on with stolen credentials

30
New cards

You have just received a genericlooking email that is addressed as coming from the administrator of your company. The email says that, as part of a system upgrade, you are to go to a website and enter your user name and password at a new website so you can manage your email and spam using the new service.

What should you do?

Verify that the email was sent by the administrator and that this new service is

legitimate.

31
New cards

Dumpster diving is a lowtech way to gathering information that may be useful in gaining unauthorized access or as a starting point for more advanced attacks. How can a company reduce the risk associated with dumpster diving?

Establish and enforce a document destruction policy

32
New cards

Which of the following are examples of social engineering? (Select two.)

1. Shoulder surfing

2. Dumpster diving

33
New cards

Which of the following social engineering attacks use Voice over IP (VoIP) to gain sensitive information?

Vishing

34
New cards

A senior executive reports that she received a suspicious email concerning a sensitive internal project that is behind production. The email was sent from someone she doesn't know, and he is asking for immediate clarification on several of the project's details so the project can get back on schedule.

Which type of an attack best describes the scenario?

Whaling

35
New cards

Identify and label the following attacks by dragging the term on the left to the definition on the right. Not all terms are used.

1. Masquerading

2.Whaling

3.Vishing

4.Spear phishing

5. Spim

1.An attacker convinces personnel to grant access to sensitive information or protected systems by pretending to be someone who is authorized and/or requires that access.

2.An attacker pretending to be from a trusted organization sends emails to senior executives and high-profile personnel asking them to verify personal information or send money.

3.Attackers use Voice over IP (VoIP) to pretend to be from a trusted organization and ask victims to verify personal information or send money.

4.Attackers send emails with specific information about the victim (such as which online banks

they use) that ask them to verify personal information or send money.

5.Attackers send unwanted and unsolicited text messages to many people with the intent to sell products or services.

36
New cards

The receptionist received a phone call from an individual claiming to be a partner in a highlevel project and requesting sensitive information. The individual is engaging in which type of social engineering?

Authority

37
New cards

You've just received an email message explaining that a new and serious malicious code threat is ravaging across the internet. The message contains detailed information about the threat, its source code, and the damage it can inflict. The message states that you can easily detect whether or not you have already been a victim of this threat by the presence of three files in the \Windows\System32 folder. As a countermeasure, the message suggests that you delete these three files from your system.

In response to this message, which action should you take first?

Verify the information on wellknown malicious code threat management websites

38
New cards

What is the weakest point in an organization's security infrastructure?

People

39
New cards

Which of the following is the main difference between a DoS attack and a DDoS attack?

The DDoS attack uses zombie computers.

40
New cards

An attacker sets up 100 drone computers that flood a DNS server with invalid requests. This is an

example of which kind of attack?

DDoS

41
New cards

Which of the following are denial of service attacks? (Select two.)

1.Fraggle

2.Fraggle

42
New cards

Which attack form either exploits a software flaw or floods a system with traffic in order to prevent legitimate activities or transactions from occurring?

Denial of service attack

43
New cards

As the victim of a Smurf attack, what protection measure is the most effective during the attack?

Communicate with your upstream provider

44
New cards

You suspect that an Xmas tree attack is occurring on a system. Which of the following could result if you do not stop the attack? (Select two.)

1. The threat agent will obtain information about open ports on the system.

2. The system will be unavailable to respond to legitimate requests.

45
New cards

You need to enumerate the devices on your network and display the network's configuration details.

nmap

46
New cards

An attacker is conducting passive reconnaissance on a targeted company. Which of the following could he be doing?

Browsing the organization's website

47
New cards

Which type of active scan turns off all flags in a TCP header?

Null

48
New cards

Which of the following denial of service (DoS) attacks uses ICMP packets and is only successful if the victim has less bandwidth than the attacker?

Ping flood

49
New cards

In which of the following denial of service (DoS) attacks does the victim's system rebuild invalid

UDP packets, causing the system to crash or reboot?

Teardrop

50
New cards

A SYN packet is received by a server. The SYN packet has the exact same address for both the sender and receiver addresses, which is the address of the server. This is an example of what type of attack?

Land attack

51
New cards

Which of the following is a denial of service attack that:

• Subverts the TCP threeway handshake process by attempting to open numerous sessions on a victim server

• Intentionally fails to complete the session by not sending the final required packet

SYN flood

52
New cards

Which of the following is a form of denial of service attack that uses spoofed ICMP packets to flood a victim with echo requests using a bounce/amplification network?

Smurf

53
New cards

A SYN attack or SYN flood exploits or alters which element of the TCP threeway handshake?

ACK

54
New cards

When a SYN flood is altered so that the SYN packets are spoofed in order to define the source and destination address as a single victim IP address, the attack is now called what?

Land attack

55
New cards

Which of the following best describes the ping of death?

An ICMP packet that is larger than 65,536 bytes

56
New cards

Which of the following is the best countermeasure against maninthemiddle attacks?

IPsec

57
New cards

What is modified in the most common form of spoofing on a typical IP packet?

Source address

58
New cards

Which type of activity changes or falsifies information in order to mislead or redirect traffic?

Spoofing

59
New cards

What is spoofing?

Changing or falsifying information in order to mislead or redirect traffic.

60
New cards

Which type of denial of service (DoS) attack occurs when a name server receives malicious or misleading data that incorrectly maps host names and IP addresses?

DNS poisoning

61
New cards

Which of the following describes a man-in-the-middle attack?

A false server intercepts communications from a client by impersonating the intended

server.

62
New cards

Capturing packets as they travel from one host to another with the intent of altering the contents of the packets is a form of which attack type?

Man-in-the-middle attack

63
New cards

When the TCP/IP session state is manipulated so that a third party is able to insert alternate packets into the communication stream, what type of attack has occurred?

Hijacking

64
New cards

What is the goal of a TCP/IP hijacking attack?

Executing commands or accessing resources on a system the attacker does not

otherwise have authorization to access.

65
New cards

Which of the following is not a protection against session hijacking?

DHCP reservations

66
New cards

Which of the following is the most effective protection against IP packet spoofing on a private network?

Ingress and egress filters

67
New cards

While using the internet, you type the URL of one of your favorite sites in the browser. Instead of going to the correct site, however, the browser displays a completely different website. When you use the IP address of the web server, the correct site is displayed.

Which type of attack has likely occurred?

DNS poisoning

68
New cards

Which of the following attacks tries to associate an incorrect MAC address with a known IP address?

ARP poisoning

69
New cards

What are the most common network traffic packets captured and used in a replay attack?

Authentication

70
New cards

When a malicious user captures authentication traffic and replays it against the network later, what is the security problem you are most concerned about?

An unauthorized user gaining access to sensitive resources

71
New cards

A router on the border of your network detects a packet with a source address that is from an internal client, but the packet was received on the internetfacing interface. This is an example of what form of attack?

Spoofing

72
New cards

An attacker uses an exploit to push a modified hosts file to client systems. This hosts file redirects traffic from legitimate tax preparation sites to malicious sites to gather personal and financial information.

What kind of exploit has been used in this scenario?

(Choose two. Both responses are different names for the same exploit.)

1. DNS poisoning

2. Pharming

73
New cards

Which of the following locations contributes the greatest amount of interference for a wireless access point? (Select two.)

1. Near cordless phones

2. Near backup generators

74
New cards

Your company security policy states that wireless networks are not to be used because of the potential security risk they present to your network.

One day, you find that an employee has connected a wireless access point to the network in his office.

What type of security risk is this?

Rogue access point

75
New cards

Which of the following describes the marks attackers place outside a building to identify an open wireless network?

War chalking

76
New cards

The process of walking around an office building with an 802.11 signal detector is known as what?

War driving

77
New cards

Which of the following best describes Bluesnarfing?

Viewing calendar, emails, and messages on a mobile device without authorization

78
New cards

Which of the following sends unsolicited business cards and messages to a Bluetooth device?

Bluejacking

79
New cards

Which of the following is the best protection to prevent attacks on mobile phones through the Bluetooth protocol?

Disable Bluetooth on the phone

80
New cards

You are troubleshooting a wireless connectivity issue in a small office. You determine that the 2.4 GHz cordless phones used in the office are interfering with the wireless network transmissions.

If the cordless phones are causing the interference, which of the following wireless standards could the network be using? (Select two.)

1. Bluetooth

2. 802.11g

81
New cards

Your organization uses an 802.11g wireless network. Recently, other tenants installed the following equipment in your building:

• A wireless television distribution system running at 2.4 GHz

• A wireless phone system running at 5.8 GHz

• A wireless phone system running at 900 MHz

• An 802.11n wireless network running in the 5 GHz frequency range

Since this equipment was installed, your wireless network has been experiencing significant interference. Which system is to blame?

The wireless TV system

82
New cards

A user calls to report that she is experiencing intermittent problems while accessing the wireless network from her laptop computer. While she normally works from her office, today she is trying to access the wireless network from a conference room across the hall and next to the elevator.

What is the most likely cause of her connectivity problem?

Interference is affecting the wireless signal.

83
New cards

Which of the following best describes an evil twin?

An access point that is configured to mimic a valid access point to obtain logon

credentials and other sensitive information.

84
New cards

Network packet sniffing is often used to gain the information necessary to conduct more specific and detailed attacks. Which of the following is the best defense against packet sniffing?

Encryption

85
New cards

Which of the following common network monitoring or diagnostic activities can be used as a passive malicious attack?

Sniffing

86
New cards

Match the malicious interference type on the right with the appropriate characteristic on the left. Each characteristic can be used once, more than once, or not at all.

1. Spark Jamming

2.Random Noise Jamming

3.Random Pulse Jamming

1.Repeatedly blasts receiving equipment with highintensity, shortduration RF bursts at a rapid pace

2.Produces RF signals using random amplitudes and frequencies

3.Uses radio signal pulses of random amplitude and frequency

87
New cards

An attacker has hidden an NFC reader behind an NFC based kiosk in an airport.

The attacker uses the device to capture NFC data in transit between end user devices and the reader in the kiosk. She then uses that information to masquerade as the original end user device and establish an NFC connection to the kiosk.

What kind of attack has occurred in this scenario?

NFC relay attack

88
New cards

You are implementing a wireless network in a dentist's office. The dentist's practice is small, so you choose to use an inexpensive consumergrade access point.

While reading the documentation, you notice that the access point supports WiFi Protected Setup (WPS) using a PIN. You are concerned about the security implications of this functionality.

What should you do to reduce risk?

Disable WPS in the access point's configuration

89
New cards

You are concerned that wireless access points may have been deployed within your organization without authorization.

What should you do? (Select two. Each response is a complete solution.)

Conduct a site survey

Check the MAC addresses of devices connected to your wired switch

90
New cards

A relatively new employee in the data entry cubical farm was assigned a user account similar to the other data entry employees' accounts. However, audit logs have shown that this user account has been used to change ACLs on several confidential files and has accessed data in restricted areas.

This situation indicates which of the following has occurred?

Privilege escalation

91
New cards

An attacker has obtained the logon credentials for a regular user on your network. Which type of security threat exists if this user account is used to perform administrative functions?

Privilege escalation

92
New cards

You've just deployed a new Cisco router that connects several network segments in your organization.

The router is physically located in a server room that requires an ID card to gain access. You've backed up the router configuration to a remote location in an encrypted file. You access the router configuration interface from your notebook computer by connecting it to the console port on the router. You configured the management interface with a user name of admin and a password of password.

What should you do to increase the security of this device?

Use a stronger administrativepassword.

93
New cards

While developing a network application, a programmer adds functionally that allows her to access

the running program without authentication so she can capture debugging data. The programmer

forgets to remove this functionality prior to finalizing the code and shipping the application.

What type of security weakness does this represent?

Backdoor

94
New cards

Which of the following password attacks uses preconfigured matrices of hashed dictionary words?

Rainbow table

95
New cards

Which of the following is most vulnerable to a brute force attack?

Password authentication

96
New cards

A user named Bob Smith has been assigned a new desktop workstation to complete his daytoday work.

When provisioning Bob's user account in your organization's domain, you assigned an account name of BSmith with an initial password of bw2Fs3d.

On first login, Bob is prompted to change his password, so he changes it to the name of his dog (Fido).

What should you do to increase the security of Bob's account? (Select two.) Configure

Train users not to use passwords that are easy to guess.

Use Group Policy to require strong passwords on user accounts.

97
New cards

Which type of malicious activity can be described as numerous unwanted and unsolicited email messages sent to a wide range of victims?

Spamming

98
New cards

An attacker sends an unwanted and unsolicited email message to multiple recipients with an attachment that contains malware.

What kind of attack has occurred in this scenario?

spam

99
New cards

What is the most common means of virus distribution?

e-mail

100
New cards

You install a new Linux distribution on a server in your network. The distribution includes an SMTP daemon that is enabled by default when the system boots. The SMTP daemon does not require authentication to send email messages.

Which type of email attack is this server susceptible to?

Open SMTP relay