CS 4673 Cyber Operations Quizzes

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/77

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 12:35 AM on 10/2/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

78 Terms

1
New cards

According to the lesson, what was Eligible Receiver

Eligible Receiver was a 1997 internal exercise initiated by the DoD utilizing a "red team" of hackers from the NSA who only were allowed to use publicly available computer equipment and software.

2
New cards

There are four basic means by which compromising emanations can be propagated. They are electromagnetic radiation, conduction, modulation od an intended signal, and which of the following?

Acoustics (sound) is the fourth method. Just as vibrations cause sound waves, sound waves can also cause vibrations.

3
New cards

The lesson stated that the Office of Tailored Access Operations (TAO) is a cyber-warfare intelligence-gathering unit of the NSA. It has been active since at least 1998 and identifies, monitors, infiltrates and gathers intelligence on computer systems being used by entities foreign to the U.S.

True

4
New cards

In order to defeat the problem of compromising emanations, the United States Government established the Aurora program. Begun in the mid 1950's this program focuses on evaluating and screening companies and equipment to ensure that electromagnetic radiation from information handling devices are eliminated or controlled.

False. The name of the program is TEMPEST.

5
New cards

In the defense-in-depth strategy that was emphasized in the lesson, which of the following was the innermost layer of defense?

Data defenses are the innermost layer of defense. It is the data you are trying to protect so if all other layers fail to protect it, defenses concentrating on the data are the last line of defense.

6
New cards

Active Cyber Defense (ACD) is nothing more than a "fancy" name given to the strategy of defense-in-depth. It was first introduced as a marketing strategy by Network Data Defenses (NDD) a few years ago but has since been adopted by most of the rest of industry.

False

7
New cards

To implement a security program successfully, an organization must define processes and activities for staff and systems. These policies and procedures define security controls and usage of the controls. An awareness program enhances staff understanding of the security controls. The policies and procedures define and describe all the controls at the other lavers.

This is true and was the description given for the reason for policies, procedures, and awareness in a defense-in-depth strategy

8
New cards

Defense-in-depth seems like a natural and obvious approach to security. In the case of cybersecurity, however, the lesson pointed out that the concept is easy to aspire to in theory but difficult to implement in practice. Which of the following was one of the reasons given in the lesson as to why this is the case?

It only works if all the layers work together as one, so that there is a cohesive view across all attack vectors.

9
New cards

Which layer in a defense-in-depth strategy encompasses every point at which the internal network connects to external networks and hosts?

This is the description of Perimeter Defenses provided in the lesson. Don't get it mixed up with Network Defenses which are focused on the internal network.

10
New cards

The famous SYN flooding attack takes advantage of the 3-way handshake which is part of which protocol?

The three-way handshake that is part of the SYN Flooding attack is part of the TCP protocol.

11
New cards

The Smurf attack is a distributed denial-of-service attack in which large numbers of Internet Control Message protocol (IMP) packets with the intended victim's spoofed source IP are broadcast to a computer network using an IP broadcast address. If a number of machines on the network that receive and respond to these packets is very large, the victim's computer will be flooded with traffic. This can slow down the victim's computer to the point where it becomes impossible to work on.

This is true and is the description of the Smurf attack provided in the lesson.

12
New cards

Which of the following was described in the lesson as "the world's foremost and widely-used network protocol analyzer? It lets you see what's happening on your network at a microscopic level and is the de facto standard across many commercial and non-profit enterprises, government agencies, and educational institutions

Wireshark

13
New cards

Computer Network Attack (CA) entails the scanning and exploiting of computer systems and networks. Conducting this type of activity on systems you don't own or have the permission to assess is illegal.

This was the definition of Computer Network Attack that was provided in the lesson.

14
New cards

Which of the following tools has been described as the world's most used penetration testing framework?

Metasploit

15
New cards

In the model of Defense-in-depth that the lesson concentrated on, what is the outermost layer of security?

Polices, procedures, and awareness

16
New cards

Defense-in-depth is not a product, like a firewall. Instead, it is a security architecture that calls for the network to be aware and self-protective.

True

17
New cards

Which of the following was offered in the lesson as a reason why defense-in-depth strategies can fail?

A, B, and C but not D. Changes in technology, flaws in design, abuse by trusted insiders

18
New cards

To implement a security program successfully, an organization must define processes and activities for staff and systems. These policies and procedures define security controls and usage of the controls. An awareness program enhances staff understanding of the security controls. The policies and procedures define and describe all the controls at the other layers

True

19
New cards

Which of the following is a "data-vacuuming" malware that targeted a number of Middle Eastern countries including Israel and Iran?

Flame

20
New cards

What was the name given to a series of coordinated attacks on American computer systems in 2005 but which had been ongoing for at least 3 years?

The attacks were labeled as Chinese in origin, although their precise nature, e.g. state-sponsored espionage, corporate espionage, or random hacker attacks, and their real identities remain unknown.

Titan Rain

21
New cards

Stuxnet specifically targeted PLCs which allow the automation of electromechanical processes such as those used to control machinery on factory assembly lines. In this case, it targeted the PLCs used by centrifuges for separating nuclear material.

True

22
New cards

How does a Fragmentation attack work?

A and C are descriptions of fragmentation attacks but not B.

UDP and IMP fragmentation attacks send fraudulent packets that are larger than the network's MTU

TCP fragmentation attack sends packets with overlapping fragmentations which the recipient cannot process.

23
New cards

How does the famous SYN attack that utilizes the three-way handshake work? In other words. what does the attack do in order to conduct the denial of service attack?

A SYN packet is sent to the target with a bogus "from" address. The target sends a response and waits for the final ACK but never receives it.

It continues to wait and if enough other similar packets are sent the target gets "tied up" waiting for responses and no more connection requests can be accepted.

24
New cards

The source and destination IP addresses are contained in the header of which of the following protocols?

IP

25
New cards

Which DARPA and OSI layer would you find the TCP and UDP protocols? In other words, the TCP and UDP protocols would be found in what equivalent layers of the OS and DARPA layers?

Transport Layer

26
New cards

What was the name of the tool mentioned in the lesson that performs a DoS attack on a target site by flooding the server with TCP or UDP packets with the intention of disrupting the service of a particular host?

Low Orbit Ion Cannon (LOIC)

27
New cards

of data on a disk is an example of a defense mechanism used in which of the following layers of a defense-in-depth strategy?

Data Defenses

28
New cards

Code Red was a worm with multiple variants that first appeared in July 2001 and ultimately affected nearly 300,000 computers in the U.S. It exploited a hole in Microsoft's IIS Web Servers.

True

29
New cards

What was the name of the "hacking" group from China that emerged after the May 1999 bombing of the Chinese embassy in Belgrade? It's members combined hacking skills with patriotism and nationalism and launched a series of attacks on websites in the U.S

Honker Union

30
New cards

Initially a group calling itself the "Guardians of Peace" (GOP) took credit for the attack on Sony Pictures. Eventually, however, after further investigation it was irrefutably shown that the attack actually was initiated by North Korea.

False

31
New cards

In the TEDx Talk on Cyberwar, the speaker listed 5 differences between cyber threats and conventional threats. One of these was Warning and Decision. What was the issue here?

We get no warning time for a cyber attack and because of the attribution issue a response is often not possible for a possibly considerable period of time.

32
New cards

In which risk response strategy is a portion of the risk responsibility or liability to the organization shifted to another organization?

Risk sharing

33
New cards

In which component of the risk management process are threats to the organization identified?

Assess

34
New cards

Risk management is the process of identifying, examining, measuring, mitigating, or transferring risk. Its main goal is to reduce the probability or impact of an identified risk.

True

35
New cards

Organizational viewpoint refers to the values, beliefs, and norms that influence the behaviors and actions of the senior leader/executives and individual members of an organization.

False

36
New cards

Identification of risk assumptions, risk constraints, Risk tolerance and priorities and trade-offs is part of which component of the risk management process?

Risk framing

37
New cards

The process of estimating the degree of overall harm or loss that could occur as a result of the exploitation of a security vulnerability is known as which of the following?

Impact Assessment or Impact Analysis

38
New cards

A likelihood assessment estimates the probability of a threat conducting some specific activity.

True

39
New cards

What was the term that the lesson used to describe the measure of how much data loss, in hours or days, is acceptable to an organization.

RPO (recovery point objective)

40
New cards

A qualitative assessment typically employs a set of methods, principles, or rules for assessing risk based on the use of numbers.

False

41
New cards

Which approach for calculating risk utilizes a set method, principle or set of rules for assessing risk that uses bins, scales, or represented numbers whose values and meanings are not maintained in other contexts?

Semi-Quantitative Assessment

42
New cards

As described in the lesson, the Risk Management Framework consists of 6 steps. In which step is an initial set of baseline security controls for the information system based on an organizational assessment of risk and local conditions?

Select

43
New cards

In which step of the Risk Management Framework (RMF) do you find the task to implement an informational system disposal strategy, when needed, which executes required actions when a system is removed from service?

Monitor

44
New cards

In which step of the Risk Management Framework (RMF) do you find the task to determine if the risk to organizational operations, organizational assets, individuals, other organizations, or the nation is acceptable?

Authorize

45
New cards

During which step of the Risk Management Framework (RMF) would you find the task to develop a strategy for the continuous monitoring of security control effectiveness and any proposed/actual changes to the information system and its environment of operation?

Select

46
New cards

During which step of the Risk Management Framework (RMF) would you find the task to conduct initial remediation actions on security controls based on the findings and recommendations of the security assessment report and reassess remediated controls), as appropriate?

Assess

47
New cards

The lesson defined the lifecycle of risk management as having three parts which were further defined and discussed. These three parts (not in any particular order) were Risk Mitigation/Response, Risk Analysis; and which of the following?

Risk Assessment

48
New cards

Qualitative and/or Quantitative risk calculations are part of which step of the risk management lifecycle?

Risk Analysis

49
New cards

A Business Impact Analysis (BIA) is the process of developing and distributing a questionnaire to determine the financial impact and operational impact on an organization if its business offices and/or data center facilities are not available for an extended time

True

50
New cards

As discussed in the lesson, which step of the Risk Management Framework (RMF) is the information system assets and individuals allowed to operate based on a determination of the risk to organizational operations and the decision that this risk is acceptable?

Authorize

51
New cards

The authorization package consists of three documents. They are the Security Plan, the Security Assessment Report, and which of the following?

Plan of Action and Milestones

52
New cards

The Risk Management Process consists of 4 components as defined in the lesson. These are Assess, Respond, Monitor, and which of the following?

Frame

53
New cards

Trust is a belief that an entity will behave in a predictable manner in specified circumstances. The entity may be a person, process, object, or any combination of such components.

True

54
New cards

In which component of the risk management process presented in the lesson do you verify that planned risk response measures are implemented and information security requirements derived from/traceable to organizational missions/business functions, federal legislation, directives, regulations, policies, and standards and guidelines are satisfied?

Monitor

55
New cards

Business Continuity Planning (BCP and Disaster Recovery (DR) are terms that are often used synonymously and actually do refer to the same plans. The difference is simply a preference by the individual discussing the topic.

False

56
New cards

The process of understanding the existing system and environment, and identifying risks through analysis of the information/data collected is known as which of the following?

Risk Assessment

57
New cards

Risk Management Framework (RMF) provides a disciplined and structured process that integrates information security and risk management activities into the system development life cycle. It operates primarily at Tier 3 of the 3-tiered approach presented in the lesson.

True

58
New cards

The risk management 3-tiered approach consisted of three levels. Which of the following were the three levels described in the lesson?

Organization,

Mission/Business Processes, Information Systems

59
New cards

When is Risk Avoidance the appropriate risk response?

When the identified risk exceeds the organizational risk tolerance.

60
New cards

The security authorization package documents the results of the security control assessment and provides the authorizing official with essential information needed to make a risk-based decision on whether to authorize operation of an information system.

True

61
New cards

In which step of the Risk Management Framework (RMF) would you find the task of registering the information system with appropriate organizational program/management offices?

Categorize

62
New cards

The Ghost Security Group attacks ISIS online by attempting to shut down accounts or by attacking known jihadi websites rough denial of service (DoS) attacks.

False

63
New cards

What is the name of the group of "hackers" that felt that in the Anonymous-declared war on ISIS, Anonymous was using unsophisticated tactics? The group stated that Anonymous didn't have any counterterrorism experience and they felt that not enough was being done. They thus formed this separate group to take on ISIS

Ghost Security Group

64
New cards

Which of the following were discussed in the lesson as "valid" cyberattacks from a government perspective?

A, B, C, and D, but not E

65
New cards

General Keith Alexander, commander of the U.S. Cyber Command in 2014, pointed out several issues with cyberwar today. Which of the following was an issue he pointed out?

All of the above

66
New cards

Which of the following is the best term used to describe actions and intelligence collection via computer networks that take advantage of data gathered from target or enemy information systems or networks?

Computer Network Exploration (CNE)

67
New cards

What is the term used to describe a computer "hacker" or computer security expert who may sometimes violate laws or typical ethical standards but does not have any malicious intent?

Grey hat hacker

68
New cards

Not in any specific order, the 5 phases of a penetration test are Scanning, Gaining Access, Reconnaissance, Covering Tracks, and which of the following?

Maintaining Access

69
New cards

According to the lesson, the term kill chain was originally used as a military concept related to the structure of an attack. The original cyber kill chain reveals the stages of a cyberattack from early reconnaissance to the goal of data exfiltration.

True

70
New cards

Which of the following is the " of the original "CIA of security"?

Integrity

71
New cards

According to Lara Ballard, special advisor on privacy and technology to the State Department. which of the following is the most valuable type of defense?

Human Intelligence

72
New cards

While there has been much discussion about the vulnerability of industrial control systems in the nation's critical infrastructures, there has actually only been less than a dozen known attacks. This still shows the possibility of attacking our infrastructures and is why DHS has stressed industrial control system security is an increasingly important part of national defense.

False

73
New cards

According to the TED talk on cyberwar, why is the most powerful cyber state also most likely the most vulnerable?

The nation that is the most powerful from a cyber perspective will also have a large reliance on cyber themselves and will therefore also be vulnerable to cyber attacks.

74
New cards

In 2008 malware known as Agent. btz was used in an attack on the Department of Defense. It spread extensively throughout DoD networks. The infection began when an infected USB flash drive was inserted into a U.S. military laptop at a base in the Middle East. As a result the DoD suspended the use of USB drives (i.e. does not allow them) or other external media by service members.

True

75
New cards

Which of the following is the name of the malware identified by DHS deep within the industrial control systems that operate critical infrastructures? It appears to originally only be targeting the theft of information but officials fear it could be modified for sabotage purposes.

Black Energy

76
New cards

As discussed in an article in the lesson, the Internet has become a catalyst for radicalization, in reference to the recruiting of terrorists. Processes that previously might have taken a few months or even a year - to do from following a benign ideology to traveling abroad to become a foreign fighter - in some cases take only a few weeks.

True

77
New cards

Which of the following was mentioned in the lesson as an example of a cyber attack which occurred during a time of revolution or conflict?

All of the above

78
New cards

According to the TED talk from the lesson, in the face of possible cyber warfare and cyberattacks, the government has to "step up its game" and become responsible for not just attacks on the federal government and critical infrastructures, it needs to become engaged in the defense of major industry organizations such as Sony.

False