Module 01 - Part 2: Review: Module 02 Pervasive Attack Surfaces and Controls

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/29

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 1:18 AM on 9/2/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

30 Terms

1
New cards

An individual who was recently fired goes to their former place of employment on a weekend. Since they are unable to enter, security goes to the front door to inquire. The fired employee says they forgot their access card and just needs to pick up their tablet in their office. What attack surface is the former employee trying to exploit?

Human vector

Why: Because social engineering occurs through the exploitation of a person, it is sometimes said to be accomplished using human vectors as the attack surface.

2
New cards

The CEO of a small retail chain is visiting a client. They call the help desk in a panic and request a password reset because it expired. The technician says they are not allowed to manually reset passwords but to kindly use the online password reset system. The CEO gets irate, says "You're fired," and hangs up. Which of the following best characterizes what happened, or what should have happened?

The technician did the right thing.

Why: Since the question says the CEO called and not someone pretending to be the CEO, this is not necessarily social engineering. If the caller had falsely claimed to be the CEO, then it could be characterized as social engineering. The technician did the right thing by not succumbing to pressure that would violate one of the company's security policies.

3
New cards

Chafik works at Company A. He apparently receives an email from Jon Dough of the purchasing department. The email includes a link along with a request to fill out a survey because they want to improve the procurement process. The from field in the email reads as follows:From: Jon Dough

This is an example of a potential phishing attack.

The recipient is potentially more likely to click on the link because a reason was supplied.

Why: One of the most common forms of social engineering is phishing. Phishing is sending an email or displaying a web announcement that falsely claims to be from a legitimate source in an attempt to trick the user into taking an action. Chafik works at Company A, but the email is coming from Company B, so this should raise suspicion. Many social engineering threat actors are careful to add a reason along with their request. By giving a rationalization and using the word because, it is much more likely the target will take action.

4
New cards

Company A sends a fictitious overdue invoice that appears legitimate via email to Company B, a large corporation. Company A hopes that Company B will comply and make the payment without investigating. What type of attack is this? Select two.

BEC

Phishing

Why: A business email compromise (BEC) takes advantage of the common practice today by businesses and organizations of electronically making payments or transferring funds. Attackers take advantage of the size and complexity of large enterprises to request funds from what appears to be a legitimate source, knowing that the target will often comply without investigating if the request is legitimate. Sending a fake invoice is an example of a BEC attack.

5
New cards

You receive a call from someone pretending to be a government agent. They claim there is an issue with your taxes and you need to provide certain information to clear up the problem. However, the caller's true goal is to obtain private information. Which of the following best describes this behavior?

Pretexting

Why: Social engineering impersonation is masquerading as a real or fictitious character and then playing out the role of that person on a target. Sometimes the goal of the impersonation is to obtain private information, called pretexting.

6
New cards

Which of the following most accurately describes the differences or similarities between typo squatting and cybersquatting? Select two.

Cybersquatting is registering a domain that contains trademarks and then selling it.

A domain name with a one-letter change relative to an authentic site is an example of typo squatting.

Why: Fake sites may pretend to be legitimate sites or just be filled with ads for which the attacker receives money for traffic generated to the site. They exist because attackers purchase and register the domain names of sites that are spelled similarly to actual sites. This is called typo squatting. Cybersquatting involves registering an Internet domain name that contains trademarks for the sole purpose of selling that domain name to the trademark owner.

7
New cards

Gemalyn enters websiteA.com in the address bar of a browser but is redirected to websiteB.com due to an infected DNS. What type of exploit did Gemalyn experience?

A redirection technique called pharming.

Pharming is a redirection technique that attempts to exploit how a URL is converted to its corresponding Internet protocol address. A threat actor may install malware on a user's computer that performs the redirection when the user enters the URL in a web browser. A variation is to infect a DNS that would then direct large numbers of users to the fake site.

8
New cards

Which of the following most accurately describes the differences or similarities between misinformation and disinformation? Select two.

Disinformation is a type of misinformation.

A false warning is an example of disinformation.

Why: Misinformation is false or inaccurate information, regardless of the intent to mislead; it does not consider the intent. Disinformation is false or inaccurate misinformation that comes from a malicious intent. One example of cyber disinformation is a hoax or a false warning.

9
New cards

A series of individuals (engineers and executives) from a large electronics firm are members of a professional organization. They visit the website of the organization, often to contribute papers, do research, and sign up for a variety of conferences. An attacker attempts to target the individuals by infecting the website. What type of attack is this?

Watering hole attack

Why: A watering hole attack is directed toward a smaller group of specific individuals. These individuals all tend to visit a common website. An attacker who wants to target this group of individuals will attempt to determine the common website they frequent and then infect it with malware that will make its way onto the group's computers.

10
New cards

A threat actor does research, including Google searches, and discovers the cleaning establishment used by the company they want to target. The threat actor gets a job with the cleaning establishment for the sole purpose of obtaining any information that will help in their malicious efforts. What type of attack is the threat actor most likely to engage in?

Dumpster diving

Why: Dumpster diving involves digging through trash receptacles to find information that can be useful in an attack. Items that may have valuable information include calendars, memos, organizational charts, phone directories, and policy manuals.

11
New cards

Which of the following most accurately describes the similarities and/or differences between spear phishing and whaling? Select two.

Whaling targets wealthy individuals and senior executives in a business.

Spear phishing uses customized information to target specific users.

Why: Whaling is a type of spear phishing. It targets the wealthy individuals or senior executives within a business who typically would have larger sums of money in a bank account that an attacker could access. Whereas phishing usually sends generic email messages to millions of users, spear phishing targets specific users. The emails used in spear phishing are customized to the recipient.

12
New cards

Lamarr receives a text message indicating the password to his bank account has been changed but needs verification to commit the change. It includes a number to call and a link, both of which will lead to fraud if Lamarr follows through with the instructions. This is an example of what type of attack?

Smishing

Why: Another avenue for spreading social engineering attacks uses the short message service (SMS) to send fraudulent text messages. This is known as smishing and can be combined with callback recorded phone messages.

13
New cards

Which of the following can be included under the physical security controls umbrella? Select three.

Data leakage

Gel-based paint

Perimeter defenses

Why: Physical security controls include data leakage; countermeasures should be implemented as needed to prevent it. Gel-based paint is an anticlimb fencing-deterrent paint making any coated surface difficult to climb. Perimeter defenses are physical security controls used to restrict access.

14
New cards

A company uses a fence to deter physical access. An audit report concluded that since the fence can be easily scaled, additional measures should be implemented. What additional fencing-deterrent measure could the company implement to gain an added layer of protection? Select three.

Anticlimb collar

Roller barrier

Rotating spikes

Why: An anticlimb collar is a spiked collar that extends horizontally from the pole to prevent anyone from climbing it. Roller barriers are large, independently rotating cups affixed to the top of a fence that prevent the hands of intruders from gripping the top to climb over it. Rotating spikes are installed at the top of walls, gates, or fences with tri-wing spike collars that rotate around a central spindle.

15
New cards

One of the two security guards on duty at a company goes on a periodic patrol tour. The guard drives around the outside perimeter of the premises, which is under video surveillance. The guard also verifies there is no suspicious or abnormal activity in restricted areas. What type of security has this company adopted? Select two.

Two-person integrity

Active security defense

Why: In settings that require a higher level of protection, multiple security guards may be required. This prevents one security guard who has been compromised from participating in an attack. Using two security guards is called two-person integrity/control. Whereas barriers function as passive devices to restrict access, human security guards who patrol and monitor restricted areas are an active security defense.

16
New cards

Karlo installs an alarm system that is capable of emitting and detecting a signal in the light spectrum. The capability serves the purpose of detecting motion and how close an object is in a limited space. Which of the following best describes the type of signal the emitter can transmit?

Infrared

Why: Active infrared (IR) sensors both emit and detect IR radiation using a light-emitting diode (LED) and a receiver. When an object comes close to the sensor, the IR light from the LED reflects off the object and is detected by the receiver. Active IR sensors act as proximity sensors to determine how close an object is.

17
New cards

You are tasked with installing a system in a large warehouse that is capable of detecting levels of daylight to dim interior lights to conserve energy. In addition, if an intruder enters the warehouse an alarm should be triggered. The system you install will most likely support what type of signal/radio wave?

Microwave

Why: A microwave sensor uses high-frequency radio waves and functions similarly to radar. Microwave sensors are effective in monitoring large areas such as a warehouse to determine if an intruder has entered a restricted area. It can also sense levels of daylight and dim interior lights to save energy.

18
New cards

An intruder breaks into a large storehouse. An ultrasonic sensor triggers the alarm one-quarter of a second after detecting the intruder. About how far was the intruder when the alarm was sounded?

43 meters

Why: The measurement formula for an ultrasonic sensor at sea level is: Distance = 1/2 (Time) * 343 where Time is in seconds and 343 is the speed of sound in meters per second. When you plug in 1/4 of a second for Time, we get: Distance = 1/2 (1/4) * 343 = 1/8 * 343 = 42.875 Thus, the intruder was about 43 meters away.

19
New cards

Which one of the following technologies is most likely to be used in a system that is able to detect when a vehicle enters a restricted area and the direction in which it is headed?

Pressure sensors

Why: The controller in an underground pressure sensor converts the change in pressure to an electric signal that is then analyzed by a microprocessor. It can automatically detect and identify targets (pedestrian, car, truck, etc.). For vehicles, it can also determine the direction of travel.

20
New cards

What type of security buffer are you most likely to encounter at a high-security data center that enforces restricted access and requires a security clearance to gain entry.

Access control vestibule

Why: An automated access control vestibule is used to create a buffer to separate a nonsecure area from a secure area. A device monitors and controls two interlocking doors to a vestibule. When in operation, only one door can be opened at any time. Access control vestibules are used in high-security areas where only authorized individuals can enter.

21
New cards

Which of the following best describes what could be considered a security buffer? Select two.

Reception area of a company

Waiting room at a doctor's office

Why: In areas in which medium security is needed, a reception area can be used. Users are allowed to enter the area in which a receptionist can check credentials before allowing them to pass through the inner door to the next area. In areas of low security, a generic waiting room can be used instead. This type of setting is commonly seen in doctors' offices in which patients check in with a receptionist behind a window before a nurse or assistant opens the inner door at the time of the appointment.

22
New cards

Vika is asked to do research on the types of locks available to secure entry into a controlled access area. What type of lock should Vika recommend? Select two.

A lock that can be opened with a code sent from a cell phone via Bluetooth.

One capable of displaying a virtual keypad where the numbers are not fixed.

Why: Growing in popularity are smart locks, which use a smartphone that sends a code via wireless Bluetooth to open the door. One brand of electronic lock mitigates shoulder surfing or detection of fingerprint smudges by using a virtual screen. It substitutes physical buttons with a virtual keypad that displays numbers that are randomly assigned.

23
New cards

Which of the following statements best describes how a Faraday cage prevents data leakage?

It is used to prevent EMI from escaping the enclosure.

Why: Computer systems, printers, and similar digital electronic devices all emit electromagnetic fields. These can often result in interference called electromagnetic interference (EMI). Unauthorized persons could detect and read these electromagnetic signals. A Faraday cage can be used to protect against this type of eavesdropping. It is a metallic enclosure that prevents the entry or escape of an electromagnetic field.

24
New cards

A large complex is being constructed on a restricted site. They require a very high-speed, low maintenance (from a physical perspective) classified network. What type of PDS should they install?

Alarmed carrier PDS

Why: An alarmed carrier protected distribution system (PDS) is deployed with specialized optical fibers in a conduit that can sense acoustic vibrations that occur when an intruder attempts to gain access to the cables, which triggers an alarm. It provides continuous monitoring and eliminates the need for periodic visual inspections (low maintenance) as required in a hardened carrier PDS.

25
New cards

Which of the following lists the data type in order from the type that needs the highest level of protection to the lowest level?

Confidential, private, sensitive

Why: Confidential data has the highest level of sensitivity. Private data is restricted data with a medium level of confidentiality. Sensitive data should be restricted to employees who have a business need to access the data with prior approval.

26
New cards

Zaiden is asked to classify data elements based on certain criteria. Which of the following best describes what Zaiden should take into consideration? Select two.

Confidentiality

Integrity

Why: When considering which classification to use, a data element should be assigned, and the confidentiality of the data should be considered along with its integrity and availability.

27
New cards

A company designs an artifact. To secure protection against competitors who may attempt to copy it, the company applies for, and is granted, a patent. What type of data is being protected?

IP

Why: Intellectual property (IP) data is an invention or a work that is the result of creativity. The owner of IP can apply for protection from others who attempt to duplicate it. One of these protections over IP or its expression is a patent.

28
New cards

A large medical records archiving company adopts the slogan "Health Information Protected Against Attackers" to try to convey medical records are secure. If the organization suffers a significant data breach, who must they notify?

DHHS

Why: The Health Insurance Portability and Accountability Act (HIPAA) Breach Notification Rule requires that data breaches of 500 or more records must be reported to the Secretary of the Department of Health and Human Services (DHHS) no later than 60 days after its discovery.

29
New cards

Which of the following examples best describes the states in which data could reside? Select three.

Data sitting in RAM about to be transmitted

Data on a hard drive about to be accessed

Downloading an image from a website

Why: Data sitting in RAM about to be transmitted is an example of data in processing (it is neither at rest nor actively in transit). Data on a hard drive about to be accessed is an example of data at rest (it is about to be accessed but not yet accessed). Downloading an image from a website is an example of data in transit.

30
New cards

A company needs a lot of data to test an application. They want to make a copy of their production data and modify it in such a way that the original data cannot be recovered. Which of the following best describes the process the company should use to ensure the privacy of the original data? Select two.

Data masking

Data sanitation

Why: Data masking involves creating a copy of the original data but using obfuscation to make sensitive elements unintelligible. Data masking should replace all actual information that is not absolutely required. Proper data masking provides no means to reverse the process to restore the data back to its original state. Data masking is one means of performing data sanitization, which is the process of cleaning data to provide privacy protection.