1/99
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What is the primary tool used by modern attackers for various attacks?
The network
What are the three components of the CIA triad that network attacks may target?
Confidentiality, Integrity, Availability
What type of attack seeks to access sensitive data?
Confidentiality-violating attacks
What type of attack aims to alter information?
Integrity-targeting attacks
What is the goal of availability-targeting attacks?
To impair others' use of the network
How can network attacks be categorized?
By the part of the CIA triad they target, the layer of the network, or the specific protocols targeted.
What is adversary reconnaissance?
The process of gathering information about a target network, often starting with passive OSINT gathering.
What is a common tool used for active network scanning?
Port scanners
What does a TCP packet with all flags set, known as a Christmas tree packet, indicate?
It is used to gather information about a remote host's open ports.
What is fuzzing in the context of network attacks?
Inserting random or invalid data into header fields or application data inputs to learn how a service responds.
What is banner grabbing?
Sending a routine packet to a network service and analyzing the response for information about software and protocol versions.
Why are network scans considered active attacks?
They can reveal potential vulnerabilities and may be visible to network administrators.
What is address spoofing?
A technique where an attacker falsifies source information to facilitate an attack.
How can spoofing be used in network attacks?
By impersonating a known host or interface to bypass security controls.
What is MAC cloning?
A method that allows an attacker to bypass MAC address filtering by impersonating a permitted MAC address.
What is the drawback of spoofing a source IP address?
The attacker might not receive replies addressed to the forged IP.
What is the purpose of configuring firewalls and IDS/IPS in relation to network scans?
To limit the information an unauthorized scan reveals about the network.
What is the significance of the TCP 3-way handshake in network scanning?
It can be used to determine if a port is open and what services are running.
What type of attacks can target the physical hardware of a network?
Attacks that target the physical layer of the network.
What is the role of network protocols in security?
Some protocols are insecure by nature and can be vulnerable to attacks.
What is a common method to detect network scans?
Monitoring for unusual patterns of traffic that indicate scanning activity.
What is the relationship between network scans and more serious network attacks?
Network scans often precede more serious attacks, making their detection crucial.
What are some examples of social engineering tactics related to spoofing?
Spoofing email sender addresses or caller IDs in VoIP calls.
What is the potential impact of a successful fuzzing attack?
It can crash applications and hosts or gain access permissions.
What is the importance of understanding the vulnerabilities of network services?
Every network service has individual vulnerabilities that can be exploited.
What is the primary goal of many network attacks?
To exploit vulnerabilities in order to gain unauthorized access or disrupt services.
What does it mean for a protocol to be insecure by nature?
It has inherent weaknesses that make it vulnerable to attacks.
What is spoofing in network attacks?
Spoofing is a technique used to enable other attacks or make them more effective, often hiding the true source of an attack.
What is ARP poisoning?
ARP poisoning involves using spoofed ARP messages to alter the ARP cache of a target, allowing an attacker to eavesdrop or modify data.

What are the limitations of ARP poisoning?
ARP poisoning is limited to local network segments and has no inherent security measures.
What is DNS poisoning?
DNS poisoning redirects traffic by corrupting the DNS cache in a host or by compromising a DNS server.
How does DNS poisoning differ from ARP poisoning?
DNS poisoning can work beyond the Layer 2 segment, while ARP poisoning is limited to local networks.
What is pharming?
Pharming is a form of DNS poisoning that compromises DNS lookups or modifies the hosts file to redirect users to malicious sites.
What are rogue services in network attacks?
Rogue services imitate legitimate services, such as phishing sites or evil twin access points, to redirect traffic.
What is URL redirection?
URL redirection occurs when a website redirects users to a different URL, often used in phishing attacks.
What is domain hijacking?
Domain hijacking involves re-registering an expired domain or compromising the account controlling it to redirect traffic.
What is VLAN hopping?
VLAN hopping is when an attacker compromises VLAN control protocols to divert traffic to the wrong VLAN.
What are countermeasures against ARP poisoning?
Countermeasures include using switch security features to protect against ARP poisoning and VLAN hopping.
What is a denial-of-service (DoS) attack?
A DoS attack aims to deny network services to legitimate users, causing slowdowns or crashes.
What is the simplest method to achieve a DoS attack?
The simplest method is volumetric DoS, which floods the target with enough data or requests to exhaust resources.
What is a ping flood?
A ping flood is a type of DoS attack that sends excessive ICMP ping requests to consume a host's bandwidth.
What is a distributed denial-of-service (DDoS) attack?
A DDoS attack uses multiple attacking systems to generate overwhelming traffic, making it harder to block.

What is a reflected DDoS attack?
A reflected DDoS attack uses IP spoofing to generate traffic from unrelated hosts, overwhelming the target.
What was the smurf attack?
The smurf attack involved pinging multiple systems with the target's IP address forged as the source, flooding the victim.
What are amplification techniques in DDoS attacks?
Amplification techniques produce more traffic or cause a fixed amount of traffic to consume more target resources.
What are common targets for reflected DDoS attacks?
Common targets include critical services like DNS or NTP, which can amplify the attack's impact.
What is the impact of DoS attacks on network performance?
DoS attacks can cause temporary slowdowns, crashes, or even hardware damage, disrupting regular functions.
What is the goal of a DoS attack?
The goal can be to inconvenience users, extort system owners, or destabilize a system for further exploits.
What is the difference between DoS and DDoS attacks?
DoS attacks come from a single source, while DDoS attacks involve multiple sources generating traffic.
What are the consequences of a successful DoS attack?
Consequences can include service denial, performance degradation, and potential hardware failure.
How can network administrators counteract DoS attacks?
Network administrators can block traffic from offending sites and configure servers to mitigate flood attacks.
What is the role of botnets in DDoS attacks?
Botnets are often used to conduct DDoS attacks, allowing attackers to leverage multiple compromised systems.
What is a DoS attack?
A Denial of Service attack aims to disrupt the normal functioning of a targeted server, service, or network by overwhelming it with traffic.
What is the purpose of sending oversized packets in a DoS attack?
Oversized packets can confuse a host and cause undesired behavior, potentially crashing the receiving application or allowing remote code execution.
What is a SYN flood attack?
A SYN flood attack abuses the TCP connection by sending a constant stream of SYN packets to open connections without responding to acknowledgments, leading to resource exhaustion.
How can malformed packets affect a system?
Malformed packets containing garbage data can cause a vulnerable application to crash or behave unpredictably, wasting application resources.
What is the impact of DoS attacks on operational technology (OT) devices?
DoS attacks on OT devices aim to disrupt physical operations, potentially causing permanent damage to machinery and facilities.
What was the purpose of the Stuxnet worm?
The Stuxnet worm was designed to infect centrifuges used in the Iranian nuclear program, altering their speeds to cause hardware failure.
What are some local means of conducting a DoS attack?
Local means include sabotaging power or network connections, corrupting software, or destroying hardware.
What is an example of a friendly DoS attack?
A friendly DoS attack occurs when a system is overwhelmed by unexpected levels of legitimate traffic due to a new product or news story.
What is packet sniffing?
Packet sniffing is the act of capturing and analyzing network traffic, often done by attackers to intercept sensitive information.
What is an on-path attack?
An on-path attack, also known as a man-in-the-middle (MITM) attack, occurs when an attacker intercepts and relays traffic between two hosts, impersonating each host to the other.
How can ARP cache poisoning be used in an on-path attack?
ARP cache poisoning involves sending spoofed ARP packets to convince a victim's NIC that the attacker's MAC address is that of a legitimate host, allowing interception of traffic.
What types of protocols are vulnerable to eavesdropping?
Protocols like HTTP, FTP, Telnet, POP, IMAP, SLIP, and SNMPv1 and v2 send sensitive data as unprotected plaintext, making them highly vulnerable to eavesdropping.
What is the role of a NIC in promiscuous mode?
A NIC in promiscuous mode can capture all packets on the network segment, even those not addressed to it, facilitating packet sniffing.
What is the goal of interception in network security?
The goal of interception is to capture sensitive information being transmitted over the network, such as login credentials, without the user's knowledge.
What is the significance of using encrypted protocols?
Encrypted protocols provide better security by protecting data from being easily intercepted and read by attackers.
What happens during a SYN flood attack?
During a SYN flood attack, a target server receives a large number of SYN packets, leading to a backlog of half-open connections that prevent legitimate users from connecting.
What is the purpose of the hping3 utility in a DoS attack exercise?
The hping3 utility is used for crafting and sending arbitrary network packets, including those used in DoS flood attacks.
What is the expected outcome of launching a SYN flood attack?
The expected outcome is a spike in network traffic and alerts in the intrusion detection system (IDS) due to the high volume of SYN packets.
What can be a consequence of a successful DoS attack on OT devices?
A successful DoS attack on OT devices can disrupt critical physical operations and potentially cause significant damage.
What is the role of Task Manager in monitoring a DoS attack?
Task Manager can be used to view network traffic levels and monitor the impact of a DoS attack on system performance.

What is the effect of signal jamming on wireless networks?
Signal jamming disrupts wireless communications, effectively serving as a DoS attack by preventing legitimate users from accessing the network.
What is the significance of monitoring tools like barnyard2.exe during a DoS attack?
Monitoring tools like barnyard2.exe help analyze and report on network traffic and alerts generated by intrusion detection systems during a DoS attack.
What are some common methods for intercepting network traffic?
Common methods include physically tapping into cables, using wireless sniffers, and exploiting network vulnerabilities to gain access.
How does network segmentation help against packet sniffing?
Network segmentation makes it more difficult for attackers to capture traffic by isolating different segments of the network.
How does Mallory facilitate an on-path attack?
Mallory relays messages between Alice and Bob, making it appear as if they are communicating directly.
What is a replay attack?
An attack where the attacker intercepts data transmissions and resends them to disrupt communications or gain unauthorized access.
How can replay attacks be mitigated?
By using timestamps and number sequences that are not updated in replayed communications.
What is session replay/hijacking?
An application-level replay attack targeting session-based protocols, allowing an attacker to take over an existing session.
What distinguishes session hijacking from session replay?
Session hijacking occurs immediately after the client logs in, while session replay can happen later.
What is a downgrade attack?
An attack that tricks clients into using weaker encryption methods by interfering with the initial connection setup.
What is SSL stripping?
An on-path attack that bypasses secure connections by relaying messages between a client and server using plaintext.
What is a browser-based on-path attack?
An attack where malware modifies the user's web experience, potentially bypassing strong network encryption.
What is the main advantage of on-path attacks over passive eavesdropping?
On-path attacks can intercept and modify encrypted conversations by negotiating separate encryption with each host.
What can an attacker do during an on-path attack on a banking transaction?
The attacker can change transaction amounts and destinations, and send false confirmation information back to the user.
What is the purpose of using a packet sniffer like Wireshark?
To capture and analyze network traffic, which can include sensitive information like passwords.

What is FTP and why is it insecure?
FTP is a plaintext protocol that transmits data, including usernames and passwords, without encryption.

How can an attacker replicate the method of capturing credentials?
By gaining access to the communication path, such as through a SPAN port or traffic redirection.
What are some ways to reduce the risk of credential theft?
Using secure protocols like FTPS or SFTP, blocking insecure protocols with ACLs, and implementing network segmentation.
What is the CIA triad in cybersecurity?
Confidentiality, Integrity, and Availability; a framework for understanding security goals.
Why is gaining access to a sensitive system valuable for an attacker?
It allows the attacker to compromise the CIA triad and pivot to attack the entire network.
What is a common method for attackers to bypass access controls?
Targeting systems that lack authentication or have users logged in without a password.
What is the significance of stealing passwords in cyber attacks?
Stealing passwords is a common goal for hackers and social engineers to gain unauthorized access.
What can be done to protect against unauthorized access on a network?
Implementing strong authentication measures and securing network services that do not require authentication.
What is one common goal of hackers and social engineers?
Stealing passwords.
What is credential harvesting?
The process of stealing credentials, including passwords and private keys.
How can physical intruders obtain passwords?
By looking for sticky notes or monitoring unencrypted network traffic.
What is a card cloner?
A device that reads ID cards and produces a working facsimile.
What do skimmers do?
They capture card information and PINs from ATMs.