1/34
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Which term refers to a potential source of harm that could exploit a weakness?
Threat
A vulnerability is best described as:
A weakness that can exist even if no attack occurs
Which of the following best describes an attack?
An action that exploits a vulnerability
Why are insiders considered a significant cybersecurity threat?
They already have authorized access to systems
Which motivation is most commonly associated with cybercriminals?
Financial gain
An opportunistic attack is best described as an attack that:
Looks for easy targets without caring who is affected
Why are small organizations frequently targeted by cyber attacks?
They often have fewer resources and security controls
Which type of attack is most likely to focus on remaining undetected for long periods of time?
Targeted attack
Which phase of an attack involves gathering information about a target?
Reconnaissance
What is the primary goal of data exfiltration?
Quietly remove valuable data
Why are integrity attacks often difficult to detect?
Data may appear normal while being altered
Which factor most strongly influences how a threat actor behaves?
The attacker’s motivation
Which of the following is an example of a misconfiguration vulnerability?
A system using default passwords
Why do many cyber attacks go unnoticed for extended periods of time?
Early attack stages cause little visible disruption
Which statement best explains why eliminating all vulnerabilities is unrealistic?
Systems and environments are complex and constantly evolving
An employee with authorized system access intentionally steals confidential company information. Which threat actor classification best applies?
Insider
An attacker researches a specific employee and then sends that employee a customized phishing email. What type of attack is this?
Spear phishing
Which phishing technique specifically targets senior executives or other high profile individuals?
Whaling
During a targeted attack, malware that has entered the network begins receiving instructions from the attacker. Which phase is occurring?
Command and control communication
Which activity best describes data exfiltration?
Transferring stolen data to an area controlled by the attacker
An attacker wants to determine which computers or devices are currently active and connected to a network. Which technique would be used?
Ping sweep
What is a botnet?
A group of compromised zombie computers controlled through a central infrastructure
What distinguishes a fileless virus?
It uses legitimate programs to infect a computer and may operate in memory
Which malware provides a back door that allows an attacker to obtain administrative control over a target computer?
Remote Access Trojan (RAT)
What is a primary characteristic of an opportunistic attack?
The attacker generally seeks quick financial gain with minimal effort
An attacker creates a believable fictitious scenario to convince a victim to reveal information. Which technique is being used?
Pretexting
Employees begin using an unauthorized cloud storage application to share company documents because they find it easier than the organization's approved system. What does this represent?
Shadow IT
Which of the following is identified as part of the lecture's general defense strategy?
Layered defenses
Which malware is installed without the user's consent or knowledge and is designed to intercept information or take partial control of the computer?
Spyware
An attacker wants to determine which TCP or UDP services may be available on a server. Which technique would be most appropriate?
Port scan
Which type of malware is designed to provide hidden, administrator level access to a computer?
Rootkit
Which type of malware disguises itself as legitimate or desirable software?
Trojan horse
An attacker compromises a network and attempts to remain undetected for an extended period. What type of threat does this represent?
Persistent threat
A social engineer has a conversation with an employee and subtly encourages the employee to disclose information without making the employee suspicious. Which technique best describes this?
Elicitation
Which security principle limits users to only the access and permissions required to perform their responsibilities?
Least privilege