CISE 119 Quizes

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/34

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 4:08 PM on 9/23/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

35 Terms

1
New cards

Which term refers to a potential source of harm that could exploit a weakness?

Threat

2
New cards

A vulnerability is best described as:

 

A weakness that can exist even if no attack occurs

3
New cards

Which of the following best describes an attack?

 

An action that exploits a vulnerability

4
New cards

Why are insiders considered a significant cybersecurity threat?

 

They already have authorized access to systems

5
New cards

Which motivation is most commonly associated with cybercriminals?

 

Financial gain

6
New cards

An opportunistic attack is best described as an attack that:

 

Looks for easy targets without caring who is affected

7
New cards

Why are small organizations frequently targeted by cyber attacks?

 

They often have fewer resources and security controls

8
New cards

Which type of attack is most likely to focus on remaining undetected for long periods of time?

 

Targeted attack

9
New cards

Which phase of an attack involves gathering information about a target?

 

Reconnaissance

10
New cards

What is the primary goal of data exfiltration?

 

Quietly remove valuable data

11
New cards

Why are integrity attacks often difficult to detect?

 

Data may appear normal while being altered

12
New cards

Which factor most strongly influences how a threat actor behaves?

 

The attacker’s motivation

13
New cards

Which of the following is an example of a misconfiguration vulnerability?

 

A system using default passwords

14
New cards

Why do many cyber attacks go unnoticed for extended periods of time?

 

Early attack stages cause little visible disruption

15
New cards

Which statement best explains why eliminating all vulnerabilities is unrealistic?

 

Systems and environments are complex and constantly evolving

16
New cards

An employee with authorized system access intentionally steals confidential company information. Which threat actor classification best applies?

Insider

17
New cards

An attacker researches a specific employee and then sends that employee a customized phishing email. What type of attack is this?

 

Spear phishing

18
New cards

Which phishing technique specifically targets senior executives or other high profile individuals?

 

Whaling

19
New cards

During a targeted attack, malware that has entered the network begins receiving instructions from the attacker. Which phase is occurring?

 

Command and control communication

20
New cards

Which activity best describes data exfiltration?

 

Transferring stolen data to an area controlled by the attacker

21
New cards

An attacker wants to determine which computers or devices are currently active and connected to a network. Which technique would be used?

 

Ping sweep

22
New cards

What is a botnet?

 

A group of compromised zombie computers controlled through a central infrastructure

23
New cards

What distinguishes a fileless virus?

 

It uses legitimate programs to infect a computer and may operate in memory

24
New cards

Which malware provides a back door that allows an attacker to obtain administrative control over a target computer?

 

Remote Access Trojan (RAT)

25
New cards

What is a primary characteristic of an opportunistic attack?

 

The attacker generally seeks quick financial gain with minimal effort

26
New cards

An attacker creates a believable fictitious scenario to convince a victim to reveal information. Which technique is being used?

Pretexting

27
New cards

Employees begin using an unauthorized cloud storage application to share company documents because they find it easier than the organization's approved system. What does this represent?

 

Shadow IT

28
New cards

Which of the following is identified as part of the lecture's general defense strategy?

 

Layered defenses

29
New cards

Which malware is installed without the user's consent or knowledge and is designed to intercept information or take partial control of the computer?

 

Spyware

30
New cards

An attacker wants to determine which TCP or UDP services may be available on a server. Which technique would be most appropriate?

 

Port scan

31
New cards

Which type of malware is designed to provide hidden, administrator level access to a computer?

 

Rootkit

32
New cards

Which type of malware disguises itself as legitimate or desirable software?

 

Trojan horse

33
New cards

An attacker compromises a network and attempts to remain undetected for an extended period. What type of threat does this represent?

 

Persistent threat

34
New cards

A social engineer has a conversation with an employee and subtly encourages the employee to disclose information without making the employee suspicious. Which technique best describes this?

Elicitation

35
New cards

Which security principle limits users to only the access and permissions required to perform their responsibilities?

 

Least privilege