CompTIA Security+ - Module 5 Quiz

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/9

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 4:30 AM on 10/2/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

10 Terms

1
New cards

A user sees a message in their browser that appears to be from the company whose OS is installed on their computer. It displays a number to call support to fix the problem. When the user calls, the threat actor requests permission to install software to scan the system but instead installs a threat agent for later access. What type of malware did the attacker most likely install?

a. Bloatware

b. Keylogger

c. Buffer overflow

d. RAT

RAT

A remote access Trojan (RAT) has the basic functionality of a Trojan but also gives the threat agent unauthorized remote access to the victim's computer. This creates an opening into the victim's computer, allowing the threat actor unrestricted access. In this scenario, the attacker may very well scan the computer and request money to fix the "problem," but leave an opening for unauthorized remote access.

2
New cards

A company's network is infected with ransomware. They are told data has been stolen. In addition, they are told to pay a ransom to decrypt the data on their servers, or the stolen data will be released to the public. Which of the following would be the best option for the company?

a. Decrypt the data themselves.

b. Pay the ransom.

c. There is no best option.

d. Restore data from their backups.

There is no best option.

This is a blended attack that puts the company in a bind, so there is no best option. If they restore the data, successfully decrypt the data themselves, or pay, the malicious actor will or may release the stolen data anyway. In addition, there is no guarantee there will be no data corruption once the data has been decrypted after paying the ransom.

3
New cards

A security company is testing an unpatched server running an older OS connected to the internet in an isolated network. However, the anti-malware software installed on the server was consistently not able to detect a particular type of infection. What type of infection was least likely to be detected by the anti-malware app?

a. Virus

b. Rootkit

c. Bot

d. Trojan

e. Worm

Rootkit

A rootkit is malware that can hide its presence and the presence of other malware on the device. It does this by accessing lower layers of the OS or even using undocumented functions to make alterations. This enables the rootkit and any accompanying software to become undetectable by the OS or anti-malware scanning software.

4
New cards

Which of the following statements best describes a TOCTTOU race condition?

a. When data is written to the wrong memory location.

b. When software is used to trap a memory error condition.

c. When the TOC expires before the corresponding data in memory is retrieved.

d. When one thread overwrites the data created by another thread.

When one thread overwrites the data created by another thread.

If two threads have access to the same location in memory, a second thread may overwrite the data stored in the memory location before the first thread is done. When the first thread retrieves the data, it will retrieve the value stored by the second thread. Even though the software checks the state of a resource before using that resource, the resource's state can change between the check and the use in a way that invalidates the results of the check. This is called a time of check (TOC) to time of use (TOU) race condition (TOCTTOU).

5
New cards

Hissana enters information on a compromised website, which does a poor job sanitizing the input. As a result, the web server sends back a response that infects her system. What type of attack is this?

a. SSRF

b. Replay

c. CSRF

d. XSS

XSS

In a cross-site scripting (XSS) attack, a website that accepts user input without validating it (called "sanitizing") and uses that input in a response can be exploited. If the input is not verified it could instead be added to a code segment that becomes part of an automated response. An attacker can take advantage of this in an XSS attack by tricking a valid website into feeding a malicious script to another user's web browser, which will then execute it.

6
New cards

You are serving as a contractor at a company to help harden endpoints. Which of the following could you implement to help achieve the goal? Select two.

a. Install antivirus software.

b. Use a patch management system.

c. Install a HIPS, HIDS, and/or an EDR.

d. Use an application allow list.

e. Disable all ports and protocols.

Use a patch management system.

Use an application allow list.

Hardening endpoints involves patch management and OS protections. One of the most important steps in hardening an endpoint computer is patching, which involves installing software security updates. Hardening the OS includes employing application allow listing. This is approving in advance only specific applications to run on the OS so that any item not approved will not function.

7
New cards

Jennifer's computer is infected due to a phishing scam. Based on the message presented, she is willing to pay in Bitcoin to regain access to her computer because she does not want to lose her video productions. However, she is having a difficult time launching a browser to pay the ransom. What type of malware was most likely installed?

a. Encrypting ransomware

b. Locking ransomware

c. Crypto ransomware

d. Blocking ransomware

Blocking ransomware

Blocking ransomware infects the computer and then manipulates the operating system (OS) in such a way as to block all normal access to the device, such as the inability to launch a browser. This type of infection can make it more difficult to pay the ransom.

8
New cards

Pamela installed a program that scanned the internet for coupons. A week later her bank account was hacked. How was Pamela's bank account most likely compromised?

a. A website where she used one of the coupons was hacked.

b. She installed a computer Trojan.

c. A "too good to be true" coupon led her to a malicious website.

d. A hardware keylogger was installed.

She installed a computer Trojan.

A computer Trojan is an executable program that masquerades as performing a benign activity but also does something malicious. For example, in addition to finding coupons, a Trojan may also install malware to scan the system for sensitive financial information and transmit it to the attacker.

9
New cards

A malicious actor modifies the return address in an application to execute the code in the malware they injected into memory. What type of attack is this?

a. TOC

b. TOU

c. Exception handling malware

d. TOCTTOU

e. Buffer overflow

Buffer overflow

A buffer overflow attack occurs when a process attempts to store data in RAM beyond the boundaries of a fixed-length storage buffer. The extra data overflows into the adjacent memory locations. Because the storage buffer typically contains the "return address" memory location of the software program being executed when another function interrupted the process, an attacker can overflow the buffer with a new address pointing to the attacker's malware code.

10
New cards

A software quality assurance associate is testing two modules in an application on a web server. One module generates data and the other reads data. However, whenever data is being generated, as soon as the module that reads data is initiated, the application crashes. Which of the following is most likely to be causing the problem?

a. A cross-site scripting condition that was not sanitized.

b. Dereferencing a pointer with a NULL value.

c. An unauthorized directory traversal injection condition.

d. A cross-site request forgery condition with weak input validation.

Dereferencing a pointer with a NULL value.

An improper handling situation is a NULL pointer/object dereference. A dereference obtains from a pointer the address of a data item held in another location. When an application dereferences a pointer that it expects to be valid but instead has a value of NULL, it typically causes a program to crash or exit. A NULL pointer/object dereference can occur through several flaws, including careless programming practices. In the scenario, the module that is supposed to be reading data could be overwriting a critical memory location with a NULL value.