Twa kɔ nsɛm atitiriw so
Log in
Sign up for FREE
arrow_back
Laabri

AP Cybersecurity: Unit 01 Test Review

star
star
star
star
star
Last updated about 2 hours ago
80 Nsɛmmisa
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
Asemmisa {{asɛmmisaAhyɛnsode}}
1.

Script kiddies are best described as adversaries who:

Asemmisa {{asɛmmisaAhyɛnsode}}
2.

Hacktivists are primarily motivated by:

Asemmisa {{asɛmmisaAhyɛnsode}}
3.

Which adversary has legitimate access to systems and poses a unique threat due to credentials and insider knowledge?

Asemmisa {{asɛmmisaAhyɛnsode}}
4.

A cyberterrorist's main objective is usually to:

Asemmisa {{asɛmmisaAhyɛnsode}}
5.

Transnational criminal organizations typically focus on:

Asemmisa {{asɛmmisaAhyɛnsode}}
6.

Which adversary is employed by a government and often uses advanced zero-day vulnerabilities?

Asemmisa {{asɛmmisaAhyɛnsode}}
7.

The constant evolution of attacker tools, techniques, and procedures is an example of:

Asemmisa {{asɛmmisaAhyɛnsode}}
8.

An attack is defined as:

Asemmisa {{asɛmmisaAhyɛnsode}}
9.

Which is NOT a form of social engineering?

Asemmisa {{asɛmmisaAhyɛnsode}}
10.

An adversary who claims to be IT support to trick an employee into revealing a password is using:

Asemmisa {{asɛmmisaAhyɛnsode}}
11.

This offer is only available for the next 10 minutes! is an example of which social engineering tactic?

Asemmisa {{asɛmmisaAhyɛnsode}}
12.

An adversary intercepts and alters communication between a user and website without detection. This is:

Asemmisa {{asɛmmisaAhyɛnsode}}
13.

An adversary inputs malicious code into a login field to change a database query. This is an example of:

Asemmisa {{asɛmmisaAhyɛnsode}}
14.

What differentiates a DoS attack from a DDoS attack?

Asemmisa {{asɛmmisaAhyɛnsode}}
15.

A fake login page designed to steal usernames and passwords is an example of:

Asemmisa {{asɛmmisaAhyɛnsode}}
16.

The first phase of a cyberattack, where adversaries gather OSINT, is called:

Asemmisa {{asɛmmisaAhyɛnsode}}
17.

Establishing a foothold on a system through phishing or weak credentials happens during:

Asemmisa {{asɛmmisaAhyɛnsode}}
18.

Which phase involves setting up a remote access trojan (RAT) for sustained control?

Asemmisa {{asɛmmisaAhyɛnsode}}
19.

Moving from one compromised system to another with higher privileges is called:

Asemmisa {{asɛmmisaAhyɛnsode}}
20.

Exfiltrating data and disrupting services happens during which phase?

Asemmisa {{asɛmmisaAhyɛnsode}}
21.

An adversary deletes log files to cover their tracks. This is part of which phase?

Asemmisa {{asɛmmisaAhyɛnsode}}
22.

Risk analysis considers two factors:

Asemmisa {{asɛmmisaAhyɛnsode}}
23.

Which of the following is an example of reputational damage?

Asemmisa {{asɛmmisaAhyɛnsode}}
24.

The likelihood of a vulnerability being exploited depends on:

Asemmisa {{asɛmmisaAhyɛnsode}}
25.

A hacktivist targeting a company’s website to protest illegal fishing is an example of:

Asemmisa {{asɛmmisaAhyɛnsode}}
26.

Which vulnerability is more likely to be exploited?

Asemmisa {{asɛmmisaAhyɛnsode}}
27.

Highly motivated and capable adversaries are more likely to use:

Asemmisa {{asɛmmisaAhyɛnsode}}
28.

Describing a vulnerability as “high impact but low likelihood” is an example of:

Asemmisa {{asɛmmisaAhyɛnsode}}
29.

Assigning a monetary value to a potential exploit is an example of:

Asemmisa {{asɛmmisaAhyɛnsode}}
30.

Which is NOT one of the four main risk management strategies?

Asemmisa {{asɛmmisaAhyɛnsode}}
31.

Stopping the risky activity altogether is called:

Asemmisa {{asɛmmisaAhyɛnsode}}
32.

Purchasing cybersecurity insurance is an example of:

Asemmisa {{asɛmmisaAhyɛnsode}}
33.

Installing a firewall to reduce the chance of attack is an example of:

Asemmisa {{asɛmmisaAhyɛnsode}}
34.

Residual risk is:

Asemmisa {{asɛmmisaAhyɛnsode}}
35.

Resiliency means:

Asemmisa {{asɛmmisaAhyɛnsode}}
36.

A fully equipped backup site with current data ready to use immediately is a:

Asemmisa {{asɛmmisaAhyɛnsode}}
37.

A site with utilities and hardware but lacking the latest backups is a:

Asemmisa {{asɛmmisaAhyɛnsode}}
38.

A location that only has utility connections but no equipment is a:

Asemmisa {{asɛmmisaAhyɛnsode}}
39.

A static copy of critical files at a point in time is called a:

Asemmisa {{asɛmmisaAhyɛnsode}}
40.

Cross-training employees and rotating job roles increases:

Asemmisa {{asɛmmisaAhyɛnsode}}
41.

Ensuring only authorized individuals can access data refers to:

Asemmisa {{asɛmmisaAhyɛnsode}}
42.

Which principle ensures data remains accurate and trustworthy?

Asemmisa {{asɛmmisaAhyɛnsode}}
43.

Which principle is violated if a system becomes unexpectedly unavailable?

Asemmisa {{asɛmmisaAhyɛnsode}}
44.

Ensuring actions can be traced back to an entity is called:

Asemmisa {{asɛmmisaAhyɛnsode}}
45.

Verifying that someone is who they claim to be is:

Asemmisa {{asɛmmisaAhyɛnsode}}
46.

Permissions that specify what resources a user can access are called:

Asemmisa {{asɛmmisaAhyɛnsode}}
47.

Tracking login times and user actions refers to:

Asemmisa {{asɛmmisaAhyɛnsode}}
48.

A layered security approach with multiple controls is called:

Asemmisa {{asɛmmisaAhyɛnsode}}
49.

Defense-in-depth is important because:

Asemmisa {{asɛmmisaAhyɛnsode}}
50.

Before implementing a control, organizations should perform a:

Asemmisa {{asɛmmisaAhyɛnsode}}
51.

Which of the following is a physical control?

Asemmisa {{asɛmmisaAhyɛnsode}}
52.

Which is a technical control?

Asemmisa {{asɛmmisaAhyɛnsode}}
53.

Which is a managerial control?

Asemmisa {{asɛmmisaAhyɛnsode}}
54.

Preventative controls are designed to:

Asemmisa {{asɛmmisaAhyɛnsode}}
55.

An intrusion detection system (IDS) is an example of a:

Asemmisa {{asɛmmisaAhyɛnsode}}
56.

Patching vulnerabilities is an example of a:

Asemmisa {{asɛmmisaAhyɛnsode}}
57.

A company discovers that an employee has been secretly copying customer data to sell on the dark web. What type of adversary is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
58.

A group launches a cyberattack on a country’s water treatment plant, leaving residents without clean water for several days. The adversary is most likely:

Asemmisa {{asɛmmisaAhyɛnsode}}
59.

An inexperienced teenager uses a downloaded tool to launch a denial-of-service attack against their school’s website, causing it to crash. This is an example of:

Asemmisa {{asɛmmisaAhyɛnsode}}
60.

A group defaces an oil company’s website with slogans protesting climate change policies. What is their primary motivation?

Asemmisa {{asɛmmisaAhyɛnsode}}
61.

An attacker sends an urgent email appearing to be from the CEO demanding that employees transfer funds immediately. Which social engineering tactic is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
62.

An employee receives a text message claiming they won a prize and must click a link to claim it. This is an example of:

Asemmisa {{asɛmmisaAhyɛnsode}}
63.

During an investigation, analysts discover malicious code inserted into a website’s login field that modified a database query. What attack occurred?

Asemmisa {{asɛmmisaAhyɛnsode}}
64.

A company experiences an outage after thousands of compromised computers flood its servers with traffic. Which type of attack is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
65.

An adversary sets up a fake login portal that looks identical to a bank’s website. Users who log in have their usernames and passwords stolen. This is an example of:

Asemmisa {{asɛmmisaAhyɛnsode}}
66.

A cybersecurity team notices an adversary removing log files to cover their tracks after stealing data. This occurs during which attack phase?

Asemmisa {{asɛmmisaAhyɛnsode}}
67.

An attacker gains access to a low-level account on a network, then uses it to move into admin accounts. This describes which phase of an attack?

Asemmisa {{asɛmmisaAhyɛnsode}}
68.

A company decides not to offer online payment services because of the high likelihood of fraud. Which risk management strategy is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
69.

A hospital buys cyber insurance so that if ransomware encrypts patient files, the cost of recovery is covered. This is an example of:

Asemmisa {{asɛmmisaAhyɛnsode}}
70.

An organization installs a firewall and anti-malware to reduce the likelihood of compromise. This represents:

Asemmisa {{asɛmmisaAhyɛnsode}}
71.

A company sets up a fully equipped secondary site with current backups and ready-to-use servers. If the primary site goes down, operations can continue immediately. This is an example of:

Asemmisa {{asɛmmisaAhyɛnsode}}
72.

A retail company describes a vulnerability as “high likelihood but low impact.” This is an example of:

Asemmisa {{asɛmmisaAhyɛnsode}}
73.

An organization uses both firewalls and intrusion detection systems. If one fails, the other may still stop the attack. This is an example of:

Asemmisa {{asɛmmisaAhyɛnsode}}
74.

A user logs into their company account with a password and then receives a text with a verification code. This process ensures:

Asemmisa {{asɛmmisaAhyɛnsode}}
75.

A company policy requires IT to log all system access attempts and changes made by users. This security principle is called:

Asemmisa {{asɛmmisaAhyɛnsode}}
76.

A software update is released to fix a critical vulnerability. Installing the update is an example of which control type?

Asemmisa {{asɛmmisaAhyɛnsode}}
77.

A hospital’s computer systems are suddenly locked, and attackers demand payment in Bitcoin to restore access to patient records. What type of attack is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
78.

A company’s social media account is taken over after an employee clicked a link in a fake password reset email. What was the most likely cause?

Asemmisa {{asɛmmisaAhyɛnsode}}
79.

A small business receives thousands of junk requests to its website at once, overwhelming the server and making it crash. What type of attack occurred?

Asemmisa {{asɛmmisaAhyɛnsode}}
80.

A government contractor discovers that sensitive project files were stolen. Logs reveal attackers spent months secretly inside the system without being detected. What kind of adversary is most likely responsible?