Script kiddies are best described as adversaries who:
Hacktivists are primarily motivated by:
Which adversary has legitimate access to systems and poses a unique threat due to credentials and insider knowledge?
A cyberterrorist's main objective is usually to:
Transnational criminal organizations typically focus on:
Which adversary is employed by a government and often uses advanced zero-day vulnerabilities?
The constant evolution of attacker tools, techniques, and procedures is an example of:
An attack is defined as:
Which is NOT a form of social engineering?
An adversary who claims to be IT support to trick an employee into revealing a password is using:
This offer is only available for the next 10 minutes! is an example of which social engineering tactic?
An adversary intercepts and alters communication between a user and website without detection. This is:
An adversary inputs malicious code into a login field to change a database query. This is an example of:
What differentiates a DoS attack from a DDoS attack?
A fake login page designed to steal usernames and passwords is an example of:
The first phase of a cyberattack, where adversaries gather OSINT, is called:
Establishing a foothold on a system through phishing or weak credentials happens during:
Which phase involves setting up a remote access trojan (RAT) for sustained control?
Moving from one compromised system to another with higher privileges is called:
Exfiltrating data and disrupting services happens during which phase?
An adversary deletes log files to cover their tracks. This is part of which phase?
Risk analysis considers two factors:
Which of the following is an example of reputational damage?
The likelihood of a vulnerability being exploited depends on:
A hacktivist targeting a company’s website to protest illegal fishing is an example of:
Which vulnerability is more likely to be exploited?
Highly motivated and capable adversaries are more likely to use:
Describing a vulnerability as “high impact but low likelihood” is an example of:
Assigning a monetary value to a potential exploit is an example of:
Which is NOT one of the four main risk management strategies?
Stopping the risky activity altogether is called:
Purchasing cybersecurity insurance is an example of:
Installing a firewall to reduce the chance of attack is an example of:
Residual risk is:
Resiliency means:
A fully equipped backup site with current data ready to use immediately is a:
A site with utilities and hardware but lacking the latest backups is a:
A location that only has utility connections but no equipment is a:
A static copy of critical files at a point in time is called a:
Cross-training employees and rotating job roles increases:
Ensuring only authorized individuals can access data refers to:
Which principle ensures data remains accurate and trustworthy?
Which principle is violated if a system becomes unexpectedly unavailable?
Ensuring actions can be traced back to an entity is called:
Verifying that someone is who they claim to be is:
Permissions that specify what resources a user can access are called:
Tracking login times and user actions refers to:
A layered security approach with multiple controls is called:
Defense-in-depth is important because:
Before implementing a control, organizations should perform a:
Which of the following is a physical control?
Which is a technical control?
Which is a managerial control?
Preventative controls are designed to:
An intrusion detection system (IDS) is an example of a:
Patching vulnerabilities is an example of a:
A company discovers that an employee has been secretly copying customer data to sell on the dark web. What type of adversary is this?
A group launches a cyberattack on a country’s water treatment plant, leaving residents without clean water for several days. The adversary is most likely:
An inexperienced teenager uses a downloaded tool to launch a denial-of-service attack against their school’s website, causing it to crash. This is an example of:
A group defaces an oil company’s website with slogans protesting climate change policies. What is their primary motivation?
An attacker sends an urgent email appearing to be from the CEO demanding that employees transfer funds immediately. Which social engineering tactic is this?
An employee receives a text message claiming they won a prize and must click a link to claim it. This is an example of:
During an investigation, analysts discover malicious code inserted into a website’s login field that modified a database query. What attack occurred?
A company experiences an outage after thousands of compromised computers flood its servers with traffic. Which type of attack is this?
An adversary sets up a fake login portal that looks identical to a bank’s website. Users who log in have their usernames and passwords stolen. This is an example of:
A cybersecurity team notices an adversary removing log files to cover their tracks after stealing data. This occurs during which attack phase?
An attacker gains access to a low-level account on a network, then uses it to move into admin accounts. This describes which phase of an attack?
A company decides not to offer online payment services because of the high likelihood of fraud. Which risk management strategy is this?
A hospital buys cyber insurance so that if ransomware encrypts patient files, the cost of recovery is covered. This is an example of:
An organization installs a firewall and anti-malware to reduce the likelihood of compromise. This represents:
A company sets up a fully equipped secondary site with current backups and ready-to-use servers. If the primary site goes down, operations can continue immediately. This is an example of:
A retail company describes a vulnerability as “high likelihood but low impact.” This is an example of:
An organization uses both firewalls and intrusion detection systems. If one fails, the other may still stop the attack. This is an example of:
A user logs into their company account with a password and then receives a text with a verification code. This process ensures:
A company policy requires IT to log all system access attempts and changes made by users. This security principle is called:
A software update is released to fix a critical vulnerability. Installing the update is an example of which control type?
A hospital’s computer systems are suddenly locked, and attackers demand payment in Bitcoin to restore access to patient records. What type of attack is this?
A company’s social media account is taken over after an employee clicked a link in a fake password reset email. What was the most likely cause?
A small business receives thousands of junk requests to its website at once, overwhelming the server and making it crash. What type of attack occurred?
A government contractor discovers that sensitive project files were stolen. Logs reveal attackers spent months secretly inside the system without being detected. What kind of adversary is most likely responsible?