A company uses a computer dedicated to hosting shared files and managing user access for all employees. This device is best classified as
An employee uses a laptop primarily for word processing, email, and web browsing. Which type of computing device is this?
A smart thermostat connected to a home Wi-Fi network controls heating and cooling automatically. What type of device is this?
An adversary tricks a user into installing a “free PDF converter” that secretly gives the attacker remote control of the system. This malware is best described as
Malware that spreads automatically from one system to another without user interaction is known as
A user opens an email attachment, and shortly after their files become inaccessible with a message demanding payment. This attack most likely involved
Which type of malware is specifically designed to hide itself deep within an operating system and avoid detection?
Malicious code that exists only in memory and uses legitimate system tools instead of stored files is known as
A company delays installing operating system updates on employee computers. What risk does this create?
An attacker inserts a USB drive into a computer and malware executes automatically. Which configuration enabled this attack?
A device accepts inbound connections on several unused ports. Why is this risky?
Which security control helps block malicious incoming or outgoing traffic on a single device?
A compromised email server exposes sensitive customer data. How should this risk most accurately be classified?
A factory uses embedded systems to control machinery. Remote access is protected by a password but no MFA. This vulnerability represents
An employee laptop has an open telnet port but stores no sensitive data. This is best classified as
Which authentication factor relies on something a user knows?
A system requires a password and a one-time code sent to a phone. This is an example of
Which authentication factor would a fingerprint scanner use?
Why do systems store password hashes instead of plaintext passwords?
Two users choose the same password, but their stored password hashes are different. Why?
Which property of cryptographic hashes makes it difficult to determine the original password from the hash?
Why are MD5 and SHA1 considered insecure for password storage?
An attacker captures a user:password hash database and cracks passwords offline. Why can’t this attack be detected in logs?
An attacker uses leaked usernames and passwords from another breach to attempt logins on a new service. This is an example of
Which policy defines what activities users are allowed or prohibited from performing on organizational devices?
Why must anti-malware software be regularly updated?
Why do software updates and patches improve security?
Which login setting helps prevent automated password guessing attacks?
A host-based firewall is configured to block outbound FTP traffic. What attack does this help prevent?
An analyst notices many failed login attempts from one IP address across several user accounts in a short time. This is most likely an indicator of
Define IoC 1:
Write your response in complete sentences with clear explanations.
Use cybersecurity terminology appropriately.
Focus on technical details, risk assessment, and actionable recommendations.
Define IoC 2:
Write your response in complete sentences with clear explanations.
Use cybersecurity terminology appropriately.
Focus on technical details, risk assessment, and actionable recommendations.
Define IoC 3:
Write your response in complete sentences with clear explanations.
Use cybersecurity terminology appropriately.
Focus on technical details, risk assessment, and actionable recommendations.