Twa kɔ nsɛm atitiriw so
Log in
Sign up for FREE
arrow_back
Laabri

AP Cybersecurity: Unit 04 - Test Review

star
star
star
star
star
Last updated about 2 hours ago
67 Nsɛmmisa
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
Asemmisa {{asɛmmisaAhyɛnsode}}
1.

A hospital installs high-powered machines to manage patient records, imaging, and authentication for thousands of users. These machines provide services to all connected devices. What type of computer are they using?

Asemmisa {{asɛmmisaAhyɛnsode}}
2.

An architect uses a machine for 3D modeling, design work, and email. It is designed for one person to use at a time. What type of computer is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
3.

A delivery driver relies on a smartphone app to track packages and communicate with the central office. What type of computer is the smartphone?

Asemmisa {{asɛmmisaAhyɛnsode}}
4.

A factory machine automatically fills bottles with liquid. The controller in the machine runs only the specialized program needed to control the filling process. What type of computer is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
5.

An employee downloads an attachment that looks like a report, but when they open it, their system becomes infected. What type of malware is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
6.

A malicious program spreads automatically across a network without any user clicking or opening a file. What type of malware is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
7.

A user installs a free game, not realizing it contains hidden code that lets an adversary remotely access their computer. What type of malware is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
8.

A business finds its files encrypted and a message demanding payment for a decryption key. What type of malware is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
9.

An adversary secretly installs software that records every keystroke a user makes, including passwords. What type of malware is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
10.

A malicious program is hidden in system processes and is almost impossible to detect because it operates at the operating system level. What type of malware is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
11.

An organization discovers malware that never writes files to disk but instead lives only in system memory. What type of malware is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
12.

A company fails to install a security update. An attacker uses the unpatched software flaw to take over the system and steal files. Which vulnerability was exploited?

Asemmisa {{asɛmmisaAhyɛnsode}}
13.

An attacker guesses an employee’s weak password and gains access to company resources. Which vulnerability was exploited?

Asemmisa {{asɛmmisaAhyɛnsode}}
14.

An adversary boots a stolen laptop into recovery mode and bypasses user logins because no BIOS password was set. Which vulnerability was exploited?

Asemmisa {{asɛmmisaAhyɛnsode}}
15.

An employee plugs in a USB drive that automatically launches malware without clicking anything. Which vulnerability was exploited?

Asemmisa {{asɛmmisaAhyɛnsode}}
16.

An attacker connects to an unsecured network service on a computer that was not protected. Which vulnerability was exploited?

Asemmisa {{asɛmmisaAhyɛnsode}}
17.

A device’s firewall is disabled, allowing malicious packets to flood in and disrupt the system. Which vulnerability was exploited?

Asemmisa {{asɛmmisaAhyɛnsode}}
18.

A computer without anti-malware software becomes infected when a malicious email attachment is opened. Which vulnerability was exploited?

Asemmisa {{asɛmmisaAhyɛnsode}}
19.

A hospital’s patient database is encrypted by ransomware, preventing staff from accessing medical records. What level of risk does this represent?

Asemmisa {{asɛmmisaAhyɛnsode}}
20.

An email server has not been updated with the latest patch, leaving it vulnerable to a critical exploit. What level of risk does this represent?

Asemmisa {{asɛmmisaAhyɛnsode}}
21.

A water treatment facility uses systems with username/password access but does not require multifactor authentication. What level of risk does this represent?

Asemmisa {{asɛmmisaAhyɛnsode}}
22.

An employee’s personal laptop has Telnet port 23 open. If exploited, the impact would be minimal. What level of risk does this represent?

Asemmisa {{asɛmmisaAhyɛnsode}}
23.

A bank requires employees to log in using both a password and a fingerprint scan. What type of authentication is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
24.

A user logs in to their email by entering a PIN they created. What type of authentication factor is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
25.

An employee swipes an access card to enter a secure server room. What type of authentication factor is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
26.

A company uses facial recognition software to allow access to workstations. What type of authentication factor is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
27.

A financial service blocks logins from outside the United States unless the user has prior approval. What type of authentication factor is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
28.

A hash function takes an input of any length and outputs a fixed-length string. What is this output called?

Asemmisa {{asɛmmisaAhyɛnsode}}
29.

Two different files are processed by the same hash function and produce the same output. What is this called?

Asemmisa {{asɛmmisaAhyɛnsode}}
30.

An important property of cryptographic hash functions is that given a hash, it is infeasible to figure out the input. What is this called?

Asemmisa {{asɛmmisaAhyɛnsode}}
31.

MD5 and SHA1 are no longer considered secure because adversaries can force collisions. What has happened to these algorithms?

Asemmisa {{asɛmmisaAhyɛnsode}}
32.

Why should organizations store password hashes instead of plaintext passwords?

Asemmisa {{asɛmmisaAhyɛnsode}}
33.

Why do systems add a random salt when hashing passwords?

Asemmisa {{asɛmmisaAhyɛnsode}}
34.

A hacker steals a user’s password. Since the organization has not enabled multifactor authentication, the hacker can log in with the same rights as the user. What attack is this exploiting?

Asemmisa {{asɛmmisaAhyɛnsode}}
35.

An attacker tries many password guesses directly against a company’s login portal. What type of attack is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
36.

An attacker obtains a stolen database of usernames and hashed passwords, then tests them on their own computer. What type of attack is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
37.

A hacker uses stolen usernames and passwords from a breach at another company to try logging into employees’ accounts. What is this attack called?

Asemmisa {{asɛmmisaAhyɛnsode}}
38.

An adversary attempts one very common password (like “Password123”) across hundreds of accounts in the same organization. What attack is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
39.

An IoT device is left with the default admin username and password. An attacker tries these credentials to gain access. What attack is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
40.

An adversary uses a program to try every possible combination of letters, numbers, and symbols until the password is found. What attack is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
41.

An attacker uses a file of common passwords to test against a captured hash. What attack is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
42.

An attacker uses a precomputed list of passwords and their hashes to quickly match against a captured password hash. What attack is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
43.

An organization creates rules that prohibit employees from visiting gaming or social media sites while on company devices. What type of control is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
44.

A company requires employees to create passwords of at least 12 characters and to change them every 90 days. What type of control is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
45.

A company restricts who can log in to servers remotely and requires all services not being used to be disabled. What type of control is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
46.

An organization prohibits employees from installing their own applications and requires them to request software through IT. What type of control is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
47.

A security tool isolates malicious files and removes them after detecting suspicious activity. What type of software is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
48.

Anti-malware programs compare files against a database of known malicious patterns. What are these patterns called?

Asemmisa {{asɛmmisaAhyɛnsode}}
49.

A company releases an update to fix a security hole in its operating system. What is this update called?

Asemmisa {{asɛmmisaAhyɛnsode}}
50.

Why is keeping operating systems and applications up to date important for security?

Asemmisa {{asɛmmisaAhyɛnsode}}
51.

A company requires employees to include uppercase, lowercase, numbers, and special characters in their passwords. What setting is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
52.

A company requires all user passwords to be at least 14 characters long. What setting is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
53.

An organization requires users to change their password every 120 days. What setting is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
54.

A system prevents users from reusing any of their last 10 passwords. What setting is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
55.

A company locks a user account for 15 minutes after five failed login attempts. What setting is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
56.

A user enables a program on their laptop that filters which network connections are allowed in or out of the device. What is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
57.

A firewall rule on a laptop blocks all outbound FTP traffic. What type of firewall is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
58.

A host-based firewall is configured to allow traffic only from specific IP addresses. What is this firewall using?

Asemmisa {{asɛmmisaAhyɛnsode}}
59.

A system administrator reviews logs showing multiple failed login attempts late at night. What is this an example of?

Asemmisa {{asɛmmisaAhyɛnsode}}
60.

A suspicious process is found running on a server that was not authorized by the administrator. What is this an example of?

Asemmisa {{asɛmmisaAhyɛnsode}}
61.

A file on a laptop is discovered to have a hash that matches a known malware sample. What is this an example of?

Asemmisa {{asɛmmisaAhyɛnsode}}
62.

An administrator notices many failed login attempts from the same IP address. What is this an example of?

Asemmisa {{asɛmmisaAhyɛnsode}}
63.

A system log shows one user attempting dozens of incorrect passwords in rapid succession. What type of attack does this indicate?

Asemmisa {{asɛmmisaAhyɛnsode}}
64.

A log reveals a legitimate employee account logging in from a foreign country at 3 a.m. What does this suggest?

Asemmisa {{asɛmmisaAhyɛnsode}}
65.

Logs show dozens of different employees failing to log in within seconds, all from the same IP address. What type of attack is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
66.

A system shows repeated login attempts using default admin credentials like “admin:password.” What type of attack is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
67.

Why can’t offline password attacks be detected through system logs?