A company uses a machine that provides email and file storage services to hundreds of employees across the organization. Which type of computing device is this?
A smartwatch that tracks heart rate and steps would best be classified as which type of device?
A hospital MRI machine contains a computer that controls imaging functions and communicates with specialized hardware. This computer is best described as a(n):
An employee opens an email attachment that looks like an invoice, and malware installs itself on the device. Which type of malware best fits this description?
Malware spreads automatically from one computer to another across a network without user interaction. This malware is most likely a:
A program pretends to be a free game but secretly gives an attacker remote control of the system once installed. Which malware type is this?
A user’s files suddenly become inaccessible, and a message demands payment in exchange for restoring access. Which malware is responsible?
Malware silently records everything a user types, including passwords and messages. Which malware is this?
Malware hides deep in the operating system and actively avoids detection by security software. Which type best matches this behavior?
Malicious code runs only when a specific date and time are reached. This is an example of a:
Which statement best describes fileless malware?
A company delays installing operating system updates on its servers. Which risk does this most directly create?
An attacker guesses a weak password to access an employee’s account. Which vulnerability was exploited?
An employee receives a phone call pretending to be IT support and gives away their login credentials. This attack relies on:
A company laptop is stolen. The attacker boots into recovery mode and resets the user’s password. Which vulnerability allowed this?
Malware stored on a USB drive installs automatically when the drive is plugged in. What setting enabled this attack?
An attacker scans a system and connects through an open network service. Which vulnerability made this possible?
Which situation represents the highest risk?
Which factor most increases the likelihood portion of a risk assessment?
Which factor most affects the impact portion of a risk assessment?
Scenario:
A student brings a personal laptop to school and plugs in a USB drive they found in the parking lot to see if it contains anything important. The laptop automatically opens files when removable media is inserted, and the student does not use any security software beyond the default settings.
Based on the scenario, answer the following:
• Identify the type of computing device described.
• Identify one type of malware that could realistically affect this device.
• Explain how a vulnerability could be exploited to allow that malware to impact the device.
• Assess the risk associated with this device by stating whether it is low, moderate, or high, and justify your assessment based on likelihood and impact.
Your response should clearly connect the device, vulnerability, malware, and risk.
Scoring:
Type of Computing Device - 1 point
Type of Malware - 1 point
Vulnerability - 1 point
Risk Assessment - 1 point & Justification - 1 point
What type of device is being described
What is a type of malware that could infect the device?
Explain the device vulnerability that was exploited in this scenario
What level of risk would you assess in this scenario and why?