Twa kɔ nsɛm atitiriw so
Log in
Sign up for FREE
arrow_back
Laabri

AP Cybersecurity: Topic 3.1 - Quiz

star
star
star
star
star
Last updated about 2 hours ago
20 Nsɛmmisa
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
Asemmisa {{asɛmmisaAhyɛnsode}}
1.

A company identifies a zero-day vulnerability in a critical, proprietary system. Exploiting this flaw would require a highly specialized, state-sponsored actor and custom-developed code (making the likelihood very low). However, a successful exploit would result in the complete and irreparable shutdown of the organization's core business (making the impact very high).

In a standard risk assessment model, when the likelihood of an exploit is determined to be low but the potential impact of a breach is determined to be high, what is the most appropriate typical resulting risk classification?

Asemmisa {{asɛmmisaAhyɛnsode}}
2.

Mark is at a café and sees two Wi-Fi networks: "Cafe-Guest" and "Cafe-Free-WiFi." He connects to "Cafe-Free-WiFi" because it looks legitimate, but it was actually set up by a malicious party with a similar name to capture traffic.

The malicious "Cafe-Free-WiFi" network established by the adversary is an example of what?

Asemmisa {{asɛmmisaAhyɛnsode}}
3.

During a critical online exam in a university testing center, all wireless connections suddenly drop and fail to reconnect. A security team traces the issue to a strong, sustained electromagnetic signal broadcasting across the Wi-Fi frequency bands near the center, preventing any legitimate wireless communication.

This scenario most closely describes which type of denial-of-service (DoS) attack?

Asemmisa {{asɛmmisaAhyɛnsode}}
4.

An attacker sends unauthorized Address Resolution Protocol (ARP) packets to the network's default gateway. These packets falsely claim that the attacker's device has the Media Access Control (MAC) address of the primary file server, redirecting traffic meant for the server.

This unauthorized modification of the IP-to-MAC address table on the gateway is specifically known as a/an:

Asemmisa {{asɛmmisaAhyɛnsode}}
5.

A cybercriminal connects to an internal network switch and immediately bombards it with a massive number of Ethernet frames, each containing a unique, fictitious MAC address. The goal is to overwhelm the switch's internal memory.

What is the primary objective of this MAC flooding attack?

Asemmisa {{asɛmmisaAhyɛnsode}}
6.

A banking customer tries to navigate to "https://www.google.com/search?q=examplebank.com" but is instead redirected to a malicious website that looks identical. An investigation reveals that an attacker successfully linked the legitimate URL to the IP address of the fake site.

This attack, typically used for credential harvesting by redirecting traffic to a fake site, is best classified as which of the following?

Asemmisa {{asɛmmisaAhyɛnsode}}
7.

A security analyst walks around a corporate campus, using specialized equipment to passively detect and analyze Wi-Fi signals emanating from the buildings. The analyst is specifically looking for the network's SSID and identifying signal leakage.

The analyst is performing an attack technique known as:

Asemmisa {{asɛmmisaAhyɛnsode}}
8.

An adversary manages to send malicious packets into a company's internal network. They use the response (or lack thereof) to these packets to understand the layout of the network, including which devices are active and how they are connected, without exploiting any data.

This technique of sending malicious traffic is primarily used by the adversary to achieve what goal?

Asemmisa {{asɛmmisaAhyɛnsode}}
9.

An attacker has successfully compromised a low-security workstation in the accounting department. From this machine, the attacker begins to search for and exploit vulnerabilities on other computers and servers within the same Local Area Network (LAN) to increase their access.

The attacker's activity of moving from the initial point of compromise to other devices on the LAN is called:

Asemmisa {{asɛmmisaAhyɛnsode}}
10.

An unauthorized visitor finds an unlocked closet and plugs their laptop directly into a wall data port that connects to an unconfigured switch. The visitor immediately gains access to the company's LAN and attempts a MAC spoofing attack.

What security control, if enabled on the switch, could have prevented this direct unauthorized access to the LAN?

Asemmisa {{asɛmmisaAhyɛnsode}}
11.

An attacker stands in the parking lot outside a secure office building. They are successfully capturing the faint broadcast signals from the internal wireless access point, including the beacon frames and other network identifiers.

What can the attacker potentially gather and attempt using these external signals?

Asemmisa {{asɛmmisaAhyɛnsode}}
12.

A company's internal Wi-Fi network allows any device to connect and receive an IP address without requiring a username, password, or digital certificate for verification. An adversary connects their own device and begins to scan for vulnerable servers.

Networks that do not enforce device and user authentication make it easier for adversaries to achieve what objective?

Asemmisa {{asɛmmisaAhyɛnsode}}
13.

An unattended guest plugs a small, unauthorized personal Wi-Fi router into an open Ethernet port in an unused office. The attacker later goes outside the building finds this new wireless signal and uses it to connect directly to the internal LAN, completely bypassing the corporate firewall.

This unauthorized device creating a new, separate wireless entry point to the LAN is known as a/an:

Asemmisa {{asɛmmisaAhyɛnsode}}
14.

A hacker specifically targets the WPA2 handshake process of a corporate Wi-Fi network. After capturing enough packet data, they use an offline dictionary attack to successfully crack the pre-shared key.

What is the ultimate goal of the adversary in breaking the wireless encryption?

Asemmisa {{asɛmmisaAhyɛnsode}}
15.

A critical vulnerability is discovered in a widely used network protocol. An attacker successfully exploits this flaw, allowing them to manipulate network traffic, leading to sensitive data being exposed and services crashing.

Network vulnerabilities, when exploited, primarily pose a risk to which three core security principles?

Asemmisa {{asɛmmisaAhyɛnsode}}
16.

An advanced zero-day network vulnerability is discovered. Exploiting this flaw requires deep, specialized knowledge of network protocol stack manipulation and custom-written exploit code, which few attackers possess.

The requirement for advanced technical ability and knowledge mainly impacts which factor of the security risk calculation?

Asemmisa {{asɛmmisaAhyɛnsode}}
17.

A major organization runs a mission-critical server on an unsegmented internal network that is accessible via a wireless network with weak encryption. An attacker compromises one device and can immediately access the critical server.

This scenario is categorized as a high risk because it allows an adversary to easily have a significant impact by performing actions like:

Asemmisa {{asɛmmisaAhyɛnsode}}
18.

An organization’s external firewall is configured to block most incoming traffic but is improperly set to allow all external ICMP (Internet Control Message Protocol) traffic. An attacker uses this openness to send echo requests (pings) and map out the presence of internal devices.

This vulnerability is best described as a moderate risk because it primarily gives the adversary the ability to:

Asemmisa {{asɛmmisaAhyɛnsode}}
19.

A company’s wireless access points broadcast a beacon frame that includes the network’s Service Set Identifier (SSID) and the strong WPA3 encryption protocol used. This information is publicly available outside the building.

This specific vulnerability is generally considered a low risk because:

Asemmisa {{asɛmmisaAhyɛnsode}}
20.

An attacker successfully executes an ARP poisoning attack on a subnet. After the IP-to-MAC table is corrupted, the attacker's machine begins to receive traffic intended for the financial server. The attacker is now secretly able to view and modify the data flow between the users and the server.

By successfully redirecting traffic and then reading/altering it, the attacker has effectively established what kind of larger-scale attack?