Twa kɔ nsɛm atitiriw so
Log in
Sign up for FREE
arrow_back
Laabri

AP Cybersecurity: Topic 4.4 Quiz

star
star
star
star
star
Last updated about 2 hours ago
24 Nsɛmmisa
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
Asemmisa {{asɛmmisaAhyɛnsode}}
1.

A device audit finds that an executable named update_tool.exe was created late at night in a public folder. What type of IoC is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
2.

A user logs in at 2:00 AM from a city they never visit, which is unusual for their normal schedule. What does this suggest?

Asemmisa {{asɛmmisaAhyɛnsode}}
3.

A malware scanner detects a file whose hash matches a known malicious signature. What type of IoC is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
4.

Several employees attempt to log in from the same IP address within seconds using the same password, but most fail. Which password attack is likely happening?

Asemmisa {{asɛmmisaAhyɛnsode}}
5.

An administrator sees a series of logins using default credentials (like admin:admin) across multiple accounts in quick succession. What type of attack is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
6.

After a suspected attack, a device’s firewall rules were modified without authorization. What type of IoC is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
7.

A user’s account fails login five times in a row, then succeeds on the sixth attempt. This happened from an unusual IP. What should be investigated?

Asemmisa {{asɛmmisaAhyɛnsode}}
8.

A system shows a background process named updater.exe running automatically on startup, but no software was installed by the user. What kind of indicator is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
9.

A system administrator reviews logs and sees repeated failed login attempts on a single account over 10 minutes. Which attack does this pattern suggest?

Asemmisa {{asɛmmisaAhyɛnsode}}
10.

A login attempt is made from an IP address in a foreign country that the user has never logged in from before. What type of IoC is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
11.

Which type of attack is impossible to detect using logs?

Asemmisa {{asɛmmisaAhyɛnsode}}
12.

An IT audit finds that a new service was configured to start automatically at boot, linked to a suspicious executable. Which IoC is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
13.

A device has unusual processes running that weren’t part of normal startup routines. Which category of IoC is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
14.

A security officer finds that several user accounts have been successfully logged in from unusual locations at unusual times. The officer locks out the accounts. What should the officer do next?

Asemmisa {{asɛmmisaAhyɛnsode}}
15.

An audit shows that a file has a name matching a known malicious program, but was not executed. What type of IoC is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
16.

A single user’s account tries multiple passwords in a short period the final attempt succeeds in logging in the account. Which of the following should the administrator do first?

Asemmisa {{asɛmmisaAhyɛnsode}}
17.

A log shows dozens of failed logins across multiple accounts from one IP within seconds. What type of attack is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
18.

An administrator observes a series of default passwords attempted on several accounts from the same IP, none of the accounts are accessed. What action should the administrator take?

Asemmisa {{asɛmmisaAhyɛnsode}}
19.

A user account is seen logging in at odd hours from unusual IPs, and immediately changes permissions on files. Which IoC is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
20.

A system shows many failed logins on a single account, then a successful login occurs, and immediately sensitive data is accessed. What type of IoC is this?

Carefully read the scenario and analyze the provided log. Then respond to the following:

  1. Identify all Indicators of Compromise (IoCs) present in the scenario.

  2. For each IoC, classify it as host-based, file-based, or behavior-based.

  3. Determine the type of attack represented.

  4. Suggest one mitigation strategy and explain how it would secure the device.

Scoring (5 points total):

  • IoCs identified: 1 point – all relevant IoCs are listed.

  • IoC classification: 1 point – each IoC correctly classified as host-based, file-based, or behavior-based.

  • Attack type identified: 1 point – correct attack type chosen based on the IoCs.

  • Mitigation strategy: 2 points – a plausible action is described and clearly justified in terms of improving security.

An IT analyst analyzes the following login attempts:

2026-02-05 10:05:12 - admin:admin - FAIL - 198.51.100.45

2026-02-05 10:05:14 - guest:guest - FAIL - 198.51.100.45

2026-02-05 10:05:16 - test:test - FAIL - 198.51.100.45

2026-02-05 10:05:18 - user:user - SUCCESS - 198.51.100.45

1
Asemmisa {{asɛmmisaAhyɛnsode}}
21a.

What Indicators of Compromise are present?

1
Asemmisa {{asɛmmisaAhyɛnsode}}
21b.

Are the IoCs host-based, file-based, or behavior-based? Explain

1
Asemmisa {{asɛmmisaAhyɛnsode}}
21c.

What type of attack is occuring?

2
Asemmisa {{asɛmmisaAhyɛnsode}}
21d.

What actions would you take to mitigate the attack? How would that secure the device?