Twa kɔ nsɛm atitiriw so
Log in
Sign up for FREE
arrow_back
Laabri

AP Cybersecurity: Unit 04 Test

star
star
star
star
star
Last updated about 2 hours ago
33 Nsɛmmisa
3
3
3
3
3
3
3
3
3
3
3
3
3
3
3
3
3
3
3
3
3
3
3
3
3
3
3
3
3
3
Asemmisa {{asɛmmisaAhyɛnsode}}
1.

A company uses a computer dedicated to hosting shared files and managing user access for all employees. This device is best classified as

Asemmisa {{asɛmmisaAhyɛnsode}}
2.

An employee uses a laptop primarily for word processing, email, and web browsing. Which type of computing device is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
3.

A smart thermostat connected to a home Wi-Fi network controls heating and cooling automatically. What type of device is this?

Asemmisa {{asɛmmisaAhyɛnsode}}
4.

An adversary tricks a user into installing a “free PDF converter” that secretly gives the attacker remote control of the system. This malware is best described as

Asemmisa {{asɛmmisaAhyɛnsode}}
5.

Malware that spreads automatically from one system to another without user interaction is known as

Asemmisa {{asɛmmisaAhyɛnsode}}
6.

A user opens an email attachment, and shortly after their files become inaccessible with a message demanding payment. This attack most likely involved

Asemmisa {{asɛmmisaAhyɛnsode}}
7.

Which type of malware is specifically designed to hide itself deep within an operating system and avoid detection?

Asemmisa {{asɛmmisaAhyɛnsode}}
8.

Malicious code that exists only in memory and uses legitimate system tools instead of stored files is known as

Asemmisa {{asɛmmisaAhyɛnsode}}
9.

A company delays installing operating system updates on employee computers. What risk does this create?

Asemmisa {{asɛmmisaAhyɛnsode}}
10.

An attacker inserts a USB drive into a computer and malware executes automatically. Which configuration enabled this attack?

Asemmisa {{asɛmmisaAhyɛnsode}}
11.

A device accepts inbound connections on several unused ports. Why is this risky?

Asemmisa {{asɛmmisaAhyɛnsode}}
12.

Which security control helps block malicious incoming or outgoing traffic on a single device?

Asemmisa {{asɛmmisaAhyɛnsode}}
13.

A compromised email server exposes sensitive customer data. How should this risk most accurately be classified?

Asemmisa {{asɛmmisaAhyɛnsode}}
14.

A factory uses embedded systems to control machinery. Remote access is protected by a password but no MFA. This vulnerability represents

Asemmisa {{asɛmmisaAhyɛnsode}}
15.

An employee laptop has an open telnet port but stores no sensitive data. This is best classified as

Asemmisa {{asɛmmisaAhyɛnsode}}
16.

Which authentication factor relies on something a user knows?

Asemmisa {{asɛmmisaAhyɛnsode}}
17.

A system requires a password and a one-time code sent to a phone. This is an example of

Asemmisa {{asɛmmisaAhyɛnsode}}
18.

Which authentication factor would a fingerprint scanner use?

Asemmisa {{asɛmmisaAhyɛnsode}}
19.

Why do systems store password hashes instead of plaintext passwords?

Asemmisa {{asɛmmisaAhyɛnsode}}
20.

Two users choose the same password, but their stored password hashes are different. Why?

Asemmisa {{asɛmmisaAhyɛnsode}}
21.

Which property of cryptographic hashes makes it difficult to determine the original password from the hash?

Asemmisa {{asɛmmisaAhyɛnsode}}
22.

Why are MD5 and SHA1 considered insecure for password storage?

Asemmisa {{asɛmmisaAhyɛnsode}}
23.

An attacker captures a user:password hash database and cracks passwords offline. Why can’t this attack be detected in logs?

Asemmisa {{asɛmmisaAhyɛnsode}}
24.

An attacker uses leaked usernames and passwords from another breach to attempt logins on a new service. This is an example of

Asemmisa {{asɛmmisaAhyɛnsode}}
25.

Which policy defines what activities users are allowed or prohibited from performing on organizational devices?

Asemmisa {{asɛmmisaAhyɛnsode}}
26.

Why must anti-malware software be regularly updated?

Asemmisa {{asɛmmisaAhyɛnsode}}
27.

Why do software updates and patches improve security?

Asemmisa {{asɛmmisaAhyɛnsode}}
28.

Which login setting helps prevent automated password guessing attacks?

Asemmisa {{asɛmmisaAhyɛnsode}}
29.

A host-based firewall is configured to block outbound FTP traffic. What attack does this help prevent?

Asemmisa {{asɛmmisaAhyɛnsode}}
30.

An analyst notices many failed login attempts from one IP address across several user accounts in a short time. This is most likely an indicator of

You are a cybersecurity analyst responsible for monitoring a company’s networks. The company has separate networks for its offices and manufacturing plants. Last month, the office network experienced a cyberattack, but the manufacturing network was not compromised. However, recent monitoring has detected suspicious activity on the manufacturing network.

You have been provided with excerpts from the authorization and system logs for devices on the manufacturing network.

Task:

  1. Review the provided log excerpts carefully.

  2. Identify at least three indicators of compromise (IoCs). For each IoC, describe:

    • What the indicator shows (e.g., unusual login attempts, unexpected processes, or suspicious file activity)

    • Why it suggests the device or network may have been targeted or compromised

  3. Recommend mitigation or protective measures for each IoC you identified. Your recommendations should map directly to the vulnerability or suspicious activity you describe.

Expectations:

  • Write your response in complete sentences with clear explanations.

  • Use cybersecurity terminology appropriately.

  • Focus on technical details, risk assessment, and actionable recommendations.

  • Your response should be structured like a short incident report, but you do not need to follow a rigid template.

Grading (15 points total):

  • Indicator 1: 5 points — 3 points for identifying the IoC correctly, 2 points for explanation of why it is suspicious and recommendation.

  • Indicator 2: 5 points — 3 points for identifying the IoC correctly, 2 points for explanation of why it is suspicious and recommendation.

  • Indicator 3: 5 points — 3 points for identifying the IoC correctly, 2 points for explanation of why it is suspicious and recommendation.

Authorization Server Logs

03:12:45 - Failed login attempt: user=jwilliams, source_ip=198.51.100.87

03:12:47 - Failed login attempt: user=jwilliams, source_ip=198.51.100.87

03:12:50 - Failed login attempt: user=jwilliams, source_ip=198.51.100.87

03:12:52 - Account locked: user=jwilliams

03:45:10 - Successful login: user=msmith, source_ip=203.0.113.29

03:50:23 - Successful login: user=msmith, source_ip=198.51.100.88


Workstation Activity Logs

04:15:12 - New process started: keylogger_installer.exe

04:15:15 - Unexpected service launched: remote_admin_tool

04:16:05 - File created: C:\Users\Public\malware_temp\payload.bin

04:17:48 - Outbound connection established to 203.0.113.45 on port 445


Server File System Logs

04:30:02 - File modified: /srv/data/financials.csv (unexpected timestamp)

04:30:05 - Unauthorized permission change: /srv/data/financials.csv

04:31:10 - Executable detected with hash match: Known RAT signature

5
Asemmisa {{asɛmmisaAhyɛnsode}}
31a.

Define IoC 1:

  • Write your response in complete sentences with clear explanations.

  • Use cybersecurity terminology appropriately.

  • Focus on technical details, risk assessment, and actionable recommendations.

5
Asemmisa {{asɛmmisaAhyɛnsode}}
31b.

Define IoC 2:

  • Write your response in complete sentences with clear explanations.

  • Use cybersecurity terminology appropriately.

  • Focus on technical details, risk assessment, and actionable recommendations.

5
Asemmisa {{asɛmmisaAhyɛnsode}}
31c.

Define IoC 3:

  • Write your response in complete sentences with clear explanations.

  • Use cybersecurity terminology appropriately.

  • Focus on technical details, risk assessment, and actionable recommendations.