Twa kɔ nsɛm atitiriw so
Log in
Sign up for FREE
arrow_back
Laabri

AP Cybersecurity: 5.6A - CFUs

star
star
star
star
star
Last updated about 3 hours ago
20 Nsɛmmisa
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
1
Asemmisa {{asɛmmisaAhyɛnsode}}
1.

A system administrator reviews the following log entries:

User: jsmith | 1:10 PM | Accessed email
User: jsmith | 2:45 AM | Accessed payroll.xlsx
User: jsmith | 2:47 AM | Copied payroll.xlsx

Which activity is the strongest indicator of suspicious behavior?

Asemmisa {{asɛmmisaAhyɛnsode}}
2.

A cybersecurity analyst notices a user accessing files from a new country at an unusual time. What makes this suspicious?

Asemmisa {{asɛmmisaAhyɛnsode}}
3.

A honeypot file named “credit_cards.txt” is accessed by a user. Why is this a strong indicator of malicious activity?

Asemmisa {{asɛmmisaAhyɛnsode}}
4.

A company uses honeypots to detect attackers. What is the main purpose of a honeypot?

Asemmisa {{asɛmmisaAhyɛnsode}}
5.

A file is hashed and produces the same hash value every time it is checked. What does this indicate?

Asemmisa {{asɛmmisaAhyɛnsode}}
6.

A file originally has a hash of ABC123. Later, its hash is DEF456. What is the most likely explanation?

Asemmisa {{asɛmmisaAhyɛnsode}}
7.

A student claims that if two files look identical, they must have the same contents. Why is hashing more reliable than visual inspection?

Asemmisa {{asɛmmisaAhyɛnsode}}
8.

Which situation best demonstrates suspicious activity based on access logs?

Asemmisa {{asɛmmisaAhyɛnsode}}
9.

A cybersecurity analyst sees the following:

User: rpatel | 3:00 PM | Accessed project.docx

User: rpatel | 3:05 PM | Logged out

Why is this activity likely not suspicious?

Asemmisa {{asɛmmisaAhyɛnsode}}
10.

A company records the hash of a file today and compares it to the hash of the same file next week. Why do they do this?

Asemmisa {{asɛmmisaAhyɛnsode}}
11.

A user runs the command “sha256sum data.csv” twice and gets different results. What should they conclude?

Asemmisa {{asɛmmisaAhyɛnsode}}
12.

Which of the following best describes a cryptographic hash function?

Asemmisa {{asɛmmisaAhyɛnsode}}
13.

A system shows no unusual login times or locations, but a file’s hash has changed. What does this suggest?

Asemmisa {{asɛmmisaAhyɛnsode}}
14.

Which of the following is an example of suspicious behavior based on user patterns?

Asemmisa {{asɛmmisaAhyɛnsode}}
15.

A honeypot file is never accessed. What can be concluded?

Asemmisa {{asɛmmisaAhyɛnsode}}
16.

Which command would generate a SHA256 hash on a Windows system?

Asemmisa {{asɛmmisaAhyɛnsode}}
17.

A user argues that accessing a honeypot file could be normal behavior. Why is this incorrect?

Asemmisa {{asɛmmisaAhyɛnsode}}
18.

A company notices a user copying large amounts of sensitive data. Why is this considered suspicious?

Asemmisa {{asɛmmisaAhyɛnsode}}
19.

Which situation provides the strongest evidence that an attack has occurred?

Asemmisa {{asɛmmisaAhyɛnsode}}
20.

A file’s hash remains the same before and after being shared with another user. What does this indicate?