A corporation employs a group of experienced cybercriminals to establish a prolonged, in-depth presence within a competitor's network. This presence enables the corporation to steal or sabotage sensitive data belonging to that competitor.
What type of attack does this scenario depict?
ADDoS
BRansomware
CMan-in-the-middle
DAPT
0
Community Discussion
No comments yet. Be the first to start the discussion!
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Save question
0
Community Discussion
No comments yet. Be the first to start the discussion!
Employees in a company’s accounting department receive an email about the newest federal accounting regulations. The email includes a hyperlink to register for a webinar that provides the latest updates on financial transaction security. The webinar is hosted by a government agency. As a security officer, you notice that the hyperlink directs to an unknown party.
Which type of cybersecurity threat should you investigate?
ASpear phishing
BRansomware
CSmishing
DVishing
For each statement, select True when it adheres to the cybersecurity code of ethics; otherwise, select False.
True or False
Statements
True
False
A security analyst may use a disgruntled employee's network credentials to monitor behavior.
A security analyst may access employee data on a company server if authorized.
A security analyst may share sensitive data with unauthorized users.
Which adversary activity is an example of an exploit intended to obtain user credentials?
AObtaining a directory listing of files located on the web database server
BInstalling a backdoor in order to enable two-way communication with the device
CExecuting a remote port scan of all of the enterprise-registered IP addresses
DSending an email with a link to a fictitious web portal login page
To access online banking, you enter a strong password and then provide the 5-digit code sent to your smartphone.
What type of authentication does this situation represent?
AMultifactor
BVPN
CRADIUS
DAAA
Match each definition on the left with the appropriate CIA Triad term on the right.
Partial credit is awarded for every correct match.
Drag & Drop
Legitimate requests should have access to data at all times.
Data should never be altered or compromised.
Data should be accessed and read only by authorized users.
Confidentiality
Integrity
Availability
Which wireless encryption technology requires AES to protect home wireless networks?
AWPA
BTKIP
CWPA2
DWEP
You need to restrict the websites that employees can access on the company network.
Which type of device should you deploy?
AIPS
BProxy server
CIDS
DHoneypot
Which two private IPv4 addresses should be blocked on the Internet to avoid security and performance issues?
Note: You will receive partial credit for each correct selection.
Choose two
A203.0.113.168
B192.168.18.189
C224.0.2.172
D172.18.100.78
You must transfer configuration files to a router over an unsecured network.
Which protocol should be used to encrypt the files while they are in transit?
ATFTP
BHTTP
CSSH
DTelnet
Several employees report that the company intranet site no longer accepts their login credentials. You try connecting with the URL and observe misspellings on the site. When you connect using the IP address, the site works normally.
What should you do?
ARestore a backup copy of the authentication database.
BVerify the accuracy of the entry for the site in the local DNS server.
CTake the company web portal offline immediately.
DUpdate the web server software to the latest version.
Customers of an online shopping store report that they cannot access the website. As an IT technician, you restart the site. After 30 minutes, the website crashes once more. You suspect the website has suffered a cyberattack.
Which type of cybersecurity threat should you investigate?
ARansomware
BSocial engineering
CDenial of service
DSpear phishing
A system on your network is showing slower-than-normal response times. To collect information about the system's status, you run the netstat -1 command to display all TCP ports in the Listening state.
What does the Listening state indicate for these ports?
AThe state of the connection on the ports is unknown.
BThe remote end disconnected and the ports are closing.
CThe ports are open on the system and are waiting for connections.
DThe ports are actively connected to another system or process.
While reviewing the company’s remote-access procedures, you discover that Telnet is used to connect to the corporate database server to check inventory levels.
Which two actions should you take immediately?
Note: You will receive partial credit for each correct selection.
Choose two
AReconfigure the server to only accept HTTP connections.
BImplement SSH access on the server.
CDisable telnet access on the server.
DForce users to implement secure telnet passwords.
What should be created to prevent spoofing on the internal network?
AA DNS record
BAn ACL
CA record in the host file
DA NAT rule
What command shows both the configured DNS server details and the IP address resolution for a URL?
Aping
Btraceroute
CNmap
Dnslookup
You need to enable employees to access your company’s secure network while working from home.
Which type of security should you implement?
AIDS
BSNMP
CBYOD
DVPN
Your home network appears to have slowed down significantly. In the home router GUI, you notice that an unknown host is connected to the network.
What should you do to stop this specific host from connecting to the network again?
ABlock the host IP address.
BChange the network SSID.
CImplement MAC address filtering.
DCreate an IP access control list.
What allows the network security team to track the operating-system versions, security updates, and patches on end users’ devices?
AAsset management
BIncident management
CSecurity policies and procedures
DBusiness continuity planning
You are a security technician who has just completed a full scan on a Windows 10 PC.
Where should you go to view the scan results?
AWindows Task Manager
BWindows Application Logs
CWindows Security
DWindows System Logs
A security analyst determines that a hacker gained root access to an enterprise Linux server. The hacker accessed the server as a guest, used a program to bypass the root password, and then, as the root user, killed essential server processes.
Community Discussion