Chapter 03: Cyberattacks and Cybersecurity
d.
Hacktivists
37. A type of computer crime perpetrator whose primary motive is to achieve financial gain is known as which
of the following?
a.
industrial spy
b.
hacktivist
c.
black hat hacker
d.
cybercriminal
38. Software and/or hardware that monitors system and network resources and activities, and notifies network
security personnel when it identifies network traffic that attempts to circumvent the security measures of a
networked computer environment is known as which of the following?
a.
b.
c.
d.
39. Which of the following is a form of Trojan horse which executes when it is triggered by a specific event
such as a change in a particular file, by typing a specific series of keystrokes, or by a specific time or date?
Chapter 03: Cyberattacks and Cybersecurity
a.
denial-of-service attack
b.
logic bomb
c.
botnet
d.
rootkit
40. In computing, a term for any sort of general attack on an information system that takes advantage of a
particular system vulnerability is known as which of the following?
a.
exploit
b.
patch
c.
firewall
d.
security audit
41. An antivirus software scans for a specific sequence of bytes that indicates the presence of specific malware.
This sequence of bytes is known as which of the following?
a.
script kiddie
b.
virus signature
c.
CAPTCHA
d.
Trojan horse
Chapter 03: Cyberattacks and Cybersecurity
42. A business policy that permits employees to use their own mobile devices to access company computing
resources and applications is known as which of the following?
a.
USA Patriot Act
b.
Bring your own device (BYOD)
c.
Mobile Alliance Policy (MAP)
d.
CAPTCHA
43. What type of attack keeps the target so busy responding to a stream of automated requests that legitimate
users cannot get in?
a.
spam
b.
rootkit
c.
logic bomb
d.
distributed denial-of-service
44. Many organizations use software to provide a comprehensive display of all key performance indicators
related to an organization’s security defenses, including threats, exposures, policy compliance, and incident
alerts. What is this type of software known as?
a.
firewall
b.
security dashboard
c.
intrusion detection software
d.
proxy server software
Chapter 03: Cyberattacks and Cybersecurity
45. Malware that stops you from using your computer or accessing your data until you meet certain demands is
known as which of the following?
a.
trojan horse
b.
worm
c.
ransomware
d.
phishing
46. Which organization offers a number of security-related policy templates that can help an organization
quickly develop effective security policies?
a.
Department of Homeland Security
b.
IEEE
c.
SANS Institute
d.
US-CERT
47. The most common computer security precaution taken by businesses is the installation of which of the
following?
a.
emergency response team
b.
rootkit
c.
virtual private network
d.
firewall
Chapter 03: Cyberattacks and Cybersecurity
48. Which term is defined as an exploit that takes place before the security community or software developer
knows about the vulnerability or has been able to repair it?
a.
logic bomb
b.
DDoS attack
c.
zero-day attack
d.
rootkit
49. The act of fraudulently using email to try to get the recipient to reveal personal data is known as which of
the following?
a.
Pharming
b.
Phishing
c.
Spamdexing
d.
Flyposting
50. Which type of exploit is defined as the sending of fraudulent emails to an organization’s employees
designed to look like they came from high-level executives from within the organization?
a.
Spamdexing
b.
Vishing
c.
Smishing
d.
Spear phishing
Chapter 03: Cyberattacks and Cybersecurity
51. The intimidation of government or civilian population by using information technology to disable critical
national infrastructure in order to achieve political, religious, or ideological goals is known as which of the
following?
a.
whistleblowing
b.
cyberterrorism
c.
hacktivism
d.
cyberespionage
52. Which of the following enables remote users to securely access an organization’s collection of computing
and storage devices and share data remotely?
a.
firewall
b.
social network
c.
intrusion detection device
d.
virtual private network
53. Before the IT security group can begin an eradication effort, it must:
a.
seek permission of the firm’s legal counsel
b.
collect and log all possible criminal evidence from the system
c.
consider the potential for negative publicity
d.
develop an estimate for the monetary damage caused
Chapter 03: Cyberattacks and Cybersecurity
54. A piece of programming code, usually disguised as something else, that causes a computer to behave in an
unexpected and usually undesirable manner is known as which of the following?
a.
virus
b.
operating system
c.
zombie
d.
CAPTCHA
55. Many organizations outsource their network security operations to a company that monitors, manages, and
maintains computer and network security for them. This type of company is known as which of the following?
a.
security dashboard
b.
computer forensics
c.
managed security service provider
d.
product lifecycle management
Subjective Short Answer
56. Define computer forensics and briefly describe how one may prepare for a role as a computer forensics
investigator.
Chapter 03: Cyberattacks and Cybersecurity
57. Briefly describe ransomware and how a computer typically becomes infected with this type of malware.
58. Identify and briefly discuss five reasons why the number, variety, and impact of security incidents is
increasing.
Chapter 03: Cyberattacks and Cybersecurity
Chapter 03: Cyberattacks and Cybersecurity
59. State the purpose of an IT security audit and briefly discuss the key elements of such an audit.
60. Briefly explain why many organizations are choosing to outsource their network security operations to a
managed security service provider (MSSP).
Chapter 03: Cyberattacks and Cybersecurity