Chapter 03: Cyberattacks and Cybersecurity
True / False
1. Vishing frequently leads consumers to counterfeit Web sites designed to trick them into initiating a denial-of-
service attack.
a.
True
b.
False
2. The Fifth Amendment regulates the collection of the content of wire and electronic communications.
a.
True
b.
False
3. Today’s computer menace is much better organized and may be part of an organized group.
a.
True
b.
False
4. Computer viruses differ from worms in that viruses can propagate without human intervention, often sending
copies of themselves to other computers by email.
a.
True
b.
False
Chapter 03: Cyberattacks and Cybersecurity
DATE MODIFIED:
8/2/2017 1:26 PM
5. The cost to repair the worldwide damage done by a computer worm has exceeded $1 billion on more than
one occasion.
a.
True
b.
False
ANSWER:
DIFFICULTY:
QUESTION TYPE:
True / False
HAS VARIABLES:
DATE MODIFIED:
8/2/2017 1:26 PM
6. Ransomware is malware that stops you from using your computer or accessing your data until you meet
certain demands, such as paying a ransom or sending photos to the attacker.
a.
True
b.
False
POINTS:
DIFFICULTY:
QUESTION TYPE:
True / False
DATE CREATED:
8/2/2017 1:26 PM
DATE MODIFIED:
8/11/2017 1:46 PM
7. The Controlling the Assault of Non-Solicited Pornography and Marketing (CAN-SPAM) Act states that it is
legal to spam, provided the messages meet a few basic requirements.
a.
True
b.
False
POINTS:
REFERENCES:
Types of Exploits
QUESTION TYPE:
True / False
DIFFICULTY:
QUESTION TYPE:
True / False
HAS VARIABLES:
Chapter 03: Cyberattacks and Cybersecurity
8. A spear phishing attack typically employs a group of zombies to keep the target so busy responding to a
stream of automated requests that legitimate users cannot access the target.
a.
True
b.
False
9. Rootkit is a set of programs that enables its users to gain administrator-level access to a computer without the
end user’s consent or knowledge.
a.
True
b.
False
10. Trojan horse has become an umbrella term for many types of malicious code.
a.
True
b.
False
11. The cost of creating an email campaign for a product or a service is typically more expensive and takes
longer to conduct than a direct-mail campaign.
a.
True
Chapter 03: Cyberattacks and Cybersecurity
b.
False
12. Bring your own device (BYOD) is a business policy that permits, and in some cases encourages, employees
to use their own mobile devices (smartphones, tablets, or laptops) to access company computing resources and
applications.
a.
True
b.
False
13. Cyberterrorism involves the deployment of malware that secretly steals data in the computer systems of
organizations, such as government agencies, military contractors, political organizations, and manufacturing
firms.
a.
True
b.
False
14. After virus eradication, you can use a previous backup to restore an infected computer.
a.
True
b.
False
Chapter 03: Cyberattacks and Cybersecurity
15. Cyberterrorism is the intimidation of government or civilian population by using information technology to
disable critical national infrastructure to achieve political, religious, or ideological goals.
a.
True
b.
False
16. A completed risk assessment identifies the most dangerous threats to a company and helps focus security
efforts on the areas of highest payoff.
a.
True
b.
False
17. A security policy outlines exactly what needs to be done to safeguard computers and their data, but not how
it must be accomplished.
a.
True
b.
False
Chapter 03: Cyberattacks and Cybersecurity
18. Whenever possible, automated system rules should mirror an organization’s written policies.
a.
True
b.
False
19. Employees and contract workers must be educated about the importance of security so that they will be
motivated to understand and follow the security policies.
a.
True
b.
False
20. Computer forensics is such a new field that there is little training or certification processes available.
a.
True
b.
False
21. Installation of a corporate firewall is the least common security precaution taken by businesses as it does not
provide sufficient security.
a.
True
b.
False
Chapter 03: Cyberattacks and Cybersecurity
22. A router is a hardware- or software-based network security system that is able to detect and block
sophisticated attacks by filtering network traffic dependent on the packet contents.
a.
True
b.
False
23. It is not unusual for a security audit to reveal that too many people have access to critical data and that many
people have capabilities beyond those needed to perform their jobs.
a.
True
b.
False
24. Even when preventive measures are implemented, no organization is completely secure from a determined
computer attack.
a.
True
b.
False
Chapter 03: Cyberattacks and Cybersecurity
25. Discussing security attacks through public trials and the associated publicity has not only enormous
potential costs in public relations but real monetary costs as well.
a.
True
b.
False
Multiple Choice
26. Often a successful attack on an information system is due to poor system design or implementation. Once
such a vulnerability is discovered, software developers quickly create and issue which of the following, in order
to eliminate the problem?
a.
patch
b.
bot
c.
rootkit
d.
Trojan horse
27. Which of the following is a partnership between the Department of Homeland Security and the public and
private sectors, established in 2003 to protect the nation’s Internet infrastructure against cyberattacks?
a.
Carnegie Mellon’s Computer Response Team
b.
U.S. Computer Emergency Readiness Team
c.
The National Institute of Standards and Technology
d.
The Science and Technology Directorate of Homeland Security
Chapter 03: Cyberattacks and Cybersecurity
28. Which of the following gets a rootkit installation started and can be easily activated by clicking on a link to
a malicious Web site in an email or opening an infected PDF file?
a.
logic bomb
b.
zombie
c.
dropper code
d.
loader
29. Which of the following concepts recognizes that managers must use their judgment to ensure that the cost of
control does not exceed the system’s benefits or the risks involved?
a.
competitive intelligence
b.
reasonable assurance
c.
separation of duties
d.
risk assessment
30. Which of the following is a federal law that provides a definition of the term cyberterrorism and under
which young people primarily involved in what they consider to be minor computer pranks have been tried as
cyberterrorist?
a.
USA Patriot Act
b.
Computer Fraud and Abuse Act
c.
Stored Wire and Electronic Communications and Transactional Records Access Statutes
d.
Identity Theft and Assumption Deterrence Act
Chapter 03: Cyberattacks and Cybersecurity
31. What type of viruses have become a common and easily created form of malware that are created using
applications such as Visual Basic or VBScript?
a.
Macro viruses
b.
Logic bombs
c.
Trojan horses
d.
Zombies
32. The fundamental problem with trying to detect a rootkit is that the operating system cannot be trusted to
provide which of the following?
a.
valid test results
b.
correct system login ids
c.
the correct date and time
d.
sufficient memory for operations
33. What exploit is characterized as the abuse of email systems to send unsolicited email to large numbers of
people?
a.
A botnet
b.
Spam
c.
Logic bombing
d.
A worm
Chapter 03: Cyberattacks and Cybersecurity
34. A network attack in which an intruder gains access to a network and stays there, undetected, with the
intention of stealing data over a long period of time is known as which of the following?
a.
DDoS
b.
APT
c.
rootkit
d.
trojan horse
35. Spammers can defeat the registration process of free email services by launching a coordinated attack that
can sign up for thousands of untraceable email accounts. What is this type of attack known as?
a.
distributed denial-of-service attack
b.
bot attack
c.
CAPTCHA attack
d.
logic bomb
36. Which type of attacker hacks computers or websites in an attempt to promote a political ideology?
a.
Industrial spies
b.
Hackers
c.
Cyberterrorists