Intro to Network Security Flashcards
A user that does not want to be identified while communicating on a network uses an application to alter the computer’s identity.
Which type of exploit is being perpetrated?
Spoofing
An attacker attempts to misdirect traffic on a network back to the attacker by corrupting the network computer’s cache of IP address to MAC address mappings that are cached.
Which exploit is the attacker perpetrating?
ARP poisoning
Which exploit actually breaches the physical medium or uses devices to monitor signals from outside the physical medium itself?
Wiretapping
Which type of attack can overwhelm a web server by inserting more data into a web form than the system was configured to hold?
Buffer overflow
Which type of attack sends an email claiming to be from a reputable business in order to entice the recipient to provide sensitive information?
Phishing
A user on a network is planning to launch an exploit against a coworker in a neighboring department. The user needs to identify the IP address of a coworker in the desired department.
Which tool or utility will allow the user to watch network traffic in real time to identify a target?
Sniffer
Which group of attackers is typically used for penetration testing?
Red team
Which type of attack exploits an unpatched software vulnerability?
Zero-day
A company has the policy that all new user passwords are P@ssw0rd but does not require new users to change their password. An employee randomly tries a coworker’s account with the new user password to see if they can log in as the coworker.
Which type of vulnerability does this create?
Default password
An employee that does not want to miss emails from important clients sets up her cellular smartphone to allow her to check email. Unfortunately, she does not install antivirus software on the cellular phone.
What type of vulnerability is represented?
BYOD/Mobile
What is required to establish a secure connection to a remote network over an insecure link?
Virtual Private Network (VPN) service
An organization is concerned about brute force attacks.
How should the organization counter this risk?
Institute a log-in policy that locks users out of an account after three failed password attempts.
An organization suffers a social engineering attack that results in a cybercriminal gaining access to its networks and to its customers’ private information.
How can the organization mitigate this risk in the future?
Provide regular cybersecurity training for employees
An attacker plans to exploit flaws in an operating system to gain access to a user’s computer system.
What is a prevention mechanism for this type of attack?
Patching
An unauthorized third-party has gained access to a company network.
How can they be prevented from deleting data?
Access controls