Network Security Exam Study Set| 900+ Questions
and Answers (Verified Answers) Latest Update
2024-25
________ attacks take advantage of flawed human judgment by convincing the victim to take
actions that are counter to security policies. - ✔✔Social engineering
The definition of spam is "unsolicited commercial e-mail." - ✔✔TRUE
You receive an e-mail that seems to come from your bank. Clicking on a link in the message
takes you to a website that seems to be your bank's website. However, the website is fake. This
is called a ________ attack. - ✔✔phishing
You receive an e-mail that seems to come from a frequent customer. It contains specific
information about your relationship with the customer. Clicking on a link in the message takes
you to a website that seems to be your customer's website. However, the website is fake. This
is ________. - ✔✔spear fishing
Most traditional external attackers were heavily motivated by ________. - ✔✔the thrill of
breaking in
Most traditional external hackers cause extensive damage or commit theft for money. -
✔✔FALSE
Most traditional external hackers do not cause extensive damage or commit theft for money. -
✔✔TRUE
Traditional hackers are motivated by ________. - ✔✔thrill, validation of power, doing
damage as a by-product
,Attackers rarely use IP address spoofing to conceal their identities. - ✔✔FALSE
In response to a chain of attack, victims can often trace the attack back to the final attack
computer. - ✔✔TRUE
ICMP Echo messages are often used in ________. - ✔✔IP address scanning
Sending packets with false IP source addresses is called ________. - ✔✔IP address spoofing
Attackers cannot use IP address spoofing in port scanning attack packets. - ✔✔TRUE
The primary purpose for attackers to send port scanning probes to hosts is to identify which
ports are open. - ✔✔FALSE
To obtain IP addresses through reconnaissance, an attacker can use ________. - ✔✔a chain
of attack computers
Following someone through a secure door for access without using an authorized ID card or
pass code is called ________. - ✔✔piggybacking
Watching someone type their password in order to learn the password is called ________. -
✔✔shoulder surfing
In pretexting, an attacker calls claiming to be a certain person in order to ask for private
information about that person. - ✔✔TRUE
Social engineering is rarely used in hacking. - ✔✔FALSE
,A(n) ________ attack attempts to make a server or network unavailable to serve legitimate
users by flooding it with attack packets. - ✔✔DoS
Which of the following are examples of social engineering? - ✔✔Wearing a uniform to give
the appearance that you work at a business
Gaining unauthorized access by following an authorized individual in to a business
Generally speaking, script kiddies have high levels of technical skills. - ✔✔FALSE
A(n) ________ attack requires a victim host to prepare for many connections, using up
resources until the computer can no longer serve legitimate users. - ✔✔SYN Flooding
A botmaster can remotely ________. - ✔✔fix a bug in the bots, update bots with new
functionality
Botnets usually have multiple owners over time. - ✔✔TRUE
One of the two characterizations of expert hackers is ________. - ✔✔dogged persistence
Sophisticated attacks often are difficult to identify amid the "noise" of many ________ attacks.
- ✔✔script kiddie
The dominant type of attacker today is the ________. - ✔✔career criminal
Compared to non-computer crime, computer crime is very small. - ✔✔FALSE
Prosecuting attackers in other countries is relatively straightforward under existing computer
crime laws. - ✔✔FALSE
, Cybercriminals avoid black market forums. - ✔✔FALSE
Many e-commerce companies will not ship to certain countries because of a high rate of
consumer fraud. To get around this, attackers use ________. - ✔✔transshippers
Money mules transfer stolen money for criminals and take a small percentage for themselves. -
✔✔TRUE
In fraud, the attacker deceives the victim into doing something against the victim's financial
self-interest. - ✔✔TRUE
________ is form of online fraud when bogus clicks are performed to charge the advertiser
without creating potential new customers. - ✔✔Click fraud
________ threaten to do at least temporary harm to the victim company's IT infrastructure
unless the victim pays the attacker. - ✔✔Extortionists
Identity theft is stealing credit card numbers. - ✔✔FALSE
Stealing credit card numbers is also known as ________. - ✔✔carding
Carding is more serious than identity theft. - ✔✔FALSE
Under current U.S. federal laws, if a company allows personal information to be stolen, it may
be subject to government fines. - ✔✔TRUE
When a company visits a website to collect public information about a competitor, this is a
form of trade secret espionage. - ✔✔FALSE
and Answers (Verified Answers) Latest Update
2024-25
________ attacks take advantage of flawed human judgment by convincing the victim to take
actions that are counter to security policies. - ✔✔Social engineering
The definition of spam is "unsolicited commercial e-mail." - ✔✔TRUE
You receive an e-mail that seems to come from your bank. Clicking on a link in the message
takes you to a website that seems to be your bank's website. However, the website is fake. This
is called a ________ attack. - ✔✔phishing
You receive an e-mail that seems to come from a frequent customer. It contains specific
information about your relationship with the customer. Clicking on a link in the message takes
you to a website that seems to be your customer's website. However, the website is fake. This
is ________. - ✔✔spear fishing
Most traditional external attackers were heavily motivated by ________. - ✔✔the thrill of
breaking in
Most traditional external hackers cause extensive damage or commit theft for money. -
✔✔FALSE
Most traditional external hackers do not cause extensive damage or commit theft for money. -
✔✔TRUE
Traditional hackers are motivated by ________. - ✔✔thrill, validation of power, doing
damage as a by-product
,Attackers rarely use IP address spoofing to conceal their identities. - ✔✔FALSE
In response to a chain of attack, victims can often trace the attack back to the final attack
computer. - ✔✔TRUE
ICMP Echo messages are often used in ________. - ✔✔IP address scanning
Sending packets with false IP source addresses is called ________. - ✔✔IP address spoofing
Attackers cannot use IP address spoofing in port scanning attack packets. - ✔✔TRUE
The primary purpose for attackers to send port scanning probes to hosts is to identify which
ports are open. - ✔✔FALSE
To obtain IP addresses through reconnaissance, an attacker can use ________. - ✔✔a chain
of attack computers
Following someone through a secure door for access without using an authorized ID card or
pass code is called ________. - ✔✔piggybacking
Watching someone type their password in order to learn the password is called ________. -
✔✔shoulder surfing
In pretexting, an attacker calls claiming to be a certain person in order to ask for private
information about that person. - ✔✔TRUE
Social engineering is rarely used in hacking. - ✔✔FALSE
,A(n) ________ attack attempts to make a server or network unavailable to serve legitimate
users by flooding it with attack packets. - ✔✔DoS
Which of the following are examples of social engineering? - ✔✔Wearing a uniform to give
the appearance that you work at a business
Gaining unauthorized access by following an authorized individual in to a business
Generally speaking, script kiddies have high levels of technical skills. - ✔✔FALSE
A(n) ________ attack requires a victim host to prepare for many connections, using up
resources until the computer can no longer serve legitimate users. - ✔✔SYN Flooding
A botmaster can remotely ________. - ✔✔fix a bug in the bots, update bots with new
functionality
Botnets usually have multiple owners over time. - ✔✔TRUE
One of the two characterizations of expert hackers is ________. - ✔✔dogged persistence
Sophisticated attacks often are difficult to identify amid the "noise" of many ________ attacks.
- ✔✔script kiddie
The dominant type of attacker today is the ________. - ✔✔career criminal
Compared to non-computer crime, computer crime is very small. - ✔✔FALSE
Prosecuting attackers in other countries is relatively straightforward under existing computer
crime laws. - ✔✔FALSE
, Cybercriminals avoid black market forums. - ✔✔FALSE
Many e-commerce companies will not ship to certain countries because of a high rate of
consumer fraud. To get around this, attackers use ________. - ✔✔transshippers
Money mules transfer stolen money for criminals and take a small percentage for themselves. -
✔✔TRUE
In fraud, the attacker deceives the victim into doing something against the victim's financial
self-interest. - ✔✔TRUE
________ is form of online fraud when bogus clicks are performed to charge the advertiser
without creating potential new customers. - ✔✔Click fraud
________ threaten to do at least temporary harm to the victim company's IT infrastructure
unless the victim pays the attacker. - ✔✔Extortionists
Identity theft is stealing credit card numbers. - ✔✔FALSE
Stealing credit card numbers is also known as ________. - ✔✔carding
Carding is more serious than identity theft. - ✔✔FALSE
Under current U.S. federal laws, if a company allows personal information to be stolen, it may
be subject to government fines. - ✔✔TRUE
When a company visits a website to collect public information about a competitor, this is a
form of trade secret espionage. - ✔✔FALSE