NETW 450 Quiz Week 1 through Week 7
WEEK 1
1. Question :
(TCO 1) Which attack type is most often associated with the use of
social engineering?
Student Answer: Unauthorized access
Session fragment
Data manipulation
Malicious applets
Instructor
Access attacks can be initiated by gathering information via social
Explanation:
engineering.
Points Received: 3 of 3
Comments:
Question 2. Question :
(TCO 1) The agents used in a distributed denial of service attack are
called .
Student Answer: zombies
vampires
werewolves
Smurfs
Instructor
These agents are called zombies, robots, or bots.
Explanation:
Points Received: 0 of 3
Comments:
,Question 3. Question :
(TCO 1) Ping scans and port scans are tools used for an attack
method called .
Student Answer: repudiation
reconnaissance
masquerading
denial of service (DoS)
Instructor
The attempt to gather information about a network is called a
Explanation:
reconnaissance attack.
Points Received: 3 of 3
Comments:
Question 4. Question :
(TCO 1) The attack method modifies the IP header to indicate
that there are more data than there actual are.
Student Answer: Ping of Death
SYN flood
Smurf
Land.c
Instructor
A Ping of Death attack is a fragmented ICMP attack that sends more data than
Explanation:
a router can handle.
Points Received: 0 of 3
Comments:
Question 5. Question :
(TCO 1) The component of network security that ensures that data
being sent or received cannot be read by unauthorized users is
.
, Student Answer: data integrity
data confidentiality
data and system availability
data and user authentication
Instructor
Data confidentiality is accomplished using encryption algorithms, such as
Explanation:
DES, 3DES, and AES.
Points Received: 3 of 3
Comments:
Question 6. Question :
(TCO 1) The component of network security that ensures that data
being sent or received have not been corrupted or modified in transit
is .
Student Answer: data integrity
data confidentiality
data and system availability
data and user authentication
Instructor
Data integrity is tested at Layer 2 with a CRC field in a frame; data integrity at
Explanation:
higher layers uses an MD5 or SHA hash algorithm.
Points Received: 3 of 3
Comments:
Question 7. Question :
(TCO 1) The type of security control that makes use of security audits
and tests is called .
Student Answer: administrative
, physical
technical
clerical
Instructor
The use of audits and tests must be performed as mandated in the
Explanation:
administrative section of the security policy.
Points Received: 3 of 3
Comments:
Question 8. Question :
(TCO 1) An external menace to a system or its design is called a(n)
.
Student Answer: vulnerability
threat
risk
exploit
Instructor
A weakness becomes a threat when the weakness is known to an external
Explanation:
entity.
Points Received: 3 of 3
Comments:
WEEK 2
1. Question :
(TCO 2) Which of the following prompts indicates that you have
booted (normally) into the IOS stored in Flash memory?
Student Answer: Router>
WEEK 1
1. Question :
(TCO 1) Which attack type is most often associated with the use of
social engineering?
Student Answer: Unauthorized access
Session fragment
Data manipulation
Malicious applets
Instructor
Access attacks can be initiated by gathering information via social
Explanation:
engineering.
Points Received: 3 of 3
Comments:
Question 2. Question :
(TCO 1) The agents used in a distributed denial of service attack are
called .
Student Answer: zombies
vampires
werewolves
Smurfs
Instructor
These agents are called zombies, robots, or bots.
Explanation:
Points Received: 0 of 3
Comments:
,Question 3. Question :
(TCO 1) Ping scans and port scans are tools used for an attack
method called .
Student Answer: repudiation
reconnaissance
masquerading
denial of service (DoS)
Instructor
The attempt to gather information about a network is called a
Explanation:
reconnaissance attack.
Points Received: 3 of 3
Comments:
Question 4. Question :
(TCO 1) The attack method modifies the IP header to indicate
that there are more data than there actual are.
Student Answer: Ping of Death
SYN flood
Smurf
Land.c
Instructor
A Ping of Death attack is a fragmented ICMP attack that sends more data than
Explanation:
a router can handle.
Points Received: 0 of 3
Comments:
Question 5. Question :
(TCO 1) The component of network security that ensures that data
being sent or received cannot be read by unauthorized users is
.
, Student Answer: data integrity
data confidentiality
data and system availability
data and user authentication
Instructor
Data confidentiality is accomplished using encryption algorithms, such as
Explanation:
DES, 3DES, and AES.
Points Received: 3 of 3
Comments:
Question 6. Question :
(TCO 1) The component of network security that ensures that data
being sent or received have not been corrupted or modified in transit
is .
Student Answer: data integrity
data confidentiality
data and system availability
data and user authentication
Instructor
Data integrity is tested at Layer 2 with a CRC field in a frame; data integrity at
Explanation:
higher layers uses an MD5 or SHA hash algorithm.
Points Received: 3 of 3
Comments:
Question 7. Question :
(TCO 1) The type of security control that makes use of security audits
and tests is called .
Student Answer: administrative
, physical
technical
clerical
Instructor
The use of audits and tests must be performed as mandated in the
Explanation:
administrative section of the security policy.
Points Received: 3 of 3
Comments:
Question 8. Question :
(TCO 1) An external menace to a system or its design is called a(n)
.
Student Answer: vulnerability
threat
risk
exploit
Instructor
A weakness becomes a threat when the weakness is known to an external
Explanation:
entity.
Points Received: 3 of 3
Comments:
WEEK 2
1. Question :
(TCO 2) Which of the following prompts indicates that you have
booted (normally) into the IOS stored in Flash memory?
Student Answer: Router>