SECURITY CONTROLS
THREAT ACTORS
MALWARE
SOCIAL ENGINEERING
ATTACK STRATEGIES
100

A company installs a security camera to identify unauthorized activity around a building. What functional control type is this?

Detective

100

An employee has legitimate access to company systems and could misuse that access to harm the organization. What type of threat actor is this?

Insider

100

What type of malware disguises itself as a legitimate application while performing malicious activities?

Trojan horse

100

An employee receives an email pretending to be from the IT department. The email asks the employee to run a file and enter a network password. What technique is being used?

Phishing

100

An attacker gathers information about a company's systems and users before launching an attack. What strategy is being used?

Reconnaissance

200

A company uses locked doors, security gates, and lighting to protect its facilities. What security control category is being used?

Physical

200

A hacker attacks a company after the company makes a controversial policy decision. What threat actor is most likely responsible?

Hacktivist

200

A company's files suddenly become encrypted, and the attacker demands payment in exchange for the decryption key. What type of malware is responsible?

Crypto-ransomware

200

A person receives a phone call from someone pretending to represent a bank and asking for financial information. What technique is being used?

Vishing

200

After gaining access, an attacker configures additional rights to gain more access than originally permitted. What strategy is this?

Escalating privileges

300

A company requires employees to follow an Acceptable Use Policy and provides security training. What security control category do these represent?

Operational

300

An attacker carries out an attack using scripts or programs created by more experienced hackers. What type of threat actor is this?

Script kiddie

300

What type of malware is installed alongside software selected by the user or bundled with a computer?

Bloatware

300

An attacker researches an employee, starts communicating with them, builds trust, and then asks them to open a suspicious attachment. Which phase of the social engineering process involves the attacker building the relationship?

Development

300

An attacker penetrates a system's defenses to gain unauthorized access. What strategy is this?

Breaching

400

A security manager wants to implement controls that discourage attackers from attempting to breach the network. What functional control type should be used?

Deterrent

400

A highly resourced attacker conducts a systematic campaign with strategic objectives intended to influence or undermine an organization. What type of motivation is most closely associated with this scenario?

Political

400

A malicious program monitors what a user does on a computer and sends the information to another source. What type of malware is this?

Spyware

400

An attacker has researched an employee, built a relationship, and now sends a malicious attachment hoping the employee will open it. What phase is the attacker in?

Exploitation

400

An attacker uses a vulnerability to steal information, crash systems, or deny services. What general attack strategy is being used?

Exploitation

500

A network administrator needs to prevent employees from accessing unapproved streaming websites. What security control category would a web-filtering system fall under?

Technical

500

A company wants to reduce the risk of employees misusing their authorized access. Which security measures would help prevent insider threats?

You must name two of the three security measures.

Least privilege

Onboarding/off-boarding procedures

Physical security controls

500

A company’s employee installs a malicious program that remains inactive on the computer. The program is designed to delete critical files only after a specific date is reached or a particular event occurs. What type of malware is this?

Logic bomb

500

A threat actor tells a janitor they forgot their badge at home to gain access to a restricted building area. What social engineering technique is being used?

Pretexting

500

An attacker prepares a compromised computer to perform additional tasks during the attack. What strategy is this?

Staging

M
e
n
u