1
2
3
4
Threats and Vulnerabilities
100

What does DLP do ?

It prevents data from getting stolen/lost

100

What is a script kiddie ?

Script Kiddies are people who don't know how to really hack, they just copy paste other peoples scripts.

100

What is MAC Spoofing Attack

A MAC spoofing attack is where the intruder sniffs the network for valid MAC addresses and attempts to act as one of the valid MAC addresses.

100

What is a hacktivist ?

A hacktivist is someone who hacks for a cause that they believe in usually a political reason.

100

What is Click Jacking ?

Malicious act of manipulating a website user's activity by concealing hyperlinks beneath legitimate clickable content, thereby causing the user to perform actions of which they are unaware.

200

What does delay based filtering do ?

Adds a delay between opening the connection and the websites welcome banner.  Any spam on the site will not wait for this delay and will be immediately flagged and dropped as soon as it comes through before the welcome banner. Also works with emails but is less common.

200

What is SSL/TLS?

Protocols for establishing authenticated and encrypted links between networked computers.

200

What does IKE stand for ?

Internet Key Exchange


200

How do Spam filters operate? (Cannot simply say "blocks spam")

Spam filters detect unsolicited, unwanted, and virus-infested email (called spam) and stop it from getting into email inboxes

200

Difference between Blue-jacking and Blue-snarfing ?

Blue-Jacking is used to send anonymous messages to devices which have an active Bluetooth connection. 

Blue-Snarfing on the other hand is used to steal information from Bluetooth activated devices.

300

What is Network Mapping ?

  • Discovers devices on the network and how they are connected.

  • Is often done apart of a network scan but is focused on connectivity.

300

What is a rouge access point ?

A rogue access point is a device not by an administrator, but is operating on the network anyway. This could be an access point set up by either an employee or by an intruder. The access point could also belong to a nearby company.

300

What is a flood guard ?

Flood guards are tools that you can use to prevent Denial-of-Service (DoS) attacks. ... It is designed to detect network floods and then block this traffic. Flood guards help block malicious traffic from entering a network.

300

What is a HoneyPot ?

 honeypot works in a similar way, baiting a trap for hackers. It mimics a target for hackers, and uses their intrusion attempts to gain information about cybercriminals and the way they are operating or to distract them from other targets. 

In simpler terms it creates its own fake work that the hacker can play arround with without realizing it.

300

What type of file on your hard drive stores preferences from web sites?

Cookie

400

What is a Protocol Analyzer ? (Cannot say it analyzes protocols.)

A protocol analyzer is simply a tool (hardware or software) that can be used to capture and analyze traffic passing over a communications channel, such as a network.

400

What a Hardware Security Module (HSM) and what does it do ?

A hardware security module (HSM) is a physical computing device that safeguards and manages digital keys, performs encryption and decryption functions for digital signatures, strong authentication and other cryptographic functions.

400

What is SSH and what does it do?

SSH or Secure Shell is a network communication protocol that executes commands securely and enables two computers to communicate

400

What is a bridge on OSI layer two ?

It operates by connecting two separate network segments and allows communication between the two segments on the layer 2 address on a packet.

400

Botnets can be used to set what type of coordinated attack in motion ?

Distributed Denial of Service (DDoS)


600

What is the difference between an Offline Password Cracker and an Online Password Cracker ?

  • Offline crackers attempt to discover passwords by analyzing a database or files to discover a code

  • Online attempts to discover passwords by using a Brute Force Attack (Guessing all possible combinations)

600

What are the 7 layers of the OSI model?

  • Physical Layer
  • Data Link Layer
  • Network Layer
  • Transport Layer
  • Session Layer 
  • Presentation Layer
  • Application Layer
600

While cleaning out his desk, Diego threw several papers containing Personal Identifiable Information (PII) into the recycling bin. Which type of attack can exploit this action.

Dumpster Diving

M
e
n
u