A gym's front-desk employee receives this email:
"This is Denise from Corporate Billing. Your payroll deposit for this week was rejected due to a system error. Reply immediately with your direct-deposit account number so we can resend before Friday's payroll runs. — Denise"
Which psychological tactic is PRIMARILY at work?
A: Elicitation through friendly small talk
B:Urgency created by a looming payroll deadline.
C: Intimidation through a threat of punishment.
D:Both intimidation and urgency combined equally.
B:Urgency created by a looming payroll deadline.
An adversary writes a script that tries every possible combination of lowercase letters and digits — from "aaaaaa" through "zzzzz9" — against a login form until one works.
Which type of password attack is this?
A:A dictionary attack
B:A brute-force attack.
C:A phishing attack
D:A social engineering attack.
B:A brute-force attack.
A security researcher discovers that an attacker wrote brand-new exploit code to take advantage of a flaw in a company's software — a flaw the company itself didn't know existed.
Which adversary class BEST describes this attacker?
A:Low-skilled adversary, because the flaw was easy to find.
B:High-skilled adversary, because writing new exploit code for a zero-day requires deep technical ability.
C:Low-skilled adversary, because they used a tool downloaded online.
D:High-skilled adversary, because they only targeted a known vulnerability.
B:High-skilled adversary, because writing new exploit code for a zero-day requires deep technical ability.
A scammer clones the voice of a company's CFO using a 30-second clip pulled from an earnings-call video posted online, then calls the finance department requesting an urgent wire transfer.
Which AI-augmented attack is being used?
A:Training-data poisoning.
B:Prompt extraction.
C:Voice cloning for impersonation.
D:AI-powered reconnaissance
C:Voice cloning for impersonation.
A cybersecurity firm's AI tool scans a client's firewall configuration and recommends removing several rules it flags as unnecessary.
What MUST happen before those changes are made?
A:The firm should apply all the changes immediately since the AI found them.
B:A knowledgeable security technician must review each recommendation first
C:The client should be billed for a full audit before any review happens.
D:The AI should wait a week and rescan before suggesting anything.
B:A knowledgeable security technician must review each recommendation first
An online furniture retailer has two unrelated incidents in the same week:
1: a caller pretending to be a delivery driver convinces a warehouse employee to prop open a secured door without checking ID
2: a separate attacker runs an automated scanner against the retailer's website looking for outdated plugins.
Which incident is an example of social engineering?
A:Incident 1 — it manipulates a person into bypassing a security procedure.
B:Incident 2 — because the scan is automated and hard to trace
C:Both incidents equally, since both target the same company
D:Neither incident, because no phishing email or text was involved
A:Incident 1 — it manipulates a person into bypassing a security procedure.
Use the login log below to answer.
Jan 9 22:14:03 Failed login — jsmith — 88.14.201.9
Jan 9 22:14:04 Failed login — jsmith — 88.14.201.9
Jan 9 22:14:05 Failed login — jsmith — 88.14.201.9
Jan 9 22:14:06 Successful login — jsmith — 88.14.201.9
Jan 10 07:52:11 Successful login — jsmith — 174.20.11.3
Which sign of a password attack is shown by the first four lines of this log?
A:Logins from an unknown device.
B: A login at an unusual time of day.
C:A password built from the account owner's personal information.
D:Many failed attempts in a short window.
D:Many failed attempts in a short window.
During a school assembly in the gym, no student's phone can get a cellular or Wi-Fi signal for the entire hour — but the moment the assembly ends and students leave the gym, signal returns to normal.
Which wireless attack is MOST consistent with this pattern?
A:Evil twin access-point attack.
B:War-driving reconnaissance
C:Jamming denial-of-service attack
D:A brute-force password attack
C:Jamming denial-of-service attack
An employee receives a phishing email in flawless, native-sounding French, personalized with details about a project the company announced only two days earlier on LinkedIn.
Which TWO AI-attacks are MOST directly responsible for how effective this email is?
A:LLM-fluent phishing and AI-powered reconnaissance.
B:Training-data poisoning and voice cloning
C:Prompt extraction and AI-enhanced malware coding.
D:Voice cloning and AI-powered reconnaissance
A:LLM-fluent phishing and AI-powered reconnaissance.
Why is AI considered ESSENTIAL, rather than optional, for threat detection at a large organization?
A:AI tools are legally required for any company that handles customer data.
B:The organization generates far more log events per day than analysts could ever review manually, so AI sorts the signal from the noise.
C:AI eliminates every false positive, so analysts never waste time on bad alerts.
D:AI replaces the security team entirely, cutting payroll costs.
B:The organization generates far more log events per day than analysts could ever review manually, so AI sorts the signal from the noise.
Use the email below to answer:
From: helpdesk@schooI-portal-support.net
To: teachers@lincolnhigh.edu
Subject: Immediate Action: Your Gradebook Access Expires Tonight
"Dear Staff Member, our records show your gradebook access will be suspended at midnight due to a licensing update. Click here within the next 3 hours to keep your access active: schooI-portal-support.net/renew. 89% of staff have already renewed. — IT Help Desk"
Which detail is the STRONGEST evidence that this email is a phishing attempt?
A:The greeting reads "Dear Staff Member" instead of using a name.
B:The sender's domain swaps a capital "I" for the lowercase "l" in "school."
C:The email references a licensing update, which schools sometimes do have.
D:The email includes a clear, specific subject line.
B:The sender's domain swaps a capital "I" for the lowercase "l" in "school."
Jan 9 22:14:03 Failed login — jsmith — 88.14.201.9
Jan 9 22:14:04 Failed login — jsmith — 88.14.201.9
Jan 9 22:14:05 Failed login — jsmith — 88.14.201.9
Jan 9 22:14:06 Successful login — jsmith — 88.14.201.9
Jan 10 07:52:11 Successful login — jsmith — 174.20.11.3
The successful login at 22:14:06 came from the same IP as the failed attempts just before it. Which defense would have most directly PREVENTED that login from succeeding, even after the correct password was guessed?
A:Permanently blocking the IP address 88.14.201.9.
B:Requiring multifactor authentication on the account.
C:Logging every attempt for analysts to review later
D:Requiring the account to use a password manager going forward.
B:Requiring multifactor authentication on the account.
A commuter wants to confirm a train station's Wi-Fi is genuine before connecting.
Which action is the MOST RELIABLE way to do this?
A:Join the network with the strongest signal near the platform.
B:Join whichever open (no password) network appears first in the list.
C:Check the station's posted signage or ask an employee for the exact network name and match it character-for-character
D:Join the network that already has the most devices connected to it.
C:Check the station's posted signage or ask an employee for the exact network name and match it character-for-character
An employee pastes a confidential client contract into a free public chatbot to "summarize it faster."
What is the MOST CONCERNING risk of this action?
A:The chatbot will take longer than usual to respond.
B:The chatbot may retain or train on the pasted content, making it potentially extractable later
C:The chatbot will refuse to summarize confidential material
D:The client will be charged an additional service fee
B:The chatbot may retain or train on the pasted content, making it potentially extractable later
A city's IT department uses an AI tool to draft new detection rules for their intrusion-prevention system based on recent attack patterns.
Who must approve those rules before they go live?
A:A knowledgeable detection or security engineer.
B:Any employee with basic computer skills.
C:The city's mayor.
D:No one — the AI's technical accuracy is sufficient on its own
A:A knowledgeable detection or security engineer.
From: helpdesk@schooI-portal-support.net
To: teachers@lincolnhigh.edu
Subject: Immediate Action: Your Gradebook Access Expires Tonight
"Dear Staff Member, our records show your gradebook access will be suspended at midnight due to a licensing update. Click here within the next 3 hours to keep your access active: schooI-portal-support.net/renew. 89% of staff have already renewed. — IT Help Desk"
If a teacher clicks the link and enters their portal username and password on the page that loads, which impact category does this MOST DIRECTLY illustrate?
A:Malware/credential capture leading to account takeover of the gradebook portal
B:A firewall update will install automatically on the teacher's laptop.
C: The school's network administrator will be alerted within seconds.
D:The teacher's paycheck will be delayed until the issue is resolved.
A:Malware/credential capture leading to account takeover of the gradebook portal
Which password is the WEAKEST choice for a student's school email account?
A:A 20-character random string generated and stored by a password manager.
B:A five-word random passphrase like "lantern-otter-brick-window-42."
C:"Mules2027!" — the student's school mascot plus their graduation year.
D:A unique 16-character password used only for this one account.
C:"Mules2027!" — the student's school mascot plus their graduation year.
At the Lincoln Public Library, a student's Wi-Fi list shows two very similar networks: "Lincoln_Library_Public," which requires a password, and "Lincoln Library Public“, which has no password at all and lets anyone join instantly.
Which network is MOST LIKELY the evil twin?
A:Lincoln_Library_Public" — the real network, because it requires a password.
B:Both are equally likely to be fake, since Wi-Fi names can't be trusted at all.
C:Neither — an evil twin always uses the exact same name as the real network
D:"Lincoln Library Public" — the copycat name with no password required.
D:"Lincoln Library Public" — the copycat name with no password required.
A parent receives a video call that looks and sounds exactly like their child, saying they're in trouble and need money sent to an unfamiliar account right away.
Which defense would be MOST effective for the parent to use in the moment?
A:Hang up immediately and never answer that number again
B:Send a small amount of money first to see if it's really them
C:Ask the caller to say a pre-agreed shared secret word or phrase.
D:Ask the caller to move their camera closer to their face.
C:Ask the caller to say a pre-agreed shared secret word or phrase.
An AI-powered SIEM is set to automatically log out any account after three failed multifactor authentication attempts. One night it auto-logs out the on-call network engineer who mistyped their code three times during a real outage, delaying the response.
What does this scenario MOST clearly illustrate?
A:AI should never be allowed to take any automatic action, ever.
B:Automatic AI actions need a human override capability for cases the rule didn't anticipate.
C:The on-call engineer was the actual threat.
D:MFA should be removed from all critical accounts.
B:Automatic AI actions need a human override capability for cases the rule didn't anticipate.
A teacher gets a text from an unrecognized number:
"This is Dr. Romano from the district office. I need the WiFi password for the teacher's lounge for a technician who's on site right now."
Which response BEST reduces the risk that this is social engineering?
A: Send the password, since the request sounds like routine IT work
B: Never respond to any text from an unknown number again
C: Call the district office directly, using a known number, to confirm before responding.
D: Ask the sender to text a selfie as proof of identity
C: Call the district office directly, using a known number, to confirm before responding.
A student reuses the same password across five different sites, including their email and an online shopping site.
Which single change would most reduce their risk going forward?
A:Change the password on the shopping site only, and keep it the same everywhere else.
B:Add extra numbers to the end of the current password on all five sites.
C:Stop using the shopping site, but keep the same password everywhere else.
D:Give every account a unique password, so a breach at one site can't unlock the others.
D:Give every account a unique password, so a breach at one site can't unlock the others.
Use the same library scenario above. The student joins the open "Lincoln Library Public" network — the evil twin — but turns on a reputable VPN before browsing anything.
Which of these BEST describes what the evil-twin operator can still observe?
A:Nothing at all — the VPN fully hides the connection from the local network
B:Every website the student visits, in plain text.
C: The encrypted traffic's size, timing, and connection metadata from before the VPN tunnel started.
D:Only the student's school email login.
C: The encrypted traffic's size, timing, and connection metadata from before the VPN tunnel started.
Which of the following is NOT one of the ways AI augments cyberattacks?
A:Using an AI tool to help pick the lock on a server room door.
B:Using AI to generate fluent phishing text in a victim's native language.
C:Planting false information online so it gets absorbed into an LLM's training data.
D:Using AI coding assistants to discover vulnerabilities in a target's software.
A:Using an AI tool to help pick the lock on a server room door.
Which of the following BEST reflects the human-in-the-loop principle in AI-powered cyber defense?
A:A human expert reviews AI-generated recommendations before they're implemented, and can override automated actions.
B:AI acts independently on every detection to maximize response speed.
C:AI should be used only for reporting, never for any kind of detection.
D:Humans should avoid learning how the AI tool works so it stays unbiased.
A:A human expert reviews AI-generated recommendations before they're implemented, and can override automated actions.