Midterm Quiz No. 1
Which type of vulnerability can be caused by leaving default accounts active?
Correct answer: Misconfigurations
Correct answer: Misconfigurations
Which of the following is an example of a network vulnerability?
Correct answer: Weak passwords
Correct answer: Weak passwords
Which of the following is an example of a network threat?
Correct answer: SQL injection attacks
Correct answer: SQL injection attacks
You notice that your computer is running slower than usual and there are frequent pop-up advertisements appearing on your screen. What might be the cause?
Correct answer: Malware or adware infection on your computer.
Correct answer: Malware or adware infection on your computer.
Which of the following is a common type of password attack?
Correct answer: Brute force attacks
Correct answer: Brute force attacks
While accessing a website, you notice that the URL does not start with "https://" and there is no padlock icon in the browser's address bar. What does this indicate?
Correct answer: The website does not have a valid SSL certificate and may not be secure.
Correct answer: The website does not have a valid SSL certificate and may not be secure.
What is the main cause of major security breaches?
Correct answer: Outdated or unpatched software
Correct answer: Outdated or unpatched software
You receive an email from your coworker with an attachment that claims to be an important document related to your project. What should you do
Correct answer: Verify with your coworker through a separate communication channel before opening the attachment.
Correct answer: Verify with your coworker through a separate communication channel before opening the attachment.
You receive an email from an unknown sender with an urgent subject line, asking you to click on a link to verify your account details. What should you do
Correct answer: Delete the email without clicking on any links or providing any information.
Correct answer: Delete the email without clicking on any links or providing any information.
What is the purpose of malware
Correct answer: To delete important files and steal confidential information
Correct answer: To delete important files and steal confidential information
What makes zero-day vulnerabilities particularly dangerous
Correct answer: They are previously unknown and unpatched by the vendor
Correct answer: They are previously unknown and unpatched by the vendor
What is the purpose of regular vulnerability scans
Correct answer: To identify and remediate network vulnerabilities
Correct answer: To identify and remediate network vulnerabilities
What type of vulnerability is a weakness that has not been patched by the vendor
Correct answer: Zero-day vulnerabilities
Correct answer: Zero-day vulnerabilities
What type of attack exploits vulnerabilities in web applications using SQL
Correct answer: SQL injection attacks
Correct answer: SQL injection attacks
You receive a phone call from someone claiming to be from your internet service provider. They ask for your account details, including your username and password, to resolve a technical issue. What should you do?
Correct answer: Hang up the phone without providing any information and call your internet service provider directly to verify the call.
Correct answer: Hang up the phone without providing any information and call your internet service provider directly to verify the call.
Midterm Quiz No. 2
What is an important consideration when implementing an IDPS?
Correct answer: Designing a process to deal with false positives
Correct answer: Designing a process to deal with false positives
Which of the following IDPS solutions is known for offering advanced threat protection against attacks?
Correct answer: Palo Alto Networks
Correct answer: Palo Alto Networks
You receive an email from an unfamiliar sender claiming to be your bank, requesting your account information to resolve a security issue. What should you do?
Correct answer: Contact your bank directly using a trusted contact method to verify the request.
Correct answer: Contact your bank directly using a trusted contact method to verify the request.
Which of the following is not one of the top web application attacks?
Correct answer: XSS (Cross Site Scripting)
Correct answer: XSS (Cross Site Scripting)
Which security testing approach involves scanning source code to find and eliminate software vulnerabilities?
Correct answer: SAST
Correct answer: SAST
Web application security is the practice of protecting websites, applications, and APIs from:
Correct answer: Cyber attacks
Correct answer: Cyber attacks
What is the function of an intrusion prevention system (IPS) within an IDPS?
Correct answer: It takes automated courses of action to prevent incidents
Correct answer: It takes automated courses of action to prevent incidents
Which technique of IDPS analyzes traffic payload against a database of known malware signatures?
Correct answer: Signature-based detection
Correct answer: Signature-based detection
Which best practice for implementing an IDPS involves ensuring up-to-date information on malware and protocol standards?
Correct answer: Ensuring up-to-date information
Correct answer: Ensuring up-to-date information
What is the function of an intrusion detection system (IDS) within an IDPS?
Correct answer: It monitors and alerts bad traffic or policy violations
Correct answer: It monitors and alerts bad traffic or policy violations
Which type of IDPS is deployed within the wireless network and monitors wireless protocol activity?
Correct answer: Wireless intrusion prevention system (WIPS)
Correct answer: Wireless intrusion prevention system (WIPS)
What is the ultimate goal of web application security?
Correct answer: All of the above
Correct answer: All of the above
What type of detection approach relies on setting accepted levels and checking for deviations from normal behavior?
Correct answer: Anomaly-based detection
Correct answer: Anomaly-based detection
Which prevention-level functionality of an IDPS involves blocking users or traffic originating from a particular IP address?
Correct answer: Banishment vigilance
Correct answer: Banishment vigilance
Which type of IDPS is deployed at network boundaries, behind firewalls, routers, and remote access servers?
Correct answer: Network-based intrusion prevention system (NIPS)
Correct answer: Network-based intrusion prevention system (NIPS)
What is the primary purpose of running simulations regularly in an IDPS?
Correct answer: To fine-tune the system's settings and profiles
Correct answer: To fine-tune the system's settings and profiles
Which type of security test is best for low-risk applications that must comply with regulatory assessments?
Correct answer: DAST
Correct answer: DAST
What is the primary target of web security testing?
Correct answer: Application layer
Correct answer: Application layer
While browsing a website, a pop-up window suddenly appears, stating that your computer is infected with a virus and urging you to click a link for immediate removal. What should you do?
Correct answer: Run a full system scan using your trusted antivirus software.
Correct answer: Run a full system scan using your trusted antivirus software.
What is the primary purpose of an intrusion detection and prevention system (IDPS)?
Correct answer: To monitor network traffic for suspicious activity
Correct answer: To monitor network traffic for suspicious activity