Information Security Management Examination (SG) | Section A Threats and Attack Techniques 02
Problem 1 ・ Question 1 / 10
Which malware encrypts files and demands money in exchange for restoring them?
View explanation
Ransomware makes data or a device unusable and demands a ransom.
Problem 1 ・ Question 2 / 10
Which malicious program records the keys typed without the user noticing?
View explanation
A keylogger records keyboard input and steals credentials and the like.
Problem 1 ・ Question 3 / 10
Which attack lures users from a mail pretending to be from a real company to a fake site and steals their credentials?
View explanation
Phishing uses fake mails and fake sites to make people enter secret information.
Problem 1 ・ Question 4 / 10
Which attack targets a particular organisation with mail disguised as relating to its business?
View explanation
A targeted attack researches its target and uses content the recipient will readily believe.
Problem 1 ・ Question 5 / 10
Which attack sends huge volumes of traffic from many devices to make a service unusable?
View explanation
A DDoS attack is a denial-of-service attack that concentrates traffic from many distributed devices.
Problem 1 ・ Question 6 / 10
Which attack puts malicious commands into a web input field to manipulate a database?
View explanation
SQL injection causes malicious SQL to be executed by way of input values.
Problem 1 ・ Question 7 / 10
Which attack exploits a vulnerability for which no fix has yet been released?
View explanation
An attack aimed at a vulnerability before countermeasures are in place, such as just after disclosure, is called a zero-day attack.
Problem 1 ・ Question 8 / 10
Which act is searching discarded documents in the rubbish to obtain secret information?
View explanation
Trashing is the act of hunting through waste for credentials and confidential information.
Problem 1 ・ Question 9 / 10
Which attack tries candidate passwords one after another over every possible combination?
View explanation
A brute-force attack tries combinations of characters exhaustively.
Problem 1 ・ Question 10 / 10
Which threat is an authorised employee taking customer information out improperly?
View explanation
Taking information out by an insider who holds legitimate rights counts as insider fraud.
Result
More sets in this exam
- Information Security Management Examination (SG) | Section A Security Fundamentals 01
- Information Security Management Examination (SG) | Section A Security Management and Law 04
- Information Security Management Examination (SG) | Section A Risk and Access Management 05
- Information Security Management Examination (SG) | Section A Attack Mitigation and Business Continuity 06
- Information Security Management Examination (SG) | Section A Security Properties and Design Principles Questions 07
- Information Security Management Examination (SG) | Section A Risk Treatment, Supplier, and Incident Management Questions 08