SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
CISSP Attacks
Start Test
Study First
Subjects
:
certifications
,
it-skills
,
cissp
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Type: DoS - How: Attacker sends your packets to a non-existent address - How: One way is special type of ARP poisioning.
Shellcode
TDL-4 Bot-Net #3
ARP Table Poisioning
Black Hole
2. How: Attacker sends forged stream of TCP SYN packets with Source & Destination = to victim's IP address - Victim's system attempts to reply to itselft (attacks itself) - Vulnerable systems: Systems with BSD TCP/IP stack - Counter: Edge routers drop p
Land
Trinoo
Loki
Mail bombing
3. Attacker deletes incriminating evidence or data from audit logs. - Countermeasure: Protect log from modification via strict access control
Bluesnarfing
SMiShing
Bluetooth DoS (1 or more attackers)
Scrubbing
4. Type: DoS (Flood or Crashing) - How: Malformed fragmented packts - Why: Causes vulnerable host to fail and/or reboot - Countermeasure: Network IDS - drop faulty or corrupted packets - ingress filters
Wardialing
Ping of Death
Teardrop
Botnet Names
5. Allows skilled individuals to access phone Commands using Bluetooth wireless technology without notifying or alerting the phone's user. - Why: This vulnerability allows the hacker to initiate phone calls - send and read SMS - read and write phoneboo
Bluesnarfing
Web Spoofing Attack
Worms
Bluebugging
6. Attacker uses program presenting Fake Logon Screen Capture Username & Pswd - Counter: Host IDS
Remote Code
E-mail address spoofing
Slamming
Spoofing at Login
7. 'Pairing' establishes trust relationship - Access to All Data on device
Web Spoofing Attack
Bluetooth BackDoor Attack
TDL-4 Bot-Net
Tap
8. Type: Man-in-Middle Attack - AKA: Phishing - URL Spoofing - How: Spoofs the public key of web site/server - Why: Get users to go to Attackers Website instead - Goal: usually to get user's data (ID - password - bank account info - etc.) However - coul
Deliberate exploit
Race Condition
Caller ID Spoofing
Web Spoofing Attack
9. Type: Buffer Overflow - How: Memory Stack is overflown to write data into another area of memory in the Identify of the System. (Priviledged System account) - Why: The most common cause of stack overflows is excessively deep or infinite recursion. T
Botnet Names
TDL-4 Bot-Net #2
Worms
Stack Overflow
10. Social engineering technique
Remote Code
Time of Use/Time of Check Attack
ARP Table Poisioning
Phishing
11. TDL-4's makers created their own encryption algorithm - Kaspersky's Golovanov said in his analysis - and the botnet uses the domain names of the C&C servers as the encryption keys.
Web Spoofing Attack
Cramming
Stack Overflow
TDL-4 Bot-Net #2
12. Type: DDoS - How: TFN uses a master program to communicate with attack agents across multiple nets. TFN can launch several types of attacks simultaneously: UDP flood - TCP SYN flood - ICPM echo request flood and ICMP directed broadcasts. - Why: TFN M
Botnet Names
Jamming
Tribal Flood Network (TFN) & TFN2K
Cramming
13. RF interference / blocking
Web Spoofing Attack
Land
Bluetooth Malicious Threats
Jamming
14. Type: Buffer Overflow in the heap data area. - Heap overflows are exploitable in a different manner to that of stack-based overflows. Memory on the heap is dynamically allocated by the application at run-time and typically contains program data. Expl
TDL-4 Bot-Net #3
Heap Overflow
Trinoo
Time of Use/Time of Check Attack
15. Mobile device attack that seeks to dupe the recipient of an SMS (short message service - text) message into downloading malware onto their handset. Once the handset is infected - it can be turned into a 'zombie -' allowing attackers to control the de
Remote Code
Shellcode
S-RPC
SMiShing
16. Counters:Best: Proper programming with Input value bounds checking. Keep systems current: Patching - hot fixes - etc.
Buffer Overflow
Bluetooth DoS (1 or more attackers)
Network Address Hijacking
Bluejacking
17. 1) If phone is vulnerable to bluesnarfing or bluebugging-- seek patches. Manufacturer or manufacturer-authorized dealer. Software patches available for many older Bluetooth phones. 2) Turn device to non-discoverable mode when not using Bluetooth tech
Stack Overflow
TDL-4 Bot-Net
Botnet Names
Bluetooth Threat Mitigation
18. AKA: Asynchronous attack - How: Takes advantage of dependency of event timing in a multitasking OS - How: Attacker gets between instructions and manipulates something. Goal is Control the result.
Bluetooth Threat Mitigation
Remote Code
Bluesnarfing
Time of Use/Time of Check Attack
19. AKA Session Hijacking - Enables user to gain control of session read change data and/or packets. Could potentially get passwords or Paswd file if attacks admin
Network Address Hijacking
Worm Names
Bluesnarfing
Deliberate exploit
20. Change user's service provider - w/o concent
Slamming
Worm Names
Bluetooth DoS (1 or more attackers)
Worms
21. Type: Fun or Snoop Info - How: Attacker sends unsolicited message to Bluetooth enabled device. e.g. insert contact into address book. Why: May Enable future attacks on the device via emails - Recipent reaction or get data w/o your knowledge while con
Buffer Overflow
Web Spoofing Attack
Teardrop
Bluejacking
22. Zeus - Mariposa - Storm
Caller ID Spoofing
S-RPC
Tribal Flood Network (TFN) & TFN2K
Botnet Names
23. Redirect victim to fake website - How: DNS poison -
Bluetooth BackDoor Attack
Remote Code
Teardrop
Pharming
24. The botnet also uses the public Kad P2P network for one of its two channels for communicating between infected PCs and the C&C servers - said Kaspersky. Previously - botnets that communicated via P2P used a closed network they had created.
SMiShing
Port Scanning
Bluejacking
TDL-4 Bot-Net #3
25. Type: DoS - How: Send Packet > max allowable size of 65535 bytes - Why: Causes vulnerable host to fail and/or reboot - Counter: Ingress filter - patch systems
Ping of Death
Web Spoofing Attack
Shellcode
Black Hole
26. Juggernaut & HUNT Project - Spy then attack
Black Hole
Hijacking Tools
Shellcode
TDL-4 Bot-Net
27. Flood w/ Pairing requests. (spoofed or not) - Victim consumed with Responses
Stack Overflow
Bluetooth Threat Mitigation
Bluetooth DoS (1 or more attackers)
Jamming
28. Bluebugging - Bluesnarfing
Bluetooth BackDoor Attack
TDL-4 Bot-Net
Jamming
Bluetooth Malicious Threats
29. Type: DDoS - How: uses a master program to communicate with attack agents across multiple nets. Attacker remotely connects to Master host - then master commands agents to perform UDP flood to a list of Target IP addresses. - Why: your IP address is i
Shellcode
Trinoo
Bluetooth Threat Mitigation
Loki
30. How: SMTP doesn't provide any authentication.E-mail address spoofing is done in quite the same way as writing a forged return address using snail mail. As long as the letter fits the protocol - (i.e. stamp - postal code) the SMTP protocol will send t
Spoofing at Login
S-RPC
E-mail address spoofing
Bluetooth Threat Mitigation
31. Type: Brute force How: Attack hashing function via Brute force. Changes message until he gets one that produces the same hash value. - Why: Attacker wants to change your message without detection.
SMiShing
Birthday
Land
Remote Code
32. Sasser - Blaster - Melissa - ILOVEYOU - Conflicker
TDL-4 Bot-Net #3
Time of Use/Time of Check Attack
Buffer Overflow
Worm Names
33. Covert Channel ICMP comms - writes data after header Sniffing - Counter: Secure protocols -
Bluetooth Threat Mitigation
Teardrop
Loki
Hijacking Tools
34. Type of Remote Shellcode that downloads and executes some form of malware on the target system. This type of shellcode does not spawn a shell - but rather instructs the machine to download a certain executable file off the network - save it to disk
Ping of Death
S-RPC
Download and Execute
Spoofing at Login
35. Type: Masquerading Attack - How: For a given IP address in ARP table - attacker enters his MAC address - Why: Attacker alters System ARP table. Goal to receive packets.
ARP Table Poisioning
Tap
Heap Overflow
Ping of Death
36. Overwhelm mail server & Clients
Phishing
Bluetooth Malicious Threats
Mail bombing
Scrubbing
37. Counter: Non-public #s - Tight AC for modems / pools
Botnet Names
Mail bombing
Wardialing
TDL-4 Bot-Net #2
38. May result in data at a specific location being altered in an arbitrary way - or in arbitrary code being executed. - Counter: make sure your OS and application libraries are patched to detect/prevent against these types of overflows
Deliberate exploit
Worm Names
S-RPC
ARP Spoof
39. Hacker gains access to data stored on Bluetooth enabled phone. Why: hacker make phone calls - send & receive text messages - read & write phonebook contacts - eavesdrop on phone conversations - and connect to Internet. - How: requires advanced equip
Bluesnarfing
Bluetooth BackDoor Attack
Tap
Caller ID Spoofing
40. Completed by using commercially available couplers to place a microbend in the cable to allow light to radiate through the cladding and be exposed to a photodetector. photodetector is connected to an electro-optical converter that acts as an interfac
Bluetooth Threat Mitigation
Tap
Bluesnarfing
Slamming
41. In computer security - a shellcode is a small piece of code used as the payload in the exploitation of a software vulnerability. It is called 'shellcode' because it typically starts a command shell from which the attacker can control the compromised
Botnet Names
Mail bombing
Shellcode
SMiShing
42. Intruder re-routes data traffic from a network device to Attacker's machine
Worms
Network Address Hijacking
Tribal Flood Network (TFN) & TFN2K
Heap Overflow
43. aka ARP Flooding - poisioning
Tribal Flood Network (TFN) & TFN2K
ARP Spoof
Network Address Hijacking
Buffer Overflow
44. Type: Reconn - How: Use port scanning tool to identify Listening Ports (TCP/UDP) on Servers - Tools: Nmap - Foundstone Products (Scanline - etc.) - Angry IP Scanner - etc.
ARP Spoof
Port Scanning
Remote Code
S-RPC
45. Attacker must win the race of responding between 2 different processes carrying out a task/function. Counter: Do not Split up critical tasks that can have results or sequence altered. - Employ Software locks to files to prevent unauthorized access.
Network Address Hijacking
Network Address Hijacking
Race Condition
Spoofing at Login
46. Add extra bogus charges
Bluetooth Threat Mitigation
Cramming
Race Condition
TDL-4 Bot-Net
47. Installs its rootkit on the MBR - Sector 0 - Invisible to OS & security software - advanced encryption and the use of a public peer-to-peer (P2P) network for the instructions issued to the malware by (C&C) servers
Remote Code
Tap
TDL-4 Bot-Net
Spoofing at Login
48. How: Attacker uses technologies (especially associated with VoIP) that allow callers to lie about their identity and present false names and numbers - Why: defraud or harass.
Tribal Flood Network (TFN) & TFN2K
Caller ID Spoofing
E-mail address spoofing
Mail bombing
49. Type: Worm. How: Self replicating usually Rapid over net or other means.
Worms
Port Scanning
Hijacking Tools
Network Address Hijacking
50. Uses DiffieH PK to determine shared Symm key
ARP Table Poisioning
Worm Names
S-RPC
Loki