Cybersecurity Threats and Mitigation Flashcards
7 cards from real ICT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Cybersecurity Threats and Mitigation flashcards as text
Which type of threat actor is typically motivated by financial gain and operates as an organized criminal enterprise?
Answer: Cybercriminal group
Cybercriminal groups are primarily financially motivated, running ransomware-as-a-service, fraud schemes, and data theft for profit.
What is DNS poisoning (cache poisoning)?
Answer: Inserting false DNS records to redirect users to malicious sites
DNS cache poisoning corrupts a DNS resolver's cache with fraudulent entries, causing users to be redirected to attacker-controlled IP addresses instead of legitimate sites.
A penetration tester has no prior knowledge of the target system before the test begins. Which type of test is this?
Answer: Black-box testing
Black-box penetration testing simulates an external attacker with no insider knowledge, testing defenses from the perspective of an uninformed adversary.
Which of the following is an example of a supply chain attack?
Answer: Compromising a trusted software vendor to distribute malware via legitimate updates
Supply chain attacks target less-secure vendors or software providers to reach the actual target, as demonstrated by the SolarWinds attack where malicious code was inserted into software updates.
What is the purpose of a Security Information and Event Management (SIEM) system?
Answer: To aggregate, correlate, and analyze security logs from multiple sources for threat detection
A SIEM collects log data from across an organization's infrastructure, correlates events, and generates alerts to help security teams detect and respond to threats.
Which attack technique involves sending malformed packets to crash or exploit a service by exceeding its input buffer capacity?
Answer: Buffer overflow attack
A buffer overflow attack sends more data than a program's buffer can hold, overwriting adjacent memory and potentially allowing attackers to execute arbitrary code.
What does the term 'attack surface' refer to in cybersecurity?
Answer: The total set of points where an attacker could try to enter or extract data from a system
The attack surface encompasses all possible entry points and vulnerabilities in a system that an attacker could exploit, including software, hardware, network interfaces, and human factors.