c c c c c c c c c c c c
2 2nd Edition Ciampa c c c
Name: Class: Date:
Modulec1c-cEnterprisecThreatscandcVulnerabilities
1. Nik,caccybersecuritycanalyst,chascbeencaskedctocexaminecancemployee'sciPhonecthatciscexhibitingcstrangecbehavi
or.cAfterclookingcthroughcthecphone,checfindscthatcthecusercapparentlychascbeencablectocuploadcthird-
partycappscthatcarecnotcincthecAppcStore.cWhichcofcthecfollowingchascmostclikelycoccurredcwithcthiscphone?
a. Rooting
b. Jailbreaking
c. Clapping
d. Raking
ANSWER: b
FEEDBACK:
a.cIncorrect.cRootingciscactermcassociatedcwithcmodifyingcthecoperatingcsyste
mcorcfirmwarecofcancAndroidcdevice,cnotcanciPhone.
b. Correct.cJailbreakingciscthectermcforcmodifyingcanciPhonecsocitccancloadcthird-
cpartycappscthatcarecnotcincthecAppcStore.
c. Incorrect.cClappingciscacmade-upctermcforcthecpurposescofcthiscscenario.
d. Incorrect.cRakingciscacmade-upctermcforcthecpurposescofcthiscscenario.
POINTS: 1
QUESTIONcTYPE: MultiplecChoice
HAScVARIABLES: False
LEARNINGcOBJECTIVES: CIAM.CYSA.22.1.1c-cIdentifycdifferentctypescofccommoncattacks
ACCREDITINGcSTANDARDS:c CIAM.CYSA.22.1.5c-
cExplaincthecthreatscandcvulnerabilitiescassociatedcwithcspecializedctechnology.
TOPICS: ThreatscandcVulnerabilitiescofcSpecializedcTechnology
KEYWORDS: Bloom's:cApply
DATEcCREATED: 7/9/2021c3:31cPM
DATEcMODIFIED: 7/19/2021c10:33cAM
2. Gabe,cacpenetrationctester,chascgainedcphysicalcaccessctocaccompany'scfacilitiescandcplantedcdevicescbehindcse
veralcprinterscthatcwillcsendchimccopiescofcallcdocumentscsentctocthosecprinters.cWhichcofcthecfollowingchascGab
ecexecuted?
a. MITMcattack
b. Replaycattack
c. XSS
d. XSRF
ANSWER: a
FEEDBACK: a.cCorrect.cAcman-in-the-
middlecattackcactivelycinterceptscorceavesdropsconccommunications.cBycplanti
ngcacdevicecbehindcprinters,cGabeccanccapturecthecdatacgoingctocthecprintercan
dcsendcitcoutsidecofcthecnetworkcforclatercanalysis.
b. Incorrect.cAcreplaycattackcresendsccapturedcdatactocacsystemcincorderctocperf
ormcsomecothercaction.cIncthiscscenario,cGabecisconlyccapturingcthecdatacandc
sendingcitcoutsidecofcthecnetworkcforcanalysis.
c. Incorrect.cCross-
sitecscriptingcdoescnotcinvolvecplantingcdevicescincancorganization.
CopyrightcCengagecLearning.cPoweredcbycCognero. Pagec1
mynursytest.store
, d. Incorrect.cCross-sitecrequestcforgerycdoescnotcinvolvecplantingcdevicescincan
CopyrightcCengagecLearning.cPoweredcbycCognero. Pagec2
mynursytest.store
, DOWNLOAD THE Test Bank for CompTIA CySA Guide to Cybersecurity Analyst CS0 00
c c c c c c c c c c c c
2 2nd Edition Ciampa c c c
Name: Class: Date:
Modulec1c-cEnterprisecThreatscandcVulnerabilities
organization.
POINTS: 1
QUESTIONcTYPE: MultiplecChoice
HAScVARIABLES: False
LEARNINGcOBJECTIVES: CIAM.CYSA.22.1.1c-cIdentifycdifferentctypescofccommoncattacks
ACCREDITINGcSTANDARDS:c CIAM.CYSA.22.1.7c-
cGiven cacscenario,cimplementccontrolsctocmitigatecattackscandcsoftwarecvulnerabilities.
TOPICS: TypescofcAttacks
KEYWORDS: Bloom's:cApply
DATEcCREATED: 7/9/2021c3:31cPM
DATEcMODIFIED: 7/19/2021c10:36cAM
3. Lakiachascbeenchiredcascacpenetrationctestercforcaclargecorganization.cShecfindscthatconecofcthecbranchcofficesciscstil
lcrunningcWEPcandcquicklyccracksctheckeyctocgaincaccessctocthecnetwork.cAscshecisccapturingcnetworkcpacketscwhilec
sittingcinctheccompany'scparkingclot,cshecseescaccouplecofctokenscthatcuserscsendctocancHTTP-
basedcwebsitectoclogcin.cWhichcofcthecfollowingctypescofcattackscmightcshecbecablectocperformcwithcthiscinformation
?
a. XSS
b. Sessionchijacking
c. XSRF
d. Rootkitcattack
ANSWER: b
FEEDBACK: a.cIncorrect.cCross-
sitecscriptingcdoescnotcinvolveccapturingcthecsessionctokencofcacuser.
b. Correct.cSessionchijackingciscancattackcincwhichcacthreatcactorcattemptsctoci
mpersonatecacusercbycusingchiscsessionctoken.
c. Incorrect.cCross-
sitecrequestcforgerycdoescnotcinvolveccapturingcthecsessionctokencofcacuser.
d. Incorrect.cAcrootkitciscactypecofcmalwarecthatccanchidecitscpresencecorcthecpres
encecofcothercmalwareconcaccomputercbycaccessingclowerclayerscofcthecoperati
ngcsystemcorcevencusingcundocumentedcfunctionsctocmakecalterations.cItcdoesc
notcinvolveccapturingcthecsessionctokencofcacuser.
POINTS: 1
QUESTIONcTYPE: MultiplecChoice
HAScVARIABLES: False
LEARNINGcOBJECTIVES: CIAM.CYSA.22.1.1c-cIdentifycdifferentctypescofccommoncattacks
ACCREDITINGcSTANDARDS:c CIAM.CYSA.22.1.7c-
cGiven cacscenario,cimplementccontrolsctocmitigatecattackscandcsoftwarecvulnerabilities.
TOPICS: TypescofcAttacks
KEYWORDS: Bloom's:cApply
DATEcCREATED: 7/9/2021c3:31cPM
DATEcMODIFIED: 7/19/2021c10:38cAM
CopyrightcCengagecLearning.cPoweredcbycCognero. Pagec3
mynursytest.store