SY0-601 Threats, Attacks & Vulnerabilities — Questions and Answers
Question 1: What is phishing?
- Computer virus
- Firewall breach
- Data backup
- Fraudulent email scam (Correct answer)
Correct answer: Fraudulent email scam
Phishing is a type of cyberattack where attackers attempt to trick individuals into revealing sensitive information, such as usernames, passwords, or credit card details. This is typically done by disguising themselves as a trustworthy entity in electronic communication, most commonly through fraudulent emails. The goal is to deceive the recipient into clicking malicious links or providing confidential data.
Question 2: What is malware?
- Authentication tool
- Encryption app
- Malicious software (Correct answer)
- Firewall
Correct answer: Malicious software
Malware is an umbrella term for 'malicious software' designed to disrupt, damage, or gain unauthorized access to a computer system. It encompasses various types of threats, including viruses, worms, Trojans, and ransomware. Malware can steal data, encrypt files, or simply make a system unusable, posing significant security risks.
Question 3: What is a DDoS attack?
- Data encryption
- Traffic routing
- Flooding service with traffic (Correct answer)
- Password cracking
Correct answer: Flooding service with traffic
A Distributed Denial of Service (DDoS) attack aims to make an online service unavailable by overwhelming it with a flood of traffic from multiple compromised computer systems. This excessive traffic consumes the target's resources, preventing legitimate users from accessing the service. The goal is to disrupt operations and cause service outages.
Question 4: What is ransomware?
- Free antivirus
- Data backup
- Data locked for ransom (Correct answer)
- System update
Correct answer: Data locked for ransom
Ransomware is a type of malicious software that encrypts a victim's files, rendering them inaccessible. The attacker then demands a ransom payment, typically in cryptocurrency, in exchange for the decryption key. If the ransom is not paid, the data may remain encrypted or be permanently lost, making it a highly disruptive form of cyberattack.
Question 5: What is the main goal of social engineering?
- Change system settings
- Install patches
- Trick people for data (Correct answer)
- Fix bugs
Correct answer: Trick people for data
The main goal of social engineering is to trick people into divulging confidential information or performing actions that compromise security. Unlike technical attacks, social engineering exploits human psychology, such as trust, fear, or curiosity, rather than system vulnerabilities. Attackers manipulate individuals to gain unauthorized access to systems or data.
Question 6: Which is a type of malware?
- Trojan (Correct answer)
- Firewall
- VPN
- Patch
Correct answer: Trojan
A Trojan, or Trojan horse, is a type of malware that disguises itself as legitimate software to trick users into installing it. Once inside a system, it can create backdoors, steal data, or launch other attacks without the user's knowledge. Trojans are dangerous because they appear harmless, making them difficult to detect until they execute their malicious payload.
Question 7: What does vulnerability mean?
- Update feature
- System upgrade
- Weakness in system (Correct answer)
- Access log
Correct answer: Weakness in system
In cybersecurity, a vulnerability refers to a weakness or flaw in a system, application, or network that can be exploited by an attacker. These weaknesses could be in software code, configurations, or even human processes. Identifying and patching vulnerabilities is crucial to prevent unauthorized access, data breaches, and other security incidents.
Question 8: What is spyware?
- Encrypts data
- Speeds up PC
- Gathers info secretly (Correct answer)
- Blocks spam
Correct answer: Gathers info secretly
Spyware is a type of malicious software designed to secretly gather information about a user's activities without their knowledge or consent. This can include monitoring keystrokes, capturing screenshots, tracking browsing history, or collecting personal data. Its primary purpose is to covertly transmit this collected information to an unauthorized third party, often for advertising or malicious purposes.
Question 9: Which is an example of insider threat?
- Email phishing
- Firewall misconfig
- Employee data theft (Correct answer)
- Malware infection
Correct answer: Employee data theft
An insider threat refers to a security risk that originates from within an organization, often from current or former employees, contractors, or business partners. Employee data theft is a prime example, where an individual with authorized access misuses their privileges to steal sensitive information. These threats are particularly challenging to detect and mitigate due to the trusted nature of the perpetrator.
What is phishing?