CIS377 Cybersecurity Midterm Review

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Alfredhook3
A
Alfredhook3
Community Contributor
Quizzes Created: 5562 | Total Attempts: 3,155,788
| Questions: 30 | Updated: Oct 5, 2026
Please wait...
Question 1 / 31
🏆 Rank #-- ▾
0 %
0/100
Score 0/100

1. Which social engineering attack involves following an authorized person through a secure doorway without credentials?

Explanation

Tailgating is a social engineering attack where an unauthorized individual gains access to a secure area by closely following an authorized person through a doorway. This exploits the trust and lack of vigilance of the authorized individual, allowing the attacker to bypass security measures without proper credentials. It highlights the importance of maintaining awareness of one's surroundings and ensuring that doors are not held open for strangers in secure environments.

Submit
Please wait...
About This Quiz
Cis377 Cybersecurity Midterm Review - Quiz

This assessment focuses on key concepts in cybersecurity, covering the CIA Triad, malware types, and social engineering tactics. It evaluates your understanding of essential principles like confidentiality, integrity, and security measures. Perfect for those preparing for cybersecurity exams or seeking to enhance their knowledge in this critical field.

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. Which of the following best describes cryptojacking?

Submit

3. Match each security control category with its correct example.

Submit

4. A ____ attack tries every possible combination of characters until the correct password is found.

Submit

5. Which of the following are examples of 'Something You Are' authentication factors? (Select all that apply)

Submit

6. Which of the following correctly lists the stages of the Cyber Kill Chain in order?

Submit

7. Stuxnet was a famous worm specifically designed to sabotage ____.

Submit

8. Match each network security term with its correct description.

Submit

9. An IDS (Intrusion Detection System) actively blocks malicious traffic on a network.

Submit

10. Which tool is commonly used to identify open ports, active hosts, and running services on a network?

Explanation

Nmap is a powerful network scanning tool specifically designed for discovering hosts and services on a computer network. It can identify open ports, detect active devices, and determine the services running on those ports. This functionality makes it invaluable for network security assessments and troubleshooting. Unlike Wireshark, which captures and analyzes network traffic, or Metasploit and Burp Suite, which focus on exploitation and web application security, Nmap's primary role is network mapping and vulnerability scanning. Its versatility and efficiency in scanning large networks make it a preferred choice among network administrators and security professionals.

Submit

11. Telnet is considered insecure because it transmits data in an unencrypted format.

Explanation

Telnet is considered insecure because it sends data, including usernames and passwords, in plain text over the network. This means that anyone with access to the network can easily intercept and read the transmitted information, making it vulnerable to eavesdropping and man-in-the-middle attacks. Unlike secure protocols such as SSH, which encrypt data during transmission, Telnet lacks any form of encryption, exposing sensitive information to potential threats. Therefore, its use in secure environments is highly discouraged.

Submit

12. Which of the following are examples of wireless and mobile security attacks? (Select all that apply)

Explanation

Rogue access points are unauthorized devices that mimic legitimate networks, allowing attackers to intercept data. Bluesnarfing involves exploiting Bluetooth vulnerabilities to access information from devices without consent. Wireless jamming disrupts communication by overwhelming the frequency used by wireless devices, causing denial of service. These attacks specifically target wireless and mobile environments, unlike SQL injection, which is a web application attack.

Submit

13. War driving refers to searching for open or unprotected Wi-Fi networks from a moving vehicle.

Explanation

War driving involves the practice of driving around with a device that scans for unsecured Wi-Fi networks. This activity typically aims to identify open networks that can be accessed without authorization. Individuals engaging in war driving often use specialized software and GPS to map the locations of these networks, which can pose security risks to both the network owners and users. The term originated from the combination of "war" and "driving," reflecting the method of searching for these networks while in transit.

Submit

14. Which of the following correctly describes a Man-in-the-Middle (MitM) attack?

Explanation

A Man-in-the-Middle (MitM) attack involves an attacker secretly intercepting and potentially altering the communication between two parties without their knowledge. This allows the attacker to eavesdrop on sensitive information, manipulate messages, or impersonate one of the parties, thereby compromising the integrity and confidentiality of the communication. Unlike other types of attacks, such as denial-of-service or script injection, MitM specifically focuses on the covert interception and modification of data exchanged between legitimate users.

Submit

15. A ____ attack compromises a specific website frequently visited by a target organization to infect its members.

Explanation

A watering hole attack involves compromising a specific website that is regularly visited by members of a targeted organization. The attacker infects the site with malware, hoping that users from the organization will visit it, thereby unwittingly downloading the malicious software. This method relies on the assumption that the target organization’s members will frequent the compromised site, allowing the attacker to gain access to the organization's network or sensitive information. It’s a strategic approach that focuses on the habits of the target rather than directly attacking the organization itself.

Submit

16. Which component of the CIA Triad ensures that data is accessible only to authorized users?

Explanation

Confidentiality is a key component of the CIA Triad that focuses on protecting sensitive information from unauthorized access. It ensures that only individuals or systems with the proper permissions can view or interact with the data. By implementing measures such as encryption, access controls, and authentication protocols, organizations can safeguard their information against breaches and maintain privacy, thereby preventing unauthorized users from accessing confidential data.

Submit

17. Match each attack type with its correct description.

Submit

18. Which attack involves injecting malicious SQL statements into user input fields to manipulate a backend database?

Explanation

SQL Injection is a type of attack where an attacker inserts or "injects" malicious SQL statements into input fields of a web application. This manipulation targets the backend database, allowing the attacker to execute arbitrary SQL commands. By exploiting vulnerabilities in input validation, attackers can gain unauthorized access to sensitive data, modify database contents, or even execute administrative operations. This attack highlights the importance of proper input sanitization and secure coding practices to protect against unauthorized database interactions.

Submit

19. A rootkit is designed to gain administrative control over an operating system while actively hiding its presence.

Explanation

A rootkit is a type of malicious software specifically created to provide unauthorized access and control over a computer system. It operates by modifying the operating system to conceal its presence, making it difficult for users and security software to detect. By hiding its files, processes, and system modifications, a rootkit allows attackers to maintain persistent control, often for malicious purposes such as data theft, surveillance, or further exploitation of the system. Therefore, the statement accurately describes the primary function and characteristics of a rootkit.

Submit

20. Which of the following best describes a botnet?

Explanation

A botnet refers to a collection of compromised devices, often infected with malware, which are controlled by a central entity. These devices can be utilized to execute coordinated attacks, such as Distributed Denial of Service (DDoS) attacks, send spam, or perform other malicious activities. Unlike a single device used for tasks like cryptocurrency mining, a botnet operates as a network, leveraging the collective power of multiple devices to achieve its objectives, making it a significant threat in cybersecurity.

Submit

21. A ____ is malicious code embedded in software that executes only when specific conditions or dates are met.

Explanation

A logic bomb is a type of malicious code designed to trigger under specific conditions, such as a particular date or event. Unlike viruses or worms, which spread independently, a logic bomb remains dormant within a software program until the predetermined criteria are met, at which point it executes harmful actions. This can include data deletion, system corruption, or unauthorized access, making it a stealthy and insidious threat. Logic bombs are often hidden within legitimate software, posing significant risks to data integrity and security.

Submit

22. Which type of malware encrypts user data and demands payment to restore access?

Explanation

Ransomware is a type of malware designed to encrypt a user's files, rendering them inaccessible. The attacker then demands a ransom payment, typically in cryptocurrency, in exchange for the decryption key needed to restore access to the data. This form of cyberattack exploits users' urgency and fear, often targeting both individuals and organizations. Unlike other malware types, ransomware specifically focuses on financial gain through extortion.

Submit

23. Match each type of attacker with their correct description.

Submit

24. A zero-day attack targets a software vulnerability that is unknown to the vendor or has no official patch available.

Explanation

A zero-day attack exploits a security flaw in software that the vendor is not aware of, meaning there is no existing patch or fix to protect users. These vulnerabilities are particularly dangerous because they can be targeted by attackers before any defensive measures are developed. Once the vulnerability is discovered, it is referred to as a "zero-day" because the vendor has zero days to address the issue before it can be exploited. This makes zero-day attacks highly valuable and effective for cybercriminals.

Submit

25. Which of the following is an example of Protected Health Information (PHI)?

Explanation

Medical records are considered Protected Health Information (PHI) because they contain sensitive health information that can identify an individual and relate to their past, present, or future physical or mental health conditions. Unlike Social Security numbers or driver's license numbers, which are not exclusively health-related, medical records specifically pertain to an individual's healthcare and treatment, making them subject to privacy regulations like HIPAA. This emphasizes the importance of safeguarding such information to protect patient confidentiality.

Submit

26. Data actively loaded into RAM and being processed by applications is classified as ____.

Explanation

Data actively loaded into RAM and being processed by applications is referred to as "data in use." This classification highlights the information that is currently being accessed and manipulated by software, distinguishing it from data stored on disk (data at rest) or data being transmitted over networks (data in transit). Understanding this distinction is crucial for implementing appropriate security measures, as data in use is vulnerable to threats such as unauthorized access or malware attacks while it is actively being utilized by applications.

Submit

27. Non-repudiation ensures that the sender of a message cannot deny having sent it.

Explanation

Non-repudiation is a security principle that guarantees the authenticity of a message's origin. It ensures that the sender cannot later deny having sent the message, typically through the use of digital signatures or encryption. This mechanism provides proof of the sender's identity and the integrity of the message, making it legally binding and verifiable. Thus, in communication and transaction contexts, non-repudiation is crucial for accountability and trust, affirming that the sender is responsible for the message's content.

Submit

28. Which principle states that users and systems should only be granted the minimum level of access required to perform their functions?

Explanation

The Least Privilege principle emphasizes that users and systems should have only the necessary permissions to perform their specific tasks. This minimizes potential security risks by limiting access to sensitive information and critical system functions, thereby reducing the attack surface. By ensuring that permissions are restricted, organizations can better protect their resources from unauthorized access and potential breaches, enhancing overall security posture.

Submit

29. The cybersecurity principle of using multiple layered security controls so that if one fails others continue to protect the system is called ____.

Explanation

Defense in depth is a cybersecurity strategy that employs multiple layers of security controls to protect systems and data. This approach ensures that if one security measure fails, additional layers still provide protection, reducing the likelihood of a successful attack. By integrating various defensive mechanisms—such as firewalls, intrusion detection systems, and encryption—organizations create a more robust security posture, making it harder for attackers to breach the system. This layered strategy enhances overall resilience against threats and minimizes potential risks.

Submit

30. Which CIA Triad component focuses on preventing unauthorized modification of data?

Explanation

Integrity in the CIA Triad refers to the assurance that data is accurate and unaltered. It focuses on preventing unauthorized modifications, ensuring that information remains trustworthy and reliable. By maintaining integrity, organizations can detect and respond to any attempts to alter data maliciously or accidentally, safeguarding the authenticity of information. This component is crucial for protecting data against corruption and ensuring that it can be relied upon for decision-making and operational purposes.

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (30)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
Which social engineering attack involves following an authorized...
Which of the following best describes cryptojacking?
Match each security control category with its correct example.
A ____ attack tries every possible combination of characters until the...
Which of the following are examples of 'Something You Are'...
Which of the following correctly lists the stages of the Cyber Kill...
Stuxnet was a famous worm specifically designed to sabotage ____.
Match each network security term with its correct description.
An IDS (Intrusion Detection System) actively blocks malicious traffic...
Which tool is commonly used to identify open ports, active hosts, and...
Telnet is considered insecure because it transmits data in an...
Which of the following are examples of wireless and mobile security...
War driving refers to searching for open or unprotected Wi-Fi networks...
Which of the following correctly describes a Man-in-the-Middle (MitM)...
A ____ attack compromises a specific website frequently visited by a...
Which component of the CIA Triad ensures that data is accessible only...
Match each attack type with its correct description.
Which attack involves injecting malicious SQL statements into user...
A rootkit is designed to gain administrative control over an operating...
Which of the following best describes a botnet?
A ____ is malicious code embedded in software that executes only when...
Which type of malware encrypts user data and demands payment to...
Match each type of attacker with their correct description.
A zero-day attack targets a software vulnerability that is unknown to...
Which of the following is an example of Protected Health Information...
Data actively loaded into RAM and being processed by applications is...
Non-repudiation ensures that the sender of a message cannot deny...
Which principle states that users and systems should only be granted...
The cybersecurity principle of using multiple layered security...
Which CIA Triad component focuses on preventing unauthorized...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!