Free Practice Quiz Question List

2 Threats and Attacks Online Quiz Questions

Use this free practice quiz with 20 questions to review 2 Threats and Attacks, test your knowledge, and prepare for your next test or exam.

20 questions
01
True or false
1 point

An organization identifies a plausible phishing attack that could compromise an employee account. It estimates how likely the event is and what harm could result, while recognizing that the attack may never occur. Is this consistent with a threat assessment?

  1. A

    True

  2. B

    False

02
True or false
1 point

An attacker sends a text message impersonating a delivery company and directs the recipient to a deceptive login page. This is an example of vishing.

  1. A

    True

  2. B

    False

03
Choose one
1 point

A fake bank alert arrives by text and urges the recipient to enter credentials on a deceptive website. Which related form of phishing best describes the delivery channel?

  1. A

    Vishing

  2. B

    Smishing

  3. C

    Whaling

  4. D

    Spear phishing

04
Written response
1 point

An attacker crafts a personalized email to trick a company’s chief executive into approving a fraudulent payment. What type of phishing targets a senior or otherwise high-value individual?

05
Choose one
1 point

Attackers compromise a software supplier’s update process so that customers who trust and install the update are exposed to malicious activity. Which attack method best describes this route into the customers’ systems?

  1. A

    Credential attack

  2. B

    Denial of service

  3. C

    Supply-chain compromise

  4. D

    Data tampering

06
Written response
1 point

What type of malware can spread between systems, often without requiring a user to run an infected file?

07
Choose all
1 point

A staff member receives an unexpected message requesting a password reset and demanding immediate action. Which actions are appropriate? Select all that apply.

  1. A

    Verify the request through a separate, trusted channel.

  2. B

    Comply immediately because the message says the request is urgent.

  3. C

    Report the suspicious message using the organization’s process.

  4. D

    Treat the unexpected request as a warning sign and investigate it.

08
Choose all
1 point

When estimating the impact of a possible attack, which consequences are relevant considerations described in the threat-assessment guidance? Select all that apply.

  1. A

    Loss of confidentiality of sensitive information

  2. B

    A change to the organization’s brand colors

  3. C

    Disruption to service availability

  4. D

    Financial harm to the organization

09
Choose one
1 point

A company is concerned that a convincing phishing message could expose an employee’s password and lead to account compromise. Which safeguard most directly makes stolen credentials alone insufficient to access important accounts?

  1. A

    Allow every employee account to access all shared files.

  2. B

    Require phishing-resistant multifactor authentication for important accounts.

  3. C

    Disable protected backups to simplify recovery.

  4. D

    Rely only on staff recognizing every deceptive message.

10
Open ended
1 point

A small organization depends on email and shared files for daily operations. Explain how it could assess the risk that a convincing phishing message leads to a compromised employee account, and describe how it should use the assessment to reduce and revisit that risk.

11
Choose one
1 point

An organization discovers that an exposed service contains a weakness. A competitor may have limited resources but appears interested in the data available through that service. Which approach best reflects the guidance for assessing this adversarial threat?

  1. A

    Classify the actor by label alone and ignore the target and available access.

  2. B

    Consider the actor’s capability, intent, and targeting, including the exposed service.

  3. C

    Assume that a competitor cannot pose a threat because competitors are not listed as common actors.

  4. D

    Treat the attack as certain solely because a weakness exists.

12
True or false
1 point

True or false: A threat assessment establishes that a particular attack will certainly occur.

  1. A

    True

  2. B

    False

13
Choose one
1 point

A group disrupts a public-facing service to draw attention to a social cause. Which threat-actor category best fits this scenario?

  1. A

    A cybercriminal seeking payment through fraud

  2. B

    A hacktivist promoting a social cause

  3. C

    A nation-state actor seeking intelligence

  4. D

    An insider making an accidental mistake

14
Choose one
1 point

An employee receives an unexpected message demanding an urgent password reset through a link. What is the safest next step before acting?

  1. A

    Reply to the message asking the sender to confirm it

  2. B

    Open the link in the message to inspect the request

  3. C

    Verify the request through a separate, trusted channel

  4. D

    Forward the message to a colleague and follow their first impression

15
Written response
1 point

Malware spreads from one system to others on a network without requiring users to run an infected file. What type of malware is it?

16
Choose one
1 point

An attacker floods a company’s public service with traffic, preventing legitimate customers from using it. Which attack method is being used?

  1. A

    Denial of service

  2. B

    Credential attack

  3. C

    Data tampering

  4. D

    Supply-chain compromise

17
Choose one
1 point

An attacker alters a trusted software supplier’s update so that organizations installing it are exposed. Which attack method best describes this route into the organizations?

  1. A

    Credential attack

  2. B

    Exploitation of a local software flaw

  3. C

    Social engineering of an employee

  4. D

    Supply-chain compromise

18
Written response
1 point

An attacker sends a deceptive message designed specifically to trick a company’s senior executive. What is this targeted form of phishing called?

19
Fill in the blank
1 point

An analyst documents an adversary's broad goal, the method used to pursue it, and the specific implementation. In MITRE ATT&CK, the goal is a , the method is a , and the specific implementation is a .

20
Fill in the blank
1 point

An employee unintentionally deletes shared records while doing normal work. In the source categories described in the material, this is an source of harm, not an adversarial one.