Menu

B1 Threats to data

Card 1 of 73 0 got it 0 still learning
Question
TapClick or press space to see the answer
Answer
All 73 cards in this set
A hacker breaks into a company's network and boasts about it online to other hackers. What is the main reason for the attack?
To gain recognition for their skills
A rival company pays a hacker to obtain a manufacturer's design plans. What is the rival likely to do with them?
Produce counterfeit copies or gain a competitive advantage
An attacker locks a company's servers and demands money before unlocking them. What is the attacker aiming for?
Financial gain through extortion
Why might a former employee be more likely to break into an organisation's systems successfully?
They already know the systems and their weaknesses
A group floods a retailer's website with fake traffic so customers cannot place orders. What is the main aim?
To disrupt the company's normal operations
A criminal uses someone else's name, address and bank details to take out a loan. Which crime does this describe?
Identity theft
Which statement best describes the difference between industrial espionage and data and information theft?
Industrial espionage targets business secrets, while data theft targets personal details
An online shop's website is defaced and cannot take orders for a week. What is the main effect on the shop?
It loses earnings and its reputation is damaged
An attacker steals customer data and sells it to an organised criminal gang. Which reason for attacking systems does this describe?
Financial gain
Which term describes the act of stealing business information, trade secrets or intellectual property from an organisation?
Industrial espionage
What is meant by a personal attack on the systems of an organisation?
An attack motivated by a grudge, often by a former employee
Which term describes gaining money by threatening someone or putting them under pressure?
Extortion
What is meant by data and information theft?
Stealing valuable details such as names, addresses and financial data and selling them on a black market
Which term describes any attack that prevents an organisation from operating normally, such as defacing a website or slowing down a service?
Disruption
What is meant by an attack carried out for fun or for the challenge?
The attacker has the skill to break in and finds it interesting
Which broad term describes the different ways an attacker deceives people into revealing sensitive information such as usernames, passwords and personal details?
Social engineering
What is meant by 'pharming'?
An attack that compromises a DNS server so that users are redirected to a fake website that looks genuine
What is the name for a group of compromised computers that an attacker controls and orders to attack a target all at the same time?
Botnet
What is meant by 'shoulder surfing'?
Watching someone closely, in person or through binoculars, in order to read their passwords or PINs
What is meant by a denial-of-service attack?
An attack that overwhelms a server with requests so that legitimate users cannot use it
Which term describes a situation where the communication between two devices is intercepted by a third party, who may also change the data before passing it on?
Man-in-the-middle
What is meant by malware?
Software written to cause harm or steal data
Which type of attack is carried out using spoof emails, text messages or phone calls that pretend to come from an organisation the victim trusts?
Phishing
Which statement describes black hat hacking?
Gaining access to a system without permission in order to exploit it
Malware encrypts all the files on a company's computers and a payment is demanded to unlock them. Which type of malware is this?
Ransomware
Why is a distributed denial-of-service attack more likely to succeed than a single denial-of-service attack?
Many infected computers send requests to the server at once
Which feature of an email suggests it may be a phishing attempt?
It asks the reader to confirm a password by clicking a link
A customer is checking their bank account on a laptop while travelling on a train. Why is shoulder surfing a risk in this situation?
People sitting nearby can read the screen and see private information
A customer sends encrypted data over open Wi-Fi and a man-in-the-middle attacker intercepts it. Why is the attacker unable to read the data?
Encrypted data cannot be decoded by the attacker
A company laptop has become infected with malware. Which of these could explain how the malware got onto it?
A user opened an infected email attachment
A program copies itself and spreads across a company network, infecting computers without anyone opening a file or clicking a link. Which type of malware is this?
A worm
A user downloads a free game that appears genuine, but hidden inside it is malware that gives an attacker control of their computer. What is this type of malware called?
A Trojan
A visitor waits outside a secure door and follows an employee through it without being challenged. Which social engineering technique is this?
Tailgating
Software on a user's phone secretly records their activity, including passwords, and sends the details to an attacker. Which type of malware is this?
Spyware
A file that is already infected is opened on a computer and the malware copies itself into other files so that they become infected too. Which type of malware is this?
A virus
What is meant by an internal threat to an organisation's digital systems?
A risk to data that comes from inside the organisation
A member of staff turns off the firewall on a work computer so they can download a game. Why does this threaten the organisation's data?
The computer loses protection, so malware can access data
A member of staff emails a file of customer details to the wrong customer. Which internal threat is this?
Unintentional disclosure of data
An employee who is about to leave copies the customer database and sells it to a competitor. Which internal threat is this?
Intentional leaking of information
Why might an organisation stop staff from using USB flash drives to move work files?
They are small and easy to lose, so data could be stolen
A member of staff downloads files from an untrustworthy website onto a work computer. How could this threaten the organisation's data?
The files could contain malware that steals information
A member of staff never logs out of the customer database when they leave their desk. Why is this a threat to the organisation's data?
Another person could use their account to access or change data
A member of staff has edit permission for the whole customer database although their role only needs them to view it. Why does this increase the risk of data loss?
They could delete or change records by mistake
A member of staff is unhappy about being passed over for promotion. Why might this make them an internal threat?
They may leak company data on purpose for revenge
An organisation has not updated the security software on its computers for over a year. Why does this increase the risk to its data?
New malware will not be recognised by the software
A member of staff opens an attachment in an email that appears to come from the IT team. How could this threaten the organisation's data?
The attachment could install malware that collects data
A member of staff is about to use a website they have not seen before. Which feature suggests the website is untrustworthy?
The web address has random letters and numbers in it
A member of staff keeps the only copy of some project files on a USB flash drive. The drive stops working. Why is this a threat to the organisation's data?
Portable devices can fail, so the files could be lost
Which term describes a member of staff sharing confidential data with someone who is not authorised to see it, without meaning to?
Unintentional disclosure of data
What is meant by users overriding security controls?
Staff finding a way around the security measures that are in place
What is meant by the use of portable storage devices as an internal threat?
Staff connecting items such as USB sticks to work computers
What is the name for a colleague deliberately looking at the computer screen of a member of staff to read confidential information?
Shoulder surfing
What is meant by accidental deletion of data as an internal threat?
A member of staff removing files or records by mistake
What is meant by accidental damage as an internal threat to an organisation?
A member of staff dropping a device or spilling liquid on it
What is meant by poor password practice as an internal threat?
Staff using passwords that are weak or shared with others
A retailer's systems are taken offline for two days while a breach is investigated, so customers cannot place orders. Which impact is this?
Downtime, because the service is unavailable
Why can a security breach reduce the productivity of a company's staff?
They must spend time recovering data instead of doing their normal work
Which of these is an example of financial loss caused by a security breach?
Paying a ransom to the attackers
A company did not protect customer data properly, so the Information Commissioner's Office took it to court. Which impact is this?
Legal action taken against the company
A customer's personal data is leaked in a security breach. Which impact does this have on the customer?
They may feel stressed and spend time resolving the problem
Customer data stolen in a breach is sold online. What is the most likely impact on those customers?
Loans could be taken out in their name
After a breach, a company finds that the customer records it held can never be recovered. Which impact is this?
Permanent data loss
A breach is reported in the news and the company's reputation is badly damaged. What is the most likely result?
Customers take their business to a competitor
A company's systems are offline for three days after a breach, so it cannot process customer orders. Why does this lead to financial loss?
The company cannot process orders, so it loses income
A company suffers severe financial loss after a security breach. Which of these could happen as a result?
Staff being made redundant or the company going bankrupt
Why can a security breach lead to legal action against a company?
The company may not have protected personal data as the law requires
Which term describes when an organisation loses information it holds, either temporarily or permanently?
Data loss
What is meant by 'downtime'?
A temporary complete loss of service while systems are shut down
What is the name for the harm to a company's reputation and the trust people have in it after a security breach?
Damage to public image
What is meant by 'financial loss'?
Money lost through fines, repairing systems or reduced sales
Which term describes an organisation being fined or sued for not properly protecting personal data?
Legal action
What is meant by 'reduced productivity'?
Staff cannot work as efficiently because systems are unavailable or data has to be recovered
Which term means the same as damage to public image?
Loss of reputation