Systems and Usable Security: Week-1 Assignment
1. A type of malware hides its presence by modifying system processes and intercepting
kernel operations so that security tools cannot detect it. What is this called?
A. Adware
B. Rootkit
C. Trojan Dropper
D. Keylogger
Ans: B (Rootkit)
2. Collects information from one computer and sends it to another computer illegally.
A. Ransomware
B. Viruses
C. Spyware
D. Worms
Ans. C (Spyware)
3. Which of the following attack uses a Rainbow Table
A. Supply Chain Attack
B. Password Attack
C. Spear Phishing
D. Cryptographic attack
Ans: B (Password Attack)
4. A hacker uses software to capture data packets transmitted over a public Wi-Fi network,
gaining unauthorized access to sensitive information. What type of attack does this
represent?
A. Denial-of-Service
B. Eavesdropping
C. Alteration
D. Non-repudiation
Ans. B (Eavesdropping)
5. An attacker sends a fake email that claims to be from the IT department and asks
employees to reset passwords using a malicious link. This attack is known as:
A. SQL Injection
B. Phishing
C. Shoulder Surfing
D. Session Hijacking
Ans: B) Phishing
6. Which type of attack floods a network with ICMP packets, overwhelming its bandwidth
and devices?
A. ICMP Flood
B. DNS Spoofing
C. ARP Poisoning
D. XSS Attack
Ans: A) ICMP Flood
7. What does "complete mediation" ensure in a security context?
A. No security checks are required after initial login
B. Only selected actions of a user are checked
C. A security authority should check every action of a user
D. Users are granted unlimited access to resources
Ans. C (A security authority should check every action of a user)
8. Which principle states that users should only have the minimum level of access required
to perform their job functions?
A. Least Privilege
B. Separation of Duties
C. Fail-Safe Defaults
D. Open Design
Ans: A) Least Privilege
9. A malware that attaches itself to documents like Word or Excel files and executes when
the document is opened is called:
A. Macro Virus
B. Boot Sector Virus
C. Companion Virus
D. Packet Sniffer
Ans: A) Macro Virus
10. Which of the following statements is/are false regarding a security mechanism designed
using the golden principle called "Fail-Safe Defaults"?
A. The security mechanism will continue operating normally even when in a fail state.
B. The security mechanism will continue to work but falls back to its default
configuration.
C. The security mechanism will crash.
D. The security mechanism will remain fully functional without interruption during a fail
state.
Ans. A, C, and D (The security mechanism will continue operating normally even when in
a fail state, The security mechanism will crash, The security mechanism will remain fully
functional without interruption during a fail state.)