0% found this document useful (0 votes)
19 views2 pages

Mobile Security Attack Types Quiz

This document contains 17 multiple choice questions about various topics related to information security including: forms of mobile passcode attacks; examples of physical authentication devices; types of biometrics; principles of information security; network attacks; phishing techniques; intrusion detection methods; firewalls; and encryption methods like public key cryptography and RSA. The questions are designed to test knowledge on these topics in information security.

Uploaded by

naaz_pinu
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
19 views2 pages

Mobile Security Attack Types Quiz

This document contains 17 multiple choice questions about various topics related to information security including: forms of mobile passcode attacks; examples of physical authentication devices; types of biometrics; principles of information security; network attacks; phishing techniques; intrusion detection methods; firewalls; and encryption methods like public key cryptography and RSA. The questions are designed to test knowledge on these topics in information security.

Uploaded by

naaz_pinu
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Module 5: Multiple-choice questions:

1. Which of the following are forms of attacks on mobile passcode:


a) Smudge attacks
b) Shoulder-surfing attacks
c) Advanced attacks
d) All of the above
2. All of the following are forms of attacks on mobile passcode, except for:
a) Smudge attacks
b) Shoulder-surfing attacks
c) Facilitated attacks
d) Advanced attacks
3. All of the following are examples of physical devices used to authenticate users, except for:
a) RFID
b) Smart cards
c) eToken
d) smart hub
4. Which of the following are examples of groups of biometrics:
a) Physical biometrics
b) Behavioral biometrics
c) All of the above
d) None of the above
5. All of the following are examples of physical biometrics, except for:
a) Hand geometry
b) Retina
c) Voice
d) DNA
6. All of the following are examples of behavioral biometrics, except for:
a) Gait
b) Keystroke
c) Voice
d) DNA
7. All of the following questions pertain to the 2-factor authentication, except for:
a) Something you are
b) Something you have
c) Something you know
d) Something you think
8. All of the following are principles of information security except for:
a) Confidentiality
b) Communication
c) Availability
d) Integrity
9. Threats to information security include:
a) Intercepted data transfers
b) Physical loss of data
c) Unauthorized access to physical records
d) All of the above
10. All of the following are true for public key cryptography except for:
a) It includes a public-key
b) It includes a private-key
c) It represents a symmetric encryption
d) Those who encrypt messages or verify signatures cannot decrypt messages or create signatures
11. All of the following are approaches to attach RSA security, except for:
a) Targeted attacks
b) Mathematical attacks
c) Timing attacks
d) Brute force key search
12. Methods of DoS attacks include all of the following, except for:
a) Ping of death
b) Browser crashing
c) TCP-SYN flood
d) All of the above are methods of DoS attacks
13. Among the most common types of network attacks are all of the following, except for:
a) Browser attacks
b) Brute force
c) Denial of service
d) PCL
14. All of the following are phishing techniques, except for:
a) Whaling
b) Triggering
c) Clone phishing
d) Spear phishing
15. Intrusion detection methods include:
a) Signature-based methods
b) Anomaly-based methods
c) All of the above
d) None of the above
16. All of the following regarding firewalls are true, except for:
a) It sits between two networks
b) Is used to protect one from the other
c) Places a bottleneck between the networks
d) Some communications must pass through the bottleneck
17. All of the following are protection methods that firewall uses, except for:
a) Proxy services
b) Packet filtering
c) IP masquerading
d) All of the answers are protection methods that firewall uses

Common questions

Powered by AI

RSA encryption can be targeted through mathematical attacks that exploit weaknesses in its number-theory foundations, timing attacks analyzing elapsed computational times, and brute force searches for key discovery. Each method aims to undermine the encryption's reliability by either breaking the encryption itself or obtaining private keys through indirect observation or calculation .

Attacks on mobile passcodes include smudge attacks, shoulder-surfing attacks, and advanced attacks, all of which exploit different vulnerabilities. Smudge attacks rely on analyzing residue on the screen to deduce passcodes. Shoulder-surfing involves observing the user entering their passcode from a close distance. Advanced attacks can include more sophisticated methods such as malware to intercept or guess passcodes .

Phishing techniques such as whaling and clone phishing are tailored to different targets. Whaling targets high-level executives with personalized attacks often leveraging business-related content. Clone phishing adapts legitimate emails to trick regular users by replicating known communications, often embedding malware. Both exploit trust and authority, adapting to the perceived importance and susceptibility of the target .

Public key cryptography involves separate keys for encryption and decryption—a public key to encrypt and a private key to decrypt. This contrasts with symmetric encryption, which uses a single key for both processes. The separation of keys in public key cryptography enables secure communications over insecure channels without the need for key sharing before communication .

2-factor authentication enhances security by requiring two different types of evidence to verify identity: typically something you have, know, or are. This reduces the risk posed by compromised credentials of one type, as an attacker would need to breach both factors to gain unauthorized access, providing a robust layer of security .

Physical biometrics involve static physical attributes like hand geometry and retina, whereas behavioral biometrics focus on actions like keystroke dynamics and gait. Physical biometrics are generally more consistent and harder to replicate, while behavioral biometrics can be influenced by external factors and may require continuous monitoring for authentication .

Signature-based methods rely on known attack patterns, making them ineffective against novel threats. Anomaly-based methods can identify unusual activities, but they may produce false positives by flagging legitimate behavior as malicious. Both methods require continuous updating and tuning to improve accuracy and relevance in changing threat landscapes .

Methods of DoS attacks include ping of death, which involves sending malformed or oversized packets; TCP-SYN flood, where attackers overwhelm resources by initiating many connections without completion; and browser crashing, targeting vulnerabilities to crash the web applications. Each method disrupts operations by exhausting resources or exploiting software vulnerabilities, preventing legitimate access .

Misuse or misconfiguration of firewalls can introduce vulnerabilities such as improperly blocked traffic, which could allow unauthorized access. Unplanned bottlenecks can hamper legitimate communication between networks. Additionally, reliance on firewalls without complementary security measures might provide a false sense of security .

The primary principles of information security are confidentiality, integrity, and availability. Communication is not included because it serves as a medium rather than a protective measure. These principles focus on safeguarding data by ensuring it is only accessible to authorized individuals, accurate and reliable, and readily available when needed .

You might also like