0% found this document useful (0 votes)
28 views3 pages

Zombie Usage in Cyber Attacks

1) The quiz questions cover characteristics of worms, how zombies are used in attacks, tools for identifying open ports, types of attacks like DoS and password cracking, the purpose of rootkits and how malware can be concealed. 2) Worms are self-replicating and travel to new computers without user intervention. Zombies are infected machines used to carry out DDoS attacks. Nmap provides lists of open ports. DoS aims to prevent servers handling requests. Rootkits gain privileged access while concealing themselves. 3) Malware concealment examples include tricking users to install malware, building botnets, overwhelming networks with packets, and increasing traffic to malicious sites.

Uploaded by

Benojr
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
28 views3 pages

Zombie Usage in Cyber Attacks

1) The quiz questions cover characteristics of worms, how zombies are used in attacks, tools for identifying open ports, types of attacks like DoS and password cracking, the purpose of rootkits and how malware can be concealed. 2) Worms are self-replicating and travel to new computers without user intervention. Zombies are infected machines used to carry out DDoS attacks. Nmap provides lists of open ports. DoS aims to prevent servers handling requests. Rootkits gain privileged access while concealing themselves. 3) Malware concealment examples include tricking users to install malware, building botnets, overwhelming networks with packets, and increasing traffic to malicious sites.

Uploaded by

Benojr
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as DOCX, PDF, TXT or read online on Scribd

Chapter 2 - Attacks, Concepts and Techniques Quiz

1. Which two characteristics describe a worm?


a) Hides in a dormant state until wanted by an attacker
b) Executes when software is run on a computer
c) Travels to new computers without any intervention or knowledge of the user
d) Infects computers by attaching to software code
e) Is self-replicating
2. In what ways are zombies used in security attacks?
a) They are maliciously formed code segments to replace legitimate applications
b) They probe a group of machines for open ports to learn which services are running
c) They target specific individuals to gain corporate or personal information
d) They are infected machines that carry out a DDoS attack
3. Which tool is used to provide a list of open port on network devices?
a) Nmap
b) Ping
c) Whois
d) Tracert
4. Which type of attack allows an attacker to use a brute force approach?
a) Social engineering
b) Denial of service
c) Packet sniffing
d) Password cracking
5. What is the primary goal of a DoS attack?
a) To facilitate access to external networks
b) To prevent the target server from being able to handle additional requests
c) To obtain all addresses in the address book within the server
d) To scan the data on the target server
6. What is the purpose of a rootkit?
a) To replicate itself independently of any other programs
b) To gain privileged access to a device while concealing itself
c) To deliver advertisements without user consent
d) To masquerade as a legitimate program
7. Which example illustrates how malware might be concealed?
a) A hacker uses techniques to improve the ranking of a website so that the users are
directed to a malicious website
b) An attack is launched against the public website of an online retailer with the
objective of blocking its response to visitors
c) A botnet of zombies carries personal information back to the hacker
d) An email is sent to an employee of an organization with an attachment that looks
like an antivirus update, but the attachment actually consists of spyware
8. What is the main goal of search engine optimization (SEO) poisoning?
a) To trick someone into installing malware or divulging personal information
b) To build a botnet of zombies
c) To overwhelm a network device with maliciously formed packets
d) To increase web traffic to malicious sites

Page 1|3
9. This is the name given to amateur hackers.

a) Hacktivist
b) Gray Hat
c) Black Hat
d) Script Kiddies

10. This category of threat is actually from current employees authorized to be on


the network.

a) Internal
b) Gray hat
c) External
d) Black Hat

Chapter Summary

1) Identify examples of security vulnerabilities:

 weak passwords
 unsecured network protocols
 misconfigured firewalls

2) Explain how a security vulnerability is exploited.

When an attacker discovers a security vulnerability in a system, they will attempt to exploit it to
gain access or control of the system. The process of exploiting a vulnerability involves the following
steps:

 Reconnaissance
 Escalation of Privileges
 Exploitation
 Maintaining Access
 Covering Tracks

3) Describe types of malware and their symptoms, methods of infiltration, methods used to deny
service:

 Ransomware : Ransomware is malware designed to encrypt data on a user's computer in


exchange for payment. Symptoms include files suddenly encrypted or a ransom message

Page 2|3
appearing on the screen. Ransomware can deny service by rendering files inaccessible until
the ransom is paid.
 Virus : A virus is a program that infects other programs or files, and it can spread rapidly
through email attachments or infected downloads. Symptoms include slow computer
performance, frequent crashes, and missing files. Viruses can deny service by causing the
system to reboot continuously or by deleting critical system files.
 Spyware : Spyware is designed to secretly monitor a user's computer activity, internet usage
or steal personal information such as usernames and passwords. Symptoms include slow
computer performance or odd behavior when browsing the web. Spyware can deny service
by launching an endless series of pop-up ads or redirecting users to unwanted websites.
 Trojan : A trojan is a type of malware that disguises itself as a legitimate software program,
but instead it works quietly in the background to steal sensitive information or grant
unauthorized access. Symptoms may include slower computer performance or pop-up ads.
Trojans can deny service by opening up a backdoor on the infected machine or by deleting
important files.

4) Describe a blended attack and the importance of impact reduction:

A blended attack is a type of cyber attack that combines multiple methods or techniques to achieve
a specific goal, such as stealing data or taking control of a system. Blended attacks can use a
combination of social engineering, malware, and other tactics to bypass security measures and gain
unauthorized access to a network or system.

Impact reduction is important in the context of blended attacks because the goal is to minimize the
overall impact of an attack. Impact reduction strategies can include things like regular data backups,
network segmentation, security monitoring and incident response plans. By implementing these
measures, organizations can minimize the overall damage caused by a potential breach.

Page 3|3

Common questions

Powered by AI

Ransomware symptoms include sudden data encryption or ransom messages on screens demanding payment to restore access. The consequences include potential data loss and business disruption, as files become inaccessible without decryption keys. This restriction is enforced by encrypting data, rendering it unreadable until the ransom is paid .

Viruses and trojans differ primarily in their methods of infiltration and behavior. Viruses infect other programs or files and spread through email attachments or downloads, often causing system crashes and file loss. Trojans disguise themselves as legitimate software, but once installed, they quietly steal information or install backdoors. Unlike viruses, trojans do not self-replicate .

Zombies, which are infected machines, function by inundating a target with traffic as part of a DDoS attack. They offer the advantage of overwhelming the target server, preventing it from handling legitimate requests, while keeping the attacker anonymous as the real source of the attack is masked behind infected computers .

Script kiddies use premade scripts without deep understanding, making their attacks less sophisticated but easier to execute. While effective against poorly defended systems, they lack the adaptability and complexity of more advanced techniques used by skilled hackers, which can target specific systems and evade detection through custom-crafted exploits .

SEO poisoning is used to manipulate search engine rankings to direct users to malicious sites. This can lead to malware infections or the theft of personal information, as victims are tricked into visiting websites that appear safe and relevant but are controlled by attackers .

Worms are particularly insidious because they can travel to new computers without user intervention or knowledge, making them difficult to detect and stop. They are self-replicating, which allows them to spread rapidly across networks by exploiting vulnerabilities in network-attached devices .

A blended attack combines multiple attack methods, such as social engineering and malware, to bypass defenses and achieve malicious goals. Impact reduction strategies include regular data backups to prevent data loss, network segmentation to contain intrusion spread, and detailed incident response plans to quickly react and minimize damage during an attack .

Internal threats originate from within the organization, often involving employees with authorized access who misuse their privileges, such as accessing confidential information. External threats come from outside, typically involving hackers attempting unauthorized access or attacks via methods like phishing or exploiting vulnerabilities. Internal threats are often more challenging to detect due to existing permissions .

Maintaining access is crucial for attackers to continue exploiting a system or exfiltrating data over time. Methods include installing rootkits, which provide privileged access while hiding their presence, and creating backdoors to allow re-entry at will without detection .

Reconnaissance is the process of gathering information about a target system to identify vulnerabilities that can be exploited. It is critical as it informs the attacker about the weaknesses, network architecture, and potential entry points, setting the foundation for a successful attack by guiding subsequent steps like escalation of privileges and exploitation .

You might also like