1. What is Phishing ? Junior A. corrupting DNS responses so a name resolves to an attacker-controlled IP address B. tricking a logged-in user's browser into sending an unwanted authenticated request C. channel an attacker uses to remotely direct compromised hosts after initial access D. deceptive messages tricking users into revealing credentials or installing malware Reveal the answer + AI explanation — free account
2. Which term means: "deceptive messages tricking users into revealing credentials or installing malware"? Junior A. Phishing B. Spear phishing C. Malware D. Vishing Reveal the answer + AI explanation — free account
3. Which statement is correct? Junior A. Phishing — deceptive messages tricking users into revealing credentials or installing malware B. Phishing — authenticating by replaying a captured password hash without knowing the plaintext password C. Phishing — hiding the true destination of traffic behind a trusted domain on a shared CDN to evade filtering D. Phishing — stealthy, well-resourced adversary maintaining long-term unauthorized access to a network Reveal the answer + AI explanation — free account
4. What is Malware ? Junior A. malicious software such as viruses, worms, trojans, or spyware designed to harm or exploit systems B. attack that overwhelms a system's resources to make it unavailable to legitimate users C. targeted phishing crafted for a specific individual or organization using personalized details D. Distributed Denial of Service using many compromised hosts to flood a target simultaneously Reveal the answer + AI explanation — free account
5. Which term means: "malicious software such as viruses, worms, trojans, or spyware designed to harm or exploit systems"? Junior A. Malware B. Domain fronting C. Smishing D. Lateral movement Reveal the answer + AI explanation — free account
6. Which statement is correct? Junior A. Malware — tricking a logged-in user's browser into sending an unwanted authenticated request B. Malware — requesting service tickets and cracking their encryption offline to recover service-account passwords C. Malware — deceptive messages tricking users into revealing credentials or installing malware D. Malware — malicious software such as viruses, worms, trojans, or spyware designed to harm or exploit systems Reveal the answer + AI explanation — free account
7. What is Ransomware ? Junior A. abusing legitimate built-in tools and binaries to evade detection during an attack B. malware that encrypts a victim's data and demands payment for the decryption key C. techniques an attacker uses to pivot from one compromised host to others inside a network D. deceptive messages tricking users into revealing credentials or installing malware Reveal the answer + AI explanation — free account
8. Which term means: "malware that encrypts a victim's data and demands payment for the decryption key"? Junior A. Brute-force attack B. DDoS C. Ransomware D. Tailgating Reveal the answer + AI explanation — free account
9. Which statement is correct? Junior A. Ransomware — compromising a website a target group frequents to infect visitors with malware B. Ransomware — malware that encrypts a victim's data and demands payment for the decryption key C. Ransomware — attack that overwhelms a system's resources to make it unavailable to legitimate users D. Ransomware — systematically trying many credentials or keys until the correct one is found Reveal the answer + AI explanation — free account
10. What is Denial of Service (DoS) ? Junior A. attack that overwhelms a system's resources to make it unavailable to legitimate users B. social-engineering attack conducted over voice calls to extract information or credentials C. manipulating people into divulging information or performing actions that weaken security D. vulnerability unknown to the vendor and exploited before a patch is available Reveal the answer + AI explanation — free account
11. Which term means: "attack that overwhelms a system's resources to make it unavailable to legitimate users"? Junior A. DDoS B. Clickjacking C. Denial of Service (DoS) D. DNS spoofing Reveal the answer + AI explanation — free account
12. Which statement is correct? Junior A. Denial of Service (DoS) — overlaying invisible UI to trick a user into clicking something different from what they perceive B. Denial of Service (DoS) — attack that overwhelms a system's resources to make it unavailable to legitimate users C. Denial of Service (DoS) — physically following an authorized person through a secured door to gain entry D. Denial of Service (DoS) — compromising a trusted vendor, dependency, or build pipeline to reach downstream targets Reveal the answer + AI explanation — free account
13. What is Social engineering ? Junior A. Distributed Denial of Service using many compromised hosts to flood a target simultaneously B. channel an attacker uses to remotely direct compromised hosts after initial access C. manipulating people into divulging information or performing actions that weaken security D. requesting service tickets and cracking their encryption offline to recover service-account passwords Reveal the answer + AI explanation — free account
14. Which term means: "manipulating people into divulging information or performing actions that weaken security"? Junior A. Social engineering B. DDoS C. Clickjacking D. Smishing Reveal the answer + AI explanation — free account
15. Which statement is correct? Junior A. Social engineering — manipulating people into divulging information or performing actions that weaken security B. Social engineering — physically following an authorized person through a secured door to gain entry C. Social engineering — compromising a website a target group frequents to infect visitors with malware D. Social engineering — authenticating by replaying a captured password hash without knowing the plaintext password Reveal the answer + AI explanation — free account
16. What is Brute-force attack ? Junior A. requesting service tickets and cracking their encryption offline to recover service-account passwords B. stealthy, well-resourced adversary maintaining long-term unauthorized access to a network C. hiding the true destination of traffic behind a trusted domain on a shared CDN to evade filtering D. systematically trying many credentials or keys until the correct one is found Reveal the answer + AI explanation — free account
17. Which term means: "systematically trying many credentials or keys until the correct one is found"? Junior A. Privilege escalation B. Brute-force attack C. Kerberoasting D. Command and Control (C2) Reveal the answer + AI explanation — free account
18. Which statement is correct? Junior A. Brute-force attack — vulnerability unknown to the vendor and exploited before a patch is available B. Brute-force attack — systematically trying many credentials or keys until the correct one is found C. Brute-force attack — channel an attacker uses to remotely direct compromised hosts after initial access D. Brute-force attack — attack that overwhelms a system's resources to make it unavailable to legitimate users Reveal the answer + AI explanation — free account
19. What is Cross-Site Request Forgery (CSRF) ? Mid A. tricking a logged-in user's browser into sending an unwanted authenticated request B. overlaying invisible UI to trick a user into clicking something different from what they perceive C. attack that overwhelms a system's resources to make it unavailable to legitimate users D. targeted phishing crafted for a specific individual or organization using personalized details Reveal the answer + AI explanation — free account
20. Which term means: "tricking a logged-in user's browser into sending an unwanted authenticated request"? Mid A. Command and Control (C2) B. Cross-Site Request Forgery (CSRF) C. Kerberoasting D. Smishing Reveal the answer + AI explanation — free account
21. Which statement is correct? Mid A. Cross-Site Request Forgery (CSRF) — tricking a logged-in user's browser into sending an unwanted authenticated request B. Cross-Site Request Forgery (CSRF) — channel an attacker uses to remotely direct compromised hosts after initial access C. Cross-Site Request Forgery (CSRF) — abusing legitimate built-in tools and binaries to evade detection during an attack D. Cross-Site Request Forgery (CSRF) — hiding the true destination of traffic behind a trusted domain on a shared CDN to evade filtering Reveal the answer + AI explanation — free account
22. What is Man-in-the-Middle (MitM) ? Mid A. channel an attacker uses to remotely direct compromised hosts after initial access B. Distributed Denial of Service using many compromised hosts to flood a target simultaneously C. requesting service tickets and cracking their encryption offline to recover service-account passwords D. intercepting and possibly altering communication between two parties who believe they talk directly Reveal the answer + AI explanation — free account
23. Which term means: "intercepting and possibly altering communication between two parties who believe they talk directly"? Mid A. Business Email Compromise (BEC) B. Cross-Site Request Forgery (CSRF) C. Man-in-the-Middle (MitM) D. Privilege escalation Reveal the answer + AI explanation — free account
24. Which statement is correct? Mid A. Man-in-the-Middle (MitM) — phishing carried out via SMS text messages containing malicious links or requests B. Man-in-the-Middle (MitM) — compromising a website a target group frequents to infect visitors with malware C. Man-in-the-Middle (MitM) — stealthy, well-resourced adversary maintaining long-term unauthorized access to a network D. Man-in-the-Middle (MitM) — intercepting and possibly altering communication between two parties who believe they talk directly Reveal the answer + AI explanation — free account
25. What is Privilege escalation ? Mid A. channel an attacker uses to remotely direct compromised hosts after initial access B. attack that overwhelms a system's resources to make it unavailable to legitimate users C. exploiting a flaw to gain higher permissions than originally granted D. Distributed Denial of Service using many compromised hosts to flood a target simultaneously Reveal the answer + AI explanation — free account
26. Which term means: "exploiting a flaw to gain higher permissions than originally granted"? Mid A. Denial of Service (DoS) B. Cross-Site Request Forgery (CSRF) C. Command and Control (C2) D. Privilege escalation Reveal the answer + AI explanation — free account
27. Which statement is correct? Mid A. Privilege escalation — sending forged ARP messages to associate the attacker's MAC with another host's IP on a LAN B. Privilege escalation — compromising a trusted vendor, dependency, or build pipeline to reach downstream targets C. Privilege escalation — exploiting a flaw to gain higher permissions than originally granted D. Privilege escalation — Distributed Denial of Service using many compromised hosts to flood a target simultaneously Reveal the answer + AI explanation — free account
28. What is DDoS ? Mid A. manipulating people into divulging information or performing actions that weaken security B. malicious software such as viruses, worms, trojans, or spyware designed to harm or exploit systems C. malware that encrypts a victim's data and demands payment for the decryption key D. Distributed Denial of Service using many compromised hosts to flood a target simultaneously Reveal the answer + AI explanation — free account
29. Which term means: "Distributed Denial of Service using many compromised hosts to flood a target simultaneously"? Mid A. Zero-day B. DDoS C. Lateral movement D. ARP spoofing Reveal the answer + AI explanation — free account
30. Which statement is correct? Mid A. DDoS — Distributed Denial of Service using many compromised hosts to flood a target simultaneously B. DDoS — vulnerability unknown to the vendor and exploited before a patch is available C. DDoS — channel an attacker uses to remotely direct compromised hosts after initial access D. DDoS — physically following an authorized person through a secured door to gain entry Reveal the answer + AI explanation — free accountShowing 30 of 87 Threats & Attacks questions — the full set, with answers, explanations and an AI tutor on every question, is inside.