Match the key security concept with its description.請將關鍵安全概念與其描述配對。
| threat威脅(threat) | any circumstance or event with the potential to cause harm to an asset任何可能對資產造成損害的情況或事件 |
| vulnerability弱點(vulnerability) | likelihood that a particular threat using a specific attack will exploit particular vulnerability特定威脅利用特定攻擊手法,實際利用某項弱點的可能性 |
| exploit利用(exploit) | weakness that compromises either the security or the functionality of a system會危及系統安全性或功能性的弱點 |
| risk風險(risk) | methods and corrective actions that you can take to protect against threats, specific exploits, and so on可用來防範威脅、特定利用手法等的方法與矯正措施 |
| mitigation techniques緩解技術(mitigation techniques) | mechanism that is used to leverage a vulnerability to compromise the security or functionality of a system用來運用某項弱點以危及系統安全性或功能性的機制 |
Which two options are examples of a DDoS attack? (Choose two.)以下哪兩項是 DDoS 攻擊的範例?(選擇兩項。)
You have detected that there is a rogue DHCP server in the local area network that replies to client DHCP requests before they reach the authentic DHCP server in the company. Which two options describe this type of attack? (Choose two.)你偵測到區域網路中有一台惡意 DHCP 伺服器,會在用戶端的 DHCP 請求送達正式 DHCP 伺服器之前,搶先回覆這些請求。以下哪兩個選項描述了這種攻擊類型?(選擇兩項。)
You are reading an article in the news regarding a DNS amplification attack to a specific organization. The attack caused DDoS that made it impossible for anyone to resolve the organization's website IP address and access the website. Which statement regarding an amplification attack is correct?你正在閱讀一篇關於某組織遭受 DNS 放大攻擊的新聞報導。該攻擊造成 DDoS,使得任何人都無法解析該組織網站的 IP 位址並存取該網站。關於放大攻擊,以下哪個敘述是正確的?
You are asked to conduct a training session in your company to educate employees about social engineering attacks. What is a common social engineering technique?你被要求在公司內舉辦一場訓練課程,向員工說明社交工程攻擊。以下何者是常見的社交工程手法?
Match the type of attack with its description.請將攻擊類型與其描述配對。
| spear phishing魚叉式網路釣魚(spear phishing) | emails sent to smaller, more targeted groups, even a single individual寄送給規模較小、更具針對性群體,甚至單一個人的電子郵件 |
| whaling捕鯨式釣魚(whaling) | Victims are lured by compromising name services.受害者是透過遭入侵的名稱服務被誘導上鉤。 |
| pharming農場式攻擊(pharming) | uses voice and the phone system as its medium以語音與電話系統作為媒介 |
| watering hole水坑式攻擊(watering hole) | emails sent to targeted groups of high profile individuals, such as top executives寄送給高知名度目標群體(例如高階主管)的電子郵件 |
| vishing語音釣魚(vishing) | uses SMS texting as its medium以簡訊(SMS)作為媒介 |
| smishing簡訊釣魚(smishing) | leverages a compromised web server to target select group that visits this website regularly利用遭入侵的網頁伺服器,鎖定經常造訪該網站的特定群體 |
Which two security measures can help block password brute force attacks? (Choose two.)以下哪兩項安全措施有助於阻擋密碼暴力破解攻擊?(選擇兩項。)
You want to display public information regarding your company's domain from the public DNS registries so you can see what information can be gathered by a reconnaissance attack on the DNS. Which command-line tool can you use on a Microsoft Windows computer?你想從公開的 DNS 註冊機構顯示有關公司網域的公開資訊,以便了解攻擊者透過對 DNS 進行偵察攻擊可以蒐集到哪些資訊。在 Microsoft Windows 電腦上,你可以使用哪一種命令列工具?
Which statement regarding a buffer overflow attack is correct?關於緩衝區溢位攻擊,以下哪一個敘述是正確的?
Which two options represent man-in-the-middle attacks? (Choose two.)以下哪兩項屬於中間人攻擊?(選擇兩項。)
The anti-malware software in your company has discovered malicious software that replicated itself on several computers with functional copies that can cause the same type of damage. Which two malware types can compromise other systems? (Choose two.)你公司的防惡意軟體軟體發現了一個惡意軟體,它已在多台電腦上自我複製,並產生具有相同破壞能力的功能性副本。以下哪兩種惡意軟體類型可以入侵其他系統?(選擇兩項。)
Which three represent common vectors that can inflict data loss and exfiltration regarding unauthorized transfer of company data? (Choose three.)以下哪三項是可能導致資料遺失與外洩、涉及公司資料未經授權轉移的常見向量?(選擇三項。)
You are working as IT security engineer and you are browsing through the sectools.org website to see the top network security tools, as well as find more details on each particular tool and read reviews for it. What is the initiative that runs this website?你目前擔任 IT 安全工程師,正在瀏覽 sectools.org 網站,以查看熱門的網路安全工具,並進一步了解每項工具的詳細資訊與相關評論。是哪個組織在營運這個網站?
Match the example of threat vectors with its description.請將威脅向量的範例與其描述配對。
| cognitive threats via social networks透過社群網路的認知威脅 | Attackers create false identities on social networks, building and exploiting friend relationships with others on the social network.攻擊者在社群網路上建立虛假身分,藉此與社群網路上的其他人建立並利用朋友關係。 |
| consumer electronics exploits消費性電子產品漏洞利用 | Attackers try to exploit operating systems and applications that leave traces of data in memory, to fetch information directly from the volatile memory.攻擊者嘗試利用會在記憶體中留下資料痕跡的作業系統與應用程式,直接從揮發性記憶體擷取資訊。 |
| virtualization exploits虛擬化漏洞利用 | Attackers target operating systems on consumer devices, such as smartphones, tablets, and so on.攻擊者鎖定消費性裝置(例如智慧型手機、平板電腦等)上的作業系統。 |
| memory scraping記憶體擷取 | Attackers perform bus sniffing, altering firmware, memory dumping to find crypto keys, utilize hardware-based keyloggers, etc.攻擊者進行匯流排監聽、竄改韌體、傾印記憶體以尋找加密金鑰,並利用以硬體為基礎的按鍵側錄器等手法。 |
| hardware hacking硬體駭入 | Attackers targeting virtual servers, virtual switches, and trust relationships at the hypervisor level.攻擊者鎖定虛擬伺服器、虛擬交換器,以及 Hypervisor 層級的信任關係。 |