Unit 6: Hacking Wi-Fi and Bluetooth, Mobile Device Security, Cloud Technologies and Security - Practice Quiz

INT244 — Securing Computing Systems 50 Questions
0 Correct 0 Wrong 50 Left
0/50

1 Which IEEE standard governs Wireless LAN (WLAN) technologies?

A. IEEE 802.11
B. IEEE 802.1X
C. IEEE 802.15
D. IEEE 802.3

2 In the context of wireless security, what is an 'Evil Twin' attack?

A. A rogue access point that mimics a legitimate SSID to intercept traffic
B. Two hackers working simultaneously on the same network
C. A virus that replicates itself on mobile devices
D. A bluetooth attack that crashes the device

3 Which wireless encryption protocol is considered the weakest and has been deprecated due to severe vulnerabilities?

A. WPA3
B. WPA2
C. WEP
D. WPA-Enterprise

4 What is the primary difference between Bluejacking and Bluesnarfing?

A. Bluejacking sends unsolicited messages, while Bluesnarfing involves stealing data
B. Bluejacking involves stealing data, while Bluesnarfing sends unsolicited messages
C. There is no difference; they are synonyms
D. Bluejacking takes full control of the device, while Bluesnarfing only crashes it

5 Which Bluetooth attack allows an attacker to take full control of a target device to make calls or send texts?

A. Bluestriking
B. Bluejacking
C. Bluebugging
D. Bluesnarfing

6 What is the primary function of a SIEM (Security Information and Event Management) system?

A. To encrypt mobile device hard drives
B. To aggregate and analyze log data from various sources to detect security incidents
C. To manage cloud subscriptions
D. To act as a firewall for wireless networks

7 In a Security Operations Center (SOC), what is the main responsibility of Tier 1 analysts?

A. Triage and initial classification of security alerts
B. Managing the budget of the security team
C. Deep forensic analysis
D. Threat hunting

8 What core component does the Android operating system use as its foundation?

A. Windows NT Kernel
B. Microkernel
C. Darwin Kernel
D. Linux Kernel

9 iOS utilizes a security mechanism that restricts apps from accessing data or processes of other apps. What is this called?

A. Hypervising
B. Rooting
C. Containerization
D. Sandboxing

10 The process of removing software restrictions imposed by Apple on iOS devices is known as:

A. Rooting
B. Unlocking
C. Jailbreaking
D. Sideloading

11 On Android devices, gaining administrative (superuser) privileges is referred to as:

A. Rooting
B. Bootloading
C. Jailbreaking
D. Phishing

12 Which mobile security model involves separating personal and corporate data on the same device?

A. BYOD (Bring Your Own Device)
B. Direct Access
C. Containerization
D. CYOD (Choose Your Own Device)

13 What is 'Sideloading' in the context of mobile security?

A. Installing applications from sources other than the official app store
B. Charging a device via a malicious USB port
C. Turning the phone sideways to bypass facial recognition
D. Transferring data to the cloud

14 Which solution allows IT administrators to remotely wipe, lock, and configure mobile devices across an enterprise?

A. MDM (Mobile Device Management)
B. IDS (Intrusion Detection System)
C. WPA2
D. VPN (Virtual Private Network)

15 What is the 'Shared Responsibility Model' in cloud computing?

A. Security obligations are divided between the cloud provider and the customer
B. Multiple cloud providers share the cost of security
C. The customer is responsible for everything
D. The cloud provider is responsible for everything

16 Which Cloud Service Model provides the consumer with the capability to provision processing, storage, and networks (e.g., AWS EC2)?

A. DaaS (Desktop as a Service)
B. PaaS (Platform as a Service)
C. IaaS (Infrastructure as a Service)
D. SaaS (Software as a Service)

17 Which Cloud Service Model delivers applications over the internet (e.g., Gmail, Salesforce)?

A. SaaS (Software as a Service)
B. PaaS (Platform as a Service)
C. IaaS (Infrastructure as a Service)
D. FaaS (Function as a Service)

18 Google App Engine and Microsoft Azure App Service are examples of which cloud model?

A. SaaS
B. PaaS
C. Hybrid
D. IaaS

19 Which cloud deployment model is exclusively used by a single organization?

A. Private Cloud
B. Public Cloud
C. Hybrid Cloud
D. Community Cloud

20 What is a major security risk associated with Insecure APIs in cloud computing?

A. They consume too much electricity
B. They slow down the internet connection
C. They can expose sensitive data or allow unauthorized control if not properly authenticated
D. They prevent the use of firewalls

21 In the context of Wireless security, what is 'War Driving'?

A. Using a drone to jam signals
B. Physically driving around to locate and map open or vulnerable wireless networks
C. Driving a tank into a data center
D. Overclocking a CPU to increase speed

22 Which of the following is a countermeasure against Bluetooth attacks?

A. Using a PIN of '0000'
B. Keeping Bluetooth in 'Discoverable' mode at all times
C. Broadcasting the device name publicly
D. Setting the device to 'Non-discoverable' or 'Hidden' mode when not pairing

23 What is a 'Rogue Access Point'?

A. An unauthorized wireless access point installed on a secure network
B. A software update for Wi-Fi drivers
C. A secure router provided by the ISP
D. A firewall rule that blocks traffic

24 What is the purpose of SSID broadcasting?

A. To announce the presence and name of the wireless network to nearby devices
B. To encrypt the data traffic
C. To block unauthorized users
D. To increase the speed of the internet

25 Which mobile threat involves an attacker intercepting communication between the user and a server?

A. Screen locking
B. Man-in-the-Middle (MitM) attack
C. Geofencing
D. Data resting

26 What is 'Shadow IT' in the context of Cloud Security?

A. Backup data stored in a dark room
B. A hacking group targeting clouds
C. The use of IT systems and cloud services without explicit approval from the IT department
D. Dark mode interfaces in cloud apps

27 Which cloud attack involves an attacker exploiting the shared resources in a virtualized environment to access data from another tenant?

A. Phishing
B. SQL Injection
C. Guest-Escape / Hypervisor Jumping
D. DDoS

28 What is a CASB (Cloud Access Security Broker)?

A. A government agency regulating clouds
B. A type of cloud malware
C. A physical lock for server rooms
D. Software that sits between cloud service users and cloud applications to enforce security policies

29 Why is 'Multitenancy' a security concern in the cloud?

A. It makes the internet slower
B. Multiple customers share the same physical resources, creating a risk of data leakage if isolation fails
C. It requires more electricity
D. It increases the cost of storage

30 Which of the following is a critical step when testing security in the cloud (Penetration Testing)?

A. Testing only on weekends
B. Ignoring the Service Level Agreement
C. Launching an attack without warning
D. Obtaining permission from the Cloud Service Provider (CSP) before testing

31 What does WPA3 use to replace the WPA2 Pre-Shared Key exchange, making it resistant to offline dictionary attacks?

A. Plaintext
B. Simultaneous Authentication of Equals (SAE)
C. TKIP
D. WEP

32 What is a 'Botnet' often used for in cloud attacks?

A. Perform Distributed Denial of Service (DDoS) attacks
B. Indexing web pages
C. Mining cryptocurrency legally
D. Backing up data

33 What allows Android users to verify what capabilities an application is requesting (e.g., access to camera, contacts)?

A. Root Access
B. App Permissions
C. The instruction manual
D. Kernel Panic

34 Which wireless security protocol uses TKIP (Temporal Key Integrity Protocol)?

A. WPA
B. WPA2
C. WPA3
D. WEP

35 What is 'Geo-tagging' and why is it a mobile security risk?

A. Using GPS for maps; it uses data
B. Playing games based on location; it wastes battery
C. Tagging friends in photos; it is a privacy violation
D. Embedding location data in photos/posts; it reveals the user's physical location to stalkers

36 In the context of SOC, what does 'Correlation' mean?

A. Backing up files to two locations
B. Linking different events from log files to identify a complex attack pattern
C. Communicating with the HR department
D. Connecting the power cables

37 Which of the following is a physical security threat to mobile devices?

A. Malware
B. Theft or Loss
C. SQL Injection
D. Phishing

38 What is 'Cryptojacking' in a cloud environment?

A. Hacking into a bank
B. Encrypting data for ransom
C. Unauthorized use of cloud computing resources to mine cryptocurrency
D. Stealing credit card numbers

39 The NIST definition of Cloud Computing includes 'Rapid Elasticity'. What does this mean?

A. The cloud is made of rubber
B. Data is stored on flexible disks
C. Capabilities can be elastically provisioned and released to scale rapidly outward and inward
D. The internet speed is constant

40 Which attack vector involves a malicious insider abusing their authorized access to cloud data?

A. War Driving
B. DDoS
C. Outsider Threat
D. Insider Threat

41 What is the primary function of a Virtual Private Network (VPN) on a mobile device connecting to public Wi-Fi?

A. To boost signal strength
B. To create an encrypted tunnel for data, protecting it from interception
C. To download apps faster
D. To bypass battery limits

42 Which Bluetooth class has the longest range (approximately 100 meters)?

A. Class 3
B. Class 4
C. Class 1
D. Class 2

43 What is 'MAM' in mobile security?

A. Main Access Module
B. Man-Against-Machine
C. Mobile Access Monitoring
D. Mobile Application Management

44 Which file format is used for installing software on the Android operating system?

A. .EXE
B. .IPA
C. .APK
D. .DMG

45 In cloud security, what does 'Data Sovereignty' refer to?

A. The speed of data transfer
B. The king of data
C. The concept that data is subject to the laws of the country in which it is physically stored
D. The encryption level of data

46 What is a 'Hybrid Cloud'?

A. A cloud that runs on gas and electricity
B. A cloud that only stores images
C. A cloud maintained by a single person
D. A composition of two or more clouds (private, community, or public) that remain unique entities but are bound together

47 Which wireless attack involves capturing handshake packets and attempting to crack the password offline?

A. WPA Cracking / Dictionary Attack
B. Beacon Flooding
C. Signal Jamming
D. MAC Filtering

48 What is 'MAC Address Filtering'?

A. Cleaning the router
B. Blocking websites
C. Filtering out Mac computers
D. Allowing or denying network access based on the hardware address of the network card

49 Why is 'Remote Wipe' a critical feature for enterprise mobile security?

A. To clean the screen remotely
B. To delete apps that are not used
C. To erase sensitive corporate data if a device is lost or stolen
D. To update the OS remotely

50 Which of the following is a symptom of a mobile device being infected with malware?

A. Screen becoming brighter
B. Faster performance
C. Extended battery life
D. Unexpected data usage spikes and rapid battery drain