4.4 Quiz: Detecting Attacks on Devices
4.4 Quiz: Detecting Attacks on Devices
5 questions · 7-minute target · Instant feedback · AP exam format
Answer all 5 questions. Click Check Answer after each to see feedback. Score appears after the last question. Target: 4 of 5 or better before moving to Lesson 4.5.
00:00
Dynamic is a manufacturing company that makes precision metal components. Its office network was breached on 11 March 2026. IT operations lead Yusuf Aydin has asked you to review the authentication logs from devices on the manufacturing network, identify any indicators of compromise, and recommend detection controls. Incident reference DYN-IR-2026-018.
The estate you are covering: 240 office laptops and desktops, 6 servers holding customer and payroll records, 60 plant-floor embedded controllers, 18 shared kiosk PCs, and one internet-facing remote-access portal. The portal locks an account after 5 failed sign-ins in 15 minutes.
02:14:03 FAIL user=a.okonkwo src=203.0.113.77 reason=bad_password 02:14:05 FAIL user=b.ramirez src=203.0.113.77 reason=bad_password 02:14:06 FAIL user=c.delacruz src=203.0.113.77 reason=bad_password ... 37 further accounts, one attempt each ... 02:14:51 FAIL user=y.aydin src=203.0.113.77 reason=bad_password 02:58:12 FAIL user=a.okonkwo src=203.0.113.77 reason=bad_password ... the same 41 accounts again, one attempt each ... 02:59:02 FAIL user=y.aydin src=203.0.113.77 reason=bad_password 02:59:04 OK user=r.castellano src=203.0.113.77Which conclusion does this log BEST support?
ROW DEVICE GROUP DETECTION METHOD REASON GIVEN
1 240 office laptops/desktops Third-party EDR service Highest-value user endpoints; the
with a central console license cost buys unified monitoring
2 6 customer and payroll servers Hybrid: signature scanning Sensitive data and critical services
plus anomaly monitoring justify maximum coverage
3 60 plant-floor controllers Anomaly-based agent on Anomaly detection uses fewer system
each controller resources than signature scanning
4 18 shared kiosk PCs Signature-based anti- Low-power hardware; signature
malware, daily updates matching has few false positives
5 Remote-access portal Automated authentication- Auth logs are where online password
log analysis with alerts attacks become visible
Which correction does the plan MOST need?
I. A sign-in by an authorized user from an IP address and at an hour that are both unusual for that account is a behavior-based indicator of compromise.
II. A file whose hash matches a known-malware hash is a behavior-based indicator, because the hash describes what the file does when it runs.
III. Because the system logs every login attempt, failed attempts from an offline attack on a stolen hash database will appear in the portal’s authentication log.
Which of the statements above is TRUE?
r.castellano. Working from that account, the adversary exported the portal’s local user-and-hash database before Yusuf cut the session. Plant systems supervisor Bea Lindqvist wants the smallest change that will close the incident. Which response is BEST?
Get in Touch
Whether you're a student, parent, or teacher — I'd love to hear from you.
Just want free AP CS resources?
Enter your email below and check the subscribe box — no message needed. Students get daily practice questions and study tips. Teachers get curriculum resources and teaching strategies.
Message Sent!
Thanks for reaching out. I'll get back to you within 24 hours.
Prefer email? Reach me directly at [email protected]