Directions: Read the following passage carefully and answer the question that follows.
As commercial enterprises, state institutions, and the general public increasingly transition toward comprehensive digital operations, network security has emerged as a fundamental cornerstone of daily functioning. Over the past year and a half, security breaches have escalated significantly, targeting organizations of all scales where safeguarding data infrastructure is vital to ongoing performance. Consequently, digital threat protection has ascended to the highest levels of corporate governance. As firms transitioned to remote working arrangements, unauthorized database access and network intrusions proliferated, causing substantial revenue leakage across multiple sectors. Even environments previously deemed highly resilient experienced breaches. Industry statistics reveal that tens of thousands of organizational portals were compromised over a ten-month period by international threat actors concealing their origins.
A major vulnerability stems from inadequate credentials, particularly systems operating with unmanaged or default passwords. Furthermore, malicious code frequently disguised within routine document attachments poses a severe risk once launched by unsuspecting users. Additionally, operating within unencrypted environments—such as public Wi-Fi networks—to access confidential systems or utilizing unauthorized portable drives introduces serious exposure. Organizations bear the primary responsibility to implement preventive countermeasures. They must train personnel to formulate complex credentials and follow strict access safety guidelines. Furthermore, enterprises should continuously update system firewalls through prompt patch management to withstand malware exploits, alongside mandating secure encrypted channels like virtual private networks.
Threat vectors manifest both internally and externally; internal breaches often arise from workforce oversight or lack of awareness, whereas external threats emanate from former staff members, industry competitors, or cybercriminals employing identity spoofing and phishing schemes. Such compromises invariably lead to reputational fallout, capital loss, judicial proceedings, regulatory scrutiny, and a decline in client retention. Concurrently, extortion attacks have intensified, with sensitive data leaks reaching unprecedented levels. For instance, a major social network platform recently endured a critical data compromise in which millions of user files containing contact details and personal identifiers were traded on illicit web forums.
To mitigate these exposure risks, specialized insurance policies have gained traction, covering first-party damages, third-party liabilities, and extortion demands.
First-party coverage addresses financial losses resulting from digital theft, communication disruptions, electronic vandalism, and operational downtime. Third-party coverage protects against client claims arising from security lapses, unauthorized data disclosure, or alleged intellectual property violations. Cyber extortion involves perpetrators threatening system disruption or data leakage unless financial demands are met. Incorporating cyber coverage enables organizations to absorb post-breach recovery expenses and legal costs, serving as an indispensable component of comprehensive business continuity planning.
According to the passage, which of the following factors can lead to a cyber-attack?
Correct Answer :
All of these
Solution :
The correct answer is All of these.
Explanation:
According to the second paragraph of the passage, several distinct factors contribute directly to network vulnerabilities and cyber-attacks:
1. Unmanaged or Default Credentials: The text highlights that "A major vulnerability stems from inadequate credentials, particularly systems operating with unmanaged or default passwords."
2. Malicious Software disguised in Attachments: The passage states that "malicious code frequently disguised within routine document attachments poses a severe risk once launched by unsuspecting users."
3. Unencrypted Environments & Portable Drives: The passage explicitly notes that "operating within unencrypted environments—such as public Wi-Fi networks—to access confidential systems or utilizing unauthorized portable drives introduces serious exposure."
Because all three statements represent vulnerabilities and attack vectors detailed in the text, the correct option is All of these.
Access expert-curated educational resources and study materials—completely free.
Create, conduct, and manage professional online assessments with Mindyard. Perfect for teachers and institutes.
Copyright © 2026 Mindyard. All Rights Reserved.