Challenge Categories
3 questions
CTF challenges cluster into a handful of recognisable categories — web, cryptography, reverse engineering, vulnerability exploitation, and flag retrieval — each demanding a different toolkit.
Q1
A "web application challenge" in CTF terms typically requires participants to:
1 mark
Q2
A "reverse engineering challenge" requires participants to:
1 mark
Q3
In CTF "flag retrieval" challenges, participants typically:
1 mark
Challenge Categories score
0/3
Social Engineering & OSINT
7 questions
Social engineering manipulates people, not machines. OSINT (Open-Source Intelligence) gathers information from public sources — and both show up regularly as CTF challenge categories.
Q4
Social engineering, as defined in the lecture, is:
1 mark
Q5
Which of these are named as ways social engineering can operate? (select all)
2 marks
Q6
OSINT stands for:
1 mark
Q7
Who, according to the slides, can practise OSINT?
1 mark
Q8
Which of these is listed as an OSINT tool in the lecture?
1 mark
Q9
Which OSINT resource lets you view historical/archived snapshots of a website (useful for finding "the first version" of a site)?
1 mark
Q10
Why are keystrokes and mouse movements a security concern, per the lecture?
1 mark
Social Engineering & OSINT score
0/8
Hardware & Real-World Cases
4 questions
Not every CTF challenge is purely digital — some involve physical hardware, and real-world incidents show how far these attacks can reach.
Q11
The Olympic CTF 2014 "shredded paper" challenge is used as an example that some CTF puzzles require:
1 mark
Q12
Hardware-based CTF challenges may involve:
1 mark
Q13
The "Industroyer" attack by the Sandworm group targeted:
1 mark
Q14
MITRE, known for the ATT&CK framework, is also mentioned as leading efforts in which growing CTF area?
1 mark
Hardware & Real-World Cases score
0/4
Mindset & Tips
6 questions
Misc challenges are often the hardest because they don't fit a predictable pattern — success comes down to a deliberate approach and a willingness to expect (and work around) failure.
Q15
When approaching an unfamiliar CTF challenge, the lecture's first recommended step is to pause and think about:
1 mark
Q16
A common terminology confusion the lecture warns novices about is:
1 mark
Q17
"Murphy's Law," as invoked in the lecture, means:
1 mark
Q18
Why are miscellaneous ("misc") CTF challenges often considered among the hardest category?
1 mark
Q19
Which of these is explicitly named as a technique used in social-engineering-flavoured CTF challenges?
1 mark
Q20
For image-based misc challenges, the lecture suggests checking for:
1 mark
Mindset & Tips score
0/6
—
Complete all questions to see your final score