INFO I-230 Exam

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/140

flashcard set

Earn XP

Description and Tags

Exam for INFO I-230 on October 1.

Last updated 1:23 PM on 10/1/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

141 Terms

1
New cards

What is the CIA Triad?

The foundational principles of Cybersecurity: Confidentiality, Integrity, and Availability.

2
New cards

Confidentiality

Individual assets are only accessible to authorized parties.

3
New cards

Integrity

Individual assets can only be modified by authorized parties in authorized ways.

4
New cards

Availability

Authorized parties can access the assets to an agreed extent.

5
New cards

Non-repudiation

Prevents individuals from denying their actions when agreeing to digital transactions.

6
New cards

Threat actors

a term for individuals whose purpose is to exploit system weaknesses.

7
New cards

Hacktivist

Dedicated individuals who wreak havoc to draw attention to a political or ideological cause.

8
New cards

Insider Threats

Individuals who pose a threat to the organization they work for.

9
New cards

Organized Crime

Groups that maintain a level of coordination through the use of employing different teams to develop malware.

10
New cards

Shadow IT

Individuals within an organization who utilize unauthorized devices to bypass IT policies.

11
New cards

Internal threat actors

Individuals with official access to data of an organization who pose a threat.

12
New cards

External threat actors

Individuals that work outside an organization to weaken defenses.

13
New cards

Resources and funding

Resources bad actors may have. Organized crime groups may have high resources, hacktivists and unskilled attackers rely on publicly available tools.

14
New cards

What is a threat vector?

A method or pathway a cyber attacker uses to gain initial access to a system or network.

15
New cards

Message-based vector

Exploits email, SMS, or instant messaging platforms to deceive users.

16
New cards

Image-based vector

Exploits harmless-looking images to compromise systems.

17
New cards

File-based vector

Exploits trusted file formats to deliver malicious payloads.

18
New cards

Voice call vector

Known as vishing, these attack vectors impersonate trusted entities, deceiving victims into revealing sensitive information. They primarily rely on spoofing techniques.

19
New cards

Removable Devices vector

A type of threat vector that employs the use of portable items such as USB drives.

20
New cards

Vulnerable software vector

A type of threat vector that targets system vulnerabilities to execute malicious code, steal data, or gain unauthorized access.

21
New cards

Unsupported Systems and Applications

Systems that no longer receive updates, patches, or technical support from the vendor.

22
New cards

Unsecure Networks

Networks that are a prominent target for threat actors due to their inherit vulnerabilities and widespread use in personal and corporate environments.

23
New cards

Open Service Ports

A gateway for attackers to exploit misconfigured or unnecessary services.

24
New cards

Default Credentials

Usernames and passwords that come with systems that aren’t changed, creating a great risk.

25
New cards

Supply Chain

The interconnected systems that organizations operate on are attacked.

26
New cards

Phishing

An attacker sending emails, texts, or harmful links that lure the user into giving confidential info.

27
New cards

Vishing

An attacker impersonates a trusted entity to tempt a user into giving confidential information.

28
New cards

Smishing

Text phishing. An attacker employs urgency to get the user to giving confidential information.

29
New cards

Misinformation

A social engineering tactic involving an attacker sharing false information to manipulate behavior.

30
New cards

Pretexting

A fabricated scenario that manipulates a victim into providing important information.

31
New cards

Watering hole

Targets specific groups or organizations by compromising websites they are likely to visit.

32
New cards

Brand impersonation

A vector where attackers mimic the appearance of well-known brands to deceive victims.

33
New cards

Typosquatting

Exploits minor typographical errors that users make when entering website URLs.

34
New cards

What is a vulnerability?

A flaw or weakness in a system that attackers exploit to compromise CIA.

35
New cards

Buffer overflow

A vulnerability where a program writes more data to a memory buffer than it can hold, overwriting adjacent memory. Allows attackers to inject and execute malicious code.

36
New cards

Race conditions

A vulnerability where multiple threads or processes attempt to access and modify a shared resource simultaneously without proper synchronization.

37
New cards

Time-of-use (TOU)

An attack where an attacker exploits a timing gap by modifying or swapping the resource between the check and the access.

38
New cards

Structured Query Language injection (SQLi)

An attack that bypasses authentication, retrieving sensitive data, and modifying database contents.

39
New cards

Cross-site scripting (XSS)

Weakens web applications, allowing for attackers to inject malicious scripts into web pages for other users.

40
New cards

Cryptographic Vulnerability

Weak encryption, poor key management, or insecure protocols that let attackers access or alter protected data.

41
New cards

Misconfiguration

Incorrect system settings that leave systems exposed to unauthorized access or attack.

42
New cards

Zero-day

An unknown software, hardware, or firmware flaw that has not yet been discovered or addressed by the vendor.

43
New cards

Side loading

A vulnerability where an application is installed from unofficial or unverified sources.

44
New cards

Jailbreaking

Removing the manufacturer’s restrictions on a mobile device to gain root or administrative access.

45
New cards

Hardware vulnerabilities

A vulnerability from weaknesses in physical components, allowing attackers to compromise them at a fundamental level.

46
New cards

Firmware vulnerabilities

A vulnerability in a low-level device software that attackers can exploit for high-privilege access.

47
New cards

Virtual machine (VM) escape

A critical threat to environments reliant on virtualized infrastructure where attackers gain access to the host system or other guest VMs.

48
New cards

Resources reuse

A vulnerability that arises when virtual machines share physical resources, such as memory or disk space. allowing attackers to exploit this by recovering residual data after a VM is shut down or reallocated.

49
New cards

Supply chain vulnerability

A weakness in a trusted third party or component attackers exploit. Service providers, hardware providers, and software providers.

50
New cards

Technical controls

 Technology used to protect information systems and enforce policies.

51
New cards

Managerial controls

Provide policies, procedures, and guidelines that define an organization’s security framework

52
New cards

Operational controls

human oversight over day-to-day activities and processes that upkeep security.

53
New cards

Physical controls

Cameras, security guards, etc., protecting tangible assets of an organization.

54
New cards

Preventive controls

Designed to stop security incidents before they occur.

55
New cards

Deterrent controls

Designed to discourage malicious activity instead of directly preventing it.

56
New cards

Detective controls

Identifies and alerts security teams to suspicious activities or security breaches.

57
New cards

Corrective controls

Responding to security incidents and mitigating their impact.

58
New cards

Directive controls

Establish security expectations and ensure compliance with security policies.

59
New cards

Non-repudiation

Prevents individuals from denying their digital actions.

60
New cards

Authenticating People

A process that ensures that users who are accessing a system are who they claim to be.

61
New cards

Authenticating Systems

Ensures devices, applications, and services communicating in a network are legitimate.

62
New cards

Authorization Models

Determines what authenticated users and systems are enabled to do in a network or application.

63
New cards

Access Control

 A fundamental security measure regulating who or what can access the systems, data, and resources of an organization.

64
New cards

Access Control list (ACL)

An access control method that defines rules specifying which users or systems can access certain network resources.

65
New cards

Least Privilege

Ensures users, applications, and systems are granted access necessary to perform their specific functions.

66
New cards

Domain-based Message Authentication, Reporting, and Conformance (DMARC)

An email authentication protocol that helps protect domains from spoofing and phishing attacks.

67
New cards

DomainKeys Identified Mail (DKIM)

A process that checks the authenticity of an email by attaching a digital signature to its header.

68
New cards

Sender Policy Framework (SPF)

Allows domain owners to specify which mail servers are authorized to send messages on their behalf.

69
New cards

Gateways

Filters out spam, phishing attempts, and malicious content before they reach end users in email systems.

70
New cards

Group Policy

Allows administrators to enforce security settings and configurations across multiple devices in a network.

71
New cards

SELinux (Security-Enhanced Linux)

A security module integrated into Linux operating systems, enforcing mandatory access control (MAC).

72
New cards

Mandatory Access Control (MAC)

The system determines who has access based on predefined security policies. These cannot be altered by the user.

73
New cards

Discretionary Access Control (DAC)

A user-friendly model allowing resource owners to decide who can access their data or resources, can give too many permissions.

74
New cards

Role-based Access Control (RBAC)

A model that assigns permissions based on a user’s role within an organization.

75
New cards

Attribute-based Access Control (ABAC)

Evaluates access requests based on attributes associated with the user, resource, or environment.

76
New cards

Public Key Infrastructure (PKI)

A framework that enables secure communication and authentication using cryptographic key pairs.

77
New cards

Public key

A cryptographic key freely distributed, used for encryption or digital signature verification

78
New cards

Private key

A secret cryptographic key that is securely stored, used for decryption or digital signature verification.

79
New cards

Key escrow

Cryptographic keys securely stored by a trusted third party for recovery purposes.

80
New cards

Encryption

A fundamental security measure protecting data by converting readable information into an unreadable format.

81
New cards

Full-disk encryption

Protects all data stored on an entire storage device

82
New cards

Partition encryption

A level of encryption that secures a certain section of a storage device instead of the entire disk.

83
New cards

File encryption

A level of encryption that protects individual files by encrypting their contents.

84
New cards

Volume encryption

A level of encryption that applies protection to a logical volume, spanning multiple physical storage devices.

85
New cards

Database encryption

Secures entire databases or specific tables within a database.

86
New cards

Record encryption

Encrypts individual records within a database or file system.

87
New cards

Transport and communication encryption

A level of encryption that protects data in transit.

88
New cards

Asymmetric encryption

A level of encryption that uses a pair of cryptographic keys–one public and one private–to secure data.

89
New cards

Symmetric encryption

A level of encryption that relies on a single shared key for both encryption and decryption, making it faster and more efficient than asymmetric encryption.

90
New cards

Key exchange

Ensures that encryption keys are securely shared between communicating parties.

91
New cards

Encryption algorithms

Define the mathematical processes used to transform plaintext into ciphertext and vice versa.

92
New cards

Hardware Security Module (HSM)

A device that securely generates, stores, and manages cryptographic keys for high-security applications.

93
New cards

Key Management System (KMS)

A centralized solution for creating, distributing, storing, and revoking cryptographic keys across an organization.

94
New cards

Secure enclave

An isolated processing environment protecting sensitive data and cryptographic operations from unauthorized access.

95
New cards

Obfuscation

Makes data difficult to understand or interpret, protecting sensitive information from unauthorized access.

96
New cards

Steganography

Hiding data within another file or medium, such as embedding a message within an image, audio file, or video.

97
New cards

Tokenization

Replaces sensitive data with unique identifiers, or tokens, that have no exploitable value outside of a secure environment

98
New cards

Hashing

Transforms input data into a fixed length.

99
New cards

Salting

Adding a unique, random value (the “salt”) to input data before hashing, Producing different hash outputs even if same input.

100
New cards

Digital Signature

Leverages hashing to verify the authenticity and integrity of data or messages.