1/140
Exam for INFO I-230 on October 1.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What is the CIA Triad?
The foundational principles of Cybersecurity: Confidentiality, Integrity, and Availability.
Confidentiality
Individual assets are only accessible to authorized parties.
Integrity
Individual assets can only be modified by authorized parties in authorized ways.
Availability
Authorized parties can access the assets to an agreed extent.
Non-repudiation
Prevents individuals from denying their actions when agreeing to digital transactions.
Threat actors
a term for individuals whose purpose is to exploit system weaknesses.
Hacktivist
Dedicated individuals who wreak havoc to draw attention to a political or ideological cause.
Insider Threats
Individuals who pose a threat to the organization they work for.
Organized Crime
Groups that maintain a level of coordination through the use of employing different teams to develop malware.
Shadow IT
Individuals within an organization who utilize unauthorized devices to bypass IT policies.
Internal threat actors
Individuals with official access to data of an organization who pose a threat.
External threat actors
Individuals that work outside an organization to weaken defenses.
Resources and funding
Resources bad actors may have. Organized crime groups may have high resources, hacktivists and unskilled attackers rely on publicly available tools.
What is a threat vector?
A method or pathway a cyber attacker uses to gain initial access to a system or network.
Message-based vector
Exploits email, SMS, or instant messaging platforms to deceive users.
Image-based vector
Exploits harmless-looking images to compromise systems.
File-based vector
Exploits trusted file formats to deliver malicious payloads.
Voice call vector
Known as vishing, these attack vectors impersonate trusted entities, deceiving victims into revealing sensitive information. They primarily rely on spoofing techniques.
Removable Devices vector
A type of threat vector that employs the use of portable items such as USB drives.
Vulnerable software vector
A type of threat vector that targets system vulnerabilities to execute malicious code, steal data, or gain unauthorized access.
Unsupported Systems and Applications
Systems that no longer receive updates, patches, or technical support from the vendor.
Unsecure Networks
Networks that are a prominent target for threat actors due to their inherit vulnerabilities and widespread use in personal and corporate environments.
Open Service Ports
A gateway for attackers to exploit misconfigured or unnecessary services.
Default Credentials
Usernames and passwords that come with systems that aren’t changed, creating a great risk.
Supply Chain
The interconnected systems that organizations operate on are attacked.
Phishing
An attacker sending emails, texts, or harmful links that lure the user into giving confidential info.
Vishing
An attacker impersonates a trusted entity to tempt a user into giving confidential information.
Smishing
Text phishing. An attacker employs urgency to get the user to giving confidential information.
Misinformation
A social engineering tactic involving an attacker sharing false information to manipulate behavior.
Pretexting
A fabricated scenario that manipulates a victim into providing important information.
Watering hole
Targets specific groups or organizations by compromising websites they are likely to visit.
Brand impersonation
A vector where attackers mimic the appearance of well-known brands to deceive victims.
Typosquatting
Exploits minor typographical errors that users make when entering website URLs.
What is a vulnerability?
A flaw or weakness in a system that attackers exploit to compromise CIA.
Buffer overflow
A vulnerability where a program writes more data to a memory buffer than it can hold, overwriting adjacent memory. Allows attackers to inject and execute malicious code.
Race conditions
A vulnerability where multiple threads or processes attempt to access and modify a shared resource simultaneously without proper synchronization.
Time-of-use (TOU)
An attack where an attacker exploits a timing gap by modifying or swapping the resource between the check and the access.
Structured Query Language injection (SQLi)
An attack that bypasses authentication, retrieving sensitive data, and modifying database contents.
Cross-site scripting (XSS)
Weakens web applications, allowing for attackers to inject malicious scripts into web pages for other users.
Cryptographic Vulnerability
Weak encryption, poor key management, or insecure protocols that let attackers access or alter protected data.
Misconfiguration
Incorrect system settings that leave systems exposed to unauthorized access or attack.
Zero-day
An unknown software, hardware, or firmware flaw that has not yet been discovered or addressed by the vendor.
Side loading
A vulnerability where an application is installed from unofficial or unverified sources.
Jailbreaking
Removing the manufacturer’s restrictions on a mobile device to gain root or administrative access.
Hardware vulnerabilities
A vulnerability from weaknesses in physical components, allowing attackers to compromise them at a fundamental level.
Firmware vulnerabilities
A vulnerability in a low-level device software that attackers can exploit for high-privilege access.
Virtual machine (VM) escape
A critical threat to environments reliant on virtualized infrastructure where attackers gain access to the host system or other guest VMs.
Resources reuse
A vulnerability that arises when virtual machines share physical resources, such as memory or disk space. allowing attackers to exploit this by recovering residual data after a VM is shut down or reallocated.
Supply chain vulnerability
A weakness in a trusted third party or component attackers exploit. Service providers, hardware providers, and software providers.
Technical controls
Technology used to protect information systems and enforce policies.
Managerial controls
Provide policies, procedures, and guidelines that define an organization’s security framework
Operational controls
human oversight over day-to-day activities and processes that upkeep security.
Physical controls
Cameras, security guards, etc., protecting tangible assets of an organization.
Preventive controls
Designed to stop security incidents before they occur.
Deterrent controls
Designed to discourage malicious activity instead of directly preventing it.
Detective controls
Identifies and alerts security teams to suspicious activities or security breaches.
Corrective controls
Responding to security incidents and mitigating their impact.
Directive controls
Establish security expectations and ensure compliance with security policies.
Non-repudiation
Prevents individuals from denying their digital actions.
Authenticating People
A process that ensures that users who are accessing a system are who they claim to be.
Authenticating Systems
Ensures devices, applications, and services communicating in a network are legitimate.
Authorization Models
Determines what authenticated users and systems are enabled to do in a network or application.
Access Control
A fundamental security measure regulating who or what can access the systems, data, and resources of an organization.
Access Control list (ACL)
An access control method that defines rules specifying which users or systems can access certain network resources.
Least Privilege
Ensures users, applications, and systems are granted access necessary to perform their specific functions.
Domain-based Message Authentication, Reporting, and Conformance (DMARC)
An email authentication protocol that helps protect domains from spoofing and phishing attacks.
DomainKeys Identified Mail (DKIM)
A process that checks the authenticity of an email by attaching a digital signature to its header.
Sender Policy Framework (SPF)
Allows domain owners to specify which mail servers are authorized to send messages on their behalf.
Gateways
Filters out spam, phishing attempts, and malicious content before they reach end users in email systems.
Group Policy
Allows administrators to enforce security settings and configurations across multiple devices in a network.
SELinux (Security-Enhanced Linux)
A security module integrated into Linux operating systems, enforcing mandatory access control (MAC).
Mandatory Access Control (MAC)
The system determines who has access based on predefined security policies. These cannot be altered by the user.
Discretionary Access Control (DAC)
A user-friendly model allowing resource owners to decide who can access their data or resources, can give too many permissions.
Role-based Access Control (RBAC)
A model that assigns permissions based on a user’s role within an organization.
Attribute-based Access Control (ABAC)
Evaluates access requests based on attributes associated with the user, resource, or environment.
Public Key Infrastructure (PKI)
A framework that enables secure communication and authentication using cryptographic key pairs.
Public key
A cryptographic key freely distributed, used for encryption or digital signature verification
Private key
A secret cryptographic key that is securely stored, used for decryption or digital signature verification.
Key escrow
Cryptographic keys securely stored by a trusted third party for recovery purposes.
Encryption
A fundamental security measure protecting data by converting readable information into an unreadable format.
Full-disk encryption
Protects all data stored on an entire storage device
Partition encryption
A level of encryption that secures a certain section of a storage device instead of the entire disk.
File encryption
A level of encryption that protects individual files by encrypting their contents.
Volume encryption
A level of encryption that applies protection to a logical volume, spanning multiple physical storage devices.
Database encryption
Secures entire databases or specific tables within a database.
Record encryption
Encrypts individual records within a database or file system.
Transport and communication encryption
A level of encryption that protects data in transit.
Asymmetric encryption
A level of encryption that uses a pair of cryptographic keys–one public and one private–to secure data.
Symmetric encryption
A level of encryption that relies on a single shared key for both encryption and decryption, making it faster and more efficient than asymmetric encryption.
Key exchange
Ensures that encryption keys are securely shared between communicating parties.
Encryption algorithms
Define the mathematical processes used to transform plaintext into ciphertext and vice versa.
Hardware Security Module (HSM)
A device that securely generates, stores, and manages cryptographic keys for high-security applications.
Key Management System (KMS)
A centralized solution for creating, distributing, storing, and revoking cryptographic keys across an organization.
Secure enclave
An isolated processing environment protecting sensitive data and cryptographic operations from unauthorized access.
Obfuscation
Makes data difficult to understand or interpret, protecting sensitive information from unauthorized access.
Steganography
Hiding data within another file or medium, such as embedding a message within an image, audio file, or video.
Tokenization
Replaces sensitive data with unique identifiers, or tokens, that have no exploitable value outside of a secure environment
Hashing
Transforms input data into a fixed length.
Salting
Adding a unique, random value (the “salt”) to input data before hashing, Producing different hash outputs even if same input.
Digital Signature
Leverages hashing to verify the authenticity and integrity of data or messages.