Computer Security mid term

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/81

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 7:11 PM on 10/7/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

82 Terms

1
New cards

CIA triad

Confidentiality, Integrity, Availability

2
New cards

Confidentiality

Only authorized people can see the data

3
New cards

Integrity

Data is accurate and unaltered

4
New cards

Availability

Authorized users can access data when needed

5
New cards

AAA

Authentication, Authorization, Accounting

6
New cards

Authentication

Proving who you are

7
New cards

Authorization

What you are allowed to do

8
New cards

Accounting

Recording what a user did

9
New cards

Three layers of protection

Products, people, and policies & procedures

10
New cards

Security vs. convenience

Inversely related - more security usually means less convenience

11
New cards

Asset

Something of value that needs protecting

12
New cards

Threat

A type of action that could cause harm

13
New cards

Threat actor

A person or group who carries out an attack

14
New cards

Vulnerability

A weakness that allows a threat to cause harm

15
New cards

Exploit

Taking advantage of a vulnerability

16
New cards

Risk

The likelihood that a threat actor will exploit a vulnerability

17
New cards

Why attacks are hard to prevent

Easy-to-use attack tools, faster and more sophisticated attacks, vulnerabilities found faster than patched, confused users

18
New cards

Cybercriminals

Motivated by financial gain; organized and well funded

19
New cards

Script kiddies

Low-skill attackers using tools written by others; want thrills/attention

20
New cards

Brokers

Find vulnerabilities and sell them to the highest bidder

21
New cards

Insiders

Employees or contractors with trusted access; revenge, money, or carelessness

22
New cards

Cyberterrorists

Motivated by ideology; aim to cause fear and disruption, often targeting infrastructure

23
New cards

Hacktivists

Motivated by political or social causes

24
New cards

State actors

Government-backed attackers serving national interests (espionage); most resources, long stealthy attacks

25
New cards

Five key elements of a comprehensive security strategy

Block attacks, update defenses, minimize losses, manage risk, send secure information

26
New cards

Authentication elements

Something you know, something you have, something you are (also somewhere you are, something you do)

27
New cards

Hashing

Turning a password into a fixed-length string with a one-way algorithm

28
New cards

Digest

The fixed-length output of a hash algorithm; what the server stores instead of the password

29
New cards

How password login is checked

The typed password is hashed and its digest compared to the stored digest

30
New cards

Why passwords are weak

People can only remember short, simple passwords, so they reuse them and pick predictable ones

31
New cards

Brute force attack

Trying every possible combination of characters

32
New cards

Dictionary attack

Trying common words and known passwords

33
New cards

Password spraying

Trying a few common passwords against many accounts

34
New cards

Rainbow table

Precomputed digests used to crack stolen password hashes quickly

35
New cards

Credential stuffing

Reusing username/password pairs leaked from another breach

36
New cards

Social engineering

Tricking people into breaking security; targets human psychology, not technology

37
New cards

Social engineering psychological approaches

Authority, intimidation, urgency, scarcity, consensus, familiarity, trust

38
New cards

Phishing

Fake messages or sites that trick users into giving up information

39
New cards

Spear phishing

Phishing targeted at specific people

40
New cards

Whaling

Phishing aimed at executives or wealthy targets

41
New cards

Vishing

Voice phishing (phone calls)

42
New cards

Smishing

Phishing by text message (SMS)

43
New cards

Typo squatting

Registering misspelled domain names to catch users' typing errors (URL hijacking)

44
New cards

Hoax

A false warning that tricks users into a harmful action, like deleting a file

45
New cards

Identity theft

Using someone's personal information to open accounts or make purchases in their name

46
New cards

First step in creating a defensive stance

Identify the assets that need protection

47
New cards

Strong password

Long (length matters most), unique, not based on personal info; passphrases help

48
New cards

Password manager

Software that generates and securely stores passwords

49
New cards

Two-factor authentication (2FA)

Login requiring two different types of authentication

50
New cards

Two steps of avoiding identity theft

1) Deter thieves by protecting personal info; 2) Monitor financial statements and credit reports

51
New cards

Malware

Software that enters a computer without consent and performs harmful actions

52
New cards

Zero-day attack

Exploits a flaw before the vendor knows about it or has a patch

53
New cards

How malware is classified

By the primary action it performs

54
New cards

Kidnap malware

Ransomware

55
New cards

Eavesdrop malware

Spyware and keyloggers

56
New cards

Masquerade malware

PUPs, Trojans, RATs

57
New cards

Launchpad malware

Viruses, worms, bots/botnets

58
New cards

Sidestep malware

Backdoors, logic bombs, rootkits

59
New cards

Ransomware

Holds a computer or its data hostage until a ransom is paid

60
New cards

Blocking (locker) ransomware

Locks the user out of the device

61
New cards

Crypto-malware

Ransomware that encrypts the user's files

62
New cards

Spyware

Secretly collects information about the user

63
New cards

Software keylogger

A program that records keystrokes

64
New cards

Hardware keylogger

A small physical device between keyboard and computer that records keystrokes

65
New cards

PUP (potentially unwanted program)

Unwanted but not clearly malicious software, like adware or toolbars

66
New cards

Trojan

Looks like useful software but hides malware

67
New cards

RAT (remote access Trojan)

A Trojan that also gives the attacker remote control of the computer

68
New cards

Virus

Attaches to a file and needs user action to spread

69
New cards

Two types of viruses

File-based and fileless

70
New cards

Worm

Spreads by itself across networks with no user action

71
New cards

Bot / botnet

Infected computer controlled by a bot herder; many bots form a botnet used for spam or DDoS

72
New cards

Backdoor

A hidden way to bypass normal security for secret access

73
New cards

Logic bomb

Dormant code that activates when a specific condition is met

74
New cards

Rootkit

Hides malware by altering the operating system so normal tools can't detect it

75
New cards

Patch

A vendor software update that fixes security flaws

76
New cards

Most important step to protect your computer

Keep it patched / install updates promptly

77
New cards

Antivirus vs. antimalware

Antivirus mainly finds viruses via signatures; antimalware covers more threats (spyware, rootkits, ransomware) often with behavior-based detection

78
New cards

Firewall

Hardware or software that filters network traffic by rules

79
New cards

Software (host-based) firewall

Runs on one computer; can control which apps send/receive traffic, including outbound

80
New cards

Hardware (network) firewall

Separate device protecting all devices on a network by filtering incoming traffic

81
New cards

Best defense against ransomware

Current backups you can restore from

82
New cards

Ways to create backups

External drive (local) or cloud/online backup; keep one copy disconnected