Threats & Vulnerabilities

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/18

flashcard set

Earn XP

Description and Tags

Last updated 1:00 AM on 10/1/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

19 Terms

1
New cards

What is a cyberattack that disrupts access to a website, service, or network by overwhelming it with excessive traffic or malicious requests from a single, compromised source

DoS (DDoS if using multiple compromised sources)

2
New cards

What is a cyberattack where a rouge WAP is set up for eavesdropping or stealing sensitive user data by replacing a legitamite AP and advertising its own presence with the same SSID

Evil twin

3
New cards

What is an attack that takes advantage of a previously unknown software vulnerability that the developer has not yet patched

Zero-day attack

4
New cards

What is the term for an attacker falsifyingan identifier (email address, IP address, MAC address, caller ID, or website) to appear as a trusted source, with the intent to decieve targets, bypass filters, or redirect traffic for malicious purpouses

Spoofing

5
New cards

What is an attack where the attacker, impersonates one of the communicating parties to alter the communication, intercept and modify the packets sent between two communicating devices, or place themselves in the middle of the communication route

On-path attack

6
New cards

What is a cyberattack that relies on testing every possible combination of letters, numbers, and symbols to gain unauthorized access to accounts, systems, or encrypted data

Brute-force attack

7
New cards

What password attack takes advantage of a predefined list of words

Dictionary attack

8
New cards

What is a term for disgruntled employee abusing legitimate access to a company’s internal resources

Insider threat

9
New cards

What is a security vulnerability that allows an attacker to inject malicious code into input fields, such as search bars or login forms, to execute unauthorized commands on a database

SQL Injection

10
New cards

What is a cyberattack where an attacker injects a malicious script into a trusted website, is executed in the user’s browser, and exploits the trust a user’s web browser has in a website

XXS attack

11
New cards

What is a phishing cyberattack that impersonates executives, vendors, or trusted partners via email to trick organizations into harmful actions

BEC

12
New cards

What is a cybersecurity threat where attackers compromise a trusted third-party vendor, software provider, or service in the distribution pipeline to insert malicious code, hardware, or updates

Supply chain attack

13
New cards

What defines a set of rules enforced in a network that clients attempting to access the network must comply with

NAC (Network Access Control)

14
New cards

What is it called when NAC policies are applied before the host is allowed to connect to the network

Pre-admission NAC

15
New cards

What is it called when a host is granted or denied permissions based on its actions after it has been provided access to the network

Post-admission NAC

16
New cards

What is a type of vulnerability where a system is breached because of known critical security flaws

Unpatched systems

17
New cards

What controls are considered basic first-line, active defenses that reduce risk from common vulnerabilities on endpoints

  • Host-based firewalls

  • Antivirus software


18
New cards

What is the most critical security risk posed by an EOL system

Newly discovered vulnerabilities will remain permanently unpatched

19
New cards

What mobile device deployment model allows employees to use their personal mobile devices to access a company’s restricted data and application

BYOD