1/18
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What is a cyberattack that disrupts access to a website, service, or network by overwhelming it with excessive traffic or malicious requests from a single, compromised source
DoS (DDoS if using multiple compromised sources)
What is a cyberattack where a rouge WAP is set up for eavesdropping or stealing sensitive user data by replacing a legitamite AP and advertising its own presence with the same SSID
Evil twin
What is an attack that takes advantage of a previously unknown software vulnerability that the developer has not yet patched
Zero-day attack
What is the term for an attacker falsifyingan identifier (email address, IP address, MAC address, caller ID, or website) to appear as a trusted source, with the intent to decieve targets, bypass filters, or redirect traffic for malicious purpouses
Spoofing
What is an attack where the attacker, impersonates one of the communicating parties to alter the communication, intercept and modify the packets sent between two communicating devices, or place themselves in the middle of the communication route
On-path attack
What is a cyberattack that relies on testing every possible combination of letters, numbers, and symbols to gain unauthorized access to accounts, systems, or encrypted data
Brute-force attack
What password attack takes advantage of a predefined list of words
Dictionary attack
What is a term for disgruntled employee abusing legitimate access to a company’s internal resources
Insider threat
What is a security vulnerability that allows an attacker to inject malicious code into input fields, such as search bars or login forms, to execute unauthorized commands on a database
SQL Injection
What is a cyberattack where an attacker injects a malicious script into a trusted website, is executed in the user’s browser, and exploits the trust a user’s web browser has in a website
XXS attack
What is a phishing cyberattack that impersonates executives, vendors, or trusted partners via email to trick organizations into harmful actions
BEC
What is a cybersecurity threat where attackers compromise a trusted third-party vendor, software provider, or service in the distribution pipeline to insert malicious code, hardware, or updates
Supply chain attack
What defines a set of rules enforced in a network that clients attempting to access the network must comply with
NAC (Network Access Control)
What is it called when NAC policies are applied before the host is allowed to connect to the network
Pre-admission NAC
What is it called when a host is granted or denied permissions based on its actions after it has been provided access to the network
Post-admission NAC
What is a type of vulnerability where a system is breached because of known critical security flaws
Unpatched systems
What controls are considered basic first-line, active defenses that reduce risk from common vulnerabilities on endpoints
Host-based firewalls
Antivirus software
What is the most critical security risk posed by an EOL system
Newly discovered vulnerabilities will remain permanently unpatched
What mobile device deployment model allows employees to use their personal mobile devices to access a company’s restricted data and application
BYOD