1/52
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What are the highest of security concerns for senior executives and others who are charged with IT governance?
Breaches of data, theft, service interruptions, and regulatory non-compliance
What are Data Breaches?
Occur when information is compromised and utilized without the authorization of the owner
What are Service Interruptions/Disruptions?
An unplanned event that causes the general system or major application to be inoperable for an unacceptable length of time
What is Compliance Risk?
Regulators can require organizations to comply with cybersecurity regulations. Failure to comply with these regulations can result in fines and financial penalties.
What is Cybersecurity?
The practice of protecting an organization’s IT infrastructure and critical data from bad actors by deploying a variety of different items
What is the gaol of cybersecurity?
To manage the cybersecurity risks by securing and enhancing confidentiality, data integrity, and availability
How should organizations combat cybersecurity risk?
Discuss various programs to mitigate cybersecurity risks and constantly update security measures
What is a cyberattack?
Any kind of malicious activity that targets computer information systems, infrastructures, computer networks, or personal computer devices and attempts to collect, disrupt, deny, degrade, or destroy information system resources or the information itself
Who do cyberattacks impact?
Everyone (customer, vendor, org)
What is a threat agent?
An internal or external attacker that could negatively impact data security through theft, manipulation, or control of sensitive information or systems
What are examples of the different types of threat agents?
Attacker, Threat Actor, or Hacker
Adversary
Government-Sponsored/State-Sponsored Actors
Hacktivists
Insiders
External Threats
What is an Attacker, Threat Actor, or Hacker?
These are individuals or groups of individuals known as hacking rings or Advanced Persistent Threats (APTs) that target people or organizations to gain access to systems, networks, and data
What is an Adversary?
These are actors with interests in conflict with the organization
What are Government-Sponsored/Stated-Sponsored Actors?
These threat actors are funded, directed, or sponsored by nations
What are Hacktivists?
These are usually groups of hackers that operate to promote certain social causes or political agendas
What are Insiders?
Employees who either organically develop into someone with malicious intentions or intentionally infiltrate an organization to achieve nefarious objectives
What are External Threats?
Threats that occur from outside of the organization, entity, or individual that is the source of the cyberattack
What are the different types of cyberattacks?
Network-Based Attacks
Application-Based Attacks
Host-Based Attacks
Social Engineering Attacks
Physical (on-Premises) Attacks
Supply Chain Attacks
What are Network-Based Attacks?
These attacks target the infrastructure of a network, including switches, routers, servers, and cabling, with the intent to gain unauthorized access or disrupt operations for users
What are examples of Network-Based Attacks?
Backdoors and Trapdoors
Covert Channels
Buffer Overflows
Denial-of-Service (DoS)
Distributed Denial-of-Service (DDoS)
Man-in-the-Middle (MITM)
Port Scanning
Ransomware
Reverse Shell
Replay (eavesdropping)
Return-Oriented
Spoofing
What are Backdoors and Trapdoors?
Methods to bypass security installed by system owners (facilitate entry)
What are Covert Channels?
Method to transmit data not originally intended (2 Types: Storage & Timing)
What are Buffer Overflows?
Attackers overload a program’s storage with more input than it can hold
What is a Denial-of-Service (Dos)?
Attacker floods a system’s network by congesting it with large volumes of traffic greater than it can handle
What is a Distributed Denial-of-Service (DDoS)?
When multiple attackers work in unison to flood an org’s network with traffic
What is a Man-in-the-Middle (MITM) attack?
Type of eavesdropping where the attacker intercepts communication between 2 parties
What is Port Scanning?
Done to find vulnerabilities that can be exploited to gain unauthorized access (logical parts)
What is Ransomware?
Malware that locks users and systems/apps unless ransom is paid
What is a Reverse Shell attack?
Victim initiates communication with attacker so attacker can bypass the firewall (originates inside)
What is Replay (Eavesdropping)?
Type of MITM attack where the attacker records it
What is a Return-Oriented attack?
Utilizes pieces of organization’s legit system code in a sequence to perform operations useful to the attacker
What is Spoofing?
Act of impersonating someone to obtain unauthorized access to system (Types: Address Resolution, Domain Name, Hyperlink)
What is an Application-Based Attack?
These forms of attacks target specific software or applications (desktop or web), such as databases or websites, to gain unauthorized access or disrupt functionality
What are examples of Application-Based Attacks?
Structured Query Language (SQL) Injection
Cross-Site Scripting (XSS)
Race Condition
Malicious Mobile Code
What is a Structured Query Language (SQL) Injection?
Inject malicious SQlL code into existing SQL code on a company’s website to gain unauthorized access
What is Cross-Site Scripting (XSS)?
Inject code to a company’s website that attacks users visiting the company’s website. When the user visits the site, browser executes the malicious code.
What is Race Condition?
Attacker exploits system that relies on a specific sequence of operations
What is Malicious Mobile Code?
Malicious code referred to as a virus (overwrite, multi-partite, parasitic, polymorphic, resident)
What are Host-Based Attacks?
These attacks target a single host, such as a laptop, mobile device, or server, to disrupt functionality or obtain unauthorized access
What are examples of host-based attacks?
Brute Force Attacks
Keystroke Logging
Malware
Rogue Movile Apps
What are Brute Force Attacks?
Password-cracking scheme
What is a Keystroke Logging attack?
Tracking the sequence of keys pressed by a user to collect data
What is Malware?
Software intended to perform unauthorized processes that has an advantageous impact
What is a Rogue Mobile App?
The use of a malicious app that appears legit
What is a Social Engineering Attack?
These attacks involve the use of psychological manipulation or deception to get employees to divulge sensitive information, provide unauthorized access, or assist an attacker in committing fraud
What are examples of Social Engineering Attacks?
Phishing
Spear Phishing
Business Email Compromise (BEC)
Pretexting
Catfishing
Pharming
Vishing
What is Phishing?
An authentic looking, but bogus email
What is Spear Phishing?
Targets specific employees in an organization by posing as a legitimate employee
What is a Business Email Compromise (BEC)?
Targets executives and other high-ranking people (aka whaling)
What is Pretexting?
Creating a fake identity/scenario so that employee has a sense of urgency
What is Catfishing?
Creating a fake online persona
What is Pharming?
Victim enters personal information into a web that looks legit
What is Vishing?
Using the telephonic voice over internet protocol (VolP) to create a fake caller ID