S3: Security and Confidentiality

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/52

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 2:05 AM on 10/1/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

53 Terms

1
New cards

What are the highest of security concerns for senior executives and others who are charged with IT governance?

Breaches of data, theft, service interruptions, and regulatory non-compliance

2
New cards

What are Data Breaches?

Occur when information is compromised and utilized without the authorization of the owner

3
New cards

What are Service Interruptions/Disruptions?

An unplanned event that causes the general system or major application to be inoperable for an unacceptable length of time

4
New cards

What is Compliance Risk?

Regulators can require organizations to comply with cybersecurity regulations. Failure to comply with these regulations can result in fines and financial penalties.

5
New cards

What is Cybersecurity?

The practice of protecting an organization’s IT infrastructure and critical data from bad actors by deploying a variety of different items

6
New cards

What is the gaol of cybersecurity?

To manage the cybersecurity risks by securing and enhancing confidentiality, data integrity, and availability

7
New cards

How should organizations combat cybersecurity risk?

Discuss various programs to mitigate cybersecurity risks and constantly update security measures

8
New cards

What is a cyberattack?

Any kind of malicious activity that targets computer information systems, infrastructures, computer networks, or personal computer devices and attempts to collect, disrupt, deny, degrade, or destroy information system resources or the information itself

9
New cards

Who do cyberattacks impact?

Everyone (customer, vendor, org)

10
New cards

What is a threat agent?

An internal or external attacker that could negatively impact data security through theft, manipulation, or control of sensitive information or systems

11
New cards

What are examples of the different types of threat agents?

  • Attacker, Threat Actor, or Hacker

  • Adversary

  • Government-Sponsored/State-Sponsored Actors

  • Hacktivists

  • Insiders

  • External Threats


12
New cards

What is an Attacker, Threat Actor, or Hacker?

These are individuals or groups of individuals known as hacking rings or Advanced Persistent Threats (APTs) that target people or organizations to gain access to systems, networks, and data

13
New cards

What is an Adversary?

These are actors with interests in conflict with the organization

14
New cards

What are Government-Sponsored/Stated-Sponsored Actors?

These threat actors are funded, directed, or sponsored by nations

15
New cards

What are Hacktivists?

These are usually groups of hackers that operate to promote certain social causes or political agendas

16
New cards

What are Insiders?

Employees who either organically develop into someone with malicious intentions or intentionally infiltrate an organization to achieve nefarious objectives

17
New cards

What are External Threats?

Threats that occur from outside of the organization, entity, or individual that is the source of the cyberattack

18
New cards

What are the different types of cyberattacks?

  • Network-Based Attacks

  • Application-Based Attacks

  • Host-Based Attacks

  • Social Engineering Attacks

  • Physical (on-Premises) Attacks

  • Supply Chain Attacks


19
New cards

What are Network-Based Attacks?

These attacks target the infrastructure of a network, including switches, routers, servers, and cabling, with the intent to gain unauthorized access or disrupt operations for users

20
New cards

What are examples of Network-Based Attacks?

  • Backdoors and Trapdoors

  • Covert Channels

  • Buffer Overflows

  • Denial-of-Service (DoS)

  • Distributed Denial-of-Service (DDoS)

  • Man-in-the-Middle (MITM)

  • Port Scanning

  • Ransomware

  • Reverse Shell

  • Replay (eavesdropping)

  • Return-Oriented

  • Spoofing


21
New cards

What are Backdoors and Trapdoors?

Methods to bypass security installed by system owners (facilitate entry)

22
New cards

What are Covert Channels?

Method to transmit data not originally intended (2 Types: Storage & Timing)

23
New cards

What are Buffer Overflows?

Attackers overload a program’s storage with more input than it can hold

24
New cards

What is a Denial-of-Service (Dos)?

Attacker floods a system’s network by congesting it with large volumes of traffic greater than it can handle

25
New cards

What is a Distributed Denial-of-Service (DDoS)?

When multiple attackers work in unison to flood an org’s network with traffic

26
New cards

What is a Man-in-the-Middle (MITM) attack?

Type of eavesdropping where the attacker intercepts communication between 2 parties

27
New cards

What is Port Scanning?

Done to find vulnerabilities that can be exploited to gain unauthorized access (logical parts)

28
New cards

What is Ransomware?

Malware that locks users and systems/apps unless ransom is paid

29
New cards

What is a Reverse Shell attack?

Victim initiates communication with attacker so attacker can bypass the firewall (originates inside)

30
New cards

What is Replay (Eavesdropping)?

Type of MITM attack where the attacker records it

31
New cards

What is a Return-Oriented attack?

Utilizes pieces of organization’s legit system code in a sequence to perform operations useful to the attacker

32
New cards

What is Spoofing?

Act of impersonating someone to obtain unauthorized access to system (Types: Address Resolution, Domain Name, Hyperlink)

33
New cards

What is an Application-Based Attack?

These forms of attacks target specific software or applications (desktop or web), such as databases or websites, to gain unauthorized access or disrupt functionality

34
New cards

What are examples of Application-Based Attacks?

  • Structured Query Language (SQL) Injection

  • Cross-Site Scripting (XSS)

  • Race Condition

  • Malicious Mobile Code


35
New cards

What is a Structured Query Language (SQL) Injection?

Inject malicious SQlL code into existing SQL code on a company’s website to gain unauthorized access

36
New cards

What is Cross-Site Scripting (XSS)?

Inject code to a company’s website that attacks users visiting the company’s website. When the user visits the site, browser executes the malicious code.

37
New cards

What is Race Condition?

Attacker exploits system that relies on a specific sequence of operations

38
New cards

What is Malicious Mobile Code?

Malicious code referred to as a virus (overwrite, multi-partite, parasitic, polymorphic, resident)

39
New cards

What are Host-Based Attacks?

These attacks target a single host, such as a laptop, mobile device, or server, to disrupt functionality or obtain unauthorized access

40
New cards

What are examples of host-based attacks?

  • Brute Force Attacks

  • Keystroke Logging

  • Malware

  • Rogue Movile Apps


41
New cards

What are Brute Force Attacks?

Password-cracking scheme

42
New cards

What is a Keystroke Logging attack?

Tracking the sequence of keys pressed by a user to collect data

43
New cards

What is Malware?

Software intended to perform unauthorized processes that has an advantageous impact

44
New cards

What is a Rogue Mobile App?

The use of a malicious app that appears legit

45
New cards

What is a Social Engineering Attack?

These attacks involve the use of psychological manipulation or deception to get employees to divulge sensitive information, provide unauthorized access, or assist an attacker in committing fraud

46
New cards

What are examples of Social Engineering Attacks?

  • Phishing

  • Spear Phishing

  • Business Email Compromise (BEC)

  • Pretexting

  • Catfishing

  • Pharming

  • Vishing


47
New cards

What is Phishing?

An authentic looking, but bogus email

48
New cards

What is Spear Phishing?

Targets specific employees in an organization by posing as a legitimate employee

49
New cards

What is a Business Email Compromise (BEC)?

Targets executives and other high-ranking people (aka whaling)

50
New cards

What is Pretexting?

Creating a fake identity/scenario so that employee has a sense of urgency

51
New cards

What is Catfishing?

Creating a fake online persona

52
New cards

What is Pharming?

Victim enters personal information into a web that looks legit

53
New cards

What is Vishing?

Using the telephonic voice over internet protocol (VolP) to create a fake caller ID