1/20
These flashcards cover key vocabulary and concepts from the lecture on Threats and Vulnerability Assessment.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Threat
Potential occurrence of an undesirable event that can damage and disrupt operational activities of an organization.
Malware
Malicious software designed to perform activities intended by the attacker without user consent.
Trojan
A malicious program contained inside a harmless program that can gain control and cause damage.
Ransomware
Malware that restricts access to a computer system or files and demands ransom for removal.
Insider Threat
Threat from individuals within an organization, who may harm the organization intentionally or unintentionally.
External Threat
Threats originating from outside the organization, typically exploiting network vulnerabilities.
Zero-Day Vulnerability
Unknown vulnerabilities in software that are exposed but not yet patched.
Botnet
A collection of compromised computers connected to the Internet used to perform distributed tasks.
Spyware
A stealthy software that secretly monitors and records user activities on a target computer.
Keylogger
Software or hardware that records the keys struck on a keyboard to capture sensitive data.
Vulnerability
A weakness in a system that can be exploited to compromise its security.
Ransom Payment
Monetary payment demanded by ransomware attackers to restore access to a system.
Unintentional Threats
Threats arising from accidental actions or errors, such as negligence or user mistakes.
Buffer Overflow
A common software vulnerability where attackers gain access by writing beyond the buffer's limit.
Misconfiguration
The most common vulnerability, often due to human error, that allows unauthorized access to systems.
Legacy Vulnerabilities
Security risks arising from outdated software code that can lead to data breaches.
Active Scanning
A vulnerability scanning method that interacts directly with the target network to find vulnerabilities.
Passive Scanning
A vulnerability assessment method that identifies vulnerabilities without direct interaction with the target.
Credentialed Assessment
A vulnerability check where the assessor has credentials for all machines in the assessed network.
Automated Assessment
Use of tools to perform vulnerability assessments without manual interaction by security professionals.
Monitor (in Vulnerability Management)
The phase of vulnerability management where organizations maintain system security through continuous observation.