SY0-701 Domain 2

0.0(0)
Studied by 2 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/109

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 1:45 AM on 2/12/25
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

110 Terms

1
New cards

Nation-state

Government-sponsored attackers conducting cyber espionage, sabotage, or warfare.

2
New cards

Unskilled attacker

Uses pre-made tools and scripts with little technical expertise.

3
New cards

Hacktivist

Politically or socially motivated hacker aiming to disrupt or expose.

4
New cards

Insider threat

Employees or contractors misusing access for personal or external gain.

5
New cards

Organized crime

Well-funded cybercriminal groups targeting financial gain through fraud or extortion.

6
New cards

Shadow IT

Unauthorized use of IT systems, apps, or services, leading to security risks.

7
New cards

Internal/external

Internal actors have system access, while external actors attack from outside.

8
New cards

Resources/funding

Well-funded actors (e.g., nation-states) conduct more sophisticated attacks.

9
New cards

Level of sophistication/capability

Highly skilled actors execute complex, stealthy, and targeted attacks.

10
New cards

Data exfiltration

Theft of sensitive information for unauthorized use.

11
New cards

Espionage

Theft of sensitive data for intelligence, corporate secrets, or political advantage.

12
New cards

Service disruption

Interrupting or degrading services to cause harm.

13
New cards

Blackmail

Using stolen or compromised data to extort victims.

14
New cards

Financial gain

Cybercriminals seeking profit through fraud, ransomware, or data theft.

15
New cards

Philosophical/political beliefs

Motivated by ideological causes to disrupt or expose entities.

16
New cards

Ethical

Conducting security testing within legal and ethical boundaries.

17
New cards

Revenge

Former employees or insiders causing damage due to grievances.

18
New cards

Disruption/chaos

Attacks aiming to cripple systems, businesses, or governments.

19
New cards

War

Cyberattacks used as a tool in geopolitical conflicts.

20
New cards

Email

Used for phishing, spam, and malicious attachments to deceive users.

21
New cards

Short Message Service (SMS)

Smishing attacks attempt to trick users via text messages.

22
New cards

Instant messaging (IM)

Attackers exploit chat apps for phishing and malware distribution.

23
New cards

Image-based

Malicious images contain hidden code or exploits.

24
New cards

File-based

Malicious files, such as PDFs or executables, spread malware.

25
New cards

Voice call

Social engineering attacks like vishing impersonate legitimate entities.

26
New cards

Removable device

USB drives and external storage spread malware or steal data.

27
New cards

Vulnerable software

Applications with security flaws exploited by attackers.

28
New cards

Client-based vs. agentless

Client-based requires software installation, while agentless relies on browser-based execution.

29
New cards

Unsupported systems and applications

Older systems lack security updates, making them vulnerable.

30
New cards

Unsecure networks

Open Wi-Fi, weak encryption, and exposed wired connections allow attackers access.

31
New cards

Wireless

Poorly secured wireless networks are easy targets for interception.

32
New cards

Wired

Physical access to network cables can enable unauthorized access.

33
New cards

Bluetooth

Exploited for unauthorized pairing and data theft.

34
New cards

Open service ports

Exposed ports allow attackers to exploit running services.

35
New cards

Default credentials

Unchanged manufacturer passwords create easy entry points.

36
New cards

Supply chain

Compromised vendors, suppliers, or MSPs introduce risks.

37
New cards

Managed service providers (MSPs)

Attackers exploit third-party IT providers to gain access.

38
New cards

Vendors

Hardware and software suppliers can be targeted for backdoor exploits.

39
New cards

Suppliers

Attackers compromise supply chains to distribute infected products.

40
New cards

Phishing

Deceptive emails trick users into revealing sensitive data.

41
New cards

Vishing

Phone-based phishing to extract information.

42
New cards

Smishing

SMS phishing using fraudulent messages.

43
New cards

Misinformation/disinformation

Spreading false information to manipulate public opinion.

44
New cards

Impersonation

Attackers pose as trusted entities to gain access.

45
New cards

Business email compromise

Fraudulent emails impersonating executives to request money transfers.

46
New cards

Pretexting

Social engineering tactic where attackers fabricate scenarios to obtain information.

47
New cards

Watering hole

Compromising websites frequently visited by a target group.

48
New cards

Brand impersonation

Fake websites or messages mimicking trusted brands.

49
New cards

Typosquatting

Registering misspelled domain names to trick users.

50
New cards

Memory injection

Injecting malicious code into memory to evade detection.

51
New cards

Buffer overflow

Excess data overwrites memory, leading to system crashes or control hijacking.

52
New cards

Race conditions

Exploiting the timing of operations to manipulate outcomes.

53
New cards

Time-of-check (TOC)

Attacker changes data between validation and use.

54
New cards

Time-of-use (TOU)

Exploiting the delay between validation and execution.

55
New cards

Malicious update

Fake or tampered software updates install malware.

56
New cards

Operating system (OS)-based

Exploiting OS vulnerabilities for unauthorized access.

57
New cards

Structured Query Language injection (SQLi)

Injecting malicious SQL queries to manipulate databases.

58
New cards

Cross-site scripting (XSS)

Injecting scripts into web pages to steal data or hijack sessions.

59
New cards

Firmware

Exploiting vulnerabilities in embedded system software.

60
New cards

End-of-life

Unsupported hardware and software that no longer receive updates.

61
New cards

Legacy

Older systems with outdated security mechanisms.

62
New cards

Virtual machine (VM) escape

Breaking out of a virtual machine to gain control over the host system.

63
New cards

Resource reuse

Exploiting residual data from previous sessions.

64
New cards

Cloud-specific

Cloud misconfigurations and API vulnerabilities pose security risks.

65
New cards

Service provider

Attackers target cloud or IT service providers.

66
New cards

Hardware provider

Hardware vulnerabilities exploited for backdoor access.

67
New cards

Software provider

Software supply chain attacks insert malicious code into legitimate applications.

68
New cards

Cryptographic

Exploiting weaknesses in encryption algorithms.

69
New cards

Misconfiguration

Incorrect security settings expose systems to attacks.

70
New cards

Mobile device

Threats targeting smartphones and tablets.

71
New cards

Side loading

Installing apps from unverified sources, increasing malware risk.

72
New cards

Jailbreaking

Removing security restrictions on a device to install unauthorized apps.

73
New cards

Zero-day

Newly discovered security flaws with no available patches.

74
New cards

Ransomware

Encrypts files and demands payment for decryption.

75
New cards

Trojan

Malware disguised as legitimate software to create backdoors.

76
New cards

Worm

Self-replicating malware that spreads without user action.

77
New cards

Spyware

Secretly collects user data and activities.

78
New cards

Bloatware

Unnecessary pre-installed software that can introduce vulnerabilities.

79
New cards

Virus

Malicious code that spreads by attaching to files.

80
New cards

Keylogger

Records keystrokes to steal sensitive data.

81
New cards

Logic bomb

Dormant malicious code activated under specific conditions.

82
New cards

Rootkit

Malware that hides its presence by modifying system files.

83
New cards

Brute force

Repeatedly guessing passwords or encryption keys.

84
New cards

Radio frequency identification (RFID) cloning

Copying RFID credentials for unauthorized access.

85
New cards

Environmental

Attacks leveraging physical conditions like temperature or humidity changes.

86
New cards

Distributed denial-of-service (DDoS)

Overwhelms a target with excessive traffic.

87
New cards

Amplified

Uses reflection techniques to magnify attack traffic.

88
New cards

Reflected

Spoofs the victim’s IP to redirect attack traffic.

89
New cards

Domain Name System (DNS) attacks

Manipulating DNS records to redirect users.

90
New cards

On-path

Intercepting communication between two parties.

91
New cards

Credential replay

Capturing and reusing valid credentials for unauthorized access.

92
New cards

Malicious code

Any code designed to harm, steal, or disrupt.

93
New cards

Injection

Exploiting input vulnerabilities to insert malicious commands.

94
New cards

Replay

Capturing and reusing transmitted data.

95
New cards

Privilege escalation

Gaining unauthorized higher-level system access.

96
New cards

Forgery

Creating fake authentication credentials or transactions.

97
New cards

Directory traversal

Accessing restricted directories by manipulating file paths.

98
New cards

Downgrade

Forcing a system to use weaker security settings.

99
New cards

Collision

Exploiting hash function collisions to break encryption.

100
New cards

Birthday

Exploiting probability to find hash function collisions.