Cybersecurity Comprehensive Study Guide

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/52

flashcard set

Earn XP

Description and Tags

Comprehensive vocabulary flashcards covering information security concepts, network attacks, cryptography, wireless security, and enterprise device management.

Last updated 8:56 PM on 6/16/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai

No analytics yet

Send a link to your students to track their progress

53 Terms

1
New cards

Information Security

The practice of protecting information systems, data, and resources from unauthorized access, use, disclosure, disruption, modification, or destruction.

2
New cards

CIA Triad

The core model of information security representing Confidentiality, Integrity, and Availability.

3
New cards

Confidentiality

A property of the CIA Triad that ensures sensitive information is only accessible to authorized users.

4
New cards

Integrity

A property of the CIA Triad that ensures data is accurate and has not been altered.

5
New cards

Availability

A property of the CIA Triad that ensures systems and data are accessible when required.

6
New cards

Virus

A type of malware that attaches itself to legitimate programs and requires user action to execute.

7
New cards

Worm

Self-replicating malware that spreads automatically across networks.

8
New cards

Ransomware

Malware that encrypts victim files and demands payment for decryption.

9
New cards

Launch Action

The execution phase of malware, such as ransomware beginning to encrypt files.

10
New cards

Evade Action

Techniques used by malware to avoid detection, such as polymorphism.

11
New cards

Phishing

Fraudulent communication, often via email, designed to steal credentials by using suspicious URLs or urgent language.

12
New cards

Improper Input Handling

A system vulnerability where the failure to validate user input leads to injection attacks.

13
New cards

Vertical Privilege Escalation

A security breach where a regular user gains administrative or root privileges.

14
New cards

Horizontal Privilege Escalation

A security breach where a user gains access to another user's account at the same level.

15
New cards

BIOS (Basic Input/Output System)

Firmware stored on a chip that performs the Power-On Self-Test (POST) and detects hardware during the boot process.

16
New cards

UEFI (Unified Extensible Firmware Interface)

A modern replacement for BIOS that provides faster startup and enhanced security features.

17
New cards

Secure Boot

A security standard that ensures only trusted, digitally signed software executes during the computer startup process.

18
New cards

DoS (Denial of Service) Attack

An attack where a single attacker overwhelms a service with fake requests to make it unavailable.

19
New cards

DDoS (Distributed Denial of Service) Attack

An attack where many devices, often a botnet, flood a system simultaneously to cause a service timeout.

20
New cards

Evil Twin

A fake Wi-Fi hotspot that mimics a real network to secretly intercept or alter communication.

21
New cards

IP Spoofing

Faking a source IP address to bypass IP-based controls or hide identity.

22
New cards

DNS Spoofing

Faking DNS records to redirect users to malicious websites.

23
New cards

Sniffing

The act of capturing network traffic to read unencrypted information such as passwords or session cookies.

24
New cards

Replay Attack

An attack where valid messages or authentication tokens are recorded and retransmitted to gain unauthorized access.

25
New cards

Nmap

A network security assessment tool used to find active hosts, open ports, and services.

26
New cards

Nessus

A security tool used to identify missing patches, weak passwords, and misconfigurations.

27
New cards

Wireshark

A tool used to capture and analyze network traffic, such as detecting repeated login attempts.

28
New cards

Proxy Server

An intermediary between users and the internet that hides internal IPs and enforces usage policies.

29
New cards

Load Balancer

A device that distributes traffic across multiple servers to prevent overload and reduce DoS impact.

30
New cards

IDS (Intrusion Detection System)

A security appliance that monitors traffic and alerts administrators of suspicious activity.

31
New cards

IPS (Intrusion Prevention System)

A security appliance that detects and actively blocks malicious traffic.

32
New cards

NGFW (Next-Generation Firewall)

A firewall that includes Deep Packet Inspection, application filtering, and threat intelligence integration.

33
New cards

Stateful Inspection

A traffic filtering method that tracks the state of active connections to prevent spoofing.

34
New cards

DPI (Deep Packet Inspection)

A filtering method that analyzes the actual content or payload of a packet at the application layer.

35
New cards

Defence in Depth

A layered security approach ensuring that if one defensive layer fails, others still protect the system.

36
New cards

EDR (Endpoint Detection and Response)

A tool that continuously monitors endpoint devices for suspicious activity and responds to threats.

37
New cards

Symmetric Encryption

An encryption method that uses the same key for both encryption and decryption, such as AES.

38
New cards

Asymmetric Encryption

An encryption method where a public key encrypts data and a private key decrypts it, such as RSA.

39
New cards

Hashing

A one-way function that converts plaintext into a fixed-length value, commonly used for integrity checks and password storage.

40
New cards

Data at Rest

Data stored on a disk or database, typically protected by methods like BitLocker.

41
New cards

Data in Transit

Data moving across a network, typically protected by TLS/SSL or VPNs.

42
New cards

Data in Use

Data being actively processed, protected by secure enclaves or homomorphic encryption.

43
New cards

Collision Attack

A cryptographic attack where two different inputs produce the same hash value.

44
New cards

PKI (Public Key Infrastructure)

A framework for managing digital certificates and public-key encryption.

45
New cards

802.1X Authentication

A wireless security control where devices must verify identity through a RADIUS server before gaining network access.

46
New cards

WPA3

The strongest wireless security standard, featuring SAE authentication and forward secrecy.

47
New cards

Principle of Least Privilege

The practice of providing users only the access they actually need to perform their jobs.

48
New cards

Supply Chain Attack

An attack where an attacker targets a smaller vendor to reach a larger organization.

49
New cards

Password Spraying

A password attack where one common password is tested against many different accounts to avoid account lockout.

50
New cards

Pass-the-Hash

A technique where an attacker steals a hashed password from memory and reuses it without needing to crack it.

51
New cards

MDM (Mobile Device Management)

A centralized tool used to manage configuration, policy enforcement, and remote wipes for organizational mobile devices.

52
New cards

BYOD (Bring Your Own Device)

A deployment model where employees own their devices, offering high flexibility but low corporate security control.

53
New cards

Shadow IoT

Unauthorized IoT devices connected to a network without the knowledge of the IT department.