Module 1: Overview of Cybersecurity

0.0(0)
Studied by 1 person
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/85

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 9:24 PM on 8/22/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

86 Terms

1
New cards

What is security?

The necessary steps to protect a person or property from harm.

2
New cards

What happens to convenience as security increases?

As security increases, convenience decreases.

3
New cards

What is the relationship between security and convenience?

Security is inversely proportional to convenience.

4
New cards

What does it mean for security and convenience to be inversely proportional?

As security increases, convenience decreases; as convenience increases, security decreases.

5
New cards

What is cybersecurity?

That which protects the confidentiality, integrity, and availability of information on the devices that store, manipulate, and transmit information through products, people, and procedures. 

6
New cards

What is cybersecurity as an art?

The systematic application of knowledge and skills to protect networks and devices.

7
New cards

What is the CIA Triad?

Confidentiality, Integrity, and Availability.

8
New cards

What does CIA stand for in cybersecurity?

Confidentiality, Integrity, and Availability.

9
New cards

What is confidentiality?

Ensuring that only authorized parties can view sensitive information.

10
New cards

What is integrity?

Ensuring that information is correct and that no unauthorized person or malicious software has altered it.

11
New cards

What is availability?

Ensuring that authorized users can access information when needed.

12
New cards

What three things does cybersecurity protect information through?

Products, people, and procedures.

13
New cards

What is an asset?

Something of value.

14
New cards

What is a threat?

A type of action with the potential to cause harm.

15
New cards

What is a threat agent?

A person or element with the power to carry out a threat.

16
New cards

What is a vulnerability?

A flaw or weakness that allows a threat agent to bypass security.

17
New cards

What is an attack vector?

A means or pathway by which an attack can occur.

18
New cards

What is an example of an attack vector?

A threat actor stealing user passwords.

19
New cards

What is threat likelihood?

The probability that a threat agent will exploit a vulnerability.

20
New cards

What is risk?

A situation that involves exposure to some type of danger.

21
New cards

What are products in information security?

Security tools that form protection around data, ranging from simple door locks to complex network security equipment.

22
New cards

What are people in information security?

The people who implement and properly use security products to protect data.

23
New cards

What are policies and procedures?

Plans and policies established by an organization to ensure that people correctly use security products.

24
New cards

What is authentication?

Ensuring that an individual is who they claim to be.

25
New cards

What question does authentication answer?

"Who are you?"

26
New cards

What is authorization?

Providing permission or approval to access specific technology resources.

27
New cards

What question does authorization answer?

"What are you allowed to access or do?"

28
New cards

What is accounting?

Tracking events through an audit trail.

29
New cards

What question does accounting answer?

"What did you do?"

30
New cards

What is the difference between authentication and authorization?

Authentication verifies who you are; authorization determines what you are allowed to access or do.

31
New cards

What is the difference between confidentiality and integrity?

Confidentiality protects information from unauthorized viewing; integrity protects information from unauthorized changes.

32
New cards

What is the difference between integrity and availability?

Integrity ensures information is correct and unchanged; availability ensures authorized users can access it.

33
New cards

What is the ultimate goal of cybersecurity?

To protect information, rather than simply protecting the devices themselves.

34
New cards

Why is information often more valuable than the device itself?

Devices can usually be replaced, but information such as photos, contacts, messages, and other data may be difficult or impossible to replace.

35
New cards

What is the difference between a threat and a threat agent?

A threat is the potential harmful action; a threat agent is the person or element capable of carrying it out.

36
New cards

What is the difference between a vulnerability and an attack vector?

A vulnerability is the weakness; an attack vector is the pathway or means used to exploit the weakness.

37
New cards

What is the difference between threat likelihood and risk?

Threat likelihood is the probability that a threat agent will exploit a vulnerability; risk is the exposure to danger.

38
New cards

What is Cora's scooter an example of?

An asset.

39
New cards

What is the thief in Cora's scooter example?

The threat agent.

40
New cards

What is stealing Cora's scooter?

The threat.

41
New cards

What is the hole in Cora's fence?

The vulnerability.

42
New cards

What is climbing through the hole in the fence?

The attack vector.

43
New cards

What does the scooter example teach about cybersecurity terminology?

An asset can be threatened by a threat agent who exploits a vulnerability using an attack vector, creating risk.What is a cybercriminal?

44
New cards

What motivates cybercriminals?

Fortune or financial gain.

45
New cards

What is a script kiddie?

A typically less-skilled attacker who downloads and uses automated attack software or scripts.

46
New cards

What is a broker?

An attacker who discovers vulnerabilities and sells knowledge of them to other attackers, governments, or other buyers.

47
New cards

Why can brokers command high prices?

The vulnerability may be previously unknown and unlikely to be patched quickly.

48
New cards

What is an insider?

An employee, contractor, or business partner who misuses legitimate access to an organization's information or systems.

49
New cards

Why can insider attacks be difficult to recognize?

Insiders already have legitimate access to the organization's systems and information.

50
New cards

What is a cyberterrorist?

A threat actor motivated by ideology who attacks to cause disruption and panic.

51
New cards

What is a hactivist?

A threat actor who uses cyberattacks to support an ideology, protest, or political/social cause.

52
New cards

What is a state actor?

A government-sponsored threat actor that conducts cyberattacks for government objectives.

53
New cards

What is an Advanced Persistent Threat (APT)?

An attack that uses advanced tools and silently extracts data over an extended period of time.

54
New cards

What type of threat actor are APTs most commonly associated with?

State actors.

55
New cards

What motivates cyberterrorists and hactivists?

Ideology, principles, or beliefs.

56
New cards

What is the main difference between cyberterrorists and hactivists?

Cyberterrorists aim to cause disruption and panic, while hactivists generally use attacks for activism, protest, or political/social purposes.

57
New cards

What does "block attacks" mean?

Use strong security perimeters and defenses to prevent attackers from reaching systems and information.

58
New cards

What does "update defenses" mean?

Regularly update software and hardware defenses to protect against new attacks.

59
New cards

What does "minimize losses" mean?

Prepare in advance to reduce damage if an attack succeeds, such as by keeping backups.

60
New cards

What does "use layers" mean?

Use multiple independent defenses so that if one defense fails, other defenses can still protect the system.

61
New cards

What does "stay alert" mean?

Remain vigilant and make cybersecurity a consideration in everyday decisions.

62
New cards

Why are layers important in cybersecurity?

If one defense is breached, additional defenses can still stop the attacker.

63
New cards

What is an example of minimizing losses?

Keeping backup copies of important data in a safe place.

64
New cards

What is an example of updating defenses?

Applying the latest security updates from software and hardware vendors.

65
New cards

Who is responsible for cybersecurity?

All users; cybersecurity should not be considered the responsibility of "somebody else.

66
New cards

What is the greatest difficulty in preventing attacks according to the textbook?

User confusion.

67
New cards

Why are universally connected devices a security problem?

Attackers anywhere in the world can potentially attack devices connected to the Internet.

68
New cards

Why is the speed of attacks a problem?

Attackers can scan and attack millions of devices very quickly, often using automation.

69
New cards

Why is the sophistication of attacks a problem?

Attackers can make malicious activity look like legitimate network traffic and vary their behavior.

70
New cards

Why is the availability of attack tools a problem?

Attack tools are widely available and can allow attackers with limited technical knowledge to launch attacks.

71
New cards

Why are delays in security updates a problem?

Vendors can be overwhelmed by the number of new threats, causing delays in protecting users.

72
New cards

What are distributed attacks?

Attacks in which attackers use many compromised computers to attack a single target.

73
New cards

What does HIPAA protect?

Protected health information and requires organizations to implement safeguards.

74
New cards

What is GLBA?

Gramm-Leach-Bliley Act.

75
New cards

What does GLBA require?

Financial institutions to protect personally identifiable financial information.

76
New cards

What is Sarbanes-Oxley (Sarbox)?

A law related to corporate financial reporting and accountability.

77
New cards

What is PCI DSS?

Payment Card Industry Data Security Standard.

78
New cards

What is GDPR?

General Data Protection Regulation.

79
New cards

What are the five elements of a practical cybersecurity strategy?

Block attacks, update defenses, minimize losses, use layers, and stay alert.

80
New cards

What are the three information security layers?

Products, people, and policies and procedures.

81
New cards

Why is it difficult to defend against today's attacks?

Devices are universally connected, attacks are faster and more sophisticated, attack tools are widely available, vulnerabilities are discovered quickly, updates can be delayed, update distribution can be weak, attacks can be distributed, and users can be confused.

82
New cards

What is HIPAA?

Health Insurance Portability and Accountability Act.

83
New cards

What is the difference between an asset and a threat?

An asset is something valuable; a threat is an action with the potential to cause harm to that asset.

84
New cards

Black hat hackers

Violate computer security for personal gain or to inflict malicious damage.

85
New cards

White hat hackers

Ethical hackers who use their skills to improve security by identifying vulnerabilities without malicious intent.

86
New cards

Grey hat hackers

Hackers who may violate ethical standards or laws but do not have malicious intent, typically identifying vulnerabilities without authorization but without the intent to cause harm.