1/85
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What is security?
The necessary steps to protect a person or property from harm.
What happens to convenience as security increases?
As security increases, convenience decreases.
What is the relationship between security and convenience?
Security is inversely proportional to convenience.
What does it mean for security and convenience to be inversely proportional?
As security increases, convenience decreases; as convenience increases, security decreases.
What is cybersecurity?
That which protects the confidentiality, integrity, and availability of information on the devices that store, manipulate, and transmit information through products, people, and procedures.
What is cybersecurity as an art?
The systematic application of knowledge and skills to protect networks and devices.
What is the CIA Triad?
Confidentiality, Integrity, and Availability.
What does CIA stand for in cybersecurity?
Confidentiality, Integrity, and Availability.
What is confidentiality?
Ensuring that only authorized parties can view sensitive information.
What is integrity?
Ensuring that information is correct and that no unauthorized person or malicious software has altered it.
What is availability?
Ensuring that authorized users can access information when needed.
What three things does cybersecurity protect information through?
Products, people, and procedures.
What is an asset?
Something of value.
What is a threat?
A type of action with the potential to cause harm.
What is a threat agent?
A person or element with the power to carry out a threat.
What is a vulnerability?
A flaw or weakness that allows a threat agent to bypass security.
What is an attack vector?
A means or pathway by which an attack can occur.
What is an example of an attack vector?
A threat actor stealing user passwords.
What is threat likelihood?
The probability that a threat agent will exploit a vulnerability.
What is risk?
A situation that involves exposure to some type of danger.
What are products in information security?
Security tools that form protection around data, ranging from simple door locks to complex network security equipment.
What are people in information security?
The people who implement and properly use security products to protect data.
What are policies and procedures?
Plans and policies established by an organization to ensure that people correctly use security products.
What is authentication?
Ensuring that an individual is who they claim to be.
What question does authentication answer?
"Who are you?"
What is authorization?
Providing permission or approval to access specific technology resources.
What question does authorization answer?
"What are you allowed to access or do?"
What is accounting?
Tracking events through an audit trail.
What question does accounting answer?
"What did you do?"
What is the difference between authentication and authorization?
Authentication verifies who you are; authorization determines what you are allowed to access or do.
What is the difference between confidentiality and integrity?
Confidentiality protects information from unauthorized viewing; integrity protects information from unauthorized changes.
What is the difference between integrity and availability?
Integrity ensures information is correct and unchanged; availability ensures authorized users can access it.
What is the ultimate goal of cybersecurity?
To protect information, rather than simply protecting the devices themselves.
Why is information often more valuable than the device itself?
Devices can usually be replaced, but information such as photos, contacts, messages, and other data may be difficult or impossible to replace.
What is the difference between a threat and a threat agent?
A threat is the potential harmful action; a threat agent is the person or element capable of carrying it out.
What is the difference between a vulnerability and an attack vector?
A vulnerability is the weakness; an attack vector is the pathway or means used to exploit the weakness.
What is the difference between threat likelihood and risk?
Threat likelihood is the probability that a threat agent will exploit a vulnerability; risk is the exposure to danger.
What is Cora's scooter an example of?
An asset.
What is the thief in Cora's scooter example?
The threat agent.
What is stealing Cora's scooter?
The threat.
What is the hole in Cora's fence?
The vulnerability.
What is climbing through the hole in the fence?
The attack vector.
What does the scooter example teach about cybersecurity terminology?
An asset can be threatened by a threat agent who exploits a vulnerability using an attack vector, creating risk.What is a cybercriminal?
What motivates cybercriminals?
Fortune or financial gain.
What is a script kiddie?
A typically less-skilled attacker who downloads and uses automated attack software or scripts.
What is a broker?
An attacker who discovers vulnerabilities and sells knowledge of them to other attackers, governments, or other buyers.
Why can brokers command high prices?
The vulnerability may be previously unknown and unlikely to be patched quickly.
What is an insider?
An employee, contractor, or business partner who misuses legitimate access to an organization's information or systems.
Why can insider attacks be difficult to recognize?
Insiders already have legitimate access to the organization's systems and information.
What is a cyberterrorist?
A threat actor motivated by ideology who attacks to cause disruption and panic.
What is a hactivist?
A threat actor who uses cyberattacks to support an ideology, protest, or political/social cause.
What is a state actor?
A government-sponsored threat actor that conducts cyberattacks for government objectives.
What is an Advanced Persistent Threat (APT)?
An attack that uses advanced tools and silently extracts data over an extended period of time.
What type of threat actor are APTs most commonly associated with?
State actors.
What motivates cyberterrorists and hactivists?
Ideology, principles, or beliefs.
What is the main difference between cyberterrorists and hactivists?
Cyberterrorists aim to cause disruption and panic, while hactivists generally use attacks for activism, protest, or political/social purposes.
What does "block attacks" mean?
Use strong security perimeters and defenses to prevent attackers from reaching systems and information.
What does "update defenses" mean?
Regularly update software and hardware defenses to protect against new attacks.
What does "minimize losses" mean?
Prepare in advance to reduce damage if an attack succeeds, such as by keeping backups.
What does "use layers" mean?
Use multiple independent defenses so that if one defense fails, other defenses can still protect the system.
What does "stay alert" mean?
Remain vigilant and make cybersecurity a consideration in everyday decisions.
Why are layers important in cybersecurity?
If one defense is breached, additional defenses can still stop the attacker.
What is an example of minimizing losses?
Keeping backup copies of important data in a safe place.
What is an example of updating defenses?
Applying the latest security updates from software and hardware vendors.
Who is responsible for cybersecurity?
All users; cybersecurity should not be considered the responsibility of "somebody else.
What is the greatest difficulty in preventing attacks according to the textbook?
User confusion.
Why are universally connected devices a security problem?
Attackers anywhere in the world can potentially attack devices connected to the Internet.
Why is the speed of attacks a problem?
Attackers can scan and attack millions of devices very quickly, often using automation.
Why is the sophistication of attacks a problem?
Attackers can make malicious activity look like legitimate network traffic and vary their behavior.
Why is the availability of attack tools a problem?
Attack tools are widely available and can allow attackers with limited technical knowledge to launch attacks.
Why are delays in security updates a problem?
Vendors can be overwhelmed by the number of new threats, causing delays in protecting users.
What are distributed attacks?
Attacks in which attackers use many compromised computers to attack a single target.
What does HIPAA protect?
Protected health information and requires organizations to implement safeguards.
What is GLBA?
Gramm-Leach-Bliley Act.
What does GLBA require?
Financial institutions to protect personally identifiable financial information.
What is Sarbanes-Oxley (Sarbox)?
A law related to corporate financial reporting and accountability.
What is PCI DSS?
Payment Card Industry Data Security Standard.
What is GDPR?
General Data Protection Regulation.
What are the five elements of a practical cybersecurity strategy?
Block attacks, update defenses, minimize losses, use layers, and stay alert.
What are the three information security layers?
Products, people, and policies and procedures.
Why is it difficult to defend against today's attacks?
Devices are universally connected, attacks are faster and more sophisticated, attack tools are widely available, vulnerabilities are discovered quickly, updates can be delayed, update distribution can be weak, attacks can be distributed, and users can be confused.
What is HIPAA?
Health Insurance Portability and Accountability Act.
What is the difference between an asset and a threat?
An asset is something valuable; a threat is an action with the potential to cause harm to that asset.
Black hat hackers
Violate computer security for personal gain or to inflict malicious damage.
White hat hackers
Ethical hackers who use their skills to improve security by identifying vulnerabilities without malicious intent.
Grey hat hackers
Hackers who may violate ethical standards or laws but do not have malicious intent, typically identifying vulnerabilities without authorization but without the intent to cause harm.