IS 340 Security EXAM 1

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/119

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 5:11 AM on 10/6/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

120 Terms

1
New cards

Cybersecurity

Protects electronic systems, networks, & data

2
New cards

Information Security

Protects all information (digital, physical, intellectual)

3
New cards

Difference b/w Cybersecurity & Information Security

Cybersecurity = Digital only & Information Security = All information

4
New cards

Confidentiality (CIA Triad)

Only authorized people can access data

5
New cards

Integrity (CIA Triad)

Data remains accurate & unaltered

6
New cards

Availability (CIA Triad)

Authorized users can access data when needed

7
New cards

Authentication (AAA)

Prove who you are

8
New cards

Authorization (AAA)

What you’re allowed to do

9
New cards

Accounting (AAA)

Records/logs activity

10
New cards

Deterrent (Security Controls)

Discourage attack

11
New cards

Preventive (Security Controls)

Stop attack

12
New cards

Directive (Security Controls)

Guide Behavior

13
New cards

Detective (Security Controls)

Discover attack

14
New cards

Compensating (Security Controls)

Alternate protection

15
New cards

Corrective (Security Controls)

Fix damage

16
New cards

Organized Crime (Threat Actors)

Money

17
New cards

Nation-State (Threat Actors)

Government-sponsored attacks

18
New cards

Hacktivists (Threat Actors)

Political/ideological motives

19
New cards

Insiders (Threat Actors)

Employees/contractors

20
New cards

Shadow IT (Threat Actors)

Unauthorized technology purchases

21
New cards

APT (Threat Actors)

Long-term stealthy attack

22
New cards

Attack surface (Attack surfaces)

Area where attackers can gain access

23
New cards

Mainstream Attack Surfaces (Attack Surfaces)

Software, Hardware, Networks

24
New cards

Communication Threat Vectors (Attack Surfaces)

Email, texts, IM, voice calls

25
New cards

Supply Chain Attack (Attack Surfaces)

Compromising products through suppliers/vendors

26
New cards

Vulnerability (Vunerability)

Weakness that can be exploited

27
New cards

Software Vulnerability (Vulnerability)

Weakness in software

28
New cards

Hardware Vulnerability (Vulnerability)

Weakness in hardware/firmware

29
New cards

Misconfiguration (Vulnerability)

Incorrect settings causing weakness

30
New cards

Zero-Day (Vulnerability)

Exploited before defenders know it exists

31
New cards

Framework (Information Security Resources)

Security blueprint (NIST)

32
New cards

Regulation (Information Security Resources)

Required rules organization must follow

33
New cards

Legislation (Information Security Resources)

Security-related laws

34
New cards

Standard (Information Security Resources)

Agreed-upon guideline (PCI DSS)

35
New cards

Benchmark (Information Security Resources)

Secure configuration guide

36
New cards

Information Sources (Information Security Resources)

RFCs, vulnerability feeds, TTPs, NVD

37
New cards

Social Engineering (Social Engineering Attack)

Manipulate people to reveal information or weaken security

38
New cards

Phishing (Social Engineering Attack)

Fake email/message pretending to be legitmate

39
New cards

Spear Phishing (Social Engineering Attack)

Phishing targeting a specific person

40
New cards

Vishing (Social Engineering Attack)

Voice phishing via phone call

41
New cards

Smishing (Social Engineering Attack)

Phishing through text message

42
New cards

Business Email Compromise (Social Engineering Attack)

Fake business email requesting money transfer

43
New cards

Impersonation (Social Engineering Attack)

Pretending to be someone else to gain trust

44
New cards

Redirection (Social Engineering Attack)

Sending victims to a fake website

45
New cards

Misinformation (Social Engineering Attack)

False information regardless of intent

46
New cards

Disinformation (Social Engineering Attack)

False information intended to deceive

47
New cards

Watering Hole Attack (Social Engineering Attack)

Infecting a website frequently visited by targets

48
New cards

Data Reconnaissance (Social Engineering Attack)

Gathering information before an attack

49
New cards

Dumpster Diving (Social Engineering Attack)

Searching trash for useful information

50
New cards

Shoulder Surfing (Social Engineering Attack)

Watching someone enter sensitive information

51
New cards

Google Dorking (Social Engineering Attack)

Advanced Google searches to find exposed data

52
New cards

What are phishing red flags?

Fake sender

Urgent tone

Requests credentials

Generic greeting

Mismatched links

Random attachments

53
New cards

Industrial Camouflage (Perimeter Defenses)

Hiding a facility’s true purpose

54
New cards

Barier (Perimeter Defenses)

Physical obstacle preventing access

55
New cards

Fence (Perimeter Defenses)

Keep unauthorized people out

56
New cards

Barricade (Perimeter Defenses)

Stops vehicle traffic

57
New cards

Bollard (Perimeter Defenses)

Prevents vehicle ramming attacks

58
New cards

Security Guards (Perimeter Defenses)

Active human security monitoring

59
New cards

IR sensor (Perimeter Defenses)

Detects infared enregy

60
New cards

Microwave Sensor (Perimeter Defenses)

Uses radio waves like radar

61
New cards

Ultrasonic sensor (Perimeter Defenses)

Measures object distance

62
New cards

Pressure Sensor (Perimeter Defenses)

Detects physical presence/movement

63
New cards

Mantrap (Perimeter Defenses)

Two-door security checkpoint

64
New cards

Reception Area (Perimeter Defenses)

Medium-security buffer

65
New cards

Waiting Room (Perimeter Defenses)

(Perimeter Defenses)

66
New cards

Electronic Lock (Perimeter Defenses)

Keypad lock with access logs

67
New cards

Fingerprint Lock (Perimeter Defenses)

Uses biometric authentication

68
New cards

Data Leakage

Sensitive data escaping unauthorized control

69
New cards

Faraday Cage (Preventing Data Leakage)

Blocks electromagnetic signals from entering or leaving

70
New cards

Faraday Bag (Preventing Data Leakage)

Portable version of a Faraday cage

71
New cards

Protected Distribution System (Preventing Data Leakage)

Secure conduit for transmitting classified information

72
New cards

Hardened Carrier PDS (Preventing Data Leakage)

Sealed metal conduit protecting cables

73
New cards

Alarmed Carrier PDS (Preventing Data Leakage)

Detects tampering through sensors

74
New cards

Cable Lock (Preventing Data Leakage)

Physically secures portable devices

75
New cards

Confidential (Data Classification)

Highest sensitivity

76
New cards

Private (Data Classification)

Need to know basis

77
New cards

Sensitive (Data Classification)

Could seriously harm company if disclosed

78
New cards

Critical (Data Classification)

Must be avaible for business operations

79
New cards

Public (Data Classification)

Safe for anyone to view

80
New cards

Restricted (Data Classification)

Not public; use caution

81
New cards

Regulated Data (Data Types)

Governed by external rules & regulations

82
New cards

Intellectual Property (Data Types)

Creative works or inventions

83
New cards

Trade Secret (Data Types)

Proprietary information not publicly disclosed

84
New cards

Legal Information (Data Types)

Information related to laws & legal processes

85
New cards

Financial Information (Data Types)

Enterprise monetary data

86
New cards

Human-Readable Data (Data Types)

Easily understood by people

87
New cards

Machine-Readable Data (Data Types)

Intended for computers to interpret

88
New cards

Data in Processing (Data States)

Currently being used

89
New cards

Data in Transit (Data States)

Moving across a network

90
New cards

Data at Rest (Data States)

Stored on device or media

91
New cards

Data Minimization (Data States)

Collect only the necessary data

92
New cards

Tokenization (Data States)

Replace sensitve data with tokens

93
New cards

Restrictions (Data States)

Limit access by user or location

94
New cards

Segmentation (Data States)

Separate sensitive data into protected areas

95
New cards

What’s the difference between Steganography & Cryptography?

Steganography hides the message that exists while Cryptography scrambles the message

96
New cards

Cipher

Mathematical algorithm used to encrypt & decrypt data

97
New cards

Transposition Cipher

Rearranges letters

98
New cards

Substitution Cipher

Replaces letters with other letters

99
New cards

Key

Mathematical value used by an algorithm to produce ciphertext

100
New cards

Plaintext (Text Type)

Orginal data