1/68
Flashcards covering key vocabulary, security concepts, attack techniques, and tool classifications from Module 3: Network Security Concepts.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Asset
Anything of value to an organization, including people, equipment, resources, and data.
Vulnerability
A weakness in a system or its design that could be exploited by a threat.
Threat
A potential danger to a company's assets, data, or network functionality.
Exploit
A mechanism that takes advantage of a vulnerability.
Mitigation
The counter-measure that reduces the likelihood or severity of a potential threat or risk.
Risk
The likelihood of a threat to exploit the vulnerability of an asset to negatively affect an organization, measured using the probability of occurrence and its consequences.
Attack Vector
A path by which a threat actor can gain access to a server, host, or network, originating from inside or outside the corporate network.
Data Loss
Also known as data exfiltration, this occurs when data is intentionally or unintentionally lost, stolen, or leaked to the outside world.
White Hat Hackers
Ethical hackers who use programming skills for legal purposes and report security vulnerabilities to developers before they can be exploited.
Gray Hat Hackers
Individuals who commit crimes or unethical acts not for personal gain or damage, but who may disclose vulnerabilities to an organization after compromising its network.
Black Hat Hackers
Unethical criminals who compromise computer and network security for personal gain or malicious reasons.
Script Kiddies
Teenagers or inexperienced hackers who run existing scripts, tools, and exploits to cause harm, typically not for profit.
Vulnerability Broker
Usually gray hat hackers who discover exploits and report them to vendors, sometimes for prizes or rewards.
Hacktivists
Gray hat hackers who publicly protest organizations or governments by posting content, leaking sensitive information, or executing network attacks.
Cybercriminals
Black hat hackers who operate independently or work for large cybercrime organizations.
State-Sponsored Hackers
White hat or black hat hackers employed to steal government secrets, gather intelligence, and sabotage networks of foreign governments, corporations, or groups.
Password Crackers
Password recovery tools that repeatedly guess credentials to crack passwords, such as John the Ripper, Ophcrack, and THC Hydra.
Wireless Hacking Tools
Tools used to intentionally hack into wireless networks to detect security vulnerabilities, such as Aircrack-ng and Kismet.
Network Scanning Tools
Tools used to probe network devices, servers, and hosts for open TCP or UDP ports, such as Nmap and Angry IP Scanner.
Packet Crafting Tools
Tools used to probe and test firewall robustness using forged packets, such as Hping, Scapy, and Netcat.
Packet Sniffers
Applications or devices that capture and analyze packets in Ethernet LANs or WLANs, such as Wireshark and Tcpdump.
Rootkit Detectors
Directory and file integrity checkers used by white hat hackers to detect installed rootkits, such as AIDE.
Fuzzers
Tools used by threat actors to discover security vulnerabilities in software or systems, such as Skipfish and Wapiti.
Forensic Tools
Tools used by white hat hackers to discover traces of evidence existing in a computer, such as Sleuth Kit and Encase.
Debuggers
Tools used to reverse engineer binary files when writing exploits or analyzing malware, such as GDB and IDA Pro.
Hacking Operating Systems
Specially designed operating systems preloaded with tools optimized for hacking, such as Kali Linux and BackBox Linux.
Encryption Tools
Software that uses algorithm schemes to encode data to prevent unauthorized access, such as VeraCrypt and OpenSSL.
Vulnerability Exploitation Tools
Tools designed to identify whether a remote host is vulnerable to a security attack, such as Metasploit and Sqlmap.
Vulnerability Scanners
Tools used to scan networks, virtual machines, and systems for known vulnerabilities and open ports, such as Nessus and OpenVAS.
Eavesdropping Attack
An attack where a threat actor captures and listens to network traffic, also referred to as sniffing or snooping.
Data Modification Attack
An attack where captured network traffic is altered in transit without the knowledge of the sender or receiver.
IP Address Spoofing Attack
An attack where a threat actor constructs an IP packet that appears to originate from a valid address inside the corporate intranet.
Password-Based Attack
An attack where a threat actor uses discovered valid user accounts to gain unauthorized access and administrative privileges.
Denial of Service (DoS) Attack
An attack that prevents normal use of a system or network by flooding it with traffic or sending maliciously formatted packets.
Man-in-the-Middle (MITM) Attack
An attack where a threat actor positions themselves between a source and destination to transparently monitor, capture, and control communications.
Compromised-Key Attack
An attack where a threat actor obtains a secret key to gain unauthorized access to secured communications.
Virus
Malware that attaches itself to computer code or documents and requires human action to execute, propagate, and infect systems.
Trojan Horse
A program that appears useful but carries malicious payload code to perform actions like remote access or keylogging.
Adware
Malware typically distributed via online downloads that displays unsolicited advertisements using pop-ups or webpage redirects.
Ransomware
Malware that encrypts a user's files and demands payment, typically via wire transfer or cryptocurrency, for the decryption key.
Rootkit
Malware used to gain administrator-level account access while concealing its presence by modifying system files and security tools.
Spyware
Malware designed to secretly gather user information, such as browsing data or financial details, and transmit it to threat actors.
Worm
A self-replicating program that automatically propagates across a network without requiring user interaction by exploiting software vulnerabilities.
Reconnaissance Attack
An unauthorized discovery and mapping technique used to gather information about target systems, services, or vulnerabilities prior to an attack.
Access Attack
An attack exploiting vulnerabilities in authentication, web, or FTP services to gain entry to sensitive data or elevate access privileges.
Social Engineering
An access attack method that relies on manipulating individuals into performing actions or divulging confidential information.
Pretexting
A social engineering technique where an attacker invents a scenario needing personal or financial data to confirm a victim's identity.
Phishing
A technique using fraudulent emails disguised as legitimate sources to trick recipients into revealing information or installing malware.
Spear Phishing
A targeted phishing attempt customized specifically for an individual or organization.
Baiting
A technique where an attacker leaves a malware-infected drive in a public location for an unsuspecting victim to find and use.
Tailgating
A physical security compromise where an unauthorized person closely follows an authorized person into a restricted area.
Shoulder Surfing
Direct observation techniques where an attacker looks over a target's shoulder to obtain passwords or confidential information.
Dumpster Diving
Rummaging through trash bins to discover disposed confidential documents and data.
Smurf Attack
A type of DDoS attack utilizing ICMP reflection and amplification to overload a target system.
Non-Blind Spoofing
An address spoofing technique where the attacker can inspect traffic between the target and host, enabling session hijacking.
Blind Spoofing
An address spoofing technique where the attacker cannot view the traffic exchanged between source and destination, commonly used in DoS attacks.
TCP SYN Flood Attack
A DoS attack where multiple SYN requests are sent to a server, consuming resources as the server waits to complete half-opened handshakes.
Gratuitous ARP
An unsolicited ARP Reply sent by a host that can be exploited by threat actors to poison ARP caches and perform MITM attacks.
Fast Flux
A DNS stealth technique that rapidly changes DNS IP addresses within minutes using compromised hosts to hide malicious websites.
Double IP Flux
A DNS stealth technique that rapidly changes both hostname-to-IP address mappings and the authoritative name server.
Domain Generation Algorithms
Malware algorithms used to randomly create domain names serving as dynamic rendezvous points for botnet C&C servers.
Domain Shadowing
An attack where compromised domain registration credentials are used to create subdomains pointing to malicious servers.
DNS Tunneling
The practice of placing non-DNS protocol traffic inside DNS packets to bypass network security controls and exfiltrate data.
Rogue DHCP Server
An unauthorized DHCP server connected to a network that issues false configuration parameters to clients to initiate DoS or MITM attacks.
Confidentiality
A security principle ensuring only authorized individuals or processes can access sensitive data, often enforced using encryption like AES.
Integrity
A security principle protecting data against unauthorized modification or tampering, often verified using cryptographic hashing algorithms like SHA.
Availability
A security principle ensuring authorized users have reliable, uninterrupted access to network resources through redundancy.
Defense-in-Depth
A multi-layered security strategy employing multiple devices, policies, and services across networks to safeguard infrastructure.
Intrusion Prevention System (IPS)
An inline security device or software that detects and actively blocks malicious network traffic patterns using signatures.