1/145
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What is a threat actor?
An individual, group, or entity responsible for activity that negatively affects another entity's security. Also called a malicious actor.
What characteristics help identify a threat actor?
Internal vs. external, resources/funding, sophistication/capability, and motivation.
What is an APT?
Advanced Persistent Threat - a highly capable attacker that maintains long-term access and conducts targeted operations. Often associated with nation-states.
What characteristics suggest a nation-state attacker?
Massive funding/resources, very high sophistication, long-term objectives, espionage, disruption, warfare, or strategic data theft.
What is an unskilled attacker?
An attacker using premade tools/scripts with limited technical understanding and little funding.
What is a hacktivist?
An attacker motivated primarily by ideology, political/philosophical beliefs, revenge, or disruption.
What makes an insider threat dangerous?
The attacker already has legitimate access, organizational knowledge, and potentially trusted credentials/resources.
What motivation is most strongly associated with organized crime?
Financial gain. Organized criminal groups can also have substantial funding and sophistication.
What is Shadow IT?
Technology, cloud services, applications, or infrastructure deployed outside the organization's approved IT processes.
Why is Shadow IT a security problem even if users aren't malicious?
IT/security may not know the system exists, so it may lack approved security configurations, monitoring, patching, or data protections.
What is a threat/attack vector?
The method or path an attacker uses to gain access to or compromise a target.
What are common message-based threat vectors?
Malicious email, SMS, instant messages, links, attachments, and social engineering messages.
Why can image-based attacks be difficult to detect?
Images and formats such as SVG may contain active content or malicious scripts that are less obvious than plain text.
Why are compressed files such as ZIP/RAR useful to attackers?
They can conceal multiple malicious files and may bypass simple inspection mechanisms.
What risk do malicious Office documents often introduce?
Macros, scripts, or malicious add-ins that execute code.
What is vishing?
Voice phishing - social engineering conducted through phone calls or voicemail.
What is smishing?
SMS phishing - phishing delivered through text messages.
What is phishing?
Social engineering, often combined with spoofing, designed to trick victims into revealing information, clicking links, or executing malicious content.
What is Business Email Compromise (BEC)?
An attacker impersonates or compromises a trusted business identity to manipulate employees, commonly into making fraudulent payments or wire transfers.
CEO requests an urgent secret wire transfer to a new bank account. What should you suspect?
Business Email Compromise / CEO fraud.
What is typosquatting?
Registering domains resembling legitimate domains by using misspellings or typing mistakes to mislead users.
What is pretexting?
Creating a believable fabricated story or identity to convince a victim to provide information or take an action.
Pretexting vs. impersonation?
Pretexting = fabricated scenario/story. Impersonation = pretending to be another person/entity. They frequently work together.
What is elicitation?
Using conversation and psychological techniques to extract information without the victim realizing they are being interrogated.
What is a watering-hole attack?
Compromising a website frequently visited by the intended victims so attackers can target them indirectly.
Why is a watering-hole attack different from ordinary phishing?
Instead of bringing malicious content directly to the victim, the attacker compromises somewhere the victim already visits.
What is brand impersonation?
Creating fraudulent websites/messages that mimic recognizable brands to gain trust, steal information, or distribute malware.
What is disinformation?
Deliberately distributing false information to deceive or manipulate an audience.
How can removable media bypass network defenses?
USB devices can physically introduce malware or remove data without traffic crossing the normal network perimeter.
Why is a malicious USB especially dangerous to an air-gapped network?
It provides a physical method of transferring malicious code into a network that intentionally lacks external connectivity.
What is a supply-chain attack?
Compromising a vendor, supplier, developer, update process, hardware provider, or other trusted upstream component to reach downstream victims.
Why can an MSP become a valuable attacker target?
A Managed Service Provider may have privileged access to many customers, so compromising one provider can provide access to many networks.
What is memory injection?
Injecting malicious code into the memory space of another running process to hide or inherit that process's privileges.
What is DLL injection?
Injecting/loading a malicious Dynamic-Link Library into another process so malicious code executes as part of that process.
Why would malware inject itself into a legitimate process?
To hide from detection and gain the legitimate process's access rights/permissions.
What is a buffer overflow?
Writing more data into a memory buffer than it can hold, overwriting adjacent memory and potentially causing crashes or code execution.
What coding practice helps prevent buffer overflows?
Bounds checking / proper memory validation.
What is a race condition?
A vulnerability where security or program behavior depends on the timing/order of simultaneous operations.
What is TOCTOU?
Time-of-Check to Time-of-Use - a race condition where something changes between checking a condition and using the result.
A system checks that a file is safe, then an attacker replaces it before the system opens it. What attack?
TOCTOU race condition.
Why can software updates themselves become an attack vector?
Users trust updates. If the vendor/update infrastructure is compromised, malicious code can be delivered as a legitimate update.
What major concept does the SolarWinds incident demonstrate?
Software supply-chain compromise / malicious trusted updates.
What is SQL injection (SQLi)?
Injecting malicious SQL commands through application input so the backend database executes attacker-controlled queries.
What commonly enables SQL injection?
Improper handling/validation of user input and insecure database queries.
' OR '1'='1 appearing in an authentication field suggests what?
SQL injection.
What is XSS?
Cross-Site Scripting - injecting malicious client-side scripts, commonly JavaScript, that execute in another user's browser.
What does XSS primarily exploit: database trust or browser/user trust?
The user's/browser's trust in a legitimate website.
What is reflected XSS?
Malicious script is contained in a request/link and immediately reflected by the vulnerable site into the victim's browser.
What is stored/persistent XSS?
Malicious script is permanently stored on the target application and executes whenever users view the affected content.
Reflected vs. stored XSS?
Reflected: payload arrives with a specific request/link. Stored: payload remains on the server and affects future visitors.
XSS vs. SQL injection?
XSS targets the user's browser/client-side execution. SQLi targets backend database queries.
What is firmware?
Software embedded inside a hardware device that controls its basic functionality.
What is EOL?
End of Life - the vendor stops selling a product; some support may potentially continue.
What is EOSL?
End of Service Life - vendor support and routine updates/security patches have ended.
Why is EOSL usually a bigger security concern than EOL?
Unsupported systems may no longer receive security patches for newly discovered vulnerabilities.
What is a legacy platform?
An older system/application still in use despite outdated technology, limited support, or security limitations.
What is VM escape?
Breaking out of a guest virtual machine and accessing the hypervisor/host or other guest systems.
Why is VM escape extremely dangerous?
Compromising the host can potentially give the attacker influence over multiple guest VMs.
What is the virtualization resource reuse risk?
Physical memory/storage/CPU resources are reused between VMs, creating potential data exposure if resource handling is insecure.
What are common cloud security vulnerabilities?
Weak authentication, unpatched systems, misconfigurations, excessive permissions, exposed data, and vulnerable applications/APIs.
What is an open permission vulnerability?
A resource is configured so unauthorized users can access data or functionality.
Why are unsecured administrative accounts especially dangerous?
Compromise provides powerful privileges capable of changing configurations, accessing data, or controlling the system.
Which is safer: direct root login or using a normal account plus sudo?
A normal account using controlled privilege elevation such as sudo.
Why are default credentials dangerous?
Vendor default usernames/passwords are widely known and can give attackers immediate administrative access.
What famous malware abused default IoT credentials?
Mirai botnet.
Why should unnecessary services and ports be disabled?
Every service/port expands the attack surface and may contain exploitable vulnerabilities or misconfigurations.
Why are Telnet and FTP considered insecure protocols?
They traditionally transmit information without encryption, potentially exposing credentials/data in plaintext.
Secure replacements for Telnet and FTP?
SSH instead of Telnet; SFTP instead of FTP.
What is jailbreaking?
Bypassing Apple's iOS restrictions to gain deeper operating-system access and install unauthorized software.
What is rooting?
Gaining privileged/root-level access to an Android device.
What is sideloading?
Installing an application manually from outside the approved application store/distribution channel.
Why can jailbreaking/rooting weaken MDM protections?
They bypass normal OS security restrictions, allowing users/apps to circumvent controls enforced by MDM.
What is a zero-day vulnerability?
A vulnerability that is unknown to or not yet fixed by the vendor when attackers can exploit it.
Why are zero-days difficult to defend against?
Existing signatures, patches, and known-vulnerability defenses may not yet exist.
What is malware?
Malicious software designed to damage, disrupt, spy, steal, manipulate, or gain unauthorized access.
What is ransomware?
Malware that makes data/resources unavailable, commonly through encryption, and demands payment for restoration.
What is one of the strongest defenses against ransomware impact?
Protected offline/isolated backups, combined with patching and endpoint protection.
What is a virus?
Self-replicating malware that generally requires execution/user activity or a host file/program to spread.
What is a worm?
Malware that self-propagates automatically, commonly across networks without requiring user interaction.
Virus vs. worm?
Virus usually needs execution/host interaction. Worm spreads automatically.
What is fileless malware?
Malware operating primarily in memory rather than installing a traditional malicious executable on disk.
Why can fileless malware evade traditional antivirus?
Traditional AV often relies heavily on scanning malicious files stored on disk.
What is spyware?
Malware that secretly monitors users and collects information such as browsing behavior or credentials.
What is a keylogger?
Software/hardware that records keystrokes, potentially capturing passwords, messages, and sensitive information.
Why can keylogging bypass network encryption?
The keystrokes are captured before the data is encrypted for transmission.
What is a logic bomb?
Malicious code that remains dormant until a predefined condition/event occurs.
What is a time bomb?
A logic bomb triggered by a specific time or date.
What is a rootkit?
Malware designed to hide deeply within a system, often modifying low-level/core system components to conceal itself or maintain privileged access.
Why are rootkits difficult to detect?
A rootkit may manipulate the operating system itself, hiding malicious processes/files from normal monitoring tools.
What is bloatware?
Unnecessary preinstalled software that consumes resources and may increase attack surface.
Why is physical access considered such a major security risk?
An attacker with physical control can potentially bypass many software-based defenses.
What is RFID cloning?
Copying information from an RFID badge/fob to another device/card to impersonate the legitimate holder.
What is an environmental attack/risk?
Disrupting supporting infrastructure such as power, cooling/HVAC, humidity control, or fire suppression.
What is DoS?
Denial of Service - making a system/service unavailable by overwhelming it, exploiting a vulnerability, or disrupting supporting resources.
What is DDoS?
Distributed Denial of Service - many systems coordinate to overwhelm or exhaust a target.
Why are botnets commonly associated with DDoS?
They provide attackers with thousands or millions of compromised devices that can generate traffic simultaneously.
What is DDoS reflection?
Attacker spoofs the victim's address so third-party systems send their replies to the victim.
What is DDoS amplification?
Small attacker requests generate much larger responses toward the victim, multiplying attack traffic.
Which protocols are often associated with reflection/amplification attacks?
Protocols such as DNS and NTP that can generate significant responses and historically lacked strong request authentication.
What is DNS poisoning?
Manipulating DNS information or responses so users are redirected to an incorrect/malicious destination.