Updated MODULE 1: Overview of Cybersecurity

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/195

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 9:23 PM on 8/22/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

196 Terms

1
New cards

What is security?

According to the lecture, security is the necessary steps taken to protect a person or property from harm.

2
New cards

What is the relationship between security and convenience?

Security is inversely proportional to convenience; as security increases, convenience generally decreases.

3
New cards

Why is security and convenience not directly proportional?

More security usually requires additional restrictions, steps, or controls, which reduces convenience.

4
New cards

What is cybersecurity?

Cybersecurity is the art, practice, and task of protecting networks, devices, and information.

5
New cards

What is the comprehensive definition of cybersecurity?

Cybersecurity protects the confidentiality, integrity, and availability of information on devices that store, manipulate, and transmit information through products, people, and procedures.

6
New cards

What are the three mandatory protections of cybersecurity?

Confidentiality, Integrity, and Availability (CIA).

7
New cards

What does CIA stand for?

Confidentiality, Integrity, and Availability.

8
New cards

What is confidentiality?

Ensuring that sensitive information is accessed only by authorized individuals or systems.

9
New cards

What is integrity?

Ensuring that data remains accurate, consistent, complete, and unaltered.

10
New cards

What is availability?

Ensuring that information and network resources are accessible to authorized users when needed.

11
New cards

What are the three protection layers of cybersecurity?

People, Products, and Policies.

12
New cards

Why is cybersecurity considered an art?

It protects networks and devices and is never a one-and-done task.

13
New cards

Why is cybersecurity considered a practice?

It continuously protects information that has value to people and organizations.

14
New cards

Why is cybersecurity considered a task?

It protects devices that store, process, and transmit information.

15
New cards

Why is cybersecurity difficult?

There is no single simple solution that can stop all cyberattacks.

16
New cards

What are examples of cyberattacks?

Malware, phishing, denial-of-service (DoS), and spoofing.

17
New cards

Who is at risk of cyberattacks?

Anyone who uses a computing device or has a device connected to the Internet.

18
New cards

What types of devices can be attacked?

Laptops, tablets, smartphones, security cameras, doorbells, thermostats, and other Internet-connected devices.

19
New cards

Why are universally connected devices a cybersecurity challenge?

Attackers can potentially attack devices from anywhere in the world.

20
New cards

Why does the increased speed of attacks make cybersecurity difficult?

Attackers can launch attacks against millions of computers within minutes.

21
New cards

Why does the sophistication of attacks make cybersecurity difficult?

Attack tools can change their behavior so that the same attack can appear differently each time.

22
New cards

Why is the availability of attack tools a problem?

Attacks are no longer limited to highly skilled attackers because attack tools are widely available and easier to use.

23
New cards

Why is the faster discovery of weaknesses a problem?

Attackers can discover security holes in hardware and software faster than defenders can respond.

24
New cards

Why are delays in security updates dangerous?

Vendors may struggle to update products quickly enough to defend against the newest attacks.

25
New cards

Why is weak security-update distribution a problem?

Some software products do not have effective ways to distribute security updates in a timely manner.

26
New cards

What are distributed attacks?

Attacks in which attackers use thousands of computers to attack a single computer or network.

27
New cards

Why is user confusion a cybersecurity problem?

Users often have to make difficult security decisions with little or no instruction.

28
New cards

What two statements from the lecture's attack knowledge check are correct?

Some attacks can vary their behavior so the same attack appears differently, and user confusion is a major difficulty in preventing attacks.

29
New cards

What is an asset?

Something of value that needs to be protected.

30
New cards

What is an example of an asset?

An employee database or other information that has value to an organization.

31
New cards

What is a threat?

A type of action with the potential to cause harm.

32
New cards

What is a threat agent?

A person or element with the power to carry out a threat.

33
New cards

What is a vulnerability?

A flaw or weakness that allows a threat agent to bypass security.

34
New cards

What is an attack vector?

The means by which an attack can occur.

35
New cards

What is an example of an attack vector?

A threat actor stealing a user's password through a software flaw.

36
New cards

What is threat likelihood?

The probability that a threat agent will exploit a vulnerability.

37
New cards

What is risk?

A situation involving exposure to some type of danger.

38
New cards

What is the difference between a threat and a threat agent?

A threat is an action with potential to cause harm, while a threat agent is the person or element capable of carrying out the threat.

39
New cards

What is the relationship between vulnerability and threat agent?

A vulnerability is a weakness that allows a threat agent to bypass security.

40
New cards

What are the five ways to deal with risk?

Risk avoidance, risk acceptance, risk mitigation, risk deterrence, and risk transference.

41
New cards

What is risk avoidance?

Changing plans or eliminating an activity so the risk does not occur.

42
New cards

What is risk acceptance?

Recognizing a risk and choosing to accept it.

43
New cards

What is risk mitigation?

Taking steps to reduce the likelihood or impact of a risk.

44
New cards

What is risk deterrence?

Taking actions that discourage attackers from carrying out an attack.

45
New cards

What is risk transference?

Shifting some or all of the risk to another party.

46
New cards

What are the major goals of cybersecurity?

Prevent data theft, thwart identity theft, foil cyberterrorism or sabotage, avoid legal consequences, maintain productivity, and protect the country and population from cyber threats or cyberwar.

47
New cards

What are the five key elements of a practical cybersecurity strategy?

Block attacks, update defenses, minimize losses, use layers, and stay alert.

48
New cards

What does "Block Attacks" mean?

Create security perimeters and defenses designed to prevent attacks from reaching systems and information.

49
New cards

Why is local security still important if a network has a security perimeter?

Some attacks can breach the perimeter, so individual computers and devices also need protection.

50
New cards

What does "Update Defenses" mean?

Regularly update cybersecurity hardware and software to defend against new types of attacks.

51
New cards

Why must cybersecurity defenses be updated?

New attacks appear constantly, so older defenses may not protect against them.

52
New cards

What is one important way to update defenses?

Apply operating-system and vendor security updates regularly.

53
New cards

What does "Minimize Losses" mean?

Take actions in advance to reduce the damage if an attack succeeds.

54
New cards

What are examples of minimizing losses?

Backing up important data and establishing a business recovery policy.

55
New cards

What is a business recovery policy?

A policy that explains what to do if a successful attack occurs.

56
New cards

What does "Use Layers" mean?

Use multiple security defenses so attackers must overcome several protections.

57
New cards

Why are security layers useful?

Attackers must breach multiple defenses, which can discourage them and cause them to seek an easier target.

58
New cards

What does "Stay Alert" mean?

Everyone must remain aware of cybersecurity threats and know what actions to take to stay secure.

59
New cards

Why is cybersecurity everyone's responsibility?

Users, administrators, managers, and security professionals all play a role in protecting information and systems.

60
New cards

What are the three major hacker types?

Black hat hackers, white hat hackers, and gray hat hackers.

61
New cards

What is a black hat hacker?

An attacker who violates computer security for personal gain or to cause malicious damage.

62
New cards

What is a white hat hacker?

An ethical attacker who, with an organization's permission, looks for weaknesses and reports them to the organization.

63
New cards

What is a gray hat hacker?

An attacker who accesses a system without permission but not necessarily for personal gain, often publicly disclosing the vulnerability to pressure or shame the organization.

64
New cards

What is the main difference between a white hat and gray hat hacker?

A white hat hacker has permission to test the system; a gray hat hacker does not.

65
New cards

What is the main difference between a black hat and white hat hacker?

Black hats attack without authorization for malicious or personal purposes, while white hats are authorized ethical attackers.

66
New cards

Who are cybercriminals?

Attackers primarily motivated by financial gain, such as stealing credit card information.

67
New cards

What is the typical objective of cybercriminals?

Fortune over fame; they primarily seek financial profit.

68
New cards

Who are script kiddies?

Attackers who use existing tools primarily for thrills, notoriety, or curiosity rather than advanced technical skill.

69
New cards

What is the typical target of script kiddies?

Businesses and users.

70
New cards

Who are vulnerability brokers?

People who find vulnerabilities and sell them to the highest bidder.

71
New cards

What is the typical objective of vulnerability brokers?

To make money by selling information about vulnerabilities.

72
New cards

Who are insiders?

People inside an organization who misuse their access, often to retaliate, embarrass the organization, or expose information.

73
New cards

Who are cyberterrorists?

Attackers who seek to cause disruption and panic.

74
New cards

What is an example of a cyberterrorist attack?

Crippling computers that control a water-treatment system.

75
New cards

Who are hacktivists?

Attackers motivated by political or social causes who attempt to right a perceived wrong.

76
New cards

Who are state actors?

Government-sponsored attackers who may spy on citizens or disrupt foreign governments.

77
New cards

What is a common goal of state actors?

Espionage, surveillance, disruption, or advancing government interests.

78
New cards

What is information security?

The protection of information and its critical elements, including systems and hardware that use, store, and transmit that information.

79
New cards

What does information security include?

Information security management, data security, and network security.

80
New cards

What are the three foundational goals of information security?

Confidentiality, Integrity, and Availability.

81
New cards

What are the seven characteristics of information?

Confidentiality, Integrity, Availability, Accuracy, Authenticity, Utility, and Possession.

82
New cards

What does confidentiality mean in information security?

The quality or state of preventing disclosure or exposure to unauthorized individuals or systems.

83
New cards

What does integrity mean in information security?

The quality or state of being whole, complete, and uncorrupted.

84
New cards

What does availability mean in information security?

Ensuring users who need information can access it without interference or obstruction and in the required format.

85
New cards

What does accuracy mean?

Information is free from mistakes or errors and has the value the end user expects.

86
New cards

What does authenticity mean?

The quality or state of being genuine or original rather than a reproduction or fabrication.

87
New cards

What does utility mean?

Information has value when it serves a particular purpose.

88
New cards

What does possession mean?

The quality or state of having ownership or control of an object or item.

89
New cards

What is the difference between possession and confidentiality?

A breach of confidentiality always results in a breach of possession, but a breach of possession does not always result in a breach of confidentiality.

90
New cards

What is an information system?

The entire set of hardware, software, data, people, procedures, and networks.

91
New cards

What are the six components of an information system?

Hardware, software, data, people, procedures, and networks.

92
New cards

Why is perfect information security impossible?

Security is a continuous process rather than a final goal.

93
New cards

What is the security balance?

Security must balance protection with availability and reasonable access.

94
New cards

Why can't an organization simply maximize security?

Too much security can make systems difficult or impossible for authorized users to access and use.

95
New cards

What is the CNSS Security Model also known as?

The McCumber Cube.

96
New cards

Who is associated with the McCumber Cube?

John McCumber.

97
New cards

What does the McCumber Cube illustrate?

The intersection of information characteristics/objectives, information states, and security safeguards.

98
New cards

What are the three information states in the McCumber Cube?

Information at rest, information in processing/use, and information in transmission.

99
New cards

What are the three fundamental information-security objectives in the McCumber Cube?

Confidentiality, Integrity, and Availability.

100
New cards

What are the three primary means of implementing security in the McCumber Cube?

Policy, education, and technology.