Mid Term Part 2

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/294

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 12:37 AM on 10/5/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

295 Terms

1
New cards

CIA Triad

The three core security goals: Confidentiality (only authorized access), Integrity (data stays accurate and unaltered), Availability (systems and data accessible when needed).

2
New cards

Confidentiality

Ensures information is safe from accidental or intentional disclosure; only authorized people/processes can access sensitive data.

3
New cards

Integrity

Ensures data is complete, accurate, and not altered or corrupted, accidentally or intentionally.

4
New cards

Availability

Ensures authorized users can access information, systems, and resources whenever they need them.

5
New cards

Opposite of confidentiality, integrity, and availability

Confidentiality = Disclosure; Integrity = Alteration; Availability = Destruction.

6
New cards

Controls that support confidentiality

Encryption and strong passwords.

7
New cards

Controls that support integrity

Hashing, digital signatures, and encryption (which keeps intercepted data from being altered meaningfully).

8
New cards

Controls that support availability

Backups and redundant systems.

9
New cards

Common threats to confidentiality

Data breaches, man-in-the-middle attacks, phishing, insider threats, malware, and spyware.

10
New cards

Common threats to integrity

Man-in-the-middle attacks, SQL injection, ransomware, malicious code, and viruses.

11
New cards

Common threats to availability

DDoS attacks, ransomware, hardware failure, natural disasters, and insider threats or faulty updates (e.g., the CrowdStrike outage).

12
New cards

Why the CIA Triad needs balance

Focusing on only one pillar (e.g., confidentiality) leaves systems exposed to data manipulation or outages. A holistic approach across all three is required.

13
New cards

Which CIA pillars do banking systems prioritize?

Confidentiality and Integrity (gaming servers, by contrast, prioritize Availability).

14
New cards

Vulnerability

A flaw, weakness, or security hole in a system, component, or procedure (e.g., buffer overflow, weak password policy, unencrypted Wi-Fi).

15
New cards

Threat

Any entity, force, or agent (person, code, or nature) capable of exploiting a vulnerability to compromise C, I, and/or A.

16
New cards

Examples of threats

Hackers, nation-state actors, terrorists, worms, viruses, phishing emails, ransomware, floods, windstorms, solar storms.

17
New cards

Risk

The likelihood that assets will be compromised, causing loss of C, I, and/or A; the cost of a mission-impacting event weighted by its probability.

18
New cards

Risk formula

Risk = Vulnerability x Threat x Impact

19
New cards

When is risk zero?

When either the vulnerability or the threat is absent. Risk requires both to exist at the same time.

20
New cards

Example of zero risk: no password

A computer with no password (vulnerability) but no threat actors able to exploit it has risk = 0.

21
New cards

Example of zero risk: hurricane

A Florida hurricane (threat) cannot harm servers located in Wyoming (no exposure/vulnerability), so risk = 0.

22
New cards

Realized risk

Occurs when a threat actor or event successfully exploits a vulnerability and impacts the confidentiality, integrity, or availability of an asset.

23
New cards

Ultimate goal of cybersecurity

Reduce risk to an acceptable level by applying controls and countermeasures.

24
New cards

Primary mission of threat actors

Steal money or steal data (which is converted into money) by compromising C, I, or A.

25
New cards

Countermeasure (control)

A tool or technique applied to reduce risk, enabling greater mission capability and system reliability.

26
New cards

Protect (countermeasure function)

Preventative measures that block unauthorized actions and security incidents.

27
New cards

Detect (countermeasure function)

Mechanisms that identify when a breach or adverse event occurs or when an attacker bypasses defenses (e.g., IDS).

28
New cards

React (countermeasure function)

Responsive actions that handle adverse events quickly to minimize mission impact.

29
New cards

Physical controls

Tangible mechanisms that prevent physical access: gates, fences, locks.

30
New cards

Logical (technical) controls

Technology/software mechanisms protecting digital systems: firewalls, OS updates, software patches.

31
New cards

Administrative controls

Policy-driven and managerial controls: security policies and user security training.

32
New cards

NIST SP 800-53

A comprehensive catalog of security and privacy controls published by the National Institute of Standards and Technology.

33
New cards

Defense in depth

Layering multiple security measures at different levels (e.g., door locks + network firewalls + security policies) to protect critical assets.

34
New cards

How controls relate to risk

Controls and countermeasures act on vulnerabilities and threats to decrease total risk to C, I, and A.

35
New cards

People, Process, Technology

The triad of effective security: People (training, awareness, culture), Process (policies, governance, procedures), Technology (firewalls, access controls, monitoring tools).

36
New cards

Script kiddie

An inexperienced attacker who uses existing automated scripts or tools.

37
New cards

Hacktivist

An attacker motivated by political, ideological, or social agendas.

38
New cards

Organized crime (threat actor)

Structured groups seeking financial gain through cyber attacks.

39
New cards

Nation-state / APT

State-sponsored groups with high sophistication, large resources, and long-term targets.

40
New cards

Insider threat

An employee, contractor, or trusted person who misuses authorized access.

41
New cards

Competitor (threat actor)

A corporate entity trying to gain illegal commercial advantage or intelligence.

42
New cards

Advanced Persistent Threat (APT)

A sophisticated, well-resourced, long-term attacker, typically state-sponsored.

43
New cards

White hat hacker

An ethical security professional who finds and fixes vulnerabilities with the system owner's permission.

44
New cards

Black hat hacker

A hacker who breaks into systems illegally with malicious intent (financial gain, data theft, disruption).

45
New cards

Grey hat hacker

A hacker who may break laws or ethical norms but usually without malicious intent.

46
New cards

Purple hat hacker

A professional who combines offensive (red team) and defensive (blue team) skills to strengthen security.

47
New cards

Social engineering

Manipulating people into giving up access or information by exploiting human psychology instead of technical vulnerabilities.

48
New cards

Phishing

Broad fraudulent messages designed to trick users into revealing credentials or information.

49
New cards

Spear phishing

Targeted phishing aimed at specific individuals or organizations.

50
New cards

Vishing

Voice-based phishing over phone or audio channels.

51
New cards

Dumpster diving

Searching trash for discarded paperwork that contains credentials or sensitive information.

52
New cards

Shoulder surfing

Directly observing someone entering credentials on a keyboard or screen.

53
New cards

Denial of Service (DoS)

An attack that overwhelms a single target (one endpoint) so legitimate users cannot access it.

54
New cards

Distributed Denial of Service (DDoS)

A DoS attack launched from many sources at once, flooding a network or service with traffic to knock it offline.

55
New cards

Man-in-the-middle (MITM) attack

An attacker secretly sits between two communicating parties to intercept and possibly alter their communication.

56
New cards

Buffer overflow

A software vulnerability where data exceeds a memory buffer's size, letting attackers corrupt memory or run malicious code.

57
New cards

Replay attack

An attacker intercepts a legitimate communication and resends it to trick the receiver into performing unauthorized actions.

58
New cards

Evil twin

A fraudulent Wi-Fi access point that mimics a legitimate network to intercept users' sensitive information.

59
New cards

Rogue access point

An unauthorized wireless device connected to a network, enabling data interception, malware distribution, and MITM attacks.

60
New cards

Birthday attack

A cryptographic attack exploiting hash-collision probability to find two different inputs that produce the same hash.

61
New cards

Known plaintext / ciphertext attack

The attacker has both plaintext and its matching ciphertext and tries to deduce the key or algorithm.

62
New cards

Rainbow table

A precomputed database mapping plaintext passwords to hash values, used to reverse hashes quickly without brute force. Salting defeats it.

63
New cards

Brute force attack

Systematically guessing passwords, usernames, or keys by trial and error, often with automated tools.

64
New cards

Ransomware

Malware that encrypts a victim's files and demands payment for the decryption key.

65
New cards

Ransomware-as-a-Service (RaaS)

A commercialized criminal model where ransomware platforms are rented (often via dark web subscriptions) to independent affiliates.

66
New cards

Botnet

A network of hijacked devices (often unsecured IoT) controlled by an attacker, e.g., the Mirai botnet.

67
New cards

Why unsecured IoT devices are dangerous

They can be hijacked to build botnets or used as lateral-movement pivot points into secure enterprise networks.

68
New cards

Deepfake

Synthetic video, audio, or images made with deep learning, used for social engineering, fraud, or disinformation.

69
New cards

AI-driven attacks

Attacks using AI for automated exploitation, advanced evasion, and intelligence gathering.

70
New cards

Quantum computing risk

Powerful quantum computers could break today's public-key (asymmetric) encryption, driving research into post-quantum cryptography (PQC).

71
New cards

Blockchain

A distributed ledger that records transactions across many computers so data is secure, transparent, and immutable; underpins cryptocurrencies like Bitcoin.

72
New cards

Stuxnet

A computer worm discovered around 2010 that marked a shift toward targeted, state-level cyber operations against specific infrastructure.

73
New cards

Why attackers hide MAC and IP addresses

Addresses are identifiers for a device; attackers can use them to locate and target you, so attackers themselves mask identity with tools like VPNs.

74
New cards

Internet Protocol (IP)

The networking protocol that provides addressing so data packets reach the correct destination.

75
New cards

Network protocol

A standardized set of rules governing how data is transferred across networks.

76
New cards

Evolution of threat actors: lone hackers

1980s-1990s: curiosity-driven individuals using phreaking and basic remote exploitation.

77
New cards

Evolution of threat actors: cybercrime rings

2000s: financially motivated syndicates running botnets, spam, identity theft, and carding forums.

78
New cards

Evolution of threat actors: nation-states

2010s: well-funded APTs pursuing espionage, military advantage, and infrastructure sabotage with zero-day exploits.

79
New cards

Evolution of threat actors: RaaS era

Present: commercialized extortion with modular ransomware platforms rented to affiliates.

80
New cards

NIST definition of cybersecurity

The ability to protect or defend the use of cyberspace from cyber attacks.

81
New cards

Practical definition of cybersecurity

Protecting systems, networks, and data from digital attacks, unauthorized access, damage, or disruption (also called IT security or electronic information security).

82
New cards

Three core system security questions

What are the cyber components? What are the threats and vulnerabilities? How can risk be reduced by design through engineering controls?

83
New cards

Information security

Protecting information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction.

84
New cards

Cybersecurity vs. cybersecurity engineering

Cybersecurity is the broad governance/risk/policy/human-factors discipline; cybersecurity engineering is the technical discipline that designs, builds, and configures security controls.

85
New cards

Cybersecurity engineering vs. information security

Engineering is hands-on and technical (scans, pen tests, firewalls, IDS, EDR); information security is strategic and governance-oriented (policies, compliance, audits, incident business impact).

86
New cards

Cybersecurity engineering 4-stage lifecycle

1) Design, 2) Build and Test, 3) Operate and Defend, 4) Improve.

87
New cards

Cybersecurity analyst

Monitors security telemetry and network feeds to detect, analyze, triage, and prevent threats.

88
New cards

Cybersecurity engineer

Architects and monitors critical systems, writes patches, and builds technical countermeasures.

89
New cards

Penetration tester

An ethical hacker who uses offensive tools to legally breach defenses and uncover exploitable vulnerabilities.

90
New cards

Network engineer

Deploys network hardware, configures firewalls, monitors traffic anomalies, and updates infrastructure.

91
New cards

Cloud security engineer

Designs, deploys, and manages security controls for public, private, or hybrid cloud environments.

92
New cards

Cyber incident responder / forensics specialist

Performs triage, forensics, containment, log analysis, and root-cause investigation after a breach.

93
New cards

GRC specialist

Governance, Risk, and Compliance: builds governance frameworks, ensures regulatory compliance, manages audits and risk mitigation.

94
New cards

Core domains of cybersecurity defense

Application, information, network, and operational security; encryption; access control; user education/awareness; disaster recovery and business continuity.

95
New cards

Hardware vs. software

Hardware is the physical components (CPU, motherboard, screen); software is code-based programs running on hardware (apps, operating systems).

96
New cards

Operating system (OS)

Software that manages hardware resources (CPU, memory, storage) and sits between application software and physical hardware.

97
New cards

Virtual machine (VM)

Software that emulates physical hardware and an OS, letting one physical machine host multiple guest operating systems.

98
New cards

Why software is vulnerable

Software is built from source code, and code is imperfect; bugs and logic errors create vulnerabilities attackers exploit.

99
New cards

Case study: Colonial Pipeline

DarkSide ransomware forced a shutdown of a major fuel pipeline supplying much of the U.S. East Coast, triggering state emergencies; a Bitcoin ransom was paid and largely recovered by the FBI.

100
New cards

Case study: SolarWinds Orion

A supply chain attack by APT29 (Cozy Bear) that compromised the software build pipeline, pushing trojanized updates to downstream customers.