Information Security: Barbarians at the Gateway Flashcards

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/33

flashcard set

Earn XP

Description and Tags

A comprehensive set of vocabulary flashcards covering information security threats, malware types, authentication methods, and organizational defense strategies from Chapters 21.3 and 21.4.

Last updated 2:20 AM on 6/10/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai

No analytics yet

Send a link to your students to track their progress

34 Terms

1
New cards

Social Engineering

Methods of manipulation that exploit human psychology rather than technical vulnerabilities to gain unauthorized access or information.

2
New cards

Phishing

The use of technology to acquire sensitive information or trick users into installing malicious software, often appearing to come from a trusted institution.

3
New cards

Spear Phishing

A targeted form of phishing aimed at a specific organization or group, making the attack more convincing and dangerous.

4
New cards

Bad Apples

Rogue employees who represent an internal threat by stealing trade secrets, installing malware, or holding a firm hostage using their trusted access.

5
New cards

AI Deepfakes

Sophisticated AI-generated audio, image, or video designed to convincingly impersonate real people or fabricate events.

6
New cards

Honey Trapping

A social engineering tactic where an attractive individual is deployed to charm targets into revealing information or granting favors.

7
New cards

Zero-Day Exploits

Brand-new attacks that have not yet been identified or incorporated into security screening systems, meaning no patch exists at the time of attack.

8
New cards

Script Kiddies

Unsophisticated attackers who rely on pre-built scripts and downloaded tools to launch attacks.

9
New cards

Biometrics

The measurement of unique human body characteristics, such as fingerprints, facial geometry, or voice prints, for authentication.

10
New cards

Two-Factor Authentication (2FA)

A security process requiring two separate forms of identification, typically something you know combined with something you have.

11
New cards

Multi-Factor Authentication (MFA)

An extension of 2FA2FA that requires more than two credential types to dramatically raise the bar for attackers.

12
New cards

Single-Use Tokenization

A security architecture that generates a unique token per transaction, rendering intercepted data useless for future fraud.

13
New cards

Passkeys

A password replacement standard developed by the FIDO Alliance that uses biometric authentication and public-key cryptography stored on a device.

14
New cards

Malware

Any software that seeks to compromise a computing system without the owner's permission.

15
New cards

Viruses

Malware that attaches to and infects legitimate software or files, spreading when the infected program runs.

16
New cards

Worms

Malware that exploits security vulnerabilities to spread automatically across networks without user interaction.

17
New cards

Trojans

Malicious software that disguises itself as legitimate software to sneak past defenses and execute a payload.

18
New cards

Botnets / Zombie Networks

Networks of hijacked devices used by attackers for click fraud, spam campaigns, and password attacks.

19
New cards

Keylogger

A type of malware or device that records every keystroke to capture passwords, credit card numbers, and confidential messages.

20
New cards

Ransomware

Malware that encrypts files and demands payment for the decryption key, intended to extort individuals or organizations.

21
New cards

Blended Threats

Cyberattacks that combine multiple malware types or hacking exploits for maximum damage and evasion.

22
New cards

SQL Injection

An exploit targeting poorly coded software that fails to validate user input, allowing attackers to manipulate database queries.

23
New cards

Cross-Site Scripting (XSS)

The process of injecting malicious scripts into web pages viewed by other users to hijack sessions or redirect victims.

24
New cards

Buffer Overflow

An attack that overwrites adjacent memory by submitting more data than a program can handle, potentially executing attacker-controlled code.

25
New cards

Dumpster Diving

A physical threat technique involving combing through discarded trash to recover sensitive documents, hardware, or storage media.

26
New cards

Shoulder Surfing

Gaining access credentials by observing someone type or read a screen in a public place.

27
New cards

Encryption

The process of scrambling data using a cipher to render it unreadable to anyone without the corresponding key.

28
New cards

Brute-Force Attacks

Attacks that exhaustively try every possible password combination to gain access.

29
New cards

ISO 27000 Series

The global gold standard for enterprise security governance, providing a model for establishing and maintaining an Information Security Management System.

30
New cards

Red Teams

Authorized adversaries who probe an organization's systems for weaknesses and test organizational defenses.

31
New cards

Adversary ROI Formula

Adversary ROI=Asset Value to AdversaryAdversary Cost\text{Adversary ROI} = \text{Asset Value to Adversary} - \text{Adversary Cost}

32
New cards

Honeypots

Deliberately tempting, bogus targets designed to lure and expose attackers.

33
New cards

Whitelists

A strict security posture that permits communication only with pre-approved entities or in approved formats.

34
New cards

Single Sign-On (SSO)

A tool providing employees with one highly secure, frequently rotated password that works across all applications.