SECURITY THREATS - IAS

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/31

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 10:42 AM on 8/26/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

32 Terms

1
New cards

Information Systems

Are integrated sets of components for collecting, storing, processing, and communicating information.

2
New cards

1. Transaction Processing System (TPS)

2. Management Information System (MIS)

3. Decision Support System (DSS)

4. Executive Information System (EIS)

5. Enterprise Resource Planning Systems (ERPS)

Types of Information Systems:

3
New cards

Ensuring data integrity, confidentiality, and availability is critical to avoid data breaches, financial losses, and damage to an organization's

What is the importance of Security in IS?

4
New cards

1. Malware

2. Phishing

3. Denial of Service (DoS) and Distributed Denial of Service (DDoS) Attacks

4. Insider Threats

5. Advanced Persistent Threats

6. Social Engineering

7. Zero-Day Exploit

What are the common security threats?

5
New cards

Malware

Software designed to disrupt, damage, or gain unauthorized access to computer systems.

Types:

6
New cards

1. Viruses

2. Worms

3. Trojan Horses

4. Ransomware

Types of Malware:

7
New cards

Viruses

Infect programs and replicate themselves.

8
New cards

Worms

Standalone software that replicates to spread to other computers.

9
New cards

Trojan Horses

Disguised as legitimate software but perform harmful activities.

10
New cards

Ransomware

Encrypts data and demands ransom for decryption.

11
New cards

Phishing

Fraudulent attempts to obtain sensitive information by pretending to be a trustworthy entity.

12
New cards

1. Email Phishing

2. Spear Phishing

3. Whaling

Common Tactics of Phishing:

13
New cards

Email Phishing

Deceptive emails designed to lure individuals into providing personal information.

14
New cards

Spear Phishing

Targeted phishing aimed at specific individuals or organizations.

15
New cards

Whaling

Phishing attacks directed at high-profile targets like executives.

16
New cards

Denial of Service (DoS) and Distributed Denial of Service (DDoS) Attacks

Attacks aimed at disrupting the normal functioning of a system by overwhelming it with a flood of internet traffic.

17
New cards

Can cause websites or services to become unavailable to legitimate users.

Impact of Denial of Service (DoS) and Distributed Denial of Service (DDoS) Attacks

18
New cards

Insider Threats

Security risks that originate from within the organization.

19
New cards

1. Malicious Insider

2. Accidental Insider

3. Mitigation

Types of Insider Threats:

20
New cards

Malicious Insider

An employee or contractor with intent to harm

21
New cards

Accidental Insider

Employees who unintentionally cause security breaches by mishandling data or systems.

22
New cards

Mitigation

Strong access controls, monitoring, and employee training.

23
New cards

Advanced Persistent Threats

Prolonged and targeted cyberattacks in which an intruder gains access to a network and remains undetected for an extended period.

24
New cards

Often involve sophisticated techniques and are aimed at stealing data or surveillance.

Characteristics of Advanced Persistent Threats

25
New cards

Social Engineering

Manipulation of individuals into performing actions or divulging confidential

information.

26
New cards

1. Pretexting

2. Baiting

Techniques of Social Engineering:

27
New cards

Pretexting

Pretending to be someone else to gain access to information.

28
New cards

Baiting

Luring victims with promises of goods or services to steal information.

29
New cards

Zero-Day Exploits

Attacks that exploit previously unknown vulnerabilities in software before developers can fix them.

30
New cards

Difficult to defend against due to the unknown nature of the threat.

Challenges of Zero-Day Exploits?

31
New cards

1. Financial Losses

2. Reputation Damage

3. Legal and Regulatory Consequences

4. Operational Disruptions

Impacts of Security Threats:

32
New cards

1. Regular Update and Patch Management

2. Implementing Strong Authentication Mechanisms

3. Employee Training and Awareness Programs

4. Data Encryption

5. Network Security Measures

6. Regular Security Audits and Penetration Testing

7. Incident Response Planning

8. Backup and Recovery

Best Practices for Mitigationg Security Threats: