Jeremy's IT Lab CCNA Security Fundamentals Day 48

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/53

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 6:59 AM on 7/24/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

54 Terms

1
New cards

[...] are a form of authentication often used to prove the identity of a website.

Digital certificates

2
New cards

[...] are malware that infect other software, called a host program.

Viruses

3
New cards

[...] are malware that is disguised as legitimate software.

Trojan horses

4
New cards

[...] are standalone malware that spread on their own, without user interaction.

Worms

5
New cards

[...] attacks are used to gather information about a target.

Reconnaissance

6
New cards

[...] attacks compromise sites that the target victim frequently visits.

Watering hole

7
New cards

[...] attacks involve entering restricted, secured areas by walking in behind an authorized person as they enter.

Tailgating

8
New cards

[...] attacks involve psychological manipulation to make the target reveal confidential information or perform some other action.

Social engineering

9
New cards

[...] is a kind of phishing targeted at high-profile individuals.

Whaling

10
New cards

[...] is a kind of social engineering which typically involves fraudulent emails that try to appear legitimate.

Phishing

11
New cards

[...] is a more targeted form of phishing, for example aimed at employees of a certain company.

Spear phishing

12
New cards

[...] is phishing performed over the phone.

Vishing

13
New cards

[...] is phishing using SMS text messages.

Smishing

14
New cards

[...] programs are designed to make employees aware of potential security threats and risks.

User awareness

15
New cards

[...] programs are formal sessions which educate users on corporate security policies and issues.

User training

16
New cards

[...] protects equipment and data from potential attackers by only allowing authorized users into protected areas such as network closets.

Physical access control

17
New cards

[...] refers to a variety of harmful programs that can infect a computer.

Malware

18
New cards

A [...] attack runs through a list of common words or passwords to find the target's password.

dictionary

19
New cards

A [...] attack tries every possible combination of letters, numbers, and special characters to guess the target's password.

brute force

20
New cards

A [...] is any potential weakness that can compromise the security of a system.

vulnerability

21
New cards

A [...] is the potential of a vulnerability to be exploited.

threat

22
New cards

A [...] technique is something that can protect against threats.

mitigation

23
New cards

A TCP [...] attack exploits the TCP three-way handshake.

SYN flood

24
New cards

A TCP SYN flood results in a [...] on the target.

denial-of-service

25
New cards

AAA: [...] is the process of granting a user the appropriate access and permissions.

Authorization

26
New cards

AAA: [...] is the process of recording the user's activities on the system.

Accounting

27
New cards

AAA: [...] is the process of verifying a user's identity.

Authentication

28
New cards

An [...] attack is a more dangerous kind of reflection attack.

amplification

29
New cards

An [...] is something that can potentially be used to take advantage of a vulnerability.

exploit

30
New cards

ARP spoofing is also known as [...].

ARP poisoning

31
New cards

CIA Triad: [...] = data should not be tampered with by unauthorized users.

Integrity

32
New cards

CIA Triad: [...] = only authorized users should be able to access data.

Confidentiality

33
New cards

CIA Triad: [...] = the network/systems should be operational and accessible to authorized users.

Availability

34
New cards

Cisco's AAA server is [...]

ISE

35
New cards

In a [...] attack, an attacker causes a reflector to send traffic to the target.

reflection

36
New cards

In a [...] attack, an attacker floods the target with DHCP Discover messages.

DHCP exhaustion

37
New cards

In a [...] attack, the attacker intercepts communications between two devices.

man-in-the-middle

38
New cards

In an [...] attack, an attacker sends fraudulent ARP replies.

ARP spoofing

39
New cards

RADIUS uses [...] ports 1812 and 1813.

UDP

40
New cards

RADIUS uses UDP ports [...] and [...].

1812 / 1813

41
New cards

TACACS+ uses [...] port 49

TCP

42
New cards

TACACS+ uses TCP port [...]

49

43
New cards

To [...] an address is to use a fake source address (IP/MAC)

spoof

44
New cards

What are the three factors of multi-factor authentication?

Something you know

Something you have

Something you are

45
New cards

What does AAA stand for?

Authentication, Authorization, and Accounting

46
New cards

What does Cisco ISE stand for?

Identity Services Engine

47
New cards

What does DDoS attack stand for?

distributed denial-of-service

48
New cards

What does DoS attack stand for?

denial-of-service

49
New cards

What does MFA stand for?

Multi-factor authentication

50
New cards

What is the A of the CIA triad?

Availability

51
New cards

What is the C of the CIA triad?

Confidentiality

52
New cards

What is the I of the CIA triad?

Integrity

53
New cards

Which AAA protocol is an open standard?

RADIUS

54
New cards

Which AAA protocol is Cisco proprietary?

TACACS+