Information Security Chapter 2

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/58

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 4:59 PM on 8/25/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

59 Terms

1
New cards

Vulnerability

  • Asset Value

  • Ease of Exploit


2
New cards

Threat

  • Internal/External

  • Malicious/Accidental

  • Threat Actor

  • Threat Vector


3
New cards

Risk

(Impact * Likelihood)

4
New cards

Attributes of Threat Actors (1)

Known threats vs adversary behaviours

5
New cards

Internal/External (Attributes of Threat Actors 2)

Attribute of an attacker, not where an attack takes place

6
New cards

Internal Threats

Have authorized access already

7
New cards

Level of sophistication/Capability

  • Low Capability Actors

  • High Capability Actors

  • Access to Military Assets

  • (Attribute of Threat Actors 3)


8
New cards

Low Capability Actors

Rely on Commodity tools

9
New cards

High Capability Actors

Can develop new attack

10
New cards

Resources/funding

Attributes of Threat Actors (4)

11
New cards

Motivations of Threat Actors (1)

Intent/Motivation

12
New cards

Chaotic Motivation, Financial Motivations, Political Motivations

Three types of motivations of Threat Actors

13
New cards

Intent/Motivation (Motivation of Threat Actors)

  • Maliciously Targeted versus opportunistic

  • Accidental/Unintentional


14
New cards

Strategies (Motivations of Threat Actors)

Service disruption, data exfiltration, and disinformation

15
New cards

Financial Motivations

Blackmail, extortion, and fraud


16
New cards

Political Motivation

Whistleblowers, campaign groups, nation-state actors

17
New cards

Lone Hacker

  • White hats vs black hats

  • Authorized vs non-authorized


18
New cards

Unskilled Attacker

Script Kiddies

19
New cards

Lone Hacker, Unskilled Attacker, Hacker Teams, and Hacktivists

Four types of hacker and hacktivists

20
New cards

APT

Advance Persistent Threat

21
New cards

Nation-State Actors and Advanced Persistent Threats

  • Attached to military/secret services

  • High Level of Capability

  • APT

  • Espionage and strategic advantage

  • Deniability

  • False Flag Operations


22
New cards

Organized Crime

  • Operates under legal jurisdiction

  • Motivated by criminal profit

  • Can be well-resourced and funded


23
New cards

Competitors

  • Cyber espionage and disinformation

  • Combine with insider threat


24
New cards

Malicious Internal Threat and Unintentional Insider Threat

Two Types of Internal Threat Actors

25
New cards

Malicious Internal Threat

  • Has or had Authorized Access

  • Employees, Contractors, Partners

  • Sabotage, Financial Gain, Business Advantage


26
New cards

Unintentional Insider Threat

  • Weak Policies and procedures

  • Weak Adherence to policies and procedures

  • Lack of Training/Security Awareness

  • Shadow IT


27
New cards

Attack Surface

  • Points where an attacker can discover/exploit vulnerabilities

  • Physical, Network, Application, and Human Surfaces

  • Whole Organization or single system/app scope


28
New cards

Threat Vectors

  • High-capability actors can expand the attack surface by developing novel vectors


29
New cards

Vulnerable Software

  • Faults in code or design

  • Delays and difficulties in patching


30
New cards

Client-Based vs Agentless

  • Characteristic of automated vulnerability scanners


31
New cards

Vulnerable Software, Unsupported System and Application, Client-Based vs Agentless

Three Vulnerable Software Vectors

32
New cards

Remote vs local exploit techniques, Unsecure Networks, and Specific Vectors

Three Network Vectors

33
New cards

Unsecure Networks

Lack of Confidentiality, Integrity, and Availability

34
New cards

Specific Vectors

  • Direct Access and Wired (Physical Ports)

  • Remote, Wireless, Cloud, and Bluetooth

  • Default Credentials

  • Open Service Port (TCP and UDP ports)


35
New cards

Lure-Based Vectors

Bait That Will tempt the target into opening it


36
New cards

Removable Device, Executable File, Document Files, Image Files

Four Kinds of Lure-Based Vectors

37
New cards

Removable Device

Drop Attack

38
New cards

Executable File

Trojan Horse Malware

39
New cards

Document Files

Macro and Scripting technologies

40
New cards

Image Files

Viewer/Browser vulnerabilities

41
New cards

Email, Short Message Service (SMS), Instant Messaging (IM), Web and Social Media, Voice Call

Five Message-Based Vectors

42
New cards

Supply-Chain Attack Surface

  • End-to-end process of designing, manufacturing, and distributing goods and services to a customer

  • Procurement Management

  • Suppliers, Vendors, and Business Partners

  • Whole Supply Chain can be Highly Complex

  • Managed Service Providers (MSPs)


43
New cards

Social Engineering

“Hacking The Human”

44
New cards

Reconnaissance and eliciting information, Intrusion and gaining unauthorized access

Purposes of Social Engineering

45
New cards

Persuade a user to run a malicious file

Scenarios for social engineering (1)

46
New cards

Contact a help desk and solicit information

Scenarios for social engineering (2)

47
New cards

Gain Access to premises and install a monitoring device

Scenarios for social engineering (3)

48
New cards

Impersonation

  • Pretending to be someone else

  • Persuasiveness/consensus/liking approach

  • Coercion/Threat/Urgency Approach


49
New cards

Pretexting

  • Exploit Situations where identity-proofing is difficult

  • Using a scenario with convincing additional detail

  • Obtain or spoof data that supports the identity claim


50
New cards

Phishing

  • Tricks target into using a malicious resource

  • Spoof legitimate communications and site


51
New cards

Vishing

Using a voice channel

52
New cards

SMishing

Using text messaging

53
New cards

Pharming

Redirection by DNS Spoofing

54
New cards

Passive Techniques

Have less risk of detection

55
New cards

Typosquatting

Cousin domains that look like a trusted domain

56
New cards

Pose as colleague, Business Partner, or vendor

Targets of Pishing/Vishing/Smishing to a specific individual

57
New cards

Spear phishing, whaling, CEO Fraud, and Angler Phishing

Four types of phishing on BUSINESS EMAIL COMPROMISE

58
New cards

Brand Impersonation and Disinformation

  • Making convincing fake phishing messages, business correspondence, and pharming websites

  • Disinformation vs Misinformation


59
New cards

Watering Hole Attack

Compromise a third-party site that the threat actor knows is used by the target