MID TERM

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/131

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 1:29 AM on 10/6/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

132 Terms

1
New cards

Lodz Tram Attack

An amateur, most likely a script kiddie, was able to get in the proximity of this tram system, bypass authentication signals, and remotely change the direction which the tracks were going resulting in a major accident of the tram.

  1. Aspects of CIA violated: Integrity and availability

  2. Vulnerabilities present: Lack of authentication; moderate sophistication.

  3. Threats present: Juvenile

  4. Mitigate the risk or damage: Authentication & Physical Security

In January 2008, a 14‑year‑old Polish student in Łódź, Poland, hacked the city’s tram control system, causing four derailments, emergency stops, and injuries to at least a dozen people


2
New cards

Script Kiddie

an unskilled individual who uses malicious scripts or programs developed by others or LLMs.They typically lack advanced knowledge of programming or system administration and exploit existing software vulnerabilities to carry out attacks.

3
New cards

Mirai Botnet

Threat actors proved they were able to use IoT Devices to create a botnet, AKA an army of machines that can flood a network to deliver a DDos Attack.

  • Aspects of security violated: Availability

  • Vulnerabilities present: Firewall/Network Filtering, Lack of DDos Security.

  • Possible mitigation of risks/damage: Enable firewall filtering and enable IPS or IDS

  • - The Mirai Botnet was a major distributed denial-of-service (DDoS) attack using compromised IoT devices to overwhelm target networks, demonstrating significant flaws in device security and network defenses.


4
New cards

IoT Devices

are physical objects embedded with sensors, software, and connectivity that collect, exchange, and act on data over the Internet.

5
New cards

Botnet

a network of compromised devices, such as computers, servers, mobile devices, or IoT devices, that are infected with malware and controlled remotely by an attacker, often without the owner's knowledge. Each infected device, referred to as a "bot" or "zombie," operates under the command of a central entity known as the bot herder. Botnets are primarily used to execute large-scale malicious activities.

6
New cards

DDos Attack

A distributed denial-of-service (DDoS) attack is a malicious attempt to disrupt the normal traffic of a targeted server, service, or network by overwhelming the target or its surrounding infrastructure with a flood of Internet traffic.

7
New cards

Yahoo 2013

Attackers stole information from all 3 billion Yahoo accounts, including security questions and account data. This massive data breach, which occurred in 2013, resulted in the exposure of personal user information including names, email addresses, and hashed passwords.

  1. Aspects of Security Violated: Confidentiality, integrity

  2. Vulnerabilities: Weak security and inadequate protection of account data.

  3. Threats: External hackers/data thieves

  4. Mitigation: Implementing strong encryption, multi-factor authentication, and regular security audits. Educating users about phishing attacks and employing intrusion detection systems. Better password protection and continuous monitoring.


  5. - is one of the largest data breaches in internet history, affecting users globally. It highlighted the need for increased security measures and user awareness.


8
New cards

Colonial Pipeline Attack

Ransomware attack forced colonial pipeline to shut down operations.

This cyberattack in May 2021 disrupted fuel supply across the Eastern United States, highlighting vulnerabilities in critical infrastructure and prompting discussions on cyber security measures.

It resulted in a ransom payment of approximately $4.4 million and led to federal regulatory scrutiny.

  1. Aspects of Security Violated: Confidentiality and availability

  2. Vulnerabilities: Compromised VPN account and lack of MFA.

  3. Threats: Ransomware/cybercriminals - Darkside a Russian speaking cybercriminal hacker group.

  4. Mitigation: Use MFA, network segmentation, strong access controls, backups, and incident response plans.


  5. - significant because it demonstrated how cyberattacks on infrastructure can disrupt essential services, emphasizing the crucial need for robust cybersecurity protocols.


9
New cards

Sony Pictures

Attackers stole confidential data and used malware to disrupt Sony’s computer systems in a high-profile cyberattack in 2014. This breach exposed personal information, unreleased films, and internal communications, leading to financial losses and reputational damage for the company.

  1. Aspects of Security Violated: Confidentiality, integrity, and availability.

  2. Vulnerabilities: Weak credential protection and insufficient security defenses

  3. Threats: External hackers and state-sponsored actors (guardians of peace / north korea - Lazarus Group). Hackers using destructive malware. The attack is noted for its significant impact on corporate security practices and highlighted the importance of improving data protection measures in the entertainment industry.

  4. Mitigation: Use encryption, MFA, network segmentation, endpoint protection, backups, and monitoring. This compromise is one of the most damaging in history, causing significant operational and financial fallout for the company.


10
New cards

Linux Command Line

A text-based interface used to interact with the Linux operating system, allowing users to execute commands, manage files, and control system operations.

  • It provides users with powerful tools for automation and system administration, enhancing efficiency in managing system tasks.

  • The OG of how computers were operated before GUI

  • Stilll used by technical people, hackers, and linux users. The Linux Command Line is an essential interface for users to perform operations using commands, managing files and processes efficiently without a graphical user interface.

  • Allows you to run programs, do final manipulation, modify/view network traffic, and more


11
New cards

Linux File Structure

The hierarchical organization of files and directories in a Linux operating system, starting from the root directory (/) and branching into various subdirectories such as /home, /etc, /usr, and /var, each serving specific purposes in system management.

<p>The hierarchical organization of files and directories in a Linux operating system, starting from the root directory (/) and branching into various subdirectories such as /home, /etc, /usr, and /var, each serving specific purposes in system management. </p>
12
New cards

Ls command

A command used in the Linux command line to list the contents of a directory, providing information such as file names, sizes, and modification dates.

13
New cards

Ls -l command

A variant of the ls command that displays detailed information about the contents of a directory, including file permissions, owner, size, and last modified date. It provides a long listing format, making it easier for users to view and interpret file attributes.

14
New cards

File Command

A command used in Linux to determine the type of a file by analyzing its contents. The file command provides information such as whether a file is a text file, binary file, or executable.

15
New cards

PWD command

A command in Linux that prints the current working directory, displaying the full path of the directory you are currently in.

16
New cards

cd command

A command in Linux that allows users to change their current working directory to a specified directory. It is commonly used to navigate through the file system.

17
New cards

cat command

A command in Linux used to concatenate and display the contents of files. It can also create new files or append content to existing ones.

18
New cards

Man/Help command

A command in Linux that displays the manual or help documentation for other commands, providing usage instructions and options available for each command.

19
New cards

Ifconfig/Ipconfig command

A command in Linux and Windows used to configure and display network interface parameters. It provides information on IP addresses, subnet masks, and default gateways. It is essential for network troubleshooting and management, helping users diagnose connectivity issues and configure their network settings.

  • ip = windows, if=legacy system, unix, linux, macos


20
New cards

Chmod command

A command in Linux used to change the permissions of files and directories. It allows users to define who can read, write, or execute a file by setting different permission levels.

21
New cards

What does chmod 777 file mean

It means that the file has full permissions for all users: read, write, and execute. This setting allows anyone to modify or execute the file.

  • owner: read write and execute

  • group: read write execute

  • others: read write execute


22
New cards

Relative Path

The current directory you’re in, doesn’t start with the root directory.

  • ex. Documenets/Myfiles

  • is a path that relates to the current working directory. It can be used to locate files or directories relative to the current directory without specifying the full path.


23
New cards

Absolute Path

The whole path starting from the root directory

  • ex. /root/home/student

  • is used to specify the exact location of a file or directory in a filesystem, regardless of the current working directory. It begins with a leading slash, indicating the root of the filesystem.


24
New cards

Virtual Machines * STUDY

a software-based emulation of a physical computer. It operates as an independent computing environment, running its own operating system (OS) and applications. VMs are created using virtualization technology, which abstracts physical hardware resources like CPU, memory, and storage into virtualized components. These virtualized resources are managed by a hypervisor, a software layer that allows multiple VMs to run on a single physical machine.

25
New cards

Hypervisor

a software layer that allows multiple virtual machines to run of a single physical machine. It was what manages the virtualized resources like CPU, memory, and storage.

26
New cards

the layering between the hypervisor, guest OS, host OS, and hardware -FINISH ****

is known as virtualization architecture, which defines how virtual machines interact with the underlying hardware and each other through the hypervisor.


Type 1 (bare-metal, e.g., ESXi, Xen, Hyper-V):
Hardware → Hypervisor → Guest OS(es) → Apps

The hypervisor runs directly on the hardware, with no host OS in between. It allocates CPU, memory, and I/O to each virtual machine, and each guest OS thinks it has its own dedicated hardware.

Type 2 (hosted, e.g., VirtualBox, VMware Workstation):
Hardware → Host OS → Hypervisor → Guest OS(es) → Apps

The hypervisor is just an application running on a normal host OS (Windows, Linux, macOS). The host OS owns the hardware, and the hypervisor asks it for resources to hand to the guests. This adds an extra layer, so it's usually slower and less isolated than Type 1.

27
New cards

CIA Triad

is a model for information security that comprises three principles: confidentiality, integrity, and availability. It serves as a framework for organizations to safeguard their data and ensure its proper management.

28
New cards

Confidentiality

Protecting data from unauthorized access and disclosure. It ensures that sensitive information is only accessible to those who are authorized to view it.

29
New cards

Integrity

Ensuring data is not manipulated or changed in transit

30
New cards

Availability

refers to ensuring that data and resources are accessible to authorized users when needed. It involves maintaining system uptime and preventing interruptions.

31
New cards

Vulnerability

A flaw or weakness in a system, software, computer component

32
New cards

Threat

The person or thing acting against a system, software, or computer component. It can exploit vulnerabilities to cause harm or disrupt services, leading to potential breaches of confidentiality, integrity, or availability.

33
New cards

Risk

The existence of both a threat and a vulnerability

that could potentially lead to unauthorized access, data loss, or damage to systems.

  • Vulnerability & Threat = Risk

  • There is nothing if there is not both a threat and vulnerability present at the SAME time.


34
New cards

Controls

The things that we do as cybersecurity professionals to combat vulnerabilities and deter threats to overall reduce risk


35
New cards

RISK Equation

Risk = Vulnerability x Threat x Impact

  • represents the effect or "cost" of a mission-impacting event weighted by the probability that such an event will occur.


36
New cards

Countermeasures

Do one of the following: Protect, Detect, or React

  • 3 categories:

  • Physical: Hiring Security Guards

  • Logical/Technical: Encrypting Network Traffic

  • Administrative: All users must take phishing training.


37
New cards

Control Vs Countermeasure

Controls are proactive steps taken to mitigate risks, whereas countermeasures are specific actions implemented to address existing vulnerabilities or threats.

  • In security terminology, “controls” and “countermeasures” are closely related — in many frameworks (including OWASP) they are used interchangeably, but “control” is the broader category, while “countermeasure” refers to the specific safeguard or action that implements that control that helps in achieving the objectives of the control.

  • Controls encompass policies, procedures, and practices, whereas countermeasures are tactical responses.


38
New cards

APT’s - Advanced Persistent Threat

a sophisticated, sustained cyberattack in which an intruder establishes an undetected presence in a network in order to steal sensitive data over a prolonged period of time. An APT attack is carefully planned and designed to infiltrate a specific organization, evade existing security measures and fly under the radar.

Executing an APT attack requires a higher degree of customization and sophistication than a traditional attack. Adversaries are typically well-funded, experienced teams of cybercriminals that target high-value organizations. They’ve spent significant time and resources researching and identifying vulnerabilities within the organization.

39
New cards

Social Engineering Attacks

Manipulative tactics used to deceive individuals into divulging confidential information or performing actions that compromise security. Exploiting human psychology to manipulate targets.


40
New cards

Phishing

is a type of social engineering attack that involves sending fraudulent communications, often via email, appearing to come from a reputable source, to trick individuals into revealing personal information or installing malware. bait victims to take and action, which typically involves clicking a malicious link or opening an email attachment that harbors a malware payload.

41
New cards

Ransomware

is a type of malware that encrypts a victim's files, rendering them inaccessible until a ransom is paid to the attacker. Ransomware attacks often target businesses and individuals, demanding payment in cryptocurrency for the decryption key.

42
New cards

Identification

Associating an identity with a subject

  • claiming my name is John Doe


43
New cards

verification

confirming who you are

  • I own a driver’s license which proves I am john Doe


44
New cards

Authentication

Validating that you are who you say you are through a method of verification

  • I give my drivers license to the bouncer, who sees the picture, my name, and authenticates me. Involves use/review of credentials.


45
New cards

Authorization

Associating rights or capabilities with a subject

  • I am authenticated into the club, but only authorized to stay on the first floor.


46
New cards

Factors of Identification

Something you know (Password)

Something you have (key or card)

Something you are (fingerprint, face id)

MFA (multi factor authentication) = 2 OR MORE of these. 2FA is just 2.

47
New cards

Passwords

4 digit password = 4^10 different combinations. 1048576

10 digit password with lowercase alphabet and numbers = 10^(36) possibilities. 1E36. 1,000,000,000,000,000,000,000,000,000,000,000,000

48
New cards

Common attacks against identification methods

Dumpster diving, shoulder surfing

49
New cards

Dumpster Diving

Searching through trash for sensitive information.

50
New cards

Shoulder surfing

Observing someone to obtain their personal information, such as passwords or PINs. Literally looking over their shoulder.

51
New cards

Biometrics

Something you are

Generally considered the strongest form of authentication. Generally, relies on unique biological characteristics like fingerprints or facial recognition. Unique to everyone and hard to steal

52
New cards

FAR - False Acceptance Rate

The rate at which we accept an illegitimate user; false accepting the wrong person

BIOMETRICS

53
New cards

FRR - False Rejection Rate

The rate at which legitimate users are incorrectly rejected; false rejecting the right person.

BIOMETRICS

54
New cards

Authorization

The process of granting a user permission to access resources or perform actions based on their credentials or roles.

What you're allowed to do.

55
New cards

Access Control

What the system enforces you to do (policy based)

  • Literally what you have access to.



56
New cards

Defense In Depth

Implementing security controls on all layers (Policy, physical, network, computer, application, and device.

57
New cards

Principle of least privilege

only gives people the permissions they need to perform the task at hand.

58
New cards

Subjects

the thing/people who recieve access

59
New cards

Object

the thing which subjects are receiving access to

60
New cards

Discretionary Access Control

is a type of access control mechanism that allows resource owners to make decisions on who is allowed to access their resources. Owner decides access. The access control policy allows users to control permissions.

61
New cards

Mandatory Access Control

is a security strategy that restricts access to resources based on predefined policies. In this model, access rights are assigned by a central authority and cannot be changed by individual users. Label-based, most strict of all 5, common in government and military settings.

62
New cards

Access Control Matrix

A matrix containing permissions that are associated between subjects and objects in a system, outlining which subjects have which permissions on specific objects.

63
New cards

Privilege Separation

Ensuring two groups or users do not overlap in permissions and do not cause a conflict of interest.

one software-based technique for implementing the principle of least privilege. With privilege separation, a program is divided into parts which are limited to the specific privileges they require in order to perform a specific task.

64
New cards

Role-Based Access Control

is an access control method that assigns permissions based on user roles within an organization, allowing users to access only the resources necessary for their job functions. ie. department, location, seniority, work duties).

65
New cards

Rule based access control

is an access control approach that uses specific rules to determine access permissions for users based on attributes such as time of access, location, and other contextual factors. ie. can only access between 9 am to 5 pm

66
New cards

Attribute Based Access Control

is a security model that grants access permissions based on the attributes of the user, resource, and environmental conditions, allowing for more granular control over access rights. Based off certain attributes of users (role, task), the resource (critical, public), or the environment (night morning).

67
New cards

Identification

Review of credentials

Ex. Delivery Person shows employee badge

Process: User enters username

68
New cards

Authentication

Validate credentials as genuine

Ex. Gabe reads badge to determine it is real

process: user provides password

69
New cards

Authorization

Permission granted for admittance

Ex. Gabe opens door to allow delivery person in

Process: User allowed to login

70
New cards

Access

Right given to access specific resources

Ex, Delivery person can only retrieve box by the door

Process: User allowed to access only specific resources/data

71
New cards

Accounting

Record of user actions

Ex: Gabe signs to confirm package was picked up

Process: Info recorded in log file

72
New cards

Access Control List

Breaks down this matrix and represents a single object and what permissions the subjects have for that object.

  • Generated by decomposing the Access Control Matrix by columns.


73
New cards

Capabilities/Handles

Generated by decomposing the Access Control Matrix by rows.

Attachment: Associated directly with the subject requesting access.

What a subject can do for each object.

74
New cards

Read File Permission Bit Number

4

75
New cards

Write File Permission Bit Number

2

76
New cards

Execute File Permission Bit Number

1

77
New cards

Nothing File Permission Bit Number

0

78
New cards

X1X2X3 - X1

Owner - the first 3 bits represent the owner's permission settings (for when its in letter format. If its represented in numbers it is the first number)

79
New cards

X1X2X3 - X2

Group

  • the second 3 bits denote the group’s permission settings.

(for when its in letter format. If its represented in numbers it is the second number)

80
New cards

X1X2X3

Everyone else. The third 3 bits indicate permissions for other users. (for when its in letter format. If its represented in numbers it is the third number)

81
New cards

What does 777 Mean - in terms of file permissions

All 3 - owner, group, and everyone else - have full read, write, and execute permissions for the file. 4+2+1=7

82
New cards

What does 664 Mean

Owner has read and write rights

Group has read and write rights

Everyone else has read rights

83
New cards

Bell-Lapadula Security Model

Focused on confidentiality

  • No Read Up

  • No Write Down


84
New cards

Biba Security Model

Focused on Integrity

  • No read down

  • No write up


85
New cards

Accountability

What you did (tracing actions, logging, non-repudiation(suffiecent evidence exists such that the user can not deny an action), and deterrent (idea that someone is watching)

86
New cards

Auditing

Reviewing what was actually done (log review and monitoring, assessments, inventory, etc.)

87
New cards

Who is accountable when something goes wrong?

Everyone, but each person has a specific role to play.

88
New cards

Vulnerability Assessment

Scanning for vulnerabilities and weaknesses

89
New cards

Penetration Test

Actually, exploiting vulnerabilities found in the vulnerability assessment - discovers scope of issue, possible mitigation tactics, and potential weaknesses elsewhere.

90
New cards

RACI

Stands for:

Responsible

Accountable

Consulted

Informed

91
New cards

R in RACI

Responsible - the person assigned to do the work

92
New cards

A in RACI

Accountable - The person who has the authority to assign or delegate work, this is the person people go to for answers

93
New cards

C in RACI

Consulted - This person must be consulted before the work is started, needs to give their blessing.

94
New cards

I in RACI

Informed - This person needs to be kept updated on progress and outcomes but does not participate in the decision-making process. Just kept in the loop of whats happening.

95
New cards

Cybersecurity Audit

This will typically be a comprehensive analysis and review of all IT systems, processes, and will usually include a vulnerability assessment and/or penetration test. This is meant to ensure that companies are keeping up with standards of the industry.

  • Scope will typically include: Data security, operational security, system security, and physical security


96
New cards

Cryptology

The study of secret codes

  • The overarching umbrella that encompasses cryptography and cryptanalysis


97
New cards

Cryptanalysis

The process of deciphering or breaking codes and ciphers, aiming to uncover hidden information.

98
New cards

Cryptography

The practice and study of techniques for securing communication and information, typically involving the creation of codes and ciphers.

99
New cards

encryption

turning some text from legible (plaintext) to secret (ciphertext)

100
New cards

Asymmetric (AKA Public Key Crypto)

2 keys, a public that is shared between the sender and receiver, and a private which both the sender and receiver have their own unique key which is the only thing that can be used to decrypt the message.