1/43
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
CIA Triad
Confidentiality, Integrity, and availability
Least Privelage
Minimum access needed is given to perform a task
Non-Repudiation
Provides proof that an action or message came from a specific person or system. Ex. Digital systems
CSIRT/CERT/CIRT
Team that responds to security incidents
AJr Gapping
Isolating a system from other networks
Managerial Control
Oversees all security operations in a system
Operational Control
Security operations programmed by humans
Technical Control
Security measures implemented by hardware and software.
Physical Control
Physical controls like security cameras that protect equipment.
Preventive Control
Stops an attack before it takes place.
Detective Control
Detects attack as it happens or has happened
Corrective
Fixes damage after an attack
Compensating
Alternative control when another can’t be implemented.
Physical control TYPE
Involves a physical barrier or device
Deterrent
Discouraging someone from attempting an attack before it happens
Attack Surface
Any vulnerabilities that can be exploited
Direct Access
Physical access to a device/system Ex. USB
Wired Network
Attack path via Ethernet or wired network connections
wireless network
attack path via Wi-fi or remote network
Cloud
Internet - accessible cloud services, storage, accounts, and APIs that can be targeted
Bluetooth
Short-range wireless connection that can be attacked if poorly secured
Default Credentials
Factory-set usernames or passwords attackers may already know
Open ports
Network ports accepting connections, unnecessary open ports increase exposure
Script Kiddie
Inexperienced attacker using tools and scripts created by others without knowing how they work
Hacktivist
Attacker motivated mainly by a political, social, or economic cause
Organized crime
Criminal group using cyberattacks mainly for financial gain
Nation-state
Government-backed/aligned attacker with substantial resources, skill, and long-term goals like espionage or disruption
insider
Employee, contractor, or trusted person who already has some level of authorized access. Threat may be malicious or accidental.
Phishing
Fraudulent message designed to gain personal info from the victim
Vishing
Voice phishing, like scam calls
Smishing
Phishing via SMS/text message
Social Engineering
Manipulating people into revealing info or do things that weaken security
Dumpster Diving
Searching discarded documents for useful info
Impersonation
Pretending to be someone else, like an employee, technician, manager, or vendor
Piggybacking
Entering a restricted area with an authorized person’s knowledge
tailgating
following authorized person into restricted area without proper authorization
Watering Hole Attack
compromising a website that a target group frequently visits, then using the site to attack visitors
Typosquatting
Registering misspelled or look-alike domain name to trick users into visiting a malicious site
Logic Bomb
Malicious code that activates when a specific condition, date, time, or event occurs
Worm
Self-replicating malware that can spread across networks without normal user action
Trojan
Malware disguised as legitimate or useful software.
Stuxnet
Highly sophisticated malware that targeted industrial court systems and commonly used as cyberwarfare and sabotage
Rootkit
Malware designed to obtain high level access and hide itself or other dangerous activity from system
Botnet
Group of compromised devices controlled by a attacker; used for DDoS attacks, spam, malware distribution, or other tasks.