CYB-110 (Introduction to Cybersecurity) Midterm

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/95

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 12:44 AM on 6/27/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai

No analytics yet

Send a link to your students to track their progress

96 Terms

1
New cards

InfoSec Primary Mission

To ensure that information assets, and the systems that house them, remain safe and useful.

2
New cards

Protecting function, protecting data, enabling safe app operations, and safeguarding technology assets

4 InfoSec Functions

3
New cards

The Business Wins Rule

When security needs and business needs collide, business needs win out.

4
New cards

Three Communities of Interest

General management, IT management, and InfoSec management.

5
New cards

Data Protection States

Data in transit, data in processing, and data at rest.

6
New cards

Planning, Policy, Programs, Protection, People, and Project management.

The Six Ps of InfoSec

7
New cards

Primary IT Focus

To ensure the effective and efficient processing of information.

8
New cards

Primary InfoSec Focus

To ensure the confidentiality, integrity, and availability (CIA) of information.

9
New cards

GRC Approach

Governance, Risk Management, and Compliance.

10
New cards

McCumber Cube

A 3D security model mapping 27 cells across Information States, Security Measures, and the CIA Triad.

11
New cards

SecSDLC

A systems development process that maps security considerations directly across all execution phases.

12
New cards

Confidentiality

The security characteristic achieved when unauthorized individuals or systems are prevented from viewing information.

13
New cards

Availability

Enables authorized users to access information without interference or obstruction and receive it in the required format.

14
New cards

Possession

The quality or state of having ownership or physical control of an asset.

15
New cards

Utility

The quality or state of an asset having value for a specific purpose or end.

16
New cards

Authenticity

The quality or state of being genuine or original, rather than a reproduction or fabrication.

17
New cards

Data Owners

Senior managers responsible for the classification, security, and final business utility of information assets.

18
New cards

Data Custodians

Individuals assigned the task of managing a specific data set and coordinating its storage, protection, and backups.

19
New cards

Data Users

Personnel who interact with information systems to perform daily job duties and support the mission.

20
New cards

Blackout

A long-term interruption or complete outage in electrical power availability.

21
New cards

Brownout

A prolonged drop in electrical voltage levels.

22
New cards

Sag

A short-term drop in voltage.

23
New cards

Fault

A momentary power interruption that typically clears itself automatically.

24
New cards

Exploit

A technique used to compromise a system or vulnerability.

25
New cards

Trap Door / Backdoor

A component installed in a system by a virus or worm that allows an attacker to bypass authentication at will.

26
New cards

Zombies

Compromised systems directed remotely by an attacker to participate in secondary attacks like DDoS.

27
New cards

Man-in-the-Middle

An attack where an adversary monitors, sniffs, modifies, and inserts rogue packets back into a network stream.

28
New cards

Hacktivist Operations

Online vandalism or disruptions designed to protest the operations, policies, or actions of an organization or government.

29
New cards

MTBF

Mean time between failures; total operation time divided by the total number of hardware failures.

30
New cards

Software Piracy

The unauthorized duplication, installation, or distribution of copyrighted software.

31
New cards

Buffer Overflow

An application anomaly where a program overwrites adjacent memory blocks, potentially leading to executable control.

32
New cards

Cross-Site Scripting

An application-layer attack where malicious scripts are injected into otherwise benign and trusted websites.

33
New cards

Trojan Horse

A malware program that hides its true intent and reveals its destructive behavior only after execution.

34
New cards

Polymorphic Threat

A threat or malware variant that changes its physical shape or characteristics over time to evade detection.

35
New cards

Spam

Unsolicited commercial email that can clog user inboxes and serve as a delivery mechanism for malicious payloads.

36
New cards

Phishing

An attacker's attempt to obtain personal or financial information using fraudulent, spoofed communication.

37
New cards

Enterprise Information Security Policy

The high-level policy that sets the strategic direction, scope, and tone for all organizational security efforts.

38
New cards

Issue-Specific Security Policy

A policy designed to regulate a specific technical area requiring detailed management guidance, such as email or internet use.

39
New cards

Systems-Specific Security Policy

Technical policies that often function as standards or procedures used when configuring or maintaining specific systems.

40
New cards

Operational Controls

Security controls addressing personnel security, physical security, and the protection of production inputs and outputs.

41
New cards

Policy Administrator

The designated individual responsible for the creation, regular review, modification, and maintenance of an organizational policy.

42
New cards

Policies

Managerial statements that mandate or dictate certain behavior within an organization.

43
New cards

Capability Table

A user-centric security specification matrix tracking what functions a specific user can perform across diverse assets.

44
New cards

Access Control List

An asset-centric list that tracks which specific users or processes have permission to access a resource.

45
New cards

ISO/IEC 27002

An international standard providing recommendations for effective information security management.

46
New cards

Knowing Yourself (Sun Tzu)

Identifying, examining, and understanding information assets, systems, and vulnerabilities.

47
New cards

Knowing the Enemy (Sun Tzu)

Identifying, examining, and understanding threats facing the organization's information assets.

48
New cards

Risk Management Definition

The process of identifying risk, assessing its relative magnitude, and taking steps to reduce it to an acceptable level.

49
New cards

Risk Identification

The recognition, enumeration, and documentation of risks to an organization's information assets.

50
New cards

Risk Assessment

The combined phase of identification, analysis, and evaluation of risk.

51
New cards

Risk Treatment (Risk Control)

The application of safeguards or controls that reduce risks to an acceptable level.

52
New cards

Risk Framework

The overall structure of the strategic planning and design for the entirety of an organization's risk management efforts.

53
New cards

Acceptance Strategy

The choice to do nothing to protect a vulnerability and to accept the operational outcome of its exploit.

54
New cards

Threat Assessment

An evaluation of threats to assets that determines their likelihood of occurrence and potential business impact.

55
New cards

Annualized Rate of Occurrence (ARO)

How often you expect a specific type of attack to occur within a year.

56
New cards

Exposure Factor

The expected percentage of loss that would occur to an asset from a single successful attack.

57
New cards

TVA Worksheet

A document showing a comparative ranking of prioritized assets against prioritized threats to map key vulnerabilities.

58
New cards

Cost-Benefit Analysis

The formal process evaluating whether the economic savings of a safeguard exceed its acquisition and operational costs.

59
New cards

Single Loss Expectancy (SLE)

The calculated monetary loss expected from a single occurrence of a specific risk; Asset Value multiplied by Exposure Factor.

60
New cards

Annualized Loss Expectancy (ALE)

The calculated total monetary loss expected from a risk over a one-year timeframe; SLE multiplied by ARO.

61
New cards

Contingency Planning (CP)

Overall planning for unexpected adverse events to prepare for, detect, react to, and recover from threats.

62
New cards

Business Impact Analysis (BIA), Incident Response (IR) plan, Disaster Recovery (DR) plan, and Business Continuity (BC) plan.

Four Components of CP

63
New cards

BIA vs Loss Analysis

BIA is broader, containing organizational impacts and systemic relationships, not just potential asset losses.

64
New cards

Alert Message

A scripted description of an incident providing just enough info for individuals to know what portion of the IRP to implement.

65
New cards

Hot Site

A fully configured computer facility capable of establishing operational capabilities at a moment's notice.

66
New cards

Cold Site

A resumption location providing physical space and utilities but no pre-installed computer hardware.

67
New cards

Warm Site

A backup facility that features physical space, infrastructure, and cooling plus some partially configured hardware but lacks final data backups.

68
New cards

Business Continuity Plan

A strategic framework ensuring that critical business functions continue if a catastrophic incident or disaster occurs.

69
New cards

Continuity Planning Management Team (CPMT)

The group of senior managers organized to lead all contingency planning efforts.

70
New cards

Digital Malfeasance

A crime involving digital media, computer technology, or related technology components.

71
New cards

Crisis Management

An organization's set of planning efforts for dealing with potential human injury, emotional trauma, or loss of life during a disaster.

72
New cards

Chain of Evidence

Detailed documentation of the collection, storage, transfer, and ownership of evidentiary material from a crime scene through court.

73
New cards

Full Backup

A comprehensive duplication of every piece of data stored within a target system.

74
New cards

Differential Backup

An archival strategy that captures only data modified since the conclusion of the most recent full backup.

75
New cards

Incremental Backup

An archival strategy that captures only data modified since the conclusion of the most recent backup of any kind.

76
New cards

Incident Damage Assessment

The process of assessing the immediate state of systems and data to determine the physical and technical impact of an incident.

77
New cards

IR vs DR Focus

Incident Response focuses on immediate detection and tactical containment, whereas Disaster Recovery focuses on full technical reestablishment.

78
New cards

Laws

Rules that mandate or prohibit certain behavior, backed by the coercive power and enforcement of a governing state authority.

79
New cards

Ethics

The collective principles of acceptable, socially tolerated conduct based on organizational or societal norms without state enforcement.

80
New cards

Cultural Mores

Fixed moral attitudes or customs of a particular group.

81
New cards

Liability

The legal obligation of an entity extending beyond criminal or contract law, including restitution.

82
New cards

Restitution

The legal obligation to compensate an injured party for wrongs committed.

83
New cards

Jurisdiction

A court's right to hear a case if the wrong was committed in its territory or involved its citizenry.

84
New cards

Long-arm Jurisdiction

The application of laws to those residing outside a court's normal jurisdiction.

85
New cards

Due Care

The legal standard requiring an organization to act responsibly, execute required safeguards, and understand consequences.

86
New cards

Due Diligence

The continuous monitoring and verification that an organization is actively maintaining its required security posture.

87
New cards

ISACA

A professional association focused on IT auditing, control, and security containing both technical and managerial professionals.

88
New cards

The Health Insurance Portability and Accountability Act of 1996 (HIPAA)

Act that protects the confidentiality and security of healthcare data.

89
New cards

Payment Card Industry Data Security Standard (PCI-DSS)

Technical and operational rules designed to enhance the security of payment account data.

90
New cards

InfraGard

An FBI-established program matching field offices with public, private, and academic entities to collaborate on asset protection.

91
New cards

Ethical Education

The overriding factor shown by studies to level and improve ethical perceptions within a small population.

92
New cards

Computer Fraud and Abuse Act

The foundational 1984 US cybersecurity law modified by the National Information Infrastructure Protection Act of 1996.

93
New cards

Information Aggregation

The process of combining pieces of nonprivate data that together create a dataset violating privacy boundaries.

94
New cards

Privacy Act of 1974

A federal law regulating how government agencies collect, maintain, use, and disseminate individual records.

95
New cards

The Gramm-Leach-Bliley Act of 1999 (GLBA)

Controls the privacy and technical security of consumer financial data.

96
New cards

USA PATRIOT Act

A law providing law enforcement with broader latitude in intercepting communications during threat investigations.