1/49
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Define data breaches, service disruptions, and compliance risks.
• Data Breaches: Unauthorized access, acquisition, or disclosure of sensitive, protected, or confidential data.\n• Service Disruptions: Events or attacks (like DDoS) that cause systems, networks, or applications to become unavailable to authorized users, hindering operations.\n• Compliance Risks: The risk of legal penalties, financial forfeiture, or material loss an organization faces when it fails to act in accordance with industry laws, regulations, or prescribed internal controls.
Identify some examples of threat agents.
Threat agents (or actors) include: Cybercriminals, hacktivists, state-sponsored actors, malicious insiders (employees/contractors), accidental insiders (human error), and automated bots.
Describe the concept of network-based attacks.
Network-based attacks target the network infrastructure, communication protocols, or data in transit between devices, looking to exploit vulnerabilities in network services or configurations rather than individual system files.
Identify some examples of methods and mechanisms related to network-based attacks.
• Denial of Service (DoS / DDoS)\n• Man-in-the-Middle (MitM) attacks\n• Packet sniffing / Eavesdropping\n• IP Address Spoofing\n• Port scanning
Identify some examples of methods and mechanisms related to application-based attacks.
• SQL Injection (SQLi)\n• Cross-Site Scripting (XSS)\n• Buffer overflow\n• Remote Code Execution (RCE)\n• Brute-force / Credential stuffing
Define host-based attacks and identify some examples of host-based attacks.
• Definition: Attacks directed against a single, specific computer host or endpoint rather than the network layout itself.\n• Examples: Malware installations (viruses, worms, trojans), ransomware encrypting local drives, spyware/keyloggers, and local privilege escalation.
Identify some examples of social engineering attacks.
• Phishing (Email)\n• Spear phishing (Targeted email)\n• Smishing (SMS) / Vishing (Voice)\n• Baiting / Tailgating\n• Pretexting
Identify some examples of physical (on-premises) attacks.
• Tailgating / Piggybacking through secure doors\n• Dumpster diving for paper documentation\n• Hardware theft (laptops, servers, flash drives)\n• Planting unauthorized physical keyloggers or rogue USB devices
Identify some examples of supply chain attacks.
• Compromising third-party vendor software updates (e.g., SolarWinds)\n• Inserting malicious code into open-source software libraries\n• Tampering with hardware components during manufacturing or transit
Identify the stages of a cyberattack.
Reconnaissance (Gathering intelligence)\n2. Weaponization & Delivery (Creating and sending the exploit)\n3. Exploitation & Installation (Executing code and planting malware)\n4. Command & Control (C2 - Establishing remote access)\n5. Actions on Objectives (Exfiltrating data or disrupting systems)
Identify specific risks to cloud computing.
• Data loss / Leakage due to weak access controls\n• Insecure Application Programming Interfaces (APIs)\n• Misconfigured cloud storage buckets\n• Shared technology vulnerabilities (hypervisor escapes)\n• Lack of visibility / Limited control over infrastructure
Identify specific risks to mobile technologies.
• Unsecured public Wi-Fi connections\n• Lost or stolen physical devices lacking remote wipe features\n• Malicious mobile apps (sideloading)\n• Outdated mobile operating systems bypassing patch management
Identify specific risks to the Internet of Things (IoT).
• Weak, hardcoded, or default passwords\n• Inability to easily patch or update firmware\n• Device spoofing and unauthorized network entry\n• Lack of built-in encryption for data in transit
Identify the phases typically involved in threat modeling.
Identify Objectives (What needs protection)\n2. Deconstruct the System (Mapping architecture, data flows, and trust boundaries)\n3. Identify Threats (Locating potential entry points and vulnerabilities)\n4. Identify Vulnerabilities (Evaluating weaknesses)\n5. Mitigate and Respond (Implementing countermeasures)
Identify three commonly used methodologies for threat models.
STRIDE (Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege)\n2. PASTA (Process for Attack Simulation and Threat Analysis)\n3. DREAD (Damage, Reproducibility, Exploitability, Affected users, Discoverability)
Depending on an entity's size and business model, different structures may be better suited for adoption. What models are reommended by NIST
Identify the factors that organizations should consider when selecting the appropriate structure and staffing models for incident response teams under NIST computer secuirty incident handling guide.
Define event, cybersecurity event, adverse event, incident, computer security incident, and cyber security incident in a cybersecurity context.
Identify some common methods of testing when organizations periodically test whether IRP plans respond as expected to both hypothetical and actual cybersecuirty threats.
Identify some of the most common losses related to a cyberattack that are typically covered by cyber insurance.