1/30
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What is a birthday attack?
Exploits the probability of hash collisions — two different inputs producing the same hash — using the birthday paradox to find a match far faster than brute force.
What is a collision attack?
Finding two different inputs that produce the same hash value, letting an attacker substitute a malicious file for a legitimate one with a matching hash. Why MD5 and SHA-1 are deprecated.
What is a downgrade attack?
Forcing a connection to fall back to an older, weaker protocol or cipher the attacker can break — such as pushing TLS down to SSL. Mitigated by disabling legacy versions entirely.
What is SSL stripping?
An on-path attack that downgrades a victim's HTTPS connection to HTTP, exposing traffic in cleartext. Mitigated by HSTS (HTTP Strict Transport Security)
What is key stretching?
Applying a hashing function repeatedly (PBKDF2, bcrypt, scrypt, Argon2) to make each password guess computationally expensive, slowing brute-force attacks.
What is salting, and what does it prevent?
Adding unique random data to each password before hashing, so identical passwords produce different hashes. Defeats rainbow tables and precomputed hash lookups.
What is a brute-force attack?
Systematically trying every possible character combination until the correct password is found. Guaranteed to work eventually, but slow — countered by length, lockouts, and rate limiting.
What is a dictionary attack?
Trying passwords from a list of common words, leaked passwords, and predictable variations. Much faster than brute force because it targets likely candidates.
What is password spraying?
Trying one or a few common passwords against many accounts, avoiding lockout thresholds that would trigger from repeated attempts on a single account.
What is credential stuffing?
Using username/password pairs leaked from one breach against other services, exploiting password reuse. Defeated by unique passwords and MFA.
What is a rainbow table attack?
Using precomputed tables of hash-to-plaintext mappings to reverse password hashes quickly. Salting makes it ineffective.
What is the difference between an online and offline password attack?
Online attacks guess against a live system and are limited by lockouts and rate limiting. Offline attacks crack a stolen hash file locally with no such limits, so speed depends only on hardware.
What is a pass-the-hash attack?
Authenticating with a captured password hash directly, without ever cracking it to plaintext. Enables lateral movement in Windows environments.
What is a denial-of-service (DoS) attack?
Overwhelming a system's resources or exploiting a flaw to make a service unavailable to legitimate users.
What is a distributed denial-of-service (DDoS) attack?
A DoS launched from many compromised hosts at once, usually a botnet, making it far harder to block by source.
What is an amplification/reflection attack?
Sending small spoofed requests to third-party servers (DNS, NTP, memcached) that send much larger responses to the victim, multiplying attack volume and hiding the source.
What is DNS poisoning / cache poisoning?
Injecting false records into a DNS resolver's cache so users are silently redirected to attacker-controlled sites. Mitigated by DNSSEC.
What is domain hijacking?
An attacker gains control of a domain registration itself — through registrar account compromise or social engineering — and redirects all traffic for that domain.
What is a DNS tunneling attack?
Encoding data inside DNS queries and responses to exfiltrate data or maintain C2 through a port that's almost never blocked.
What is typosquatting / URL hijacking?
Registering domains that are near-misses of legitimate ones to catch mistyped traffic for phishing or malware delivery.
What is an on-path (man-in-the-middle) attack?
The attacker positions between two parties to intercept, read, or alter traffic while both sides believe they're communicating directly.
What is ARP (Address Resolution Protocol) poisoning?
Sending forged ARP replies on a LAN so traffic for another device is sent to the attacker's MAC address instead. A common way to establish an on-path position.
What is MAC flooding?
Overwhelming a switch's MAC address table so it fails open and floods traffic to all ports, letting the attacker sniff it. Mitigated by port security.
What is MAC cloning / spoofing?
Changing a device's MAC address to impersonate an authorized device, bypassing MAC filtering and port-based restrictions.
What is a replay attack?
Capturing valid traffic — like an authentication token or session cookie — and retransmitting it to gain access. Countered by timestamps, nonces, and sequence numbers.
What is session hijacking?
Taking over an authenticated session by stealing or predicting the session token, letting the attacker act as the logged-in user without credentials.
What is a rogue access point, and what is an evil twin?
A rogue AP is any unauthorized wireless AP on the network. An evil twin specifically impersonates a legitimate SSID to trick users into connecting through the attacker.
What is a wireless disassociation/deauthentication attack?
Sending forged management frames to forcibly disconnect clients from an AP, often to force reconnection to an evil twin or capture a handshake. Mitigated by protected management frames.
What is RF jamming?
Flooding a wireless frequency with interference to disrupt legitimate communication — a wireless denial-of-service attack.
What is a malicious Bluetooth attack — bluejacking vs. bluesnarfing?
Bluejacking sends unsolicited messages to a nearby Bluetooth device — mostly a nuisance.
Bluesnarfing steals data from the device.
Bluebugging goes further and takes control of the device.
What is a credentialed indicator of a password attack?
A spike in failed logins, lockouts across many accounts, logins at unusual hours, or impossible-travel logins — all signs of spraying, stuffing, or brute force.