Cyber Operations Exam 1

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/127

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 12:35 AM on 10/2/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

128 Terms

1
New cards

What are the three Security Principles?

Confidentiality, Integrity, and Availability.

2
New cards

Confidentiality

The security principle that ensures information is only disclosed or made available to authorized users.

3
New cards

Integrity

The security principle that ensures information is only modified in an authorized manner.

4
New cards

Availability

The security principle that ensures information is accessible by authorized users whenever required.

5
New cards

Vulnerability

A weakness or flaw in a system's design, implementation, operation, or management.

6
New cards

Threat

Any event that can negatively impact a system through unauthorized access, destruction, disclosure or modification of data, or denial of service. In order for a threat to get through, a vulnerability must be exploited.

7
New cards

Threat Actor

A person or group who exploits a vulnerability.

8
New cards

Data Breach

The exposure of data to an unauthorized user.

9
New cards

Data Loss

The loss of access to data.

10
New cards

Data Exfiltration

The unauthorized transfer of data.

11
New cards

Script Kiddie

An unskilled individual who uses malicious scripts developed by security hackers to exploit vulnerabilities.

12
New cards

State Actor

A person or group who is acting on behalf of a government.

13
New cards

Hacktivist

An activist who uses computer-based techniques to promote the activist's agenda. They often operate as part of a larger group or collective.

14
New cards

Cyber Syndicate

A criminal syndicate which uses the Internet to engage in criminal conduct, like fraud, extortion, ransom, and identity theft.

15
New cards

Competitor

A rival organization whose activities have the potential to reduce another organization's share of the market, usually by performing espionage, harming reputation, or deny customer access.

16
New cards

Threat Vector

A path or means by which an attack is realized.

17
New cards

What are examples of Threat Vectors?

Direct Access, Wireless, Vulnerable Software, Unsupported Systems and Applications, Messaging, Image, Supply Chain, Social Media, Removable Media, and the Cloud.

18
New cards

Attack Surface

The sum of the points on a system's boundary where a threat actor can attempt to enter, cause an effect on, or extract data from. It consists of the system's vulnerabilities.

19
New cards

What are examples of Attack Surface?

Unencrypted wireless data, lack of user training, open ports, default passwords, and unpatched operating systems.

20
New cards

Automated Indicator Sharing (AIS)

A capability that enables the real-time exchange of threat intelligence.

21
New cards

Structured Threat Information Expression (STIX)

A standardized markup languages for expressing threat intelligence.

22
New cards

Trusted Automated Exchange of Intelligence Information (TAXII)

An application protocol for sharing threat intelligence.

23
New cards

Threat Intelligence Source

Public or private information resource on security threats, attacks, and attackers.

24
New cards

Open-Source Intelligence

Intelligence data derived from publicly available information on an individual or organization.

25
New cards

Predictive Analysis

Using gathered intelligence from threat intelligence sources to determine the likelihood of future security events.

26
New cards

Vulnerability Database

A database for storing, maintaining, and disseminating information, via feeds, about security vulnerabilities in a system or software.

27
New cards

Social Engineering

The manipulation of people into revealing information or performing actions that may compromise a system's security.

28
New cards

Influence Principle

A concept that takes advantage of human nature to manipulate a target.

29
New cards

What are examples of Influence Principles?

Authority, Familiarity, Intimidation, Trust, Consensus, Scarcity, and Urgency.

30
New cards

Watering Hole Attack

An attack method that infects web sites that a group is likely to trust and visit.

31
New cards

Typosquatting

A form of cybersquatting that relies on mistakes, such as typographical errors, made by Internet users when inputting information into a Web browser.

32
New cards

Pharming

A phishing attack that automatically redirects the user to a fake site using altered DNS entries.

33
New cards

Phishing

A social-based attack in which the attacker "fishes" for confidential info by sending a fraudulent message to a target. Vishing is via phone, and Smishing is over text.

34
New cards

Spear Phishing

A phishing attack that targets only specific users.

35
New cards

Whaling

A phishing attack that targets only wealthy individuals.

36
New cards

Malware

Malicious software developed to compromise the confidentiality, integrity, or availability of data.

37
New cards

What are the classifications of Malware?

Spread, Block, Spy, Mislead, and Hide.

38
New cards

Virus

A type of malware that spreads; it self-replicates and moves throughout a system, taking up resources and attempting to find data.

39
New cards

Fileless Virus

a virus that exists in memory only, making the virus impossible to detect by scanning for infected files.

40
New cards

Worm

A destructive computer program that bores its way through a computer's files or through a computer's network.

41
New cards

Bot

A device infected with malware than enables an attacker to remotely control (some) functions of a device.

42
New cards

Cryptomalware

Malware to remain in place for as long as possible, quietly mining cryptocurrency in the background.

43
New cards

Ransomware

Software that encrypts programs and data until a ransom is paid to remove it.

44
New cards

Spyware

A type of malware that locates and saves data from users without them knowing about it.

45
New cards

Bloatware

A program that uses an excessive amount of disk space, consumes resources, and may include spyware.

46
New cards

Keylogger

A type of malware that records keystrokes to gain personal information like credit card numbers or passwords.

47
New cards

Trojan

A type of malware disguised as legitimate software, such as a game or application, that steals information or causes unwanted damage.

48
New cards

Remote Access Trojan (RAT)

A Trojan that also gives the threat agent unauthorized remote access to the victim's computer by using specially configured communication protocols.

49
New cards

Potentially Unwanted Program (PUP)

A PUP is a software inadvertently installed that contains adware, installs toolbars, or has other objectives. Does not necessarily cause damage.

50
New cards

Backdoor

A type of malware that enables unauthenticated access to a device, allowing an attacker to bypass regular authentication procedures.

51
New cards

Logic Bomb

A type of malware that activates an attack when specific conditions are met.

52
New cards

Rootkit

A type of malware that provides administrative, or root access to a computing device without permission or detection.

53
New cards

Security Control

A mechanism used to protect the confidentiality, integrity, and availability of an organization's systems and data.

54
New cards

Technical Control

A control that is performed by the system.

55
New cards

Managerial Control

A control that addresses risk management and governance through established procedures.

56
New cards

Operational Control

A control that is performed by employees.

57
New cards

Physical Control

A control that secures the physical environment.

58
New cards

Preventive Control

A control that prevents a security issue.

59
New cards

Deterrent Control

A control that deters an individual from violating security policies.

60
New cards

Directive Control

A control that gives direction.

61
New cards

Detective Control

A control that detects a security issue.

62
New cards

Corrective Control

A control that restores normal operations after a security issue occurs.

63
New cards

Identity and Access Management (IAM)

A framework of technologies and policies for managing user identities in a system and controlling user access to the system's resource.

64
New cards

Identity Proofing

The process of verifying a user's identity during account creation.

65
New cards

Attribute

A specific characteristic of an identity.

66
New cards

Authentication

The act of verifying or proving a user's claim to an identity.

67
New cards

Authentication Factors

The different types of evidence a user can provide to prove the user's claim to an identity.

68
New cards

Access Control Model

A set of technology-independent rules for controlling access to an object by a subject.

69
New cards

What are examples of Authentication Factors?

Knowledge Factor: Something you know.

Possession Factor: Something you have.

Inherence Factor: Something you are.

Location Factor: Somewhere you are.

Behavior Factor: Something you can do.

70
New cards

Two-Factor Authentication

An authentication method requiring two different authentication factors.

71
New cards

Knowledge-Based Authentication

An authentication method requiring knowledge of a user's personal information.

72
New cards

Time-Based One-Time Password

A one-time password that changes periodically, using an increment of time called a timestep.

73
New cards

HMAC-Based One-Time Password (HOTP)

A one-time password that changes when a specific event occurs.

74
New cards

Software Token

An application that generates an OTP.

75
New cards

Security Token

A physical device that an authorized computer services user is given to ease authentication.

76
New cards

Trusted Platform Module (TPM)

A secure processor that performs cryptographic operations.

77
New cards

Full Disk Encryption

System that encrypts all data saved to a hard disk automatically and transparently.

78
New cards

Password Authentication Protocol (PAP)

An authentication protocol used for authenticating a client to a server over a point-to-point connection. It is down only once per session at the time of the initial connection establishment.

79
New cards

Challenge Handshake Authentication Protocol (CHAP)

An authentication protocol that uses a shared secret to authenticate a client to a server, periodically re-authenticating the client with challenges.

80
New cards

Kerberos

An authentication protocol that uses a ticket-based mechanism to authenticate a user and enable a user to access a network service. It uses port 88 by default.

81
New cards

What are the components of a Kerberos setup?

Key Distribution Center: A trusted third party that authenticates a user and enables a user to access a service hosted on a server.

Authentication Server: Authenticates a user.

Ticket-Granting Server: Issues a ticket to a user that enables a user to access a service.

82
New cards

Extensible Authentication Protocol (EAP)

An authentication framework for transporting different types of authentication protocols. Messages include:

EAP Request

EAP Response

EAP Success

EAP Failure

83
New cards

EAP-TLS

A form of EAP that uses transport-layer security and certificates for mutual authentication.

84
New cards

EAP-FAST

A form of EAP that uses a protected access credential to establish a transport-layer tunnel between a server and client.

85
New cards

PEAP

A form of EAP that encapsulates EAO messages within an encrypted and authenticated transport-layer tunnel. Does not require a client certificate.

86
New cards

IEEE 802.1X

A standard used for port-based access control that is used for passing EAP messages over a wired network.

87
New cards

What the the components of an IEEE 802.1X setup?

Supplicant: A user or device that wants to authenticate to a network.

Authentication Server: A server that authenticates a supplicant and makes an access control decision.

Authenticator: A device that acts as a proxy for a supplicant and controls a supplicant's communication with an authentication server.

88
New cards

Remote Authentication Dial-In User Service (RADIUS)

A protocol where a RADIUS server provides authentication and authorization services and a RADIUS client is a Network Access Server that acts as an intermediary for a connection request from a user to the RADIUS server.

89
New cards

Terminal Access Controller Access-Control System Plus (TACACS+)

A TACACS+ client is a Network Access Server. A TACACS+ server holds authentication information about users, and the NAS forwards information from the user to be checked against the server.

90
New cards

Security Assertions Markup Language (SAML)

An XML-based data format used to exchange authentication information between a client and a service. There are three roles defined in SAML.

91
New cards

What are the three roles in SAML?

Principal: A human user.

Identity Provider: An entity that creates, manages, and maintains identity information for a principal.

Service Provider: An entity that provides a service to a principal.

92
New cards

SAML Assertion Statements

Authentication Statement: Asserts a principal authenticated at a specific time using a specific authentication method.

Attribute Statement: Asserts that a principal is associated with a specific attribute.

Authorization Statement: Asserts that a principal is permitted to perform a specific action on a specific resource.

93
New cards

Account Types

User Account: Assigned to an individual that wants to access a computer resource.

Privileged Account: Assigned to a system administrator with full authorization and control.

Shared Account: An account accessed by more than one user.

Guest Account: Assigned to a temporary user.

Service Account: Assigned to an application or service.

94
New cards

Discretionary Access Control (DAC)

An access control model in which access to an object is at the discretion of the object's owner.

95
New cards

Mandatory Access Control (MAC)

An access control model in which access to an object is mandated by a set of rules and classification labels.

96
New cards

Role-Based Access Control (RBAC)

An access control model in which a subject's access rights to an object are based on the subject's role within a system.

97
New cards

Attribute-Based Access Control (ABAC)

An access control model in which access to an object is based on attributes and access control policies that define the allowable operations for a given attribute combination.

98
New cards

Rule-Based Access Control

An access control model that based on a list of predefined rules that determine what accesses should be granted.

99
New cards

Encryption

Encryption uses an algorithm and a key to hide the meaning of a message. Asymmetric encryption involves two different keys for encryption and decryption. Symmetric encryption uses the same key, and can be either done with a stream or block cipher.

100
New cards

Cryptographic Hash Function

Outputs a fixed-length string for a variable-length input string.