2.2 — Threat Vectors & Social Engineering

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/46

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 5:38 PM on 9/8/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

47 Terms

1
New cards

Threat Vector

The method or path an attacker uses to reach or compromise a target.

2
New cards

Messaging Threat Vector

Using email, SMS, instant messaging, or similar communication to deliver malicious content or social engineering.

3
New cards

Malicious File

A file designed to execute malicious code, exploit a vulnerability, or deceive a user.

4
New cards

Executable File Risk

An executable can directly run malicious code when opened.

5
New cards

PDF Attack Vector

PDF files can contain scripts or objects that may be used maliciously.

6
New cards

Archive File Risk

ZIP and RAR files can conceal or package malicious content.

7
New cards

Office Document Attack Vector

Office documents may contain malicious macros or other active content.

8
New cards

SVG

Scalable Vector Graphics, an XML-based image format that can contain HTML or JavaScript and may be used maliciously.

9
New cards

Browser Extension Risk

A malicious browser extension can add unwanted or harmful capabilities to a browser.

10
New cards

Drive-by Download

Malware downloaded from a malicious or compromised website without the user intentionally downloading the malware.

11
New cards

Voice Threat Vector

Using telephone or voice communication as part of an attack or social engineering attempt.

12
New cards

Removable Media

Portable storage such as USB devices that can introduce malware or remove sensitive information.

13
New cards

Malicious USB Device

A modified USB device may impersonate another device such as a keyboard and automatically enter commands.

14
New cards

Air Gap

Physical or logical separation that prevents direct network communication between systems or networks.

15
New cards

Removable Media and Air Gaps

USB devices can transfer malware or information into or out of systems that do not have direct network connectivity.

16
New cards

Vulnerable Software

Software containing weaknesses that attackers may exploit.

17
New cards

Unsupported Software

Software for which the manufacturer no longer provides updates or security patches.

18
New cards

Asset Inventory

A record of organizational systems and software that helps identify assets requiring updates or replacement.

19
New cards

Network Scan

A method of identifying systems, services, or vulnerabilities on a network.

20
New cards

802.1X

Network authentication technology used to authenticate devices or users before allowing wired or wireless network access.

21
New cards

Wireless Threat Vector

Attack path involving wireless networks, including rogue access points, open networks, or weak security protocols.

22
New cards

Rogue Access Point

An unauthorized wireless access point that can create an untrusted path into or through a network.

23
New cards

Open Port

A network port accepting connections for a service, potentially increasing the attack surface.

24
New cards

Open Port Risk

More unnecessary exposed services and ports create additional opportunities for attack.

25
New cards

Default Credentials

Manufacturer-provided usernames and passwords that may be publicly known and should be changed.

26
New cards

Supply Chain Attack

An attack that compromises a trusted vendor, product, service provider, hardware component, or software component to reach the intended target.

27
New cards

MSP

Managed Service Provider, a third-party organization that manages services for customers and can become part of the supply-chain attack surface.

28
New cards

Target Supply Chain Breach

Attackers compromised an HVAC vendor and used its access to reach Target systems and ultimately point-of-sale systems.

29
New cards

Phishing

Fraudulent communication designed to trick a victim into revealing information, opening malicious content, or performing an attacker-desired action.

30
New cards

Phishing Warning Signs

Unexpected messages, suspicious senders or domains, unusual links, urgency, formatting problems, or credential requests.

31
New cards

Vishing

Voice-based phishing conducted through phone or voice communication.

32
New cards

Smishing

Phishing conducted through SMS or text messages.

33
New cards

Pretexting

Social engineering using a fabricated story or scenario to convince a victim to provide information or perform an action.

34
New cards

Pretext

The fabricated story or scenario used during a social engineering attack.

35
New cards

Impersonation

Pretending to be another person or trusted organization to manipulate a victim.

36
New cards

Typosquatting

Registering or using a misspelled or look-alike domain to deceive users who mistype or misread a legitimate address.

37
New cards

Watering Hole Attack

Compromising a website frequently visited by the intended targets and waiting for them to visit it.

38
New cards

Watering Hole Process

Research the target, identify a frequently visited site, compromise the site, wait for the victim, then attack when the victim visits.

39
New cards

Misinformation

False or inaccurate information that may be spread regardless of intent.

40
New cards

Disinformation

False information deliberately created or distributed to deceive.

41
New cards

False Information Amplification

Fake accounts can create posts and artificial engagement that algorithms amplify before real users begin sharing the content.

42
New cards

Brand Impersonation

Using the identity or appearance of a trusted brand to make malicious communications or websites appear legitimate.

43
New cards

Phishing vs Vishing

Phishing is the broader fraudulent communication attack, while vishing specifically uses voice.

44
New cards

Vishing vs Smishing

Vishing uses voice calls, while smishing uses SMS or text messages.

45
New cards

Pretexting vs Impersonation

Pretexting creates the fake story or scenario, while impersonation involves pretending to be a trusted person or organization.

46
New cards

Typosquatting vs Impersonation

Typosquatting relies on a similar or misspelled domain, while impersonation relies on pretending to be a trusted identity.

47
New cards

Threat Actor vs Threat Vector

Threat actor is who attacks, while threat vector is how the attack is delivered.