1/19
These flashcards cover key concepts related to information systems attack methods and techniques essential for the ISOKA SYS exam.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What is a man in the middle attack?
It refers to various types of attacks where an attacker intercepts communications between two parties.
Name three types of man in the middle attacks.
IP spoofing, DNS spoofing, and email hijacking.
What is a denial of service attack?
An attack that overwhelms a victim's system with traffic, making it unable to process legitimate requests.
What is an example of a volume based denial of service attack?
UDP floods.
What is a SYN attack?
An attack that exploits the TCP handshake, leaving a server waiting indefinitely for a confirmation that never arrives.
What is phishing?
A form of fraud that involves tricking individuals into providing sensitive information through deceptive emails or messages.
What is spear phishing?
Targeted phishing attacks aimed at specific individuals or organizations.
What are SQL injection attacks?
Attacks that manipulate SQL queries to gain unauthorized access to a database.
What is cross site scripting (XSS)?
Inserting malicious scripts into trusted websites, executed when a victim visits the site.
What is malware?
Malicious software designed to disrupt or damage computers or gain unauthorized access.
What are the common types of malware?
Viruses, worms, trojans, ransomware, and spyware.
What is a zero day attack?
An attack that exploits a previously unknown vulnerability for which no patches are available.
What is an insider threat?
Malicious or negligent actions by individuals within an organization that jeopardize security.
What does the term M and M scenario refer to in cybersecurity?
It describes a security model with strong perimeter protections but weak internal security.
What are some measures to mitigate insider threats?
Network segmentation, separation of duties, and internal monitoring.
What is the attack lifecycle?
The sequence of stages attackers go through, including reconnaissance, scanning, gaining access, maintaining access, and covering tracks.
What is the Lockheed Martin cyber kill chain?
A model used to understand the stages of an attack lifecycle.
What is the importance of defense in depth?
A strategy that involves multiple layers of security controls to protect information assets.
What are security controls?
Measures implemented to guard against vulnerabilities and attacks.
What is the role of incident response in cybersecurity?
It involves the process of managing and responding to security breaches.