Information System Attack Methods for ISOKA SYS Exam

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/19

flashcard set

Earn XP

Description and Tags

These flashcards cover key concepts related to information systems attack methods and techniques essential for the ISOKA SYS exam.

Last updated 2:45 AM on 10/12/25
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

20 Terms

1
New cards

What is a man in the middle attack?

It refers to various types of attacks where an attacker intercepts communications between two parties.

2
New cards

Name three types of man in the middle attacks.

IP spoofing, DNS spoofing, and email hijacking.

3
New cards

What is a denial of service attack?

An attack that overwhelms a victim's system with traffic, making it unable to process legitimate requests.

4
New cards

What is an example of a volume based denial of service attack?

UDP floods.

5
New cards

What is a SYN attack?

An attack that exploits the TCP handshake, leaving a server waiting indefinitely for a confirmation that never arrives.

6
New cards

What is phishing?

A form of fraud that involves tricking individuals into providing sensitive information through deceptive emails or messages.

7
New cards

What is spear phishing?

Targeted phishing attacks aimed at specific individuals or organizations.

8
New cards

What are SQL injection attacks?

Attacks that manipulate SQL queries to gain unauthorized access to a database.

9
New cards

What is cross site scripting (XSS)?

Inserting malicious scripts into trusted websites, executed when a victim visits the site.

10
New cards

What is malware?

Malicious software designed to disrupt or damage computers or gain unauthorized access.

11
New cards

What are the common types of malware?

Viruses, worms, trojans, ransomware, and spyware.

12
New cards

What is a zero day attack?

An attack that exploits a previously unknown vulnerability for which no patches are available.

13
New cards

What is an insider threat?

Malicious or negligent actions by individuals within an organization that jeopardize security.

14
New cards

What does the term M and M scenario refer to in cybersecurity?

It describes a security model with strong perimeter protections but weak internal security.

15
New cards

What are some measures to mitigate insider threats?

Network segmentation, separation of duties, and internal monitoring.

16
New cards

What is the attack lifecycle?

The sequence of stages attackers go through, including reconnaissance, scanning, gaining access, maintaining access, and covering tracks.

17
New cards

What is the Lockheed Martin cyber kill chain?

A model used to understand the stages of an attack lifecycle.

18
New cards

What is the importance of defense in depth?

A strategy that involves multiple layers of security controls to protect information assets.

19
New cards

What are security controls?

Measures implemented to guard against vulnerabilities and attacks.

20
New cards

What is the role of incident response in cybersecurity?

It involves the process of managing and responding to security breaches.