1/35
This set of flashcards covers key vocabulary from a lecture on the human factor in cybersecurity, focusing on concepts, techniques, and principles.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Social Engineering
Leveraging human weaknesses (curiosity, trust, authority) to obtain unauthorized access or information.
CIA Triad
The three core principles that guide cybersecurity efforts: Confidentiality, Integrity, and Availability.
Weakest Link
The idea that humans are the primary target for attackers in cybersecurity.
Curiosity Exploitation
Leveraging the natural human desire to explore unknown content to trick users.
Pretexting
Crafting a believable story or identity to gain the target's trust.
QR-Code Phishing
Using a QR code to direct users to a malicious URL.
Disguised URLs
Hiding the true destination of a link to trick users into clicking.
Authority Abuse
Using a position of power to lend credibility to a malicious request.
Penetration Testing
A structured, simulated attack on an organization's assets to discover weaknesses.
Technical Controls
Security measures like encryption and firewalls that must be maintained by knowledgeable humans.
Human Errors
Mistakes made by individuals that create opportunities for attackers.
Network Analogies
Comparing computer networks to road or postal networks to visualize data movement.
Attack vs. Exploitation
Attack is the act of gaining unauthorized access; exploitation is using that access.
Observation
Watching victims’ inputs to identify potential targets for social engineering.
Documentation
A detailed written account of every step taken during a cybersecurity attack.
Reconnaissance
Gathering intelligence on a target to improve attack design.
Target Identification
Identifying the most vulnerable individual or process in a security system.
Governance
Understanding laws and social norms that influence security settings.
Responsibility
Those who know technological controls also need to be aware of relevant laws.
Phishing Tactics
Techniques used to deceive individuals into providing sensitive information or access.
Psychological Pressure
Creating stressful scenarios for the target to increase the likelihood of errors.
Continuous Change
The need for regular reassessment of security due to evolving systems and staff.
Legal Considerations
Understanding regional laws that impact data security and privacy mandates.
Security Posture
The overall security status of an organization considering all vulnerabilities.
Human Factor Risks
Threats to cybersecurity that arise from human behavior and decision-making.
Cybersecurity Culture
The collective behaviors and attitudes towards security within an organization.
Simulation
Creating realistic scenarios to practice detection and response to security threats.
Attack Sequence
The order of steps taken to execute an attack successfully.
Confidence Building
Enhancing the attacker’s assurance through rehearsal of the attack plan.
Data Residency
The physical or geographical location of an organization’s data.
Weak Cryptographic Algorithms
Insecure methods of encryption that can be easily broken by attackers.
Unexpected Behavior
The unpredictability of human responses, which can complicate attack strategy.
Ethical Violations
Breaking legal or ethical standards during cybersecurity exercises.
Remediation Recommendations
Suggestions made post-attack to improve security and mitigate vulnerabilities.
Effective Offensive Security
The practice of simulating attacks to improve organizational defenses.
Follow-Up Training
Post-assessment education designed to help users recognize and avoid phishing.