Human Factor in Cybersecurity Overview

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/35

flashcard set

Earn XP

Description and Tags

This set of flashcards covers key vocabulary from a lecture on the human factor in cybersecurity, focusing on concepts, techniques, and principles.

Last updated 5:23 AM on 11/13/25
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

36 Terms

1
New cards

Social Engineering

Leveraging human weaknesses (curiosity, trust, authority) to obtain unauthorized access or information.

2
New cards

CIA Triad

The three core principles that guide cybersecurity efforts: Confidentiality, Integrity, and Availability.

3
New cards

Weakest Link

The idea that humans are the primary target for attackers in cybersecurity.

4
New cards

Curiosity Exploitation

Leveraging the natural human desire to explore unknown content to trick users.

5
New cards

Pretexting

Crafting a believable story or identity to gain the target's trust.

6
New cards

QR-Code Phishing

Using a QR code to direct users to a malicious URL.

7
New cards

Disguised URLs

Hiding the true destination of a link to trick users into clicking.

8
New cards

Authority Abuse

Using a position of power to lend credibility to a malicious request.

9
New cards

Penetration Testing

A structured, simulated attack on an organization's assets to discover weaknesses.

10
New cards

Technical Controls

Security measures like encryption and firewalls that must be maintained by knowledgeable humans.

11
New cards

Human Errors

Mistakes made by individuals that create opportunities for attackers.

12
New cards

Network Analogies

Comparing computer networks to road or postal networks to visualize data movement.

13
New cards

Attack vs. Exploitation

Attack is the act of gaining unauthorized access; exploitation is using that access.

14
New cards

Observation

Watching victims’ inputs to identify potential targets for social engineering.

15
New cards

Documentation

A detailed written account of every step taken during a cybersecurity attack.

16
New cards

Reconnaissance

Gathering intelligence on a target to improve attack design.

17
New cards

Target Identification

Identifying the most vulnerable individual or process in a security system.

18
New cards

Governance

Understanding laws and social norms that influence security settings.

19
New cards

Responsibility

Those who know technological controls also need to be aware of relevant laws.

20
New cards

Phishing Tactics

Techniques used to deceive individuals into providing sensitive information or access.

21
New cards

Psychological Pressure

Creating stressful scenarios for the target to increase the likelihood of errors.

22
New cards

Continuous Change

The need for regular reassessment of security due to evolving systems and staff.

23
New cards

Legal Considerations

Understanding regional laws that impact data security and privacy mandates.

24
New cards

Security Posture

The overall security status of an organization considering all vulnerabilities.

25
New cards

Human Factor Risks

Threats to cybersecurity that arise from human behavior and decision-making.

26
New cards

Cybersecurity Culture

The collective behaviors and attitudes towards security within an organization.

27
New cards

Simulation

Creating realistic scenarios to practice detection and response to security threats.

28
New cards

Attack Sequence

The order of steps taken to execute an attack successfully.

29
New cards

Confidence Building

Enhancing the attacker’s assurance through rehearsal of the attack plan.

30
New cards

Data Residency

The physical or geographical location of an organization’s data.

31
New cards

Weak Cryptographic Algorithms

Insecure methods of encryption that can be easily broken by attackers.

32
New cards

Unexpected Behavior

The unpredictability of human responses, which can complicate attack strategy.

33
New cards

Ethical Violations

Breaking legal or ethical standards during cybersecurity exercises.

34
New cards

Remediation Recommendations

Suggestions made post-attack to improve security and mitigate vulnerabilities.

35
New cards

Effective Offensive Security

The practice of simulating attacks to improve organizational defenses.

36
New cards

Follow-Up Training

Post-assessment education designed to help users recognize and avoid phishing.