1/27
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What are the 5 factors that may cause accidental data loss or disclosure?
Negligence
Poor training
Not following security procedures
Inadequate monitoring and reporting
Weak security culture
What 5 forms of accidental damage are there?
Floods
Power outages
Fire
Storms
Terrorism
When an organisation has weak security controls what are they in danger of?
Intruders exploiting weaknesses which allows them to steal data
What things can happen if an employee visits untrustworthy websites?
Drive by downloads
Phishing
Malicious adverts
Pop ups
What are the the different types of viruses and what do they do?
Virus
Malicious code that attaches to files and spreads when executed.
Boot Sector Virus
Infects the boot sector and runs at startup.
Web Script Virus
Malicious script delivered through a web page.
Macro Virus
Uses document macros to spread.
Worm
Self-replicates across networks.
Rootkit
Hides malware and provides privileged access.
Trojan
Disguises itself as legitimate software.
Browser Hijack
Changes browser settings without permission.
Polymorphic Virus
Changes its code to avoid detection.
What are the types of spy ware and what do they do?
Spyware
Secretly gathers information.
Keylogger/Data Thief
Captures keystrokes or steals data.
System Monitor
Tracks user activity.
Mobile Device Tracker/Stalkerware
Monitors a mobile device user.
Web Beacons and Tracking Cookies
Track browsing behaviour.
What the different types of ad ware and what do they do?
Adware
Displays unwanted advertisements.
PUP
Software users may not want installed.
Legitimate Adware
Advertising-supported software disclosed to users.
Abusive or Deceptive Adware
Uses misleading advertising practices.
What are the different types of ransomware and what do they do?
Ransomware Demands payment to restore access.
Encryptors Encrypt files and demand a ransom.
Lockers Lock access to a device.
Scareware Uses false warnings to pressure payment.
Leakware/Doxware Threatens to release stolen data.
.
What is a bot?
Compromised devices controlled remotely
What 3 ways is malware classified?
Execution - how malware starts running on a computer
Propogation - spreads by itself / needs another file
Concealment - hiding malware from antivirus software /changing code /hiding in files
What are the following terms?
Self replicating worms
Masquerading trojans
Polymorphic mutation
Spreads itself automatically
Pretends to be legitimate software
Changes it’s signature to avoid detection
What is the kernel level?
The core of the operating system, evades security checks /task manager /antivirus
What is a root kit?
A type of malware that is designed to hide itself on a computer / network - makes them difficult to detect and remove
What is a ddos attack?
Botnets flood bandwidth or exhaust the cpu which is larger than a dos attack
What is a dos attack?
A single source which floods a server with requests
What are the following?
Data destruction
Data poisoning
Data tampering
Where a cyber criminal deletes files
Deliberate corruption of data to cause inaccurate /misleading outputs
Alteration of data to cause damage
What is back end manipulation?
Direct modification of sql databases, data stores or system records to alter financial logs or grant unauthorised permissions
What is front end defracement?
Compromising web server files to alter public displays, spreads misinformation or damage organizational trust
What is an autonomous device?
A device that can perform tasks and make decisions on its own
What are the following terms?
Espoinage
Sabotage
Economic attacks
Infrastructure attacks
Espionage Stealing information of value that would give one organisation or government an advantage over another.
Sabotage Destroying a digital system and preventing it from working again; this could be against a commercial organisation or a public service.
Economic attacks These cause damage to a target country's economy by attacking its largest financial organisations or the government itself.
Infrastructure Attacks These could cause widespread chaos by targeting communication and transport control systems; this would have a major impact on a socie ty.
What are the following terms?
tailgating
Forced entry
Impersonation
Coercion
Unauthorised users following authorised users into a secure area
Breaching barriers via physical force
Posing as staff or contractors to gain access
Forcing staff to grant access
What sre the following terms?
Unattended devices
Shoulder surfing
Theft
Accidental loss
Public access devices
Leaving active devices unattended for a malicious actor to access files and data
Unauthorised visual observation of a screen
Can lead to a brute force attack
Enables offline brute force attack
Making sure devices are locked when not in use
What is the ncsc and what is the role?
The uks authority on cyber threat intelligence
Co ordinTes major incident responses
Acts on evolving threats
What are the owasp and what is their role?
Global non profit organisation whucg improves the software security via open source software
What is the nist?
An organisation that sets key benchmarks for security controls and risk management
Maintains the national vulnerability database
What is NICE?
A national initiative for cybersecuity education
Builds cybersecuity workforce
What is NCCoE?
National cybersecuity center of excellence
Develops practical, repeatable solutions
What is NCCoE s role?
To protect national infrastructure