Internet and Firewall Security midterm

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/239

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 2:14 AM on 10/9/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

240 Terms

1
New cards

Best defense against zero-day exploit impact

None (unpreventable)

2
New cards

Verifying user ID and restricting specific areas

Authentication and Authorization

3
New cards

Challenges in information security compliance

Industry regulations conflict

4
New cards

Text message scam vector classification

Specialized and Communications

5
New cards

Framework defining security policies and controls

Security framework

6
New cards

Employee changes own grade in database

Insider threat

7
New cards

Primary motivation of organized crime actors

Financial gain

8
New cards

Multiyear intrusion campaign for national security data

APT and Espionage

9
New cards

Unskilled attacker goal upon penetrating network

Exfiltration and Service disruption

10
New cards

Best target to steal new missile contract specs

Enterprise

11
New cards

Viruses removed using bootable flash drive control type

Corrective control

12
New cards

Cybersecurity vs information security umbrella scope

Cybersecurity protects devices

13
New cards

Role directly above security administrator

Security manager

14
New cards

NIST CSF core functional components

Protect and Detect

15
New cards

Attacking competitor to steal product research

Competitor

16
New cards

Security control ensuring only authorized viewing

Encryption (Confidentiality)

17
New cards

Example of mainstream attack surface

Network

18
New cards

Broker discovering software weakness action

Sell vulnerability

19
New cards

Database tracking threat actor attack behaviors

TTP database

20
New cards

Major non-financial impact of credit card breach

Loss of reputation

21
New cards

Vulnerabilities of device with default IP and Telnet

Open ports and Unsecure protocols

22
New cards

Connecting unapproved wireless router to network

Shadow IT

23
New cards

Security control type for awareness training

Operational control

24
New cards

Action required for hardware reaching EOL state

Replace router

25
New cards

Attacker changing item price from $200 to $20

Integrity breach

26
New cards

Political ideology motivated attacker category

Hacktivist

27
New cards

Nation-state actor behavior after failed attempt

Continue trying

28
New cards

Security principle recording who logged in and when

Accounting

29
New cards

Target category for stolen phone contacts and cards

Individual

30
New cards

Reason organized crime switched to cyberattacks

Easier to hide

31
New cards

Distance calculation for 0.25s ultrasonic sensor ping

43 meters

32
New cards

Fake invoice sent to large firm email attack type

BEC and Phishing

33
New cards

Attacker infecting industry forum website malware

Watering hole attack

34
New cards

Physical fence climbing deterrent measures

Anticlimb collar, Roller barrier, Rotating spikes

35
New cards

Searching trash receptacles for sensitive documents

Dumpster diving

36
New cards

High-speed low-maintenance physical network conduit

Alarmed carrier PDS

37
New cards

Executive targeted email attack vs spear phishing

Whaling

38
New cards

Primary criteria for classifying data elements

Criticality and Sensitivity

39
New cards

Redirection technique exploiting infected DNS

Pharming

40
New cards

Buffer area separating nonsecure from secure space

Reception area / Waiting room

41
New cards

Data classification order: highest to lowest sensitivity

Confidential, private, sensitive

42
New cards

Legal protection type for invented artifact

Intellectual property (IP)

43
New cards

Obfuscating production data copy for testing

Data masking and Sanitization

44
New cards

Physical door lock opened via phone Bluetooth signal

Smart lock

45
New cards

Physical security controls umbrella components

Gel-based paint, Perimeter defenses, Data leakage

46
New cards

Registering trademark domain names to sell them back

Cybersquatting

47
New cards

Enclosure blocking electromagnetic fields (EMI)

Faraday cage

48
New cards

Security guards patrolling outer perimeter classification

Two-person integrity and Active defense

49
New cards

Sensor emitting and detecting light spectrum signals

Active infrared (IR)

50
New cards

Attack vector exploited by social engineering

Human vector

51
New cards

Email From field showing external company domain

Phishing and BEC

52
New cards

False warning created with malicious intent

Disinformation

53
New cards

Technician refuses irate CEO over-phone reset

Did the right thing

54
New cards

Radio wave sensor used to dim lights and spot movement

Microwave

55
New cards

State of data sitting in RAM ready to transmit

Data in processing

56
New cards

Underground sensor detecting vehicle and direction

Pressure sensor

57
New cards

Impersonating government official over phone for info

Pretexting / Vishing

58
New cards

Interlocking door buffer for high-security facilities

Access control vestibule

59
New cards

Agency notified of healthcare breach over 500 records

DHHS

60
New cards

Fraudulent text message with fake link or number

Smishing

61
New cards

Two main benefits of using cryptography

Hardening and Mitigation

62
New cards

Keys used to verify sender authenticity and integrity

Sender public key and Recipient private key

63
New cards

Flawed approach relying on hidden mechanisms

Security through obscurity

64
New cards

Main challenge securing low-powered devices with crypto

Time and energy cost

65
New cards

Cryptographic attack analyzing ciphertext patterns

Known ciphertext attack

66
New cards

Cryptographic property preventing denial of action

Nonrepudiation

67
New cards

Cryptographic algorithm used by Blockchain

SHA-256 (Hash algorithms)

68
New cards

Characteristics of block ciphers vs stream ciphers

Stream ciphers less secure / Block output random

69
New cards

Database encryption with lowest performance penalty

File-level encryption

70
New cards

OS feature protecting entire drive data on crash

BitLocker (FDE)

71
New cards

Element that MUST be guarded in crypto algorithms

Encryption key

72
New cards

Key size and block size for AES vs Blowfish

AES 256-bit / Blowfish 64-bit blocks

73
New cards

Primary purpose of a cryptographic hash

Verify message integrity

74
New cards

Hiding secret message meaning using another language

Encryption

75
New cards

Native Microsoft Windows folder encryption system

EFS

76
New cards

Three critical requirements for a secure hash

Fixed size, Unique output, Original digest

77
New cards

Secure hash algorithm types

RipeMD, SHA-2, Whirlpool

78
New cards

Attack forcing system to use older insecure protocol

Downgrade attack

79
New cards

Components required to generate a digital signature

Private key and Message digest

80
New cards

Critical requirement for symmetric key ciphers

Key kept private

81
New cards

Asymmetric algorithm matching 1024-bit RSA security

ECC (160-bit)

82
New cards

Result of a one-way hash algorithm

Message digest (Fingerprint)

83
New cards

Security protection provided by immutable archives

Integrity

84
New cards

Key exchange method providing different session keys

Perfect forward secrecy

85
New cards

Asymmetric encryption key process

Encrypt public / Decrypt private

86
New cards

Unencrypted text input used for encryption

Plaintext

87
New cards

Cipher using XOR bit operations and key substitution

Substitution / Requires key

88
New cards

Searching for two distinct inputs yielding same hash

Collision attack

89
New cards

Self-Encrypting Drive authentication requirement

Authentication before access

90
New cards

Hiding secret messages inside harmless image files

Steganography

91
New cards

Transparent protocol operating without program edits

IPSec

92
New cards

Digital signature weakness regarding sender identity

Proves key owner only

93
New cards

Best security posture for a root CA server

Offline / Powered down

94
New cards

Type of signature on root digital certificates

Self-signed

95
New cards

Centralized public folder viewing certificate status

Certificate repository (CR)

96
New cards

Published document defining rules governing PKI

Certificate policy (CP)

97
New cards

Trust model where users cross-sign certificates

Web of trust

98
New cards

Infrastructure controlling public keys and certificates

PKI

99
New cards

Entity verifying applicant identity before CA issuance

Registration authority (RA)

100
New cards

Block cipher mode chaining previous output blocks

Cipher Block Chaining (CBC)