1/239
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Best defense against zero-day exploit impact
None (unpreventable)
Verifying user ID and restricting specific areas
Authentication and Authorization
Challenges in information security compliance
Industry regulations conflict
Text message scam vector classification
Specialized and Communications
Framework defining security policies and controls
Security framework
Employee changes own grade in database
Insider threat
Primary motivation of organized crime actors
Financial gain
Multiyear intrusion campaign for national security data
APT and Espionage
Unskilled attacker goal upon penetrating network
Exfiltration and Service disruption
Best target to steal new missile contract specs
Enterprise
Viruses removed using bootable flash drive control type
Corrective control
Cybersecurity vs information security umbrella scope
Cybersecurity protects devices
Role directly above security administrator
Security manager
NIST CSF core functional components
Protect and Detect
Attacking competitor to steal product research
Competitor
Security control ensuring only authorized viewing
Encryption (Confidentiality)
Example of mainstream attack surface
Network
Broker discovering software weakness action
Sell vulnerability
Database tracking threat actor attack behaviors
TTP database
Major non-financial impact of credit card breach
Loss of reputation
Vulnerabilities of device with default IP and Telnet
Open ports and Unsecure protocols
Connecting unapproved wireless router to network
Shadow IT
Security control type for awareness training
Operational control
Action required for hardware reaching EOL state
Replace router
Attacker changing item price from $200 to $20
Integrity breach
Political ideology motivated attacker category
Hacktivist
Nation-state actor behavior after failed attempt
Continue trying
Security principle recording who logged in and when
Accounting
Target category for stolen phone contacts and cards
Individual
Reason organized crime switched to cyberattacks
Easier to hide
Distance calculation for 0.25s ultrasonic sensor ping
43 meters
Fake invoice sent to large firm email attack type
BEC and Phishing
Attacker infecting industry forum website malware
Watering hole attack
Physical fence climbing deterrent measures
Anticlimb collar, Roller barrier, Rotating spikes
Searching trash receptacles for sensitive documents
Dumpster diving
High-speed low-maintenance physical network conduit
Alarmed carrier PDS
Executive targeted email attack vs spear phishing
Whaling
Primary criteria for classifying data elements
Criticality and Sensitivity
Redirection technique exploiting infected DNS
Pharming
Buffer area separating nonsecure from secure space
Reception area / Waiting room
Data classification order: highest to lowest sensitivity
Confidential, private, sensitive
Legal protection type for invented artifact
Intellectual property (IP)
Obfuscating production data copy for testing
Data masking and Sanitization
Physical door lock opened via phone Bluetooth signal
Smart lock
Physical security controls umbrella components
Gel-based paint, Perimeter defenses, Data leakage
Registering trademark domain names to sell them back
Cybersquatting
Enclosure blocking electromagnetic fields (EMI)
Faraday cage
Security guards patrolling outer perimeter classification
Two-person integrity and Active defense
Sensor emitting and detecting light spectrum signals
Active infrared (IR)
Attack vector exploited by social engineering
Human vector
Email From field showing external company domain
Phishing and BEC
False warning created with malicious intent
Disinformation
Technician refuses irate CEO over-phone reset
Did the right thing
Radio wave sensor used to dim lights and spot movement
Microwave
State of data sitting in RAM ready to transmit
Data in processing
Underground sensor detecting vehicle and direction
Pressure sensor
Impersonating government official over phone for info
Pretexting / Vishing
Interlocking door buffer for high-security facilities
Access control vestibule
Agency notified of healthcare breach over 500 records
DHHS
Fraudulent text message with fake link or number
Smishing
Two main benefits of using cryptography
Hardening and Mitigation
Keys used to verify sender authenticity and integrity
Sender public key and Recipient private key
Flawed approach relying on hidden mechanisms
Security through obscurity
Main challenge securing low-powered devices with crypto
Time and energy cost
Cryptographic attack analyzing ciphertext patterns
Known ciphertext attack
Cryptographic property preventing denial of action
Nonrepudiation
Cryptographic algorithm used by Blockchain
SHA-256 (Hash algorithms)
Characteristics of block ciphers vs stream ciphers
Stream ciphers less secure / Block output random
Database encryption with lowest performance penalty
File-level encryption
OS feature protecting entire drive data on crash
BitLocker (FDE)
Element that MUST be guarded in crypto algorithms
Encryption key
Key size and block size for AES vs Blowfish
AES 256-bit / Blowfish 64-bit blocks
Primary purpose of a cryptographic hash
Verify message integrity
Hiding secret message meaning using another language
Encryption
Native Microsoft Windows folder encryption system
EFS
Three critical requirements for a secure hash
Fixed size, Unique output, Original digest
Secure hash algorithm types
RipeMD, SHA-2, Whirlpool
Attack forcing system to use older insecure protocol
Downgrade attack
Components required to generate a digital signature
Private key and Message digest
Critical requirement for symmetric key ciphers
Key kept private
Asymmetric algorithm matching 1024-bit RSA security
ECC (160-bit)
Result of a one-way hash algorithm
Message digest (Fingerprint)
Security protection provided by immutable archives
Integrity
Key exchange method providing different session keys
Perfect forward secrecy
Asymmetric encryption key process
Encrypt public / Decrypt private
Unencrypted text input used for encryption
Plaintext
Cipher using XOR bit operations and key substitution
Substitution / Requires key
Searching for two distinct inputs yielding same hash
Collision attack
Self-Encrypting Drive authentication requirement
Authentication before access
Hiding secret messages inside harmless image files
Steganography
Transparent protocol operating without program edits
IPSec
Digital signature weakness regarding sender identity
Proves key owner only
Best security posture for a root CA server
Offline / Powered down
Type of signature on root digital certificates
Self-signed
Centralized public folder viewing certificate status
Certificate repository (CR)
Published document defining rules governing PKI
Certificate policy (CP)
Trust model where users cross-sign certificates
Web of trust
Infrastructure controlling public keys and certificates
PKI
Entity verifying applicant identity before CA issuance
Registration authority (RA)
Block cipher mode chaining previous output blocks
Cipher Block Chaining (CBC)