1/112
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
What is security?
Necessary steps to protect a person or property from harm.
What is the relationship between security and convenience?
Security is inversely proportional to convenience; as security increases, convenience generally decreases.
Why is there no single simple solution to cybersecurity?
There are many different types of attacks, devices, vulnerabilities, and threat actors, so no single defense can stop every attack.
What is cybersecurity?
The art, practice, and task of protecting networks, devices, and information.
What is the comprehensive definition of cybersecurity?
Cybersecurity protects the confidentiality, integrity, and availability of information on devices that store, manipulate, and transmit information through products, people, and procedures.
What are the three mandatory protections of cybersecurity?
Confidentiality, Integrity, and Availability (CIA).
What are the three protection layers of cybersecurity?
People, Products, and Policies.
What is confidentiality?
Ensuring that sensitive information is accessed only by authorized individuals or systems.
What is integrity?
Ensuring that information remains accurate, consistent, complete, and unaltered.
What is availability?
Ensuring that information and network resources are accessible to authorized users when needed.
Why is cybersecurity considered an ongoing process?
New attacks, vulnerabilities, and technologies constantly appear, so security must continuously be maintained and improved.
Why is cybersecurity difficult?
Devices are universally connected, attacks are faster and more sophisticated, attack tools are widely available, vulnerabilities are discovered quickly, updates can be delayed, attacks can be distributed, and users may be confused about security decisions.
Why does universal connectivity make cybersecurity difficult?
Attackers can potentially launch attacks against devices from anywhere in the world.
Why does the speed of attacks make cybersecurity difficult?
Attackers can attack millions of computers within minutes.
Why does the sophistication of attacks make cybersecurity difficult?
Attack tools can change their behavior so the same attack may appear differently.
Why is the availability of attack tools dangerous?
Attacks are no longer limited to highly skilled attackers because tools are easier to obtain and use.
Why are security updates important?
New vulnerabilities and attacks appear constantly, so systems must be updated to defend against them.
Why is user confusion a cybersecurity problem?
Users often have to make difficult security decisions with little or no instruction.
What is an asset?
Something of value that needs to be protected.
What is a threat?
A type of action with the potential to cause harm.
What is a threat agent?
A person or element with the power to carry out a threat.
What is a vulnerability?
A flaw or weakness that allows a threat agent to bypass security.
What is an attack vector?
The means by which an attack can occur.
What is threat likelihood?
The probability that a threat agent will exploit a vulnerability.
What is risk?
A situation involving exposure to some type of danger.
What is the relationship between a threat, threat agent, and vulnerability?
A threat is the potential harmful action, the threat agent is capable of carrying it out, and a vulnerability is the weakness that allows the threat agent to succeed.
What are the five ways to deal with risk?
Risk avoidance, risk acceptance, risk mitigation, risk deterrence, and risk transference.
What is risk avoidance?
Eliminating or changing an activity so the risk does not occur.
What is risk acceptance?
Recognizing a risk and choosing to accept it.
What is risk mitigation?
Taking steps to reduce the likelihood or impact of a risk.
What is risk deterrence?
Taking actions intended to discourage an attacker from carrying out an attack.
What is risk transference?
Shifting some or all of the risk to another party.
What are the major goals of cybersecurity?
Prevent data theft, thwart identity theft, prevent cyberterrorism or sabotage, avoid legal consequences, maintain productivity, and protect the country and population from cyber threats.
What are the five key elements of a practical cybersecurity strategy?
Block attacks, update defenses, minimize losses, use layers, and stay alert.
What does "Block Attacks" mean?
Create security perimeters and defenses that prevent attacks from reaching systems and information.
What does "Update Defenses" mean?
Regularly update hardware and software security defenses to protect against new attacks.
What does "Minimize Losses" mean?
Prepare in advance for attacks that get through by using backups and recovery procedures.
What does "Use Layers" mean?
Use multiple security defenses so an attacker must overcome several protections.
What does "Stay Alert" mean?
Everyone must remain aware of threats and know what actions to take to stay secure.
Why are layers of security important?
If one defense fails, other defenses can still protect the system, and multiple layers may discourage attackers.
What is a business recovery policy?
A policy that explains what to do if a successful attack occurs.
What are the three major types of hackers?
Black hat, white hat, and gray hat hackers.
What is a black hat hacker?
An attacker who violates computer security for personal gain or to cause malicious damage.
What is a white hat hacker?
An ethical attacker who has permission to test a system for weaknesses and report them to the organization.
What is a gray hat hacker?
An attacker who accesses a system without permission but generally does not do so for personal gain and may publicly disclose the vulnerability.
What is the main difference between white hat and gray hat hackers?
White hats have permission to test systems; gray hats do not.
Who are cybercriminals?
Attackers primarily motivated by financial gain.
Who are script kiddies?
Attackers who use existing attack tools, often for thrills, notoriety, or curiosity.
Who are vulnerability brokers?
People who find vulnerabilities and sell them to the highest bidder.
Who are insiders?
People within an organization who misuse their authorized access.
Who are cyberterrorists?
Attackers who seek to cause disruption and panic.
Who are hacktivists?
Attackers motivated by political or social causes who attempt to right a perceived wrong.
Who are state actors?
Government-sponsored attackers who may conduct espionage, surveillance, or disruption.
What is information security?
The protection of information and its critical elements, including the systems and hardware that use, store, and transmit information.
What does information security include?
Information security management, data security, and network security.
How did information security evolve?
It evolved from protecting physical documents and equipment to protecting digital information, systems, networks, and organizations from increasingly sophisticated threats.
What were major early information-security threats during World War II?
Physical theft of equipment, espionage, and sabotage.
Why is World War II important to computer-security history?
Code-breaking efforts during World War II helped create the first modern computers.
What was the Enigma machine?
A machine used by Nazi Germany to encrypt communications during World War II.
What was the Bombe?
A machine developed to help break Enigma-encrypted messages.
What happened to computer security during the 1960s?
Mainframe computers became more common and connected, creating new security concerns.
What was ARPA?
The Advanced Research Projects Agency, which examined the feasibility of a redundant networked communications system.
What was ARPANET?
A network developed from ARPA's work that eventually evolved into the Internet.
Who led the development of ARPANET?
Larry Roberts.
What were major ARPANET security problems during the 1970s and 1980s?
Insufficient controls at remote sites, vulnerable password structures, unsafe dial-up connections, and weak or nonexistent user identification and authorization.
What was RAND Report R-609?
A seminal report on computer security that identified the need for computer security and emphasized management and policy issues.
Who authored RAND Report R-609?
Willis H. Ware.
What year was RAND Report R-609 written?
1970.
Why is RAND Report R-609 important?
It helped establish computer security as an area of study and recognized the importance of management and policy.
How did the scope of computer security expand during the 1970s and 1980s?
It expanded from physical security to securing data, limiting unauthorized access, and involving personnel from multiple levels of an organization.
What happened to information security during the 1990s?
Networks and Internet connectivity grew rapidly, and information security began developing into a formal discipline and profession.
When was DEFCON established?
1993.
What happened to cybersecurity from 2000 to the present?
The growth of interconnected systems increased cyber risk and led to greater emphasis on cybersecurity.
What are major modern threat actors?
Semiprofessional hackers, professional cybercriminals, and government-sponsored actors.
What are the seven characteristics of information?
Confidentiality, Integrity, Availability, Accuracy, Authenticity, Utility, and Possession.
What is accuracy?
Information is free from mistakes or errors and has the value the end user expects.
What is authenticity?
Information is genuine or original rather than a reproduction or fabrication.
What is utility?
Information has value because it serves a particular purpose.
What is possession?
The quality or state of having ownership or control of an object or item.
What is the difference between confidentiality and possession?
A breach of confidentiality always results in a breach of possession, but a breach of possession does not always result in a breach of confidentiality.
What is a control, safeguard, or countermeasure?
A security mechanism, policy, or procedure that improves security.
What is an exposure?
A condition or state of being exposed.
What is a loss?
An instance in which an information asset suffers damage, destruction, unauthorized modification or disclosure, or denial of use.
What is an attack?
An intentional or unintentional act that can damage or compromise information or the systems supporting it.
What is access?
The ability of a subject or object to use, manipulate, modify, or affect another subject or object.
What is an exploit?
A technique or code that takes advantage of a vulnerability to carry out an attack.
What is a threat source?
A category of objects, people, or other entities that represents a danger to an asset.
What is a security posture?
The entire set of controls and safeguards an organization implements to protect an asset.
What is an information system?
The entire set of hardware, software, data, people, procedures, and networks.
Why is perfect information security impossible?
Security is a process, not a goal; organizations must continuously manage threats and balance protection with availability.
What is the security balance?
The level of security must provide reasonable access while still protecting against threats.
What is the CNSS Security Model also called?
The McCumber Cube.
What does the McCumber Cube represent?
The intersection of information states, the CIA security objectives, and the methods used to implement security.
What are the three information states in the McCumber Cube?
Information at rest, information in processing/use, and information in transmission.
What are the three security objectives in the McCumber Cube?
Confidentiality, Integrity, and Availability.
What are the three methods of implementing security in the McCumber Cube?
Policy, education, and technology.
What is a top-down approach to information security?
An approach where upper management establishes policies, procedures, processes, accountability, and direction for security.
What are advantages of the top-down approach?
Strong management support, dedicated funding, clear planning, accountability, and the ability to influence organizational culture.
What is a grassroots approach to information security?
A bottom-up approach where technical personnel, such as system administrators, improve the security of their own systems.
Why does the grassroots approach often fail?
It often lacks management support, funding, organizational staying power, and broad accountability.