Short Module 1

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/112

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 9:24 PM on 8/22/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

113 Terms

1
New cards

What is security?

Necessary steps to protect a person or property from harm.

2
New cards

What is the relationship between security and convenience?

Security is inversely proportional to convenience; as security increases, convenience generally decreases.

3
New cards

Why is there no single simple solution to cybersecurity?

There are many different types of attacks, devices, vulnerabilities, and threat actors, so no single defense can stop every attack.

4
New cards

What is cybersecurity?

The art, practice, and task of protecting networks, devices, and information.

5
New cards

What is the comprehensive definition of cybersecurity?

Cybersecurity protects the confidentiality, integrity, and availability of information on devices that store, manipulate, and transmit information through products, people, and procedures.

6
New cards

What are the three mandatory protections of cybersecurity?

Confidentiality, Integrity, and Availability (CIA).

7
New cards

What are the three protection layers of cybersecurity?

People, Products, and Policies.

8
New cards

What is confidentiality?

Ensuring that sensitive information is accessed only by authorized individuals or systems.

9
New cards

What is integrity?

Ensuring that information remains accurate, consistent, complete, and unaltered.

10
New cards

What is availability?

Ensuring that information and network resources are accessible to authorized users when needed.

11
New cards

Why is cybersecurity considered an ongoing process?

New attacks, vulnerabilities, and technologies constantly appear, so security must continuously be maintained and improved.

12
New cards

Why is cybersecurity difficult?

Devices are universally connected, attacks are faster and more sophisticated, attack tools are widely available, vulnerabilities are discovered quickly, updates can be delayed, attacks can be distributed, and users may be confused about security decisions.

13
New cards

Why does universal connectivity make cybersecurity difficult?

Attackers can potentially launch attacks against devices from anywhere in the world.

14
New cards

Why does the speed of attacks make cybersecurity difficult?

Attackers can attack millions of computers within minutes.

15
New cards

Why does the sophistication of attacks make cybersecurity difficult?

Attack tools can change their behavior so the same attack may appear differently.

16
New cards

Why is the availability of attack tools dangerous?

Attacks are no longer limited to highly skilled attackers because tools are easier to obtain and use.

17
New cards

Why are security updates important?

New vulnerabilities and attacks appear constantly, so systems must be updated to defend against them.

18
New cards

Why is user confusion a cybersecurity problem?

Users often have to make difficult security decisions with little or no instruction.

19
New cards

What is an asset?

Something of value that needs to be protected.

20
New cards

What is a threat?

A type of action with the potential to cause harm.

21
New cards

What is a threat agent?

A person or element with the power to carry out a threat.

22
New cards

What is a vulnerability?

A flaw or weakness that allows a threat agent to bypass security.

23
New cards

What is an attack vector?

The means by which an attack can occur.

24
New cards

What is threat likelihood?

The probability that a threat agent will exploit a vulnerability.

25
New cards

What is risk?

A situation involving exposure to some type of danger.

26
New cards

What is the relationship between a threat, threat agent, and vulnerability?

A threat is the potential harmful action, the threat agent is capable of carrying it out, and a vulnerability is the weakness that allows the threat agent to succeed.

27
New cards

What are the five ways to deal with risk?

Risk avoidance, risk acceptance, risk mitigation, risk deterrence, and risk transference.

28
New cards

What is risk avoidance?

Eliminating or changing an activity so the risk does not occur.

29
New cards

What is risk acceptance?

Recognizing a risk and choosing to accept it.

30
New cards

What is risk mitigation?

Taking steps to reduce the likelihood or impact of a risk.

31
New cards

What is risk deterrence?

Taking actions intended to discourage an attacker from carrying out an attack.

32
New cards

What is risk transference?

Shifting some or all of the risk to another party.

33
New cards

What are the major goals of cybersecurity?

Prevent data theft, thwart identity theft, prevent cyberterrorism or sabotage, avoid legal consequences, maintain productivity, and protect the country and population from cyber threats.

34
New cards

What are the five key elements of a practical cybersecurity strategy?

Block attacks, update defenses, minimize losses, use layers, and stay alert.

35
New cards

What does "Block Attacks" mean?

Create security perimeters and defenses that prevent attacks from reaching systems and information.

36
New cards

What does "Update Defenses" mean?

Regularly update hardware and software security defenses to protect against new attacks.

37
New cards

What does "Minimize Losses" mean?

Prepare in advance for attacks that get through by using backups and recovery procedures.

38
New cards

What does "Use Layers" mean?

Use multiple security defenses so an attacker must overcome several protections.

39
New cards

What does "Stay Alert" mean?

Everyone must remain aware of threats and know what actions to take to stay secure.

40
New cards

Why are layers of security important?

If one defense fails, other defenses can still protect the system, and multiple layers may discourage attackers.

41
New cards

What is a business recovery policy?

A policy that explains what to do if a successful attack occurs.

42
New cards

What are the three major types of hackers?

Black hat, white hat, and gray hat hackers.

43
New cards

What is a black hat hacker?

An attacker who violates computer security for personal gain or to cause malicious damage.

44
New cards

What is a white hat hacker?

An ethical attacker who has permission to test a system for weaknesses and report them to the organization.

45
New cards

What is a gray hat hacker?

An attacker who accesses a system without permission but generally does not do so for personal gain and may publicly disclose the vulnerability.

46
New cards

What is the main difference between white hat and gray hat hackers?

White hats have permission to test systems; gray hats do not.

47
New cards

Who are cybercriminals?

Attackers primarily motivated by financial gain.

48
New cards

Who are script kiddies?

Attackers who use existing attack tools, often for thrills, notoriety, or curiosity.

49
New cards

Who are vulnerability brokers?

People who find vulnerabilities and sell them to the highest bidder.

50
New cards

Who are insiders?

People within an organization who misuse their authorized access.

51
New cards

Who are cyberterrorists?

Attackers who seek to cause disruption and panic.

52
New cards

Who are hacktivists?

Attackers motivated by political or social causes who attempt to right a perceived wrong.

53
New cards

Who are state actors?

Government-sponsored attackers who may conduct espionage, surveillance, or disruption.

54
New cards

What is information security?

The protection of information and its critical elements, including the systems and hardware that use, store, and transmit information.

55
New cards

What does information security include?

Information security management, data security, and network security.

56
New cards

How did information security evolve?

It evolved from protecting physical documents and equipment to protecting digital information, systems, networks, and organizations from increasingly sophisticated threats.

57
New cards

What were major early information-security threats during World War II?

Physical theft of equipment, espionage, and sabotage.

58
New cards

Why is World War II important to computer-security history?

Code-breaking efforts during World War II helped create the first modern computers.

59
New cards

What was the Enigma machine?

A machine used by Nazi Germany to encrypt communications during World War II.

60
New cards

What was the Bombe?

A machine developed to help break Enigma-encrypted messages.

61
New cards

What happened to computer security during the 1960s?

Mainframe computers became more common and connected, creating new security concerns.

62
New cards

What was ARPA?

The Advanced Research Projects Agency, which examined the feasibility of a redundant networked communications system.

63
New cards

What was ARPANET?

A network developed from ARPA's work that eventually evolved into the Internet.

64
New cards

Who led the development of ARPANET?

Larry Roberts.

65
New cards

What were major ARPANET security problems during the 1970s and 1980s?

Insufficient controls at remote sites, vulnerable password structures, unsafe dial-up connections, and weak or nonexistent user identification and authorization.

66
New cards

What was RAND Report R-609?

A seminal report on computer security that identified the need for computer security and emphasized management and policy issues.

67
New cards

Who authored RAND Report R-609?

Willis H. Ware.

68
New cards

What year was RAND Report R-609 written?

1970.

69
New cards

Why is RAND Report R-609 important?

It helped establish computer security as an area of study and recognized the importance of management and policy.

70
New cards

How did the scope of computer security expand during the 1970s and 1980s?

It expanded from physical security to securing data, limiting unauthorized access, and involving personnel from multiple levels of an organization.

71
New cards

What happened to information security during the 1990s?

Networks and Internet connectivity grew rapidly, and information security began developing into a formal discipline and profession.

72
New cards

When was DEFCON established?

1993.

73
New cards

What happened to cybersecurity from 2000 to the present?

The growth of interconnected systems increased cyber risk and led to greater emphasis on cybersecurity.

74
New cards

What are major modern threat actors?

Semiprofessional hackers, professional cybercriminals, and government-sponsored actors.

75
New cards

What are the seven characteristics of information?

Confidentiality, Integrity, Availability, Accuracy, Authenticity, Utility, and Possession.

76
New cards

What is accuracy?

Information is free from mistakes or errors and has the value the end user expects.

77
New cards

What is authenticity?

Information is genuine or original rather than a reproduction or fabrication.

78
New cards

What is utility?

Information has value because it serves a particular purpose.

79
New cards

What is possession?

The quality or state of having ownership or control of an object or item.

80
New cards

What is the difference between confidentiality and possession?

A breach of confidentiality always results in a breach of possession, but a breach of possession does not always result in a breach of confidentiality.

81
New cards

What is a control, safeguard, or countermeasure?

A security mechanism, policy, or procedure that improves security.

82
New cards

What is an exposure?

A condition or state of being exposed.

83
New cards

What is a loss?

An instance in which an information asset suffers damage, destruction, unauthorized modification or disclosure, or denial of use.

84
New cards

What is an attack?

An intentional or unintentional act that can damage or compromise information or the systems supporting it.

85
New cards

What is access?

The ability of a subject or object to use, manipulate, modify, or affect another subject or object.

86
New cards

What is an exploit?

A technique or code that takes advantage of a vulnerability to carry out an attack.

87
New cards

What is a threat source?

A category of objects, people, or other entities that represents a danger to an asset.

88
New cards

What is a security posture?

The entire set of controls and safeguards an organization implements to protect an asset.

89
New cards

What is an information system?

The entire set of hardware, software, data, people, procedures, and networks.

90
New cards

Why is perfect information security impossible?

Security is a process, not a goal; organizations must continuously manage threats and balance protection with availability.

91
New cards

What is the security balance?

The level of security must provide reasonable access while still protecting against threats.

92
New cards

What is the CNSS Security Model also called?

The McCumber Cube.

93
New cards

What does the McCumber Cube represent?

The intersection of information states, the CIA security objectives, and the methods used to implement security.

94
New cards

What are the three information states in the McCumber Cube?

Information at rest, information in processing/use, and information in transmission.

95
New cards

What are the three security objectives in the McCumber Cube?

Confidentiality, Integrity, and Availability.

96
New cards

What are the three methods of implementing security in the McCumber Cube?

Policy, education, and technology.

97
New cards

What is a top-down approach to information security?

An approach where upper management establishes policies, procedures, processes, accountability, and direction for security.

98
New cards

What are advantages of the top-down approach?

Strong management support, dedicated funding, clear planning, accountability, and the ability to influence organizational culture.

99
New cards

What is a grassroots approach to information security?

A bottom-up approach where technical personnel, such as system administrators, improve the security of their own systems.

100
New cards

Why does the grassroots approach often fail?

It often lacks management support, funding, organizational staying power, and broad accountability.