Untitled Flashcards Set

Cybersecurity Flashcards – Quizlet Format

Question | Answer

CIA Triad | Confidentiality, Integrity, Availability – the three core principles of cybersecurity.

Risk Formula | Risk = Threat × Vulnerability × Consequence.

Threat Actor | An individual or group that poses a cybersecurity threat.

Phishing | A deceptive email or message tricking users into revealing personal information.

Baiting | A social engineering attack that lures victims with fake rewards or incentives.

Ransomware | Malware that encrypts data and demands a ransom for its release.

Man-in-the-Middle Attack (MITM) | A cyberattack where an attacker intercepts communication between two parties.

SQL Injection | An attack that manipulates database queries to gain unauthorized access.

Cross-Site Scripting (XSS) | Injecting malicious scripts into web pages to steal user data.

Zero Trust Model | A security approach that requires verification for all users and devices before granting access.

Multi-Factor Authentication (MFA) | A security measure requiring two or more verification methods.

Incident Response Plan | A structured approach to handling cybersecurity incidents and breaches.

Access Control | The process of restricting access to systems and data to authorized users.

Password Hygiene | Best practices for creating and managing strong passwords.

Passphrase | A long, easy-to-remember phrase used as a secure alternative to a password.

Brute Force Attack | A hacking method that systematically tries all possible passwords.

Credential Stuffing | A cyberattack where stolen credentials are used to access multiple accounts.

Salting & Hashing | Methods used to secure stored passwords by adding random data (salting) before encryption (hashing).

Firewall | A network security device that monitors and blocks unauthorized traffic.

Social Engineering | Manipulating individuals into divulging confidential information.

Denial of Service (DoS) | Overloading a system to make it unavailable to users.

Insider Threat | A security risk posed by employees or trusted individuals misusing access.

Dark Web | A part of the internet used for anonymous activities, including illegal transactions.

Personally Identifiable Information (PII) | Data that can uniquely identify a person, such as SSN or email.

Data Privacy | The practice of ensuring that personal data is collected and handled securely.

Big Data | Large and complex datasets analyzed to reveal patterns and trends.

Ethical Hacking | Legally testing security systems to identify and fix vulnerabilities.

Advanced Persistent Threat (APT) | A prolonged, targeted cyberattack conducted by skilled hackers.

Security Posture | The overall strength and readiness of an organization’s cybersecurity defenses.

Defense-in-Depth | A layered security strategy that employs multiple defense mechanisms.

Cyber Attribution | The process of identifying the source and intent of cyberattacks.

Indicators of Compromise (IOC) | Evidence that a system has been breached.

Indicators of Attack (IOA) | Early signs that an attack is currently in progress.

Zero-Day Exploit | A vulnerability that is unknown to software vendors and actively exploited by hackers.

Synthetic Identity | A fake identity created using real and stolen data.

Nation-State Hacker | A hacker working on behalf of a government to conduct cyber espionage.

Dark Web Monitoring | A service that alerts users if their credentials are found on the dark web.

Encryption | The process of converting data into a secure format to prevent unauthorized access.

Decryption | The process of converting encrypted data back into its original format.

Fingerprinting | A tracking method that collects device or browser-specific data to identify users.

Malware | Malicious software designed to disrupt, damage, or gain unauthorized access to systems.

Spyware | Software that secretly collects information about a user without their knowledge.

Patch Management | The process of updating software to fix security vulnerabilities.

Cyber Hygiene | Routine security practices that reduce cyber risks and improve defenses.

Digital Footprint | The trail of data left by online activities and interactions.

Two-Factor Authentication (2FA) | A security process requiring two different forms of verification.

Social Media Scraping | Collecting personal data from social media profiles for malicious use.

Botnet | A network of infected computers controlled by an attacker.

Data Breach | Unauthorized access or disclosure of confidential information.

Password Cracking | The act of deciphering a password through various hacking techniques.

Keylogger | Malware that records keystrokes to steal sensitive information.

Sandboxing | Running applications in an isolated environment to prevent malware infections.

Patch Tuesday | A scheduled release of security updates by software companies.

Security Awareness Training | Educating employees on how to recognize and prevent cyber threats.

Threat Intelligence | Information about potential cyber threats used to enhance security defenses.

IoT Security | Protection of internet-connected devices from cyber threats.

VPN (Virtual Private Network) | A tool that encrypts internet traffic to secure online privacy.

Data Minimization | Limiting the collection of personal data to what is strictly necessary.

Man-in-the-Browser Attack | A malware attack that alters transactions within a browser session.

Deepfake | AI-generated synthetic media used for deception or impersonation.

Steganography | Hiding data within files or images to evade detection.

Supply Chain Attack | Exploiting vulnerabilities in third-party vendors to compromise organizations.

Behavioral Biometrics | Analyzing patterns in user behavior for identity verification.

Red Team vs. Blue Team | Security exercises where the Red Team (attackers) tests defenses against the Blue Team (defenders).