Untitled Flashcards Set
Cybersecurity Flashcards – Quizlet Format
Question | Answer
CIA Triad | Confidentiality, Integrity, Availability – the three core principles of cybersecurity.
Risk Formula | Risk = Threat × Vulnerability × Consequence.
Threat Actor | An individual or group that poses a cybersecurity threat.
Phishing | A deceptive email or message tricking users into revealing personal information.
Baiting | A social engineering attack that lures victims with fake rewards or incentives.
Ransomware | Malware that encrypts data and demands a ransom for its release.
Man-in-the-Middle Attack (MITM) | A cyberattack where an attacker intercepts communication between two parties.
SQL Injection | An attack that manipulates database queries to gain unauthorized access.
Cross-Site Scripting (XSS) | Injecting malicious scripts into web pages to steal user data.
Zero Trust Model | A security approach that requires verification for all users and devices before granting access.
Multi-Factor Authentication (MFA) | A security measure requiring two or more verification methods.
Incident Response Plan | A structured approach to handling cybersecurity incidents and breaches.
Access Control | The process of restricting access to systems and data to authorized users.
Password Hygiene | Best practices for creating and managing strong passwords.
Passphrase | A long, easy-to-remember phrase used as a secure alternative to a password.
Brute Force Attack | A hacking method that systematically tries all possible passwords.
Credential Stuffing | A cyberattack where stolen credentials are used to access multiple accounts.
Salting & Hashing | Methods used to secure stored passwords by adding random data (salting) before encryption (hashing).
Firewall | A network security device that monitors and blocks unauthorized traffic.
Social Engineering | Manipulating individuals into divulging confidential information.
Denial of Service (DoS) | Overloading a system to make it unavailable to users.
Insider Threat | A security risk posed by employees or trusted individuals misusing access.
Dark Web | A part of the internet used for anonymous activities, including illegal transactions.
Personally Identifiable Information (PII) | Data that can uniquely identify a person, such as SSN or email.
Data Privacy | The practice of ensuring that personal data is collected and handled securely.
Big Data | Large and complex datasets analyzed to reveal patterns and trends.
Ethical Hacking | Legally testing security systems to identify and fix vulnerabilities.
Advanced Persistent Threat (APT) | A prolonged, targeted cyberattack conducted by skilled hackers.
Security Posture | The overall strength and readiness of an organization’s cybersecurity defenses.
Defense-in-Depth | A layered security strategy that employs multiple defense mechanisms.
Cyber Attribution | The process of identifying the source and intent of cyberattacks.
Indicators of Compromise (IOC) | Evidence that a system has been breached.
Indicators of Attack (IOA) | Early signs that an attack is currently in progress.
Zero-Day Exploit | A vulnerability that is unknown to software vendors and actively exploited by hackers.
Synthetic Identity | A fake identity created using real and stolen data.
Nation-State Hacker | A hacker working on behalf of a government to conduct cyber espionage.
Dark Web Monitoring | A service that alerts users if their credentials are found on the dark web.
Encryption | The process of converting data into a secure format to prevent unauthorized access.
Decryption | The process of converting encrypted data back into its original format.
Fingerprinting | A tracking method that collects device or browser-specific data to identify users.
Malware | Malicious software designed to disrupt, damage, or gain unauthorized access to systems.
Spyware | Software that secretly collects information about a user without their knowledge.
Patch Management | The process of updating software to fix security vulnerabilities.
Cyber Hygiene | Routine security practices that reduce cyber risks and improve defenses.
Digital Footprint | The trail of data left by online activities and interactions.
Two-Factor Authentication (2FA) | A security process requiring two different forms of verification.
Social Media Scraping | Collecting personal data from social media profiles for malicious use.
Botnet | A network of infected computers controlled by an attacker.
Data Breach | Unauthorized access or disclosure of confidential information.
Password Cracking | The act of deciphering a password through various hacking techniques.
Keylogger | Malware that records keystrokes to steal sensitive information.
Sandboxing | Running applications in an isolated environment to prevent malware infections.
Patch Tuesday | A scheduled release of security updates by software companies.
Security Awareness Training | Educating employees on how to recognize and prevent cyber threats.
Threat Intelligence | Information about potential cyber threats used to enhance security defenses.
IoT Security | Protection of internet-connected devices from cyber threats.
VPN (Virtual Private Network) | A tool that encrypts internet traffic to secure online privacy.
Data Minimization | Limiting the collection of personal data to what is strictly necessary.
Man-in-the-Browser Attack | A malware attack that alters transactions within a browser session.
Deepfake | AI-generated synthetic media used for deception or impersonation.
Steganography | Hiding data within files or images to evade detection.
Supply Chain Attack | Exploiting vulnerabilities in third-party vendors to compromise organizations.
Behavioral Biometrics | Analyzing patterns in user behavior for identity verification.
Red Team vs. Blue Team | Security exercises where the Red Team (attackers) tests defenses against the Blue Team (defenders).