Save
Upgrade to remove ads
Busy. Please wait.
Log in with Clever
or

show password
Forgot Password?

Don't have an account?  Sign up 
Sign up using Clever
or

Username is available taken
show password


Make sure to remember your password. If you forget it there is no way for StudyStack to send you a reset link. You would need to create a new account.
Your email address is only used to allow you to reset your password. See our Privacy Policy and Terms of Service.


Already a StudyStack user? Log In

Reset Password
Enter the associated with your account, and we'll email you a link to reset your password.
focusNode
Didn't know it?
click below
 
Knew it?
click below
Don't Know
Remaining cards (0)
Know
0:00
Embed Code - If you would like this activity on your web page, copy the script below and paste it into your web page.

  Normal Size     Small Size show me how

2.2

security plus 2.2

TermDefinition
Threat Vector path that a threat actor uses to execute data exfiltration, service disruption, or disinformation attack
Vulnerable software software that contains a flaw in its code or design that can be exploited to circumvent access control or to crash the process
Unsupported System/Applications particular reason why vulnerable software is exposed as a threat vector. This can be due to a vendor no longer offering updates or patches to the software
Remote (exploit technique) vulnerability can be exploited by sending code to the target over a network and does not depend on authentication within the system to execute
Local (exploit technique) exploit code must be executed from an authenticated session on the computer. This can still occur over a network, but valid credentials or hijacking an existing session are required to execute it
Unsecure network network that lacks the attributes of the CIA Triad
Lack of Confidentiality threat actors can snoop on network traffic and recover passwords or other sensitive information
Lack of Integrity threat actors are able to attach unauthorize devices. Often described as “on-path attacks”
Lack of Availability Threat actors or able to perform service disruption attacks
Direct Access threat actor uses physical access to the site to perpetrate an attack
Wired Network threat actor with access to site attaches an unauthorized device to a physical network port, and the device is permitted to communicate with other hosts
Remote and Wireless Network Threat actors obtains credentials for remote access or wireless connection to the network OR cracks security protocols used for authentication
Cloud Access threat actor finds a single account , service or host with weak credentials to gain access
Bluetooth Network threat exploits a vulnerability or misconfiguration to transmit a malicious file to a user’s device
Default Credentials Threat actors gains control of a network device or app because it has been left configured with a default password
Open Service Port threat actor is able to establish an unauthorized connection to a logical TCP or UDP network port
Isolation as a substitute for patch management compensating control
Lure something superficially attractive or interesting that causes its target to want it.
Supply chain end-to-end process of designing, manufacturing, and distributing goods and services to a customer
Removable Device attacker conceals malware on a USB thumb drive or memory card and tries to trick an employee into connecting it to a device.
Executable File threat actor conceals exploit code in a program file, typically in the form of Trojan Horse malware.
Document Files threat actor conceals malicious code by embedding it in word processing and PDF format files
Image Files threat actor conceals exploit code within an image file that targes a vulnerability in a browser or document editing software
nstant Messaging (IM) there are many replacements for SMS that run on Windows, Android, or iOS devices that can support voice and video messaging plus file attachments. Most are secured using encryption, but can still contain software vulnerabilities.
Web and Social Media malware may be concealed in files attached to posts or presented as downloads. An attacker may compromise a site so that it automatically infects vulnerable browser software (called a drive-by download)
Email attacker sends a malicious file attachment via e-mail or any other communications system that allows attachments.
Short Messaging Service (SMS file or link is sent to a mobile device using the text messaging handler built into smartphone firmware and a protocol called Signaling System 7 (SS7)
Created by: OliviaGarcia2412
 

 



Voices

Use these flashcards to help memorize information. Look at the large card and try to recall what is on the other side. Then click the card to flip it. If you knew the answer, click the green Know box. Otherwise, click the red Don't know box.

When you've placed seven or more cards in the Don't know box, click "retry" to try those cards again.

If you've accidentally put the card in the wrong box, just click on the card to take it out of the box.

You can also use your keyboard to move the cards as follows:

If you are logged in to your account, this website will remember which cards you know and don't know so that they are in the same box the next time you log in.

When you need a break, try one of the other activities listed below the flashcards like Matching, Snowman, or Hungry Bug. Although it may feel like you're playing a game, your brain is still making more connections with the information to help you out.

To see how well you know the information, try the Quiz or Test activity.

Pass complete!
"Know" box contains:
Time elapsed:
Retries:
restart all cards