click below
click below
Normal Size Small Size show me how
Chapter 16
Ch 16.2 vocab
| Term | Definition |
|---|---|
| PHI (protected health information) | Regulated data about a person's health status or health care as defined by HIPAA (the Health Insurance Portability and Accountability Act). There are serious penalties and risks if this information is not protected |
| Phishing | Sending an email message with the intent of getting the user to reveal private information that can be used for identity theft |
| PII (personally identifiable information) | Regulated data that identifies a person, including a Social Security number, email address, physical address, birthdate, birthplace, mother's maiden name, marital status, phone numbers, race, and biometric data |
| principle of least privilege | a user is classified to determine the privileges they need to do their jobs |
| rainbow table | A list of plain text passwords and their corresponding encrypted passwords, which are called "hashes." It can be used by hackers to crack the encryption code used to store passwords and figure out users' passwords |
| ransomware | Malware that holds your computer system hostage with encryption techniques until you pay money or until a given time period expires and the encrypted content is destroyed |
| root certificate | The original digital certificate issued by a Certificate Authority |
| rootkit | A type of malicious software that loads itself before the OS boot is complete and can hijack internal OS components. UEFI Secure Boot is especially designed to prevent this type of malware from loading during boot |
| server lock | A physical lock that prevents someone from opening a computer case |
| short message service (SMS) | messaging protocol that is not encrypted and can be hacked |
| shoulder surfing | As you work, other people secretly peeking at your monitor screen to gain valuable information |
| site license | A license that allows a company to install multiple copies of software |
| smart card | Any small device that contains authentication information that can be keyed into a sign-in window or read by a reader to authenticate a user on a network |
| soft token | used to restrict access to a secured physical location using data you can receive |
| spear phishing | A form of phishing where an email message appears to come from a company you already do business with |
| Spoofing | Tricking someone into thinking an imitation of a website or email message is legitimate. For example, a phishing technique tricks you into clicking a link in an email message, which takes you to an official-looking website where you are asked to enter you |
| Spyware | Malicious software that installs itself on your computer or mobile device to spy on you. It collects personal information about you and transmits it over the Internet to web-hosting sites that intend to use the information for harm |
| Structured Query Language (SQL) | popular scripting and programming language designed primarily to query databases |
| Tailgating | When an unauthorized person follows an employee through a secured entrance to a room or building |
| Trojan | A type of malware that tricks you into downloading and/or opening it by substituting itself for a legitimate program |
| two-factor authentication (2FA) | When two tokens or actions are required to authenticate to a computer or network. Factors can include what a person knows (password), what she possesses (a token such as a key fob or smart card), what she does (such as typing a certain way), or who she is |
| virus | A program that is infectious and is intended to cause damage. It might destroy data and programs |
| vishing | a phone call scam phishing attack that uses voice to try to lure you into giving out personal information |
| whaling | a phishing attack that targets a high-profile employee |
| worm | An infestation designed to copy itself repeatedly to memory, drive space, or a network until little memory, disk space, or network bandwidth remains |
| zero-day attack | An attack in which a hacker discovers and exploits a security hole in software before its developer can provide a protective patch to close the hole |
| zero-fill utility | A hard drive utility that fills every sector on the drive with zeroes |
| zombie | A computer that has been hacked to run repetitive software in the background without the knowledge of its user. A group of these working together is called a botnet |