This type of attack tricks users into revealing sensitive information through fake emails.
What is Phishing?
This device filters traffic based on rules and protects networks.
What is a firewall?
This type of encryption uses the same key to encrypt and decrypt data.
What is symmetric encryption?
This verifies who you are before granting access.
What is authentication?
This is the likelihood of a threat exploiting a vulnerability.
What is risk?
This tool scans systems for known vulnerabilities.
What is a vulnerability scanner?
Malware that locks files and demands payment.
What is ransomware?
This protocol securely encrypts web traffic.
What is HTTPS?
This ensures data has not been altered.
What is integrity?
Using two or more authentication methods is called this.
What is MFA (multi-factor authentication)?
Accepting a risk without mitigation is called this.
What is risk acceptance?
This tool captures and analyzes network traffic.
What is a packet sniffer?
An attack that overwhelms a system with traffic.
What is a Dos/DDoS attack?
A network designed to securely connect remote users?
What is a VPN?
This uses a public and private key pair.
What is asymmetric encryption?
Granting only necessary access is called this principle.
What is least privilege?
Transferring risk to another party is called this.
What is risk transfer?
This tool tests defenses by simulating attacks.
What is a penetration testing tool?
Malware that spreads without user interaction.
What is a worm?
This separates internal networks from external ones.
What is a DMZ?
A digital fingerprint of data is called this.
What is a hash?
Matching a fingerprint or face scan is this type of factor.
What is biometric authentication?
This identifies and evaluates risks.
What is risk assessment?
This monitors and logs system activity for analysis.
What is SIEM?
An attacker intercepting communication between two parties.
What is a man-in-the-middle attack?
This detects and prevents malicious activity in real time.
What is an IPS (Intrusion Prevention System)?
This verifies the sender and ensures non-repudiation.
What is a digital signature?
Granting access based on roles is called this model.
What is RBAC (Role-Based Access Control)?
Eliminating a risk completely is called this.
What is risk avoidance?
This isolates suspicious files to analyze behavior.
What is a sandbox?