What are the three components of the CIA triad?
The CIA triad consists of Confidentiality, Integrity, and Availability.
What device forwards packets between different networks?
A router forwards packets between different networks.
What is malware?
Malware is malicious software designed to disrupt, damage, gain unauthorized access to, or otherwise compromise systems or data.
What does MFA stand for?
Multi-Factor Authentication.
What is a firewall?
A firewall monitors and controls network traffic according to defined security rules.
What does confidentiality mean in cybersecurity?
Confidentiality means ensuring that information is accessible only to authorized people or systems.
What protocol is commonly used to securely browse websites?
HTTPS (HTTP over TLS) is commonly used to securely browse websites.
What type of attack attempts to trick users into revealing sensitive information through fraudulent messages?
Phishing.
What is the principle of least privilege?
The principle of least privilege means giving users and systems only the permissions they need to perform their authorized tasks.
What is antivirus software designed to detect?
Antivirus/endpoint security software is designed to detect, block, and/or remove malicious software and other suspicious activity.
A hospital's patient database becomes unavailable because of an attack. Which part of the CIA triad has been compromised?
Availability. The patient database is no longer accessible when it is needed.
What is the primary purpose of a VPN?
A VPN (Virtual Private Network) creates an encrypted connection between a device and a VPN endpoint, helping protect network traffic from interception on untrusted networks.
What type of malware encrypts files and demands payment for their recovery?
Ransomware encrypts or otherwise locks access to data and typically demands payment in exchange for restoring access.
What is the difference between authentication and authorization?
Authentication verifies who you are. Authorization determines what you are allowed to do after your identity has been established.
Why is patching software an important security practice?
Patching fixes known software vulnerabilities, reducing opportunities for attackers to exploit weaknesses in systems.
A company uses hashing to verify that a downloaded file hasn't been altered. Which CIA property is primarily being protected?
Integrity. Hashing can be used to detect whether data has been modified or corrupted.
What is the difference between TCP and UDP?
TCP is connection-oriented and provides mechanisms for reliable, ordered delivery. UDP is connectionless and generally provides lower overhead but does not guarantee delivery or ordering.
What is a DDoS attack, and what is its primary goal?
A Distributed Denial-of-Service (DDoS) attack uses many systems or sources to overwhelm a target with traffic or requests, disrupting its availability.
What is a brute-force attack against a password?
A brute-force attack systematically attempts many possible passwords or credentials until the correct one is found.
What is defense in depth?
Defense in depth is a security strategy that uses multiple layers of security controls so that if one control fails, others can still provide protection.
A hacker gains unauthorized access to a database and changes salary records without permission. Which CIA property is primarily violated, and why?
Integrity, because the attacker has improperly modified the salary records. Integrity concerns the accuracy and trustworthiness of data.
Explain why DNS can be a security concern and name one attack involving DNS.
DNS translates domain names such as example.com into IP addresses. Because DNS is critical to network communication, attacks can manipulate or disrupt it. One example is DNS spoofing/cache poisoning, where false DNS information causes users to be directed to an incorrect destination.
How does a SQL injection attack work at a high level?
SQL injection occurs when an application improperly incorporates untrusted user input into SQL queries, potentially allowing an attacker to alter the intended database query. Proper input validation, parameterized queries, and other secure coding practices help prevent it.
Why is password reuse dangerous, and how can a password manager help?
Password reuse is dangerous because if one service is breached, attackers can try the stolen password on other accounts. A password manager can generate and store unique passwords for different accounts, reducing the impact of a single compromised credential.
An employee clicks a malicious link, but the organization's endpoint protection blocks the resulting malware. What security concept does this demonstrate?
This demonstrates defense in depth. The phishing link represents one point of compromise, while endpoint protection provides another security layer that can prevent the attack from succeeding.