This is a document stipulating constraints and practices that a user must agree to for access to a corporate network or the Internet.
What is an Acceptable Use Policy?
Authenticating someone is a control for this leg of the CIA triad.
What is “Integrity”?
_________are generally younger hackers (high school or college age) with reasonably good computer skills and too much time on their hands.
What are Script Kiddies?
95% of cybersecurity breaches are caused by this.
What is Human Error?
An identification method that enables users to log in to multiple applications and websites with one set of credentials.
What is Single-Sign-On (SSO)?
This policy is often in place for employee use of personally-owned electronic assets that are used for work-related purposes.
What is a "Bring-Your-Own-Device" (BYOD) Policy?
This model outlines the obligations of CSPs and CSCs for securing cloud environments.
What is the Shared Responsibility Model?
This framework is a globally accessible knowledge base of adversary tactics and techniques based on real-world observations.
What is the MITRE ATT&CK framework?
In 2020, a cybersecurity breach affected this prominent software company, leading to unauthorized access to its source code.
What is SolarWinds?
BONUS QUESTION: This malware was used in the attack as a memory dropper.
This has all of the equipment installed but does not have active Internet or telecommunications facilities, and does not have current backups of data.
What is a Warm Site?
This is a modern security strategy based on the principle, "never trust, always verify."
What is Zero Trust?
This SOC 2 Type 2 examination opinion is issued when there are significant material and pervasive inaccuracies in the description and/or significant weaknesses in the design/operating effectiveness of controls.
What is an "adverse" opinion?
What is the term for the practice of gathering information about a target through social media and other public sources to launch targeted attacks?
What is "OSINT" or "Open Source Intelligence Gathering"?
This 2017 global ransomware attack that affected computers in over 150 countries was caused by this malware.
What is WannaCry?
This is an open-source system for automating deployment, scaling, and management of containerized applications.
What is Kubernetes?
Passed in March 2022, the Strengthening American Cybersecurity Act was passed by the Senate, which would require reporting by all nonfederal "critical infrastructure" construction to this government agency.
What is the Cybersecurity and Infrastructure Security Agency?
Information security policies, Organization of Information Security, Human Resources Security, Asset Management, Access Control, Cryptography, Physical and Environmental Security, Operations Security, Communications Security, Systems Acquisition and Maintenance, Supplier Relationships, Security Incident Management, Business Continuity Management, Compliance.
What are the 14 control domains of ISO 27001?
This type of penetration test is where the tester has an in-depth knowledge of the network and systems being tested, including network diagrams, IP addresses, and even the source code of custom applications.
What is a white box test?
This report is widely recognized across the cybersecurity industry for its comprehensive analysis of the global threat landscape, based on real-world data from actual security incidents and breaches.
What is the Verizon DBIR?
BONUS QUESTION: According to the 2023 Verizon DBIR, 1 out of every 5 breaches (19%) originates from this.
When TCP/IP was developed, the host table concept was expanded to a hierarchical name system for matching computer names and numbers known as this.
What is DNS?
BONUS QUESTION: This is the fastest IP address in the world.
This landmark OCC regulatory guidance was issued on June 6, 2023 and superseded bulletins 2013-29 and 2020-10.
What is OCC Bulletin 2023-17 OR What is Third-Party Relationships Interagency Guidance on Risk Management?
This type of report is performed by an independent CPA firm that expresses an opinion on the reliability and accuracy of an organization’s financial statements, system of internal controls, or other information.
What is an "attestation" report?
This type of testing is an automated software testing method that injects invalid, malformed, or unexpected inputs into a system to reveal software defects and vulnerabilities.
What is fuzz testing or fuzzing?
This is the global average cost of a data breach in 2023, according to the IBM Cost of a Data Breach Report.
What is $4-5M? ($4.45M)
This is an authentication system developed by the Massachusetts Institute of Technology (MIT) and used to verify the identity of networked users.
What is kerberos?