What is a vulnerability?
A vulnerability is a weakness or flaw in a system, application, network, or process that can be exploited by a threat to compromise security.
What is a threat?
A threat is anything that has the potential to exploit a vulnerability and cause harm to a system, network, or organization.
What are default credentials?
Default credentials are the preset usernames and passwords that come with a device, application, or system when it is first installed or manufactured.
What is impersonation?
Impersonation is a social engineering technique where an attacker pretends to be a trusted person or organization to deceive someone into revealing sensitive information, granting access, or performing an action.
What is typosquatting?
Typosquatting is a technique where attackers create fake websites using domain names that are very similar to legitimate websites, hoping users will make typing mistakes and visit the fake site.
Who is an unintentional insider threat?
An employee accidentally uploads confidential company files to a public cloud because they were unaware of company policy.
What is data exfiltration?
Data exfiltration is the unauthorized copying, transfer, or theft of data from a computer, network, or organization to an external location.
What is the attack surface?
The attack surface is the total number of possible entry points where an attacker can try to gain unauthorized access to a system or network.
What is pretexting?
Pretexting is a social engineering attack in which an attacker creates a believable fake story (a pretext) to trick someone into revealing confidential information or performing an action.
What is spear phishing?
Spear phishing is a targeted phishing attack where an attacker creates a personalized message aimed at a specific person or organization to trick them into revealing information, clicking malicious links, or performing an unauthorized action.
Who are nation-state actors (APTs (Advanced Persistent Threats))?
They are highly skilled and well-funded hacking groups that are sponsored or supported by a government to achieve political, military, intelligence, or economic objectives.
What is service disruption?
Service disruption is an event that interrupts or prevents the normal operation of a system, network, application, or service, making it partially or completely unavailable to users.
What is a lure-based (removable device) attack?
A lure-based (removable device) attack, also known as baiting, is a social engineering attack in which an attacker leaves an infected removable device (such as a USB flash drive) where someone is likely to find it, hoping the person will plug it into their computer, allowing malware to infect the system.
What is phishing?
Phishing is a social engineering attack where attackers use fake emails, messages, websites, or communications to trick people into revealing sensitive information, clicking malicious links, or installing malware.
What is whaling?
Whaling is a highly targeted phishing attack that specifically targets high-profile individuals within an organization, such as CEOs, executives, senior managers, or other important decision-makers.
Who are script kiddies?
A script kiddie is someone with little technical knowledge (inexperienced) who uses pre-made hacking tools to attack computers or networks.
What is disinformation?
Disinformation is false or misleading information that is deliberately created and shared to deceive people or influence their opinions or actions.
What are open TCP/UDP ports?
Open TCP/UDP ports are network communication endpoints that are listening for incoming connections or data on a device.
What is vishing?
Vishing (voice phishing) is a social engineering attack where attackers use phone calls, voice messages, or other voice communication methods to trick people into revealing sensitive information or performing an unsafe action.
What is an Advanced Persistent Threat (APT)?
An Advanced Persistent Threat (APT) is a long-term, targeted cyberattack where a skilled and well-funded attacker gains unauthorized access to a system or network and remains hidden for an extended period while collecting information or causing damage.
What is a white hat hacker?
white hat hacker is a security professional who is given legal permission to test systems, networks, or applications for vulnerabilities so they can be fixed before malicious attackers exploit them.
Who is a whistleblower?
A whistleblower is a person who reports illegal, unethical, fraudulent, or unsafe activities occurring within an organization to someone who can take action.
What is a supply chain attack?
A supply chain attack targets a trusted third party (such as a software vendor, hardware manufacturer, or service provider) )so the attacker can indirectly attack many organizations that rely on that supplier.
What is SMiShing?
SMiShing is a social engineering attack that uses SMS text messages or mobile messaging to trick people into revealing sensitive information, clicking malicious links, or installing malware.
What is Business Email Compromise (BEC)?
Business Email Compromise (BEC) is a cyberattack where attackers impersonate a trusted person (such as a company executive, supplier, or employee) to trick an organization into transferring money, revealing sensitive information, or performing unauthorized actions.