Social Engineering
Authentication
AI Threats
Attack Surface/Threat Actors
100

What is an example of social engineering?

Examples include:

Phishing

Piggybacking

Shoulder Surfing

Pretexting

100

A password is an example of: 

Something you know

100

How can AI be used by cybersecurity professionals

Analyze and find patterns in data

Reduce response time

Adapt to new threats

100

Unskilled attackers who lack technical expertise and rely on tools created by others to vandalize sites or cause chaos

Script Kiddies

200

Social engineering relies on ________ and _________.

Deception and Trickery


200

How can you protect against someone finding out your password?

Multi-Factor Authentication (MFA)

200

The synthetic media technology used in the Arup Engineering incident to impersonate several corporate executives on a video call and steal $25 million.

Deepfakes
200

The use of unauthorized technology, applications, or devices by employees without IT department approval

Shadow IT

300

How do you identify a phishing email?

Grammar mistakes

Email address does not match

Suspicious links

Urgency

300

What are 4 factors that make up a good password?

Complexity

Length

Unique

Not personal

300

What is Polymorphic Malware?

 Malware that constantly alters its code to evade detection by traditional antivirus software

300

What is the main distinction between authorized and unauthorized hackers?

Permission

400

How does a attacker gather info on a target? What is the step called?

Uses OSINT

Step is Reconnaissance

400

How do passwords actually get stored?

Passwords are stored as hashes.

They are put through a hashing algorithm which is supposed to be a one-way conversion.

400

 An offensive AI attack where adversaries manipulate training datasets to trick AI models like spam filters into misclassifying threats

Data Poisoning

400

Name 3 three different attack surfaces

Default/Weak credentials

Open ports

Removable media

Unsupported systems

500

What does OSINT stand for?

Open Source Intelligence Tools

500

Random data added as an additional input to a one-way hash function to neutralize rainbow table lookup attacks

Salt

500

Public repositories maintained by security communities that AI tools scan to track and patch known software vulnerabilities.

CVE Database (Common Vulnerabilities and Exposures)

500

 Hackers who break laws or security policies, but usually without malicious purpose, falling between authorized and unauthorized hackers

Semi-Authorized (Grey Hats)