Identifying Threat Actors
Threat Motivations
Attack Surface & Vectors
Social Engineering
Business Email & Advanced Attacks
100

What is a vulnerability?

A vulnerability is a weakness or flaw in a system, application, network, or process that can be exploited by a threat to compromise security.

100

What is a threat?

A threat is anything that has the potential to exploit a vulnerability and cause harm to a system, network, or organization.

100

What are default credentials?

Default credentials are the preset usernames and passwords that come with a device, application, or system when it is first installed or manufactured.

100

What is impersonation?

Impersonation is a social engineering technique where an attacker pretends to be a trusted person or organization to deceive someone into revealing sensitive information, granting access, or performing an action.

100

What is typosquatting?

Typosquatting is a technique where attackers create fake websites using domain names that are very similar to legitimate websites, hoping users will make typing mistakes and visit the fake site.

200

Who is an unintentional insider threat?

An employee accidentally uploads confidential company files to a public cloud because they were unaware of company policy.

200

What is data exfiltration?

Data exfiltration is the unauthorized copying, transfer, or theft of data from a computer, network, or organization to an external location.

200

What is the attack surface?

The attack surface is the total number of possible entry points where an attacker can try to gain unauthorized access to a system or network.

200

What is pretexting?

Pretexting is a social engineering attack in which an attacker creates a believable fake story (a pretext) to trick someone into revealing confidential information or performing an action.

200

What is spear phishing?

Spear phishing is a targeted phishing attack where an attacker creates a personalized message aimed at a specific person or organization to trick them into revealing information, clicking malicious links, or performing an unauthorized action.

300

Who are nation-state actors (APTs (Advanced Persistent Threats))?

They are highly skilled and well-funded hacking groups that are sponsored or supported by a government to achieve political, military, intelligence, or economic objectives.

300

What is service disruption?

Service disruption is an event that interrupts or prevents the normal operation of a system, network, application, or service, making it partially or completely unavailable to users.

300

What is a lure-based (removable device) attack?

A lure-based (removable device) attack, also known as baiting, is a social engineering attack in which an attacker leaves an infected removable device (such as a USB flash drive) where someone is likely to find it, hoping the person will plug it into their computer, allowing malware to infect the system.

300

What is phishing?

Phishing is a social engineering attack where attackers use fake emails, messages, websites, or communications to trick people into revealing sensitive information, clicking malicious links, or installing malware.

300

What is whaling?

Whaling is a highly targeted phishing attack that specifically targets high-profile individuals within an organization, such as CEOs, executives, senior managers, or other important decision-makers.

400

Who are script kiddies?

A script kiddie is someone with little technical knowledge (inexperienced) who uses pre-made hacking tools to attack computers or networks.

400

What is disinformation?

Disinformation is false or misleading information that is deliberately created and shared to deceive people or influence their opinions or actions.

400

 What are open TCP/UDP ports?

Open TCP/UDP ports are network communication endpoints that are listening for incoming connections or data on a device.

400

What is vishing?

Vishing (voice phishing) is a social engineering attack where attackers use phone calls, voice messages, or other voice communication methods to trick people into revealing sensitive information or performing an unsafe action.

400

What is an Advanced Persistent Threat (APT)?

An Advanced Persistent Threat (APT) is a long-term, targeted cyberattack where a skilled and well-funded attacker gains unauthorized access to a system or network and remains hidden for an extended period while collecting information or causing damage.

500

What is a white hat hacker?

white hat hacker is a security professional who is given legal permission to test systems, networks, or applications for vulnerabilities so they can be fixed before malicious attackers exploit them.

500

Who is a whistleblower?

A whistleblower is a person who reports illegal, unethical, fraudulent, or unsafe activities occurring within an organization to someone who can take action.

500

What is a supply chain attack?

A supply chain attack targets a trusted third party (such as a software vendor, hardware manufacturer, or service provider) )so the attacker can indirectly attack many organizations that rely on that supplier.

500

What is SMiShing?

SMiShing is a social engineering attack that uses SMS text messages or mobile messaging to trick people into revealing sensitive information, clicking malicious links, or installing malware.

500

What is Business Email Compromise (BEC)?

Business Email Compromise (BEC) is a cyberattack where attackers impersonate a trusted person (such as a company executive, supplier, or employee) to trick an organization into transferring money, revealing sensitive information, or performing unauthorized actions.