Password Attacks
Regulations
Cybersecurity Basics
Hardware
Types of Cyber Attacks
100

This type of password attack involves trying to guess a password by repeatedly trying different combinations of characters.

What is a brute-force attack?

100

This U.S. government agency is responsible for enforcing federal laws related to computer crime and protecting national security.

What is the Federal Bureau of Investigation (FBI)?

100

A password that is easy to guess, such as "password" or "1234", is considered to be this.

What is a weak password?

100

This type of device is used to encrypt and decrypt data as it enters and leaves a network.

What is a VPN gateway?

100

This type of attack involves overwhelming a website with traffic in order to make it unavailable to users.

What is a DDoS attack?

200

This type of password attack involves using a pre-computed table of commonly used or easily guessable words and phrases in an attempt to crack a password.

What is a dictionary attack?

200

This U.S. regulatory agency was created to protect the integrity of the nation's financial systems and is responsible for enforcing compliance with the Gramm-Leach-Bliley Act.

What is the Federal Financial Institutions Examination Council (FFIEC)?

200

This type of software is designed to protect a computer or network from malicious software, such as viruses and Trojan horses.

What is anti-virus software?

200

This type of device is used to detect and prevent unauthorized access to a network by analyzing network traffic and identifying potential threats.

What is a firewall?

200

This type of attack involves tricking a user into giving away sensitive information, such as login credentials, by posing as a trustworthy entity. (Usually conducted through Email)

What is phishing?

300

This type of password attack involves manipulating or altering data that is entered by the user in an attempt to bypass authentication controls.

What is a SQL Injection attack?

300

This legislation, passed in 2018, aims to protect the privacy of EU citizens' personal data by regulating how it is collected, used, and shared.

What is the General Data Protection Regulation (GDPR)?

300

The practice of regularly updating software and systems to fix known vulnerabilities is known as this.

What is patching?

300

This type of device is used to store and manage digital certificates and keys used for secure communication.

What is a Hardware Security Module (HSM)?

300

This type of attack involves stealing sensitive information by intercepting communication between a user and a website.

What is a man-in-the-middle attack?

400

This type of password attack involves using information that is publicly available about a user, such as their date of birth or mother's maiden name, in an attempt to guess their password.

What is a social engineering attack?

400

This international standard provides a set of requirements for managing information security.

What is ISO/IEC 27001?

400

These three words make up the CIA triad.

What is Confidentiality, Integrity, and Availability?

400

This type of device is used to protect against threats from external devices, such as malware-infected USB drives, by analyzing them and blocking any malicious content.

What is a USB firewall?

400

This type of attack involves using malware to encrypt files on a victim's computer, making them inaccessible until a ransom is paid.

What is ransomware?

500

This type of password attack involves the use of malware to steal a user's password, often by recording keystrokes or capturing screenshots of the user's computer.

What is a keylogger or screenlogger attack?

500

This regulation, passed in 2002, requires that publicly traded companies disclose material cybersecurity risks and incidents to investors.

What is the Sarbanes-Oxley Act (SOX)?

500

This type of security measure is used to restrict access to a computer or network to only authorized users.  

What is authentication?

500

This type of device is used to protect against network-based attacks, such as DDoS and Man-in-the-Middle attacks, by diverting traffic to a secure location for analysis.

What is a Network Intrusion Prevention System (NIPS)?

500

This type of attack involves exploiting vulnerabilities in software in order to gain unauthorized access to a computer or network.

What is an exploit attack?