EXAM Flashcards
What are 3 types of social engineering?
- Pretexting
- Phishing
- Vishing
What is the difference between a worm and a virus?
A worm doesn’t need to attach itself to an existing program
What is a virus?
A program that spreads by modifying other programs or files
What is a DoS attack?
Denial of Service
How does a DoS attack work?
Flood the system or network with traffic
What is a DDOS?
Distributed Denial of Service
When is a brute force attack most effective?
When passwords or encryption codes can be extracted to be attacked off-site
What type of attack is associated with command and control (C&C) centers?
Botnets and Zombies
What is a DMZ in networking?
Area of the network that is accessible to both internal and external users
What is Port-Forwarding?
Rule-based method of directing traffic between devices on separate networks
Which is safer, using a DMZ or Port-Forwarding?
Port-Forwarding
What does WEP stand for?
Wired Equivalent Privacy
What does WPA stand for?
Wi-Fi Protected Access
Which wireless security protocol included AES?
WPA2
What are the 2 protocols associated with 802.11i?
- TKIP (WPA)
- CCMP (WPA2)
What is an MIC?
Message Integrity Check
What is EAP?
Extensible Authentication Protocol
What is EAP-TLS associated with?
RADIUS server
What are the 2 steps with EAP-TLS authentication?
- Exchange digital certificates with public key
- Exchange random number encrypted with public key
What is a very common type of DoS attack?
HTTP flood
What is a TFN? (DDoS)
Tribe Flood Network
What are 3 examples of a TFN attack? (DDoS)
- UDP flood
- TCP SYN flood
- Smurf/Fraggle
How do classic DoS attacks work?
Exploit TCP/IP protocol by sending packets with unexpected header information
What is a SMURF attack?
Flood the host with ICMP PINGS
What is a Fraggle attack?
Uses UDP to flood the host
What is a teardrop attack?
Crafting a packet that contains nonsense (gaps, overlaps) that crashes the victim when trying to reassemble
What is spoofing?
Falsifying the address
What is a LAND attack?
Local Area Network Denial