Human Element Security Flashcards
Why are humans considered the “weakest link” in cybersecurity?
Because they can be tricked or manipulated into revealing sensitive information.
What is social engineering?
The psychological manipulation of people to gain access to information or systems.
What is HUMINT (Human Intelligence)?
Intelligence gathered by talking to people rather than using technical methods.
What is OSINT (Open-Source Intelligence)?
Intelligence gathered from publicly available sources like social media, job postings, and public records.
What is Google Dorking?
A search technique that uses advanced Google search operators to find exposed data.
What is pretexting?
An attacker creates a false scenario to trick a victim into revealing sensitive information.
Example: A scammer pretends to be tech support and asks for login credentials.
What is phishing?
A fraudulent email, text, or call designed to trick users into providing information or downloading malware.
What is tailgating (piggybacking)?
When an attacker follows an authorized person into a restricted area without credentials.
What are three best practices for password security?
Use strong, unique passwords for each account.
Store passwords in a password manager.
Enable Multi-Factor Authentication (MFA).
How can employees recognize phishing emails?
Look for misspellings & unusual requests.
Check the sender’s email address.
Hover over links before clicking.
Why should employees avoid public WiFi for work?
Public WiFi lacks encryption, allowing attackers to intercept data.
What is a Clean Desk Policy?
A policy requiring employees to secure sensitive documents and lock computers when leaving their desks.